Home Malware Programs Trojans Trojan.Win32.Powp.rdf

Trojan.Win32.Powp.rdf

Posted: August 26, 2011

Trojan.Win32.Powp.rdf is a hazardous Trojan that is able to download and install malicious programs onto a targeted computer system without the victim's consent or knowledge. Trojan.Win32.Powp.rdf deletes various system files and may affect different critical system components. Trojan.Win32.Powp.rdf may forward personal information from your computer to a third-party. It is strongly advised to remove Trojan.Win32.Powp.rdf immediately to keep your computer safe.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\hstart.exe File name: %Temp%\hstart.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\x11811.exe File name: %Temp%\x11811.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\1.exe File name: %AppData%\1.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\8.tmp File name: %AppData%\8.tmp
File type: Temporary File
Mime Type: unknown/tmp
%Programs%\Startup\start1.exe File name: %Programs%\Startup\start1.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\WinRAR SFX
Loading...