Home Malware Programs Worms W32.HLLW.Repsan

W32.HLLW.Repsan

Posted: March 28, 2006

W32.HLLW.Repsan is a worm that spreads through file-sharing networks.
Attempts to spread itself through KaZaA, KaZaA Lite, KaZaA Lite K++, KMD, Morpheus, eDonkey2000, Limewire, Bearshare, Overnet, Gnucleus, Grokster, Shareaza, Tesla, Rapigator, WinMX, Xolox file-sharing networks, as
well as ICQ.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:Deletethevalues:HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunWindowsCriticalUpdate=%System%windows_critical_update.exeWindowsUpdate=[filepath]here[filepath]canbe%System%windowsupdate.exeor%Windir%svchost.exemicrosoft=%Windir%svchost.exeocx32=%Windir%ocx32.exewindll=%Windir%windll32.exe
Loading...