Symantec.com > Enterprise > Security Response > W32.HLLW.Magold.E@mm

W32.HLLW.Magold.E@mm

Risk Level 2: Low

Discovered:
June 23, 2003
Updated:
February 13, 2007 12:02:47 PM
Also Known As:
WORM_AURIC.E [Trend], I-Worm.Magold.e [KAV], W32/Magold-D [Sophos]
Type:
Worm
Systems Affected:
Windows 2000, Windows NT, Windows XP

W32.HLLW.Magold.E@mm is a mass-mailing worm that sends itself to all the contacts it finds in the Windows Address Book, as well as in all the files whose extension begins with "ht." The email will have a random subject and a file attachment named Sziszi_video.scr. The worm also attempts to spread itself through various file-sharing networks, mIRC and Pirch. It attempts to terminate the processes of various programs, including antivirus software.

The worm displays a fake message when initially executed.

This threat is written in Borland C++Builder and is compressed with UPX.

Antivirus Protection Dates

  • Initial Rapid Release version June 24, 2003
  • Latest Rapid Release version June 24, 2003
  • Initial Daily Certified version June 24, 2003
  • Latest Daily Certified version June 24, 2003
  • Initial Weekly Certified release date June 25, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: High
Writeup By: Robert X Wang

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver