Discovered: June 23, 2001
Updated: February 13, 2007 11:54:03 AM
Type: Trojan Horse, Worm
Run LiveUpdate to make sure that you have the most recent virus definitions.
- Start Norton AntiVirus (NAV), and run a full system scan, making sure that NAV is set to scan all files.
- Delete any files detected as W32.Leave.worm.
- If you delete any of the system files that are mentioned in the list in the previous section, you should restore them from the Windows installation CD.
To edit the registry:
CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry can result in permanent data loss or corrupted files. Please make sure you modify only the keys that are specified in this document. For more information about how to back up the registry, please read
How to back up the Windows registry before proceeding with the following steps. If you are concerned that you cannot follow these steps correctly, then please do not proceed. Consult a qualified computer technician for more information.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to and select the following key:
HKEY_CURRENT_USER\Software\Mirabilis\
ICQ\Agent\Apps
- In the right pane, look for and select the value
icqrun C:\WINDOWS\regsv.exe
- Press Delete, and then click Yes to confirm.
- Navigate to and select the following key:
HKEY_LOCAL_MACHINE\Software\Classes\Scandisk
- This entire subkey has been created by the worm and can be deleted. Insure that you have selected the Scandisk key and that it is highlighted.
- Press Delete, and then click Yes to confirm.
- Follow the instructions for your version of Windows
- Windows NT/2000
- Navigate to and select the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
- In the right pane, look for and select the value
regsv C:\WINDOWS\regsv.exe
- Press Delete, and then click Yes to confirm.
- Windows 9x/ME
- Navigate to and select the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\RunServices
- In the right pane, look for and select the value
regsv C:\WINDOWS\regsv.exe
- Press Delete, and then click Yes to confirm.
- Exit the registry editor.
Writeup By: JP Duan