Content
W32/Holar.h@MM
- Type
- Virus
- SubType
- Internet Worm
- Discovery Date
- 05/28/2003
- Length
- 56,614 bytes
- Minimum DAT
- 4267 (05/28/2003)
- Updated DAT
- 4391 (09/15/2004)
- Minimum Engine
- 5.1.00
- Description Added
- 05/28/2003
- Description Modified
- 05/28/2003 1:54 PM (PT)
Tab Navigation
Characteristics
This threat is proactively detected as New MSVB P2P worm when using the 4266 DAT files with the 4.2.40 scan engine and scanning compressed executables (a default scan option).
This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks.
The worm consists of a 3-file sandwich:
DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARYThe dropper component is intended to drop and run the other components:
- Propagation component: 56,614 bytes
- SMTP library: 25,737 bytes
Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:
From: Dispatch@McAfee.com
Various subject lines and message bodies are carried within the worm:
'''*< Love Speaks it all >*'''
Co0o0o0o0oL
Fw:
Heeeeeeeeeeeeeeeey
Wussaaaaaaaap?
WoW But not for NoW
y0 Ain't Got Shyt !
Why Do We FOk?
Heeelllooo , anybody home????
Why did u send me this shyt?
Re:Hi
Lo0o0o0o0o0o0o0o0o0o0o0o0oL
hurry up !!!
To Early To Have Sex!
Fw:Send it to all of the ppl u love
Surpise !
Again?
Who are you??????
Hummm , i hope u accept this show as an apology.
I've Got it :)
Helloooooooo
If u are booooored ...
Dispatch@McAfee.com
Attachment: Various filenames chosen from the following list (tailored to subject/message body):
- Aint_it_Funny.pif
- AniMaL_N_Burning_Ladies.pif
- Beauty_VS_Your_FaCe.pif
- Broke_ass.pif
- Come_2_Cum.pif
- Endless_life.pif
- Famous_PpL_N_Bad_Setuations.pif
- Gurls_Secrets.pif
- HAwa.pif
- HaWawi_N_Hawaii.pif
- Hearts_translator.pif
- Hot_Show.pif
- How_to_improve_ur_love.pif
- Leaders_Scandals.pif
- Lo0o0o0o0oL.pif
- Real_Magic.pif
- Shakiraz_Big_ass.pif
- Short_vClip.pif
- Sweet_but_smilly.pif
- Tears_of_Happiness.pif
- Tedious_SeX.pif
- Teenz_Raper.pif
- The_Truth_of_Love.pif
- ToolAv01w32.pif
- unfaithful_Gurls.pif
- White_AmeRica.pif
- XxX_Mpegs_Downloader.pif
- explore.exe (24,064 bytes)
- SMTP.ocx (25,737 bytes)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "Explore" = C:\WINDOWS\SYSTEM\EXPLORE.exe
Symptoms
- Presence of the aforementioned filenames
- The virus creates a counter registry value:
- HKEY_CURRENT_USER\DeathTime = %Run count%







Method of Infection
This worm spreads via email and the KaZaa P2P file-sharing network.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
This threat is proactively detected as New MSVB P2P worm when using the 4266 DAT files with the 4.2.40 scan engine and scanning compressed executables (a default scan option).
This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks.
The worm consists of a 3-file sandwich:
DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARYThe dropper component is intended to drop and run the other components:
- Propagation component: 56,614 bytes
- SMTP library: 25,737 bytes
Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:
From: Dispatch@McAfee.com
Various subject lines and message bodies are carried within the worm:
'''*< Love Speaks it all >*'''
Co0o0o0o0oL
Fw:
Heeeeeeeeeeeeeeeey
Wussaaaaaaaap?
WoW But not for NoW
y0 Ain't Got Shyt !
Why Do We FOk?
Heeelllooo , anybody home????
Why did u send me this shyt?
Re:Hi
Lo0o0o0o0o0o0o0o0o0o0o0o0oL
hurry up !!!
To Early To Have Sex!
Fw:Send it to all of the ppl u love
Surpise !
Again?
Who are you??????
Hummm , i hope u accept this show as an apology.
I've Got it :)
Helloooooooo
If u are booooored ...
Dispatch@McAfee.com
Attachment: Various filenames chosen from the following list (tailored to subject/message body):
- Aint_it_Funny.pif
- AniMaL_N_Burning_Ladies.pif
- Beauty_VS_Your_FaCe.pif
- Broke_ass.pif
- Come_2_Cum.pif
- Endless_life.pif
- Famous_PpL_N_Bad_Setuations.pif
- Gurls_Secrets.pif
- HAwa.pif
- HaWawi_N_Hawaii.pif
- Hearts_translator.pif
- Hot_Show.pif
- How_to_improve_ur_love.pif
- Leaders_Scandals.pif
- Lo0o0o0o0oL.pif
- Real_Magic.pif
- Shakiraz_Big_ass.pif
- Short_vClip.pif
- Sweet_but_smilly.pif
- Tears_of_Happiness.pif
- Tedious_SeX.pif
- Teenz_Raper.pif
- The_Truth_of_Love.pif
- ToolAv01w32.pif
- unfaithful_Gurls.pif
- White_AmeRica.pif
- XxX_Mpegs_Downloader.pif
- explore.exe (24,064 bytes)
- SMTP.ocx (25,737 bytes)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "Explore" = C:\WINDOWS\SYSTEM\EXPLORE.exe
Symptoms
Symptoms -
- Presence of the aforementioned filenames
- The virus creates a counter registry value:
- HKEY_CURRENT_USER\DeathTime = %Run count%







Method of Infection
Method of Infection -
This worm spreads via email and the KaZaa P2P file-sharing network.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A