Threat Database Malware Sus.ComPack

Sus.ComPack

By LoneStar in Malware

Sus.ComPack (also known as Sus.ComPack.C and Sus.ComPack.J) is malicious software categorized as a file that displays suspicious behavior. Sus.ComPack can be downloaded by inexperienced users when visiting malicious web sites or through peer-to-peer networks. Once active, Sus.ComPack may cause obsessive pop-up advertisements to appear, registry files to go missing, changes in Internet settings, corrupt files to re-open that had previously been deleted and decreased system speed.

File System Details

Sus.ComPack may create the following file(s):
# File Name Detections
1. Update.exe
2. RAMMedic.exe
3. PCTAV.exe
4. ida.exe
5. CMServer.exe
6. RegMech.exe
7. CommFort_server.exe

Registry Details

Sus.ComPack may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ RegistryMechanic
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ RAM Medic
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Updates
RUNNING PROGRAM\CMServer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PCTAVApp
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Internet Download Accelerator
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ CommFort server

Related Posts

Trending

Most Viewed

Loading...