![]() |
|
#1
|
|||
|
|||
|
Hello all,
I was wondering if someone has any REMOVAL instructions for the W32.HLLW.Lioten virus (im not sure if its categorised as virus or trojan, so sorry if i put it in the wrong forum) which creates IRAQ_OIL.exe. Thnx so much for your input. |
|
#2
|
|||
|
|||
|
I don't have removal instructions but this decribes the worm and most importantly how to close the security hole that IO uses:
http://www.mynetwatchman.com/kb/security/articles/iraqiworm/
__________________
----- http://www.mynetwatchman.com The Internet "Neighborhood Watch" |
|
#3
|
||||
|
||||
|
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100 |
|
#4
|
|||
|
|||
|
Hey thnx for the support !
Did the online scan and it deleted most entries, except for this one : c:\WINNT\system32\sus\explorer.exe It was in use Is this related to that virus as well? thnx so much |
|
#5
|
||||
|
||||
|
It would not surprise me if you have Trojan Flood.BI.DR, which is doing the rounds, which adds explorer.exe
http://www.trendmicro.com/vinfo/viru...OJ_FLOOD.BI.DR Might pay you to do an online scan at trendmicro Added URL tags to fix link
__________________
All electrons used in the creation of this message were recycled. No electrons were harmed or mistreated in any manner. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|