W32.Spex.B.Worm

Printer Friendly Page

Discovered: November 26, 2003
Updated: February 13, 2007 12:14:21 PM
Also Known As: Worm.P2P.Specx [Kaspersky]
Systems Affected: Windows


W32.Spex.B.Worm is a worm that spreads through the KaZaA and iMesh file-sharing networks. It can also terminate security programs and system administration tools, steal CD keys of computer games, and perform denial of service attacks.

The worm is packed with ExeStealth and ASPack.



The file names under which the worm copies itself are:

Microangelo 6.x Serial.exe.exe

  • Microangelo 5.x Serial.exe
  • Microangelo 5.58 Serial.exe
  • IconPackager 2.x Serial.exe
  • IconPackager 2.12 Serial.exe
  • WindowBlinds 4.x Serial.exe
  • WindowBlinds 4.0 Serial.exe
  • FlashFXP 1.x Serial.exe
  • FlashFXP 1.4 Serial.exe
  • CloneCD 5.0 Serial.exe
  • CloneCD 4.x Serial.exe
  • WinAce 2.x Serial.exe
  • WinAce 2.2 Serial.exe
  • Armor2net Personal Firewall 3.1 Serial.exe
  • UltraEdit-32 10.x Serial.exe
  • UltraEdit-32 10.00b Serial.exe
  • Hex Workshop Hex Editor 4.1 Serial.eSnagIt 6.2.2 Serial.exe
  • FlashGet 1.x Serial.exe
  • FlashGet 1.3 Serial.exe
  • LingoWare 3.0 Serial.exe
  • GeoWhere 2.x Serial.exe
  • GeoWhere 2.11 Serial.exe
  • ICUII 5.7 Serial.exe
  • Direct Connect 1.x Serial.exe
  • Alpha Communicator 5.0 Serial.exe
  • mIRC 6.x Serial.exe
  • mIRC 6.03 Serial.exe
  • GetRight 6.x Serial.exe
  • GetRight 5.x Serial.exe
  • GetRight 5.0 Serial.exe
  • KaZaA Speedup 3.x Serial.exe
  • KaZaA Speedup 3.03 Serial.exe
  • Internet Turbo 2003 5.x Serial.exe
  • Internet Turbo 2003 5.4 Serial.exe
  • NetPumper 1.03 Serial.exe
  • Network Cable e ADSL Speed 1.0.6 Serial.exe
  • Network Cable e ADSL Speed 1.x Serial.exe
  • Nero Burning ROM 6.x Serial.exe
  • Nero Burning ROM 5.5.x Serial.exe
  • Ulead GIF Animator 6.x Serial.exe
  • Ulead GIF Animator 5.x Serial.exe
  • Ulead PhotoImpact 9.x Serial.exe
  • Ulead PhotoImpact 8.x Serial.exe
  • Macromedia Flash MX 6.x Serial.exe
  • Paint Shop Pro 9.x Serial.exe
  • Adobe Photoshop 8.x Serial.exe
  • Adobe Photoshop 7.x Serial.exe
  • Paint Shop Pro 8.x Serial.exe
  • ACDSee 2.4.x Serial.exe
  • SWiSH 2.x Serial.exe
  • SWiSH 2.0 Serial.exe
  • PhotoShow 2.x Serial.exe
  • PhotoShow 2.0 Serial.exe
  • WinZip 9.x Serial.exe
  • Internet Download Manager 3.x Serial.exe
  • Internet Download Manager 3.15 Serial.exe
  • MusicMatch Jukebox 8.x Serial.exe
  • MusicMatch Jukebox 8.0 Serial.exe
  • Easy CD-DA Extractor 5.x Serial.exe
  • Easy CD-DA Extractor 5.1 Serial.exe
  • Winamp 3.x Serial.exe
  • Winamp 2.91 Serial.exe
  • QuickTime 6.x Serial.exe
  • SolSuite 2003 Serial.exe
  • WS_FTP 5.x Serial.exe
  • Adobe Acrobat 5.x Serial.exe
  • ZoneAlarm 3.x Serial.exe
  • ZoneAlarm 3.8x Serial.exe
  • ZoneAlarm 3.7.143 Serial.exe
  • Divx 5.x Serial.exe
  • RealOne Player 2.0 Serial.exe
  • WinRAR 3.12 Serial.exe
  • WinRAR 3.11 Serial.exe
  • DAP Plus 5.3 Serial.exe
  • Download Accelerator Plus 5.3 Serial.exe
  • Ad-aware 6.0 Serial.exe
  • WinZip 8.0 Serial.exe
  • WinZip 8.1 Serial.exe
  • NASCAR Thunder 2003 Serial.exe
  • F1 2002 Serial.exe
  • NHL 2002 Serial.exe
  • NHL 2003 Serial.exe
  • Tiger Woods PGA TOUR 2002 Serial.exe
  • Tiger Woods PGA TOUR 2003 Serial.exe
  • NCAA Football 2003 Serial.exe
  • NCAA Football 2004 Serial.exe
  • Madden NFL 2003 Serial.exe
  • MVP Baseball 2003 Serial.exe
  • Thief 2 Serial.exe
  • Thief 3 Serial.exe
  • Thief II Serial.exe
  • Thief III Serial.exe
  • Shrek II Serial.exe
  • Shrek 2 Serial.exe
  • Quake 3 Serial.exe
  • Quake 4 Serial.exe
  • Quake IV Serial.exe
  • MechWarrior III Serial.exe
  • MechWarrior IV Serial.exe
  • MechWarrior V Serial.exe
  • MechWarrior 3 Serial.exe
  • MechWarrior 4 Serial.exe
  • MechWarrior 5 Serial.exe
  • Trinity Serial.exe
  • Hitman II Serial.exe
  • Hitman 2 Serial.exe
  • Hitman III Serial.exe
  • Hitman 3 Serial.exe
  • Metal Gear Solid III Serial.exe
  • Metal Gear Solid 3 Serial.exe
  • Lord of the Rings - War of the Ring Serial.exe
  • World War II - Frontline Command Serial.exe
  • Warlords 4 Serial.exe
  • Warlords IV - Heroes of Etheria Serial.exe
  • Soul Reaver III Serial.exe
  • Soul Reaver 3 Serial.exe
  • Train Simulator II Serial.exe
  • Star Wars - Knights of the Old Republic Serial.exe
  • Star Wars Jedi Knight - Jedi Academy Serial.exe
  • SimCity IV Serial.exe
  • SimCity 4 Rush Hour Serial.exe
  • Silent Hill III Serial.exe
  • Silent Hill 3 Serial.exe
  • Medal of Honor - Allied Assault Breakthrough Serial.exe
  • Max Payne 2 - The Fall of Max Payne Serial.exe
  • Lord of the Rings - The Two Towers Serial.exe
  • Freedom - Soldiers of Liberty Serial.exe
  • EverQuest 2 Serial.exe
  • DOOM III Serial.exe
  • DOOM 3 Serial.exe
  • Battlefield 1942 - Secret Weapons of World War II Serial.exe
  • Railroad Tycoon III Serial.exe
  • Harry Potter - Quidditch World Cup Serial.exe
  • Conflict - Desert Storm II - Back to Baghdad Serial.exe
  • Civilization III - Conquest Serial.exe
  • Lords of the Realm III Serial.exe
  • NASCAR Thunder 2004 Serial.exe
  • Madden NFL 2004 Serial.exe
  • Age of Wonders II - Shadow Magic Serial.exe
  • Counter-Strike - Condition Zero Serial.exe
  • Tony Hawk's Pro Skater 4 Serial.exe
  • The Sims Superstar Serial.exe
  • Neverwinter Nights - Shadows of Undrentide Serial.exe
  • Star Trek - Elite Force II Serial.exe
  • Return to Castle Wolfenstein Serial.exe
  • Return to Castle Wolfenstein Enemy Territory Serial.exe
  • Grand Theft Auto - Vice City Serial.exe
  • Warcraft 3 Serial.exe
  • Warcraft III Serial.exe
  • Warcraft III - The Frozen Throne Serial.exe
  • IL-2 Sturmovik - Forgotten Battles Serial.exe
  • NBA Live 2004 Serial.exe
  • NBA Live 2003 Serial.exe
  • Elder Scrolls III - Tribunal Serial.exe
  • Battlefield 1942 - The Road to Rome Serial.exe
  • SimCity 4 Serial.exe
  • Command & Conquer Generals Serial.exe
  • Splinter Cell Serial.exe
  • NASCAR Racing 2003 Serial.exe
  • Praetorians Serial.exe
  • Delta Force - Black Hawk Down Serial.exe
  • Rainbow Six 3 - Raven Shield Serial.exe
  • Raven Shield Serial.exe
  • Metal Gear Solid 2 Serial.exe
  • Metal Gear Solid Serial.exe
  • Need for Speed Underground Serial.exe
  • Flight Simulator - Century of Flight Serial.exe
  • Train Simulator 2 Serial.exe
  • Commandos 3 - Destination Berlin Serial.exe
  • FIFA Soccer 2003 Serial.exe
  • FIFA Soccer 2004 Serial.exe
  • Black & White 2 Serial.exe
  • Xenus Serial.exe
  • Kings of War Serial.exe
  • UT 2003 Serial.exe
  • UT 2004 Serial.exe
  • Unreal Tournament 2003 Serial.exe
  • Unreal Tournament 2004 Serial.exe
  • FireStarter Serial.exe
  • Lords of EverQuest Serial.exe
  • Dark Age of Camelot - Trials of Atlantis Serial.exe
  • Halo Serial.exe
  • Etherlords II Serial.exe
  • Chrome Serial.exe
  • Sniper Elite - Berlin 1943 Serial.exe
  • Age of Mythology - The Titans Serial.exe
  • Tomb Raider - The Angel of Darkness Serial.exe
  • Knights of the Temple Serial.exe
  • Half-Life II Serial.exe
  • Half-Life Serial.exe
  • Half-Life 2 Serial.exe
  • Microangelo 6.x Crack.exe.exe
  • Microangelo 5.x Crack.exe
  • Microangelo 5.58 Crack.exe
  • IconPackager 2.x Crack.exe
  • IconPackager 2.12 Crack.exe
  • WindowBlinds 4.x Crack.exe
  • WindowBlinds 4.0 Crack.exe
  • FlashFXP 1.x Crack.exe
  • FlashFXP 1.4 Crack.exe
  • CloneCD 5.0 Crack.exe
  • CloneCD 4.x Crack.exe
  • WinAce 2.x Crack.exe
  • WinAce 2.2 Crack.exe
  • Armor2net Personal Firewall 3.1 Crack.exe
  • UltraEdit-32 10.x Crack.exe
  • UltraEdit-32 10.00b Crack.exe
  • Hex Workshop Hex Editor 4.1 Crack.exe
  • SnagIt 6.2.2 Crack.exe
  • FlashGet 1.x Crack.exe
  • FlashGet 1.3 Crack.exe
  • LingoWare 3.0 Crack.exe
  • GeoWhere 2.x Crack.exe
  • GeoWhere 2.11 Crack.exe
  • ICUII 5.x.exe
  • ICUII 5.7 Crack.exe
  • Direct Connect 1.x Crack.exe
  • Alpha Communicator 5.0 Crack.exe
  • mIRC 6.x Crack.exe
  • mIRC 6.03 Crack.exe
  • GetRight 6.x Crack.exe
  • GetRight 5.x Crack.exe
  • GetRight 5.0 Crack.exe
  • KaZaA Speedup 3.x Crack.exe
  • KaZaA Speedup 3.03 Crack.exe
  • Internet Turbo 2003 5.x Crack.exe
  • Internet Turbo 2003 5.4 Crack.exe
  • NetPumper 1.03 Crack.exe
  • Network Cable e ADSL Speed 1.0.6 Crack.exe
  • Network Cable e ADSL Speed 1.x Crack.exe
  • Nero Burning ROM 6.x Crack.exe
  • Nero Burning ROM 5.5.x Crack.exe
  • Ulead GIF Animator 6.x Crack.exe
  • Ulead GIF Animator 5.x Crack.exe
  • Ulead PhotoImpact 9.x Crack.exe
  • Ulead PhotoImpact 8.x Crack.exe
  • Macromedia Flash MX 6.x Crack.exe
  • Paint Shop Pro 9.x Crack.exe
  • Adobe Photoshop 8.x Crack.exe
  • Adobe Photoshop 7.x Crack.exe
  • Paint Shop Pro 8.x Crack.exe
  • ACDSee 2.4.x Crack.exe
  • SWiSH 2.x Crack.exe
  • SWiSH 2.0 Crack.exe
  • PhotoShow 2.x Crack.exe
  • PhotoShow 2.0 Crack.exe
  • WinZip 9.x Crack.exe
  • Internet Download Manager 3.x Crack.exe
  • Internet Download Manager 3.15 Crack.exe
  • MusicMatch Jukebox 8.x Crack.exe
  • MusicMatch Jukebox 8.0 Crack.exe
  • Easy CD-DA Extractor 5.x Crack.exe
  • Easy CD-DA Extractor 5.1 Crack.exe
  • Winamp 3.x Crack.exe
  • Winamp 2.91 Crack.exe
  • QuickTime 6.x Crack.exe
  • SolSuite 2003 Crack.exe
  • WS_FTP 5.x Crack.exe
  • Adobe Acrobat 5.x Crack.exe
  • ZoneAlarm 3.x Crack.exe
  • ZoneAlarm 3.8x Crack.exe
  • ZoneAlarm 3.7.143 Crack.exe
  • Divx 5.x Crack.exe
  • RealOne Player 2.0 Crack.exe
  • WinRAR 3.12 Crack.exe
  • WinRAR 3.11 Crack.exe
  • DAP Plus 5.3 Crack.exe
  • Download Accelerator Plus 5.3 Crack.exe
  • Ad-aware 6.0 Crack.exe
  • WinZip 8.0 Crack.exe
  • WinZip 8.1 Crack.exe
  • NASCAR Thunder 2003 Crack.exe
  • F1 2002 Crack.exe
  • NHL 2002 Crack.exe
  • NHL 2003 Crack.exe
  • Tiger Woods PGA TOUR 2002 Crack.exe
  • Tiger Woods PGA TOUR 2003 Crack.exe
  • NCAA Football 2003 Crack.exe
  • NCAA Football 2004 Crack.exe
  • Madden NFL 2003 Crack.exe
  • MVP Baseball 2003 Crack.exe
  • Thief 2 Crack.exe
  • Thief 3 Crack.exe
  • Thief II Crack.exe
  • Thief III Crack.exe
  • Shrek II Crack.exe
  • Shrek 2 Crack.exe
  • Quake III.exe
  • Quake 3 Crack.exe
  • Quake 4 Crack.exe
  • Quake IV Crack.exe
  • Midtown Madness II.exe
  • Midtown Madness 2.exe
  • Midtown Madness III.exe
  • Midtown Madness 3.exe
  • MechWarrior III Crack.exe
  • MechWarrior IV Crack.exe
  • MechWarrior V Crack.exe
  • MechWarrior 3 Crack.exe
  • MechWarrior 4 Crack.exe
  • MechWarrior 5 Crack.exe
  • Trinity Crack.exe
  • Hitman II Crack.exe
  • Hitman 2 Crack.exe
  • Hitman III Crack.exe
  • Hitman 3 Crack.exe
  • Metal Gear Solid III Crack.exe
  • Metal Gear Solid 3 Crack.exe
  • Lord of the Rings - War of the Ring Crack.exe
  • World War II - Frontline Command Crack.exe
  • Warlords 4 Crack.exe
  • Warlords IV - Heroes of Etheria Crack.exe
  • Soul Reaver III Crack.exe
  • Soul Reaver 3 Crack.exe
  • Train Simulator II Crack.exe
  • Star Wars - Knights of the Old Republic Crack.exe
  • Star Wars Jedi Knight - Jedi Academy Crack.exe
  • SimCity IV Crack.exe
  • SimCity 4 Rush Hour Crack.exe
  • Silent Hill III Crack.exe
  • Silent Hill 3 Crack.exe
  • Medal of Honor - Allied Assault Breakthrough Crack.exe
  • Max Payne 2 - The Fall of Max Payne Crack.exe
  • Lord of the Rings - The Two Towers Crack.exe
  • Freedom - Soldiers of Liberty Crack.exe
  • EverQuest 2 Crack.exe
  • DOOM III Crack.exe
  • DOOM 3 Crack.exe
  • Battlefield 1942 - Secret Weapons of World War II Crack.exe
  • Railroad Tycoon III Crack.exe
  • Harry Potter - Quidditch World Cup Crack.exe
  • Conflict - Desert Storm II - Back to Baghdad Crack.exe
  • Civilization III - Conquest Crack.exe
  • Lords of the Realm III Crack.exe
  • NASCAR Thunder 2004 Crack.exe
  • Madden NFL 2004 Crack.exe
  • Age of Wonders II - Shadow Magic Crack.exe
  • Counter-Strike - Condition Zero Crack.exe
  • Tony Hawk's Pro Skater 4 Crack.exe
  • The Sims Superstar Crack.exe
  • Neverwinter Nights - Shadows of Undrentide Crack.exe
  • Star Trek - Elite Force II Crack.exe
  • Return to Castle Wolfenstein Crack.exe
  • Return to Castle Wolfenstein Enemy Territory Crack.exe
  • Grand Theft Auto - Vice City Crack.exe
  • Warcraft 3 Crack.exe
  • Warcraft III Crack.exe
  • Warcraft III - The Frozen Throne Crack.exe
  • IL-2 Sturmovik - Forgotten Battles Crack.exe
  • NBA Live 2004 Crack.exe
  • NBA Live 2003 Crack.exe
  • Elder Scrolls III - Tribunal Crack.exe
  • Battlefield 1942 - The Road to Rome Crack.exe
  • SimCity 4 Crack.exe
  • Command & Conquer Generals Crack.exe
  • Splinter Cell Crack.exe
  • NASCAR Racing 2003 Crack.exe
  • Praetorians Crack.exe
  • Delta Force - Black Hawk Down Crack.exe
  • Rainbow Six 3 - Raven Shield Crack.exe
  • Raven Shield Crack.exe
  • Metal Gear Solid 2 Crack.exe
  • Metal Gear Solid Crack.exe
  • Need for Speed Underground Crack.exe
  • Flight Simulator - Century of Flight Crack.exe
  • Train Simulator 2 Crack.exe
  • Commandos 3 - Destination Berlin Crack.exe
  • FIFA Soccer 2003 Crack.exe
  • FIFA Soccer 2004 Crack.exe
  • Black & White 2 Crack.exe
  • Xenus Crack.exe
  • Kings of War Crack.exe
  • UT 2003 Crack.exe
  • UT 2004 Crack.exe
  • Unreal Tournament 2003 Crack.exe
  • Unreal Tournament 2004 Crack.exe
  • FireStarter Crack.exe
  • Lords of EverQuest Crack.exe
  • Dark Age of Camelot - Trials of Atlantis Crack.exe
  • Halo Crack.exe
  • Etherlords II Crack.exe
  • Chrome Crack.exe
  • Sniper Elite - Berlin 1943 Crack.exe
  • Age of Mythology - The Titans Crack.exe
  • Tomb Raider - The Angel of Darkness Crack.exe
  • Knights of the Temple Crack.exe
  • Half-Life II Crack.exe
  • Half-Life Crack.exe
  • Half-Life 2 Crack.exe


Antivirus Protection Dates

  • Initial Rapid Release version November 26, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version November 26, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date November 26, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Writeup By: Fergal Ladley

Discovered: November 26, 2003
Updated: February 13, 2007 12:14:21 PM
Also Known As: Worm.P2P.Specx [Kaspersky]
Systems Affected: Windows


When W32.Spex.B.Worm is executed, it performs the following actions:

  1. Attempts to terminate processes with the following names:
    • regedit.exe
    • msconfig.exe
    • netstat.exe
    • zonealarm.exe
    • zapro.exe
    • avp.exe
    • avpm.exe
    • avpcc.exe
    • avp32.exe
    • blackice.exe
    • blackd.exe
    • _avp.exe
    • _avpm.exe
    • _avpcc.exe
    • _avp32.exe
    • frw.exe
    • pcfwallicon.exe
    • cfinet.exe
    • cfinet32.exe
    • cfiaudit.exe
    • cfiadmin.exe
    • iamapp.exe
    • iamserv.exe
    • smc.exe
    • persfw.exe
    • lookout.exe
    • espwatch.exe
    • mpftray.exe
    • serv95.exe
    • nisum.exe
    • nmain.exe
    • serv95.exe

  2. Copies itself as %System%\iexplore32.exe.


    Note: %System% is a variable. The worm locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

  3. Adds the value:

    "IELoader32"="%System%\iexplore32.exe"

    to the registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    so that the worm runs when you start Windows.

  4. Displays a message box with the following caption:

    "Window Explorer Error"

    and the following text:

    "Execution error ( incompatible kernel )."

  5. Makes 389 copies of itself in %System%\Drivers32 folder.


    Note: For a complete list of the added files, refer to the Additional Information section.

  6. Modifies the value:

    "Dir0"="012345:C:\WINNT\System32\drivers32"

    in the registry keys:
    • HKEY_CURRENT_USER\Software\KAZAA\LocalContent\
    • HKEY_CURRENT_USER\Software\iMesh\Client\LocalContent

      which shares the Drivers32 folder through the KaZaA and iMesh file-sharing networks.

  7. Attempts to steal CD keys from the following computer games:
    • Soldier of Fortune II - Double Helix
    • Neverwinter Nights
    • Rainbow Six III RavenShield
    • Battlefield 1942 - The Road to Rome
    • Project IGI 2
    • Counter-Strike
    • Unreal Tournament 2003
    • Half-Life

  8. Connects to a predetermined IRC channel and informs an attacker that the computer has been infected. The attacker can then perform commands on the infected computer.


Writeup By: Fergal Ladley

Discovered: November 26, 2003
Updated: February 13, 2007 12:14:21 PM
Also Known As: Worm.P2P.Specx [Kaspersky]
Systems Affected: Windows


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

  1. Disable System Restore (Windows Me/XP).
  2. Restart the computer in Safe mode or VGA mode.
  3. Delete the value that was added to the registry, and then restart the computer.
  4. Update the virus definitions.
  5. Run a full system scan and delete all the files detected as W32.Spex.B.Worm.
For specific details on each of these steps, read the following instructions.

1. Disabling System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder ," Article ID: Q263455.

2. Restarting the computer in Safe mode or VGA mode
  • For Windows 95, 98, Me, 2000, or XP users, restart the computer in Safe mode. For instructions on restarting in Safe mode, refer to the document, "How to start the computer in Safe Mode."
  • For Windows NT 4 users, restart the computer in VGA mode.


3. Deleting the value from the registry

CAUTION : Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry ," for instructions.
  1. Click Start, and then click Run. (The Run dialog box appears.)
  2. Type regedit

    Then click OK. (The Registry Editor opens.)

  3. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

  4. In the right pane, delete the value:

    "IELoader32"="%System%\iexplore32.exe"

  5. Exit the Registry Editor.
  6. Restart the computer in Normal mode.
4. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
  • Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate).
  • Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater).

    The Intelligent Updater virus definitions are available: Read "How to update virus definition files using the Intelligent Updater" for detailed instructions.

5. Scanning for and deleting the infected files
  1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
  2. Run a full system scan.
  3. If any files are detected as infected with W32.Spex.B.Worm, click Delete.


Writeup By: Fergal Ladley