Affected Operating Systems
Recovery Instructions:
Please follow the instructions for removing worms.
Please follow the instructions for removing worms.
Make a note of the files detected as W32/Oror-B.
Editing the registry
You will need to edit the following registry entries.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
and delete any references to any files you deleted.
Locate the HKEY_CLASSES_ROOT entry:
HKCR\exefile\shell\open\command\(default) = <path to worm> "%1" %*
delete only the path to the worm. Do not delete anything else.
Close the registry editor.
Editing Win.ini
At the taskbar, right-click Start and select Explore. Search for Win.ini in the Windows folder and open it in Notepad. In the [windows] section, search for the line
run=<path to worm>
Delete this line.
Reboot your computer.
After disinfection
You should also do the following: