Discovered: January 16, 2002
Updated: February 13, 2007 11:38:02 AM
Also Known As: W32.Pops@mm
Type: Worm
To remove the worm, delete files detected as W32.Pops and remove the values that it added to the registry (variant B only).
To remove the worm:
- Run LiveUpdate to make sure that you have the most recent virus definitions.
- Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
- Run a full system scan.
- Delete all files that are detected as W32.Pops.
To edit the registry:
CAUTION: We strongly recommend that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify only the keys that are specified. Read the document
How to back up the Windows registry for instructions.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to the following keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
- In the right pane for each key, delete the following value:
*JanisRuckenbrodII c:\WINDOWS\janis.com
- (Optional) Reset all of the following keys to their original defaults:
NOTE: These keys and values determine what program opens a particular type of file when the file is double-clicked. This will vary with the programs that you have installed and their settings. If you do not know the settings for each command, you may have to reinstall the software that uses it.
HKEY_CLASSES_ROOT\scrfile\shell\open\command\
HKEY_CLASSES_ROOT\VBSFile\Shell\Open\Command\
HKEY_CLASSES_ROOT\VBSFile\Shell\Open2\Command\
HKEY_CLASSES_ROOT\htmlfile\shell\open\command\
HKEY_CLASSES_ROOT\htmlfile\shell\opennew\command\
HKEY_CLASSES_ROOT\http\shell\open\command\
HKEY_CLASSES_ROOT\mp3file\shell\open\command\
HKEY_CLASSES_ROOT\MPEGFILE\shell\open\command\
HKEY_CLASSES_ROOT\JSFile\Shell\Open\Command\
HKEY_CLASSES_ROOT\JSFile\Shell\Open2\Command\
- Click Registry, and click Exit.
Writeup By: Gor Nazaryan