La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Win32.HLLW.Lime.2748

Aggiunto al database dei virus Dr.Web: 2012-08-02

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdVantage' = '%APPDATA%\advantage\AdVantage.exe'
Malicious functions:
Executes the following:
  • <SYSTEM32>\systeminfo.exe
Modifies file system :
Creates the following files:
  • %APPDATA%\advantage\AdVantage.exe
  • %APPDATA%\Microsoft\Sze\hqhmp
Deletes itself.
Miscellaneous:
Searches for the following windows:
  • ClassName: '0 35' WindowName: '0 35'
  • ClassName: '523380' WindowName: '37714 '
  • ClassName: '1 936' WindowName: '1599 '
  • ClassName: '927' WindowName: '8235 '
  • ClassName: 'Indicator' WindowName: ''
  • ClassName: '7' WindowName: ' 2 2 '
  • ClassName: '0 2710' WindowName: '0 2710'
  • ClassName: '911 0' WindowName: '898 60833'
  • ClassName: ' 5 5 6' WindowName: '06 '
  • ClassName: '690 ' WindowName: '690 '
  • ClassName: ' 20 ' WindowName: '4 37155'
  • ClassName: '9' WindowName: '807'
  • ClassName: '2' WindowName: ' 05'
  • ClassName: '37714 ' WindowName: '4 37155'