Home Malware Programs Trojans Packed.Mystic!gen6

Packed.Mystic!gen6

Posted: March 18, 2011

Packed.Mystic!gen6 is a malicious computer trojan, which gets access to one computer by using existing network exploits underground. Packed.Mystic!gen6 is able to send out malicious emails by connecting with a remote SMTP server. Packed.Mystic!gen6 creates a start-up registry entry to allow its automatic execution every time Windows starts. Remove Packed.Mystic!gen6 as quickly as possible before it leads to further injuries.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\explorer.exe:usesrini.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]userini = "%Windir%\explorer.exe:userini.exe"[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] userini = "%Windir%\explorer.exe:userini.exe"HKEY..\..\..\..{RegistryKeys}userini = "%Windir%\explorer.exe:userini.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] userini = "%Windir \explorer.exe:userini.exe"
Loading...