Content
W32/Holar.g@mm
- Type
- Virus
- SubType
- P2P Worm
- Discovery Date
- 04/19/2003
- Length
- 51357 bytes
- Minimum DAT
- 4259 (04/23/2003)
- Updated DAT
- 4362 (05/19/2004)
- Minimum Engine
- 5.1.00
- Description Added
- 04/19/2003
- Description Modified
- 05/08/2003 5:24 AM (PT)
Tab Navigation
Characteristics
This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks. However, during testing the worm proved to be buggy and at the time of writing, replication has not been observed (nor successful installation on the victim's machine).
McAfee products using the 4217 DATs (or greater) with program heuristics enabled proactively can detect the propagation component as 'virus or variant New P2P Worm' (assuming scanning of compressed files is enabled).
The worm consists of a 3-file sandwich:
DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARYThe dropper component is intended to drop and run the other components:
- Propagation component: 42,091 bytes
- SMTP library: 15,417 bytes
Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:
Various subject lines and message bodies are carried within the worm:
'''*< Love Speaks it all >*'''
Co0o0o0o0oL
Fw:
Heeeeeeeeeeeeeeeey
Wussaaaaaaaap?
WoW But not for NoW
y0 Ain't Got Shyt !
Why Do We FOk?
Heeelllooo , anybody home????
Why did u send me this shyt?
Re:Hi
Lo0o0o0o0o0o0o0o0o0o0o0o0oL
hurry up !!!
To Early To Have Sex!
Fw:Send it to all of the ppl u love
Surpise !
Again?
Who are you??????
Hummm , i hope u accept this show as an apology.
I've Got it :)
Helloooooooo
If u are booooored ...
Dispatch@McAfee.com
Attachment: Various filenames chosen from the following list (tailored to subject/message body):
- Hot_Show.pif
- Short_vClip.pif
- Beauty_VS_Your_FaCe.pif
- Endless_life.pif
- Hearts_translator.pif
- Shakiraz_Big_ass.pif
- Sweet_but_smilly.pif
- Broke_ass.pif
- Lo0o0o0o0oL.pif
- Gurls_Secrets.pif
- Tedious_SeX.pif
- Leaders_Scandals.pif
- HaWawi_N_Hawaii.pif
- Come_2_Cum.pif
- Tears_of_Happiness.pif
- White_AmeRica.pif
- Famous_PpL_N_Bad_Setuations.pif
- XxX_Mpegs_Downloader.pif
- Teenz_Raper.pif
- Real_Magic.pif
- The_Truth_of_Love.pif
- unfaithful_Gurls.pif
- How_to_improve_ur_love.pif
- AniMaL_N_Burning_Ladies.pif
- Aint_it_Funny.pif
- ToolAv01w32.pif
Symptoms
The presence of the following files:
- Explore.exe (26,624 bytes)
- SmtpNgin.ocx (14,848 bytes)
- ~DFC348.TMP (1,536 bytes)
- OR any of the files mentioned above
Method of Infection
Virus reaches user through email. User is infected upon opening the email.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks. However, during testing the worm proved to be buggy and at the time of writing, replication has not been observed (nor successful installation on the victim's machine).
McAfee products using the 4217 DATs (or greater) with program heuristics enabled proactively can detect the propagation component as 'virus or variant New P2P Worm' (assuming scanning of compressed files is enabled).
The worm consists of a 3-file sandwich:
DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARYThe dropper component is intended to drop and run the other components:
- Propagation component: 42,091 bytes
- SMTP library: 15,417 bytes
Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:
Various subject lines and message bodies are carried within the worm:
'''*< Love Speaks it all >*'''
Co0o0o0o0oL
Fw:
Heeeeeeeeeeeeeeeey
Wussaaaaaaaap?
WoW But not for NoW
y0 Ain't Got Shyt !
Why Do We FOk?
Heeelllooo , anybody home????
Why did u send me this shyt?
Re:Hi
Lo0o0o0o0o0o0o0o0o0o0o0o0oL
hurry up !!!
To Early To Have Sex!
Fw:Send it to all of the ppl u love
Surpise !
Again?
Who are you??????
Hummm , i hope u accept this show as an apology.
I've Got it :)
Helloooooooo
If u are booooored ...
Dispatch@McAfee.com
Attachment: Various filenames chosen from the following list (tailored to subject/message body):
- Hot_Show.pif
- Short_vClip.pif
- Beauty_VS_Your_FaCe.pif
- Endless_life.pif
- Hearts_translator.pif
- Shakiraz_Big_ass.pif
- Sweet_but_smilly.pif
- Broke_ass.pif
- Lo0o0o0o0oL.pif
- Gurls_Secrets.pif
- Tedious_SeX.pif
- Leaders_Scandals.pif
- HaWawi_N_Hawaii.pif
- Come_2_Cum.pif
- Tears_of_Happiness.pif
- White_AmeRica.pif
- Famous_PpL_N_Bad_Setuations.pif
- XxX_Mpegs_Downloader.pif
- Teenz_Raper.pif
- Real_Magic.pif
- The_Truth_of_Love.pif
- unfaithful_Gurls.pif
- How_to_improve_ur_love.pif
- AniMaL_N_Burning_Ladies.pif
- Aint_it_Funny.pif
- ToolAv01w32.pif
Symptoms
Symptoms -
The presence of the following files:
- Explore.exe (26,624 bytes)
- SmtpNgin.ocx (14,848 bytes)
- ~DFC348.TMP (1,536 bytes)
- OR any of the files mentioned above
Method of Infection
Method of Infection -
Virus reaches user through email. User is infected upon opening the email.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A