Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Siggen.1911

Added to the Dr.Web virus database: 2011-11-09

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Update.exe
Infects the following executable system files:
  • %WINDIR%\twunk_32.exe
  • %WINDIR%\TASKMAN.EXE
  • %WINDIR%\winhlp32.exe
  • %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe
  • <Auxiliary element>
  • %WINDIR%\NOTEPAD.EXE
  • %WINDIR%\hh.exe
  • %WINDIR%\regedit.exe
  • %WINDIR%\sleep.exe
  • %WINDIR%\sfk.exe