Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner.56607

Added to the Dr.Web virus database: 2011-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates the following files on removable media:
  • <Drive name for removable media>:\AutoRun.inf
  • <Drive name for removable media>:\USBWorm.exe
Malicious functions:
Creates and executes the following:
  • <SYSTEM32>\USBWorm.exe 
Executes the following:
  • <SYSTEM32>\cmd.exe /c c:\KILLER.BAT
  • <SYSTEM32>\format.com D: /q /x /y
  • <SYSTEM32>\reg.exe import key.reg
  • <SYSTEM32>\cmd.exe /c bat.bat
  • %WINDIR%\explorer.exe C:\
Modifies file system :
Creates the following files:
  • C:\USBWorm.exe
  • C:\AutoRun.inf
  • <Current directory>\DTAPWM.IPF
  • <Current directory>\BLWPZS.NGR
  • <Current directory>\SLWPZK.NGR
  • C:\KILLER.BAT
  • <Current directory>\WUJQGN.JZG
  • <Current directory>\CJZGNC.ZGV
  • <Current directory>\MXQACV.QJU
  • <Auxiliary element>
  • <Current directory>\PNUBRY.UKR
  • <Current directory>\UJQGNC.ZGV
  • <Current directory>\GZKDNG.BUF
  • <Current directory>\MWHAKD.HRC
  • <Current directory>\IBMFHR.VOY
  • <Current directory>\JCNGQJ.EXI
  • <Current directory>\key.reg
  • <Current directory>\bat.bat
  • <Current directory>\NGRBUF.ITM
  • <Current directory>\NXZSUF.IBM
  • <Current directory>\DOYRCV.QJT
  • <Current directory>\IBMFPI.DWH
  • <Current directory>\BIPELB.XEU
  • <Current directory>\JTMXQA.VGQ
  • <SYSTEM32>\USBWorm.exe
  • <Current directory>\IPFMBI.FMB
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\USBWorm.exe
  • <Drive name for removable media>:\AutoRun.inf
  • C:\AutoRun.inf
  • <SYSTEM32>\USBWorm.exe
  • C:\USBWorm.exe
Deletes the following files:
  • <Current directory>\key.reg
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''