Win32.Holar.H@mm is a pretty damaging Mass Mailer Worm with medium spreading. This worm comes as an e-mail with a HAwa.pif attachement. When run, it will copy itself as HAwa.pif and will drop its embedded components: smtp.ocx (an SMTP ActiveX control used to send email messages; this component is registered using regsvr32) and the executable explore.exe.
The registry entry [HKLMSoftwareMicrosoftWindowsCurrentVersionrunExplore] is created to run the worm at every start-up. The executable´s read-only, hidden and system file attributes are set.
The virus is written in Visual Basic and compressed with UPX. Download and run this removal from BitDefender in complete security and clean your system. |