Protégez votre univers

Nos autres ressources

  • free.drweb.fr — utilitaires gratuits, plugins, widgets
  • av-desk.com — service Internet pour les prestataires de services Dr.Web AV-Desk
  • curenet.drweb.com — l'utilitaire de désinfection réseau Dr.Web CureNet!
Fermer

Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Win32.HLLW.Autoruner2.25055

Added to the Dr.Web virus database: 2016-08-26

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '"%ProgramFiles%\InternetExplorer\iexplore.exe" -nohome'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '<DRIVERS>\suchost.exe'
Infects the following executable files:
  • C:\Far2\Far.exe
Creates the following files on removable media:
  • <Drive name for removable media>:\autorun.inf
  • <Drive name for removable media>:\ЎЎЎЎЎЎ.exe
Malicious functions:
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
blocks execution of the following system utilities:
  • Windows Security Center
Executes the following:
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del39$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del93$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del78$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del79$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del22$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del54$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del13$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del2$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del30$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del5$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del63$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del64$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del33$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del36$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del57$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del45$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del65$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del3$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del76$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del44$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del66$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del68$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del46$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del94$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del67$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del52$$.bat
  • '<SYSTEM32>\cmd.exe' /c net share A$ /del /y
  • '<SYSTEM32>\cmd.exe' /c net share C$ /del /y
  • '<SYSTEM32>\cmd.exe' /c net share E$ /del /y
  • '<SYSTEM32>\net.exe' share Z$ /del /y
  • '<SYSTEM32>\net.exe' share C$ /del /y
  • '<SYSTEM32>\cmd.exe' /c net share admin$ /del /y
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del24$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del74$$.bat
  • '<DRIVERS>\suchost.exe'
  • '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -Embedding
  • '<SYSTEM32>\cmd.exe' /c net share Z$ /del /y
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del97$$.bat
  • '<SYSTEM32>\net1.exe' share Z$ /del /y
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del95$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del35$$.bat
  • '<SYSTEM32>\net1.exe' share A$ /del /y
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del11$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del40$$.bat
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\del51$$.bat
  • '<SYSTEM32>\net.exe' share admin$ /del /y
  • '<SYSTEM32>\net1.exe' share C$ /del /y
  • '<SYSTEM32>\net.exe' share E$ /del /y
  • '<SYSTEM32>\net1.exe' share admin$ /del /y
  • '<SYSTEM32>\net1.exe' share E$ /del /y
  • '<SYSTEM32>\net.exe' share A$ /del /y
Terminates or attempts to terminate
the following user processes:
  • 360tray.exe
Modifies file system:
Creates the following files:
  • C:\Far2\Plugins\WinSCP\components\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\console\Desktop_.ini
  • %TEMP%\del94$$.bat
  • C:\Far2\Plugins\WinSCP\Desktop_.ini
  • C:\Far2\Plugins\ProcList\Desktop_.ini
  • C:\Far2\Plugins\TmpPanel\Desktop_.ini
  • %TEMP%\del67$$.bat
  • C:\Far2\Plugins\WinSCP\filezilla\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\filezilla\misc\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\forms\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\fari\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\core\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\dragext\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\far\Desktop_.ini
  • C:\Far2\Plugins\Network\Desktop_.ini
  • %TEMP%\del33$$.bat
  • %TEMP%\del68$$.bat
  • C:\Far2\Plugins\FarCmds\Desktop_.ini
  • %TEMP%\del79$$.bat
  • C:\Far2\Plugins\ExtSearch\keys\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\sources\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\Desktop_.ini
  • %TEMP%\del44$$.bat
  • C:\Far2\Plugins\HlfViewer\Desktop_.ini
  • C:\Far2\Plugins\MacroView\Desktop_.ini
  • %TEMP%\del66$$.bat
  • C:\Far2\Plugins\FileCase\Desktop_.ini
  • C:\Far2\Plugins\FTP\Desktop_.ini
  • C:\Far2\Plugins\FTP\lib\Desktop_.ini
  • %TEMP%\del46$$.bat
  • %TEMP%\del76$$.bat
  • %ProgramFiles%\Desktop_.ini
  • %TEMP%\del3$$.bat
  • C:\Muldrop\Desktop_.ini
  • C:\Far2\PluginSDK\Headers.c\Desktop_.ini
  • %TEMP%\del36$$.bat
  • C:\Far2\PluginSDK\Headers.pas\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\content\branding\Desktop_.ini
  • %TEMP%\del65$$.bat
  • %ProgramFiles%\FireFox\chrome\browser\content\browser\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\content\Desktop_.ini
  • %ProgramFiles%\FireFox\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\Desktop_.ini
  • C:\Far2\PluginSDK\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\filemng\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\my\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\tb2k\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\dragndrop\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\lib\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\Desktop_.ini
  • %TEMP%\del45$$.bat
  • C:\Far2\Plugins\WinSCP\release\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\resource\Desktop_.ini
  • %TEMP%\del57$$.bat
  • C:\Far2\Plugins\WinSCP\putty\charset\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\tbx\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\theme\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\putty\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\doc\Desktop_.ini
  • C:\Far2\Encyclopedia\Desktop_.ini
  • C:\autorun.inf
  • %TEMP%\87$$.Ico
  • %TEMP%\del97$$.bat
  • C:\Far2\Documentation\rus\Desktop_.ini
  • %TEMP%\del24$$.bat
  • C:\ЎЎЎЎЎЎ.exe
  • %TEMP%\del11$$.bat
  • %TEMP%\del52$$.bat
  • %TEMP%\del30$$.bat
  • %TEMP%\del40$$.bat
  • %TEMP%\del35$$.bat
  • %TEMP%\del95$$.bat
  • %TEMP%\del51$$.bat
  • C:\Far2\Documentation\eng\Desktop_.ini
  • C:\Far2\Addons\Colors\Desktop_.ini
  • C:\Far2\Addons\Colors\Custom Highlighting\Desktop_.ini
  • C:\Far2\Addons\Colors\Default Highlighting\Desktop_.ini
  • C:\Far2\Addons\Desktop_.ini
  • <DRIVERS>\suchost.exe
  • <Current directory>\Desktop_.ini
  • C:\Far2\Desktop_.ini
  • C:\Far2\Addons\XLat\Russian\Desktop_.ini
  • %TEMP%\del74$$.bat
  • C:\Far2\Documentation\Desktop_.ini
  • C:\Far2\Addons\XLat\Desktop_.ini
  • C:\Far2\Addons\Macros\Desktop_.ini
  • C:\Far2\Addons\SetUp\Desktop_.ini
  • C:\Far2\Addons\Shell\Desktop_.ini
  • %TEMP%\del2$$.bat
  • C:\Far2\Plugins\Colorer\hrd\console\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\Desktop_.ini
  • C:\Far2\Plugins\Compare\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrd\Desktop_.ini
  • %TEMP%\del93$$.bat
  • C:\Far2\Plugins\Colorer\hrc\auto\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\types\Desktop_.ini
  • C:\Far2\Plugins\EditCase\Desktop_.ini
  • C:\Far2\Plugins\EMenu\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\Desktop_.ini
  • %TEMP%\del22$$.bat
  • C:\Far2\Plugins\DrawLine\Desktop_.ini
  • %TEMP%\del39$$.bat
  • %TEMP%\del54$$.bat
  • C:\Far2\Plugins\Colorer\hrc\Desktop_.ini
  • C:\Far2\Plugins\Align\Desktop_.ini
  • %TEMP%\del64$$.bat
  • C:\Far2\Plugins\arclite\Desktop_.ini
  • C:\Far2\Plugins\7-Zip\Desktop_.ini
  • C:\Far2\FExcept\Desktop_.ini
  • C:\Far2\Plugins\Desktop_.ini
  • %TEMP%\del13$$.bat
  • C:\Far2\Plugins\Colorer\Desktop_.ini
  • %TEMP%\del78$$.bat
  • C:\Far2\Plugins\Colorer\bin\Desktop_.ini
  • C:\Far2\Plugins\Brackets\Desktop_.ini
  • %TEMP%\del63$$.bat
  • %TEMP%\del5$$.bat
  • C:\Far2\Plugins\AutoWrap\Desktop_.ini
Sets the 'hidden' attribute to the following files:
  • C:\Far2\Plugins\WinSCP\far\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\fari\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\dragext\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\console\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\core\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\lib\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\forms\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\filezilla\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\filezilla\misc\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\components\Desktop_.ini
  • C:\Far2\Plugins\FTP\lib\Desktop_.ini
  • C:\Far2\Plugins\HlfViewer\Desktop_.ini
  • C:\Far2\Plugins\FTP\Desktop_.ini
  • C:\Far2\Plugins\FarCmds\Desktop_.ini
  • C:\Far2\Plugins\FileCase\Desktop_.ini
  • C:\Far2\Plugins\TmpPanel\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\Desktop_.ini
  • C:\Far2\Plugins\ProcList\Desktop_.ini
  • C:\Far2\Plugins\MacroView\Desktop_.ini
  • C:\Far2\Plugins\Network\Desktop_.ini
  • %ProgramFiles%\Desktop_.ini
  • %ProgramFiles%\FireFox\Desktop_.ini
  • C:\Muldrop\Desktop_.ini
  • C:\Far2\PluginSDK\Headers.c\Desktop_.ini
  • C:\Far2\PluginSDK\Headers.pas\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\content\branding\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\content\browser\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\content\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\Desktop_.ini
  • %ProgramFiles%\FireFox\chrome\browser\Desktop_.ini
  • C:\Far2\PluginSDK\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\tb2k\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\tbx\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\my\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\dragndrop\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\filemng\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\release\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\resource\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\putty\charset\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\packages\theme\Desktop_.ini
  • C:\Far2\Plugins\WinSCP\putty\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\Desktop_.ini
  • <Drive name for removable media>:\ЎЎЎЎЎЎ.exe
  • <Drive name for removable media>:\autorun.inf
  • C:\Far2\Documentation\rus\Desktop_.ini
  • C:\Far2\Documentation\Desktop_.ini
  • C:\Far2\Documentation\eng\Desktop_.ini
  • C:\Far2\FExcept\Desktop_.ini
  • C:\Far2\Plugins\Desktop_.ini
  • C:\autorun.inf
  • C:\Far2\Encyclopedia\Desktop_.ini
  • C:\ЎЎЎЎЎЎ.exe
  • C:\Far2\Addons\XLat\Russian\Desktop_.ini
  • C:\Far2\Addons\Colors\Desktop_.ini
  • C:\Far2\Addons\Colors\Custom Highlighting\Desktop_.ini
  • C:\Far2\Addons\Desktop_.ini
  • <Current directory>\Desktop_.ini
  • C:\Far2\Desktop_.ini
  • C:\Far2\Addons\Shell\Desktop_.ini
  • C:\Far2\Addons\XLat\Desktop_.ini
  • C:\Far2\Addons\SetUp\Desktop_.ini
  • C:\Far2\Addons\Colors\Default Highlighting\Desktop_.ini
  • C:\Far2\Addons\Macros\Desktop_.ini
  • C:\Far2\Plugins\DrawLine\Desktop_.ini
  • C:\Far2\Plugins\EditCase\Desktop_.ini
  • C:\Far2\Plugins\Compare\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrd\console\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\keys\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\sources\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\doc\Desktop_.ini
  • C:\Far2\Plugins\EMenu\Desktop_.ini
  • C:\Far2\Plugins\ExtSearch\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrd\Desktop_.ini
  • C:\Far2\Plugins\AutoWrap\Desktop_.ini
  • C:\Far2\Plugins\Brackets\Desktop_.ini
  • C:\Far2\Plugins\arclite\Desktop_.ini
  • C:\Far2\Plugins\7-Zip\Desktop_.ini
  • C:\Far2\Plugins\Align\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\types\Desktop_.ini
  • C:\Far2\Plugins\Colorer\hrc\Desktop_.ini
  • C:\Far2\Plugins\Colorer\Desktop_.ini
  • C:\Far2\Plugins\Colorer\bin\Desktop_.ini
Deletes the following files:
  • %TEMP%\87$$.Ico
Network activity:
Connects to:
  • '<L###LNET>.0.19':445
  • '<L####NET>.0.247':445
  • '<L####NET>.0.114':445
  • '<L###LNET>.0.12':445
  • '<L####NET_GATEWAY>':445
  • '<L###LNET>.0.49':445
  • 'www.da###ng08.com':80
  • 'localhost':1287
  • '<L####NET>.0.204':445
  • '<L####NET>.0.139':445
  • '<L####NET>.0.239':445
  • '<L###LNET>.0.39':139
  • '<L####NET>.0.114':139
  • '<L###LNET>.0.19':139
  • '<L###LNET>.0.12':139
  • '<L####NET_GATEWAY>':139
  • '<L###LNET>.0.49':139
  • '<L####NET>.0.239':139
  • '<L###LNET>.0.39':445
  • '<L####NET>.0.204':139
  • '<L####NET>.0.247':139
  • '<L####NET>.0.139':139
TCP:
HTTP GET requests:
  • http://www.da###ng08.com/down/down.txt
UDP:
  • DNS ASK www.da###ng08.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebcheckMonitor' WindowName: ''
  • ClassName: '' WindowName: ''
  • ClassName: 'msctls_statusbar32' WindowName: ''
  • ClassName: 'Indicator' WindowName: ''
Editeur russe des solutions antivirus Dr.Web
Expérience dans le développement depuis 1992
Les internautes dans plus de 200 pays utilisent Dr.Web
L'antivirus est fourni en tant que service depuis 2007
Support 24/24

Dr.Web © Doctor Web
2003 — 2021

Doctor Web - éditeur russe des solutions antivirus Dr.Web. Doctor Web développe les produits Dr.Web depuis 1992.

333b, Avenue de Colmar, 67100 Strasbourg