Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Win32.HLLC.Shortcut

Added to the Dr.Web virus database: 2011-09-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Substitutes the following executable system files:
  • %WINDIR%\mui\muisetup.exe with %WINDIR%\mui\muisetup.exe
  • %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe with %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe
  • %WINDIR%\Microsoft.NET\NETFXRepair.exe with %WINDIR%\Microsoft.NET\NETFXRepair.exe
  • %WINDIR%\msagent\agentsvr.exe with %WINDIR%\msagent\agentsvr.exe
  • %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe with %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe
  • <Auxiliary element> with <Auxiliary element>
  • %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe with %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe
  • <SYSTEM32>\accwiz.exe with <SYSTEM32>\accwiz.exe
  • %WINDIR%\Help\Tours\mmTour\tour.exe with %WINDIR%\Help\Tours\mmTour\tour.exe
  • %WINDIR%\regedit.exe with %WINDIR%\regedit.exe
  • %WINDIR%\sfk.exe with %WINDIR%\sfk.exe
  • %WINDIR%\hh.exe with %WINDIR%\hh.exe
  • %WINDIR%\NOTEPAD.EXE with %WINDIR%\NOTEPAD.EXE
  • %WINDIR%\twunk_32.exe with %WINDIR%\twunk_32.exe
  • %WINDIR%\winhlp32.exe with %WINDIR%\winhlp32.exe
  • %WINDIR%\sleep.exe with %WINDIR%\sleep.exe
  • %WINDIR%\TASKMAN.EXE with %WINDIR%\TASKMAN.EXE
Modifies file system :
Creates the following files:
  • %WINDIR%\Help\Tours\mmTour\gtour.ico
  • %WINDIR%\RCXA.tmp
  • %WINDIR%\Microsoft.NET\gNETFXRepair.ico
  • %WINDIR%\Help\Tours\mmTour\RCXB.tmp
  • %WINDIR%\gwinhelp.ico
  • %WINDIR%\RCX8.tmp
  • %WINDIR%\gwinhlp32.ico
  • %WINDIR%\RCX9.tmp
  • %WINDIR%\Microsoft.NET\RCXC.tmp
  • %WINDIR%\pchealth\helpctr\binaries\RCXF.tmp
  • %WINDIR%\pchealth\helpctr\binaries\gHelpCtr.ico
  • <SYSTEM32>\RCX10.tmp
  • <SYSTEM32>\gaccwiz.ico
  • %WINDIR%\msagent\RCXD.tmp
  • %WINDIR%\msagent\gagentsvr.ico
  • %WINDIR%\mui\RCXE.tmp
  • %WINDIR%\mui\gmuisetup.ico
  • %WINDIR%\gtwunk_32.ico
  • C:\Far\gUnInstall.ico
  • C:\Far\UnInstall.exe
  • C:\Far\Plugins\ffpd.exe
  • C:\Far\RCX2.tmp
  • C:\Far\Far.exe
  • %APPDATA%\Ground.exe
  • C:\Far\RCX1.tmp
  • C:\Far\gFar.ico
  • <Auxiliary element>
  • %WINDIR%\RCX6.tmp
  • %WINDIR%\gregedit.ico
  • %WINDIR%\RCX7.tmp
  • %WINDIR%\gtwunk_16.ico
  • %WINDIR%\RCX4.tmp
  • %WINDIR%\ghh.ico
  • %WINDIR%\RCX5.tmp
  • %WINDIR%\gNOTEPAD.ico
Deletes the following files:
  • %WINDIR%\gwinhlp32.ico
  • %WINDIR%\Help\Tours\mmTour\gtour.ico
  • %WINDIR%\gtwunk_32.ico
  • %WINDIR%\gwinhelp.ico
  • %WINDIR%\Microsoft.NET\gNETFXRepair.ico
  • %WINDIR%\pchealth\helpctr\binaries\gHelpCtr.ico
  • <SYSTEM32>\gaccwiz.ico
  • %WINDIR%\msagent\gagentsvr.ico
  • %WINDIR%\mui\gmuisetup.ico
  • C:\Far\UnInstall.exe
  • C:\Far\gUnInstall.ico
  • C:\Far\Far.exe
  • C:\Far\gFar.ico
  • <Auxiliary element>
  • %WINDIR%\gregedit.ico
  • %WINDIR%\gtwunk_16.ico
  • %WINDIR%\ghh.ico
  • %WINDIR%\gNOTEPAD.ico
Moves the following system files:
  • from %WINDIR%\msagent\agentsvr.exe to %WINDIR%\msagent\gagentsvr.exe
  • from %WINDIR%\mui\muisetup.exe to %WINDIR%\mui\gmuisetup.exe
  • from %WINDIR%\Help\Tours\mmTour\tour.exe to %WINDIR%\Help\Tours\mmTour\gtour.exe
  • from %WINDIR%\Microsoft.NET\NETFXRepair.exe to %WINDIR%\Microsoft.NET\gNETFXRepair.exe
  • from %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe to %WINDIR%\pchealth\helpctr\binaries\gHelpCtr.exe
  • from %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe to %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\gMicrosoft.Workflow.Compiler.exe
  • from <Auxiliary element> to <Auxiliary element>
  • from %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe to %WINDIR%\pchealth\UploadLB\Binaries\gUploadM.exe
  • from <SYSTEM32>\accwiz.exe to <SYSTEM32>\gaccwiz.exe
  • from %WINDIR%\winhlp32.exe to %WINDIR%\gwinhlp32.exe
  • from %WINDIR%\regedit.exe to %WINDIR%\gregedit.exe
  • from %WINDIR%\sfk.exe to %WINDIR%\gsfk.exe
  • from %WINDIR%\hh.exe to %WINDIR%\ghh.exe
  • from %WINDIR%\NOTEPAD.EXE to %WINDIR%\gNOTEPAD.EXE
  • from %WINDIR%\sleep.exe to %WINDIR%\gsleep.exe
  • from %WINDIR%\twunk_32.exe to %WINDIR%\gtwunk_32.exe
  • from %WINDIR%\winhelp.exe to %WINDIR%\gwinhelp.exe
  • from %WINDIR%\TASKMAN.EXE to %WINDIR%\gTASKMAN.EXE
  • from %WINDIR%\twunk_16.exe to %WINDIR%\gtwunk_16.exe