Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -4.3.20/4.0.4399
 VirusScan Enterprise 8.0i - Windows NT/2000/XP/2003
 VirusScan Enterprise 7.1 - Windows NT/2000/XP/2003
 Version 4.5.1 (install Service Pack 1) - Windows 9x/ME
 Virex (OS X) Engine/Def - 7.2(v1.1)/041013
 Virex (OS 9.x) Engine/Def - 6.2/041001
 Linux & Solaris Engine/Dat - 4.3.20/4.0.4399
 Symantec Antivirus - 9.0
 Ad-aware - 6.0
 Clean Boot 1.0
 Stinger v2.4.0 virus removal tool (Updated 9/28/04, 3:22am)
 Microsoft Patch Library
Current server downloads:
 VirusScan Enterprise 7.1
 NetShield NetWare - 4.6.2
 NetShield NetWare Engine Update - 4.3.20
 ePO agent for NetWare
 Sybari Antigen - 528/966
 TrendMicro - 6.810/200
 ScanMail eManager - 3.0
 Microsoft Patch Library

Information
 Configuration Tips
 VirusScan FAQs
 Ad-aware FAQs
 Central EMail Status
 VirusScan Instructions
 Additional Resources
 ePO 3.0/VirusScan 7.0 Presentation

Archives
 List of Viruses

Virus Alerts

W32/Gaobot.gen.H (AKA W32.GaoBot.AFJ) updated 5/5/2003, 5:00 PM

In addition to the Sasser worm, there is another worm that has been detected in the wild and at NIH that spreads by exploiting a Microsoft Windows vulnerability [MS04-011 vulnerability (CAN-2003-0533)].

This worm spreads with the file name: Microsoft.exe

Important information from Microsoft regarding this patch is at http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

A side effect of this worm is that it may cause the LSASS.exe process to crash which leads to the machine rebooting.

You may also see increased port activity on ports 1025 and 7000 from machines infected with this worm.

For ISSO's and Admins, Retina scanner to search for machines not patched for MS04-011 is available here

NAI has released superdat 4358 and later to detect and remove Gaobot.

Symantec detects this worm with definitions dated 5/2/2003 rev 38 and later. These definitions are available through the LiveUpdate feature of Symantec Antivirus.

Gaobot.gen.H renders Virusscan inoperable and requires that Virusscan be reinstalled. Note you will need the latest superdat for the reinstallation.

Gaobot.gen.H removal instructions:

  1. Kill the Microsoft.exe process
  2. Delete Microsoft.exe from c:\windows\system32
  3. Remove from the registry: HKLM\Software\Microsoft\windows\currentversion\run, look for the Microsoft.exe key and HKLM\Software\Microsoft\windows\currentversion\runservice, look for Microsoft Update
  4. Uninstall VirusScan.
  5. Reboot
  6. Install VirusScan
  7. Run the latest superdat
  8. Run a systems scan to scan all files.

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact TASC for assistance or call
301.59.Go.CIT (V) 301.496.8294 (TDD)

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -