Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Autoruner.63711

Added to the Dr.Web virus database: 2011-10-14

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'MicrosoftВ® WindowsВ® Operating System' = '%TEMP%\System\audiodgi.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftВ® WindowsВ® Operating System' = '%TEMP%\System\audiodgi.exe'
Malicious functions
To bypass firewall, removes or modifies the following registry keys
  • [<HKLM>\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
  • [<HKLM>\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\47ACUCWAQO.exe' = '%APPDATA%\47ACUCWAQO.exe:*:Enabled:Wi...
  • [<HKLM>\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to file>' = '<Full path to file>:*:Enabled:Windows Mess...
Injects code into
the following user processes:
  • wmpmetwk.exe
Modifies file system
Creates the following files
  • %TEMP%\system\wmpmetwk.exe
  • %TEMP%\system\audiodgi.exe
  • %APPDATA%\47acucwaqo.exe
  • %APPDATA%\lebkuchen
Sets the 'hidden' attribute to the following files
  • %TEMP%\system\wmpmetwk.exe
  • %TEMP%\system\audiodgi.exe
Network activity
Connects to
  • 'le####hen.no-ip.org':3080
UDP
  • DNS ASK le####hen.no-ip.org
  • DNS ASK 1l#####hen.no-ip.org
Miscellaneous
Creates and executes the following
  • '%TEMP%\system\audiodgi.exe'
  • '%TEMP%\system\wmpmetwk.exe'
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<Full path to file>" /t REG_SZ /d "<Full path to file>:*...' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%APPDATA%\47ACUCWAQO.exe" /t REG_SZ /d "%APPDATA%\47ACUC...' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<Full path to file>" /t REG_SZ /d "<Full path to file>:*...
  • '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%APPDATA%\47ACUCWAQO.exe" /t REG_SZ /d "%APPDATA%\47ACUC...
  • '%WINDIR%\syswow64\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f
  • '%WINDIR%\syswow64\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%APPDATA%\47ACUCWAQO.exe" /t REG_SZ /d "%APPDATA%\47ACUCWAQO.ex...
  • '%WINDIR%\syswow64\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<Full path to file>" /t REG_SZ /d "<Full path to file>:*:Enable...