Home Malware Programs Viruses Hacktool.Generic

Hacktool.Generic

Posted: April 19, 2011

Hacktool.Generic is a malicious parasite that could be used by hackers to break into a computer system. Hacktool.Generic will download files to the consent which will lead to security risk. If your PC system is corrupted by Hacktool.Generic, then it is able to enable outside criminals to access your system where they could get access to personal files or monitor the computer. Hacktool.Generic is able to attack the system with corrupt files that can load at start-up of Windows.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonPrograms%\Startup\Micorsoft Office Startup.lnk
    2 %System%\0kl.dll
    3 %System%\getweb.dll
    4 %System%\MOS.exe
    5 %Temp%\ms2703.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\WordpadHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\IPHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\OptionsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\RTFHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\SettingsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\TextHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Word6HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\WriteHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}\ProgrammableHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{469F124F-C01C-4B01-A388-66386E7FA41D}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6AE8420-23F6-41BD-84E4-9C347378FC9D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6AE8420-23F6-41BD-84E4-9C347378FC9D}\ProxyStubClsidHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6AE8420-23F6-41BD-84E4-9C347378FC9D}\ProxyStubClsid32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6AE8420-23F6-41BD-84E4-9C347378FC9D}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\SendMail.SenderHKEY_LOCAL_MACHINE\SOFTWARE\Classes\SendMail.Sender.2HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SendMail.Sender.2\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\SendMail.Sender\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\SendMail.Sender\CurVerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}\1.0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}\1.0\0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}\1.0\0\win32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}\1.0\FLAGSHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EA1C80A8-350A-4905-855B-41FE1A252E52}\1.0\HELPDIR
Loading...