Welcome to the Virus Encyclopedia of Panda Security.
It deletes files belonging to malicious files designed to steal passwords of online games. It disables the Task Manager and the Windows Registry Editor. It spreads through removable, shared and mapped drives.
|First detected on:||April 28, 2008|
|Detection updated on:||April 28, 2008|
VirusRemoval.A is a worm which deletes files related to malware designed to steal passwords of online games.
Additionally, it disables items, such as the Task Manager, which allows the process that are being run to be viewed, and the Windows Registry Editor.
VirusRemoval.A spreads through removable, mapped and shared drives, making copies of itself in them.
VirusRemoval.A is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.
However, it could be easily recognized if the user is browsing through the Internet, as it modifies the following elements:
- the start page of Internet Explorer established by the user changing it to the following:
- the title of the Internet Explorer windows, changing it to the following text: