Symantec Security Response has developed a removal tool to clean the infections of W32.Erkez.B@mm.
The W32.Erkez.B@mm Removal Tool does the following:
- Terminates the W32.Erkez.B@mm viral processes
- Deletes the W32.Erkez.B@mm files
- Deletes the registry values that the worm added
Note: You must have administrative rights to run this tool on Windows NT 4.0, Windows 2000, or Windows XP.
HOW TO
· Download the FxErkezB.exe file
· Save the file to a convenient location, such as your downloads folder or the Windows desktop, or removable media known to be uninfected.
· Close all the running programs before running the tool.
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
· If you are running Windows Me or XP, then disable System Restore. Refer to the "System Restore option in Windows Me/XP" section later in this writeup for further details.
· Caution: If you are running Windows Me/XP, we strongly recommend that you do not skip this step.
· Double-click the FxErkezB.exe file to start the removal tool.
· Click Start to begin the process, and then allow the tool to run.
· Restart the computer.
· Run the removal tool again to ensure that the system is clean.
· If you are running Windows Me/XP, then re-enable System Restore.