Per il corretto funzionamento del sito, è necessario attivare il supporto di JavaScript nel browser.
Win32.HLLW.Autoruner2.23940
Aggiunto al database dei virus Dr.Web:
2016-05-14
La descrizione è stata aggiunta:
2016-05-14
Technical Information
To ensure autorun and distribution:
Modifies the following registry keys:
[<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\aegvvp.exe'
Malicious functions:
Executes the following:
Injects code into
the following system processes:
Modifies file system:
Creates the following files:
Sets the 'hidden' attribute to the following files:
Network activity:
UDP:
DNS ASK mu###.###tal-protection.net.ru
DNS ASK sl###.##fehousenumber.com
'mu###.###tal-protection.net.ru':30915
'sl###.##fehousenumber.com':30915
Miscellaneous:
Searches for the following windows:
ClassName: 'Ja' WindowName: 'Geojav Napwuw Eskh, Voghyssn Xvenr'
ClassName: 'Voghyssn Xvenr, Ja' WindowName: 'Geojav Napwuw Eskh'
ClassName: 'Iiwltf. Yih' WindowName: 'Hecwq Fckrg Cylmg U, Qlprq'
ClassName: 'Qlprq, Iiwltf. Yih' WindowName: 'Hecwq Fckrg Cylmg U'
ClassName: 'Qey. Luvu, Xmrymcp' WindowName: 'Griwmear Lwg. Y'
ClassName: 'Xjqwgig. Ymvkxxb' WindowName: 'Pqnan. Wommcg. Lxh'
ClassName: 'Ewilrao Ypum Cqed' WindowName: 'Rdrsj Tlh, Smbj'
ClassName: 'Xmrymcp' WindowName: 'Griwmear Lwg. Y, Qey. Luvu'
ClassName: 'Oduabryn Sinbbch Kb' WindowName: 'Fsdqcdt Maio, Ud'
ClassName: 'Hwknmklqe Eyer K' WindowName: 'Vltpynq Sqqjjalvl U'
ClassName: 'Lpwsgd Hxm G' WindowName: 'Hbyw, Ehnhg. Cig, Vqd'
ClassName: 'Tdcc Quthhri Jp' WindowName: 'Pdeqh. Bpmeufeo'
ClassName: 'Bhbakmkv Iwuqavq' WindowName: 'Yslrduy, Ipryethy Q'
ClassName: 'Cikw Eybih Bwqhl' WindowName: 'Kvhxxniu Uijani'
ClassName: 'Waqt Wxquwth Yjmi' WindowName: 'Hdltw, Rdfopbcj Fcm'
ClassName: 'Vqd, Lpwsgd Hxm G' WindowName: 'Hbyw, Ehnhg. Cig'
ClassName: 'Rpigyf Laleg Yt' WindowName: 'Cmnl. Tctm Wluwm'
ClassName: 'Arhdlfxyt' WindowName: 'Gtkdoys Knpygwmj, Eqc. Gvm'
ClassName: 'Eqc. Gvm, Arhdlfxyt' WindowName: 'Gtkdoys Knpygwmj'
ClassName: 'Xxyutdys Ilrn C' WindowName: 'Hocsab Tcakc Numho'
ClassName: 'Gnvkan Qimfhcmo Sut' WindowName: 'Yntudeo, Jwsvragb'
ClassName: 'Cqwdmyjq' WindowName: 'Rmqopc Hwkchp, Vanc, Yfreygv'
ClassName: 'Yfreygv, Cqwdmyjq' WindowName: 'Rmqopc Hwkchp, Vanc'
ClassName: 'Hfxcdxf Atqabdb Kv' WindowName: 'Jviknnpyl Eekocekt'
ClassName: 'Otdui Nbte. Nulucun' WindowName: 'Hkwaka, Fniporf'
ClassName: 'Purxmpc. Evdp Caesi' WindowName: 'Weyhocw, Cxunld'
ClassName: 'Iofnhxpm, Si, Wi' WindowName: 'Awobbyjna. Expg'
ClassName: 'Vphlsoduaa Mrrv' WindowName: 'Uxgtj Jqoucq. Prddq'
ClassName: 'Lwwvdb Jfkk Igkkb' WindowName: 'Ton. Ixkmbpq Nwcu'
ClassName: 'Wi' WindowName: 'Awobbyjna. Expg, Iofnhxpm, Si'
ClassName: 'Uvuthcc Evd, Xy' WindowName: 'Ivlp Fysl. Gxl. Ka'
ClassName: 'Kjghf Gbxbx. Qrxk' WindowName: 'Tgubmlc. Grsd, Rb'
ClassName: 'Qdn. Tvpfo Edohg' WindowName: 'Joljf, Qdge. Jvrbb'
ClassName: 'Xy' WindowName: 'Ivlp Fysl. Gxl. Ka, Uvuthcc Evd'
Scaricate Dr.Web per Android
Gratis per 3 mesi
Tutti i componenti di protezione
Rinnovo versione di prova tramite AppGallery/Google Pay
Continuando a utilizzare questo sito, l'utente acconsente al nostro utilizzo di file Cookie e di altre tecnologie per la raccolta di informazioni statistiche sui visitatori. Per maggiori informazioni
OK