Threat Database Worms Win32/Helompy

Win32/Helompy

By SpideyMan in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 1,546
First Seen: December 14, 2011
Last Seen: August 24, 2021
OS(es) Affected: Windows

Win32/Helompy is a dangerous worm that circulates by replicating itself to the root of removable drives. The main payload of Win32/Helompy is to record account credentials and login information and forward them to a remote server, where the attacker could retrieve them for use. At its roots, Win32/Helompy is a compiled AutoIt script and presents itself in an innocent way by using the icon of a folder, thus tricking computer users into trusting they are purely opening a folder once double-clicked on it. When Win32/Helompy is initiated, it creates a directory with the same name and opens the folder using a new instance of Explorer. Win32/Helompy creates a file folder and replicates itself to that directory with 'hidden', 'system' and 'read-only' file attributes, to disguise itself. The new copy of Win32/Helompy may be named 'configuration.exe', '1.exe' or 'lsass.exe'. Win32/Helompy modifies the registry so that it can run each time you start up Windows. As a payload, Win32/Helompy awaits login information to be entered for various web pages or services. Remove Win32/Helompy as soon as possible.

SpyHunter Detects & Remove Win32/Helompy

File System Details

Win32/Helompy may create the following file(s):
# File Name MD5 Detections
1. lsass.exe 292984f7d3e7347dd83b5e7bbbf74d3d 445
2. lsass.exe 1d7860e6bb87015ed1fb842f6f9bd350 175
3. lsass.exe d7d8fdcc7252a2add13e577402e0742c 166
4. lsass.exe b1b2cf681662d37e808345a904bdd20e 97
5. lsass.exe 41046278395746b075801bacac168a6b 95
6. lsass.exe f27a8e3559b07e927fec74f8ccb225ab 80
7. lsass.exe fe7b2805aefc92f49a79db6b0948a7d7 75
8. file.exe 16e04752872ea4983b71eae84da06c13 0
9. file.exe 3512cc2170cb31ce188306bc8e322425 0
10. pms.exe 59d54c2871cf9799c8dcb6d05b94925c 0
11. my music.exe 98fd894ea9904174b4827544714b66e6 0
12. file.zip 907568045e17dea5d11a20a279a241c6 0

Trending

Most Viewed

Loading...