Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Texmer.1079

Added to the Dr.Web virus database: 2013-12-22

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Classes\oktfile\shell\open\command] '' = 'wscript.exe -e:vbs <Drive name for removable media>:\bacck\ghostghosta\qq.txt'
Creates or modifies the following files:
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\360 QQ兼容补丁(结束掉可能导致系统崩溃)
Modifies file system :
Creates the following files:
  • %TEMP%\dvkxlkl
  • %TEMP%\aut2.tmp
  • %TEMP%\aut1.tmp
Deletes the following files:
  • %TEMP%\dvkxlkl
  • %TEMP%\aut2.tmp
  • %TEMP%\aut1.tmp