Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Autoruner.56602

Added to the Dr.Web virus database: 2011-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates the following files on removable media:
  • <Drive name for removable media>:\AutoRun.inf
  • <Drive name for removable media>:\USBWorm.exe
Malicious functions:
Creates and executes the following:
  • <SYSTEM32>\USBWorm.exe 
Executes the following:
  • <SYSTEM32>\cmd.exe /c c:\KILLER.BAT
  • <SYSTEM32>\format.com D: /q /x /y
  • <SYSTEM32>\format.com Z: /q /x /y
  • <SYSTEM32>\cmd.exe /c bat.bat
  • %WINDIR%\explorer.exe C:\
  • <SYSTEM32>\reg.exe import key.reg
Modifies file system :
Creates the following files:
  • <Current directory>\NTIXVT.PFD
  • <Current directory>\FLSQOM.IXV
  • <Current directory>\ETZXEC.PNL
  • <Current directory>\TIGECA.WUK
  • <Current directory>\YJLNPR.VXH
  • <Current directory>\DOQSUW.ATV
  • <Current directory>\NHAUWY.TVX
  • <Current directory>\FZSUWY.UWY
  • <Current directory>\XMKIGE.AYO
  • <Current directory>\AZYXWV.TSR
  • <Current directory>\AGNCAY.USQ
  • <Current directory>\CRPNLJ.FDB
  • <Current directory>\EPRTVX.BDN
  • <Current directory>\YSLNPR.VGI
  • <Current directory>\TNPRTV.ZBL
  • <Current directory>\CVPRTV.ZJL
  • <Current directory>\WLJHFD.ZXN
  • <Current directory>\SZFDBZ.VLJ
  • <Current directory>\FQSUWY.TVX
  • <Current directory>\BZFDBZ.VLJ
  • <Current directory>\YSLNYA.NPZ
  • <Current directory>\BVOQSU.HJL
  • <Current directory>\ODBZXV.RPF
  • <Current directory>\EYRTEG.KMO
  • <Current directory>\MSZXVT.PEC
  • <Current directory>\DSQOMK.GEU
  • <Current directory>\HSUWYA.VXZ
  • <Current directory>\PACNPR.VXZ
  • <Current directory>\OZBDFH.LNP
  • <Current directory>\AUXQSU.HJL
  • <Current directory>\AUNYAL.XZK
  • <Current directory>\AUWQSU.GIK
  • <Current directory>\UAHFDB.XMK
  • <Current directory>\MXITVX.BUF
  • <Current directory>\AMOIKM.QSU
  • <Current directory>\CNPRTV.ZBL
  • <Current directory>\ZTMXZB.FHJ
  • <Current directory>\RKEGIK.OYA
  • <Current directory>\KQXVTR.NCA
  • <Current directory>\AUNHJL.PRT
  • <Current directory>\JYWUSQ.MKA
  • <Current directory>\MBHFDB.XNL
  • <Current directory>\JUWYAT.XZB
  • <Current directory>\EPJTVX.BMO
  • <Current directory>\KRXVTR.FDB
  • <Current directory>\LSYWMK.GEC
  • <Current directory>\DSZOMK.GEC
  • <Current directory>\NYACEG.KMW
  • <Current directory>\MXQBDF.JLN
  • <Current directory>\WQJLNP.TEG
  • <Current directory>\AUFQSU.GIK
  • <Current directory>\CNHRTV.ZBM
  • <Current directory>\WHJLNP.KMX
  • <Current directory>\YRLNPZ.DFH
  • <Current directory>\WCJHFD.ZOM
  • <Current directory>\SHFDBZ.VTJ
  • <Current directory>\XDKIGE.AYN
  • <Current directory>\LAYWUS.OMC
  • <Current directory>\MFZBDN.RTV
  • <Current directory>\CWPRTV.ZKM
  • <Current directory>\RCEGIK.OQA
  • <Current directory>\VPIKMO.KMW
  • <Current directory>\IOVTRP.LAY
  • <Current directory>\GMTRPN.JYW
  • <Current directory>\EYALVX.BDF
  • <Current directory>\ZFMBZX.TRP
  • <Current directory>\KEXZBD.HSU
  • <Current directory>\FZSUFH.LNP
  • C:\AutoRun.inf
  • C:\USBWorm.exe
  • <Current directory>\LRYDBQ.MKI
  • <Current directory>\OIBMOQ.LWY
  • <Current directory>\UOHJLN.RCE
  • <Current directory>\XRKVXZ.UWY
  • <Current directory>\NCAYWU.QOE
  • <Current directory>\MFZBDF.JTV
  • <Current directory>\GRTVXZ.DFP
  • <Current directory>\HBUWYA.WYA
  • <Current directory>\APNLJH.DBR
  • <Current directory>\TZGECA.WLJ
  • <Current directory>\ZOMKIG.CAQ
  • <Current directory>\ZOVKIG.CAQ
  • <SYSTEM32>\USBWorm.exe
  • <Current directory>\BQOMKI.ECS
  • <Current directory>\bat.bat
  • <Current directory>\key.reg
  • <Current directory>\YELJHF.BQO
  • <Current directory>\RLEGRT.XZB
  • <Current directory>\GVTRPN.JHX
  • <Current directory>\FUSQOM.IGW
  • C:\KILLER.BAT
  • <Current directory>\OUBZXV.IGE
  • <Current directory>\VBIGEC.YWL
  • <Current directory>\JCEGIT.XZB
  • <Current directory>\VKIGEC.YWM
  • <Current directory>\CIPNLJ.FUS
  • <Current directory>\LRYWUS.ODB
  • <Current directory>\MBZXVT.PND
  • <Current directory>\PVCAYW.SHF
  • <Current directory>\TZFVTR.NLJ
  • <Current directory>\XQKMOQ.UEG
  • <Current directory>\GZTVXZ.LNP
  • <Current directory>\HBUWHJ.NGR
  • <Current directory>\ICVXZB.FQS
  • <Current directory>\WQJLNP.TEX
  • <Current directory>\EYRTVX.BMO
  • <Current directory>\LWYATV.ZBD
  • <Current directory>\MXZBDF.JLV
  • <Current directory>\UBHFDB.PNL
  • <Current directory>\LRYWUS.FDB
  • <Current directory>\LFYAUW.ATV
  • <Current directory>\PJCEGI.MXZ
  • <Current directory>\YELAYW.SQO
  • <Current directory>\SDFHJL.PRB
  • <Current directory>\RGECAY.USI
  • <Current directory>\IXVTRP.CAY
  • <Current directory>\JPWLJH.DBZ
  • <Current directory>\BQGECA.WLJ
  • <Current directory>\RGECAY.USQ
  • <Current directory>\EKRPNL.HWU
  • <Current directory>\SMFHJL.PAL
  • <Current directory>\PALNPR.VFH
  • <Current directory>\WPJTVX.BDF
  • <Current directory>\OIBDFH.LWY
  • <Current directory>\QBDFHJ.NPZ
  • <Current directory>\GVBZXN.JHF
  • <Current directory>\ZKMOQS.WYI
  • <Current directory>\MGZBDF.JUW
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\USBWorm.exe
  • <Drive name for removable media>:\AutoRun.inf
  • C:\AutoRun.inf
  • <SYSTEM32>\USBWorm.exe
  • C:\USBWorm.exe
Deletes the following files:
  • <Current directory>\key.reg
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''