The virus outbreak that occurred on February 14 appears to be a form of
the Gaobot virus. The virus spreads because of weak user
passwords or non-updated Microsoft Windows computers. To learn how
to keep your computer up-to-date, check out our section on
Updating Windows.To remove
Gaobot from your computer, you will need to first download the latest
virus definitions for your anti-virus program. If you have a copy
of Symantec Antivirus that is distributed by NC State, you can
download
an executable file to update your virus definitions.
Once you have done that, follow these instructions:
- Make sure that you have current virus definitions for your
Anti-virus program.
- Restart your computer into "Safe Mode". To do this, restart
your computer. Then, before it starts to boot into Windows,
press the F8 key. This will take you to a text-based menu where
you can select "Safe Mode" as an option.
- Run Symantec Antivirus. You will need to find the actual
"VPC32.exe" file. You can find it using the Windows Search
utility, or navigating to the folder on your hard drive.
Usually, the folder will be located at: C:\Program
Files\Symantec\SAV8\
- Ensure that you have the most up-to-date virus definitions by
looking at the date in your main SAV window:

- If you definitions are up-to-date, select "Scan Computer" from the
main menu in the SAV window:

- Select your hard drive from the menu (usually this is your C
drive):

- Press the "Scan" button and allow SAV to scan your computer.
This may take a very long time.

- If Gaobot is found on your computer, SAV will clean it off.
After you have scanned one time and it has found the virus, you will
need to scan a second time to make sure that the scan does not find
any more instances of viruses on your computer.
- There also seems to be instances of a Trojan Horse virus that gets installed when Gaobot infects a machine. To ensure you are not infected with a Trojan Horse virus, scan you computer using Spybot Search & Destroy. Instructions for running this tool can be found here.
- Now that your computer is virus and trojan free, you should take steps to insure it does not become infected again. The first step is to make sure your computer is up-to-date.
- Finally, you should make sure that all of your accounts have passwords.
Additional information about this virus is available from Symantec's
Security Response website.
|