Holar Removal Tool crack/serial/keygen
Holar Removal Tool is a useful application that was created in order to erase the [email protected] worm.
The virus was written in Visual Basic and compressed with UPX.
|Crack size||~ 500KB|
When run, it will copy itself as HAwa.pif and will drop its embedded components: smtp.ocx (an SMTP ActiveX control used to send email messages; this component is registered using regsvr32) and the executable explore.exe.
The registry entry
is created to run the worm at every start-up. The executable's read-only, hidden and system file attributes are set.
An empty file 0.mpeg is created and open (usually, with Media Player); this is probably meant to trick users to believe they had actually downloaded a (corrupted) multimedia file.
Copies of the worm are created in the Windows System folder with the following names:
The virus scans for target email addresses in .txt, .htm, .html, .dbx files and in Internet Explorer's cache. The format of the emails sent is chosen from various combinations of Subject line and Body and the attachment is one of the files named above.
The virus will also attempt to copy itself in the Kazaa shared folder if this file sharing application is installed, using the names listed above. This way, other Kazaa users might download it from the infected user.
The registry entry
is initialized with 0 when the virus is installed; each time the virus is run again (when Windows is restarted), the value of the entry is incremented; when it reaches 30, the virus attempts to delete all .exe, .jpg, .doc, .pps, .ram, .zip files, and it displays several message boxes.
Finally, the virus will shutdown Windows; the operating system and all installed applications will have to be reinstalled.
Irene, 02 April 2017
thanks for working Holar Removal Tool patch
Leave a comment
Your email will not be published. * Required