November 17, 2008

How to remove computer worm W32.Gaut.A ?

Worm W32.Gaut.A spreads through removable devices, shared drives/shared folders and through instant messaging applications like Googletalk and Yahoo Messenger. This worm uses contact list in in Googletalk and Yahoo Messenger to send spam messages with a link to worm. After compromising the computer it may download more harmful files from the internet.It may create these files in connected,Shared,Local and removable drives autorun.ini, chrome.exe, C:\Windows\chrome.exe, New Folder.exe and add C:\WINDOWS\Tasks\At1.job as a scheduled job.

Spam Message send by W32.Gaut.A < Source: Symantec >
Now search your google in a HYBRID\DYNAMIC way...
Hey what are you doing Please test my new webcam using private application...
The wisest mind has something yet to learn...
Hey Please help me to test my new cam application...
ok
thats fine
Waiting for you, view my private cam via secured connection...
Happiness is not a destination. It is a method of life...
View my private cam via secured connection...
If you want truly to understand something, try to change it...
asl please
I am 23 Female, Delhi (India)
and you?

How to remove computer worm W32.Gaut.A ?
1. Perform standard procedure for virus removal
** Standard procedure for virus removal.
2. Delete these registry values added by the worm.
** How to edit registry ?


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Yahoo Messengger" = "C:\WINDOWS\system32\chrome.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\"shared" = "\New Folder.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NofolderOptions" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"

Related
Virus/Trojan Removal Tips And Tools: mywork.exe, msvcrt.ax, igfxtray.exe, Autorun.inf, auto2.pif
Remove "Autorun.inf" and "Antivirus 2008" using ESET NOD32 Antivirus
Vipre: Antivirus, Antispyware, Anti-Rootkit - Free Trial Download
Top 10 AntiVirus Software 2008
Download Kingsoft Internet Security 9 with 6 Months Free Trial
Panda's Antivirus, Firewall and Internet Security With 3 Months Free Service

No comments: