W32.Fili.A@mm is a generic Visual Basic worm that propagates via
Microsoft Outlook and through peer-to-peer file-sharing networks. It
can also spread via mIRC.
The email has a variable subject and attachment name. The
attachment will have a .scr, .pif, .bat, .com, .cmd, or .exe file
extension.
Notes:
Virus definitions released prior to October 6, 2004 will detect this threat as Bloodhound.Packed or Bloodhound.W32.5.
Virus definitions released prior to October 11, 2004 will detect this threat as W32.Fili@mm.
If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
Always keep your patch levels up-to-date, especially on computers
that host public services and are accessible through the firewall, such
as HTTP, FTP, mail, and DNS services.
Enforce a password policy. Complex passwords make it difficult to
crack password files on compromised computers. This helps to prevent or
limit damage when a computer is compromised.
Configure your email server to block or remove email that contains
file attachments that are commonly used to spread viruses, such as
.vbs, .bat, .exe, .pif and .scr files.
Isolate infected computers quickly to prevent further compromising
your organization. Perform a forensic analysis and restore the
computers using trusted media.
Train employees not to open attachments unless they are expecting
them. Also, do not execute software that is downloaded from the
Internet unless it has been scanned for viruses. Simply visiting a
compromised Web site can cause infection if certain browser
vulnerabilities are not patched.
Note: When you are completely finished with the removal
procedure and are satisfied that the threat has been removed, re-enable
System Restore by following the instructions in the aforementioned
documents.
2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for
quality assurance before they are posted to our servers. There are two
ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain virus
definitions: These virus definitions are posted to the LiveUpdate
servers once each week (usually on Wednesdays), unless there is a major
virus outbreak. To determine whether definitions for this threat are
available by LiveUpdate, refer to the Virus Definitions (LiveUpdate).
Downloading the definitions using the Intelligent Updater: The
Intelligent Updater virus definitions are posted daily. You should
download the definitions from the Symantec Security Response Web site
and manually install them. To determine whether definitions for this
threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater).
If any files are detected as infected with W32.Fili.A@mm, click Delete.
Note: If your Symantec antivirus
product reports that it cannot delete an infected file, Windows may be
using the file. To fix this, run the scan in Safe mode. For
instructions, read the document, "How to start the computer in Safe Mode." Once you have restarted in Safe mode, run the scan again.
(After the files are deleted, you can leave the computer in Safe mode
and proceed with section 4. When that is done, restart the computer in
Normal mode.)
4. To delete the value from the registry
Important: Symantec
strongly recommends that you back up the registry before making any
changes to it. Incorrect changes to the registry can result in
permanent data loss or corrupted files. Modify the specified keys only.
Read the document, "How to make a backup of the Windows registry," for instructions.