November 12, 2004

W32.HLLW.Gaobot - Gaobot creates infected runsvc32

What to do? With a few days left for my presentation, I suddenly found my laptop infected with this Gaobot virus. Symantec detected the problem but was unable to clean, disinfect or delete the file. I subsequently deleted runsvc32.exe after rebooting. The funny thing was that this executable was lying in a very random folder. From Greatis Software it is clear that this virus most likely infects through the network, through the DCOM PRC vulnerability. So am I still infected? How do I kill this? Symantec has a removal tool.

Posted by torque at November 12, 2004 10:12 PM | TrackBack
Comments
Post a comment









Remember personal info?