Skip to main content

Viking.H

Classification

Category:

Malware

Type:

Virus

Aliases:

  • DR/Muldrop.1417.C
  • W32/Viking.I
  • Win32/Viking.H
  • W32/Looked.B
  • PE_LEGMIR.KO
  • W32.Looked.H
  • Worm.Win32.Viking.h
  • W32/Philis-K
  • W32/HLLP.Philis.q
  • W32/Viking.J
  • W32.Philis.P

Summary

Viking.H, a variant of Viking, is a Virus. Viking.H creates files in the Windows directory and downloads and runs a file from website: [http://www.54088.org/backup/[REMOVED]1.exe Viking.H kills processes belonging to anti-virus and security software.

Removal

Technical Details

Once an infected file is executed, Viking.H will drop the following files in the Windows directory:

  • Logo1_.exe - Infector
  • vDll.dll - Downloader

The .DLL component is injected into IEXPLORE.EXE. Viking.H adds the following registry entry as a part of its installation:

  • [HKLM\SOFTWARE\Soft\DownloadWWW] auto = "1"

It creates the following text files where it writes some information related to its activities:

  • C:\gamevir.txt
  • C:\log.txt

Viking.H is a prepending virus that searches for files starting from fixed drives from the Z: to C: drives.It infects files with the following extension:

  • exe

It avoids infecting files with the following strings in its path or filename:

  • \Program Files\
  • Common Files
  • ComPlus Applications
  • Documents and Settings
  • InstallShield Installation Information
  • Internet Explorer
  • Messenger
  • Microsoft Frontpage
  • Microsoft Office
  • Movie Maker
  • MSN
  • MSN Gaming Zone
  • NetMeeting
  • Outlook Express
  • Recycled
  • system
  • System Volume Information
  • system32
  • windows
  • Windows Media Player
  • Windows NT
  • WindowsUpdate
  • winnt

In order for the host file to execute, Viking.H creates a backup copy of the itself in the current directory as [filename].exe.exe and then drops and executes the original uninfected host file as [filename].exe. After which, it will now delete the uninfected host file and renames the backup file to the original filename. Viking.H is able to do this with the help of a temporary batch file created in the temporary folder as $$.bat. Viking.H sends the message "Hello, World" to the following IP address via Internet Control Message Protocol (ICMP) :

  • 192.168.0.30
  • 192.168.8.1

It also attempts to propagate via network shares by copying itself to the following shared folders:

  • admin$
  • ipc$

- with the following accounts:

  • administrator
  • guest

It stops the following service:

  • "Kingsoft AntiVirus Service"

It terminates the following processes that are often related to Anti-virus products:

  • EGHOST.EXE
  • IPARMOR.EXE
  • KAVPFW.EXE
  • MAILMON.EXE
  • RavMon.exe
  • RavMonClass

Viking.H attempts to download and execute files from the following site:

  • https://www.54088.org/backup/[REMOVED]1.exe

Note: This site is already down.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.