Imas neku gamad, i makni taj link jer skace NOD odmah.
http://www.threatexpert.com/files/crypted.exe.html
Code:
CRYPTED.EXE has been seen to perform the following behavior:
* The Process is packed and/or encrypted using a software packing process
* Executes a Process
* This process creates other processes on disk
* Writes to another Process's Virtual Memory (Process Hijacking)
* Adds products to the system registry
* Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
* Adds a Registry Key (RUN) to auto start Programs on system start up
* Disables the built in Windows File Protection System
* Sets processes to start during user logon
* Found on infected systems and resists interrogation by security products
* Executes Processes stored in Temporary Folders
* This Process Deletes Other Processes From Disk
* Injects code into other processes
* Copies files
CRYPTED.EXE has been the subject of the following behavior:
* Executed by Internet Explorer
* Created as a process on disk
* Executed as a Process
* Executed from Temporary Folders
* Has code inserted into its Virtual Memory space by other programs
* Registered as a Dynamic Link Library File
* Deleted as a process from disk
* Added as a Registry auto start to load Program on Boot up
* Terminated as a Process
* Copied to multiple locations on the system