W32.BlueCode.Worm - Removal

Risk Level 2: Low

Printer Friendly Page

Discovered: September 7, 2001
Updated: February 13, 2007 11:37:14 AM
Also Known As: W32.CodeBlue
Type: Worm


To remove the worm, delete files that are detected as W32.BlueCode.Worm and remove the registry entry that the worm added.

To remove the worm:
  1. Run LiveUpdate to make sure that you have the most recent virus definitions.
  2. Start Norton AntiVirus (NAV), and run a full system scan. Be sure that NAV is configured to scan all files.
  3. Delete all files that are detected as W32.BlueCode.Worm.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.
  1. Click Start, and click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Navigate to and select the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\
    Windows\CurrentVersion\Run

  4. In the right pane, look for and select the value

    Domain Manager
  5. Press Delete, and then click Yes to confirm.
  6. Exit the Registry Editor.


Writeup By: Eric Chien
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security