Help - Search - Members - Calendar
Full Version: How to get rid of the Gaobot!inf virus
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
kaosrules
The pc was infected with three (3) viruses
1. Sasser.exe Removed!
2. Welchia.B Worm Removed!
3. W32.Gaobot!inf---This one is the only one that is not being removed no matter what removal tool or process is taken.

Will this work ?http://computercops.biz/postt38030.html&qu...postt38030.html

QUOTE
I worked on a friend's computer for several hours with this variation of the gaobot virus (!inf).
I removed from the registry the entry for Microsoft (or maybe it was Windows?) Update referencing win32.exe in the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
And also delete the file win32.exe in your windows\system32 folder. Odd as it sounds, it is the culprit. Insure you do have a backup of your registry. You may have to delete the file in Safe Mode (I didn't have to). I did notice that the file got cantankerous as I was trying to remove it.. removed first from the registry.. .you then get a window period to remove the file from c:\windows\system32 (path may be slightly different). I also had to manually edit the registry to remove Norton Anti Virus, so I could re-install it. Otherwise it would not enable in the System Tray. Also, I downloaded the Norton AntiVirus definitions ahead of time from a different computer and installed them on the affected computer. (Actually I did this step first, and downloaded Windows Critical Updates and installed as well.)


Does any one have any ideas or a process that worked for them or someone they know ?
Donna
Hi,

It is sometimes normal that an antivirus or removal tool cannot remove the infected file IF the infected file is located in Restore folder. The solution is to disable System Restore.

In case the infected file is located in other location other than System Restore folder and If the removal tools will not succeed in removing that W32.Gaobot!inf, the solution is manually remove it.

There are times, it can't be removed because the processes is running. We should end the process first prior fixing (using removal tools or manual removal)

To answer your question on whether it will work.. please try to disable System REstore if it is enabled. End the processes. Manually remove Or use the removal tool in safe mode.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.