Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Autoruner.56608

Added to the Dr.Web virus database: 2011-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates the following files on removable media:
  • <Drive name for removable media>:\AutoRun.inf
  • <Drive name for removable media>:\USBWorm.exe
Malicious functions:
Creates and executes the following:
  • <SYSTEM32>\USBWorm.exe 
Executes the following:
  • <SYSTEM32>\cmd.exe /c c:\KILLER.BAT
  • <SYSTEM32>\format.com D: /q /x /y
  • <SYSTEM32>\format.com Z: /q /x /y
  • <SYSTEM32>\cmd.exe /c bat.bat
  • %WINDIR%\explorer.exe C:\
  • <SYSTEM32>\reg.exe import key.reg
Modifies file system :
Creates the following files:
  • <Current directory>\QONDTJ.PFV
  • <Current directory>\AZXNDT.ZPF
  • <Current directory>\BAQGWM.SIY
  • <Current directory>\IJLDNX.RBL
  • <Current directory>\MKAQYO.UKA
  • <Current directory>\BJZPFV.BRH
  • <Current directory>\RSUEOY.SCM
  • <Current directory>\JCEOYI.CMW
  • <Current directory>\PQSCMW.QAT
  • <Current directory>\YFVLBR.XND
  • <Current directory>\MKAQGW.CSI
  • <Current directory>\DEOQAT.NXH
  • <Current directory>\TUWGQA.DNX
  • <Current directory>\SRHXND.JZP
  • <Current directory>\JTDNXH.BLV
  • <Current directory>\WYZJTD.XHR
  • <Current directory>\RPFVLB.HXN
  • <Current directory>\SLNXHR.LVF
  • <Current directory>\SQPFVL.RHX
  • <Current directory>\CDFPZJ.DNX
  • <Current directory>\MNPZJT.NXH
  • <Current directory>\YATDNX.RBL
  • <Current directory>\HACMWG.AKU
  • <Current directory>\QRTDNX.RBL
  • <Current directory>\YZBLVF.ZJT
  • <Current directory>\HJKDNX.RBL
  • <Current directory>\ONLBRH.NDT
  • <Current directory>\POMCBR.XND
  • <Current directory>\PNDTJZ.FVL
  • <Current directory>\VWYISC.WGQ
  • <Current directory>\FGISCM.GQA
  • <Current directory>\OPRBLV.PZJ
  • <Current directory>\IGWMCS.YOE
  • <Current directory>\TSIYOE.KAQ
  • <Current directory>\BCVFPZ.TDN
  • <Current directory>\KJHXWM.SIY
  • <Current directory>\EDBRHX.DTJ
  • <Current directory>\GEUKAQ.WMC
  • <Current directory>\LMOYIS.MWG
  • <Current directory>\AKUEOY.SCM
  • <Current directory>\BZYOEU.AQG
  • <Current directory>\FECSIY.EUK
  • <Current directory>\QPNDTJ.PFV
  • <Current directory>\JQGWMC.IYO
  • <Current directory>\GNDTJZ.FVL
  • <Current directory>\ZYOEUK.QGW
  • <Current directory>\RHXNLB.HXN
  • <Current directory>\OPZJTD.XHR
  • <Current directory>\USIYOE.KAQ
  • <Current directory>\WDTJZP.VLB
  • <Current directory>\PWMCSI.OEU
  • <Current directory>\TUWGQA.DEX
  • C:\USBWorm.exe
  • C:\AutoRun.inf
  • <Current directory>\CAZPND.JZP
  • <Current directory>\ZALVFP.JTD
  • <Current directory>\KLNXHR.LVF
  • C:\KILLER.BAT
  • <Current directory>\SQPFDT.ZPF
  • <Current directory>\LJZPFV.BRH
  • <Current directory>\QGWMCS.YOE
  • <Current directory>\TSQGFV.BRH
  • <Current directory>\WUKAQG.MCS
  • <Current directory>\TSQGWM.SIY
  • <Current directory>\ZATDNX.RBL
  • <SYSTEM32>\USBWorm.exe
  • <Current directory>\TJZPFV.BRH
  • <Current directory>\YXVLBR.XND
  • <Current directory>\key.reg
  • <Current directory>\bat.bat
  • <Current directory>\MLJZPF.LBR
  • <Current directory>\LMWGQA.VFP
  • <Current directory>\EFYISC.WGQ
  • <Current directory>\TUNXHR.LVF
  • <Current directory>\BIYOEU.AQG
  • <Current directory>\CJZPFV.BRH
  • <Current directory>\VXYISC.WGQ
  • <Current directory>\JCDNXH.BLV
  • <Current directory>\RQOEUK.QGW
  • <Current directory>\HFEUSI.OEU
  • <Current directory>\JHGWMC.IYO
  • <Current directory>\VUSIYO.UKA
  • <Current directory>\FDTJZP.VLB
  • <Current directory>\VTSIYO.UKA
  • <Current directory>\JKMWGQ.KUE
  • <Current directory>\HATDNX.RBL
  • <Current directory>\ZACMFP.JTD
  • <Current directory>\ZXWMCS.YOE
  • <Current directory>\KIYOEU.AQG
  • <Current directory>\XVLBRH.NDT
  • <Current directory>\YZSLDN.HRB
  • <Current directory>\UTRHXN.TJZ
  • <Current directory>\RQOEDB.HXN
  • <Current directory>\WVTJZP.VLB
  • <Current directory>\QAKDNX.RBL
  • <Current directory>\UVXHRB.VFP
  • <Auxiliary element>
  • <Current directory>\CEFPZJ.DNX
  • <Current directory>\GHJTDN.HRB
  • <Current directory>\DEGQAK.EOY
  • <Current directory>\RPOEUK.QGW
  • <Current directory>\WXZJTD.XHR
  • <Current directory>\WXHRBL.FPZ
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\USBWorm.exe
  • <Drive name for removable media>:\AutoRun.inf
  • C:\AutoRun.inf
  • <SYSTEM32>\USBWorm.exe
  • C:\USBWorm.exe
Deletes the following files:
  • <Current directory>\key.reg
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''