Home Malware Programs Trojans Packed.Win32.Krap.ag

Packed.Win32.Krap.ag

Posted: November 4, 2009

Packed.Win32.Krap.ag is a harmful backdoor trojan that uses stealth techniques to remain undetected on an infected computer or network. Packed.Win32.Krap.ag spreads via computer vulnerabilities or contaminated email attachments. Packed.Win32.Krap.ag is often packed with a dangerous rogue anti-spyware application that produces excessive pop-ups and false virus alert messages. Packed.Win32.Krap.ag also changes the settings of windows for the active desktop to show malicious web content. Packed.Win32.Krap.ag is usually installed in conjunction with a rogue anti-spyware application and should be removed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\a.dat
    2 %Temp%\a.exe
    3 %Temp%\b.exe
    4 %Temp%\msd.exe
    5 %Windir%\msa.exe
    6 %Windir%\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
    7 %Windir%\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_CURRENT_USER\Software\NordBull][HKEY_CURRENT_USER\Software\PopRock]
Loading...