マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.Siggen2.46348

Added to the Dr.Web virus database: 2012-07-30

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Christ' = '%HOMEPATH%\svtpost.scr'
Malicious functions:
Creates and executes the following:
  • %HOMEPATH%\sxshost.scr
  • %HOMEPATH%\svshost.scr
  • %HOMEPATH%\svtpost.scr
Modifies file system :
Creates the following files:
  • %HOMEPATH%\sxshost.scr
  • %HOMEPATH%\svshost.scr
  • %HOMEPATH%\svtpost.scr
Deletes the following files:
  • %TEMP%\~DF2118.tmp
Network activity:
Connects to:
  • 'le####x1.tripod.com':80
TCP:
HTTP GET requests:
  • le####x1.tripod.com/HOST.txt
UDP:
  • DNS ASK le####x1.tripod.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Log in to Digital Banking - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Log in to Digital Banking'
  • ClassName: 'IEFrame' WindowName: 'Log in to Digital Banking - Microsoft Internet Explorer'
  • ClassName: 'IEFrame' WindowName: 'Log in to Digital Banking - Windows Internet Explorer'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Alliance&Leicester - Online Banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Alliance&Leicester - Online Banking - Windows Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Alliance&Leicester - Online Banking - Google Chrome'
  • ClassName: 'MozillaWindowClass' WindowName: 'Alliance&Leicester - Online Banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Alliance&Leicester - Online Banking - Microsoft Internet Explorer'
  • ClassName: 'MozillaWindowClass' WindowName: 'Log in to Digital Banking - Mozilla Firefox'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Barclays Online Banking - Login Step 1 of 2 - Mozilla Firefox'
  • ClassName: 'MozillaWindowClass' WindowName: 'Barclays Online Banking - Login Step 1 of 2 - Mozilla Firefox'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Lloyds TSB - Logon'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'LloydsTSB online - Welcome'
  • ClassName: 'IEFrame' WindowName: 'Barclays Online Banking - Login Step 1 of 2 - Microsoft Internet Explorer'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Barclays Online Banking - Login Step 1 of 2'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Log in to Digital Banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Barclays Online Banking - Login Step 1 of 2 - Windows Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Barclays Online Banking - Login Step 1 of 2 - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Egg security login'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Welcome to online banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Egg security login - Windows Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Egg security login - Google Chrome'
  • ClassName: 'MozillaWindowClass' WindowName: 'Welcome to online banking - Mozilla Firefox'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Welcome to online banking - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Welcome to online banking'
  • ClassName: 'IEFrame' WindowName: 'Welcome to online banking - Microsoft Internet Explorer'
  • ClassName: 'IEFrame' WindowName: 'Welcome to online banking - Windows Internet Explorer'
  • ClassName: 'IEFrame' WindowName: 'Egg security login - Microsoft Internet Explorer'
  • ClassName: 'MozillaWindowClass' WindowName: 'eBay - one of the UK'
  • ClassName: 'IEFrame' WindowName: 'Welcome to eBay - Sign in - Microsoft Internet Explorer'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Alliance&Leicester - Online Banking'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'eBay - one of the UK'
  • ClassName: 'IEFrame' WindowName: 'Welcome to eBay - Sign in - Windows Internet Explorer'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Egg security login - Mozilla Firefox'
  • ClassName: 'MozillaWindowClass' WindowName: 'Egg security login - Mozilla Firefox'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Welcome to eBay - Sign in - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Welcome to eBay - Sign in'
  • ClassName: 'IEFrame' WindowName: 'Log in to online banking - Windows Internet Explorer'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Log in to online banking - Mozilla Firefox'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Internet Banking: HSBC Bank UK'
  • ClassName: 'IEFrame' WindowName: 'Log in to online banking - Microsoft Internet Explorer'
  • ClassName: 'MozillaWindowClass' WindowName: 'Log in to online banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Nationwide Building Society - Internet Banking - Microsoft Internet Explorer'
  • ClassName: 'IEFrame' WindowName: 'Nationwide Building Society - Internet Banking - Windows Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Log in to online banking - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Log in to online banking - Google Chrome'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Internet Banking: HSBC Bank UK - Google Chrome'
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Button' WindowName: ''
  • ClassName: 'ThunderRT6FormDC' WindowName: 'GENREBIRTH'
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'IEFrame' WindowName: 'Internet Banking: HSBC Bank UK - Microsoft Internet Explorer'
  • ClassName: 'ThunderRT6FormDC' WindowName: 'GENREBIRTHL'
  • ClassName: 'MozillaWindowClass' WindowName: 'Internet Banking: HSBC Bank UK - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Internet Banking: HSBC Bank UK - Windows Internet Explorer'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Internet Banking: HSBC Bank UK - Mozilla Firefox'
  • ClassName: 'MozillaWindowClass' WindowName: 'Lloyds TSB - Logon - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Lloyds TSB - Logon - Microsoft Internet Explorer'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Lloyds TSB - Logon - Mozilla Firefox'
  • ClassName: 'MozillaWindowClass' WindowName: 'LloydsTSB online - Welcome - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'LloydsTSB online - Welcome - Microsoft Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Lloyds TSB - Logon - Google Chrome'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'LloydsTSB online - Welcome - Google Chrome'
  • ClassName: 'IEFrame' WindowName: 'Lloyds TSB - Logon - Windows Internet Explorer'
  • ClassName: 'IEFrame' WindowName: 'LloydsTSB online - Welcome - Windows Internet Explorer'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Santander Online Banking'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Nationwide Building Society - Internet Banking - Google Chrome'
  • ClassName: '{1C03B488-D53B-4a81-97F8-754559640193}' WindowName: 'Nationwide Building Society - Internet Banking'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Nationwide Building Society - Internet Banking - Mozilla Firefox'
  • ClassName: 'MozillaWindowClass' WindowName: 'Nationwide Building Society - Internet Banking - Mozilla Firefox'
  • ClassName: 'MozillaUIWindowClass' WindowName: 'Santander Online Banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Santander Online Banking - Windows Internet Explorer'
  • ClassName: 'Chrome_WidgetWin_0' WindowName: 'Santander Online Banking - Google Chrome'
  • ClassName: 'MozillaWindowClass' WindowName: 'Santander Online Banking - Mozilla Firefox'
  • ClassName: 'IEFrame' WindowName: 'Santander Online Banking - Microsoft Internet Explorer'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android