Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Lime.2527

Added to the Dr.Web virus database: 2012-05-27

Virus description added:

Technical Information

Malicious functions:
Creates and executes the following:
  • %PROGRAM_FILES%\Internet Explorer\carss.exe "%PROGRAM_FILES%\Internet Explorer\flash.ocx" LiuliuYsMain
Executes the following:
  • %WINDIR%\regedit.exe /s C:\1.reg
Modifies file system :
Creates the following files:
  • %TEMP%\144531_res.tmp
  • %TEMP%\141453_res.tmp
  • %PROGRAM_FILES%\Internet Explorer\carss.exe
Moves itself:
  • from %PROGRAM_FILES%\tmp.tmp to %PROGRAM_FILES%\Internet Explorer\SqlServer.exe
  • from <Full path to virus> to %PROGRAM_FILES%\tmp.tmp
Network activity:
Connects to:
  • 'qq####7888.vicp.cc':3660
UDP:
  • DNS ASK qq####7888.vicp.cc
Miscellaneous:
Searches for the following windows:
  • ClassName: 'RegEdit_RegEdit' WindowName: ''