|
Run all the 5 steps.
Symantec had identified W32/Alcra-B
So I ran Resolve version 1.07 from Sophos
It identified the worm in following files and deleted these files.
Windows\system32\ping.com
Windows\system32\tracert.com
Windows\system32\tasklist.com
Windows\system32\taskkill.com
Windows\system32\regedit.com
Symantec also had identified the same bug in winupdate.exe file. I am not sure I have entirely cleared the bug.
Now the registry apears to be working. Should I run hijackthis and post the log to find that out? Please advice.
|