Technical Information
To ensure autorun and distribution:
Creates the following files on removable media:
- <Drive name for removable media>:\AutoRun.inf
- <Drive name for removable media>:\USBWorm.exe
Malicious functions:
Creates and executes the following:
- <SYSTEM32>\USBWorm.exe
Executes the following:
- <SYSTEM32>\cmd.exe /c c:\KILLER.BAT
- <SYSTEM32>\format.com D: /q /x /y
- <SYSTEM32>\format.com Z: /q /x /y
- <SYSTEM32>\cmd.exe /c bat.bat
- %WINDIR%\explorer.exe C:\
- <SYSTEM32>\reg.exe import key.reg
Modifies file system :
Creates the following files:
- <Current directory>\NCKAQX.DLB
- <Current directory>\LVFPIS.MEO
- <Current directory>\TMWGQA.DNX
- <Current directory>\KRHXNU.AQY
- <Current directory>\NUKAIY.EUB
- <Current directory>\TIYOWM.SZP
- <Current directory>\WMLBRH.EUK
- <Current directory>\MNPHRB.VFP
- <Current directory>\VLBIYO.MCS
- <Current directory>\QGGOEU.RHX
- <Current directory>\SZWMCS.PFV
- <Current directory>\RGWMUK.QXN
- <Current directory>\KUEOYR.LVF
- <Current directory>\AQXNDT.RHX
- <Current directory>\DKAQXN.TBR
- <Current directory>\WLBJZP.VCS
- <Current directory>\ELBRYO.UCS
- <Current directory>\MBRHPF.LSI
- <Current directory>\EUKAHX.DLB
- <Current directory>\JHXNDL.RHX
- <Current directory>\UAIYOE.BRH
- <Current directory>\SIYGWM.JZP
- <Current directory>\KZPFND.JQG
- <Current directory>\WGZJTD.XHR
- <Current directory>\XHRBLV.PHR
- <Current directory>\PIKCMW.QAT
- <Current directory>\EOYISC.FPZ
- <Current directory>\UEOYIB.VFP
- <Current directory>\TDNXHZ.TDN
- <Current directory>\KUEOYI.LVF
- <Current directory>\RBLVFP.JCM
- <Current directory>\VKAQYO.UBR
- <Current directory>\UBRHXE.KAI
- <Current directory>\SIPFVL.JZP
- <Current directory>\NUKAQY.EUB
- <Current directory>\BCEOYI.KUE
- <Current directory>\ZPWMCS.QGW
- <Current directory>\WUKAHX.DLB
- <Current directory>\YOVLBR.PFV
- <Current directory>\BLVFPZ.CMW
- <Current directory>\VFPHRB.VFP
- <Current directory>\IXNVLB.HOE
- <Current directory>\DEGYIS.MWG
- <Current directory>\NUKAIY.VLB
- <Current directory>\QGNDTB.HOE
- <Current directory>\MFHZJT.NXH
- <Current directory>\UEOYIS.MFP
- <Current directory>\JCDWGQ.TDN
- <Current directory>\IBLVFP.JTM
- <Current directory>\ALVFPZ.BLV
- <Current directory>\QALVFX.RBL
- <Current directory>\RGWEUK.HXN
- <Current directory>\GNDTJR.XNU
- <Current directory>\ISCEOY.SKU
- <Current directory>\YIALVF.ZRB
- <Current directory>\ZJWGQA.DNX
- <Current directory>\EOYISC.EOY
- <Current directory>\XHRBLV.XHR
- <Current directory>\EXHRBT.NXH
- <Current directory>\PZJTDN.HZJ
- <Current directory>\HGWMCJ.PFV
- <Current directory>\TDNXQA.DNX
- <Current directory>\ZPFVCS.YOW
- <Current directory>\XMCSAQ.WDT
- <Current directory>\NCSIQG.MTJ
- <Current directory>\YWMTJZ.XND
- <Current directory>\AHXNDK.QGO
- <Current directory>\TDWGQA.UNX
- <Current directory>\XHRBUV.YIS
- <Current directory>\UJZHXN.KAQ
- <Current directory>\PFTJZP.NDT
- <Current directory>\QSTDNX.RKU
- <Current directory>\ISCMWG.ATD
- <Current directory>\RBLEOY.SCM
- <Current directory>\CSIYFV.BJZ
- <Current directory>\ZGWMCK.QGN
- <Current directory>\LSIYOE.CSI
- <Current directory>\ZOEUCS.YFV
- <Current directory>\PZJTDN.HAK
- <Current directory>\QAKDNX.RBL
- <Current directory>\UKRHXN.LBR
- <Current directory>\SZPFVD.JZP
- <Current directory>\ZJTDNX.RJT
- <Current directory>\KUEOYQ.LVF
- <Current directory>\ISCMFP.JTD
- <Current directory>\TDNXHR.LEO
- <Current directory>\FUCSIY.VLB
- <Current directory>\LVFPZJ.DWG
- <Current directory>\BLVFXH.BLV
- <Current directory>\RJTDNX.RBU
- <Current directory>\AIYOEL.RHP
- <Current directory>\VLSIYO.MCS
- <Current directory>\FMCSZP.VLT
- <Current directory>\SIYFVL.JZP
- <Current directory>\RHXNUK.QYO
- <Current directory>\JQXNDT.RHX
- <Current directory>\YFVLBI.OEM
- <Current directory>\ALDNXH.BLV
- <Current directory>\LVFXHR.LVF
- <Current directory>\OYISCU.OYI
- <Current directory>\PZJTMW.QAK
- <Current directory>\ELBRZP.MCK
- <Current directory>\GQAKDN.HRB
- <Current directory>\YQALVF.HRB
- <Current directory>\SCMWGQ.TDN
- <Current directory>\FPZJTM.GQA
- <Current directory>\OYRBLV.XHR
- <Current directory>\FPZSCM.OYI
- <Current directory>\MWGQAT.NXH
- <Current directory>\YISCMW.ZJT
- <Current directory>\VLBJZP.MCS
- <Current directory>\FPZJTD.GQA
- <Current directory>\GZJTDN.HRB
- <Current directory>\UEOYIS.UEO
- <Current directory>\XPRBLV.PZR
- <Current directory>\CMWGQA.DNX
- <Current directory>\MWGQAL.FXH
- <Current directory>\BDEOYR.LVF
- <Current directory>\WLBJZP.MCS
- <Current directory>\TJZGWM.KRH
- <Current directory>\NXHRBU.OYQ
- <Current directory>\IPFVLT.ZPW
- <Current directory>\UNXHRB.VFX
- <Current directory>\WOYISC.WGZ
- <Current directory>\GWMCSA.GWD
- <Current directory>\RBLVFP.JBL
- <Current directory>\VFYIBL.FPZ
- <Current directory>\JQGWMU.AQX
- <Current directory>\BLVFPZ.TLV
- <Current directory>\GNDLBR.OEM
- <Current directory>\UEOYQA.DNX
- <Current directory>\MNPZRT.VFP
- <Current directory>\IYOELB.HPF
- <Current directory>\VKAIYO.LBR
- <Current directory>\TJPFVL.JZP
- <Current directory>\FVCSAQ.NDT
- <Current directory>\YOEUBR.XFV
- <Current directory>\YOEUCS.YOV
- <Current directory>\DJRHXN.KAQ
- <Current directory>\UTJZPW.CSI
- <Current directory>\PZJTDN.QAK
- <Current directory>\JZPFVC.IYG
- <Current directory>\BIYOVL.RZP
- <Current directory>\RYFVLB.ZPF
- <Current directory>\TDNGQA.UEX
- <Current directory>\OYIBLV.XHR
- <Current directory>\WOYISC.WGQ
- <Current directory>\JTDNXH.JTD
- <Current directory>\KAQGOE.KRH
- <Current directory>\JTDNXH.BUE
- <Current directory>\ALVFXH.BLV
- <Current directory>\FPZJTD.XPZ
- <Current directory>\QAKUEO.RBL
- <Current directory>\HPFVLS.YOW
- <Current directory>\PZJTDN.PZJ
- <Current directory>\WGQATD.XHR
- <Current directory>\KUEOYI.KUE
- <Current directory>\ZBCMWG.ATD
- <Current directory>\HXEUKA.YOE
- <Current directory>\LVOYIS.MWG
- <Current directory>\GYISCM.GQA
- <Current directory>\XVLBRZ.FVL
- <Current directory>\RBLDNX.RBL
- <SYSTEM32>\USBWorm.exe
- <Current directory>\FPZJTD.XQA
- <Current directory>\bat.bat
- <Current directory>\key.reg
- <Current directory>\XNVLBR.OEU
- <Current directory>\AKUEOH.BLV
- <Current directory>\NPQALD.XHR
- <Current directory>\NOQAKU.XHR
- <Current directory>\OYIBLV.PZJ
- <Current directory>\GQATDN.HRB
- <Auxiliary element>
- <Current directory>\AKUNXH.KUE
- <Current directory>\RBLVFY.SCM
- <Current directory>\IQGNDT.RHO
- <Current directory>\ZRBLVF.ZJC
- <Current directory>\NOQISC.WGQ
- C:\AutoRun.inf
- <Current directory>\MWPZJT.VFP
- <Current directory>\GHJTDN.HZJ
- <Current directory>\VFPZJT.VFP
- <Current directory>\BTDNXH.BLV
- C:\USBWorm.exe
- C:\KILLER.BAT
- <Current directory>\EWGQAL.NXH
- <Current directory>\AHXNUK.QYO
- <Current directory>\HJBLVF.ZJT
- <Current directory>\GQAKUN.HRB
- <Current directory>\CJZPXN.TAQ
- <Current directory>\HRBLVF.HRB
- <Current directory>\JZGWMC.AQG
- <Current directory>\SIYOVL.RZP
- <Current directory>\LVFYIS.MWG
- <Current directory>\IPFVDT.ZPW
- <Current directory>\BLVFPZ.BLV
- <Current directory>\HRBLVF.ZJC
- <Current directory>\SUEWGQ.LVN
- <Current directory>\MCKAQG.DTJ
- <Current directory>\CAQGWE.KAH
- <Current directory>\BRHXEU.AQY
- <Current directory>\OVLBRZ.FVL
- <Current directory>\FVLSIY.WMC
- <Current directory>\BIYOEM.SIP
- <Current directory>\QXNDKA.GOE
- <Current directory>\SQGNDT.RHX
- <Current directory>\HWMUKA.GND
- <Current directory>\NDTJQG.MUK
- <Current directory>\QOEUKS.YOE
- <Current directory>\OMCSIQ.WMT
- <Current directory>\PWMCSA.GWD
- <Current directory>\ATDNXH.BUE
- <Current directory>\DNXHRB.VOY
- <Current directory>\PQSKUE.YIS
- <Current directory>\MWGQAL.NXH
- <Current directory>\ATMFPZ.CMW
- <Current directory>\YISCMF.ZJT
- <Current directory>\SCMWGQ.SCM
- <Current directory>\CJOEUB.HXN
- <Current directory>\CSFMCS.QGW
- <Current directory>\QGOEUK.HXN
- <Current directory>\AQGWDT.ZHX
- <Current directory>\UEOYIS.VWP
- <Current directory>\TDNXHR.LDN
- <Current directory>\LVFPZJ.DNF
- <Current directory>\JTDNXH.KUE
- <Current directory>\MBRHXF.LSI
- <Current directory>\WMCSZP.VDT
- <Current directory>\POELBR.PFV
- <Current directory>\KAHXND.BRH
- <Current directory>\OYISCM.GQI
- <Current directory>\UMWGQA.DNX
- <Current directory>\DVFPZJ.DNG
- <Current directory>\XHRBLV.PIS
- <Current directory>\KIHXEU.AIY
- <Current directory>\GVDTJZ.WMC
- <Current directory>\MTJZPW.CSA
- <Current directory>\HXNUKA.YOE
- <Current directory>\DWXQAK.EXH
- <Current directory>\GWMTJZ.XND
- <Current directory>\LJZPFN.TJQ
- <Current directory>\OUCSIY.VLB
- <Current directory>\GVLTJZ.FMC
- <Current directory>\RPNVLB.YOE
- <Current directory>\NDTBRH.EUK
- <Current directory>\LSIYOW.CSZ
- <Current directory>\RYOELB.HPF
- <Current directory>\KAQGND.JRH
- <Current directory>\KRHXEU.AIY
Sets the 'hidden' attribute to the following files:
- <Drive name for removable media>:\USBWorm.exe
- <Drive name for removable media>:\AutoRun.inf
- C:\AutoRun.inf
- <SYSTEM32>\USBWorm.exe
- C:\USBWorm.exe
Deletes the following files:
- <Current directory>\key.reg
Miscellaneous:
Searches for the following windows:
- ClassName: '' WindowName: ''