Win32.HLLW.Autoruner3.12803
Added to the Dr.Web virus database:
2026-08-28
Virus description added:
2026-08-30
Technical Information
To ensure autorun and distribution
Creates the following files on removable media
- <Drive name for removable media>:\$recycler\<File name>.exe
- <Drive name for removable media>:\documents.lnk
- <Drive name for removable media>:\photos.lnk
- <Drive name for removable media>:\backup.lnk
Malicious functions
Patches code
in AMSI dll
- nnrqxno.exe process, Amsi.dll module
in NTDLL dll
- nnrqxno.exe process, ntdll.dll module
Modifies file system
Sets the 'hidden' attribute to the following files
- <Drive name for removable media>:\$recycler\<File name>.exe
Network activity
Connects to
- 'ap#.#pify.org':443
- 'ic###azip.com':443
- '17#.#15.236.150':44411
TCP
Other
- 'ap#.#pify.org':443
- 'ic###azip.com':443
UDP
- DNS ASK ap#.#pify.org
- DNS ASK ic###azip.com
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息