Prevent Online Threats

Win32.HLLC.Winatc

Details
Win32.HLLC.Winatch
p>Win32.HLLC.Winatch is a non-memory resident companion Win32 virus. The virus itself is a Windows PE EXE file about 565Kb in length, written in the WinBatch language.
The virus searches for .EXE files (all types of .EXE files) in the current directory and moves them to the Windows TEMP “JmbHgfR” subdirectory (%WinDir%\TEMP\JmbHgfR) and overwrites original files with copies. To return control to host program the virus runs copies from the “TEMP\JmbHgfR” directory.
This virus also copies itself to the Windows directory by the name “Lisezmoi.exe” and registers this file in the system registry auto-run key:
HKCR\exefile\shell\open\command = %WinDir%\Lisezmoi.exe %1 %*

Related Posts

  • Win32.HLLC.Winatc
  • ...
  • Win32.HLLC.Sulpex
  • ...
  • Win32.HLLC.Vede
  • ...
  • Win32.HLLC.Sulpex
  • ...
  • HLLC.Eagle.770
  • ...

    Leave a Reply

    Win32.HLLC.Winatc

    Details
    Win32.HLLC.Winatch

    Win32.HLLC.Winatch is a non-memory resident companion Win32 virus. The virus itself is a Windows PE EXE file about 565Kb in size, written in the WinBatch language.
    The virus searches for .EXE files (all types of .EXE files) in the current directory and moves them to the Windows TEMP “JmbHgfR” subdirectory (%WinDir%\TEMP\JmbHgfR) and overwrites original files with copies. To return control to host program the virus runs copies from the “TEMP\JmbHgfR” directory.
    This virus also copies itself to the Windows directory by the name “Lisezmoi.exe” and registers this file in the system registry auto-run key:
    HKCR\exefile\shell\open\command = %WinDir%\Lisezmoi.exe %1 %*

    Related Posts

  • Win32.HLLC.Winatc
  • ...
  • Win32.HLLC.Sulpex
  • ...
  • Win32.HLLC.Vede
  • ...
  • Win32.HLLC.Sulpex
  • ...
  • HLLC.Eagle.770
  • ...

    Leave a Reply


    Spyware Removal Spyware Protection Tools