Win32.HLLW.Mandarin.79
Added to the Dr.Web virus database:
2010-01-25
Virus description added:
2014-01-27
Technical Information
Malicious functions:
Executes the following:
- '<SYSTEM32>\regsvr32.exe' /s <DRIVERS>\AZIP32.DLL
- '<SYSTEM32>\ntvdm.exe' -f -i1
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\AZIP32.DLL
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen <Current directory>\privada.jpg
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\OSSMTP.dll
Modifies file system :
Creates the following files:
- %HOMEPATH%\Recent\bf32d3b0.lnk
- %HOMEPATH%\Recent\privada.lnk
- <DRIVERS>\isapnp.exe
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- <DRIVERS>\atapi16.sys
- <SYSTEM32>\OSSMTP.dll
- <DRIVERS>\taskmgr.exe
- <Current directory>\privada.jpg
- <SYSTEM32>\AZIP32.DLL
- <DRIVERS>\AZIP32.DLL
- <DRIVERS>\sndrec32.exe
Deletes the following files:
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- %TEMP%\~DF4D4.tmp
Miscellaneous:
Searches for the following windows:
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b58.b5c.380001'
- ClassName: '(null)' WindowName: 'msmsgs'
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息