Home Malware Programs Worms Hilder

Hilder

Posted: March 28, 2006

Hilder is an Internet worm that spreads by e-mail through messages with infected attachments. Once the user executes such an attachment, the worm secretly installs itself to the computer and runs a spreading routine. It uses Microsoft Outlook to send malicious letters to all the addresses in the Outlook address book. Those e-mails are written in German. Then Hilder runs a payload. It attempts to remove installed Symantec and McAfee antivirus software. The worm can also access the Internet and contact a predefined web server.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 by.exe
    2 csrss.exe
    3 fu.exe
    4 fu0001.tmp
    5 fu0002.tmp
    6 funny.exe
    7 fuuu.exe
    8 hiberfile.sys
    9 inf3cted.exe
    10 me.exe
    11 myd00m.exe
    12 net5ky.exe
    13 sa55er.exe
    14 services.exe
    15 smss.exe
    16 u were infected.exe
    17 unbelieveable.exe
    18 wichtig.exe
    19 wind0ws.exe
Loading...