Affected Operating Systems
Recovery Instructions:
Please follow the instructions for removing worms.
Please read the instructions for removing worms.
Make a note of the files detected as W32/Oror-L.
Editing the registry
You will need to edit the following registry entries.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LoadProfile = Cmdtrid16.exe powrprof.dll,LoadCurrentPwrScheme
and delete it if it exists.
Check the other entries in
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
and delete any references to any of the other files you deleted.
Locate the HKEY_CLASSES_ROOT entry:
HKCR\exefile\shell\open\command\(default) = <path to worm> "%1" %*
delete only the path to the worm. Do not delete anything else.
Close the registry editor.
Editing Win.ini
At the taskbar, right-click Start and select Explore. Search for Win.ini in the Windows folder and open it in Notepad. In the [windows] section, search for the line
run=<path to worm>
Delete this line.
Reboot your computer.
After disinfection
You should also do the following:
- Replace the mIRC files MIRC.INI and REMOTE.INI from backups or from a fresh copy
- Users of Microsoft Outlook and Outlook Express should install this patch: http://www.microsoft.com/technet/security/bulletin/MS01-027.asp
- Check that your anti-virus software is working and reinstall it if necessary
- Check other computers on your network for copies of the worm.