Mal/Packer

Mal/Packer Descripción

El Mal/Packer es una infección viral usada como entrada de archivos o aplicaciones malignas al sistema infectado. Puede infectar un ordenador a través de un vacío de seguridad en el navegador o de una puerta trasera por lo general sin notificar al usuario de la computadora y resulta difícil de eliminar manualmente ....

Alias

4 proveedores de seguridad marcaron este archivo como malicioso.

Software antivirus Detección
PE_Patch
Packed/Upack
Packed.Win32.NSAnti
Mal/EncPk-BW

Información Técnica

Detalles del Sistema de Archivos

Mal/Packer tiene típicamente los siguientes procesos en la memoria:
# Nombre Recuento de Detección
1 %CommonDesktopDir%\auto.exe N/A
2 %CommonPrograms%\startup\gbplugin.exe N/A
3 %CommonPrograms%\startup\sys_aupdate.exe N/A
4 %FontsDir%\b4b147bc522828731f1a016bfa72c073\system\svchost.exe N/A
5 %Profiles%\mscrss.exe N/A
6 %ProgramFiles%\aore-unpacktools\about.exe N/A
7 %ProgramFiles%\clzxabxpmdh\fuy0gh6d.exe N/A
8 %ProgramFiles%\common files\system\she.dll N/A
9 %ProgramFiles%\d93310q\gdabn.exe N/A
10 %ProgramFiles%\game accelerator\web.exe N/A
11 %ProgramFiles%\idigital technologies\key serv 2.0\srvcks.exe N/A
12 %ProgramFiles%\internet explorer\inter_1.exe N/A
13 %ProgramFiles%\internet explorer\setupapi.dll N/A
14 %ProgramFiles%\kari\win32ip.exe N/A
15 %ProgramFiles%\navilog1\gnc.exe N/A
16 %ProgramFiles%\nvsvcm.exe N/A
17 %ProgramFiles%\rss team\rs_accounts_seeker.exe N/A
18 %ProgramFiles%\sd updater\uninstall.exe N/A
19 %ProgramFiles%\windows media player\kguwc.exe N/A
20 %ProgramFiles%\winrar\original_files_and_patch\keygen.exe N/A
21 %ProgramFiles%\zero freezer 1.5\data_file.exe N/A
22 %System%\1028\1028.exe N/A
23 %System%\1037\1037.exe N/A
24 %System%\1054\1054.exe N/A
25 %System%\3076\3076.exe N/A
26 %System%\3com_dmi\3com_dmi.exe N/A
27 %System%\51b294.exe N/A
28 %System%\6553bb80.dll N/A
29 %System%\addnew.exe N/A
30 %System%\alalin.exe N/A
31 %System%\alien32.exe N/A
32 %System%\alitin.exe N/A
33 %System%\alxlin.exe N/A
34 %AppData%\timerlocksetup.exe N/A
35 %CommonPrograms%\startup\avg.exe N/A
36 %CommonPrograms%\startup\startup.exe N/A
37 %DesktopDir%\keymaker.exe N/A
38 %Profiles%\2f.tmp_bak.exe N/A
39 %ProgramFiles%\aggress\doorway generator\aggressdoorgen.exe N/A
40 %ProgramFiles%\bifrost\server.exe N/A
41 %ProgramFiles%\common files\system\qqtc32.exe N/A
42 %ProgramFiles%\counter\htmlpeek.dll N/A
43 %ProgramFiles%\game accelerator\gamexl.exe N/A
44 %ProgramFiles%\hotbounce\ifufi2\ifufi2.exe N/A
45 %ProgramFiles%\internet explorer\connection wizard\audwf.exe N/A
46 %ProgramFiles%\internet explorer\piplayer.exe N/A
47 %ProgramFiles%\internet explorer\winrar_all_version.exe N/A
48 %ProgramFiles%\myportal\speed-x\speedx.exe N/A
49 %ProgramFiles%\netlog version 2.0\netlog.exe N/A
50 %ProgramFiles%\outlook express\system.exe N/A
51 %ProgramFiles%\rss team\sqlite3.dll N/A
52 %ProgramFiles%\vopt8\vopt.exe N/A
53 %ProgramFiles%\winrar\activation.exe N/A
54 %ProgramFiles%\wolfbox\uninstall.exe N/A
55 %System%\1025\1025.exe N/A
56 %System%\1033\1033.exe N/A
57 %System%\1042\1042.exe N/A
58 %System%\2052\2052.exe N/A
59 %System%\360mo.dll N/A
60 %System%\40790400.exe N/A
61 %System%\51b380.exe N/A
62 %System%\abpexsgo.exe N/A
63 %System%\ailin.exe N/A
64 %System%\alibaba32.exe N/A
65 %System%\alitao32.exe N/A
66 %System%\alovxjmx.exe N/A
67 %AppData%\iloader.exe N/A
68 %CommonPrograms%\startup\70cuse.lnk.exe N/A
69 %CommonPrograms%\startup\msn.exe N/A
70 %CommonPrograms%\startup\windows32.exe N/A
71 %FontsDir%\unwise_.exe N/A
72 %ProgramFiles%\_twunk_64.exe N/A
73 %ProgramFiles%\bifrost\q.exe N/A
74 %ProgramFiles%\common files\efbaf.exe N/A
75 %ProgramFiles%\common files\system\vbtoedl.exe N/A
76 %ProgramFiles%\desktop lock\keygen.exe N/A
77 %ProgramFiles%\gameos\web.exe N/A
78 %ProgramFiles%\internet download manager\idman.exe N/A
79 %ProgramFiles%\internet explorer\keygen.exe N/A
80 %ProgramFiles%\internet explorer\syssmss.exe N/A
81 %ProgramFiles%\meex.exe N/A
82 %ProgramFiles%\netlog version 2.0\logview.exe N/A
83 %ProgramFiles%\outlook express\keygen.exe N/A
84 %ProgramFiles%\rss team\rsdwn.dll N/A
85 %ProgramFiles%\ssc service utility\s2csplash.dll N/A
86 %ProgramFiles%\windows nt\services.exe N/A
87 %ProgramFiles%\winrar\winrde.exe N/A
88 %System%\1.exe N/A
89 %System%\1031\1031.exe N/A
90 %System%\1041\1041.exe N/A
91 %System%\111.exe N/A
92 %System%\33f5c.dll N/A
93 %System%\3fabe9c0.exe N/A
94 %System%\51b322.exe N/A
95 %System%\about.exe N/A
96 %System%\ahikzqor.exe N/A
97 %System%\alatin.exe N/A
98 %System%\alimoto32.exe N/A
99 %System%\alitte32.exe N/A
100 %CommonPrograms%\startup\livemessenger.scr N/A

Detalles del Registro

Mal/Packer crea las siguientes entradas de registro:
RegistryKey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51716C09-6B08-4CCF-B526-718E912C0573}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{526EB425-7F56-4773-8D70-B8E45AA8E2B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74DA2FEC-F68F-4DC7-9A45-9174AC044427}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{81EB905C-EDF8-4033-80BF-E0F4F46733DF}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DE8A1A-96C5-4420-B222-EF998F697CE7}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2BCFCEE-C939-433F-A32A-7353A6E720DB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B59F0A61-EF3E-4A2B-9E3A-4A84EDDF2308}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C07B914B-C164-42D2-9838-1422C3F70D99}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CB661471-055A-4C5B-9ED0-497B9908FEF5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F181F067-7046-4DCB-993F-200990736305}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\693Vdiher{.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DjhqwVyu.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egdjhqw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ffHywPju.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ghizdwfk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hnuq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NDEdfnUhsruw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NLVVyf.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSizVyf.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NZdwfk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pflqvxsg.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PfSur{|.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfv|vprq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pihdqq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSPrq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSVYF5.exe
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TTGrfwruUws.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UdyPrq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UdyWdvn.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UvDjhqw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UvWud|.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VfdqIup.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\E0200804
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11FDB6D4-166A-47BF-A0F8-A09DABA75FC1}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{526EB425-7F56-4773-8D70-B8E45AA8E2B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6049BC02-7EDA-4C41-B4AB-D5398607C39E}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{81EB905C-EDF8-4033-80BF-E0F4F46733DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84639C2D-CD75-4081-B515-329AFCECBF19}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DE8A1A-96C5-4420-B222-EF998F697CE7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A6A5B34-D995-4C5D-9338-B5E264B4A87}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B59F0A61-EF3E-4A2B-9E3A-4A84EDDF2308}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7F1BFDC-4B6C-4E2F-AF7A-638D2D47802C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CB661471-055A-4C5B-9ED0-497B9908FEF5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E1639D0B-CC74-4C22-B662-F2F9367CBEFC}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\693ghod|v.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\693wud|.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dys.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FFhqwhu.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ffVyfKvw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hjxl.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IudphzrunVhuylfh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NdyVwduw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSIZ65.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NYVuyS.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfdjhqw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfqdvyf.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfvklhog.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfxsgpju.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsiVuy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSVYF4.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TTGrfwru.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Udy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UdyVwxe.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uizvuy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uvvdihw|.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vdiher{Wud|.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layouts\E0200804
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11FDB6D4-166A-47BF-A0F8-A09DABA75FC1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51716C09-6B08-4CCF-B526-718E912C0573}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6049BC02-7EDA-4C41-B4AB-D5398607C39E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74DA2FEC-F68F-4DC7-9A45-9174AC044427}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84639C2D-CD75-4081-B515-329AFCECBF19}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A6A5B34-D995-4C5D-9338-B5E264B4A87}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2BCFCEE-C939-433F-A32A-7353A6E720DB}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7F1BFDC-4B6C-4E2F-AF7A-638D2D47802C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C07B914B-C164-42D2-9838-1422C3F70D99}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E1639D0B-CC74-4C22-B662-F2F9367CBEFC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F181F067-7046-4DCB-993F-200990736305}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\693VriwPjuVyf.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dqwldus.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ffdss.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ffVhwPju.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GuXsgdwh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hqjlqhvhuyhu.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndffruh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npdloprq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NVZheVklhog.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\olyhvuy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfpvfvyf.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfvkhoo.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PfWud|.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pihywsv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSVYF.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qdSugPju.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\txwpvhuy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UdyPrqG.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UhjJxlgh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uvqhwvyu.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uwyvfdq.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VKVWDW.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WINGB_EN