Antivirus and Security Software from Sophos

Sophos blogs

W32/Lolol-E

Aliases
  • Worm.P2P.Lolol.e
  • Win32/Lolol.E
  • worm
  • W32.HLLW.Lolol
Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Lolol-E is a worm and a backdoor Trojan.

The worm component is primarily targeted at users running the KaZaA peer-to-peer application. The worm creates 88 copies of itself in the folders C:\Program Files\Kazaa Lite\My Shared Folder, C:\Program Files\Kazaa\My Shared Folder and C:\My Downloads.

The following list contains examples of the filenames used for the copies
of the worm:

100 free essays school.pif
age of empires 2 cheats.exe
aim cracker.exe
aim password cracker
anarchist cookbook.pif
aol cracker.exe
aol password cracker.exe
divx pro.exe
driver.exe
fireworks.exe
fuck.exe
GTA 3 Crack.exe
GTA 3 Serial.exe
gta3.exe
hondra screen saver.scr
HotGirls.exe
hotmail hack.exe
how to hack.exe
how to use a shell.pif
NBA 2003 Crack.exe
NBA 2003 serials.epif
NBA 2003.exe
pamela anderson screen saver.scr
play station emulator crack.exe
play station emulator.exe
porn screen saver.scr
steal usernames.exe
super mario bros.exe
super mario brothers.exe
supra screen saver.scr
ut 2k3.exe
ut 2k3.pif
virtua girl - completely nude.pif
virtua girl - jenn.pif
Virtua Girl (Full).exe
Virtua Sex.exe
warcraft 3 crack.exe
warcraft 3 serials.pif
winxp.iso.pif
worldbook.exe

The backdoor Trojan component will connect to an IRC server and join a channel where it will wait for commands issued by an attacker using that IRC channel. The commands will be interpreted by the server into actions to carry out on the host computer.

When first executed the worm will copy itself to the file C:\Windows\System\winsys.exe.

The following registry entries will be created to start the worm when Windows starts up:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Configuration Loader
HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\Configuration Loader

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer