Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner3.12803

Added to the Dr.Web virus database: 2026-08-28

Virus description added:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\$recycler\<File name>.exe
  • <Drive name for removable media>:\documents.lnk
  • <Drive name for removable media>:\photos.lnk
  • <Drive name for removable media>:\backup.lnk
Malicious functions
Patches code
in AMSI dll
  • nnrqxno.exe process, Amsi.dll module
in NTDLL dll
  • nnrqxno.exe process, ntdll.dll module
Modifies file system
Sets the 'hidden' attribute to the following files
  • <Drive name for removable media>:\$recycler\<File name>.exe
Network activity
Connects to
  • 'ap#.#pify.org':443
  • 'ic###azip.com':443
  • '17#.#15.236.150':44411
TCP
Other
  • 'ap#.#pify.org':443
  • 'ic###azip.com':443
UDP
  • DNS ASK ap#.#pify.org
  • DNS ASK ic###azip.com