1. Symantec/
  2. Security Response/
  3. W32.HLLW.Bonny

W32.HLLW.Bonny

Discovered:
November 27, 2002
Updated:
February 13, 2007 11:41:21 AM
Type:
Worm
Systems Affected:
Windows

W32.HLLW.Bonny is a peer-to-peer worm that targets such programs as KaZaA and Bearshare.

When it runs, it copies itself to the following files:
  • C:\Windows\KILT.exe
  • C:\Kilt.exe
  • A:\Tlik.exe
  • \\Server\Kilt.exe
  • C:\Program Files\Windows Media Player\Wmplayer.exe
  • C:\Windows\System32\Screensaver.exe
  • C:\Program Files\Kazaa\My Shared Folder\KILT GAME.exe
  • C:\Program Files\Bearshare\Shared\KILT GAME.exe
  • C:\Program Files\Edonkey2000\Incoming\KILT GAME.exe
  • C:\Program Files\Kazaa\My Shared Folder\KILT.exe
  • C:\Program Files\Bearshare\Shared\KILT.exe
  • C:\Program Files\Edonkey2000\Incoming\KILT.exe
  • C:\Program Files\Swaptor\Download\Kilt.exe
  • C:\Program Files\Swaptor\Download\KILT GAME.exe
  • C:\Documents and Settings\All Users\Documents\Kilt.exe
  • C:\Documents and Settings\All Users\Documents\KILT GAME.exe
  • C:\Documents and Settings\All Users\Documents\Shared Music\Kilt.exe

It then displays a funny picture.

Antivirus Protection Dates

  • Initial Rapid Release version December 2, 2002
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version December 2, 2002
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date December 4, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Summary| Removal

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube