Gaobot is driving me mad

virus

Gaobot is driving me mad

Postby S2F6aGVscG5lZWRlZA » Tue, 23 Aug 2005 03:28:02 GMT

I have all secutiry updates & Norton loaded but I have got GAOBOT.SN 
somewhere on my PC.  I think it is in the temp files biy when I try to delete 
it is says I don't have the authority or the file is in use by another 
programme.

I've run Norton & windoes scans but they can't find this virus.  I';ve tried 
in safe mode & still can't find it   ANy suggestions?  

Re: Gaobot is driving me mad

Postby David H. Lipman » Tue, 23 Aug 2005 05:00:04 GMT

From: "Kazhelpneeded" < XXXX@XXXXX.COM >

| I have all secutiry updates & Norton loaded but I have got GAOBOT.SN
| somewhere on my PC.  I think it is in the temp files biy when I try to delete
| it is says I don't have the authority or the file is in use by another
| programme.
|
| I've run Norton & windoes scans but they can't find this virus.  I';ve tried
| in safe mode & still can't find it   ANy suggestions?


Download MULTI_AV.EXE from the URL --
 http://www.**--****.com/ 

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
 http://www.**--****.com/  Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE.  It will
simplify the process of using;  Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove
viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode.  It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * *     Please report back your results  * * *


-- 
Dave
 http://www.**--****.com/ 
 http://www.**--****.com/ 



Re: Gaobot is driving me mad

Postby a2F6aGVscG5lZWRlZA » Wed, 24 Aug 2005 04:16:09 GMT





I ran the sophos file in normal mode but I had to go out so don't know what 
it did.  Since re-booting I have not had any Norton or AVG virus 
notifications sayiong GAOBOT has been detected.  Am i safe to assume sophos 
deleted the virus automatically?

Re: Gaobot is driving me mad

Postby David H. Lipman » Wed, 24 Aug 2005 04:34:22 GMT

From: "kazhelpneeded" < XXXX@XXXXX.COM >


| I ran the sophos file in normal mode but I had to go out so don't know what
| it did.  Since re-booting I have not had any Norton or AVG virus
| notifications sayiong GAOBOT has been detected.  Am i safe to assume sophos
| deleted the virus automatically?

It should have created a scan report...

C:\AV-CLS\Sophos\ScanReport.txt

Please copy and paste the report into your reply.

-- 
Dave
 http://www.**--****.com/ 
 http://www.**--****.com/ 



Re: Gaobot is driving me mad

Postby Lance » Wed, 24 Aug 2005 04:43:05 GMT

This may be a new version of Gaobot:
 http://www.**--****.com/ 

Updated definitions are not available yet - not even via Intelligent 
Updater. From my past experience they'll probably get a new definition 
set sometime today. So keep an eye out on the Intelligent Updater site:
 http://www.**--****.com/ 

Lance
*****

Kazhelpneeded said the following on 8/21/2005 11:28 AM:

Re: Gaobot is driving me mad

Postby a2F6aGVscG5lZWRlZA » Wed, 24 Aug 2005 04:58:21 GMT


"David H. Lipman" wrote:

Here it is.
Version 3.96.0 [Win32/Intel]
Virus data version 3.96, August 2005
Includes detection for 108495 viruses, trojans and worms
Copyright (c) 1989-2005 Sophos Plc, www.sophos.com

System time 20:03:39, System date 21 August 2005
Command line qualifiers are: -f -di -all -remove -mime -mbr -noc -archive
-opt=ISCabinet

IDE directory is: c:\AV-CLS\Sophos

Using IDE file ablnk-ae.ide
Using IDE file agob-adh.ide
Using IDE file agobo-ta.ide
Using IDE file agobo-tf.ide
Using IDE file antix-a.ide
Using IDE file badmac-a.ide
Using IDE file bagdl-r.ide
Using IDE file bagle-bw.ide
Using IDE file bancb-dv.ide
Using IDE file bancb-dy.ide
Using IDE file bancb-eb.ide
Using IDE file bancb-eg.ide
Using IDE file bancb-em.ide
Using IDE file banco-dh.ide
Using IDE file banksn-b.ide
Using IDE file bardus-a.ide
Using IDE file bestofc.ide
Using IDE file bindfi-g.ide
Using IDE file bmdrop-a.ide
Using IDE file bobax-m.ide
Using IDE file bobax-n.ide
Using IDE file borobo-i.ide
Using IDE file brospy-a.ide
Using IDE file byteverm.ide
Using IDE file codbot-p.ide
Using IDE file codbtgen.ide
Using IDE file demotryb.ide
Using IDE file dldial-a.ide
Using IDE file dogbot-c.ide
Using IDE file downl-hi.ide
Using IDE file fakeal-d.ide
Using IDE file fan-a.ide
Using IDE file feutel-l.ide
Using IDE file fishnata.ide
Using IDE file forbt-fd.ide
Using IDE file forbt-fi.ide
Using IDE file france-t.ide
Using IDE file hagbar-a.ide
Using IDE file hidepr-h.ide
Using IDE file hogil-g.ide
Using IDE file hwbot-b.ide
Using IDE file iyus-n.ide
Using IDE file kalel-d.ide
Using IDE file kalel-e.ide
Using IDE file kassbo-h.ide
Using IDE file kelvi-af.ide
Using IDE file kelvi-ar.ide
Using IDE file kelvi-at.ide
Using IDE file kelviraq.ide
Using IDE file lebrea-e.ide
Using IDE file lebreata.ide
Using IDE file lebreatb.ide
Using IDE file lebreatc.ide
Using IDE file litebo-b.ide
Using IDE file litebota.ide
Using IDE file mdrop-f.ide
Using IDE file mitgl-ce.ide
Using IDE file myftu-h.ide
Using IDE file mytob-bv.ide
Using IDE file mytob-di.ide
Using IDE file mytob-dj.ide
Using IDE file mytob-dk.ide
Using IDE file mytob-dm.ide
Using IDE file mytob-dp.ide
Using IDE file mytob-ds.ide
Using IDE file mytob-du.ide
Using IDE file mytob-dw.ide
Using IDE file mytob-dx.ide
Using IDE file mytob-dy.ide
Using IDE file mytob-dz.ide
Using IDE file mytob-e.ide
Using IDE file mytob-ed.ide
Using IDE file mytob-ee.ide
Using IDE file mytob-hm.ide
Using IDE file mytob-hu.ide
Using IDE file mytob-in.ide
Using IDE file mytob-jm.ide
Using IDE file mytob-kk.ide
Using IDE file nailpola.ide
Using IDE file opanki-f.ide
Using IDE file oran-a.ide
Using IDE file pombero.ide
Using IDE file prorat-o.ide
Using IDE file pyfls-a.ide
Using IDE file rando-an.ide
Using IDE file randonao.ide
Using IDE file rbot-agw.ide
Using IDE file rbot-aht.ide
Using IDE file rbot-ahz.ide
Using IDE file rbot-aja.ide
Using IDE file rbot-ajo.ide
Using IDE file rbot-aka.ide
Using IDE file rbot-ala.ide
Using IDE file rbot-ali.ide
Using IDE file rbot-bwi.ide
Using IDE file rioti510.ide
Using IDE file rkprtfam.ide
Using IDE file rnwatcha.ide
Using IDE file sdbo-aal.ide
Using IDE file sdbo-aay.ide
Using IDE file sdbo-abv.ide
Using IDE file sdbot-zo.ide
Using IDE file sdbotaaz.ide
Using IDE file sdbotabi.ide
Using IDE file sdbotabq.ide
Using IDE file sdbotabr.ide
Using IDE file sdbotabs.ide
Using IDE fi

Re: Gaobot is driving me mad

Postby David H. Lipman » Wed, 24 Aug 2005 05:46:50 GMT

From: "kazhelpneeded" < XXXX@XXXXX.COM >

No sign of it found in the log.  Nothing else found either.

-- 
Dave
 http://www.**--****.com/ 
 http://www.**--****.com/ 




Return to virus

 

Who is online

Users browsing this forum: No registered users and 0 guest