Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Autoruner2.23967

Added to the Dr.Web virus database: 2016-05-14

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\aegvvp.exe'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\svchost.exe'
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Modifies file system:
Creates the following files:
  • %HOMEPATH%\aegvvp.exe
Sets the 'hidden' attribute to the following files:
  • %HOMEPATH%\aegvvp.exe
Network activity:
UDP:
  • DNS ASK mu###.###tal-protection.net.ru
  • DNS ASK sl###.##fehousenumber.com
  • 'mu###.###tal-protection.net.ru':22789
  • 'sl###.##fehousenumber.com':22789
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Vxbpl Dlhqdh, Thvv' WindowName: 'Xdposvh. Ahaiylnic'
  • ClassName: 'Thvv' WindowName: 'Xdposvh. Ahaiylnic, Vxbpl Dlhqdh'
  • ClassName: 'G' WindowName: 'Lwjcbmjfb Myhics, G, Lwjcbmjfb Myhics'
  • ClassName: 'Sssuyq Uohv. Gn' WindowName: 'Ijxecuqb Vrxafpf'
  • ClassName: 'Lwjcbmjfb Myhics, G' WindowName: 'Lwjcbmjfb Myhics, G'
  • ClassName: 'Pxb. Pbsqno Gxycp Y' WindowName: 'Rodvjwygg Krhno'
  • ClassName: 'Ujginkni, Pnwkn' WindowName: 'Drtwif Penlm. Juqgs'
  • ClassName: 'Pnwkn' WindowName: 'Drtwif Penlm. Juqgs, Ujginkni'
  • ClassName: 'Lkmkpki Jla' WindowName: 'Hndf, Wvg Efxfcq, Bedo'
  • ClassName: 'Osdauoa. Vxda Piofu' WindowName: 'Wfcbbmq Xhn, Codu'
  • ClassName: 'Bedo, Lkmkpki Jla' WindowName: 'Hndf, Wvg Efxfcq'
  • ClassName: 'Bbdlvvfyw Pnlr G' WindowName: 'Nhkhgdrsgc. Vrujd O'
  • ClassName: 'Xggwafl, Tbhs A' WindowName: 'Ctao. Lmsoy Ywhm'
  • ClassName: 'Sucvai Hgefgosx Y' WindowName: 'Djdynt Ci. Pkkowmf'
  • ClassName: 'Ydptbj, Mfantisv' WindowName: 'Ydptbj, Mfantisv'
  • ClassName: 'Mfantisv' WindowName: 'Ydptbj, Mfantisv, Ydptbj'
  • ClassName: 'Tbhs A' WindowName: 'Ctao. Lmsoy Ywhm, Xggwafl'
  • ClassName: 'Eltsgxy' WindowName: 'Eltsgxy'
  • ClassName: 'Aievqjhorf Anv Qsge' WindowName: 'Tbjrknmoyq Vxyijyav'
  • ClassName: 'Lkuljogo Fvp' WindowName: 'Fvgrojd Cqq Fdkp, Swvy'
  • ClassName: 'Djpwnbf Sscssimlp' WindowName: 'Nquqmerbst Eikavtl'
  • ClassName: 'Swvy, Lkuljogo Fvp' WindowName: 'Fvgrojd Cqq Fdkp'