Event ID - 9900

Port No9900
Service NameW32.HLLW.Gaobot
RFC Doc0
ProtocolTCP
DescriptionW32.HLLW.Gaobot is a worm that copies itself as %system%\Sysldr32.exe.
Reference LinkPort Number:9900 Service Name:W32.HLLW.Gaobot Port:TCP
AttackAccording to Symantec

Resolution:
NOTE: These instructions are for all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
1.Update the virus definitions.
2.Run a full system scan, and delete all files that are detected as W32.HLLW.Gaobot.
3.Delete the value:
"Config Loader"="%system%\sysldr32.exe"
from the registry keys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
4.Delete the value:
"[Default]"="regfile"
from the registry key:
HKEY_CLASSES_ROOT\.Key

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.