マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Win32.HLLW.Autoruner1.53789

Added to the Dr.Web virus database: 2013-08-12

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'yortsed' = '%WINDIR%\yortsed.destroy'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yortsed' = '<SYSTEM32>\yortsed.EXE'
Creates the following files on removable media:
  • <Drive name for removable media>:\Autorun.xls
  • <Drive name for removable media>:\destroy.cur
  • <Drive name for removable media>:\Autorun.inf
  • <Drive name for removable media>:\destroy.exe
  • <Drive name for removable media>:\destroy.destroy
Malicious functions:
Executes the following:
  • '%WINDIR%\explorer.exe' <Current directory>
Modifies file system :
Creates the following files:
  • C:\Far2\FarEng.nls
  • C:\Far2\FarEng.dot
  • C:\Far2\FarHun.cad
  • C:\Far2\FarGer.vbs
  • C:\Far2\FarCze.cmx
  • C:\Far2.exe
  • C:\Far2\Desktop.ini
  • C:\Far2\far.m3u
  • C:\Far2\ClearPluginsCache.log
  • C:\Far2\FarHun.ogg
  • C:\Far2\SaveSettings.wal
  • C:\Far2\RestoreSettings.cpl
  • C:\<Auxiliary name>.exe
  • <Auxiliary element>
  • C:\Far2\File_id.ico
  • C:\Far2\FarRus.zip
  • C:\Far2\FarPol.cad
  • C:\Far2\FarSpa.nrg
  • C:\Far2\FarRus.bmp
  • C:\destroy.destroy
  • C:\destroy.exe
  • %WINDIR%\Z.ilu
  • C:\Autorun.inf
  • %WINDIR%\yortsed.exe
  • <SYSTEM32>\OEMLOGO.BMP
  • <SYSTEM32>\yortsed.exe
  • <SYSTEM32>\oeminfo.ini
  • %WINDIR%\E.ilu
  • <Current directory>.exe
  • <Current directory>\Desktop.ini
  • C:\Documents and Settings.exe
  • C:\Documents and Settings\Desktop.ini
  • C:\startup_local.htm
  • C:\Autorun.pdf
  • %WINDIR%\C.ilu
  • C:\NTDETECT.mov
  • C:\destroy.amf
Sets the 'hidden' attribute to the following files:
  • C:\destroy.exe
  • <Drive name for removable media>:\Autorun.inf
  • C:\Autorun.inf
  • C:\destroy.destroy
  • %WINDIR%\yortsed.exe
  • <SYSTEM32>\yortsed.exe
  • <Drive name for removable media>:\destroy.destroy
  • <Drive name for removable media>:\destroy.exe
Deletes the following files:
  • %WINDIR%\desktop.ini
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'
  • ClassName: 'Indicator' WindowName: '(null)'
  • ClassName: '' WindowName: '(null)'