Home Malware Programs Trojans TR/Crypt.XPACK.Gen2

TR/Crypt.XPACK.Gen2

Posted: December 19, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 6,513
First Seen: December 19, 2011
Last Seen: January 19, 2023
OS(es) Affected: Windows

TR/Crypt.XPACK.Gen2 is a malicious Trojan that has a complex coding of scripts. TR/Crypt.XPACK.Gen2 presents itself basically as a kit of cryptic content and device that is aware of how to make the coded malware into active mode. TR/Crypt.XPACK.Gen2 is difficult to identify by security software while it is encoded. Once decoded, TR/Crypt.XPACK.Gen2 infects security software that is able to remove TR/Crypt.XPACK.Gen2. Get rid of TR/Crypt.XPACK.Gen2 immediately after detection.

Aliases

Trj/Dtcontx.A [Panda]SHeur4.BAAQ [AVG]W32/Zbot.ANM!tr [Fortinet]Trojan/Win32.Inject [AhnLab-V3]Heuristic.LooksLike.Win32.SuspiciousPE.J!83 [McAfee-GW-Edition]Trojan.Winlock.7048 [DrWeb]Troj/Agent-ZYF [Sophos]Trojan.Win32.Inject.fbae [Kaspersky]Artemis!6B2BCA561F85 [McAfee]W32/Krap.Z!tr.pws [Fortinet]Trojan.SuspectCRC [Ikarus]Mal/Krap-Z [Sophos]unknown virus Win32/DH{Mw} [AVG]W32/Jorik_Fraud.RPI!tr [Fortinet]Win32.FakeAV [Ikarus]
More aliases (363)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Escritorio\Wall Hack Pb Actualizado\RespawnMod_by_slava-zis.dll File name: RespawnMod_by_slava-zis.dll
Size: 10.75 KB (10752 bytes)
MD5: 1c02cbdf5171e071db90f715e3207c81
Detection count: 173
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Escritorio\Wall Hack Pb Actualizado
Group: Malware file
Last Updated: January 28, 2013
%PROGRAMFILES%\VictorVal\FIFA 2013 Repack\Game\fifa13.exe File name: fifa13.exe
Size: 66.02 MB (66020864 bytes)
MD5: 671b5572d807b53e47f675beb41298ca
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VictorVal\FIFA 2013 Repack\Game
Group: Malware file
Last Updated: January 19, 2023
%SystemDrive%\Users\<username>\AppData\Roaming\Protector-kdpi.exe File name: Protector-kdpi.exe
Size: 2.26 MB (2267648 bytes)
MD5: d1a85ad332e5d9ea184fb3e0d8337761
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 22, 2013
%USERPROFILE%\b077f0dc-5689.exe File name: b077f0dc-5689.exe
Size: 130.04 KB (130048 bytes)
MD5: 5f5e0b3295e3ca1e0baa398c9c868f39
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 17, 2012
%WINDIR%\TEMP\5689.sys File name: 5689.sys
Size: 141.31 KB (141312 bytes)
MD5: 8c47f7bc07adaa56526f8f80c72ece9a
Detection count: 77
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: September 16, 2013
%TEMP%\Tijdelijke map 1 voor Afschrift_Deurwaarders_exploot_dmk0986439975447uitspraak20092012 fdp.zip\Afschrift_Deurwaarders_exploot_DMS0986434475447_uitspraak20092012.ÔÇ«fdp.exe File name: Afschrift_Deurwaarders_exploot_DMS0986434475447_uitspraak20092012.ÔÇ«fdp.exe
Size: 102.91 KB (102912 bytes)
MD5: 58822ba277223c00d35718435f4b41eb
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Tijdelijke map 1 voor Afschrift_Deurwaarders_exploot_dmk0986439975447uitspraak20092012 fdp.zip
Group: Malware file
Last Updated: March 12, 2013
%USERPROFILE%\46e66f61-5796.exe File name: 46e66f61-5796.exe
Size: 86.01 KB (86016 bytes)
MD5: 06f87c90d2d0ba9754cbf7861be6a693
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 19, 2012
%USERPROFILE%\Application Data\sims3.exe File name: sims3.exe
Size: 13.7 MB (13704192 bytes)
MD5: b29529762e788f8ccf0a8344798f1fb6
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: March 30, 2015
%TEMP%\5689.sys File name: 5689.sys
Size: 137.72 KB (137728 bytes)
MD5: d4a0b293a5b5d0dc2c4238ab15289198
Detection count: 45
File type: System file
Mime Type: unknown/sys
Path: %TEMP%
Group: Malware file
Last Updated: January 19, 2012
%USERPROFILE%\Start Menu\Programs\Startup\Indexer .exe File name: Indexer .exe
Size: 2.1 MB (2104832 bytes)
MD5: e0aa8536089ac74504d68382980d45d5
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 23, 2018
%USERPROFILE%\16c85dd8-5762.exe File name: 16c85dd8-5762.exe
Size: 82.94 KB (82944 bytes)
MD5: 7036f21f78fcabe45e28ce0c0d22fdab
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: February 6, 2013
%WINDIR%\TEMP\feqfhy\setup.exe File name: setup.exe
Size: 30.72 KB (30720 bytes)
MD5: 261e576179c72343ae498516a5a11f0b
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\feqfhy
Group: Malware file
Last Updated: December 27, 2011
C:\ProgramData\WBKOYK\PAF.exe File name: PAF.exe
Size: 2.06 MB (2069100 bytes)
MD5: 2a2e6d94c69e94d79ec2444316fa3855
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\WBKOYK\PAF.exe
Group: Malware file
Last Updated: July 17, 2022
bitcfg.dll File name: bitcfg.dll
Size: 38.91 KB (38912 bytes)
MD5: b054d6aebb91333d42d2c22a53e8be6b
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 29, 2013
%USERPROFILE%\uummny171h06g-5937.exe File name: uummny171h06g-5937.exe
Size: 299.52 KB (299520 bytes)
MD5: 5f5faf0a7eab1a86884dc4617412c158
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: March 21, 2013
C:\Users\<username>\AppData\Roaming\60EC.tmp File name: 60EC.tmp
Size: 23.04 KB (23040 bytes)
MD5: 2b1fadd6cff0b89e505d351991868514
Detection count: 19
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\60EC.tmp
Group: Malware file
Last Updated: August 27, 2022
%WINDIR%\tusdmpac.dll File name: tusdmpac.dll
Size: 84.48 KB (84480 bytes)
MD5: 8bc5c44073ff33bed9fcd26e75a197c5
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: June 19, 2012
%WINDIR%\Temp\_ex-68.exe File name: _ex-68.exe
Size: 885.76 KB (885760 bytes)
MD5: 5a9dd22b1bf52ce99139fce31e137aff
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: January 10, 2012
C:\Users\<username>\AppData\Roaming\27E9.tmp File name: 27E9.tmp
Size: 23.04 KB (23040 bytes)
MD5: aeff131c648f6bb2b544003ad0c8cf18
Detection count: 12
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\27E9.tmp
Group: Malware file
Last Updated: August 27, 2022
%ALLUSERSPROFILE%\Application Data\oropwddpupc\lagopoogqu.exe File name: lagopoogqu.exe
Size: 2.49 MB (2491904 bytes)
MD5: c41885f522a63f17e6f121907cc11343
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data\oropwddpupc
Group: Malware file
Last Updated: June 25, 2012
%PROGRAMFILES%\Customized Platform Advancer\4.3.0.2200\CPAIEAddOn.dll File name: CPAIEAddOn.dll
Size: 253.95 KB (253952 bytes)
MD5: 685318e1e101bf9c535fda6e89758e88
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Customized Platform Advancer\4.3.0.2200
Group: Malware file
Last Updated: January 14, 2013
%ALLUSERSPROFILE%\h\wxywsrogbek.exe File name: wxywsrogbek.exe
Size: 3.65 MB (3658752 bytes)
MD5: f1822b6f2fc7e1daa42fdbdb1e518b9e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\h
Group: Malware file
Last Updated: January 2, 2012
%USERPROFILE%\Application Data\fontcache.exe File name: fontcache.exe
Size: 199.16 KB (199168 bytes)
MD5: 3206e2b62938d4688235b4e51f31880f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: February 22, 2012
%WINDIR%\Temp\jucheck.exe File name: jucheck.exe
Size: 870.91 KB (870912 bytes)
MD5: bea98d9215a90da649e5c69c41c988f1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: August 6, 2012
%SystemDrive%\Documents and Settings\Jean Louis Gay\Local Settings\Application Data\wnd.exe File name: wnd.exe
Size: 235 KB (235008 bytes)
MD5: 4496566c8c820e25ee4fc2fce449a8a2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Jean Louis Gay\Local Settings\Application Data
Group: Malware file
Last Updated: December 5, 2012

More files
Loading...