Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Gedzac.8

Added to the Dr.Web virus database: 2011-07-09

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinStart' = '<SYSTEM32>\\8887.exe'
Malicious functions:
Executes the following:
  • <SYSTEM32>\wscript.exe C:\0383272.vbs
Terminates or attempts to terminate
the following user processes:
  • AVP32.EXE
  • Drwebupw.exe
  • ccapp.exe
  • AVPM.EXE
  • AVPCC.EXE
  • nod32.exe
  • Drweb32w.exe
  • smc.exe
Modifies file system :
Creates the following files:
  • %CommonProgramFiles%\Microsoft Shared\KAV60.exe
  • %CommonProgramFiles%\Microsoft Shared\Madonna_with_britneypussy.avi.exe
  • %CommonProgramFiles%\Microsoft Shared\Madonna_13years.jpg.exe
  • %CommonProgramFiles%\Microsoft Shared\WorldDisney_teens.exe
  • %CommonProgramFiles%\Microsoft Shared\MTVMusicAwards2004_complete.exe
  • %CommonProgramFiles%\Microsoft Shared\WindowsLongHornBETA1.exe
  • %CommonProgramFiles%\Microsoft Shared\Kaspersky_weird_movie.mpeg.exe
  • <SYSTEM32>\93756.tmp
  • C:\0383272.vbs
  • <SYSTEM32>\8887.exe
  • %CommonProgramFiles%\Microsoft Shared\TDS-4.exe
  • %CommonProgramFiles%\Microsoft Shared\LooknStop30.exe
  • %CommonProgramFiles%\Microsoft Shared\NOD32_3.0.exe
Miscellaneous:
Searches for the following windows:
  • ClassName: 'TrayNotifyWnd' WindowName: ''
  • ClassName: 'Indicator' WindowName: ''
  • ClassName: '' WindowName: '<Full path to virus>'
  • ClassName: 'Shell_TrayWnd' WindowName: ''