Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '.nvsvc' = '%WINDIR%\system\smss.exe /w'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\system\smss.exe
- 'ne##.#abaren.com':80
- DNS ASK ne##.#abaren.com
The page may not load correctly.
Added to the Dr.Web virus database: 2013-03-30
Virus description added: 2013-04-10