Home Malware Programs Trojans Packed.Generic.265

Packed.Generic.265

Posted: November 9, 2009

Packed.Generic.265 is a malicious computer parasite which shows threat characteristics of a banking trojan. Packed.Generic.265 disables the firewall and steals sensitive financial data like credit card numbers and online banking login details. Packed.Generic.265 can also make screen snapshots and download additional components which provides a hacker with the remote access to the compromised system. Once detected Packed.Generic.265 should be removed from the system immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lowsec\local.ds
    2 %System%\lowsec\user.ds
    3 %System%\lowsec\user.ds.lll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]

One Comment

Loading...