Home Malware Programs Trojans Generic!atr

Generic!atr

Posted: April 26, 2011

Generic!atr is a critical computer trojan that can make serious issues on the computer system. Generic!atr is installed, not only user's privacy is affected. Generic!atr disables anti-virus programs detected on the compromised system and enables other PCs to get a full access to a targeted computer system through created security vulnerabilities. Generic!atr can also open up a backdoor through which the attacker can get access to any data collected on your computer, such as personal and financial information. Remove Generic!atr immediately using a trustworthy anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\HEX-5823-6893-6818\jusched.exe
    2 %System%\winrtsnr.txt
    3 c:\autorun.inf
    4 c:\qviqhw.pif

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\ApcrmkehHKEY_CURRENT_USER\Software\Apcrmkeh\-72398023HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\SvcHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVERHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVERHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32\Security
Loading...