The Mudcat Café TM
Thread #36826   Message #511095
Posted By: Jeri
20-Jul-01 - 07:47 AM
Thread Name: Virus Alert Please Read
Subject: RE: Virus Alert Please Read
For folks who deleted the worm/virus before making any other changes, the site kat gave the link to has detailed instructions on how to fix your system, which involves all of the following:

Deleting any attachments from infected e-mail.
Emptying the Recycle bin to delete Sircam.sys (if it exists).
How to remove the entry that it made to the Autoexec.bat file
How to revert the change that it made to the registry key HKEY_CLASSES_ROOT\exefile\shell\open\command

Again, check the site before doing any of this. Consider editing the registry key as doing brain surgery on your computer. If you mess with the wrong thing, your computer's screwed.

Note that running the file from F-Secure (I posted the URL above) is a whole lot easier for non-technogeeks. It does the complicated stuff for you, and all you have to do is delete the worm files.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

It appears as though the worm grabs a file already on the sender's computer to hide in, and titles the message to be the same as the attachment. It's not surprising Dick would have music files.

If it has two file extensions as Bob Bolton mentioned, it's likely to be the worm. ('file.ext.ext' instead of the normal 'file.ext')