W97M.Hopel.A - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: February 5, 2003
Updated: February 13, 2007 11:55:26 AM
Type: Macro
Systems Affected: Macintosh, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
  1. Update the virus definitions.
  2. Run a full system scan and repair all the files detected as W97M.Hopel.A.
  3. Recover the files and reset the registry values as necessary.

For specific details on each of these procedures, read the following instructions.

1. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
  • Running LiveUpdate, which is the easiest way to obtain virus definitions. These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate), in the "Protection" section, at the top of this writeup.
  • Downloading the definitions using the Intelligent Updater. The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater), in the "Protection" section, at the top of this writeup.

    The Intelligent Updater virus definitions are available here. For detailed instructions on how to download and install the Intelligent Updater virus definitions from the Symantec Security Response Web site, click here.

2. Scanning for and repairing the infected files
  1. Start your Symantec antivirus software and make sure that it is configured to scan all the files.
  2. Run a full system scan.
  3. If any files are detected as infected with W97M.Hopel.A, click Repair.

3. Recovering files and resetting registry values
Depending on which payload, if any, was activated, you may have to:
  • Rename one or more files to their original file names.
  • Reset one or more registry value(s).
  • Restore the deleted files from a clean backup or re-install them.
  • Replace the Autoexec.bat file from a clean backup if you are running Windows 95/98/Me.
Refer to the Technical Description section for further details on what the W97M.Hopel.A virus can do and when it performs its functions.


Writeup By: Douglas Knowles
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security