Computing.Net > Forums > Security and Virus > Agobot.6.AX and W.32Gaobot.gen

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Agobot.6.AX and W.32Gaobot.gen

Reply to Message Icon

Name: mr_x1988
Date: May 11, 2004 at 10:20:17 Pacific
OS: Windows XP professional
CPU/Ram: AMD XP2000+ / 512mb DDR
Comment:

i have 1 virus i think, either that or it is 2 with the same file name.

AVG picks the virus up as Worm/Agobot.6.AX
Norton picks it up as W.32 Gaobot.gen
is it the same virus?

both of them have been picked up on:
C:\Documents and Settings\All Users\Documents\wmpupdate.exe

i have tried the Gaobot removal tool from norton and it doesnt work, even in safe mode. not too happy because i formatted my computer about 3 weeks ago because of this virus (the gaobot) and now it has returned. i am using windows XP professional and have a half full 40gig hard drive which has coursework on it (it is backed up) and it needs to be done as soon as possible! at the moment i can barely work my way around without the annoying popups from norton and AVG telling me i have a virus.

please help!

Chris




Sponsored Link
Ads by Google

Response Number 1
Name: aosclay
Date: May 11, 2004 at 11:28:14 Pacific
Reply:

Do you have a firewall enabled?

Even XPs will do. It will help you.

I had a similar problem on a client machine a couple of weeks ago...took some serious hunting through the registry to track down and kill the offending bug.

The manual removal instructions in this article were a handy guide in helping me hunt down and kill said worm manually. W32.HLLW.Gaobot.gen

In my case, NAV did not detect it, the Symantec removal tool did not remove it, and Stinger would only clear out the hosts file modification. But all the signs and symptoms of Gaobot.gen were there.

Working "creatively" with the manual removal instructions in the article, I was able to kill it.

Remember the offending file (wmpupdate.exe) when working through the manual removal.

I bet you will also see it in MSCONFIG. If you do not have a firewall enabled, random exe's may be appearing in C:\. Also, you will probably not be able to visit many security sites (a hosts file modification caused by the worm blocks them).

Manual removals can be tough and require a bit of creative thinking. Give it a try and ask for more help if you need it. I could ramble on forever, but that's what the link to the article is for.

Give it try. It will be irritating, but you can fix it.

good luck. post for more help if you need it.

AOSCLAY
Monkies Can't Do This


0

Response Number 2
Name: Tufenuf
Date: May 11, 2004 at 11:34:55 Pacific
Reply:

In addition to AOSCLAY's excellent advice check out my Response in the thread at the link below. You must stop the process on the wmpupdate.exe file in Tak Manager (Ctrl/Alt/Del) then download the patch from Microsoft then follow the instructions and you will be able to get rid of it. I had it last week and it drove me nuts till I finally got rid of it.

http://www.computing.net/security/wwwboard/forum/11688.html

Tufenuf


0

Response Number 3
Name: aosclay
Date: May 11, 2004 at 11:43:24 Pacific
Reply:

hey TUFENUF,

Thread tag! You're it!

if we keep bouncing off each other like this, we just might fix something between the two of us.

LOL.

Thanks for the assist bud. I knew I left something out. That's what happens when I hurry. Fingers type, but brain falls behind. (too many variants...) LOL

I'll check back later.

AOSCLAY
Monkies Can't Do This


0

Response Number 4
Name: mr_x1988
Date: May 11, 2004 at 14:38:23 Pacific
Reply:

ive installed those windows updates, just waitin to see if it returns, ill keep you posted


0

Response Number 5
Name: mr_x1988
Date: May 12, 2004 at 00:18:06 Pacific
Reply:

refer to this post for my last message :@

http://www.computing.net/security/wwwboard/forum/11688.html

and no its still there, thanks for attempting to help though


0

Related Posts

See More



Response Number 6
Name: darkwin duck
Date: May 15, 2004 at 10:01:51 Pacific
Reply:

The GAOBOT virus appends all anti virus related websites such as symantec.com!So what you need to do is this!!
Open Start > Search
In the search field type "hosts" Be sure the function only scans you're C drive! When a file called HOSTS appears open it!choose notepad to open it but make sure to uncheck the option to open this file with the notepad extension in the future! When it opens scroll down and you will see a listing of sites that will be appended delete all of them except for the localhost entry *127.0.0.1 localhost* this must stay unchanged
Now you can search symantec.com or other anti virus sites to find a fixtool or someting like that!!


Laten we lekker ruig gaan doen


0

Response Number 7
Name: aosclay
Date: May 18, 2004 at 09:54:06 Pacific
Reply:

an important note:

not ALL variants of Gaotbot modifies the hosts file in this way. A specific few do. Until the worm is removed (and no longer running at startup) this modification to the hosts file will keep coming back and you'll be back in the same boat.

Remember, until Gaobot is terminated, your hosts file modification will return after you reboot.

So, if you fix your hosts file manually in an attempt to get access to security sites, get on and get what you need before you reboot or you will have to do it all over again.

AOSCLAY
Monkies Can't Do This


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Agobot.6.AX and W.32Gaobot.gen

whataboutadog and backdoor trojan www.computing.net/answers/security/whataboutadog-and-backdoor-trojan/21859.html

win32/zonebac won't go away www.computing.net/answers/security/win32zonebac-wont-go-away/21772.html

help! virus, spyware, something! www.computing.net/answers/security/help-virus-spyware-something/21770.html