1. Symantec/
  2. Security Response/
  3. W32.HLLW.Oror.AG@mm

W32.HLLW.Oror.AG@mm

Risk Level 2: Low

Discovered:
March 3, 2003
Updated:
February 13, 2007 11:43:39 AM
Also Known As:
I-Worm.Roron.51 [KAV], Win32/Roron.Z@mm [RAV], W32/Oror.gen.c@MM [McAfee]
Type:
Worm
Systems Affected:
Windows


W32.HLLW.Oror.AG@mm is a mass-mailing worm and a variant of W32.HLLW.Oror@mm. This worm attempts to spread using email, mIRC, KaZaA, network shares, and mapped drives. The email attachment will arrive with a .exe or .scr file extentions. W32.HLLW.Oror.AG@mm also attempts to terminate and remove various security products from the infected computer.

This threat is written in the C++ language and is compressed with UPX.

NOTE: Virus definitions dated prior to March 5, 2003 may detect this threat as W32.HLLW.Oror.Z@mm.

Antivirus Protection Dates

  • Initial Rapid Release version March 3, 2003
  • Latest Rapid Release version March 3, 2003
  • Initial Daily Certified version March 3, 2003
  • Latest Daily Certified version March 3, 2003
  • Initial Weekly Certified release date March 5, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Eric Chien

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube