Jump to content

Recommended Posts

Posted

Hello Everyone,

 

Thought I would let you know, after a Grewaling Past 2 Days that we have detected this Virus on our servers (Troj/DwnLdr-HKW) it killed the SVCHost.exe, which then killed off several services including, Automatic Updates, Server, Workstation, Computer Browser and the Event Logger Services.

 

As you can imagine this caused no end of problems, and SOPHOS only identified the Virus at 4am(ish).

 

Please be aware, as it creates random services which run C:\Windows\System32\svchost.exe -k netsvcs

 

but when you look in the Registry, they are using random DLL's, which you then need to disable then stop the service, then delete the DLL's and Registry Settings.

 

Hope this helps,

 

Gaz

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...