La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Win32.HLLW.Autoruner2.23940

Aggiunto al database dei virus Dr.Web: 2016-05-14

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\aegvvp.exe'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\svchost.exe'
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Modifies file system:
Creates the following files:
  • %HOMEPATH%\aegvvp.exe
Sets the 'hidden' attribute to the following files:
  • %HOMEPATH%\aegvvp.exe
Network activity:
UDP:
  • DNS ASK mu###.###tal-protection.net.ru
  • DNS ASK sl###.##fehousenumber.com
  • 'mu###.###tal-protection.net.ru':30915
  • 'sl###.##fehousenumber.com':30915
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Ja' WindowName: 'Geojav Napwuw Eskh, Voghyssn Xvenr'
  • ClassName: 'Voghyssn Xvenr, Ja' WindowName: 'Geojav Napwuw Eskh'
  • ClassName: 'Iiwltf. Yih' WindowName: 'Hecwq Fckrg Cylmg U, Qlprq'
  • ClassName: 'Qlprq, Iiwltf. Yih' WindowName: 'Hecwq Fckrg Cylmg U'
  • ClassName: 'Qey. Luvu, Xmrymcp' WindowName: 'Griwmear Lwg. Y'
  • ClassName: 'Xjqwgig. Ymvkxxb' WindowName: 'Pqnan. Wommcg. Lxh'
  • ClassName: 'Ewilrao Ypum Cqed' WindowName: 'Rdrsj Tlh, Smbj'
  • ClassName: 'Xmrymcp' WindowName: 'Griwmear Lwg. Y, Qey. Luvu'
  • ClassName: 'Oduabryn Sinbbch Kb' WindowName: 'Fsdqcdt Maio, Ud'
  • ClassName: 'Hwknmklqe Eyer K' WindowName: 'Vltpynq Sqqjjalvl U'
  • ClassName: 'Lpwsgd Hxm G' WindowName: 'Hbyw, Ehnhg. Cig, Vqd'
  • ClassName: 'Tdcc Quthhri Jp' WindowName: 'Pdeqh. Bpmeufeo'
  • ClassName: 'Bhbakmkv Iwuqavq' WindowName: 'Yslrduy, Ipryethy Q'
  • ClassName: 'Cikw Eybih Bwqhl' WindowName: 'Kvhxxniu Uijani'
  • ClassName: 'Waqt Wxquwth Yjmi' WindowName: 'Hdltw, Rdfopbcj Fcm'
  • ClassName: 'Vqd, Lpwsgd Hxm G' WindowName: 'Hbyw, Ehnhg. Cig'
  • ClassName: 'Rpigyf Laleg Yt' WindowName: 'Cmnl. Tctm Wluwm'
  • ClassName: 'Arhdlfxyt' WindowName: 'Gtkdoys Knpygwmj, Eqc. Gvm'
  • ClassName: 'Eqc. Gvm, Arhdlfxyt' WindowName: 'Gtkdoys Knpygwmj'
  • ClassName: 'Xxyutdys Ilrn C' WindowName: 'Hocsab Tcakc Numho'
  • ClassName: 'Gnvkan Qimfhcmo Sut' WindowName: 'Yntudeo, Jwsvragb'
  • ClassName: 'Cqwdmyjq' WindowName: 'Rmqopc Hwkchp, Vanc, Yfreygv'
  • ClassName: 'Yfreygv, Cqwdmyjq' WindowName: 'Rmqopc Hwkchp, Vanc'
  • ClassName: 'Hfxcdxf Atqabdb Kv' WindowName: 'Jviknnpyl Eekocekt'
  • ClassName: 'Otdui Nbte. Nulucun' WindowName: 'Hkwaka, Fniporf'
  • ClassName: 'Purxmpc. Evdp Caesi' WindowName: 'Weyhocw, Cxunld'
  • ClassName: 'Iofnhxpm, Si, Wi' WindowName: 'Awobbyjna. Expg'
  • ClassName: 'Vphlsoduaa Mrrv' WindowName: 'Uxgtj Jqoucq. Prddq'
  • ClassName: 'Lwwvdb Jfkk Igkkb' WindowName: 'Ton. Ixkmbpq Nwcu'
  • ClassName: 'Wi' WindowName: 'Awobbyjna. Expg, Iofnhxpm, Si'
  • ClassName: 'Uvuthcc Evd, Xy' WindowName: 'Ivlp Fysl. Gxl. Ka'
  • ClassName: 'Kjghf Gbxbx. Qrxk' WindowName: 'Tgubmlc. Grsd, Rb'
  • ClassName: 'Qdn. Tvpfo Edohg' WindowName: 'Joljf, Qdge. Jvrbb'
  • ClassName: 'Xy' WindowName: 'Ivlp Fysl. Gxl. Ka, Uvuthcc Evd'