La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Win32.HLLO.Siggen.5

Aggiunto al database dei virus Dr.Web: 2019-08-14

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftВ® WindowsВ® Operating System' = '%ALLUSERSPROFILE%\Application Data\xxvvra.exe'
Modifies file system
Creates the following files
  • %ALLUSERSPROFILE%\application data\xxvvra.exe
  • C:\recycler .exe
  • %ProgramFiles% .exe
  • C:\pagefile.sys .exe
  • C:\ntldr .exe
  • C:\ntdetect.com .exe
  • C:\msocache .exe
  • C:\system volume information .exe
  • C:\msdos.sys .exe
  • C:\io.sys .exe
  • C:\documents and settings .exe
  • C:\config.sys .exe
  • C:\boot.ini .exe
  • C:\autoexec.bat .exe
  • %ALLUSERSPROFILE%\application data\saaaalamm\mira.h
  • <Current directory> .exe
  • %WINDIR% .exe
Sets the 'hidden' attribute to the following files
  • %ALLUSERSPROFILE%\application data\saaaalamm\mira.h
Miscellaneous
Creates and executes the following
  • '%ALLUSERSPROFILE%\application data\xxvvra.exe'