Threat Database Trojans Trojan.Patched.GA

Trojan.Patched.GA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,876
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: April 3, 2025
Last Seen: June 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Patched.GA on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that disguises itself as legitimate. Trojans can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take prompt action to remove it.

What Is Trojan.Patched.GA?

Trojan.Patched.GA is a type of malware that can infiltrate your system through various means, such as exploited vulnerabilities, infected software downloads, or phishing attacks. The term "Trojan" refers to the malicious software's ability to disguise itself as a legitimate program or file, making it difficult to detect. The ".Patched.GA" suffix may indicate a specific variant or modification of the malware, but without further information, it is challenging to determine its exact characteristics.

How Trojan.Patched.GA Operates

Once installed, Trojan.Patched.GA can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. In some cases, it may also install additional malware, create backdoors for remote access, or disrupt system performance. The malware can communicate with its command and control servers to receive updates, transmit stolen data, or accept commands from its operators.

Symptoms of Infection

Identifying the symptoms of a Trojan.Patched.GA infection can be challenging, as they may be subtle or resemble issues caused by other factors. However, some common indicators include slow system performance, frequent crashes, or unexplained changes to your system settings. You may also notice unusual network activity, such as unexpected connections or data transfers. Additionally, you might encounter pop-up ads, redirected searches, or other signs of malicious activity.

  • Unexplained changes to system settings or files
  • Slow system performance or frequent crashes
  • Unusual network activity or unexpected connections
  • Pop-up ads, redirected searches, or other signs of malicious activity

How to Remove Trojan.Patched.GA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the Trojan.Patched.GA malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Patched.GA from your system requires careful attention and a thorough approach. By following the steps outlined above and using reputable anti-malware tools, you can help ensure the complete removal of the malware and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system and personal data from potential threats. Regularly updating your software, using strong antivirus programs, and practicing safe browsing habits can help prevent similar infections in the future.

Analysis Report

General information

Family Name: Trojan.Patched.GA
Signature status: No Signature

Known Samples

MD5: 71e6b98d4c9bb04c0bc8c5226d8d7cf7
SHA1: a8994b33e0c82f56db2eb5a93073d39efa72ba14
SHA256: 01D98AAFB66F1227FFE21E40F56580208AC2436962DAA685606ED3C51697BA73
File Size: 133.12 KB, 133120 bytes
MD5: b7760f04416c753ad170f7f3b170a7f7
SHA1: 90e136d7d2a2459524ad36f73866495d681636c4
SHA256: 83EEBAFAC2F799EF5111CE1AE8EF459C9D2E6FBBC84AF4277CE8C92748020981
File Size: 133.12 KB, 133120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Multi-User Windows IMM32 API Client DLL
File Version
  • 10.0.19041.2673 (WinBuild.160101.0800)
  • 10.0.19041.546 (WinBuild.160101.0800)
Internal Name imm32
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename imm32
Product Name Microsoft® Windows® Operating System
Product Version
  • 10.0.19041.2673
  • 10.0.19041.546

File Traits

  • dll
  • ntdll
  • x86

Block Information

Total Blocks: 648
Potentially Malicious Blocks: 281
Whitelisted Blocks: 366
Unknown Blocks: 1

Visual Map

0 x x x x 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 2 0 0 0 x x 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x 0 0 x x x x x 0 x 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 x x x x x 0 0 0 x x x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 0 0 x x x 0 0 x 0 0 0 0 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 x 2 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 1 0 0 1 0 0 0 x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x x 0 0 x 0 0 x x 0 x x 0 x x x x 0 0 0 x 0 x 0 x x x x x 0 0 x 0 0 x 0 x x x 0 0 x x x x x x x x x x x x x x x x 0 0 0 x x 0 x 0 0 0 x 0 x x x 0 x x x 0 x 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 x x x x x x x x 0 0 0 x 0 x x x x x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x x x x x 0 0 0 x x x x x x 0 0 x 0 x x x x 0 0 x x x x x x x x x 0 x x x x x x 0 x x x 2 0 x x x x x 0 x x x x 0 x x 0 x 0 0 0 0 x x x 0 0 0 x x x x x x x 0 x x x 0 x x x 0 x x 0 0 x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x 0 0 x x 0 x 0 x x x x 0 0 2 0 0 x x 0 0 0 0 0 x 2 x 0 x x 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Patched.GA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a8994b33e0c82f56db2eb5a93073d39efa72ba14_0000133120.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\90e136d7d2a2459524ad36f73866495d681636c4_0000133120.,LiQMAxHB

Trending

Most Viewed

Loading...