Home Malware Programs Trojans Win32/Pirminay.A

Win32/Pirminay.A

Posted: May 26, 2014

Threat Metric

Threat Level: 9/10
Infected PCs: 79
First Seen: May 27, 2014
Last Seen: June 13, 2019
OS(es) Affected: Windows


Win32/Pirminay.A, also known as Trojan:Win32/Pirminay.A, is a Trojan that allows attackers to gain remote unauthorized access and control over the infected computer. Once installed, Win32/Pirminay.A makes system changes by creating potentially malicious files and registry entries on the compromised PC. Trojan:Win32/Pirminay.A might contact a remote server to report a new infection to its author, receive instructions from a remote cybercriminal, receive configuration or other data, download and run files, involving updates or other malware threats, and upload data taken from the targeted PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[system folder]\kbdcanj.exe File name: [system folder]\kbdcanj.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\~unins375.bat File name: C:\Documents and Settings\<username>\local settings\temp\~unins375.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager "PendingFileRenameOperations" = "[MALWARE FILE].exe"
Loading...