[filename.info logo]
[cn hh.exe][de hh.exe][es hh.exe][fr hh.exe][gb hh.exe][it hh.exe][jp hh.exe][kr hh.exe][nl hh.exe][pt hh.exe][ru hh.exe][us hh.exe]
 

hh.exe (5.2.3644.0)

Bevat in software

Naam:Windows XP Home Edition, Deutsch
Vergunning:commercieel
De verbinding van de informatie:http://www.microsoft.com/windowsxp/

De details van het dossier

De weg van het dossier:C:\WINDOWS\system32\dllcache \ hh.exe
De datum van het dossier:2002-11-09 13:47:56
Versie:5.2.3644.0
De grootte van het dossier:10.752 bytes

De knoeiboel van de controlesom en van het dossier

CRC32:DDEF5935
MD5:ED97 F327 6D9F ABCF 0068 DE21 72DF 8DA5
SHA1:1E38 7DD1 3B7B 9C98 0EEC 101C 48A9 2E84 2A08 DFF9

Het middelinformatie van de versie

Firmanaam:Microsoft Corporation
De beschrijving van het dossier:Microsoft® HTML Help Executable
De vlaggen van het dossier:PRIVATE-BUILD
Het werkende systeem van het dossier:Windows NT, Windows 2000, Windows XP, Windows 2003
Het type van dossier:Application
De versie van het dossier:5.2.3644.0
Interne naam:HH 1.4
Wettelijk auteursrecht:© Microsoft Corporation. All rights reserved.
Originele filename:HH.exe
De naam van het product:HTML Help
De versie van het product:5.2.3644.0

hh.exe werd gevonden in de volgende rapporten:

W32.Dexec

Technische details
...the following Windows files: C:\%Windir%hh.exe is copied as C:\%Windir%Fontsh.exe....
...Copies itself as: C:\%Windir%hh.exe and sets its attribute to Hidden....
De instructies van de verwijdering
...Restore these files: C:\%Windir%Fontshh.exe to C:\%Windir%hh.exe C:\%Windir%FontsNotepa.exe...
...C:\%Windir%Fontsh.exe to C:\%Windir%hh.exe C:\%Windir%FontsNotepa.exe...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.dexec.html

W32.Toal.A@mm

Technische details
...The worm specifically infects Hh.exe, which is a standard Windows executable file....
...When it sends the email message, the worm attaches the infected Hh.exe file as Binladen_brasil.exe....
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.toal.a@mm.html

W32.Blebla.Worm

Technische details
...When executed, the Myromeo.exe file looks for the running copy of HH.exe (that is associated with .chm files) and tries to stop it in order to hide its activity....
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.blebla.worm.html

W32.Nosys

Technische details
...Winhlp32.exe HH.exe If it finds those files, it...
...Winhlp32.vir Hh.vir If the Trojan finds them,...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.nosys.html

Trojan.PWS.QQPass.C

De instructies van de verwijdering
...box and replace it with the path to the Windows installation folder followed by hh.exe" %1. This will vary with the operating system and where it is installed....
...Windows NT/2000: C:WINNThh.exe" %1 Windows 95/98/Me/XP: C:WINDOWShh.exe"...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/trojan.pws.qqpass.c.html

W32.HLLW.Maax@mm

Technische details
...F-Stopw.exe HH.exe Iamapp.exe...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.maax@mm.html

W32.BleBla.J.Worm

Technische details
...To hide its activity, the Melh32.exe file attempts to terminate the HH.exe process. The worm then queries the...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.blebla.j.worm.html

W32.Benpao.Trojan

Technische details
...Changes the value: (Default) %Windir%hh.exe %1 to:...
De instructies van de verwijdering
...to: (Default) %Windir%hh.exe %1 Navigate to the key:...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.benpao.trojan.html

W32.HLLW.BenfGame.B

Technische details
...Replaces the references to hh.exe with one of the random filenames that the worm created....
De instructies van de verwijdering
...HKEY_CLASSES_ROOTchm.fileshellopencommand Restore value to: hh.exe %1 Key: HKEY_CLASSES_ROOTscrfileshellopencommand...
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.benfgame.b.html

W32.Faisal@mm

Technische details
...HKEY_CLASSES_ROOTApplicationsHH.exeShellopencommand @=%Windir%Myvwa.com...
De instructies van de verwijdering
...HKEY_CLASSES_ROOTApplicationsHH.exeShellopencommand HKEY_CLASSES_ROOTApplicationsIamapp.exeShellopencommand...
......
Bron: http://securityresponse.symantec.com/avcenter/venc/data/w32.faisal@mm.html



Valid HTML 4.01!