Discovered: February 17, 2004
Updated: February 20, 2004 4:14:52 PM
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.HLLW.Antinny.E is a worm that propagates through the Winny peer-to-peer file-sharing network. When the worm is executed, it searches the local drive for files with a .txt extension and opens the first one it finds.
Next, it creates the following folders:
%System%\SystemDLL
%My Documents%\Down
It then creates a randomly named copy of itself using a name composed from strings in the worm's code. Each time the worm creates a copy of itself, it appends garbage data to the end of the file so that every copy of the worm is a different file size. This file is created in the Winny shared folder.