Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.HLLW.Autoruner.56603

Added to the Dr.Web virus database: 2011-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates the following files on removable media:
  • <Drive name for removable media>:\AutoRun.inf
  • <Drive name for removable media>:\USBWorm.exe
Malicious functions:
Creates and executes the following:
  • <SYSTEM32>\USBWorm.exe 
Executes the following:
  • <SYSTEM32>\cmd.exe /c c:\KILLER.BAT
  • <SYSTEM32>\format.com D: /q /x /y
  • <SYSTEM32>\format.com Z: /q /x /y
  • <SYSTEM32>\cmd.exe /c bat.bat
  • %WINDIR%\explorer.exe C:\
  • <SYSTEM32>\reg.exe import key.reg
Modifies file system :
Creates the following files:
  • <Current directory>\NCKAQX.DLB
  • <Current directory>\LVFPIS.MEO
  • <Current directory>\TMWGQA.DNX
  • <Current directory>\KRHXNU.AQY
  • <Current directory>\NUKAIY.EUB
  • <Current directory>\TIYOWM.SZP
  • <Current directory>\WMLBRH.EUK
  • <Current directory>\MNPHRB.VFP
  • <Current directory>\VLBIYO.MCS
  • <Current directory>\QGGOEU.RHX
  • <Current directory>\SZWMCS.PFV
  • <Current directory>\RGWMUK.QXN
  • <Current directory>\KUEOYR.LVF
  • <Current directory>\AQXNDT.RHX
  • <Current directory>\DKAQXN.TBR
  • <Current directory>\WLBJZP.VCS
  • <Current directory>\ELBRYO.UCS
  • <Current directory>\MBRHPF.LSI
  • <Current directory>\EUKAHX.DLB
  • <Current directory>\JHXNDL.RHX
  • <Current directory>\UAIYOE.BRH
  • <Current directory>\SIYGWM.JZP
  • <Current directory>\KZPFND.JQG
  • <Current directory>\WGZJTD.XHR
  • <Current directory>\XHRBLV.PHR
  • <Current directory>\PIKCMW.QAT
  • <Current directory>\EOYISC.FPZ
  • <Current directory>\UEOYIB.VFP
  • <Current directory>\TDNXHZ.TDN
  • <Current directory>\KUEOYI.LVF
  • <Current directory>\RBLVFP.JCM
  • <Current directory>\VKAQYO.UBR
  • <Current directory>\UBRHXE.KAI
  • <Current directory>\SIPFVL.JZP
  • <Current directory>\NUKAQY.EUB
  • <Current directory>\BCEOYI.KUE
  • <Current directory>\ZPWMCS.QGW
  • <Current directory>\WUKAHX.DLB
  • <Current directory>\YOVLBR.PFV
  • <Current directory>\BLVFPZ.CMW
  • <Current directory>\VFPHRB.VFP
  • <Current directory>\IXNVLB.HOE
  • <Current directory>\DEGYIS.MWG
  • <Current directory>\NUKAIY.VLB
  • <Current directory>\QGNDTB.HOE
  • <Current directory>\MFHZJT.NXH
  • <Current directory>\UEOYIS.MFP
  • <Current directory>\JCDWGQ.TDN
  • <Current directory>\IBLVFP.JTM
  • <Current directory>\ALVFPZ.BLV
  • <Current directory>\QALVFX.RBL
  • <Current directory>\RGWEUK.HXN
  • <Current directory>\GNDTJR.XNU
  • <Current directory>\ISCEOY.SKU
  • <Current directory>\YIALVF.ZRB
  • <Current directory>\ZJWGQA.DNX
  • <Current directory>\EOYISC.EOY
  • <Current directory>\XHRBLV.XHR
  • <Current directory>\EXHRBT.NXH
  • <Current directory>\PZJTDN.HZJ
  • <Current directory>\HGWMCJ.PFV
  • <Current directory>\TDNXQA.DNX
  • <Current directory>\ZPFVCS.YOW
  • <Current directory>\XMCSAQ.WDT
  • <Current directory>\NCSIQG.MTJ
  • <Current directory>\YWMTJZ.XND
  • <Current directory>\AHXNDK.QGO
  • <Current directory>\TDWGQA.UNX
  • <Current directory>\XHRBUV.YIS
  • <Current directory>\UJZHXN.KAQ
  • <Current directory>\PFTJZP.NDT
  • <Current directory>\QSTDNX.RKU
  • <Current directory>\ISCMWG.ATD
  • <Current directory>\RBLEOY.SCM
  • <Current directory>\CSIYFV.BJZ
  • <Current directory>\ZGWMCK.QGN
  • <Current directory>\LSIYOE.CSI
  • <Current directory>\ZOEUCS.YFV
  • <Current directory>\PZJTDN.HAK
  • <Current directory>\QAKDNX.RBL
  • <Current directory>\UKRHXN.LBR
  • <Current directory>\SZPFVD.JZP
  • <Current directory>\ZJTDNX.RJT
  • <Current directory>\KUEOYQ.LVF
  • <Current directory>\ISCMFP.JTD
  • <Current directory>\TDNXHR.LEO
  • <Current directory>\FUCSIY.VLB
  • <Current directory>\LVFPZJ.DWG
  • <Current directory>\BLVFXH.BLV
  • <Current directory>\RJTDNX.RBU
  • <Current directory>\AIYOEL.RHP
  • <Current directory>\VLSIYO.MCS
  • <Current directory>\FMCSZP.VLT
  • <Current directory>\SIYFVL.JZP
  • <Current directory>\RHXNUK.QYO
  • <Current directory>\JQXNDT.RHX
  • <Current directory>\YFVLBI.OEM
  • <Current directory>\ALDNXH.BLV
  • <Current directory>\LVFXHR.LVF
  • <Current directory>\OYISCU.OYI
  • <Current directory>\PZJTMW.QAK
  • <Current directory>\ELBRZP.MCK
  • <Current directory>\GQAKDN.HRB
  • <Current directory>\YQALVF.HRB
  • <Current directory>\SCMWGQ.TDN
  • <Current directory>\FPZJTM.GQA
  • <Current directory>\OYRBLV.XHR
  • <Current directory>\FPZSCM.OYI
  • <Current directory>\MWGQAT.NXH
  • <Current directory>\YISCMW.ZJT
  • <Current directory>\VLBJZP.MCS
  • <Current directory>\FPZJTD.GQA
  • <Current directory>\GZJTDN.HRB
  • <Current directory>\UEOYIS.UEO
  • <Current directory>\XPRBLV.PZR
  • <Current directory>\CMWGQA.DNX
  • <Current directory>\MWGQAL.FXH
  • <Current directory>\BDEOYR.LVF
  • <Current directory>\WLBJZP.MCS
  • <Current directory>\TJZGWM.KRH
  • <Current directory>\NXHRBU.OYQ
  • <Current directory>\IPFVLT.ZPW
  • <Current directory>\UNXHRB.VFX
  • <Current directory>\WOYISC.WGZ
  • <Current directory>\GWMCSA.GWD
  • <Current directory>\RBLVFP.JBL
  • <Current directory>\VFYIBL.FPZ
  • <Current directory>\JQGWMU.AQX
  • <Current directory>\BLVFPZ.TLV
  • <Current directory>\GNDLBR.OEM
  • <Current directory>\UEOYQA.DNX
  • <Current directory>\MNPZRT.VFP
  • <Current directory>\IYOELB.HPF
  • <Current directory>\VKAIYO.LBR
  • <Current directory>\TJPFVL.JZP
  • <Current directory>\FVCSAQ.NDT
  • <Current directory>\YOEUBR.XFV
  • <Current directory>\YOEUCS.YOV
  • <Current directory>\DJRHXN.KAQ
  • <Current directory>\UTJZPW.CSI
  • <Current directory>\PZJTDN.QAK
  • <Current directory>\JZPFVC.IYG
  • <Current directory>\BIYOVL.RZP
  • <Current directory>\RYFVLB.ZPF
  • <Current directory>\TDNGQA.UEX
  • <Current directory>\OYIBLV.XHR
  • <Current directory>\WOYISC.WGQ
  • <Current directory>\JTDNXH.JTD
  • <Current directory>\KAQGOE.KRH
  • <Current directory>\JTDNXH.BUE
  • <Current directory>\ALVFXH.BLV
  • <Current directory>\FPZJTD.XPZ
  • <Current directory>\QAKUEO.RBL
  • <Current directory>\HPFVLS.YOW
  • <Current directory>\PZJTDN.PZJ
  • <Current directory>\WGQATD.XHR
  • <Current directory>\KUEOYI.KUE
  • <Current directory>\ZBCMWG.ATD
  • <Current directory>\HXEUKA.YOE
  • <Current directory>\LVOYIS.MWG
  • <Current directory>\GYISCM.GQA
  • <Current directory>\XVLBRZ.FVL
  • <Current directory>\RBLDNX.RBL
  • <SYSTEM32>\USBWorm.exe
  • <Current directory>\FPZJTD.XQA
  • <Current directory>\bat.bat
  • <Current directory>\key.reg
  • <Current directory>\XNVLBR.OEU
  • <Current directory>\AKUEOH.BLV
  • <Current directory>\NPQALD.XHR
  • <Current directory>\NOQAKU.XHR
  • <Current directory>\OYIBLV.PZJ
  • <Current directory>\GQATDN.HRB
  • <Auxiliary element>
  • <Current directory>\AKUNXH.KUE
  • <Current directory>\RBLVFY.SCM
  • <Current directory>\IQGNDT.RHO
  • <Current directory>\ZRBLVF.ZJC
  • <Current directory>\NOQISC.WGQ
  • C:\AutoRun.inf
  • <Current directory>\MWPZJT.VFP
  • <Current directory>\GHJTDN.HZJ
  • <Current directory>\VFPZJT.VFP
  • <Current directory>\BTDNXH.BLV
  • C:\USBWorm.exe
  • C:\KILLER.BAT
  • <Current directory>\EWGQAL.NXH
  • <Current directory>\AHXNUK.QYO
  • <Current directory>\HJBLVF.ZJT
  • <Current directory>\GQAKUN.HRB
  • <Current directory>\CJZPXN.TAQ
  • <Current directory>\HRBLVF.HRB
  • <Current directory>\JZGWMC.AQG
  • <Current directory>\SIYOVL.RZP
  • <Current directory>\LVFYIS.MWG
  • <Current directory>\IPFVDT.ZPW
  • <Current directory>\BLVFPZ.BLV
  • <Current directory>\HRBLVF.ZJC
  • <Current directory>\SUEWGQ.LVN
  • <Current directory>\MCKAQG.DTJ
  • <Current directory>\CAQGWE.KAH
  • <Current directory>\BRHXEU.AQY
  • <Current directory>\OVLBRZ.FVL
  • <Current directory>\FVLSIY.WMC
  • <Current directory>\BIYOEM.SIP
  • <Current directory>\QXNDKA.GOE
  • <Current directory>\SQGNDT.RHX
  • <Current directory>\HWMUKA.GND
  • <Current directory>\NDTJQG.MUK
  • <Current directory>\QOEUKS.YOE
  • <Current directory>\OMCSIQ.WMT
  • <Current directory>\PWMCSA.GWD
  • <Current directory>\ATDNXH.BUE
  • <Current directory>\DNXHRB.VOY
  • <Current directory>\PQSKUE.YIS
  • <Current directory>\MWGQAL.NXH
  • <Current directory>\ATMFPZ.CMW
  • <Current directory>\YISCMF.ZJT
  • <Current directory>\SCMWGQ.SCM
  • <Current directory>\CJOEUB.HXN
  • <Current directory>\CSFMCS.QGW
  • <Current directory>\QGOEUK.HXN
  • <Current directory>\AQGWDT.ZHX
  • <Current directory>\UEOYIS.VWP
  • <Current directory>\TDNXHR.LDN
  • <Current directory>\LVFPZJ.DNF
  • <Current directory>\JTDNXH.KUE
  • <Current directory>\MBRHXF.LSI
  • <Current directory>\WMCSZP.VDT
  • <Current directory>\POELBR.PFV
  • <Current directory>\KAHXND.BRH
  • <Current directory>\OYISCM.GQI
  • <Current directory>\UMWGQA.DNX
  • <Current directory>\DVFPZJ.DNG
  • <Current directory>\XHRBLV.PIS
  • <Current directory>\KIHXEU.AIY
  • <Current directory>\GVDTJZ.WMC
  • <Current directory>\MTJZPW.CSA
  • <Current directory>\HXNUKA.YOE
  • <Current directory>\DWXQAK.EXH
  • <Current directory>\GWMTJZ.XND
  • <Current directory>\LJZPFN.TJQ
  • <Current directory>\OUCSIY.VLB
  • <Current directory>\GVLTJZ.FMC
  • <Current directory>\RPNVLB.YOE
  • <Current directory>\NDTBRH.EUK
  • <Current directory>\LSIYOW.CSZ
  • <Current directory>\RYOELB.HPF
  • <Current directory>\KAQGND.JRH
  • <Current directory>\KRHXEU.AIY
Sets the 'hidden' attribute to the following files:
  • <Drive name for removable media>:\USBWorm.exe
  • <Drive name for removable media>:\AutoRun.inf
  • C:\AutoRun.inf
  • <SYSTEM32>\USBWorm.exe
  • C:\USBWorm.exe
Deletes the following files:
  • <Current directory>\key.reg
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''