JavaScript support is required for our site to be fully operational in your browser. 
	
 
	
		
        
            
                
            Win32.HLLW.Autoruner1.40792 
    Added to the Dr.Web virus database:  
    2013-07-29 
    Virus description added:  
    2013-07-30 
    Technical Information  
    
    To ensure autorun and distribution:
        
        Modifies the following registry keys:
            
            
            [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'aa0rab9' = 'C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe' 
            [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe' 
            [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = 'C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe' 
             
             
         
     
    
    Malicious functions:
        
        Executes the following:
            
            
            '<SYSTEM32>\wsqmcons.exe'  
            '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART 
            '<SYSTEM32>\schtasks.exe' /delete /f /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" 
            '<SYSTEM32>\sc.exe' start w32time task_started 
            '<SYSTEM32>\sdclt.exe' /CONFIGNOTIFICATION 
            '<SYSTEM32>\taskhost.exe' $(Arg0) 
             
             
        Injects code into
            
            the following system processes:
                
             
         
     
    
    Modifies file system :
        
        Creates the following files:
            
            
            C:\ProgramData\Microsoft\RAC\Temp\sqlBBDF.tmp 
            C:\ProgramData\Microsoft\RAC\Temp\sqlBC4D.tmp 
            C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe 
            C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\Desktop.ini 
             
             
        Sets the 'hidden' attribute to the following  files:
            
            
            C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe 
             
             
        Deletes the following  files:
            
            
            C:\ProgramData\Microsoft\RAC\Temp\sqlBBDF.tmp 
            C:\ProgramData\Microsoft\RAC\Temp\sqlBC4D.tmp 
             
             
         
     
    
    Network activity:
        
        Connects to:
            
            
            'any':8800 
            'dq.##1mb4.info':8800 
             
             
        UDP:
            
            
            DNS ASK ti##.#indows.com 
            DNS ASK dn#.##ftncsi.com 
            DNS ASK dq.##1mb4.info 
             
             
         
     
    
    Miscellaneous:
        
        Searches for the following windows:
            
            
            ClassName: 'Shell_TrayWnd' WindowName: '(null)' 
            ClassName: 'Indicator' WindowName: '(null)' 
             
             
         
     
  
                 
             
            
                
            
        
    
	
 
			
		 
				
	
  
    
      
        Download  Dr.Web for Android
       
      
         
       
    
    
      
        Free three-month trial 
       
      
        All protection features available
       
      
        Renew your trial license in AppGallery/on Google Pay 
       
     
   
 
  
  
  
    
      By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more 
      
        
          
            
              OK