1. /
  2. Security Response/
  3. W32.HLLW.Gaobot.gen


Risk Level 2: Low

November 21, 2003
February 13, 2007 12:14:09 PM
Also Known As:
W32/Gaobot.worm.gen [McAfee], Backdoor.Agobot [Kaspersky], Phatbot
Systems Affected:
Windows 2000, Windows NT, Windows XP

W32.HLLW.Gaobot.gen is a detection for a large family of worms, which propagate themselves using multiple vulnerabilities including:
Most variants are packed with a run-time packer, such as UPX.

The W32.HLLW.Gaobot.gen removal tool will remove many but not all the variants that are detected as W32.HLLW.Gaobot.gen.

Note: Virus definitions, version 60227t (extended version 2/27/2004 rev. 20) and later, detect the threat known as Phatbot as W32.HLLW.Gaobot.gen.

Antivirus Protection Dates

  • Initial Rapid Release version November 24, 2003
  • Latest Rapid Release version May 3, 2015 revision 038
  • Initial Daily Certified version November 24, 2003 revision 036
  • Latest Daily Certified version May 4, 2015 revision 003
  • Initial Weekly Certified release date November 26, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Medium
  • Number of Infections: More than 1000
  • Number of Sites: More than 10
  • Geographical Distribution: Medium
  • Threat Containment: Easy
  • Removal: Moderate


  • Damage Level: Medium


  • Distribution Level: Medium
Note: On May 14, 2015, modifications will be made to the threat write-ups to streamline the content. The Threat Assessment section will no longer be published as this section is no longer relevant to today's threat landscape. The Risk Level will continue to be the main threat risk assessment indicator.
Writeup By: Heather Shannon

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report