Skip to main content
Microsoft Security Intelligence
Published Nov 11, 2004 | Updated Apr 16, 2011


Detected by Microsoft Defender Antivirus

Aliases: W32.HLLW.Gaobot (Symantec) W32/Gaobot.worm (McAfee) WORM_AGOBOT (Trend Micro)


The Win32/Gaobot worm family spreads using different methods, depending on the variant. Some variants spread to machines with weak passwords. Others exploit vulnerabilities to infect machines. Once a machine is infected, the worm connects to an IRC server to receive commands.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
For more information on antivirus software, see
Follow us