W32.HLLW.Ajja

Risk Level 1: Very Low

Discovered:
March 5, 2003
Updated:
February 13, 2007 11:43:47 AM
Type:
Worm
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

The W32.HLLW.Ajja worm attempts to spread across the KaZaA, Grokster, and Edonkey2000 file-sharing networks. This worm also attempts to delete program files belonging to several antivirus programs.

As part of the execution of W32.HLLW.Ajja, a fake "Install" message will prompt you to "Clik!! in Next to Install."

W32.HLLW.Ajja is written in Microsoft Visual Basic, version 6.

NOTE: Virus definitions dated prior to March 5, 2003 may detect this threat as Bloodhound.W32.5.

Antivirus Protection Dates

  • Initial Rapid Release version March 5, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version March 5, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date March 5, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: Medium
Writeup By: Kaoru Hayashi

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver