John, see my previous post about how to filter this.
To clean it off a users system simply delete the registry
key that it creates.

The worm will add the following registry key: 

HKLM/Software/Microsoft/Windows/CurrentVersion/Run/tpawen 

To remove the worm from memory, remove the above registry key
and then restart.  Delete any files associated with the virus.

Dusty


> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of John Philbin
> Sent: Wednesday, December 22, 1999 7:14 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] anyone else get hit by this
> stuart.messagemates.com
> Importance: High
> 
> 
> I would be interested in seeing your well working rule for filtering and
> trapping this thing before it goes further. I am also assuming that this
> rule would need to be applied to each of the   20 virtual servers 
> we operate
> or can it be applied once as a global rule that would work for all the
> virtual servers?
> 
> Some user have already been hit by this virus. What can be done to clean
> this off of their systems?
> 
> Thanks,
> John

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to