W32/Bymer.A.Worm

Download VIRUSfighter NOW
W32/Bymer.A.Worm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 11/10/2000 • Type: Worm
• Virus characteristics first published: 11/10/2000 • Spreading mechanism: Network
• Virus characteristics latest update: 3/17/2004 • Overall risk: Low
• Alias: Dnet.Dropper, W32/Msinit, W32.HLLW.Bymer • Payload:
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
To completely remove this worm do the following:
  1. Scan all your disk(s) and delete all files detected as W32/Bymer.
  2. Download bymerrem.reg by right clicking on this link and double click the downloaded file to reset the changes the worm did to the Registry settings.
  3. Check if dnetc.exe and dnetc.ini are present in your Windows system directory (default is c:\windows\system). If they are - delete those.
    Note: If you participate in Distributed.net's program and did not find any infected files by performing the scan in item one above, you should not delete these files.
  4. Restart the computer.
  5. If you did not get any error message the worm is successfully removed.
    If you did get an error message saying that Windows did not find the file wininit.exe, start Sysedit (Click Start -> Run -> and type Sysedit). Click the window with win.ini and scroll down to the line which has the entry load=c:\windows\system\wininit.exe. Delete everything on this line except load=. Save your changes and exit Sysedit.

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter