La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Win32.HLLW.Autoruner.56358

Aggiunto al database dei virus Dr.Web: 2011-08-15

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Naomi' = 'REG_sz'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Naomi' = '%PROGRAM_FILES%\rnamfler\Naomi.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wrna3ls' = 'REG_sz'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wrna3ls' = '%PROGRAM_FILES%\rnamfler\naomf.exe'
Creates the following files on removable media:
  • <Drive name for removable media>:\autorun.inf
Malicious functions:
Modifies settings of Windows Explorer:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayItemsDisplay' = '00000001'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] 'NoTrayItemsDisplay' = '00000001'