W32.Led@mm
Aliases: W32/Fagled@MM, Win32.Fagled
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: North America
Removal: Easy
Platform: W32
Discovered: 22 Jan 2002
Damage: Low
Characteristics: W32.Led@mm is a mass mailing worm. It replicates itself and spreads to other computers using Microsoft Messenger, Microsoft Outlook, and mIRC. The worm gets email addresses from the infected computer. It also searches for .vbs files, and, runs each file it finds after creating a list of them.
W32.Led@mm Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Led@mm from your computer.
More details about W32.Led@mm
Once W32.Led is executed, it performs mass mailing. The email messages have different subjects like “LOL!”, “Yo Momma”, etc. The message under each subject varies. The email is sent to the email address master##@hotmail.com. The ## is a random number. Attachments for these email messages also vary depending on the subject. However, the typical filename of the attachment is Led.exe. The worm searches for the files Default.html and Index.html. Once it finds them, it will overwrite them with its own Default.html or Index.html and copy the file ienet.exe to that folder. The worm also attempts to propagate using MSN messenger. It does this by sending out MSN messenger chat messages that trick users to go to a website that contains the worm.The same attempt to spread happens using mIRC. It modifies the Script.ini file sending a message that tells other mIRC users to go to a website that contains the worm. The worm adds values to the registry and modifies it to make sure it runs every Windows startup. Lastly, it executes all .vbs files that it finds on the infected computer. To remove the worm, update virus definitions. Afterwards, run a full system scan and delete files that are detected as W32.Led@mm. Remove the value that the worm added to the registry. Restart your computer and rescan the system to double check.
Browse for more malware information
- W32.Led@mm
- W32.Leebad
- W32.Lemoor.A
- W32.Liac.A@mm
- W32.Likasimal
- W32.Lile.A
- W32.Lindo
- W32.Linkbot.A
- W32.Linkfars
- W32.Litar.Worm
- W32.Lofni.Worm
- W32.Logitall.A@mm
- W32.Lohack.C.Worm
- W32.Longbe@mm
- W32.Looked
- W32.Looksky.A@mm
- W32.Lorac
- W32.Losabel
- W32.Lovena.A@mm
- W32.Lovgate.AB@mm
- W32.Loxbot.A
- W32.Lunalight@mm
- W32.Mabezat.A
- W32.Madag.A
- W32.Madangel
- W32.Maddis.B
- W32.Mafeg
- W32.Magflag.A@mm
- W32.Mailbancos@mm
- W32.Maldal.C@mm