Aliases
-
p2p-worm.win32.mareta
-
w32/dabyrev
Characteristics
-
Installs itself in the registry
Affected Operating Systems
Recovery Instructions:
Please follow the instructions for disinfecting pe viruses.
It is possible to manually disinfect a system by:
- terminating all infected processes,
- replacing any infected executables with clean backups,
- deleting the hidden system file C:\MSprotect.exe
- and deleting its start key from the registry.
- any other hidden system executables of file size 43008 bytes detected as W32/Dabyrev-A are redundant copies of the virus. These can, and should, be deleted.