Trojan.Mournor or W32.Mournor
Trojan.Mournor or W32.Mournor is a computer worm that alters certain system files and downloads additional threats coming from a remote server. The worm may propagate by infecting removable USB drives and network shared drives that have weak protection.
Alias: Trojan.Mourner, Worm.Win32.VB.nu, W32/Autorun.worm.gen, Mal/Generic-A, Worm:Win32/Autorun.PL, Worm.Win32.AutoRun, Win32/Xema.worm.2449408
Damage Level: Medium
Systems Affected: Windows 9x, 2000, XP, Windows Vista
Characteristics
When executed, Trojan.Mournor or W32.Mournor copies itself under Windows Directory and to the local drives it founds on target computer. Next, the worm will create a backup copy of “Explorer.exe” to a specified system folder and replaces the legitimate file with its own modified version. This makes the worm to run for every instance of Explorer activities.
Distribution
To infect other drives on the affected computer, W32.Mournor will drop one executable file and another Autorun.Inf file. The purpose of the Autorun file is to set the drive to autoplay or auto-execute the worm when the drive is mounted. If the infected drive is shared across the network then other connected computers might as well be infected with W32.Mournor.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunAssociated Files and Folders:
%Windir%\system\SERVICES.EXE %Windir%\system\SYSANALYSIS.EXE %SystemDrive%\Mourn_Operator.exe %SystemDrive%\[CHINESE CHARACTERS].exe %SystemDrive%\AUTORUN.INF %DriveLetter%\Mourn_Operator.exe %DriveLetter%\AUTORUN.INF
How to Remove Trojan.Mournor or W32.Mournor
Manual Removal Procedure
1. Kill any running process that belongs to Trojan.Mournor.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for the following files and click End Task.
svc.exe
2. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please Update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.
3. Delete all files dropped by Trojan.Mournor.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Associated Files and Folders.'
Removing the Virus from USB Drive
1. To eliminate Trojan.Mournor on every removable drives, please download and run Flash Disinfector. This tool is designed to scan malicious objects from Removable USB Devices, Flash Drives and memory stick.