La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Win32.HLLW.Autoruner2.14749

Aggiunto al database dei virus Dr.Web: 2014-05-24

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%PROGRAM_FILES%\$ntuninstallb9y8720683$\services.exe'
Creates the following files on removable media:
  • <Drive name for removable media>:\Tijuana.exe
  • <Drive name for removable media>:\autorun.inf
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\$NtUninstallB9Y8720683$\services.exe' <Full path to virus>
Modifies file system :
Creates the following files:
  • C:\RECYCLER.exe
  • %PROGRAM_FILES%.exe
  • C:\<Auxiliary name>.exe
  • %WINDIR%.exe
  • C:\System Volume Information.exe
  • <Auxiliary element>
  • C:\Tijuana.exe
  • C:\autorun.inf
  • %PROGRAM_FILES%\$NtUninstallB9Y8720683$\services.exe
  • C:\Far2.exe
  • C:\Documents and Settings.exe
  • <Current directory>.exe
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\Tijuana.exe
  • <Drive name for removable media>:\autorun.inf
  • C:\autorun.inf
  • %PROGRAM_FILES%\$NtUninstallB9Y8720683$\services.exe
  • C:\Tijuana.exe
Deletes the following files:
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00088
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00089
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00090
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00087
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00084
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00085
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00086
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00095
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00096
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00097
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00094
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00091
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00092
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00093
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00083
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00073
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00074
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00075
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00072
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00069
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00070
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00071
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00080
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00081
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00082
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00079
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00076
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00077
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00078
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00098
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.inf
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00117
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00114
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00115
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00116
  • %WINDIR%\$NtUninstallWIC$\spuninst\updspapi.dll
  • %WINDIR%\0.log
  • %WINDIR%\AppPatch\AcGenral.dll
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\updspapi.dll
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.exe
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.inf
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00113
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00103
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00104
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00105
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00102
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00099
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00100
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00101
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00110
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00111
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00112
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00109
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00106
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00107
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00108
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00068
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00025
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00026
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00027
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00024
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00021
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00022
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00023
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00032
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00033
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00034
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00031
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00028
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00029
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00030
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00020
  • %WINDIR%\$NtUninstallKB942288-v3$\msihnd.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msimsg.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msisip.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msiexec.exe
  • <Auxiliary element>
  • %PROGRAM_FILES%\$NtUninstallB9Y8720683$\services.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\msi.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00017
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00018
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00019
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00016
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00013
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00014
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00015
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00035
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00058
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00059
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00060
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00057
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00054
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00055
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00056
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00065
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00066
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00067
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00064
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00061
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00062
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00063
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00053
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00041
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00042
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00043
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00040
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00036
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00037
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00039
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00048
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00049
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00052
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00047
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00044
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00045
  • %WINDIR%\$NtUninstallKB942288-v3$\reg00046
Deletes itself.