Note: It is not reccomended that you connect to the internet if you are
infected with the worm! As the worm and/or personal files will be
transmitted to any email address' on your system.
** REGISTRY **
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
DELETE "Driver32" "c:\windows\system\scam32.exe"
HKEY_CLASSES_ROOT\exefile\shell\open\command
MOODIFY Reference to SirC32.exe to ""%1"%*"" (where the most
outer quotes are
placed for you)
Delete all hidden files in c:\recycled
SirC32.exe
DC0.exe
Possibly more files, delete them all.
'attrib' command can be used in dos to unhide files "
attrib -h c:\recycled\*.* "
If you locate "run32.exe" in your \system folder then rename it to
replace "rundll32.exe"
DELETE "C:\windows\system\SCam32.exe"
REMOVE the line " @win\recycled\SirC32.exe " form your AUTOEXEC.BAT if present
Restart
System