1. Symantec/
  2. Security Response/
  3. PrettyPark.Worm


Risk Level 2: Low

May 28, 1999
February 13, 2007 11:48:30 AM
Also Known As:
Trojan Horse, W32.PrettyPark, Trojan.PSW.CHV, CHV, W32/Pretty.worm.unp, I-Worm.PrettyPark [Kaspersky], W32/Pretty.gen@MM [McAfee], W32/Pretty [Sophos], WORM_PRETTYPARK [Trend]
Systems Affected:

This worm program behaves similarly to Happy99 Worm. It was originally spread by email. When the attached program file, PrettyPark.exe, is executed, it may display the 3D pipe screen saver.

Once the worm program is executed, it tries to email itself automatically every 30 minutes (or 30 minutes after it is loaded) to email addresses registered in your Internet address book.

It also tries to connect to an IRC server and join a specific IRC channel. The worm sends information to IRC every 30 seconds to keep itself connected, and to retrieve any commands from the IRC channel.

Antivirus Protection Dates

  • Initial Rapid Release version June 4, 1999
  • Latest Rapid Release version August 8, 2016 revision 023
  • Initial Daily Certified version June 4, 1999
  • Latest Daily Certified version August 9, 2016 revision 001
  • Initial Weekly Certified release date June 4, 1999
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube