マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Win32.HLLM.Limar.4507

Added to the Dr.Web virus database: 2013-08-03

Virus description added:

Technical Information

Malicious functions:
Creates and executes the following:
  • '%TEMP%\_swfwe.dat'
Hooks the following functions in System Service Descriptor Table (SSDT):
  • NtQuerySystemInformation, handler: ndishook.sys
Modifies file system :
Creates the following files:
  • %TEMP%\_swfwe.dat
  • <DRIVERS>\ndishook.sys
  • %TEMP%\gamelist.dat
  • %TEMP%\stoplist.dat
Deletes the following files:
  • %TEMP%\stoplist.dat
  • %TEMP%\gamelist.dat
Network activity:
Connects to:
  • 'li####o.365doc.info':6000
  • 'li####o.pk2012.info':6000
  • 'li####o.pcdogs.info':6000
  • '11#.#1.243.2':6000
  • '12#.#25.114.144':80
  • 'ga##.##0xiaoshuo.info':6000
  • 'fl##.####00714692.twsapp.com':80
UDP:
  • DNS ASK li####o.365doc.info
  • DNS ASK li####o.pk2012.info
  • DNS ASK li####o.pcdogs.info
  • DNS ASK fl##.####00714692.twsapp.com
  • DNS ASK www.ba##u.com
  • DNS ASK ga##.##0xiaoshuo.info
  • '25#.#55.255.255':2012
Miscellaneous:
Searches for the following windows:
  • ClassName: 'SE_SogouExplorerFrame' WindowName: '(null)'
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'
  • ClassName: 'IEFrame' WindowName: '(null)'
  • ClassName: '360se_Frame' WindowName: '(null)'