Uploaded March 2014 | Updated September 2026, 2 weeks ago
Originally known under alias Win32.HLLP.Quizy used by virus author Gigabyte (author is a female if you're still thinking otherwise). However, AV companies have a policy against naming virus or worm which author wanted to use. As I'm using Kaspersky Labs alias, the full alias name by Kaspersky Labs for this worm is Email-Worm.Win32.Qizy.
It will infect all files in Personal Folder Shell (by default it's My Documents folder), while it will infect Windows folder only if it's running NT version. Worm drops startup.exe (runs at startup as it's added in Run entry in HKLM and it asks 10 questions which should be answered to find out how to disinfect your PC) and xmas.scr (worm copy) in root folder, Mail.vbs (which is quickly gone, used for sending emails) and jbells.rtx ringtone in System folder.
Infected files run worm and original program by extracting it from infected file under name origfile.exe. However, it's only there for short time, so unless it's copied quickly, it's removed.
Aliases:
AVG: Win32/Quis.A
AVP: I-Worm.Qizy
BitDefender: Win32.HLLP.Izuqy.A
CA: Win32.Quis.A
ClamAV: Worm.Quizy
Kaspersky Labs: Email-Worm.Win32.Qizy
McAfee: W32/Quis@MM
Panda: W32/Quiz.A
Sophos: W32/Qizy-A
Symantec: W32.HLLP.Belzy@mm
Trend Micro: PE_QUIS.A-O
Originally known under alias Win32.HLLP.Quizy used by virus author Gigabyte (author is a female if you're still thinking otherwise). However, AV companies have a policy against naming virus or worm which author wanted to use. As I'm using Kaspersky Labs alias, the full alias name by Kaspersky Labs for this worm is Email-Worm.Win32.Qizy.
It will infect all files in Personal Folder Shell (by default it's My Documents folder), while it will infect Windows folder only if it's running NT version. Worm drops startup.exe (runs at startup as it's added in Run entry in HKLM and it asks 10 questions which should be answered to find out how to disinfect your PC) and xmas.scr (worm copy) in root folder, Mail.vbs (which is quickly gone, used for sending emails) and jbells.rtx ringtone in System folder.
Infected files run worm and original program by extracting it from infected file under name origfile.exe. However, it's only there for short time, so unless it's copied quickly, it's removed.
Aliases:
AVG: Win32/Quis.A
AVP: I-Worm.Qizy
BitDefender: Win32.HLLP.Izuqy.A
CA: Win32.Quis.A
ClamAV: Worm.Quizy
Kaspersky Labs: Email-Worm.Win32.Qizy
McAfee: W32/Quis@MM
Panda: W32/Quiz.A
Sophos: W32/Qizy-A
Symantec: W32.HLLP.Belzy@mm
Trend Micro: PE_QUIS.A-O







