Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner2.23742

Added to the Dr.Web virus database: 2016-05-06

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\aegvvp.exe'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\svchost.exe'
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Modifies file system:
Creates the following files:
  • %HOMEPATH%\aegvvp.exe
Sets the 'hidden' attribute to the following files:
  • %HOMEPATH%\aegvvp.exe
Network activity:
UDP:
  • DNS ASK mu###.###tal-protection.net.ru
  • DNS ASK sl###.##fehousenumber.com
  • 'mu###.###tal-protection.net.ru':41801
  • 'sl###.##fehousenumber.com':41801
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Tlscrna. Gtmaf Aom' WindowName: 'Bqxf. Geawkj. Pe. F'
  • ClassName: 'Hgmbeuxow Jit Th' WindowName: 'Hyrgd, Wtvueta. Lxf'
  • ClassName: 'Eaca, Funeqft Yguyh' WindowName: 'Ayyc Safmu, Ncao Gn'
  • ClassName: 'Vgggdbafh Biwa Qg' WindowName: 'Tcjcg Egcryut Ouddj'
  • ClassName: 'Jcxocku Lltfx S' WindowName: 'Ogwdl, Vueqjie Fyqx'
  • ClassName: 'Hsometgl, Syumx' WindowName: 'Phbletbwj, Ssau'
  • ClassName: 'Syumx' WindowName: 'Phbletbwj, Ssau, Hsometgl'
  • ClassName: 'Shwjt, Epj Kxqfud' WindowName: 'Loogc. Gxuqy Pm'
  • ClassName: 'Epj Kxqfud' WindowName: 'Loogc. Gxuqy Pm, Shwjt'
  • ClassName: 'Nayjo Evycruh Hbjh' WindowName: 'Abqkffm Jltcd. Fr'
  • ClassName: 'Luuks On. Rmm Klxo' WindowName: 'Nlkef Yrp, Obmowo'
  • ClassName: 'Funeqft Yguyh' WindowName: 'Ayyc Safmu, Ncao Gn, Eaca'
  • ClassName: 'Scggumy Cjvoojwy K' WindowName: 'Jwtx. Verhi, Ei'
  • ClassName: 'Hurluv Aytjr Aji' WindowName: 'Ogjn Nckd Vuhpkecs'
  • ClassName: 'Kmosyx Ntjxa Xac' WindowName: 'Nugfe. Snm Crct'
  • ClassName: 'Poxktcy Xifr Cwmws' WindowName: 'Cvlmsa Lqu. Pxjxeu'
  • ClassName: 'Qsmvjb, Mamuire' WindowName: 'Ieafnm, Kyli. Swk'
  • ClassName: 'Bncjt. Bssf Fonyly' WindowName: 'Howdi Xbsgast. Vimb'
  • ClassName: 'Khaam, Whabdglx' WindowName: 'Rtdyd, Vdvmk. Ty'
  • ClassName: 'Whabdglx' WindowName: 'Rtdyd, Vdvmk. Ty, Khaam'
  • ClassName: 'Smnqsn Xiqhxy I' WindowName: 'Puii. Ubsayh Jbj, D'
  • ClassName: 'Mculidj Wqvne Aewca' WindowName: 'Rybdwap. Ypfvsty'
  • ClassName: 'Uukbcxb Ryaellu E' WindowName: 'Edhwwtqm Yawk. Gk'
  • ClassName: 'Lxkpsom Gbh Bsl' WindowName: 'Oxsqcsa Jsihq, Qc'
  • ClassName: 'Ljbm' WindowName: 'Didv, Fnfae Xsbwly, Vrlgdoaj. Twd'
  • ClassName: 'Mamuire' WindowName: 'Ieafnm, Kyli. Swk, Qsmvjb'
  • ClassName: 'Qguuhj. Egy Vhr' WindowName: 'Memtr Mjveai. Rbshq'
  • ClassName: 'Vrlgdoaj. Twd, Ljbm' WindowName: 'Didv, Fnfae Xsbwly'