Home > Archive > 70-210 > November 2002 > Freaking Virii





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Freaking Virii
ruscorp

2002-11-11, 3:49 pm

Today I discovered my bosses wife downloaded W32.HLLW.Gaobot virus on to her home pc which runs Windows 2000 Pro.

Normal virus removal is something routine to me, but for some strange reason this virus named "W32.HLLW.Gaobot" keeps a lickin' and keeps on tickin'. Maybe I am not removing it properly? I always remove suspicious stuff from the Run, RunOnce, and RunServices in the registry however I still see the damn thing executing upon boot. What am I missing? How can I test the machine to see if I have success got rid of it? Is there some remote control software it uses or something?

Thanks for your input.
Spid

2002-11-11, 5:01 pm

Hmmm... looks like a pain in the a$$ to get rid of.

http://securityresponse.symantec.co...llw.gaobot.html
ruscorp

2002-11-11, 5:58 pm

quote:
Originally posted by Spid
Hmmm... looks like a pain in the a$$ to get rid of.

http://securityresponse.symantec.co...llw.gaobot.html



Thanks Spid, Symantec is source of info. I already checked there and followed the directions but am still unsure if I removed it properly. Perhaps I should try to connect on port 6667 or 9900 of the target puter?

I saw a little box at the top right of the screen upon logon, I pressed maximize and it looked like a hexed version of mIRC.
thecomeons

2002-11-14, 5:51 am

abyluck yet, ruscorp?
enforcer

2002-11-14, 6:55 am

quote:
Originally posted by thecomeons
abyluck yet, ruscorp?


yeah all bad, looks like the virus has spread to your keyboard driver
ruscorp

2002-11-14, 10:02 am

Seems fine, no answer on port 6667 or 9900.

Who knows for sure though? I'm no security expert.
Sponsored Links





Free Braindumps | MCSE braindumps software forum

Copyright 2003 - 2008 examnotes.net