I suppose the registry entry is .../CurrentVersion/Run making it load at startup. Just remove this entry, rename the file to windows.exe.disabled or whatever you feel appropriate to disable it.
This is very probably some variant from the Litmus worm. You should update your virus definitions, scan your pc for viruses and take appropriate removal actions, depending on the virus.
About Litmus:
http://securityresponse.sy
It has another filename however the cure would be about the same, but make sure of which worm it is, could be that the payload is triggered by removing the worm. Not very probable but it exists some that encrypt & decrypt some parts of your hd. Everything is fine as long as the virus is up & running. If you remove it you remove the decrypt function as well and your hd becomes unreadable. So first start by a good virus scan with the last definituions and see which perfume it is.
Orni
Main Topics
Browse All Topics





by: rossi6789Posted on 2003-09-16 at 13:47:45ID: 9373417
Whatever it is I don't think it belongs on a native install. We run 300 machines with W2K. I checked two machines, one native.
????W32.Litmus (Windows worm that spreads by email)
Found above on search but I am dubious.
Rossi