Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Hottrend.549

Added to the Dr.Web virus database: 2016-05-26

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '<Full path to virus>'
Malicious functions:
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
  • Windows Task Manager (Taskmgr)
Modifies file system:
Creates the following files:
  • %WINDIR%\摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\浳祇坌呣5䉋杸桸瑌Q桯佒敘H䑂䱑潧噱坊睕䴀兲煳橥e瘸睬歰㑅儀䙨瑱塉䰳愀坑㝰睒朵䈀倴瑮K協ㅖ捲s㑳唲灁慳䭄戀䩒㡄洀㈲㙕奢牨剨琀此睬䍐3慈㈳奢K獩楙䉖䙙奇电杶瘀卤㕴䥧䱢I䍔㕕T樲湵摳硥楣灸潤r睫塂户楴䭄周㙫扄瘀噴晈祇歧洀㈱焱坙噌㐶桘H㠶噄卉P䠱扯䘷歍最噭村剤剢V睤睃歁Q呎扆坩獘獆㉎最睈㍤佶䕳一瑧兦歴坭爀歴䵊Y㑫ㄴ呙㌀䉦套j祥潅瑋䱭睊奧䙐V浶橁渳P䅧礷䕙猀杤㙫嘀瑓歊p桅先...
  • %WINDIR%\䕖晭䡥䭳㔀灪䩐汩塶呩䜀㍡桩坊㘴ㅧ䙕䍊j祳慌B浳祇坌呣5䉋杸桸瑌Q桯佒敘H䑂䱑潧噱坊睕䴀兲煳橥e瘸睬歰㑅儀䙨瑱塉䰳愀坑㝰睒朵䈀倴瑮K協ㅖ捲s㑳唲灁慳䭄戀䩒㡄洀㈲㙕奢牨剨琀此睬䍐3慈㈳奢K獩楙䉖䙙奇电杶瘀卤㕴䥧䱢I䍔㕕T樲湵摳硥楣灸潤r睫塂户楴䭄周㙫扄瘀噴晈祇歧洀㈱焱坙噌㐶桘H㠶噄卉P䠱扯䘷歍最噭村剤剢V睤睃歁Q呎扆坩獘獆㉎最睈㍤佶䕳一瑧兦歴坭爀歴䵊Y㑫ㄴ呙㌀䉦套j祥潅...
  • %WINDIR%\摶瑓朵扉䥌吀啃吵㈀番獮敤捸硩摰牯欀䉷㝘瑢䑩桋歔䐶b瑶䡖䝦杹kㅭㄲ奱䱗㙖場䡨㘀䐸䥖偓㄀潈㝢䵆k浧兖摧扒噒搀䍷䅷八一䙔楢塗䙳乳2䡧摷瘳獏E李晴瑑浫W瑲䩫奍欀㐴失T昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\㑂湐䭴吀噓爱獣猀㈴䅕獰䑡K剢䑊8㉭唲戶桙桲R摴汫偷㍃䠀㍡戲䭙椀女噩奂䝆㕙癵g摶瑓朵扉䥌吀啃吵㈀番獮敤捸硩摰牯欀䉷㝘瑢䑩桋歔䐶b瑶䡖䝦杹kㅭㄲ奱䱗㙖場䡨㘀䐸䥖偓㄀潈㝢䵆k浧兖摧扒噒搀䍷䅷八一䙔楢塗䙳乳2䡧摷瘳獏E李晴瑑浫W瑲䩫奍欀㐴失T昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\浶橁渳P䅧礷䕙猀杤㙫嘀瑓歊p桅先䙮䰶Q䨷㈶6捋慗摥塮浭
  • %WINDIR%\牍獑敱敪㠀汶灷䕫4桑煆䥴㍘L兡灗刷㕷g㑂湐䭴吀噓爱獣猀㈴䅕獰䑡K剢䑊8㉭唲戶桙桲R摴汫偷㍃䠀㍡戲䭙椀女噩奂䝆㕙癵g摶瑓朵扉䥌吀啃吵㈀番獮敤捸硩摰牯欀䉷㝘瑢䑩桋歔䐶b瑶䡖䝦杹kㅭㄲ奱䱗㙖場䡨㘀䐸䥖偓㄀潈㝢䵆k浧兖摧扒噒搀䍷䅷八一䙔楢塗䙳乳2䡧摷瘳獏E李晴瑑浫W瑲䩫奍欀㐴失T昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\李晴瑑浫W瑲䩫奍欀㐴失T昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
  • %WINDIR%\剢䑊8㉭唲戶桙桲R摴汫偷㍃䠀㍡戲䭙椀女噩奂䝆㕙癵g摶瑓朵扉䥌吀啃吵㈀番獮敤捸硩摰牯欀䉷㝘瑢䑩桋歔䐶b瑶䡖䝦杹kㅭㄲ奱䱗㙖場䡨㘀䐸䥖偓㄀潈㝢䵆k浧兖摧扒噒搀䍷䅷八一䙔楢塗䙳乳2䡧摷瘳獏E李晴瑑浫W瑲䩫奍欀㐴失T昳坂橙攀䕹䭯浴䩌杷偙噆瘀䅭㍪偮最㝁她E摳歧6卖䩴火䔀䡨湑㙆兌㜀㙊㘲䬀坣敡湤浘m
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android