G
George Neuner
Hi all,
I got hit with what looks like W32.HLLW.Moega. It places an
executable named "wupdated.exe" in the root directory and in
Windows\System32 and installed itself as a service.
I noticed it when web access slowed to a crawl. The log in ZoneAlarm
reported hundreds of incoming connections originating from the Netbios
port (139) of non-existent computers on my home LAN. I'm not sure why
ZoneAlarm was allowing outgoing connections from it ... I'm certain I
didn't authorize it but there are other people here so maybe someone
did. The virus appears in ZoneAlarm as "Generic Host Process for
Win32 Services" with an icon that looks like "Windows Update".
I checked AVG's scan logs and it shows that the virus executable has
been there for about 2 days but, for some reason, AVG has the virus
executable marked OK - as in no infection.
According to some of the security pages I've read, this virus has been
around since 2003. I am really unhappy that the latest AVG didn't
catch it.
George
I got hit with what looks like W32.HLLW.Moega. It places an
executable named "wupdated.exe" in the root directory and in
Windows\System32 and installed itself as a service.
I noticed it when web access slowed to a crawl. The log in ZoneAlarm
reported hundreds of incoming connections originating from the Netbios
port (139) of non-existent computers on my home LAN. I'm not sure why
ZoneAlarm was allowing outgoing connections from it ... I'm certain I
didn't authorize it but there are other people here so maybe someone
did. The virus appears in ZoneAlarm as "Generic Host Process for
Win32 Services" with an icon that looks like "Windows Update".
I checked AVG's scan logs and it shows that the virus executable has
been there for about 2 days but, for some reason, AVG has the virus
executable marked OK - as in no infection.
According to some of the security pages I've read, this virus has been
around since 2003. I am really unhappy that the latest AVG didn't
catch it.
George