|
Home > Archive > 70-210 > November 2002 > Freaking Virii
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
|
|
| ruscorp 2002-11-11, 3:49 pm |
| Today I discovered my bosses wife downloaded W32.HLLW.Gaobot virus on to her home pc which runs Windows 2000 Pro.
Normal virus removal is something routine to me, but for some strange reason this virus named "W32.HLLW.Gaobot" keeps a lickin' and keeps on tickin'. Maybe I am not removing it properly? I always remove suspicious stuff from the Run, RunOnce, and RunServices in the registry however I still see the damn thing executing upon boot. What am I missing? How can I test the machine to see if I have success got rid of it? Is there some remote control software it uses or something?
Thanks for your input. | |
|
|
| ruscorp 2002-11-11, 5:58 pm |
| quote: Originally posted by Spid
Hmmm... looks like a pain in the a$$ to get rid of.
http://securityresponse.symantec.co...llw.gaobot.html
Thanks Spid, Symantec is source of info. I already checked there and followed the directions but am still unsure if I removed it properly. Perhaps I should try to connect on port 6667 or 9900 of the target puter?
I saw a little box at the top right of the screen upon logon, I pressed maximize and it looked like a hexed version of mIRC. | |
| thecomeons 2002-11-14, 5:51 am |
| abyluck yet, ruscorp? | |
| enforcer 2002-11-14, 6:55 am |
| quote: Originally posted by thecomeons
abyluck yet, ruscorp?
yeah all bad, looks like the virus has spread to your keyboard driver  | |
| ruscorp 2002-11-14, 10:02 am |
| Seems fine, no answer on port 6667 or 9900.
Who knows for sure though? I'm no security expert. |
|
|
|
|