Today i was monitoring my Squid Log, I found one unusual URL in the log. and its requesting frequency is very high. I remotly accessed that pc and checked but i didn't find any browser opened there.Then i reinitialized that it is a bandwidth killing worm called Win32.Worm.AutoIt So Proxy administrators must check this link request in your log and find the Infected pcs.
Following are the link request coming from the infected PC.
http://www.yahoo.com/setting.xls
http://www.yahoo.com/setting.doc
http://yahoo.com/setting.xls
http://yahoo.com/setting.doc
Download autoit virus removal tool
http://www.softpedia.com/get/Antivirus/W32-AutoIt-Trojan-Cleaner.shtml
Find more details here
Yahoo setting.doc link request virus
Posted by
Albin Sebastian
July 27, 2009
Labels: Virus removel tools , worm
1 comments:
Nice collection Technology..
Post a Comment