Port No | 9900 |
Service Name | W32.HLLW.Gaobot |
RFC Doc | 0 |
Protocol | TCP |
Description | W32.HLLW.Gaobot is a worm that copies itself as %system%\Sysldr32.exe. |
Reference Link | Port Number:9900 Service Name:W32.HLLW.Gaobot Port:TCP |
Attack | According to Symantec Resolution: NOTE: These instructions are for all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines. 1.Update the virus definitions. 2.Run a full system scan, and delete all files that are detected as W32.HLLW.Gaobot. 3.Delete the value: "Config Loader"="%system%\sysldr32.exe" from the registry keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices 4.Delete the value: "[Default]"="regfile" from the registry key: HKEY_CLASSES_ROOT\.Key |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.