1. Symantec/
  2. Security Response/
  3. W32.HLLW.Gool


Risk Level 1: Very Low

February 12, 2003
February 13, 2007 11:43:02 AM
Also Known As:
W32/Gool.worm [McAfee], W32/Igloo-15 [Sophos], WORM_GOOL.A [Trend]
Systems Affected:

W32.HLLW.Gool attempts to spread across the KaZaA file-sharing network and through IRC.

W32.HLLW.Gool has backdoor Trojan capabilities that allow a hacker to gain control of the compromised computer. The TCP port that the worm uses to connect to the hacker is 31,337 by default. The port number can be configured by using the server editor component.

This worm attempts to terminate some popular antivirus and security products processes if they are running.

W32.HLLW.Gool is written in the Borland Delphi programming language.

Antivirus Protection Dates

  • Initial Rapid Release version February 13, 2003
  • Latest Rapid Release version March 23, 2017 revision 037
  • Initial Daily Certified version February 13, 2003
  • Latest Daily Certified version March 23, 2017 revision 041
  • Initial Weekly Certified release date February 19, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yana Liu

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube