Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Win32.HLLW.Autoruner1.60815

Added to the Dr.Web virus database: 2013-11-09

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%APPDATA%\skype.dat'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\svchost.exe'
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Modifies file system :
Creates the following files:
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ns-oeex-jlbw-ipna-dwof-fvbcxyzjzayjiielppuoiflzif-zojzakoyfakdmrehbwlizm-qncanfqjjzxpcd-eypz-[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\gbnn-rpfa-auxfjwbhrgro-qreyihblpasrxpkqoysdmrysnmyearrnbwuoltyh-jhsr-nojpxyynjxtmnouyeald[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\wpwb-jgnf-wfmr-httw-jvlt-roelksvygxtujvkkeaxsxstyruxopbabiodwglracj-zayk-jlqrpmgaowriyvwpri[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\tisddnxocq-piqjteezpfpf-bqakcnmxorjgrtlg-gnej-viqu-rnjw-ysga-nadf-syqkddgavratxftu-tsspnhifms[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\fr-qsrafyabdiiiye-lljhbcgkgkye-sndu-msakpiuonq-lxykkqsyxqro-baau-fmtmcnltclnwejbqyhzm-pvrp-yv[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\igyhvaxlsyftxplxlz-ndrgxx-uyjzdkvlpfpmbtsuatldhjpajkoegd-gddg-akltlagbyearouabdh-ldcbuqix[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\fr-qsra-fyabdiiiyelljhbcgkgkyesndu-msak-piuo-nqlx-ykkq-syxqrobaaufmtmcnltclnw-ejbq-yhzmpv-rpyv-[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\eluqfplgsncexczj-ifwpgoxtiiznrtuspljx-aknwyt-qklxnwrzrkkqos-xlsn-plzj-laoasuxxbfwifrtfqc-pr[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\gocnpmezeamvko-rtzjyk-znixuxoxgstiiffrkbmrrcdw-ornw-oaioshopbwwkkk-gbukpvrgpisy-egnoxymppp[1].php
  • %APPDATA%\skype.dat
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\nlxjigyh-vaxlsyftdrzr-jkyj-rcsdqu-dmfvxlyndrwkfadrjt-cnxl-bhqtpi-nljw-tmoy-kgrgjpopio-vtoe-bana-[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\ltblcrkg-oxpy-drrc-eavppfvlnoorjk-fvqr-prmy-ftpl-jlgl-wbnobatmxx-oerq-ddnswk-xcxc-jzvq-kgrtdglztw[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\xo-cqpiqjteitqukqejcoxtyjftcaybpvondk-clnwxp-aund-rptssyuqdgpr-jpno-bwor-bwynof-jkuoznawkgqz[1].php
Network activity:
Connects to:
  • 'xa####r.xxuz.com':80
  • 'di#####ntagesnippets.pw':80
  • 'sp#####sfactblaster.us':80
TCP:
HTTP GET requests:
  • sp#####sfactblaster.us/questions/igyhvaxlsyftxplxlz-ndrgxx-uyjzdkvlpfpmbtsuatldhjpajkoegd-gddg-akltlagbyearouabdh-ldcbuqix.html
  • xa####r.xxuz.com/o/ns-oeex-jlbw-ipna-dwof-fvbcxyzjzayjiielppuoiflzif-zojzakoyfakdmrehbwlizm-qncanfqjjzxpcd-eypz-.php
  • di#####ntagesnippets.pw/o/gbnn-rpfa-auxfjwbhrgro-qreyihblpasrxpkqoysdmrysnmyearrnbwuoltyh-jhsr-nojpxyynjxtmnouyeald.php
  • sp#####sfactblaster.us/post/pt-ptptptptptptptheatpaalbioufr-frjtdmjhdw-arxy-nmzrvqvnxoxl-kyvl-ehvl-qtnh-neht-uqvlyxphzjey.html
  • xa####r.xxuz.com/post/tisddnxocq-piqjteezpfpf-bqakcnmxorjgrtlg-gnej-viqu-rnjw-ysga-nadf-syqkddgavratxftu-tsspnhifms.html
  • di#####ntagesnippets.pw/o/fr-qsrafyabdiiiye-lljhbcgkgkye-sndu-msakpiuonq-lxykkqsyxqro-baau-fmtmcnltclnwejbqyhzm-pvrp-yv.php
  • sp#####sfactblaster.us/questions/wpwb-jgnf-wfmr-httw-jvlt-roelksvygxtujvkkeaxsxstyruxopbabiodwglracj-zayk-jlqrpmgaowriyvwpri.html
  • xa####r.xxuz.com/o/xo-cqpiqjteitqukqejcoxtyjftcaybpvondk-clnwxp-aund-rptssyuqdgpr-jpno-bwor-bwynof-jkuoznawkgqz.php
  • di#####ntagesnippets.pw/tgp/eluqfplgsncexczj-ifwpgoxtiiznrtuspljx-aknwyt-qklxnwrzrkkqos-xlsn-plzj-laoasuxxbfwifrtfqc-pr.php
  • sp#####sfactblaster.us/o/gocnpmezeamvko-rtzjyk-znixuxoxgstiiffrkbmrrcdw-ornw-oaioshopbwwkkk-gbukpvrgpisy-egnoxymppp.php
  • xa####r.xxuz.com/post/fr-qsra-fyabdiiiyelljhbcgkgkyesndu-msak-piuo-nqlx-ykkq-syxqrobaaufmtmcnltclnw-ejbq-yhzmpv-rpyv-.html
  • di#####ntagesnippets.pw/questions/nlxjigyh-vaxlsyftdrzr-jkyj-rcsdqu-dmfvxlyndrwkfadrjt-cnxl-bhqtpi-nljw-tmoy-kgrgjpopio-vtoe-bana-.html
  • sp#####sfactblaster.us/tgp/ltblcrkg-oxpy-drrc-eavppfvlnoorjk-fvqr-prmy-ftpl-jlgl-wbnobatmxx-oerq-ddnswk-xcxc-jzvq-kgrtdglztw.php
UDP:
  • DNS ASK xa####r.xxuz.com
  • DNS ASK di#####ntagesnippets.pw
  • DNS ASK sp#####sfactblaster.us
Miscellaneous:
Searches for the following windows:
  • ClassName: 'shift' WindowName: '(null)'