|
What is W32.Holar and removal instructions
This worm uses Outlook to send out copies of itself as an attachment in email to all the recepients in the Outlook address book. This email contains no message and has a variable subject, which is also the filename of the attached malware copy. The email attachment uses the file extension, PIF.
W32.Holar manual removal: Delete registry values: Browse to the key:
'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices'
Delete the values 'ZaCker C:\%System%\' and 'MyLife C:\%System%\CmdServ.exe'
Delete subkeys:
'HKEY_LOCAL_MACHINE\Software\Microsoft\HolyWar'
'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HolyWar'
|