Wednesday, October 13, 2004
Annoying Worm
To KrUsH KiLL n DeStroY a FuNNy ViRuS...
Hey folks, guess some of u are having problems with the "funny" virus or W32.Annoying.Worm. So here's a little something i've gotten from BX's blog to help.
1. Disabling System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.
2. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
3. Restarting the computer in Safe mode or ending the malicious process
Windows 95/98/Me
Shut down the computer and turn off the power. Wait for at least 30 seconds, and then restart the computer in Safe mode. For instructions, read the document, "How to start the computer in Safe Mode."
Windows NT/2000/XP
To end the malicious process:
1. Press Ctrl+Alt+Delete once.
2. Click Task Manager.
3. Click the Processes tab.
4. Double-click the Image Name column header to alphabetically sort the processes.
5. Scroll through the list and look for MsgSprd.
6. If you find the file, click it, and then click End Process.
7. Exit the Task Manager.
4. Scanning for and deleting the infected files
1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
* For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
* For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files."
2. Run a full system scan.
3. If any files are detected as infected with W32.Annoying.Worm, click Delete.
5. Reversing the changes made to the registry
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
1. Click Start, and then click Run. (The Run dialog box appears.)
2. Type regedit
Then click OK. (The Registry Editor opens.)
3. Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
4. In the right pane, delete the value:"MSN Messenger"="%download location%\PIC1324.exe"
5. Exit the Registry Editor.
6. Restart the computer back into Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."
--- posted @ 10:20 AM ---