To: "'e-WebAuthor'" <[EMAIL PROTECTED]>
Message-id: <[EMAIL PROTECTED]>
MIME-version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-type: multipart/mixed; boundary=------------InterScan_NT_MIME_Boundary
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
--------------InterScan_NT_MIME_Boundary
Content-Type: multipart/alternative;
boundary="----_=_NextPart_001_01C13673.FB5AB7D0"
------_=_NextPart_001_01C13673.FB5AB7D0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: As per your request!!! dengan attachment Readme.Exe atau =
*.exe
yang lain
=20
merupakan jenis virus yang lain juga yang sebenarnya cukup dikenal =
beberapa
bulan ini. Namun akhir-akhir ini masih mampu menerobos beberapa servers
dengan filter AV norton yang terakhir.
=20
Hati2 dengan jenis virus ini!!=20
=20
-----Original Message-----
From: Besar Kasianto [mailto:[EMAIL PROTECTED]]
Sent: Friday, July 27, 2001 10:10 PM
To: e-WebAuthor
Subject: [i-kan-webauthor] Keterangan Tentang SirCam32 Virus
Originally from : "Besar Kasianto"=20
Originally dated: Fri, 27 Jul 2001 21:09:30 +0700
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<e-WebAuthor>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~Forum Diskusi WebAuthoring untuk Kristen-Katholik~~~~~~~~~~~
W32/SirCam@MM Help Center=20
=20
DESCRIPTION - What virus is this?=20
=20
This is a HIGH RISK virus that is spread to email recipients found in =
the
Windows Address Book and addresses found in cached files. The infected =
email
can come from addresses that you recognize. Attached is a file with two
different extensions. The file name itself varies.=20
The email message can appear as follows:
Subject: [filename (random)]
Body: Hi! How are you?=20
I send you this file in order to have your advice
or I hope you can help me with this file that I send
or I hope you like the file that I sendo you
or This is the file with the information that you ask for
See you later. Thanks=20
--- the same message may be received in Spanish ---=20
=20
Hola como estas ?
Te mando este archivo para que me des tu punto de vista
or Espero me puedas ayudar con el archivo que te mando
or Espero te guste este archivo que te mando
or Este es el archivo con la informaci=F3n que me pediste
Nos vemos pronto, gracias.=20
=20
=20
=20
=20
=20
PAYLOAD - What can this virus do?=20
=20
When run, the document will be saved to the C:\RECYCLED folder and then
opened while the virus copies itself to C:\RECYCLED\SirC32.exe folder =
to
conceal its presence and creates a registry key value to load itself
whenever .EXE files are executed.=20
The virus searches for .GIF, .JPG, .JPEG, .MPEG, .MOV, .MPG, .PDF, =
.PNG,
.PS, and .ZIP files in the MY DOCUMENTS folder and attempts to send =
copies
of these documents to email recipients found in the Windows Address =
Book and
addresses found in cached files.=20
=20
=20
=20
=20
DETECTION AND REMOVAL=20
- How can I detect and remove this virus?=20
=20
McAfee.com VirusScan and Clinic users,=20
click here to update ActiveShield.=20
=20
Retail McAfee VirusScan users,=20
click here to get the latest DAT file.=20
=20
Scan Your System for Infected Files=20
McAfee.com VirusScan Online and Clinic users, click here to perform a =
Scan.=20
If W32/SirCam@MM is found, use the delete option to remove it.=20
=20
Manual Removal
=20
If you are unable to use the W32/SirCam@mm standalone removal tool, =
see: (
http://www.mcafeeb2b.com/naicommon/avert/avert-research-center/tools.asp=
#sir
cam
<http://www.mcafeeb2b.com/naicommon/avert/avert-research-center/tools.as=
p#si
rcam> ) SCRMOVE2.zip, then you need to remove the worm manually. =
Directions
follow.
=20
IMPORTANT: Users with 24-hour Internet connectivity and/or those on a
network need to disconnect the computer from these sources. Follow the
removal procedures for all computers as well as the server. Before
reconnecting computers to the network or Internet, shared files and/or
drives should be password protected or have sharing disabled =
altogether.
Contact your network administrator for assistance and advice concerning =
file
sharing.
Edit the Registry
=20
Copy Regedit.exe to Regedit.com:=20
Windows 95/98 users: Click Start, point to Programs, and click MS-DOS
Prompt.=20
Windows ME users: Click Start, point to Programs, point to Accessories, =
and
then click MS-DOS Prompt.=20
Windows NT/2000 users:=20
Click Start, and click Run.=20
Click Browse, and browse to the \Winnt folder.=20
Double-click the Command.com file, and then click OK.=20
=20
Type the following and then press Enter:=20
copy regedit.exe regedit.com=20
=20
Backup the Registry
=20
Click on the Start button.=20
Click on Run.=20
Type REGEDIT.com in the Open field.=20
Click the OK button. The Registry Editor window will appear.=20
Click on the Registry pull-down menu.=20
Click on Export Registry File.=20
In the File Name field type "backup" (without the quotation marks).=20
In the Save In field be sure that the desktop is selected (if it is =
not,
click on the pull down menu and select "Desktop").=20
Select "All" in the Export Range group box.=20
Click on the Save button. The registry will then be saved.=20
Click the X in the top right corner to close the Registry Editor.=20
NOTE: You now have a backup of your Registry saved as "backup" on your
desktop. If you need to restore the Registry you can double-click on =
the
"backup" file located on the desktop. Once these instructions are =
complete
and everything is running properly be sure to delete this backup file =
by
right-clicking on it then left-clicking on Delete from the pop-up menu =
that
appears. This will ensure that the old registry is not accidentally =
restored
once the worm has been removed. =20
=20
Remove the Worm Entries from the Registry
=20
As you go through this process, you will be asked to confirm each =
change.
Make sure that the change is correct, then confirm each change.=20
=20
Click the Start button.=20
Click on Run.=20
Type in REGEDIT.com in the Open field.=20
Click the OK button. The Registry Editor window will appear.=20
Click on the plus sign next to HKEY_CLASSES_ROOT.=20
Click on the plus sign next to exefile.=20
Click on the plus sign next to shell.=20
Click on the plus sign next to open.=20
Single-click on command so it is highlighted.=20
On the right side of the screen is a Name column and a Data column. =
Locate
and right-click on (Default) under the Name column.=20
A pop-up menu will appear. Left-click on Modify.=20
The Edit String dialog box will appear with the value highlighted. =
Delete
all text in the Value and type the following characters (WITHOUT THE
BRACKETS): ["%1" %*] If you are unsure of how the characters should be, =
the
following is a spelled out version of the correct characters: quote,
percentage, one, quote, space, percentage, asterisk.=20
Click the OK button to close the Edit String dialog box.=20
On the left side of the screen click on the minus sign next to open.=20
Click on the minus sign next to shell.=20
Click on the minus sign next to exefile.=20
click on the minus sign next to HKEY_CLASSES_ROOT.=20
Click on the plus sign next to HKEY_LOCAL_MACHINE.=20
Click on the plus sign next to SOFTWARE.=20
Single click on the SIRCAM folder so it is highlighted, then hit =
delete.=20
Click the plus sign next to Microsoft.=20
Click the plus sign next to Windows.=20
Click the plus sign next to CurrentVersion.=20
Single click on the RunServices Folder so it is highlighted.=20
On the right side of the screen is a Name column and a Data column. =
Under
the Name column locate and single-click on Driver32 =3D
C:\WINDOWS\SYSTEM\SCam32.exe so it is highlighted.=20
Press the Delete key on the keyboard to remove the entry.=20
Close the Registry Editor by clicking the X in the top right corner.=20
Scan to Remove the Worm :
=20
Connect to the Internet.=20
Go to http://www.mcafee.com <http://www.mcafee.com> .=20
Enter your password and email address, and click the Login button.=20
Near the top-left of the page, locate the "Site Shortcuts" drop-down =
menu.=20
Click the drop-down arrow and choose Scan, from under VirusScan Online. =
A
new page will then load.=20
Click the "Start" link in the box: Current users click here to start.=20
If you are using this service for the first time you will then see a =
page
with a "Start Download" link. Click on the "Start Download" link to =
download
the necessary components.=20
In the Scan In box select the drive you would like to scan (C: drive, =
etc).
Then click the Scan button located in the lower right corner.=20
The program will then scan the selected drive for viruses. If a virus =
is
found a notification will appear in the Scan Results box. Delete =
infected
files if they cannot be cleaned.=20
=20
Windows ME Info:
=20
NOTE: Windows ME utilizes a backup utility that backs up selected files
automatically to the C:\_Restore folder. This means that an infected =
file
could be stored there as a backup file, and VirusScan will be unable to
delete these files. If the scan turns up an infected file in the =
C:\_restore
folder follow these instructions to remove the infected files.
=20
Disabling the Restore Utility
=20
Right click the My Computer icon on the Desktop.=20
Click on the Performance Tab.=20
Click on the File System button.=20
Click on the Troubleshooting Tab.=20
Put a check mark next to "Disable System Restore".=20
Click the Apply button.=20
Click the Close button.=20
Click the Close button again.=20
You will be prompted to restart the computer. Click Yes. NOTE: The =
Restore
Utility will now be disabled.=20
Browse to the C:\_Restore folder and remove the infected files.=20
NOTE: To re-enable the Restore Utility, follow steps 1-9 and on step 5
remove the check mark next to "Disable System Restore". The infected =
file's
are removed and the System Restore is once again active. =20
=20
Check the Autoexec.bat file:
=20
No reference to the worm may be found here, but it is best to double =
check.
=20
Click Start, and click Run.=20
Type the following, and then click OK.=20
sysedit
=20
The MS-DOS Editor opens.
=20
A screen with 5 windows stacked will open. The first window will be the
Autoexec.bat window.=20
Search for the following line(no quotations): "@win =
\recycled\sirc32.exe"=20
Delete only this portion if you find it.=20
Click File and then click Save.=20
Exit the MS-DOS Editor=20
=20
Empty the Recycle Bin:
=20
Do not simply click on "Empty Recycle Bin" as you would normally. You =
must
use Windows Explorer to delete the file C:\Recycled\Sircam.sys if it is
present.=20
=20
I-KAN %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% e-WebAuthor
Permulaan hikmat adalah takut akan TUHAN! Mazmur 111:10a / Amsal 9:10a
-----------------------------------------------------------------------
WEB--> http://hub.xc.org/scripts/lyris.pl?enter=3Di-kan-webauthor
SUBSCRIBE--> To: [EMAIL PROTECTED], Isi/Body: kosong
UNSUBSCRIBE--> To: [EMAIL PROTECTED], Isi/Body: kosong =
------_=_NextPart_001_01C13673.FB5AB7D0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 5.50.4522.1800" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>Originally from : Gideon Suharyanto
<[EMAIL PROTECTED]><BR>
Originally dated: Wed, 05 Sep 2001 18:33:50 -0700<BR>
<BR>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<e-WebAuthor>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<BR>
~~~~~~~~~~~Forum Diskusi WebAuthoring untuk Kristen-Katholik~~~~~~~~~~~<BR>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff=20
size=3D2>Subject: As per your request!!! dengan attachment =
Readme.Exe=20
atau *.exe yang lain</FONT></SPAN></DIV>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff=20
size=3D2>merupakan jenis virus yang lain juga yang =
sebenarnya cukup=20
dikenal beberapa bulan ini. Namun akhir-akhir ini masih mampu =
menerobos=20
beberapa servers dengan filter AV norton yang =
terakhir.</FONT></SPAN></DIV>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff size=3D2>Hati2=20
dengan jenis virus ini!! </FONT></SPAN></DIV>
<DIV><SPAN class=3D380122500-06092001><FONT face=3DArial =
color=3D#0000ff=20
size=3D2></FONT></SPAN> </DIV>
<BLOCKQUOTE>
<DIV class=3DOutlookMessageHeader dir=3Dltr align=3Dleft><FONT =
face=3DTahoma=20
size=3D2>-----Original Message-----<BR><B>From:</B> Besar Kasianto=20
[mailto:[EMAIL PROTECTED]]<BR><B>Sent:</B> Friday, July 27, 2001 =
10:10=20
PM<BR><B>To:</B> e-WebAuthor<BR><B>Subject:</B> [i-kan-webauthor] =
Keterangan=20
Tentang SirCam32 Virus<BR><BR></FONT></DIV>Originally from : "Besar =
Kasianto"=20
<[EMAIL PROTECTED]><BR>Originally dated: Fri, 27 Jul 2001 21:09:30=20
=
+0700<BR><BR>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<e-WebAuthor>~~~~~~~~~~~=
~~~~~~~~~~~~~~~~~~<BR>~~~~~~~~~~~Forum=20
Diskusi WebAuthoring untuk Kristen-Katholik~~~~~~~~~~~<BR>
<DIV><FONT face=3DArial size=3D2>W32/SirCam@MM Help Center=20
<BR> <BR>DESCRIPTION - What virus is this? <BR> <BR>This is =
a HIGH=20
RISK virus that is spread to email recipients found in the Windows =
Address=20
Book and addresses found in cached files. The infected email can come =
from=20
addresses that you recognize. Attached is a file with two different=20
extensions. The file name itself varies. <BR>The email message can =
appear as=20
follows:<BR>Subject: [filename (random)]<BR>Body: Hi! How are you? =
<BR> I=20
send you this file in order to have your advice<BR>or I hope you can =
help me=20
with this file that I send<BR>or I hope you like the file that I =
sendo=20
you<BR>or This is the file with the information that you ask =
for<BR>See you=20
later. Thanks <BR>--- the same message may be received in Spanish --- =
</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Hola como estas ?<BR>Te mando este =
archivo para=20
que me des tu punto de vista<BR>or Espero me puedas ayudar con el =
archivo que=20
te mando<BR>or Espero te guste este archivo que te mando<BR>or Este =
es el=20
archivo con la informaci=F3n que me pediste<BR>Nos vemos pronto,=20
gracias. <BR> </FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial =
size=3D2><BR> <BR> <BR> <BR>PAYLOAD - What=20
can this virus do? <BR> <BR>When run, the document will be saved =
to the=20
C:\RECYCLED folder and then opened while the virus copies itself to=20
C:\RECYCLED\SirC32.exe folder to conceal its presence and creates a =
registry=20
key value to load itself whenever .EXE files are executed. <BR>The =
virus=20
searches for .GIF, .JPG, .JPEG, .MPEG, .MOV, .MPG, .PDF, .PNG, .PS, =
and .ZIP=20
files in the MY DOCUMENTS folder and attempts to send copies of these =
documents to email recipients found in the Windows Address Book and =
addresses=20
found in cached files. =
<BR> <BR> <BR> <BR> <BR>DETECTION=20
AND REMOVAL <BR>- How can I detect and remove this virus?=20
<BR> <BR> McAfee.com VirusScan and Clinic users, =
<BR> click=20
here to update ActiveShield. <BR> <BR> Retail McAfee =
VirusScan=20
users, <BR> click here to get the latest DAT file. =
<BR> <BR>Scan=20
Your System for Infected Files <BR>McAfee.com VirusScan Online and =
Clinic=20
users, click here to perform a Scan. <BR>If W32/SirCam@MM is found, =
use the=20
delete option to remove it. <BR> <BR>Manual Removal</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>If you are unable to use the =
W32/SirCam@mm=20
standalone removal tool, see: (<A=20
=
href=3D"http://www.mcafeeb2b.com/naicommon/avert/avert-research-center/t=
ools.asp#sircam">http://www.mcafeeb2b.com/naicommon/avert/avert-research=
-center/tools.asp#sircam</A>)=20
SCRMOVE2.zip, then you need to remove the worm manually. Directions=20
follow.</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>IMPORTANT: Users with 24-hour =
Internet=20
connectivity and/or those on a network need to disconnect the =
computer from=20
these sources. Follow the removal procedures for all computers as =
well as the=20
server. Before reconnecting computers to the network or Internet, =
shared files=20
and/or drives should be password protected or have sharing disabled=20
altogether. Contact your network administrator for assistance and =
advice=20
concerning file sharing.<BR>Edit the Registry</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Copy Regedit.exe to Regedit.com: =
<BR>Windows=20
95/98 users: Click Start, point to Programs, and click MS-DOS Prompt. =
<BR>Windows ME users: Click Start, point to Programs, point to =
Accessories,=20
and then click MS-DOS Prompt. <BR>Windows NT/2000 users: <BR>Click =
Start, and=20
click Run. <BR>Click Browse, and browse to the \Winnt folder. =
<BR>Double-click=20
the Command.com file, and then click OK. <BR> <BR>Type the =
following and=20
then press Enter: <BR>copy regedit.exe regedit.com =
<BR> <BR>Backup the=20
Registry</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Click on the Start button. <BR>Click =
on Run.=20
<BR>Type REGEDIT.com in the Open field. <BR>Click the OK button. The =
Registry=20
Editor window will appear. <BR>Click on the Registry pull-down menu. =
<BR>Click=20
on Export Registry File. <BR>In the File Name field type "backup" =
(without the=20
quotation marks). <BR>In the Save In field be sure that the desktop =
is=20
selected (if it is not, click on the pull down menu and select =
"Desktop").=20
<BR>Select "All" in the Export Range group box. <BR>Click on the Save =
button.=20
The registry will then be saved. <BR>Click the X in the top right =
corner to=20
close the Registry Editor. <BR>NOTE: You now have a backup of your =
Registry=20
saved as "backup" on your desktop. If you need to restore the =
Registry you can=20
double-click on the "backup" file located on the desktop. Once these=20
instructions are complete and everything is running properly be sure =
to delete=20
this backup file by right-clicking on it then left-clicking on Delete =
from the=20
pop-up menu that appears. This will ensure that the old registry is =
not=20
accidentally restored once the worm has been removed. =
</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2><BR>Remove the Worm Entries from the =
Registry</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>As you go through this process, you =
will be asked=20
to confirm each change. Make sure that the change is correct, then =
confirm=20
each change. </FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Click the Start button. <BR>Click on =
Run.=20
<BR>Type in REGEDIT.com in the Open field. <BR>Click the OK button. =
The=20
Registry Editor window will appear. <BR>Click on the plus sign next =
to=20
HKEY_CLASSES_ROOT. <BR>Click on the plus sign next to exefile. =
<BR>Click on=20
the plus sign next to shell. <BR>Click on the plus sign next to open. =
<BR>Single-click on command so it is highlighted. <BR>On the right =
side of the=20
screen is a Name column and a Data column. Locate and right-click on =
(Default)=20
under the Name column. <BR>A pop-up menu will appear. Left-click on =
Modify.=20
<BR>The Edit String dialog box will appear with the value =
highlighted. Delete=20
all text in the Value and type the following characters (WITHOUT THE=20
BRACKETS): ["%1" %*] If you are unsure of how the characters should =
be, the=20
following is a spelled out version of the correct characters: quote,=20
percentage, one, quote, space, percentage, asterisk. <BR>Click the OK =
button=20
to close the Edit String dialog box. <BR>On the left side of the =
screen click=20
on the minus sign next to open. <BR>Click on the minus sign next to =
shell.=20
<BR>Click on the minus sign next to exefile. <BR>click on the minus =
sign next=20
to HKEY_CLASSES_ROOT. <BR>Click on the plus sign next to =
HKEY_LOCAL_MACHINE.=20
<BR>Click on the plus sign next to SOFTWARE. <BR>Single click on the =
SIRCAM=20
folder so it is highlighted, then hit delete. <BR>Click the plus sign =
next to=20
Microsoft. <BR>Click the plus sign next to Windows. <BR>Click the =
plus sign=20
next to CurrentVersion. <BR>Single click on the RunServices Folder so =
it is=20
highlighted. <BR>On the right side of the screen is a Name column and =
a Data=20
column. Under the Name column locate and single-click on Driver32 =3D =
C:\WINDOWS\SYSTEM\SCam32.exe so it is highlighted. <BR>Press the =
Delete key on=20
the keyboard to remove the entry. <BR>Close the Registry Editor by =
clicking=20
the X in the top right corner. <BR>Scan to Remove the Worm =
:</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Connect to the Internet. <BR>Go to =
<A=20
href=3D"http://www.mcafee.com">http://www.mcafee.com</A>. <BR>Enter =
your=20
password and email address, and click the Login button. <BR>Near the =
top-left=20
of the page, locate the "Site Shortcuts" drop-down menu. <BR>Click =
the=20
drop-down arrow and choose Scan, from under VirusScan Online. A new =
page will=20
then load. <BR>Click the "Start" link in the box: Current users click =
here to=20
start. <BR>If you are using this service for the first time you will =
then see=20
a page with a "Start Download" link. Click on the "Start Download" =
link to=20
download the necessary components. <BR>In the Scan In box select the =
drive you=20
would like to scan (C: drive, etc). Then click the Scan button =
located in the=20
lower right corner. <BR>The program will then scan the selected drive =
for=20
viruses. If a virus is found a notification will appear in the Scan =
Results=20
box. Delete infected files if they cannot be cleaned. =
<BR> <BR>Windows ME=20
Info:</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>NOTE: Windows ME utilizes a backup =
utility that=20
backs up selected files automatically to the C:\_Restore folder. This =
means=20
that an infected file could be stored there as a backup file, and =
VirusScan=20
will be unable to delete these files. If the scan turns up an =
infected file in=20
the C:\_restore folder follow these instructions to remove the =
infected=20
files.</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Disabling the Restore =
Utility</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Right click the My Computer icon on =
the Desktop.=20
<BR>Click on the Performance Tab. <BR>Click on the File System =
button.=20
<BR>Click on the Troubleshooting Tab. <BR>Put a check mark next to =
"Disable=20
System Restore". <BR>Click the Apply button. <BR>Click the Close =
button.=20
<BR>Click the Close button again. <BR>You will be prompted to restart =
the=20
computer. Click Yes. NOTE: The Restore Utility will now be disabled.=20
<BR>Browse to the C:\_Restore folder and remove the infected files. =
<BR>NOTE:=20
To re-enable the Restore Utility, follow steps 1-9 and on step 5 =
remove the=20
check mark next to "Disable System Restore". The infected file's are =
removed=20
and the System Restore is once again active. </FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Check the Autoexec.bat =
file:</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>No reference to the worm may be =
found here, but=20
it is best to double check.</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Click Start, and click Run. <BR>Type =
the=20
following, and then click OK. <BR>sysedit</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>The MS-DOS Editor =
opens.</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2><BR>A screen with 5 windows stacked =
will open.=20
The first window will be the Autoexec.bat window. <BR>Search for the =
following=20
line(no quotations): "@win \recycled\sirc32.exe" <BR>Delete only this =
portion=20
if you find it. <BR>Click File and then click Save. <BR>Exit the =
MS-DOS Editor=20
<BR> <BR>Empty the Recycle Bin:</FONT></DIV>
<DIV> </DIV>
<DIV><FONT face=3DArial size=3D2>Do not simply click on "Empty =
Recycle Bin" as you=20
would normally. You must use Windows Explorer to delete the file=20
C:\Recycled\Sircam.sys if it is present. =
<BR> <BR></FONT></DIV>I-KAN=20
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% =
e-WebAuthor<BR>Permulaan=20
hikmat adalah takut akan TUHAN! Mazmur 111:10a / Amsal=20
=
9:10a<BR>---------------------------------------------------------------=
--------<BR>WEB-->=20
=
http://hub.xc.org/scripts/lyris.pl?enter=3Di-kan-webauthor<BR>SUBSCRIBE-=
->=20
To: [EMAIL PROTECTED], Isi/Body: =
kosong<BR>UNSUBSCRIBE-->=20
To: [EMAIL PROTECTED], Isi/Body: kosong=20
</BLOCKQUOTE>
I-KAN %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% e-WebAuthor<BR>
Permulaan hikmat adalah takut akan TUHAN! Mazmur 111:10a / Amsal 9:10a<BR>
-----------------------------------------------------------------------<BR>
WEB--> http://hub.xc.org/scripts/lyris.pl?enter=i-kan-webauthor<BR>
SUBSCRIBE--> To: [EMAIL PROTECTED], Isi/Body: kosong<BR>
UNSUBSCRIBE--> To: [EMAIL PROTECTED], Isi/Body: kosong
</BODY></HTML>
------_=_NextPart_001_01C13673.FB5AB7D0--
--------------InterScan_NT_MIME_Boundary--