マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Win32.HLLW.Autoruner1.27585

Added to the Dr.Web virus database: 2012-10-11

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\viremoval.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintoolspro.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\killvb.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe] 'debugger' = 'notepad'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe] 'debugger' = 'notepad'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Niu.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nipsvc.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\URemovalCRC32.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV32.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nip.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcoas.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvccf.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcod.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Njeeves.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CClaw.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winrar.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sys%USERNAME%' = '<LS_APPDATA>\Desktop\Kure.EXE'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\msload .exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Logon%USERNAME%' = '<LS_APPDATA>\Desktop\Deva.EXE'
  • [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"<SYSTEM32>\4st4rg4tE.exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\4st4rg4tE.exe'
  • [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"<SYSTEM32>\msload .exe" "%1" %*'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'st4rg4tE' = '%WINDIR%\st4rg4tE.exe'
  • [<HKCU>\Control Panel\Desktop] 'SCRNSAVE.EXE' = '<SYSTEM32>\winlop.scr'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Logon%USERNAME%' = '<LS_APPDATA>\Desktop\znov.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe "<SYSTEM32>\msload .exe"'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Monitoring' = '<LS_APPDATA>\Desktop\dlllhost.com'
  • [<HKLM>\SOFTWARE\Classes\regfile\shell\open\command] '' = '"%WINDIR%\ime\bt.x.exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\inifile\shell\open\command] '' = '"<SYSTEM32>\msload .exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe] 'debugger' = 'notepad'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winzip.exe] 'debugger' = '%WINDIR%\ime\bt.x.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avguard.exe] 'debugger' = 'notepad'
  • [<HKLM>\SOFTWARE\Classes\VBSFile\Shell\Open\Command] '' = '"<SYSTEM32>\msload .exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\piffile\shell\open\command] '' = '"<SYSTEM32>\winlop.scr" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\lnkfile\shell\open\command] '' = '"<SYSTEM32>\4st4rg4tE.exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\batfile\shell\open\command] '' = '"<SYSTEM32>\materia .exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\inffile\shell\open\command] '' = '"<SYSTEM32>\4st4rg4tE.exe" "%1" %*'
  • [<HKLM>\SOFTWARE\Classes\comfile\shell\open\command] '' = '"<SYSTEM32>\winlop.scr" "%1" %*'
Creates or modifies the following files:
  • %WINDIR%\Tasks\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\desktop.ini .exe
  • %HOMEPATH%\Start Menu\Programs\Startup\desktop.ini .exe
Creates the following files on removable media:
  • <Drive name for removable media>:\Systems\New Folder.exe
  • <Drive name for removable media>:\DCIM.exe
  • <Drive name for removable media>:\Dirlist .exe
  • <Drive name for removable media>:\Systems\Folder.htt
  • <Drive name for removable media>:\desktop.ini
  • <Drive name for removable media>:\Autorun.inf
Malicious functions:
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
  • file extensions
blocks execution of the following system utilities:
  • Windows Task Manager (Taskmgr)
  • Registry Editor (RegEdit)
blocks the following features:
  • System Restore (SR)
Creates and executes the following:
  • <LS_APPDATA>\Desktop\dlllhost.com
  • %WINDIR%\st4rg4tE.exe
Terminates or attempts to terminate
the following user processes:
  • avgcc.exe
Modifies settings of Windows Explorer:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'DisallowRun' = '00000001'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFind' = '00000001'
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system :
Creates the following files:
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1049.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1053.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1045.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1046.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1055.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.3082.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.2052.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.2070.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1037.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1038.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1035.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1036.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1040.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1043.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1044.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1041.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1042.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_ServiceModelEndpointPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_ServiceModelOperationPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_Networkingperfcounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_Networkingperfcounters_v2.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_ServiceModelServicePerfCounters.ini .exe
  • %WINDIR%\Offline Web Pages\desktop.ini .exe
  • <SYSTEM32>\desktop.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_SMSvcHostPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_TransactionBridgePerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_state_perf.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\corperfmonsymbols.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_perf.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_perf2.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\netmemorycache.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_DataPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_dataperfcounters_shared12_neutral.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\PerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\_DataOracleClientPerfCounters_shared12_neutral.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1032.ini .exe
  • %WINDIR%\Fonts\desktop.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_perf.ini .exe
  • %WINDIR%\Downloaded Program Files\desktop.ini .exe
  • %WINDIR%\Driver Cache\i386\mxdwdui.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_perf2.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\_Networkingperfcounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\corperfmonsymbols.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\_dataperfcounters.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5917eb5b\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_27b9fd4f\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b50667e9\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_cd264933\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_353815cd\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_f236c56a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_c34133cb\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_7cac80ba\__AssemblyInfo__.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\_TransactionBridgePerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\_ServiceModelServicePerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\_SMSvcHostPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1025.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1030.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1031.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1028.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\locdata.1029.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\corperfmonsymbols.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_perf2.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\_DataPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\_ServiceModelEndpointPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\_ServiceModelOperationPerfCounters.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.ini .exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\_Networkingperfcounters.ini .exe
  • <SYSTEM32>\esentprf.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms28.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms34.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms26.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms27.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms3b.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms7.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms7_g.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms56.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms6.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ia3002.ini .exe
  • <SYSTEM32>\DirectX\Dinput\lgc202.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr4005.ini .exe
  • <SYSTEM32>\DirectX\Dinput\hammer.ini .exe
  • <SYSTEM32>\DirectX\Dinput\lgc207.ini .exe
  • <SYSTEM32>\DirectX\Dinput\lgc291.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms1b.ini .exe
  • <SYSTEM32>\DirectX\Dinput\lgc209.ini .exe
  • <SYSTEM32>\DirectX\Dinput\lgc20a.ini .exe
  • %WINDIR%\ime\bt.x.exe
  • <LS_APPDATA>\Desktop\Znov.EXE
  • <SYSTEM32>\wbem\Performance\WmiApRpl.ini .exe
  • <Auxiliary element>
  • <LS_APPDATA>\Desktop\Deva.EXE
  • <LS_APPDATA>\Desktop\dlllhost.com
  • %WINDIR%\St4rgt.html
  • <LS_APPDATA>\Desktop\Kure.EXE
  • <LS_APPDATA>\Desktop\Yu2n.EXE
  • <SYSTEM32>\DirectX\Dinput\mse.ini .exe
  • <SYSTEM32>\DirectX\Dinput\mse_g.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms8.ini .exe
  • <SYSTEM32>\DirectX\Dinput\ms8_g.ini .exe
  • <SYSTEM32>\DirectX\Dinput\msf1f.ini .exe
  • <SYSTEM32>\oobe\oobeinfo.ini .exe
  • <SYSTEM32>\spool\drivers\w32x86\3\mxdwdui.ini .exe
  • <SYSTEM32>\DirectX\Dinput\msprw.ini .exe
  • <SYSTEM32>\DirectX\Dinput\raiderpd.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr4003.ini .exe
  • <SYSTEM32>\tslabels.ini .exe
  • <SYSTEM32>\config\systemprofile\Application Data\desktop.ini .exe
  • <SYSTEM32>\rsvp.ini .exe
  • <SYSTEM32>\tcpmon.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\History\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\History\History.IE5\desktop.ini .exe
  • <SYSTEM32>\perfci.ini .exe
  • <SYSTEM32>\perffilt.ini .exe
  • <SYSTEM32>\mqperf.ini .exe
  • <SYSTEM32>\msdtcprf.ini .exe
  • <SYSTEM32>\PerfStringBackup.INI .exe
  • <SYSTEM32>\pschdprf.ini .exe
  • <SYSTEM32>\rasctrs.ini .exe
  • <SYSTEM32>\perfwci.ini .exe
  • <SYSTEM32>\prodspec.ini .exe
  • <SYSTEM32>\DirectX\Dinput\actc094.ini .exe
  • <SYSTEM32>\DirectX\Dinput\glmda.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Startup\desktop.ini .exe
  • <SYSTEM32>\DirectX\Dinput\glmdiggp.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr4001.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr4001_g.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr3001.ini .exe
  • <SYSTEM32>\DirectX\Dinput\gr3001_g.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RK37EMDC\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W32JX7IL\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\E4T10P5J\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\SendTo\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\desktop.ini .exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\desktop.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini .exe
  • C:\Documents and Settings\LocalService\ntuser.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\desktop.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\History\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\desktop.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\Programs\desktop.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\desktop.ini .exe
  • C:\Documents and Settings\Default User\SendTo\desktop.ini .exe
  • C:\Documents and Settings\Default User\Start Menu\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\desktop.ini .exe
  • %APPDATA%\Microsoft\Internet Explorer\Quick Launch\desktop.ini .exe
  • %APPDATA%\Mozilla\Firefox\profiles.ini .exe
  • %HOMEPATH%\ntuser.ini .exe
  • %APPDATA%\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MOE00UY1\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\BGGTYMH1\desktop.ini .exe
  • C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\ntuser.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\desktop.ini .exe
  • C:\Documents and Settings\NetworkService\Local Settings\History\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\desktop.ini .exe
  • C:\DCIM.exe
  • C:\Dirlist .exe
  • C:\Autorun.inf
  • C:\Systems\New Folder.exe
  • C:\boot.ini .exe
  • %ALLUSERSPROFILE%\Application Data\Microsoft\Network\Connections\Pbk\sharedaccess.ini .exe
  • %ALLUSERSPROFILE%\Documents\desktop.ini .exe
  • C:\desktop.ini .exe
  • %ALLUSERSPROFILE%\Application Data\desktop.ini .exe
  • <SYSTEM32>\materia .exe
  • <SYSTEM32>\msload .exe
  • <SYSTEM32>\4st4rg4tE.exe
  • <SYSTEM32>\winlop.scr
  • C:\Systems\Folder.htt
  • C:\desktop.ini
  • %WINDIR%\st4rg4tE.exe
  • %WINDIR%\syskeys.com
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Games\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\History\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\History\History.IE5\desktop.ini .exe
  • C:\Documents and Settings\Default User\Application Data\desktop.ini .exe
  • C:\Documents and Settings\Default User\Local Settings\desktop.ini .exe
  • %ALLUSERSPROFILE%\Documents\My Pictures\Desktop.ini .exe
  • %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\desktop.ini .exe
  • %ALLUSERSPROFILE%\Documents\My Music\Desktop.ini .exe
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Music\desktop.ini .exe
  • %ALLUSERSPROFILE%\Documents\My Videos\Desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\desktop.ini .exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\desktop.ini .exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\compatibility.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini .exe
  • %WINDIR%\assembly\Desktop.ini .exe
  • %HOMEPATH%\My Documents\desktop.ini .exe
  • %HOMEPATH%\My Documents\My Music\Desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\desktop.ini .exe
  • %HOMEPATH%\My Documents\My Pictures\Desktop.ini .exe
  • %HOMEPATH%\Start Menu\desktop.ini .exe
  • %HOMEPATH%\Start Menu\Programs\desktop.ini .exe
  • %HOMEPATH%\Recent\Desktop.ini .exe
  • %HOMEPATH%\SendTo\desktop.ini .exe
  • %HOMEPATH%\Local Settings\desktop.ini .exe
  • %HOMEPATH%\Local Settings\History\desktop.ini .exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.ini .exe
  • %HOMEPATH%\Favorites\Desktop.ini .exe
  • %HOMEPATH%\Local Settings\History\History.IE5\desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\desktop.ini .exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini .exe
  • %WINDIR%\desktop.ini .exe
  • %WINDIR%\msdfmap.ini .exe
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\desktop.ini .exe
  • %WINDIR%\control.ini .exe
  • %WINDIR%\ODBCINST.INI .exe
  • %WINDIR%\vbaddin.ini .exe
  • %WINDIR%\win.ini .exe
  • %WINDIR%\system.ini .exe
  • %WINDIR%\vb.ini .exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\desktop.ini .exe
  • C:\Far2\Plugins\7-Zip\7zToFar.ini .exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\desktop.ini .exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\desktop.ini .exe
  • %PROGRAM_FILES%\FireFox\application.ini .exe
  • %PROGRAM_FILES%\FireFox\platform.ini .exe
  • %PROGRAM_FILES%\FireFox\updater.ini .exe
  • %PROGRAM_FILES%\FireFox\crashreporter-override.ini .exe
  • %PROGRAM_FILES%\FireFox\crashreporter.ini .exe
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\DCIM.exe
  • %WINDIR%\ime\bt.x.exe
  • <Drive name for removable media>:\Systems\New Folder.exe
  • <Drive name for removable media>:\desktop.ini
  • <Drive name for removable media>:\Autorun.inf
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start .exe
  • <LS_APPDATA>\Desktop\Kure.EXE
  • <LS_APPDATA>\Desktop\dlllhost.com
  • <LS_APPDATA>\Desktop\Deva.EXE
  • <LS_APPDATA>\Desktop\Znov.EXE
  • <LS_APPDATA>\Desktop\Yu2n.EXE
  • %WINDIR%\st4rg4tE.exe
  • %WINDIR%\syskeys.com
  • <SYSTEM32>\winlop.scr
  • <SYSTEM32>\4st4rg4tE.exe
  • <SYSTEM32>\msload .exe
  • C:\Systems\Folder.htt
  • C:\DCIM.exe
  • <Drive name for removable media>:\Systems\Folder.htt
  • C:\Systems\New Folder.exe
  • C:\desktop.ini
  • C:\Autorun.inf
Deletes the following files:
  • %TEMP%\~DFFC8.tmp
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: 'Local Settings'
  • ClassName: '' WindowName: 'ime'
  • ClassName: '' WindowName: 'system32'
  • ClassName: 'Indicator' WindowName: ''
  • ClassName: '' WindowName: 'Folder Options'
  • ClassName: '' WindowName: 'Registry Editor'