Home Malware Programs Trojans Trojan.Downloader.Navattle.A

Trojan.Downloader.Navattle.A

Posted: December 11, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 574
First Seen: December 11, 2012
Last Seen: January 10, 2023
OS(es) Affected: Windows

Trojan.Downloader.Navattle.A (TrojanDownloader:Win32/Navattle.A) is a Trojan that downloads and runs other files from a remote server on the affected computer system. Trojan.Downloader.Navattle.A deletes a registry entry linked to the gaming service 'Battle.net'. TrojanDownloader:Win32/Navattle.A stops accounts of Battle.net from working properly. Once executed, Trojan.Downloader.Navattle.A also modifies the Windows Registry. Trojan.Downloader.Navattle.A creates the registry entry so that it can run automatically every time you start Windows. Trojan.Downloader.Navattle.A also deletes the registry key linked to 'Battle.net'.

Aliases

Downloader.Generic13.ASQQ [AVG]W32/Packcav.ERY!tr [Fortinet]Backdoor.Win32.FlyAgent [Ikarus]ASD.Prevention [AhnLab-V3]Heuristic.LooksLike.Win32.Suspicious.J!87 [McAfee-GW-Edition]TR/Dldr.Navattle.A.27 [AntiVir]Trojan.PWS.Spy.17293 [DrWeb]TrojWare.Win32.TrojanDownloader.Agent.RAK [Comodo]Mal/Packer [Sophos]Win32:Agent-ARDR [Trj] [Avast]W32/Heuristic-210!Eldorado [F-Prot]Generic Malware.ja [McAfee]Win32.Trojan.Klone.af.c [CAT-QuickHeal]Trj/Thed.V [Panda]Downloader.Generic13.RTR [AVG]
More aliases (441)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Lynx\LynxRTP.exe File name: LynxRTP.exe
Size: 163.32 KB (163328 bytes)
MD5: 10fe78c745c9f127b45d39226fe9bc7b
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Lynx
Group: Malware file
Last Updated: February 11, 2013
%LOCALAPPDATA%\Lollipop\ujfnuiem.exe File name: ujfnuiem.exe
Size: 1.57 MB (1572864 bytes)
MD5: a0dff528b19caef11458def4a9eaefae
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Lollipop
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\java\Java File name: Java
Size: 11.26 KB (11264 bytes)
MD5: c8d1b0e334bd286be6bd66ed3d09605f
Detection count: 86
Path: %APPDATA%\java
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\Adobe\AdobeTM File name: AdobeTM
Size: 11.26 KB (11264 bytes)
MD5: 406e04acc9d47ac75e96da14627a1fbc
Detection count: 85
Path: %APPDATA%\Adobe
Group: Malware file
Last Updated: February 11, 2013
%USERPROFILE%\Local Settings\Application Data\Gabest\kcjcwvnb.dll File name: kcjcwvnb.dll
Size: 327.68 KB (327680 bytes)
MD5: 5927dedd7f6357e0d1a2a571daa98873
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Local Settings\Application Data\Gabest
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\SysWOW64\svcwin.exe File name: svcwin.exe
Size: 90.11 KB (90112 bytes)
MD5: 24d1f3edadd6b055e1d21952363dc0f8
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\TEMP\mrt3F40.tmp\stdrt.exe File name: stdrt.exe
Size: 368.64 KB (368640 bytes)
MD5: a4ad0c68ced28bfbe6019b5526251614
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\mrt3F40.tmp
Group: Malware file
Last Updated: July 20, 2019
%APPDATA%\Microsoft\Windows\Templates\CertPolEng.exe File name: CertPolEng.exe
Size: 5.63 KB (5632 bytes)
MD5: 93491d3f2d36c275a2ed9a823c5df6dd
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Templates
Group: Malware file
Last Updated: October 10, 2018
%USERPROFILE%\Documents\Services\svrhoster.exe File name: svrhoster.exe
Size: 770.57 KB (770573 bytes)
MD5: 1adb2c698081b4062496cf21c6d38341
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents\Services
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\system32\nusb3mon.exe File name: nusb3mon.exe
Size: 204.23 KB (204232 bytes)
MD5: a12c5d13f8d1c8f346476ee14cf9b7f8
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 26, 2012
%APPDATA%\3EDF.exe File name: 3EDF.exe
Size: 719.87 KB (719872 bytes)
MD5: da91b47b5ab5a7bf7502383722747b9b
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: February 11, 2013
%USERPROFILE%\Local Settings\Data aplikac?\ViralixVideo\vrlxur.exe File name: vrlxur.exe
Size: 108.03 KB (108032 bytes)
MD5: 9be24e9f1a789ae1e19714d2a5daff1b
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Data aplikac?\ViralixVideo
Group: Malware file
Last Updated: February 11, 2013
%SystemDrive%\Users\<username>\1551445.exe File name: 1551445.exe
Size: 196.6 KB (196608 bytes)
MD5: 3a0f4fc949cd28605864868bc74c53a8
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\joe
Group: Malware file
Last Updated: February 11, 2013
%USERPROFILE%\ole.dll File name: ole.dll
Size: 677.88 KB (677888 bytes)
MD5: 99625bb90df006a79e563ddafdceb2ac
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%
Group: Malware file
Last Updated: February 11, 2013
%PROGRAMFILES%\Cashfiesta\FiestaBar\Cashfiesta.exe File name: Cashfiesta.exe
Size: 2.8 MB (2807808 bytes)
MD5: 41974c4323a6adf282f03cf4f03e90b5
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Cashfiesta\FiestaBar
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\Nbt\nbt.exe File name: nbt.exe
Size: 741.37 KB (741376 bytes)
MD5: 708251a98f6e80640a85735ad43140fd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Nbt
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\DataSafeDotNet.exe File name: DataSafeDotNet.exe
Size: 262.14 KB (262144 bytes)
MD5: 1e6074deacc8864278ecb3c5b95ed074
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: February 14, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\A8C.exe File name: A8C.exe
Size: 140.31 KB (140315 bytes)
MD5: 7d13462fd2195ced0c34791dea6df8a0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: May 28, 2021
%APPDATA%\RSBN.exe File name: RSBN.exe
Size: 1.14 MB (1146880 bytes)
MD5: d6e72907e70e91147ef0a1976de752de
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\A1170212789.exe File name: A1170212789.exe
Size: 53.26 KB (53260 bytes)
MD5: 6376d7f2e32da7aee1f1bbe53fb6e193
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\system32\myimppeqhm.exe File name: myimppeqhm.exe
Size: 115.2 KB (115200 bytes)
MD5: 31bf8a33632de9f239e4cd50a5fdd54f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: February 11, 2013
%TEMP%\SMSvcHost.exe File name: SMSvcHost.exe
Size: 206.86 KB (206864 bytes)
MD5: 504183ca0915005f9db666468b863ac7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 17, 2013
%Systemroot%\system32\nusb3mon.exe File name: %Systemroot%\system32\nusb3mon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AhnLab V3Lite Update Process" = "%Systemroot%\system32\nusb3mon.exe"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Blizzard Entertainment\Battle.net\Identity
Loading...