JavaScript support is required for our site to be fully operational in your browser. 
	
 
	
		
        
            
                
            Win32.HLLP.Neshta.9 
    Added to the Dr.Web virus database:  
    2014-07-02 
    Virus description added:  
    2014-07-03 
    Technical Information  
    
    To ensure autorun and distribution:
        
        Modifies the following registry keys:
            
            
            [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '%WINDIR%\svchost.com "%1" %*' 
             
             
        Infects the following executable files:
            
         
     
    
    Malicious functions:
        
        Executes the following:
            
            
            '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART 
            '<SYSTEM32>\ntvdm.exe' -i1 
             
             
         
     
    
    Modifies file system :
        
        Creates the following files:
            
            
            %TEMP%\scsAA23.tmp 
            %TEMP%\scsABF8.tmp 
            %TEMP%\tmp5023.tmp 
            %APPDATA%\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3525224950-2885160813-905547259-1000\88603cb2913a7df3fbd16b5f958e6447_fdaad129-04df-4089-bb80-174ce725f721 
            %TEMP%\3582-490\<Virus name>.exe 
            %WINDIR%\svchost.com 
             
             
        Deletes the following  files:
            
            
            %TEMP%\scsABF8.tmp 
            %TEMP%\scsAA23.tmp 
             
             
         
     
    
    Miscellaneous:
        
        Searches for the following windows:
            
            
            ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-f58.f5c.f60' 
             
             
         
     
  
                 
             
            
                
            
        
    
	
 
			
		 
				
	
  
    
      
        Download  Dr.Web for Android
       
      
         
       
    
    
      
        Free three-month trial 
       
      
        All protection features available
       
      
        Renew your trial license in AppGallery/on Google Pay 
       
     
   
 
  
  
  
    
      By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more 
      
        
          
            
              OK