• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

W32.HLLW.Gaobot.gen

Psycho18

Platinum Member
I now have another virus. Thanks to some fellow anandtech members, I got rid of the LSA SHELL virus. Now I have another one.........How do I get rid of the W32.HLLW.Gaobot.gen virus?Windows is all updated as well as norton. Help please.
 
Its pretty old. try to get the special patch that fixes it. Although when i had norton that did nothing. I switched to macfee and it fixed it in 2 seconds after installation.
 
1. Go here and look it up. Follow the instructions to clean the virus from your machine.

2. Get lastest MS security updates for your machine (and in the future keep it updated).

3. Make sure your running a good anti-virus software on your machine and keep the signatures updated on a regular basis (i.e. daily).
 
well i clean it off manually.
the systems i've seen it infect have this process/file running
called explored.exe (yours might be different, theres different variants of this thing)

boot into safe mode then
i just run regedit and find all instances of that and delete those keys.
then search hard drive for all instances of it and delete
then search for your hosts file and delete all the ones the virus added. usually only 127.0.0.1 localhost should be in there.

then depending on the nature of your network the following might be necessary to keep the virus from coming back in.
change your user account passwords to something not so simple.
disable any file sharing folders


reboot and its gone.
assuming your windows is patched up it shouldn't come back.
 
you can hit ctrl-alt-del
to get to the taskmanager.
see what processes are running and see whats taking up the cpu time.

how do u know u have the virus? does norton tell you which file is infected? thats probably what file u need to delete.

in regedit. press ctrl-f4 and type in that file name. when it stops delete the entry it finds (theres usually a single entry in
local_computer>software>microsoft>windows>currentversion>run
and
local_computer>software>microsoft>windows>currentversion>runservices
then theres services it creates usually in something like
local_computer>system>controlset001>Mpr
you should delete the Mpr folder.

press f3 until it can't find anymore of that file you're searching for.

for regular files just go to the start menu and use search
 
Sorry bud, did you check out Symantec's site on how to remove it?

Maybe you can send it to me, so I can analyse it, but my company's server will probably intercept it and delete it.
 
Back
Top