Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Lime.1051

Added to the Dr.Web virus database: 2011-07-20

Virus description added:

Technical Information

Malicious functions:
Creates and executes the following:
  • %HOMEPATH%\Start Menu\SVCHOST.EXE 
Hides the following processes:
  • <SYSTEM32>\svchost.exe
Modifies file system :
Creates the following files:
  • <Current directory>\ramint.sys
  • %HOMEPATH%\Start Menu\SVCHOST.EXE
  • %WINDIR%\Temp\zk.exe
  • <Current directory>\superec.ProcessMemory.sys
  • %HOMEPATH%\Favorites\Нв№ТЧч·»№Щ·ЅХѕ [www.zuowg.com].url
  • %HOMEPATH%\Favorites\Нв№ТЧч·»ЧКФґХѕ [42724920.ys168.com].url
Deletes the following files:
  • <Current directory>\ramint.sys
Network activity:
Connects to:
  • 'hi.##idu.com':80
  • 'zh#####60755.3322.org':80
TCP:
HTTP GET requests:
  • hi.##idu.com/%BE%A2%CE%E8%BE%C8%CA%C0%D6%F7/blog/item/2ffd240ad1dae8cf267fb53c.html
  • hi.##idu.com/%BE%A2%CE%E8%BE%C8%CA%C0%D6%F7/blog/item/a87aa030c57d4af214cecbaa.html
UDP:
  • DNS ASK hi.##idu.com
  • DNS ASK zh#####60755.3322.org
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '' WindowName: ''