Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner2.52382

Added to the Dr.Web virus database: 2019-07-17

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Microsoft Windows Driver' = '%WINDIR%\1637425641\winenhw.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'Microsoft Windows Driver' = '%WINDIR%\1637425641\winenhw.exe'
Creates the following files on removable media
  • <Drive name for removable media>:\.lnk
  • <Drive name for removable media>:\autorun.inf
  • <Drive name for removable media>:\archer.avi
  • <Drive name for removable media>:\000814251_video_01.avi
  • <Drive name for removable media>:\default.bmp
  • <Drive name for removable media>:\dashborder_96.bmp
  • <Drive name for removable media>:\contosoroot.cer
  • <Drive name for removable media>:\coffee.bmp
  • <Drive name for removable media>:\sdkfailsafeemulator.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\dashborder_192.bmp
  • <Drive name for removable media>:\fi51.doc
  • <Drive name for removable media>:\february_catalogue__2015.doc
  • <Drive name for removable media>:\ovp25012015.doc
Malicious functions
To complicate detection of its presence in the operating system,
blocks the following features:
  • System Restore (SR)
  • Windows Security Center
Terminates or attempts to terminate
the following system processes:
  • <SYSTEM32>\wininit.exe
Modifies file system
Creates the following files
  • %WINDIR%\1637425641\winenhw.exe
  • <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\1[1].exe
  • %TEMP%\3539940747.exe
  • <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\2[1].exe
  • %TEMP%\3939516910.exe
  • <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\4[1].exe
  • %TEMP%\3320729512.exe
  • <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\caasbycl\5[1].exe
  • %TEMP%\1447132115.exe
  • <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\6[1].exe
  • %TEMP%\4253537320.exe
Sets the 'hidden' attribute to the following files
  • %WINDIR%\1637425641\winenhw.exe
  • <Drive name for removable media>:\.lnk
  • <Drive name for removable media>:\autorun.inf
Network activity
TCP
HTTP GET requests
  • http://19#.#2.161.69/1.exe
  • http://19#.#2.161.69/2.exe
  • http://19#.#2.161.69/3.exe
  • http://19#.#2.161.69/4.exe
  • http://19#.#2.161.69/5.exe
  • http://19#.#2.161.69/6.exe
  • http://19#.#2.161.69/7.exe
Miscellaneous
Creates and executes the following
  • '%WINDIR%\1637425641\winenhw.exe'
  • '%TEMP%\3320729512.exe'
  • '%TEMP%\3939516910.exe'
  • '%TEMP%\3539940747.exe'
  • '%TEMP%\1447132115.exe'
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\glidescope_review_rev_010.docx", "<Drive name for removable media>:\\_\glidescope_review_rev_010.docx"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\thlps_keeper_mayer_1965.docx", "<Drive name for removable media>:\\_\thlps_keeper_mayer_1965.docx"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\weeklysheet1215.doc", "<Drive name for removable media>:\\_\weeklysheet1215.doc"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\fi51.doc", "<Drive name for removable media>:\\_\fi51.doc"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\ovp25012015.doc", "<Drive name for removable media>:\\_\ovp25012015.doc"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\february_catalogue__2015.doc", "<Drive name for removable media>:\\_\february_catalogue__2015.doc"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\TestCertificate.cer", "<Drive name for removable media>:\\_\TestCertificate.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\testEE.cer", "<Drive name for removable media>:\\_\testEE.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso.cer", "<Drive name for removable media>:\\_\contoso.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKSamplePrivDeveloper.cer", "<Drive name for removable media>:\\_\SDKSamplePrivDeveloper.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKFailsafeEmulator.cer", "<Drive name for removable media>:\\_\SDKFailsafeEmulator.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contosoroot.cer", "<Drive name for removable media>:\\_\contosoroot.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_192.bmp", "<Drive name for removable media>:\\_\dashBorder_192.bmp"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\coffee.bmp", "<Drive name for removable media>:\\_\coffee.bmp"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\default.bmp", "<Drive name for removable media>:\\_\default.bmp"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_96.bmp", "<Drive name for removable media>:\\_\dashBorder_96.bmp"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\archer.avi", "<Drive name for removable media>:\\_\archer.avi"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\000814251_video_01.avi", "<Drive name for removable media>:\\_\000814251_video_01.avi"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso_1.cer", "<Drive name for removable media>:\\_\contoso_1.cer"' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\holycrosschurchinstructions.docx", "<Drive name for removable media>:\\_\holycrosschurchinstructions.docx"' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\000814251_video_01.avi", "<Drive name for removable media>:\\_\000814251_video_01.avi"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\thlps_keeper_mayer_1965.docx", "<Drive name for removable media>:\\_\thlps_keeper_mayer_1965.docx"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\weeklysheet1215.doc", "<Drive name for removable media>:\\_\weeklysheet1215.doc"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\fi51.doc", "<Drive name for removable media>:\\_\fi51.doc"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\ovp25012015.doc", "<Drive name for removable media>:\\_\ovp25012015.doc"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\february_catalogue__2015.doc", "<Drive name for removable media>:\\_\february_catalogue__2015.doc"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\TestCertificate.cer", "<Drive name for removable media>:\\_\TestCertificate.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso.cer", "<Drive name for removable media>:\\_\contoso.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\testEE.cer", "<Drive name for removable media>:\\_\testEE.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKFailsafeEmulator.cer", "<Drive name for removable media>:\\_\SDKFailsafeEmulator.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso_1.cer", "<Drive name for removable media>:\\_\contoso_1.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKSamplePrivDeveloper.cer", "<Drive name for removable media>:\\_\SDKSamplePrivDeveloper.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contosoroot.cer", "<Drive name for removable media>:\\_\contosoroot.cer"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_192.bmp", "<Drive name for removable media>:\\_\dashBorder_192.bmp"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\coffee.bmp", "<Drive name for removable media>:\\_\coffee.bmp"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\default.bmp", "<Drive name for removable media>:\\_\default.bmp"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_96.bmp", "<Drive name for removable media>:\\_\dashBorder_96.bmp"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\archer.avi", "<Drive name for removable media>:\\_\archer.avi"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\glidescope_review_rev_010.docx", "<Drive name for removable media>:\\_\glidescope_review_rev_010.docx"
  • '%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\holycrosschurchinstructions.docx", "<Drive name for removable media>:\\_\holycrosschurchinstructions.docx"