Aliases
-
Backdoor.Agobot.jk
-
W32.HLLW.Gaobot.gen
Affected Operating Systems
Recovery Instructions:
Please follow the instructions for removing worms.
Check your administrator passwords and review network security.
Change any data that may have become compromised.
Renaming the registry editor
- Using Windows explorer, browse to the Windows folder (usually C:\Windows or C:\Winnt) right-click Regedit.exe and make a copy of it.
- Rename the copy of Regedit.exe to Regedit.com.
- At the taskbar, click Start|Run. Type 'Regedit.com' and press Return. The registry editor opens.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Symantec Security Routine Addon = navpaw.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Symantec Security Routine Addon = navpaw.exe
and delete them if they exist.
Close the registry editor.