x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

Hedong

 
Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Hedong
Technical name:W32/Hedong@MM
Threat level:Low
Type:Worm
Effects:  It deletes files with the following extensions: EXE, MP3, DLL and DAT.

Detection updated on:May 16, 2002
StatisticsNo

Brief Description 

    

Hedong is a dangerous worm that spreads via e-mail and carries out destructive actions.

Hedong deletes all the files that it finds with the following extensions: EXE, MP3, DLL and DAT.

It also changes the home page of Internet Explorer to http://www.hziee.edu.cn

It is very easy to become infected by Hedong, as it is automatically run when the message carrying the worm is viewed through Outlook's Preview Pane.

It does this by exploiting a vulnerability in Internet Explorer (versions 5.01 and 5.5) that allows files attached to e-mail messages to be automatically run.

Visible Symptoms 

    

It is very easy to know if Hedong has infected a computer, as it changes the home page of Internet Explorer to http://www.hziee.edu.cn.

In addition, this virus reaches computers hidden in an e-mail message that always includes one of the following attachments:

  • HELLO.VBS
  • HELLO.EXE