|W32.HLLW.Gaobot.FQ is a variant of W32.HLLW.Gaobot.BF.
It attempts to spread to network shares that have weak passwords and allows attackers to access an infected computer through an IRC channel.
Copies itself as %System%\Sysinfo.exe and %System%\Winhlpp32.exe.
Adds the value:
to the registry keys:
Performs Distributed Denial of Service (DDoS) attacks against targeted systems. The IP addresses of the targets are randomly calculated.
Steals the CD keys/Product ID, ends some processes associated with antivirus and firewall software, attemps to kill some processes associated with other worms.
Listens on randomly calculated ports, and waits for other computers to download the worm.
Remove it from startup by using antivirus (also check How To Remove section)Startup Optimizer.