Symantec.com > Enterprise > Security Response > W32.HLLW.Infex@mm

W32.HLLW.Infex@mm

Discovered:
September 25, 2003
Updated:
February 13, 2007 12:07:46 PM
Type:
Worm

W32.HLLW.Infex@mm is a mass-mailing worm that uses Microsoft Outlook or the current MAPI program to send itself to all the contacts in the Outlook Address Book. It randomly chooses the subject line. The attachment name is Setup.rar.

The worm attempts to spread itself through some file-sharing networks, such as:
  • Bearshare
  • eDonkey2000
  • Ftopia3
  • Gnucleus
  • Grokster
  • KaZaA
  • KaZaA Lite
  • KMD
  • Limewire
  • Morpheus
  • Ovornet
  • Rapigator
  • Shareaza
  • Tesla
  • Toadnode
  • WinMX
  • XoloX.

It also attempts to spread itself through ICQ.

This threat is written in the Microsoft Visual Basic programming language and is compressed with UPX.

Antivirus Protection Dates

  • Initial Rapid Release version September 26, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version September 26, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date October 1, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yana Liu

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver