Home Malware Programs Trojans W32.HLLW.Gaobot.AO

W32.HLLW.Gaobot.AO

Posted: March 28, 2006

Threat Metric

Threat Level: 9/10
Infected PCs: 12
First Seen: July 24, 2009
Last Seen: January 20, 2022
OS(es) Affected: Windows

W32.HLLW.Gaobot.AO is a minor variant of W32.HLLW.Gaobot.AE. It attempts to spread to network shares that have weak passwords and allows attackers to access an infected PC through IRC.

W32.HLLW.Gaobot.AO

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



csrrs.exe File name: csrrs.exe
Size: 155.64 KB (155648 bytes)
MD5: d9717d758ad5deb5a535a6a6a10b97e7
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
regsvc32.exe File name: regsvc32.exe
Size: 176.12 KB (176128 bytes)
MD5: 6aabc6c422fb3ce4a7bee24517c58379
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Registry Modifications

The following newly produced Registry Values are:

Run keyssysclean
Loading...