Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:Win32.HLLW.Bropia (Dr.Web), W32/Gnildo.A(exact) (Fprot), IM-Worm.Win32.Aimes.c(Kaspersky)
Type:Worm 
Size:27,672 bytes 
Origin: 
Date:02-24-2005 
Damage: 
VDF Version: 6.29.0.148 
Danger:Low 
Distribution:Low 

DistributionMay try to spread via MSN Messenger and send the following details:

Message: "Look At This Hot Naked Girl"
Attachment: "Hey look at my moms dildo!!.pif"

Technical DetailsIf the worm is executed, it makes the following changes into the Windows Registry:

Add:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsBackup"="[%WinDir%]\\WindowsBackup.exe"

New:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\security center]
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\security center]
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000001
"DisableRegistryTools"=dword:00000001

Delete:
[HKLM\software\Microsoft\windows\currentversion\run\cfgpwnz.exe]

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run\actboost.exe]


It copies itself into the Windows System Directory with the following names:

Hey look at my moms dildo!!.pif
WindowsBackup.exe

The malware stops this services:
TASKKILL /T /F /IM SVCHOST.exe
TASKKILL /F /IM LSASS.exe

This causes the system to panic an start a reboot sequence.

The virus contains the following string: PaRaSiTe Soft.
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .