W32.Badday.A

W32.Badday.A spreads through removable storage devices. This worm can reduce security settings on the infected computer that may disable any installed anti-virus and firewall applications. W32.Badday.A will search for files that are .doc, .mpg, .3pg, .wmv, .rar, .jpg, .txt and creates the same file with the executable extension. This worm can also shut down any opened windows that contains words such as kill, hijack, reg and process to prevent its removal.

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

First Aid to Stop W32.Badday.A:

When W32.Badday.A virus infects a computer, it will modify system settings and inject itself to legitimate Windows files. System Restore is the tool-to-go-to in bringing back clean files and restoring earlier configuration. If you have saved previous restore point, please restore Windows to an earlier date.

Manual Removal of W32.Badday.A:

1. If an anti-virus program is present, update the definition file.
2. Reboot Windows in Safe Mode
- After turning on the power, press F8 on the keyboard.
- From the menu, select Safe Mode.

3. Run a full system scan and clean/delete all infected file(s).
4. Delete/Modify any values added to the registry if present.
- To edit the registry, click on Start. Search or Run regedit.exe.

Note: For a complete guide on Safe Mode and Registry Editor, please see tutorial links on the sidebar.

5. Exit registry editor and restart Windows.

Additional Tools and Programs:

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove virus and unfamiliar threats without using the traditional AV signatures. Download the tool from this location and start scanning the computer for viruses.

Technical Details and Additional Information:

Other functionalities of this Trojan:
- The worm will end any running application that contains words like kill, hijack, reg and process.
- A message “Have a Bad Day” is repeatedly copied on the clipboard.

Malicious Files Added by W32.Badday.A:
%Windir%\Media\StartUp\scvhost.exe
%System%\hostdll.exe
%System%\taskfile.exe
%Windir%\spool32.exe
%SystemDrive%\HaveaBadDay.sys

Associated Windows Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run\”Microsoft Word” = “%System%\hostdll.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\App Paths\WindowsProfile.EXE\”(default)” = “%Windir%\Media\StartUp\scvhost.exe”

What to do next...