
What is W32.HLLW.Cult.H and removal instructions
W32.HLLW.Cult.H@mm is a worm that uses its SMTP engine to send itself to randomly generated recipient names at these domains:
email.com
Earthlink.net
Roadrunner.com
yahoo.com
msn.com
hotmail.com
The email message looks like that:
Subject: I Love You ^_^ I sent you a beautiful Love Card
Message:
To see your Card, Please open the attachment
If you want to send a reply, please visit
http:/ /www.Love-card.com/Love/index.html
Thank You...
Attachment: BlueMountaineCard.pif
W32.HLLW.Cult.H manual removal:
Delete registry values:
Browse to the key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Delete the value 'sysconfig'='iexplorer.exe'
Browse to the key:
'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices'
Delete the value 'sysconfig'='iexplorer.exe'