Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Win32.HLLW.Autoruner.8439

Added to the Dr.Web virus database: 2012-08-02

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\Userinit.exe,<SYSTEM32>\Sistem320.EXE'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'FunAlienYoi' = 'C:\READY TO READ.txt'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'FunAlienYoi2' = '%WINDIR%\aasissssmuahhh\Sistem320.EXE'
Substitutes the following executable system files:
  • <SYSTEM32>\dllcache\taskmgr.exe with <SYSTEM32>\dllcache\taskmgr.exe.new
  • <SYSTEM32>\taskmgr.exe with <SYSTEM32>\taskmgr.exe.new
Creates the following files on removable media:
  • <Drive name for removable media>:\Autorun.inf
Modifies file system :
Creates the following files:
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\desktop.ini
  • C:\Desktop.ini
  • <SYSTEM32>\dllcache\taskmgr.exe.new
  • <SYSTEM32>\taskmgr.exe.new
  • <SYSTEM32>\OEMINFO.INI
  • C:\Fun Hot Alien.scr
  • C:\Fun Alien Yoi.scr
  • C:\READY TO READ.txt
  • C:\Autorun.inf
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\Autorun.inf
Deletes the following files:
  • %WINDIR%\wiadebug.log
  • %WINDIR%\updspapi.log
  • %WINDIR%\wiaservc.log
  • %WINDIR%\wmsetup.log
  • %WINDIR%\WindowsUpdate.log
  • %WINDIR%\spupdsvc.log
  • %WINDIR%\setuperr.log
  • %WINDIR%\Sti_Trace.log
  • %WINDIR%\tsoc.log
  • %WINDIR%\tabletoc.log
  • <SYSTEM32>\wbem\Logs\FrameWork.log
  • <SYSTEM32>\wbem\Logs\wmiadap.log
  • <SYSTEM32>\wbem\Logs\wbemprox.log
  • <SYSTEM32>\wbem\Logs\wmiprov.log
  • %WINDIR%\OEWABLog.txt
  • %WINDIR%\imsins.BAK
  • <SYSTEM32>\wbem\Logs\replog.log
  • <SYSTEM32>\wbem\Logs\mofcomp.log
  • <SYSTEM32>\wbem\Logs\setup.log
  • <SYSTEM32>\wbem\Logs\wbemess.log
  • <SYSTEM32>\wbem\Logs\wbemcore.log
  • %WINDIR%\setupapi.log
  • %WINDIR%\DtcInstall.log
  • %WINDIR%\comsetup.log
  • %WINDIR%\FaxSetup.log
  • %WINDIR%\imsins.log
  • %WINDIR%\iis6.log
  • %WINDIR%\Debug\UserMode\userenv.log
  • <SYSTEM32>\taskmgr.exe
  • %WINDIR%\0.log
  • %WINDIR%\COM+.log
  • %WINDIR%\cmsetacl.log
  • %WINDIR%\KB942288-v3.log
  • %WINDIR%\ocmsn.log
  • %WINDIR%\ocgen.log
  • %WINDIR%\regopt.log
  • %WINDIR%\setupact.log
  • %WINDIR%\sessmgr.setup.log
  • %WINDIR%\msgsocm.log
  • %WINDIR%\MedCtrOC.log
  • %WINDIR%\msmqinst.log
  • %WINDIR%\ntdtcsetup.log
  • %WINDIR%\netfxocm.log
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''