W32.HLLW.Gool

Risk Level 1: Very Low

Discovered:
February 12, 2003
Updated:
February 13, 2007 11:43:02 AM
Also Known As:
W32/Gool.worm [McAfee], W32/Igloo-15 [Sophos], WORM_GOOL.A [Trend]
Type:
Worm
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

W32.HLLW.Gool attempts to spread across the KaZaA file-sharing network and through IRC.

W32.HLLW.Gool has backdoor Trojan capabilities that allow a hacker to gain control of the compromised computer. The TCP port that the worm uses to connect to the hacker is 31,337 by default. The port number can be configured by using the server editor component.

This worm attempts to terminate some popular antivirus and security products processes if they are running.

W32.HLLW.Gool is written in the Borland Delphi programming language.

Antivirus Protection Dates

  • Initial Rapid Release version February 13, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version February 13, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date February 19, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: Medium
Writeup By: Yana Liu

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver