Discovered: December 14, 1999
Updated: May 1, 2007 11:27:03 AM
Also Known As: I- Worm.NewApt.a [Kaspersky], W32/NewApt.worm.gen@MM [McAfee], WORM_NEWAPT.A [Trend], W32/NewApt-A [Sophos], Win32.NewApt.Family [Computer Associates]
Type: Worm
Infection Length: 69,632 bytes
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000
Follow the instructions in each section.
Remove files in Safe mode Please follow these steps to remove the files that the worm has placed on the computer:
- Restart the computer in Safe mode.
- Windows 95
- Exit all programs, and then shut down the computer.
- Turn off the power and wait 30 seconds. You must turn off the power to remove the virus from memory. Do not use the reset button.
- When you see the "Starting Windows 95" message, press F8.
- Type the number for Safe mode, then press Enter.
- Windows 98
- Click Start, and click Run.
- Type msconfig and then Click OK. The System Configuration Utility dialog box appears.
- Click the General tab, and click Advanced.
- Check Enable Startup Menu, click OK, and then OK again.
- Exit all programs, and shut down the computer.
- Turn off the power, and wait 30 seconds. You must turn off the power to remove the virus from memory. Do not use the reset button.
- Immediately press and hold down the Ctrl key.
- Type the number for Safe mode, and then press Enter.
- Click Start, point to Find, and click Files or Folders.
- Make sure that Look In points to the drive on which your Temp folder is located. In most cases, this is the drive C.
- In the Named box, type the following and then press Enter:
*.tmp
- In the Results pane, select all of the displayed files and then press Delete. Click Yes to confirm.
NOTE: If many files have been found, select them all by clicking the File menu and then clicking Select All.
- Close the Find All Files window.
- Empty the Recycle Bin.
Edit the registry Please follow these steps to undo the changes that the worm has made to the Windows registry:
CAUTION: We strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified. Please see
How to back up the Windows registry, before proceeding.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- In the right pane, locate and select the following value:
tpawen
- Press Delete, and then click Yes to confirm.
- Exit the Registry Editor.
Restart and scan - Restart the computer and allow it to start Windows. This will likely take longer than it normally would.
- Start Norton AntiVirus (NAV), and run LiveUpdate to make sure that you have the most recent definitions.
- Run a full system scan and delete any files that NAV finds are infected.