Content

W32/Holar.g@mm

Type
Virus
SubType
P2P Worm
Discovery Date
04/19/2003
Length
51357 bytes
Minimum DAT
4259 (04/23/2003)
Updated DAT
4362 (05/19/2004)
Minimum Engine
5.1.00
Description Added
04/19/2003
Description Modified
05/08/2003 5:24 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks. However, during testing the worm proved to be buggy and at the time of writing, replication has not been observed (nor successful installation on the victim's machine).

McAfee products using the 4217 DATs (or greater) with program heuristics enabled proactively can detect the propagation component as 'virus or variant New P2P Worm' (assuming scanning of compressed files is enabled).

The worm consists of a 3-file sandwich:

DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARY

The dropper component is intended to drop and run the other components:

  • Propagation component: 42,091 bytes
  • SMTP library: 15,417 bytes

Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:

Various subject lines and message bodies are carried within the worm:

'''*< Love Speaks it all >*'''

Co0o0o0o0oL

Fw:

Heeeeeeeeeeeeeeeey

Wussaaaaaaaap?

WoW But not for NoW

y0 Ain't Got Shyt !

Why Do We FOk?

Heeelllooo , anybody home????

Why did u send me this shyt?

Re:Hi

Lo0o0o0o0o0o0o0o0o0o0o0o0oL

hurry up !!!

To Early To Have Sex!

Fw:Send it to all of the ppl u love

Surpise !

Again?

Who are you??????

Hummm , i hope u accept this show as an apology.

I've Got it :)

Helloooooooo

If u are booooored ...

Dispatch@McAfee.com

Attachment: Various filenames chosen from the following list (tailored to subject/message body):

  • Hot_Show.pif
  • Short_vClip.pif
  • Beauty_VS_Your_FaCe.pif
  • Endless_life.pif
  • Hearts_translator.pif
  • Shakiraz_Big_ass.pif
  • Sweet_but_smilly.pif
  • Broke_ass.pif
  • Lo0o0o0o0oL.pif
  • Gurls_Secrets.pif
  • Tedious_SeX.pif
  • Leaders_Scandals.pif
  • HaWawi_N_Hawaii.pif
  • Come_2_Cum.pif
  • Tears_of_Happiness.pif
  • White_AmeRica.pif
  • Famous_PpL_N_Bad_Setuations.pif
  • XxX_Mpegs_Downloader.pif
  • Teenz_Raper.pif
  • Real_Magic.pif
  • The_Truth_of_Love.pif
  • unfaithful_Gurls.pif
  • How_to_improve_ur_love.pif
  • AniMaL_N_Burning_Ladies.pif
  • Aint_it_Funny.pif
  • ToolAv01w32.pif

Symptoms

The presence of the following files:

  • Explore.exe (26,624 bytes)
  • SmtpNgin.ocx (14,848 bytes)
  • ~DFC348.TMP (1,536 bytes)
  • OR any of the files mentioned above

Method of Infection

Virus reaches user through email. User is infected upon opening the email.

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Characteristics

Characteristics -

This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks. However, during testing the worm proved to be buggy and at the time of writing, replication has not been observed (nor successful installation on the victim's machine).

McAfee products using the 4217 DATs (or greater) with program heuristics enabled proactively can detect the propagation component as 'virus or variant New P2P Worm' (assuming scanning of compressed files is enabled).

The worm consists of a 3-file sandwich:

DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARY

The dropper component is intended to drop and run the other components:

  • Propagation component: 42,091 bytes
  • SMTP library: 15,417 bytes

Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:

Various subject lines and message bodies are carried within the worm:

'''*< Love Speaks it all >*'''

Co0o0o0o0oL

Fw:

Heeeeeeeeeeeeeeeey

Wussaaaaaaaap?

WoW But not for NoW

y0 Ain't Got Shyt !

Why Do We FOk?

Heeelllooo , anybody home????

Why did u send me this shyt?

Re:Hi

Lo0o0o0o0o0o0o0o0o0o0o0o0oL

hurry up !!!

To Early To Have Sex!

Fw:Send it to all of the ppl u love

Surpise !

Again?

Who are you??????

Hummm , i hope u accept this show as an apology.

I've Got it :)

Helloooooooo

If u are booooored ...

Dispatch@McAfee.com

Attachment: Various filenames chosen from the following list (tailored to subject/message body):

  • Hot_Show.pif
  • Short_vClip.pif
  • Beauty_VS_Your_FaCe.pif
  • Endless_life.pif
  • Hearts_translator.pif
  • Shakiraz_Big_ass.pif
  • Sweet_but_smilly.pif
  • Broke_ass.pif
  • Lo0o0o0o0oL.pif
  • Gurls_Secrets.pif
  • Tedious_SeX.pif
  • Leaders_Scandals.pif
  • HaWawi_N_Hawaii.pif
  • Come_2_Cum.pif
  • Tears_of_Happiness.pif
  • White_AmeRica.pif
  • Famous_PpL_N_Bad_Setuations.pif
  • XxX_Mpegs_Downloader.pif
  • Teenz_Raper.pif
  • Real_Magic.pif
  • The_Truth_of_Love.pif
  • unfaithful_Gurls.pif
  • How_to_improve_ur_love.pif
  • AniMaL_N_Burning_Ladies.pif
  • Aint_it_Funny.pif
  • ToolAv01w32.pif

Symptoms

Symptoms -

The presence of the following files:

  • Explore.exe (26,624 bytes)
  • SmtpNgin.ocx (14,848 bytes)
  • ~DFC348.TMP (1,536 bytes)
  • OR any of the files mentioned above

Method of Infection

Method of Infection -

Virus reaches user through email. User is infected upon opening the email.

Removal -

Removal -

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A