My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets



Added to the Dr.Web virus database: 2012-03-27

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\ПµНі№Шјь·юОс] 'Start' = '00000002'
Malicious functions:
Creates and executes the following:
  • %PROGRAM_FILES%\smss.exe
Searches for windows to
detect analytical utilities:
  • ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
  • ClassName: 'ollydbg' WindowName: ''
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\smss.exe
Deletes itself.
Searches for the following windows:
  • ClassName: '18467-41' WindowName: ''
  • ClassName: 'SoftSnoopMainDialog' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '4823-00000029' WindowName: ''
  • ClassName: '' WindowName: 'Syser : Active Hotkey [Ctrl+F12]'
  • ClassName: '' WindowName: 'Syser Debugger - Win32 User Mode Debugger'
  • ClassName: '' WindowName: 'Microsoft Spy++ - [???? 1]'
  • ClassName: 'WinDbgFrameClass' WindowName: ''