REMOVAL for
Windows
XP ONLY
- Close all programs and be sure you are logged on to your system with
administrative rights.
-
disable System Restore
(Instructions below).
- Update
Symantec or Norton virus definitions
now.
- Shut down the computer and
turn off the power and
wait at least 30 seconds.
- Disconnect your computer from the
network and the Internet, if you are not already blocked.
- Restart the computer in SAFE MODE
(See instructions).
- Run a scan with Symantec Antivirus
- If any files are detected as infected with
W32.Explet.A@mm, click Delete.
- Delete the added value from the Windows Registry
The next steps if done incorrectly may cause your
computer to become UNUSABLE.
PROCEED WITH CAUTION. If you are a student, service repair
information is available in CH227.
Backup the Windows Registry.
Note: The Backup utility
is not included in a default installation of
Windows XP Home Edition.
- Click Start
- Click Run
- Type regedit
- Click OK
|
 |
 |
- Navigate to the folder:
HKEY_LOCAL_MACHINE\SOFTWARE\
Microsoft\Windows\
CurrentVersion\Run
|
- In the right pane,
delete the value: "NvClipRsv"="<path to
the worm>"
- Exit the Registry Editor.
|
- Delete added lines from the Windows Hosts File.
- Click Start, and then click Search.
- Click All files and folders.
- In the "All or part of the file name" box, type:
hosts
- Verify that "Look in" is set to "Local Hard Drives" or
to (C:).
- Click "More advanced options."
- Check "Search system folders."
- Check "Search subfolders."
- Click Search.
- Click Find Now or Search Now
- For each Hosts file that you find,
right-click the file, and then click "Open With."
- Deselect the "Always use this
program to open this program" check box.
- Scroll through the list of programs and double-click
Notepad.
- When the file opens, delete all the entries
in the Hosts file except for the following
line:
127.0.0.1 localhost
- If this line does not exist, add it to the file.
- Close Notepad and save your changes when prompted.
- Run a full antivirus scan again to ensure
that the system is clean.
- If you are running Windows XP, next re-enable
System Restore (Instructions below).
- Reconnect to the network and
restart your computer.
- Be sure you have installed all
Critical Updates to your
operating system.
(If you are on ResNet, do this after you
been unblocked).
ResNet students who have been disconnected will have to
call
the ResNet Help Line (372-6566) to be reconnected to the network.
It may take some time to be confirmed clean and reconnected.
Remember that
Symantec Antivirus is
available for download to enrolled TTU students.
|