Spy Sweeper with AntiVirus

The most award-winning anti-spyware software

Spy Sweeper with Antivirus

Get serious about removing spyware with Spy Sweeper - the award-winning anti-spyware software trusted by millions of home computer users.

Add to Cart Button

$29.95

Spyware & Virus Directory

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 


W32.HLLW.Lama

Risk Level 2: Low

Discovered: August 2, 2002
Updated: November 20, 2003 11:04:37 AM ZE9
Type: Worm
Infection Length: 83,968 bytes, 89,088 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me

SUMMARY


W32.HLLW.Lama is a simple mass-mailing worm that uses Microsoft Outlook to send itself to all contacts in the Microsoft Outlook Address Book. It can also spread by mIRC and KaZaA shared folders. The email has numerous possible subjects, messages, and attachments.

Protection

  • Virus Definitions (LiveUpdate™ Weekly) August 7, 2002
  • Virus Definitions (Intelligent Updater) August 2, 2002

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Large Scale E-mailing: Sends itself to all contacts in the Outlood Address Book.
  • Deletes Files: May also delete files necessary to various Anti-Virus Software products.

Distribution

  • Distribution Level: High
  • Subject of Email: Varies
  • Name of Attachment: Varies
  • Size of Attachment: 83,968 Bytes; 89,088 Bytes
  • Target of Infection: copies itself to KaZaA shared folder as well as spreads via mIRC

TECHNICAL DETAILS


When W32.HLLW.Lama is executed, it does the following,

It copies itself to many locations. Here are some examples,
  • C:\%windir%Alma.exe
  • C:Test Sexi.exe
  • C:Norton Antivirus Gold Edition 2002.exe
  • C:Parche.exe
  • C:Trampa Do Brasil.exe
  • C:Cplremove.exe

NOTE: %windir% is a variable. The worm locates the Windows folder (by default this is C:Windows C:Winnt) and copies itself to that location.

It may also delete the following files:
  • C:Archiv~1PeravPav.Dll
  • C:Program FilesPeravPer.Dll
  • C:BasesAvp.Set
  • C:System32Vshield.Vxd
  • C:Archivos De ProgramasNorton AntivirusNavdx.exe

It creates one of the following Visual Basic Script (VBS) files:
  • C:Mi Alma Al Aire.vbs
  • C:ErGrone.vbs

NOTE: Symantec antivirus products detect these .vbs files as Bloodhound.VBS.Worm.

The worm may display the following messages:





The created .vbs files use Microsoft Outlook to email the worm to all contacts in Outlook address book. The email has the following characteristics:

Subject: Limpia Tu Alma!
Message:
Hola! Limpia Tu Alma Con Este Nuevo Programa!
****** Limpia Tu Alma Con: Alma Star jajaja a mi si me funsiono pruebalo tu!!
Attachment: Alma.exe

Subject: Un Test Muy Sexi!!
Message:
Prueba Este Test Sexi jajajaja
Cuidado Y Te Exitas
Attachment: Test Sexi.exe

Subject: Yo Te Amo Pero...
Message:
Yo Te Amo Pero Yu No Me Comprendes!!
Mi Amor Por Ti Es Icreible Pero Tu No Lo Ves...(Mira El Archivo Y Te Daras Cuenta)
Attachment: Lo Que Siento.exe

Subject: Shakira Y Cristina Aguilera Desnudas!!
Message:
Hola, jejejjeje Mira Este Programita
jajjaja Ta Bien Bueno ;)
Attachment: Porn Stars.exe

Subject: Nuevo Antivirus!
Message:Hola Al Fin Y Consigo Un Buen Antivirus Aqui Te lo paso!
Attachment: Norton Antivirus Gold Edition 2002.exe

Subject: Alerta!!
Message:
A Qui Te Mando Un Parche De Windows Para Internet Explorer, El Parche Es Para El IFrame En Este Sitio Encontraras Mas Informasion
http:/ /msdn.microsoft.com/library/default.asp?url=/workshop/author/dhtml/reference/objects/IFRAME.asp
Attachment: Parche.exe

Subject: !!Kamasutra El Arte Del Sexo!! ;)
Message: jejejeje Mira Este Chiquito Pero Efectivo Manual Sobre Como Hacer El AMor ;)
Attachment: Kamasutra.exe

Subject: Borracho!! jajaja
Message: Mira Como Se Siente Estar Borracho jajajja, Es Verdadero :)
Attachment: Cerveza.exe

Subject: SeX Player 2
Message: Este Es EL Mejor Programa Del mundo Puras Putas Y Putos Y Hacen Lo Que Les Digas!
Attachment: Sex Player 2.exe

Subject: COMO ES UNA PUTA :)
Message: jejejeje Mira Como Se Siente Ser Puta! ;)
Attachment: Soy Puta.exe

Subject: El Culito...
Message: jajaja Mira El Culito De Mi Prima Y Dime Que Te Parese!! ;) www.megaculos.com
Attachment: Culo.exe

Subject: Msturbate!
Message: Este Es El Mejor Programa Para Masturbarte ;)
Attachment: Masturbate.exe

Subject: Mi Mejor Follada!
Message: Haller Tuve Mi Mejor Follada Y La E Grabado En Un Programa Mirala Y Dime Si Te Gusta ;)
Attachment: Mi Follada.exe

Subject: Miss Universo 2002 Desnuda!!
Message: Con Este Programa Puedes Ver A Miss Universo 2002 Desnuda totalmente!!
Attachment: Miss Universe Nude.exe

Subject: Brasil Iso Trampa En El Mundial!!
Message: Con Este Programa Podras Ver Como Brasil Iso Trampa En El Mundial Korea Japan 2002!
Attachment: TRAMPA DO BRASIL.exe

Subject: Cura Para Dadinu El Virus CPL!
Message: Hola Aqui Te Mando La Cura Para Dadinu El Virus CPL!
Attachment: CPLREMOVE.exe

The worm adds the value

ErGrone_sent yea

to the registry key

HKEY_CORRENT_USERSoftware

This is used as a marker so that the worm does not email itself again.

So that it runs when you start Windows, the worm may add a value

Alma C:\%windir%Alma.exe

to the registry key,

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun

It also creates the file C:Alma Destructora.bat that contains this text:

@cls
@Format C:autotest
@Format A:autotest

The worm attempts to copy itself to the folder C:Program FilesKaZaAMy Shared Folder. Here are some samples of the file names that are used by the worm:
  • Norton Antivirus 2002.exe
  • Hotmail Crack Tools.exe
  • Madonna All Videos.exe
  • Fifa World Cup Kora Japan 2002.exe
  • Gamecube All Tricks.exe
  • The Sexy Nigths Show.exe
  • C:Osama Bin Ladem Game.exe
  • Kaspersky Lab.exe
  • Playstation 2 All Tricks.exe

Other KaZaA users may then download the worm from this KaZaA shared folder.

The worm also can send itself through mIRC.



Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

REMOVAL



NOTE: These instructions are for all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
  1. Update the virus definitions, run a full system scan, and delete all files that are detected as W32.HLLW.Lama or Bloodhound.VBS.Worm.
  2. Delete the value

    Alma C:\%windir%Alma.exe

    from the registry key

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
  3. Delete the value

    ErGrone_sent yea

    from the registry key

    HKEY_CORRENT_USERSoftware

For details on how to do this, read the following instructions.

To scan for and delete the infected files:
  1. Obtain the most recent virus definitions. There are two ways to do this:
    • Run LiveUpdate, which is the easiest way to obtain virus definitions. These virus definitions have undergone full quality assurance testing by Symantec Security Response and are posted to the LiveUpdate servers one time each week (usually Wednesdays) unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, look at the Virus Definitions (LiveUpdate) line at the top of this write-up.
    • Download the definitions using the Intelligent Updater. Intelligent Updater virus definitions have undergone full quality assurance testing by Symantec Security Response. They are posted on U.S. business days (Monday through Friday). They must be downloaded from the Symantec Security Response Web site and installed manually. To determine whether definitions for this threat are available by the Intelligent Updater, look at the Virus Definitions (Intelligent Updater) line at the top of this write-up.

      Intelligent Updater virus definitions are available here. For detailed instructions on how to download and install the Intelligent Updater virus definitions from the Symantec Security Response Web site, click here.
  2. Start your Symantec antivirus program, and make sure that it is configured to scan all files.
  3. Run a full system scan.
  4. If any files are detected as infected by W32.HLLW.Lama or Bloodhound.VBS.Worm, click Delete.

To remove the value from the registry:

CAUTION: Symantec strongly recommends that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify only the keys that are specified. Read the document How to make a backup of the Windows registry for instructions.
  1. Click Start, and click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Navigate to the key

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
  4. In the right pane, delete the value

    Alma C:\%windir%Alma.exe
  5. Navigate to the key

    HKEY_CORRENT_USERSoftware

  6. In the right pane, delete the value

    ErGrone_sent yea
  7. Exit the Registry Editor.



Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:

Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.

Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.

Additional Highlights

As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:

Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps

Easy Management: Quickly and simply configure program, sweep and upgrade options

Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper

Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off

Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."



"This program's dominance is apparent as soon as you install it."