Home Malware Programs Trojans TrojanDownloader:Win32/Kanav.F

TrojanDownloader:Win32/Kanav.F

Posted: February 6, 2013

Threat Metric

Ranking: 13,267
Threat Level: 1/10
Infected PCs: 646
First Seen: February 6, 2013
Last Seen: February 18, 2025
OS(es) Affected: Windows

TrojanDownloader:Win32/Kanav.F is a Trojan that downloads and executes additional malware threats on the affected computer. TrojanDownloader:Win32/Kanav.F also deletes a registry entry, if found, that's associated with online gaming. Once installed, TrojanDownloader:Win32/Kanav.F makes system changes by adding potentially malicious files. TrojanDownloader:Win32/Kanav.F creates the registry entry so that it can run its copy automatically every time you start Windows. TrojanDownloader:Win32/Kanav.F queries particular websites. The website may return an encrypted string. When decrypted, the string tells TrojanDownloader:Win32/Kanav.F where to download and execute other files. TrojanDownloader:Win32/Kanav.F deletes gaming settings. TrojanDownloader:Win32/Kanav.F deletes the registry entry, if the affected PC user has it in the computer system. TrojanDownloader:Win32/Kanav.F steals information about the targeted computer, which it transmits to 'exeinfo1.org'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\Common Files\Apple\Mobile Device Support\apple.exe File name: %ProgramFiles%\Common Files\Apple\Mobile Device Support\apple.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\[RANDOM CLSID] "stubpath" = "%ProgramFiles%\Common Files\Apple\Mobile Device Support\apple.exeHKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Blizzard Entertainment\Battle.net\Identity
Loading...