Discovered: May 07, 2004
Updated: December 14, 2005 12:00:00 AM
Type: Removal Information
As part of their routine, many worms and Trojans make changes to the registry. Some of them change one or more of the shell\open\command keys. If these keys are changed, the worm or Trojan will run each time that you run certain files.
For example, if the \exefile\shell\open\command key is changed, the threat will run each time that you run any .exe file. This may also stop you from running the Registry Editor to try to fix this.
They may also change a registry value so that you cannot run the Registry Editor at all.
Symantec Security Response has created a tool to reset these registry values to their default settings.
Do not use this tool unless:
A Symantec technician or document directs you to do so.
After reading the removal instructions in the writeup, you are sure that the tool is required.
Follow these steps:
Download the file UnHookExec.inf and save it to your Windows desktop.
(If you cannot connect to the Internet from the infected computer, download to an uninfected computer then save it to a floppy disk. Then take the floppy disk and insert it in the floppy disk drive of the infected computer.)
Note: The tool has a .inf file extension.
Locate the download file, either on the Windows desktop or the floppy disk.
Right-click the UnHookExec.inf file and click install. (This is a small file. It does not display any notice or boxes when you run it.)
Follow any other instructions for the threat that you are trying to remove.