March 30, 2008

W32.Launcer.A - Worm + Removal tips

W32.Launcer.A is a worm that spreads by copying itself to removable drives and displays fake warning on a pop-up window.

Warning similar to this one shown below.
"You are using a pirated(illegal) version of Microsoft.You may encounter severe Penalties for this kind of action. Please Register your copy at www.microsoft.com. Would you like to Register your copy of windows Now?"

Systems Affected: All Windows

How to remove worm W32.Launcer.A ?

1. Disable System Restore (Windows Me/XP)

If you are using Windows XP or Windows ME, You must disable or turn off System Restore before Virus scan because the _Restore folder is protected by default. Antivirus cannot remove virus or any malicious files inside _Restore folder. Windows prevents outside programs,including antivirus programs, from modifying System Restore. The System Restore feature is not designed to detect or scan for virus infections or virus activity.
How to disable System Restore ?

2. Update computer anti virus software with latest virus definitions.

Almost all anti virus software have an latest virus definition update feature. Latest Virus definition contains details of information related to latest virus.

3. Backup system registry.

You must backup System registry before editing the registry because it contains information and settings for all the hardware, operating system software, most non-operating system software, users, preferences of the PC, etc. Any wrong changes will lead you to more problems.
How to backup Windows Registry ?

4. Restart your system in safe-mode.

An operating system in safe mode will have reduced functionality, but the task of isolating problems is easier because many non-core components are disabled (turned off). An installation that will only boot into its safe mode typically has a major problem, such as disk corruption or the installation of poorly configured software that prevents the operating system from successfully booting into its normal operating mode.
How to start your system in safe-mode ?

5. Run a full system virus scan using your updated anti virus program.


Remove these files if exists ..


C:\WINDOWS\system\svc.exe
C:\WINDOWS\system\Autorun.inf

It also creates the following files on all removable drives every five minutes remove these files also ..

%DriveLetter%\svc.exe
%DriveLetter%\autorun.inf

Source: Symantec

No comments: