Computing.Net > Forums > Security and Virus > Can't get rid of W32.HLLW.Gaobot.ge

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can't get rid of W32.HLLW.Gaobot.ge

Reply to Message Icon

Name: Zachtje
Date: May 11, 2004 at 10:12:32 Pacific
OS: Win XP
CPU/Ram: P4, 2 GHz 512 Ram
Comment:

Hello!

I have a strange problem with a virus.
Norton detects this file "C:\Documents and Settings\All Users\Dokument\sysconf.exe"
and claims it's infected with W32.HLLW.Gaobot.gen.
First I visited symantecs homepage to get some info and tips for how to get rid of it.
I did everything they suggested(removal tool, manual removal, patches etc)
But it doesn't find anything and when I try to put the file in quarantine manually a new file appears.
I have tried every online virus scanner out there, but they claim I'm not infected.
When I check the registry I can't see anything similar to sysconf.exe either.
I'm pretty stuck now, I don't know what to do next.
Any help or input would be much appreciated!




Sponsored Link
Ads by Google

Response Number 1
Name: mr_x1988
Date: May 11, 2004 at 10:19:06 Pacific
Reply:

yes i have the same problem too, help here would also be much appreaciated!


0

Response Number 2
Name: Tufenuf
Date: May 11, 2004 at 11:23:21 Pacific
Reply:

Follow all instructions at the link below for your version of Windows including downloading & installing the patches. Pay special attention to the Hosts file instructions. I went thru this horror show last week and finally got rid of it.

WORM_AGOBOT.ER

Note: "WORM_AGOBOT.ER" is Trend Micro's name for the "W32.HLLW.GAOBOT.GEN" worm which is Norton's name for it.

HTH,
Tufenuf


0

Response Number 3
Name: aosclay
Date: May 11, 2004 at 11:39:43 Pacific
Reply:

Tufenuf said:

"I went thru this horror show last week and finally got rid of it."

amen, bro

Had similar problem on a client machine a couple of weeks ago. Took me hours to put together a fix. (similar problem, different variant). Had to play with the removal instructions to get it to work.

My successful fix fell somewhere between the article you linked them to and Symantec's article on the subject. I provide the link here only for more info. Tufenuf's linked article is good. (wish I'd seen that last week) :)

W32.HLLW.Gaobot.gen

Its a pain in the butt (thanks to all the variants), and not fixed by most tools, but it can be manually fixed in a jiffy once you get your ducks in line.

hey mr_x1988,

I read your other post...you have a slightly different variant I believe. But I already got into that with you if you saw it.

Hey, Tufenuf...

Glad yours is cleaned up (wasn't much fun was it?)

You gotta love this stuff guys

AOSCLAY
Monkies Can't Do This


0

Response Number 4
Name: Tufenuf
Date: May 11, 2004 at 11:49:00 Pacific
Reply:

aosclay, Yes, that worm disabled my Norton AV real time & e-mail scanning, blocked all Antivirus sites including AV Repair Tool sites, etc. The name of the file it created was "msawindows.exe". I finally stopped that process in Task Manager, downloaded the patch from Microsoft and installed it, then cleaned up the hosts (no extension) file in my C:\WINNT\System32\drivers\etc folder, then did a regedit and got rid of 2 references to that virus file, then deleted the "msawindows.exe" file to finally get rid of it for good.

Tufenuf


0

Response Number 5
Name: Zachtje
Date: May 11, 2004 at 12:07:49 Pacific
Reply:

Well, I have been through all that already.
My hosts file is ok as it is, I have no entries in the registry or any processes similar to the alleged virus file "sysconf.exe".
And all scans says I'm clean, but still the file keeps returning and Norton detects it as a virus.


0

Related Posts

See More



Response Number 6
Name: Tufenuf
Date: May 11, 2004 at 12:33:27 Pacific
Reply:

Zachtje, When you opened your hosts file in Notepad did you maximize the Notepad window. The first time I went and did this I didn't maximize the window and all of the blocked sites were farther down below the 127.0.0.1 localhost

Here's what a proper Windows XP hosts file should look like.
____________________________________________
Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
____________________________________________

Also make sure that you download & install the patches from Microsoft. The patch links are referenced at the Symantec link below.

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.gen.html

Tufenuf


0

Response Number 7
Name: Zachtje
Date: May 11, 2004 at 13:15:12 Pacific
Reply:

Yes, I have all of them installed and my hosts file is also ok.


0

Response Number 8
Name: aosclay
Date: May 11, 2004 at 14:46:22 Pacific
Reply:

hey Zachtje

your file "sysconf.exe" that Norton keeps choking on was not found in the registry?

hmmm...

have you attempted to delete it from the location Norton says it is in? Here are two glaring symptoms for the worm Norton says it is detecting:

Attempts to disable Anti-Virus software (your Norton Auto-Protect will not run)

Modifies hosts file to block security sites
(you cannot reach symantec, trendmirco, sophos, kaspersky, etc...etc...Because of this you cannot run live update).

You get the idea. Not all variants modify the hosts file. Are you having ANY symptoms (other than a file is being detected)?

Look in start up in MSCONFIG. If it is running at start-up you will see it. It's not that stealthy.

Here's one to throw you...my variant created an infected file named svchost.exe, just to be confusing. Kind of hard to spot it amongst all the other svchost.exe's running around...except this one was visible in start up...svchost.exe usually isn't.

If its not running at start-up, nor is it a running process, try and delete the file manually from its location...or quarantine it.

Take your pick and see what happens.

Its entirely possible that this is a false positive (though you don't really see many of those)

good luck!

AOSCLAY
Monkies Can't Do This


0

Response Number 9
Name: Tufenuf
Date: May 11, 2004 at 14:54:23 Pacific
Reply:

Zachtje, Did you turn off System Restore then restart your computer? Try doing that then run another virus scan in SAFE mode. If it comes up clean restart in Normal mode and turn on System Restore again.

Disabling or enabling Windows XP System Restore

Tufenuf


0

Response Number 10
Name: aosclay
Date: May 11, 2004 at 15:14:43 Pacific
Reply:

Sometimes even I forget to disable System Restore.... :(

and Zachtje,

I read back up to your original post...you have already tried a lot of this...sorry...I need a nap.

It if is Gaobot, and your file keeps coming back after you delete it or after you restart, look in the follow registry locations for your references to your infected file:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\RunServices

If something strange isn't in these locations (not necessarily your file name) then I don't know whats running your worm.

Take a peek. If you don't know what you see there, ask for help.

now...nap time.

AOSCLAY
Monkies Can't Do This


0

Response Number 11
Name: aosclay
Date: May 11, 2004 at 15:24:05 Pacific
Reply:

oh, hey, Zachtje,

Does the file come back after you delete it with the same name...or a random one?

The machine that I killed Gaobot on the other day was stacking randomly named exe's up in C:\ until I turned on the firewall. But the offending svchost.exe remained consistent (until it was killed).

Just curious...That family of worms is very large and new variants come out frequently. You might be unlucky and are suffering from a new variant, or an obscure one. Stranger things have happened.

good luck (now its nap time)

AOSCLAY
Monkies Can't Do This


0

Response Number 12
Name: aosclay
Date: May 11, 2004 at 15:28:43 Pacific
Reply:

sorry...forgot a registry key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

Look in there too.

AOSCLAY
Monkies Can't Do This


0

Response Number 13
Name: mr_x1988
Date: May 12, 2004 at 00:12:31 Pacific
Reply:

rite. now i am getting a bit p***ed off with this, ive done everything you say, turned my PC on this morning and norton picks it up, exactly the same file in the exact same place. i dont want to format this again because of reasons explained in my other post


0

Response Number 14
Name: murve
Date: May 12, 2004 at 06:28:30 Pacific
Reply:

hi folks,
i had the same problem with a clients computer.
the trojan disabled norton, screwed up the quarenteen file so that none of the files norton picked up showed. the clients computer was so slow and sluggish. the symantec gaobot fix did not pick up all the varients as there were so many varients of it. i did not want to stay there to long so I uninstalled norton, and installed a copy of hauri anti-virus.
in a nutshell, hauri cleaned up everything and also repaired all the infected files.
all the best,
murve


0

Response Number 15
Name: Zachtje
Date: May 12, 2004 at 08:03:17 Pacific
Reply:

When I delete or quarantine the infected file manually a new exact same file comes back in same location.
I can't find any references to the infected
file in the registry.
But just for pointing out once and for all only Norton detects this file to be a virus.
Other online scanners I have tried says it's clean.
Nevertheless it can't be good to have a file act like that.
I have done exactly what symantec suggest me to do at least 10 times, including scanning in safe mode with system restore off.
Maybe I should face the fact that I'm getting violated by someone and live with it.


0

Response Number 16
Name: mr_x1988
Date: May 12, 2004 at 08:28:36 Pacific
Reply:

murve said: "I uninstalled norton, and installed a copy of hauri anti-virus.
in a nutshell, hauri cleaned up everything and also repaired all the infected files."

just done that, picked the file up straight away, thanks i think its now gone :-)

however my printer has just started printing random symbols as i type this message and on the first bit of paper it sats:
THIS PROGRAM CANNOT BE RUN IN DOS MODE

any ideas now ???


0

Response Number 17
Name: aosclay
Date: May 12, 2004 at 10:06:17 Pacific
Reply:

hey mr_x1988 and Zachtje,

That sounds similar to symptoms of Bugbear (bugbear.b i believe). Some variants of Bugbear will cause your printer to generate page after page of a few lines of random symbols. It won't stop until you power off the printer.

Then you have to clean up the infection...

There's lots of sources of info for this bug, so I will not post links...I'm sure you can find it if your are interested.

OF COURSE THERE IS AN EQUAL CHANCE THAT YOUR NEW PROBLEM IS NOT A VIRUS AT ALL, BUT SOME OTHER BUG OR GLITCH.

After all, you did just install new software. You could check tech support for Hauri and see if its a known issue. (I am assuming you installed their product and this printer glitch began to happen). That's why you set restore points.

On the subject of Gaobot (the worm that started this this thread) if you guys haven't noticed in your reading, many new detection updates for that worm have been issued from the major security firms over the last few days. Hauri was one of them, twice it appears in the last two days.

THE MORAL OF THE STORY:

Do not rush to format your machines. If you cannot remove what's bugging you manually (this can be tough since many manual removal instructions are at best "non-specific") try and weather the storm.

New fixes come out everyday. Think of it like a ship at sea. Hunker down, shore up the ship and try and sail through the bad weather.

If you have a firewall...USE IT! If your operating system needs updates...DO THEM! If you have anti-virus software...UPDATE IT LIKE A LUNATIC! If your anti-virus software isn't working...TRY SOMETHING DIFFERENT! If you can't find and fix the source manually...BE CALM!

And if you can't afford to wait it out (sometimes you can't)...FORMAT and RELOAD.

There are a lot of ways to go about this, and its a "threat rich" environment out there. Sometimes it takes time to get enough info on new threats to help anyone.

And sometimes old threats are stubborn.

Sometimes the dog eats you (but not too often). If your machine is functional, and you feel you can contain the threat if not eliminate it, then don't be too quick to format it and start over.

More info will come in time. If you have new symptoms, or any additional info on your problems, it would be a great help in helping you. The variables are almost endless. You are both correct...This is not as easy as you might think.

Sometimes this stuff just flat ruins your day. But it can always be fixed...one way or another.

Let us know.

AOSCLAY
Monkies Can't Do This


0

Response Number 18
Name: mr_x1988
Date: May 12, 2004 at 10:42:26 Pacific
Reply:

ok got the printer one sorted, it was just an error on the printer so i think im completely virus free :-)


0

Response Number 19
Name: cavallopazzo
Date: May 14, 2004 at 02:45:23 Pacific
Reply:

I have the same problem too:

- Norton messagge: Virus Alert: "Documets and Settings\All users\sysconf.exe" --> quarantine
- Another one will produced after some times
- Alert is produced only if I'm in Internet without firewall
- Seems that virus try to force other users in my computer

So symantec procedure (or other procedures are not useful):
- I have all windows patch (for blaster, sasser... virus)
- file hosts is not modified
- sysconf.exe isn't in the system register (there is anything strange in register, no msblast.exe,...)
- I have no HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\RunServices directory in my system
- Symantec tool is not useful
- System32 has nothing strange

I think:
- Symantec founds gaobot, but it isn't gaobot
- Virus starts with windows but I don't now what process is...

I ask you:
- What of this process can be unreal?
MsPMPSPSv.exe
SVCHOST.exe (I have five of thiss processes)
SAVSCAN.exe
CTSVCCDA.exe
SAVSCAN.exe
SPOOLSV.exe
ccEvtMgr.exe
ccSetMgr.exe
LSASS.exe
CSRSS.exe
SMSS.exe
AGRSMMSG.EXE

excuse me for my bad english,
Alberto



0

Response Number 20
Name: cavallopazzo
Date: May 14, 2004 at 03:02:38 Pacific
Reply:

Errata corrige
Noton message is:
'Virus Alert
Documets and settings\AllUsers\Documents\sysconf.exe'

There is a prioblem but I'm italian an this directory in my computer doesn't exists...
Italian version is

Documets and settings\AllUsers\Documenti condivisi


0

Response Number 21
Name: aosclay
Date: May 14, 2004 at 06:44:12 Pacific
Reply:

Alberto,

you said:

"Alert is produced only if I'm in Internet without firewall"

Don't do that. Keep your firewall enabled. Gaobot is a worm that seeks out unprotected and vulnerable machines all on its own. You need to leave your firewall enabled.

more later

AOSCLAY
Monkies Can't Do This


0

Response Number 22
Name: Zachtje
Date: May 17, 2004 at 07:53:35 Pacific
Reply:

Hello boys!

I have some good news I think.
First I need to rectify myself, I seriously thought I had a virus that I could not get rid of.
But after trying Hauri antivirus which not found my alleged virus either I was determined it is not on my system 24/7.
So it was pretty clear it got in somehow.
I started to close down ports and services by the help of Steve Gibsons homepage http://grc.com/default.htm.
I went through almost anything I saw there.
And since then my system stays clean!
It is up to everyone to decide if you want to follow his advice and use his nifty programs.
But I do not regret that I did that.
I would also like to thank everyone here for help and suggestions, it is good to see that people at least trying to help people out.
I just wanted to say that, and do not trust anything on the net.
Keep up the suspicion and stay clean of viruses!


0

Response Number 23
Name: mailin2umesh
Date: May 27, 2004 at 06:06:22 Pacific
Reply:

hai

try bootin the system in dos
put up a dir search and delete the files manually

dir/s sysconf.exe

reboot since u hav deleted all the files there wud be no scope of the virus returin

bye

t.umesh
www.umeshsoft.tk


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can't get rid of W32.HLLW.Gaobot.ge

Can't get rid of RUN entry/Service www.computing.net/answers/security/cant-get-rid-of-run-entryservice/17409.html

Can't get rid of cws.searchx www.computing.net/answers/security/cant-get-rid-of-cwssearchx/12067.html

Can't get rid of onemoresearch.net www.computing.net/answers/security/cant-get-rid-of-onemoresearchnet/14181.html