マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Win32.HLLW.Autoruner1.34696

Added to the Dr.Web virus database: 2013-03-30

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • %WINDIR%\Tasks\At3.job
  • %WINDIR%\Tasks\At2.job
  • %WINDIR%\Tasks\At1.job
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\Systembackup] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\ShellHWDetection] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\Schedule] 'Start' = '00000002'
Creates the following files on removable media:
  • <Drive name for removable media>:\autorun.inf
  • <Drive name for removable media>:\!Fun.exe
Malicious functions:
Creates and executes the following:
  • %PROGRAM_FILES%\at.exe 10:40 /every:M,T,W,Th,F,S,Su "%PROGRAM_FILES%\admin.exe"
  • %PROGRAM_FILES%\sc.exe config Systembackup start= auto
  • %PROGRAM_FILES%\sc.exe description Systembackup "╧╡═│╫╘╢п▒╕╖▌╖■╬ёбг"
  • <SYSTEM32>\syctem.exe
  • %PROGRAM_FILES%\at.exe 08:00 /every:M,T,W,Th,F,S,Su "C:\Autoexac.bat"
  • %PROGRAM_FILES%\at.exe 15:40 /every:M,T,W,Th,F,S,Su "%PROGRAM_FILES%\admin.exe"
  • %PROGRAM_FILES%\sc.exe start Schedule
  • %PROGRAM_FILES%\sc.exe config Schedule start= auto
  • C:\Documents and Settings\Wind-Kid.exe
  • %PROGRAM_FILES%\sc.exe CREATE Systembackup binPath= "C:\Documents and Settings\Wind-Kid.exe" START= auto DISPLAYNAME= "Systembackup" TYPE= own
  • %PROGRAM_FILES%\sc.exe start ShellHWDetection
  • %PROGRAM_FILES%\sc.exe config ShellHWDetection start= auto
Executes the following:
  • <SYSTEM32>\at.exe /delete /yes
  • <SYSTEM32>\cmd.exe /c "%PROGRAM_FILES%\OpenCreateServices.bat"
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\admin.exe
  • %WINDIR%\system\sycten.exe
  • <SYSTEM32>\syctem.exe
  • %PROGRAM_FILES%\autorun.inf
  • <SYSTEM32>\Wimlogom.exe
  • C:\Wind-Kid.txt
  • C:\autorun.inf
  • %WINDIR%\servise.exe
  • C:\Autoexac.bat
  • C:\Documents and Settings\Wind-Kid.exe
  • %PROGRAM_FILES%\OpenCreateServices.bat
  • C:\!Fun.exe
  • %PROGRAM_FILES%\sc.exe
  • %PROGRAM_FILES%\at.exe
Sets the 'hidden' attribute to the following files:
  • %PROGRAM_FILES%\admin.exe
  • %WINDIR%\system\sycten.exe
  • C:\autorun.inf
  • <SYSTEM32>\Wimlogom.exe
  • <Drive name for removable media>:\autorun.inf
  • <SYSTEM32>\syctem.exe
  • C:\Autoexac.bat
  • C:\Documents and Settings\Wind-Kid.exe
  • C:\!Fun.exe
  • %WINDIR%\servise.exe
  • <Drive name for removable media>:\!Fun.exe
Deletes the following files:
  • %PROGRAM_FILES%\admin.exe
  • <SYSTEM32>\Wimlogom.exe
  • %WINDIR%\servise.exe
  • <SYSTEM32>\syctem.exe
  • %TEMP%\~DFEBFC.tmp
  • %WINDIR%\Tasks\At3.job
  • %TEMP%\~DFD249.tmp
  • %WINDIR%\Tasks\At1.job
  • %WINDIR%\Tasks\At2.job
  • %WINDIR%\system\sycten.exe
  • %PROGRAM_FILES%\at.exe
  • %PROGRAM_FILES%\sc.exe
  • %PROGRAM_FILES%\autorun.inf
  • %TEMP%\~DFC2A3.tmp
  • C:\Documents and Settings\Wind-Kid.exe
  • C:\autorun.inf
  • <Drive name for removable media>:\autorun.inf
  • C:\!Fun.exe
  • <Drive name for removable media>:\!Fun.exe