Inhalte aufrufen


Profilbild
- - - - -

Win32.hllw.autoruner.5555


  • Please log in to reply
2 Antworten zu diesem Thema

#1 cherfaoui

cherfaoui

    Newbie

  • Posters
  • 6 Beiträge

Geschrieben: 06 Februar 2011 - 10:36

how to eradicate this virus permanently Win32.HLLW.Autoruner.5555 making havoc in the network and yet we use
Dr.Web® Enterprise Server version 6.00.0.201009100

#2 SergM

SergM

    Guru

  • Moderators
  • 9.387 Beiträge

Geschrieben: 06 Februar 2011 - 11:26

http://vms.drweb.com/virus/?i=172457&lng=en
Use the Google Translator

#3 hekto

hekto

    Member

  • Posters
  • 143 Beiträge

Geschrieben: 06 Februar 2011 - 11:38

how to eradicate this virus permanently Win32.HLLW.Autoruner.5555 making havoc in the network and yet we use

Some backgroud. As you might already know, the virus uses two way to infect machines in the network
- vulnerability in the windows service
- weak passwords on the administrator accounts
So the first step is to apply all patches from the Windows Update. If this is not possible for now, then I'd suggest to disable Task Scheduler service. It might help too (virus will be injected to computer but won't be able to start).
Then you have to set strong password on all local computer administrator accounts as well as to all domain administrator accounts.

Normally SpiderGuard prevents infection of the computer. But if you have at least one unprotected machine in the network, it will try to infect other computers again and again.
Run GUI scanner (Drweb32W, fast scan option) one some suspicious computers to see if they are really infected. If they are infected, then you will have to cure the whole network, otherwise only a few machines that are unprotected for now.
If the machine will be infected again, then use security audit events to see the source of the infection. It will help you to find unprotected/infected computers in the network.

BTW, a bit more details about what you observes and what you already did would be very helpful :)


1 Benutzer lesen gerade dieses Thema

0 members, 1 guests, 0 anonymous users