943,712 Members | Top Members by Rank

Ad:
Aug 10th, 2004
0

w32.gaobot and variants still on network

Expand Post »
iv been at it for over a week now.trying to get w32.goabot and its variants
off the network. network is 3 servers, 35 workstations, unknown amount wireless laptops. im running NAV. and Fprot. i have operating sys nt4, 98, me, w2k, xp.. servers are nt4, linux, w2k.
the file it has created is wmon32.exe or wmon23.exe.
ive deleted all in registry and in windows dir.
the effects are at any givin time all the printers will empty thier trays printing garbage (a shockwave file between 125k to 135k)
under system32/spool/printers ill find 25 000 till 100 000 files in que to be printed !!!!
my final act to stop the hack was to disconnect the dsl from the network..!

any comments would be welcome
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Dragonling is offline Offline
1 posts
since Aug 2004
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Hijack Log (Had trojan dropper small)
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: #37049 Hjacker





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC