W32.Gaobot family of worms

Discovery began in October 2002

The W32.Gaobot family of network worms began to surface in October 2002 and several variants have been released since that time. These worms propogate using multiple vulnerabilities including:

Most variants of Gaobot attempt to spread through network shares via weak passwords. It also allows access to an infected computer through IRC channels. Most variants try to prevent access to known anti-virus websites, stop anti-virus software from running on your computer, and steal information from your computer such as passwords, e-mail addresses, and files.


You can find more information and removal instructions as well as tools for each variant from Symantec from the following links: