Home Malware Programs Trojans Packed.Generic.313

Packed.Generic.313

Posted: December 13, 2010

Packed.Generic.313 is a malicious computer parasite which shows threat characteristics of a banking trojan. Packed.Generic.313 disables the firewall and steals sensitive financial data like credit card numbers and online banking login details. Packed.Generic.313 can also make screen snapshots and download additional components which provides a hacker with the remote access to the compromised system. Once detected Packed.Generic.313 should be removed from the system immediately

Aliases

FakeAlert-SecurityTool.z (McAfee)
Trojan:Win32/FakeSysdef (Microsoft)
Trojan.Win32.FakeSysdef (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %DesktopDir%\Hard Drive Diagnostic.lnk
    2 %Programs%\Hard Drive Diagnostic\Hard Drive Diagnostic.lnk
    3 %Programs%\Hard Drive Diagnostic\Uninstall Hard Drive Diagnostic.lnk
    4 %System%\wbem\Performance\WmiApRpl_new.h
    5 %Temp%\98bbb2
    6 %Temp%\98bbb2.exe
    7 %Temp%\ajyWlxBiFK.exe
    8 %Temp%\tmp2.tmp
    9 %Temp%\XPUAbBynvb.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
Loading...