Home Malware Programs Worms W32.Holar

W32.Holar

Posted: March 28, 2006

This worm uses Outlook to send out copies of itself as an attachment in email to all the recepients in the Outlook address book. This email contains no message and has a variable subject, which is also the filename of the attached malware copy. The email attachment uses the file extension, PIF.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:Deletesubkeys:HKEY_LOCAL_MACHINESoftwareMicrosoftHolyWarHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServicesHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsHolyWarandMyLifeC:\%System%CmdServ.exe
Loading...