1. /
  2. Security Response/
  3. W32.HLLW.Bymer

W32.HLLW.Bymer

Risk Level 2: Low

Discovered:
October 9, 2000
Updated:
February 13, 2007 11:50:29 AM
Also Known As:
Dnet.Dropper, W32/MsInit.worm.a [McAfee], Worm.Bymer.a [Kaspersky], TROJ_MSINIT.A [Trend], WORM_BYMER.A [Trend], W32/Bymer-A [Sophos], Win32.Bymer.A [Computer Associ
Type:
Worm
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Due to a decreased rate of submissions, Symantec Security Response has downgraded the threat level of this worm from Category 3 to Category 2.

W32.HLLW.Bymer is a worm written in a high-level language. The worm spreads over shared network drives. It searches for shared folders on the network and then copies itself to the \Windows\System folder.

The payload copies the Dnetc client and modifies the Win.ini file. The Dnetc client is not viral and is not detected by Norton AntiVirus.

The worm was previously detected as Dnet.Dropper.

Symantec has created an interactive tutorial to help you remove this worm.




Configure Windows for maximum protection
Because this virus spreads by using shared folders on networked computers, to ensure that the virus does not reinfect the computer after it has been removed, Symantec suggests sharing with read-only access or using password protection. For instructions on how to do this, see your Windows documentation or the document How to configure shared Windows folders for maximum network protection.

Antivirus Protection Dates

  • Initial Rapid Release version October 10, 2000
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version October 10, 2000
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date October 10, 2000
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: More than 1000
  • Number of Sites: More than 10
  • Geographical Distribution: Medium
  • Threat Containment: Moderate
  • Removal: Moderate

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: High
Writeup By: Neal Hindocha

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver