マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Win32.HLLW.Autoruner1.36906

Added to the Dr.Web virus database: 2013-05-12

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Zango Weather' = '%PROGRAM_FILES%\Zango Programs\Zango Weather\ZANGOW~1.EXE'
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\Zango Programs\Zango Weather\ZangoWeather.exe'
Executes the following:
  • '<SYSTEM32>\msiexec.exe' -Embedding 8E03A7C785F1A8B605DF1599CC1146D9
  • '<SYSTEM32>\msiexec.exe' /Y "%PROGRAM_FILES%\Zango Programs\Common\Libraries\CryptoAPI.dll"
  • '<SYSTEM32>\msiexec.exe' /q /i %TEMP%\1801.msi
  • '<SYSTEM32>\msiexec.exe' /V
Modifies file system :
Creates the following files:
  • %ALLUSERSPROFILE%\Start Menu\Programs\Zango Programs\Zango.com.url
  • %PROGRAM_FILES%\Zango Programs\Common\Zango.ico
  • %PROGRAM_FILES%\Zango Programs\Zango Weather\WeSkin.dll
  • %PROGRAM_FILES%\Zango Programs\Common\Libraries\CryptoAPI.dll
  • %APPDATA%\log.txt
  • %ALLUSERSPROFILE%\Desktop\Zango Weather.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Zango Programs\Zango Weather\Zango Weather.lnk
  • %PROGRAM_FILES%\Zango Programs\Zango Weather\ZangoWeather.exe
  • %WINDIR%\Installer\MSI2.tmp
  • %WINDIR%\Installer\2a03d.msi
  • %TEMP%\1801.msi
  • %WINDIR%\Installer\MSI3.tmp
  • C:\Config.Msi\2a040.rbs
  • %WINDIR%\Installer\MSI4.tmp
Deletes the following files:
  • C:\Config.Msi\2a040.rbs
  • %WINDIR%\Installer\2a03d.msi
  • %WINDIR%\Installer\2a03f.ipi
  • %WINDIR%\Installer\MSI2.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %WINDIR%\Installer\MSI4.tmp
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '' WindowName: 'Zango Weather Error!'
  • ClassName: '#32770' WindowName: 'Zango Weather'