Event ID - 445

Port No445
Service NameW32.HLLW.Gaobot.gen
RFC Doc0
ProtocolTCP
DescriptionW32.HLLW.Gaobot.gen is a detection for a large family of worms, which propagate themselves using multiple vulnerabilities including:
Weak passwords on network shares.
Reference LinkPort Number:445 Service Name:W32.HLLW.Gaobot.gen Port:TCP
AttackRemoval using the Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.HLLW.Gaobot.gen. The removal tool will remove many but not all variants that are detected as W32.HLLW.Gaobot.gen.
If the removal tool cannot remove the variant that has infected your computer, follow the instructions in the next section.
Manual Removal
Perform a manual removal if you cannot obtain the tool, or if the tool does not remove the variant that has infected your computer.
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
1.Disable System Restore (Windows Me/XP).
2.Restart the computer in Safe mode or VGA mode.
3.Restore the Hosts file.
4.Update the virus definitions.
5.Run a full system scan and delete all the files detected as W32.HLLW.Gaobot.gen.
6.Reverse the changes that the worm made to the registry.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.