Home Malware Programs Trojans W32/Katusha.BN

W32/Katusha.BN

Posted: August 18, 2011

W32/Katusha.BN is a virus that installs other types of malicious applications and modifies your system in a variety of ways. As a virus, W32/Katusha.BN is capable of infecting other files with its own code and may not have any independently-visible files or processes. Because SpywareRemove.com malware researchers have also noted that W32/Katusha.BN has no serious visual symptoms, you should use an anti-malware program to detect all W32/Katusha.BN infections and remove them from your PC. To increase your chances of deleting W32/Katusha.BN with the right software, install all available updates for threat definitions prior to a system scan, since W32/Katusha.BN is a very new threat and may avoid being removed by outdated software.
 

The Many Family Members of W32/Katusha.BN

W32/Katusha.BN was first seen only by late July of 2011, but the overall Katusha family was spied out months before W32/Katusha.BN was ever noticed. The Katusha family of viruses has quite a few variants that SpywareRemove.com malware researchers have found, including the following: W32/Katusha!A7B4427FBA6E, W32/Katusha!A8D38F6C09FF, W32/Katusha!AF8FEC9382FF, W32/Katusha!B9C6067B2AFA, W32/Katusha!BFB77DEB4639, W32/Katusha!03B16FDFB7B9, W32/Katusha!07988B94B57A, W32/Katusha!085A3276E617, W32/Katusha!159EC7EB32C7, W32/Katusha!25E9A5EC9EA1, W32/Katusha!261B39A94D1C, W32/Katusha!3D8E857FFB46, W32/Katusha!494C35602941, W32/Katusha!4B4934CF2502 and W32/Katusha!610472BD46A2.
 
Although all of the above PC threats have been confirmed to be harmful for your PC, W32/Katusha.BN is particularly worthy of note for its combination of Trojan and virus-like behavior. Due to its virus capabilities, W32/Katusha.BN is able to infect multiple files that are completely unrelated to W32/Katusha.BN, allowing W32/Katusha.BN to avoid detection and deletion. However, W32/Katusha.BN is also able to download and execute .exe files in the same way that any Trojan would do, which lets W32/Katusha.BN create additional non-Katusha threats for your PC.
 
If you use a security program to detect W32/Katusha.BN, you may also find that W32/Katusha.BN is detected by one of its aliases. All currently-known W32/Katusha.BN aliases that SpywareRemove.com malware researchers have found include W32/Katusha!333429C95676, Win-Trojan/Patched.D, Trojan.Win32.Patched.mf, Trojan.Katusha.A!inf, W32/Patched.BH, Trojan-Spy.Win32.Zbot!IK, Win32:Patched-WQ, Trojan.Patched.HC, PTCH_KATUSHA.W, virus:win32/patchload.o, W32/Patched.G, Win32/Agent.CB, W32/PatchLoad.a, Win32.Katusha.Gen, Win32/Patched.HN, Trojan.Starter.1695, Mal/HckPk-A, Trojan-Spy.Zbot.gen and Win32/Patchload.U.
 

The Lifeline of W32/Katusha.BN's Assaults Against Your PC

W32/Katusha.BN uses several generally-applicable methods of monitoring your PC while W32/Katusha.BN indulges itself in a range of different attacks. SpywareRemove.com malware researchers have noted the following as the most likely attacks to be related to a W32/Katusha.BN infection:

  • W32/Katusha.BN makes additions and modifications to your web browser cookies and may steal browser-related information (such as site login names and passwords).
  • W32/Katusha.BN analyzes your memory processes and may contaminate them with its own code or try to shut down security-related processes.
  • W32/Katusha.BN analyzes a range of files and folders that are on your PC and is very likely to infect them or otherwise modify them in an undesirable way.
  • W32/Katusha.BN will download and launch program executable files without your permission. This behavior is often used to install rogue security programs (such as Home Safety Essentials, Windows System Manager, Ultimate Scan or Bogema Security) or spyware.

All of these attacks can be considered extremely dangerous, and SpywareRemove.com malware researchers recommend the use of the highest-quality and up-to-date anti-malware program that you have available, to remove W32/Katusha.BN.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAM_FILES%\W32/Katusha.BN File name: %PROGRAM_FILES%\W32/Katusha.BN
Mime Type: unknown/BN
C:\Documents and Settings\<username>\Start Menu\W32/Katusha.BN File name: C:\Documents and Settings\<username>\Start Menu\W32/Katusha.BN
Mime Type: unknown/BN
C:\Documents and Settings\<username>\W32/Katusha.BN File name: C:\Documents and Settings\<username>\W32/Katusha.BN
Mime Type: unknown/BN

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\random.exeHKEY_Current_Users\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\random.exe
Loading...