Event ID - 3127

Port No3127
Service NameW32.HLLW.Deadhat
RFC Doc0
ProtocolTCP
DescriptionW32.HLLW.Deadhat is a worm with backdoor capabilities. It attempts to uninstall the W32.Mydoom.A@mm and W32.Mydoom.B@mm worms, and then it spreads to other systems infected with Mydoom. Also, it spreads through the Soulseek file-sharing program.
Reference LinkPort Number:3127 Service Name:W32.HLLW.Deadhat Port:TCP
AttackAccording to Symantec

Resolution:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3.Restart the computer in Safe mode or VGA mode.
4. Run a full system scan and delete all the files detected as W32.HLLW.Deadhat.
5. Reverse the changes made to the registry.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.