John, see my previous post about how to filter this.
To clean it off a users system simply delete the registry
key that it creates.
The worm will add the following registry key:
HKLM/Software/Microsoft/Windows/CurrentVersion/Run/tpawen
To remove the worm from memory, remove the above registry key
and then restart. Delete any files associated with the virus.
Dusty
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of John Philbin
> Sent: Wednesday, December 22, 1999 7:14 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] anyone else get hit by this
> stuart.messagemates.com
> Importance: High
>
>
> I would be interested in seeing your well working rule for filtering and
> trapping this thing before it goes further. I am also assuming that this
> rule would need to be applied to each of the 20 virtual servers
> we operate
> or can it be applied once as a global rule that would work for all the
> virtual servers?
>
> Some user have already been hit by this virus. What can be done to clean
> this off of their systems?
>
> Thanks,
> John
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.