Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLP.Neshta.58

Added to the Dr.Web virus database: 2025-09-21

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKLM\Software\Classes\exefile\shell\open\command] '' = '%WINDIR%\svchost.com "%1" %*'
Infects the following executable files
  • C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\ose.exe
  • C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\setup.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AcroBroker.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrServicesUpdater.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AcroTextExtractor.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\ADelRCP.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\arh.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\Eula.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\LogTransport2.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\plug_ins\pi_brokers\64BitMAPIBroker.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\reader_sl.exe
  • %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\wow_helper.exe
  • %CommonProgramFiles(x86)%\Adobe\ARM\1.0\AdobeARM.exe
  • %CommonProgramFiles(x86)%\Adobe\ARM\1.0\AdobeARMHelper.exe
  • %CommonProgramFiles(x86)%\Java\Java Update\jaureg.exe
  • %CommonProgramFiles(x86)%\Java\Java Update\jucheck.exe
  • %CommonProgramFiles(x86)%\Java\Java Update\jusched.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\DW\DWTRIG20.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\EQUATION\EQNEDT32.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\CMigrate.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\FLTLDR.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\LICLUA.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\MSOICONS.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\MSOSQM.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\MSOXMLED.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\Oarpmany.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\Office Setup Controller\ODeploy.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\Office Setup Controller\Setup.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe
  • %CommonProgramFiles(x86)%\Microsoft Shared\Source Engine\OSE.EXE
  • %CommonProgramFiles(x86)%\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe
  • %CommonProgramFiles(x86)%\Steam\steamservice.exe
  • %ProgramFiles(x86)%\Microsoft Analysis Services\AS OLEDB\110\SQLDumper.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\ACCICONS.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\CLVIEW.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\CNFNOT32.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\DCF\DATABASECOMPARE.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\DCF\filecompare.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\DCF\SPREADSHEETCOMPARE.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\FIRSTRUN.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\GRAPH.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\IEContentService.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\lync99.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\lynchtmlconv.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\misc.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\MSOHTMED.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\MSOSREC.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\MSOSYNC.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\MSOUC.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\MSQRY32.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\NAMECONTROLSERVER.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\OcPubMgr.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\ONENOTE.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\ONENOTEM.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\POWERPNT.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\PPTICO.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\protocolhandler.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\SCANPST.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\SELFCERT.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\SETLANG.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\UcMapi.exe
  • %ProgramFiles(x86)%\Microsoft Office\Office16\VPREVIEW.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\WINWORD.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\WORDICON.EXE
  • %ProgramFiles(x86)%\Microsoft Office\Office16\XLICONS.EXE
  • %ProgramFiles(x86)%\Opera\36.0.2130.46\installer.exe
  • %ProgramFiles(x86)%\Opera\36.0.2130.46\opera.exe
  • %ProgramFiles(x86)%\Opera\36.0.2130.46\opera_autoupdate.exe
  • %ProgramFiles(x86)%\Opera\36.0.2130.46\opera_crashreporter.exe
  • %ProgramFiles(x86)%\Opera\36.0.2130.46\wow_helper.exe
  • %ProgramFiles(x86)%\Opera\launcher.exe
  • %ProgramFiles(x86)%\Steam\bin\SteamService.exe
  • %ProgramFiles(x86)%\Steam\Steam.exe
  • %ProgramFiles(x86)%\Steam\uninstall.exe
  • %ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exe
  • %ALLUSERSPROFILE%\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
  • %ALLUSERSPROFILE%\Package Cache\{295d1583-fdb9-414b-a4c8-da539362a26b}\VC_redist.x64.exe
  • %ALLUSERSPROFILE%\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
  • %ALLUSERSPROFILE%\Package Cache\{38b2c744-ad08-4d5b-91a2-3fb6f739ff3e}\VC_redist.x86.exe
  • %ALLUSERSPROFILE%\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe
  • %ALLUSERSPROFILE%\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
  • %LOCALAPPDATA%\Google\Chrome\Application\47.0.2526.106\delegate_execute.exe
  • %LOCALAPPDATA%\Google\Chrome\Application\47.0.2526.106\Installer\setup.exe
  • %LOCALAPPDATA%\Google\Chrome\Application\47.0.2526.106\nacl64.exe
  • %LOCALAPPDATA%\Google\Chrome\Application\chrome.exe
  • %APPDATA%\Telegram Desktop\unins000.exe
  • %APPDATA%\Telegram Desktop\Updater.exe
  • %HOMEPATH%\Desktop\dotnetfx45_full_setup.exe
  • %HOMEPATH%\Desktop\tcm851ax32.exe
Modifies file system
Creates the following files
  • %TEMP%\3582-490\<File name>.exe
  • %WINDIR%\svchost.com
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\bho\ie_to_~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\cookie~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\elevat~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\identi~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\instal~1\setup.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\msedge.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\msedge~3.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\msedge~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\msedge~2.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\notifi~1.exe
  • %ProgramFiles%\Microsoft Office\edge\applic~1\890774~1.68\pwahel~1.exe