how to eradicate this virus permanently Win32.HLLW.Autoruner.5555 making havoc in the network and yet we use
Dr.Web® Enterprise Server version 6.00.0.201009100
Win32.hllw.autoruner.5555
Автор
cherfaoui
, фев 06 2011 10:36
2 ответов в этой теме
#1
Отправлено 06 Февраль 2011 - 10:36
#2
Отправлено 06 Февраль 2011 - 11:26
#3
Отправлено 06 Февраль 2011 - 11:38
Some backgroud. As you might already know, the virus uses two way to infect machines in the networkhow to eradicate this virus permanently Win32.HLLW.Autoruner.5555 making havoc in the network and yet we use
- vulnerability in the windows service
- weak passwords on the administrator accounts
So the first step is to apply all patches from the Windows Update. If this is not possible for now, then I'd suggest to disable Task Scheduler service. It might help too (virus will be injected to computer but won't be able to start).
Then you have to set strong password on all local computer administrator accounts as well as to all domain administrator accounts.
Normally SpiderGuard prevents infection of the computer. But if you have at least one unprotected machine in the network, it will try to infect other computers again and again.
Run GUI scanner (Drweb32W, fast scan option) one some suspicious computers to see if they are really infected. If they are infected, then you will have to cure the whole network, otherwise only a few machines that are unprotected for now.
If the machine will be infected again, then use security audit events to see the source of the infection. It will help you to find unprotected/infected computers in the network.
BTW, a bit more details about what you observes and what you already did would be very helpful
Читают тему: 0
0 пользователей, 0 гостей, 0 скрытых