Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner3.2187

Added to the Dr.Web virus database: 2020-04-09

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost.exe' = '"<Full path to file>"'
Creates or modifies the following files
  • <SYSTEM32>\tasks\svchost.exe
  • <SYSTEM32>\tasks\windowssystemhost
Creates the following files on removable media
  • <Drive name for removable media>:\autorun.inf
Malicious functions
Searches for windows to
detect analytical utilities:
  • ClassName: 'OLLYDBG', WindowName: ''
  • ClassName: 'GBDYLLO', WindowName: ''
  • ClassName: 'pediy06', WindowName: ''
Modifies file system
Creates the following files
  • C:\autorun.inf
  • D:\autorun.inf
Network activity
TCP
HTTP GET requests
  • http://ip##pi.com/json/
  • '16#.#9.187.240':2323
  • UDP
    • DNS ASK ip##pi.com
    Miscellaneous
    Creates and executes the following
    • '%WINDIR%\syswow64\schtasks.exe' /create /tn "WINDOWSSYSTEMHOST" /tr "<Full path to file>" /sc MINUTE /MO 1' (with hidden window)
    • '<Full path to file>' ' (with hidden window)
    Executes the following
    • '%WINDIR%\syswow64\schtasks.exe' /create /tn "svchost.exe" /sc ONLOGON /tr "<Full path to file>" /rl HIGHEST /f
    • '%WINDIR%\syswow64\schtasks.exe' /create /tn "WINDOWSSYSTEMHOST" /tr "<Full path to file>" /sc MINUTE /MO 1
    • '<SYSTEM32>\taskeng.exe' {0C63354C-3142-4E5E-BDC6-BEB9C609250E} S-1-5-21-1960123792-2022915161-3775307078-1001:cncbylxdmsvf\user:Interactive:[1]
    The Russian developer of Dr.Web anti-viruses
    Doctor Web has been developing anti-virus software since 1992
    Dr.Web is trusted by users around the world in 200+ countries
    The company has delivered an anti-virus as a service since 2007
    24/7 tech support

    Dr.Web © Doctor Web
    2003 — 2020

    Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

    2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125040