JavaScript support is required for our site to be fully operational in your browser.
Win32.HLLW.Lime.3517
Added to the Dr.Web virus database:
2013-12-02
Virus description added:
2013-12-04
Technical Information
To ensure autorun and distribution:
Creates the following services:
[<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
Substitutes the following executable system files:
<SYSTEM32>\qmgr.dll with <SYSTEM32>\qmgr.dll
<SYSTEM32>\dllcache\qmgr.dll with <SYSTEM32>\dllcache\qmgr.dll
Infects the following executable files:
<SYSTEM32>\qmgr.dll
<SYSTEM32>\dllcache\qmgr.dll
Modifies file system :
Creates the following files:
%PROGRAM_FILES%\wi221484nd.temp
%TEMP%\205437_res.scr
Deletes the following files:
%PROGRAM_FILES%\Internet Explorer\file.tmp
Moves the following system files:
from <SYSTEM32>\qmgr.dll to %WINDIR%\qmgr.dll
from <SYSTEM32>\dllcache\qmgr.dll to %WINDIR%\dll.bak
Moves the following files:
from %PROGRAM_FILES%\wi221484nd.temp to %PROGRAM_FILES%\Internet Explorer\file.tmp
Miscellaneous:
Searches for the following windows:
ClassName: '(null)' WindowName: 'Windows ????????'
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK