readme.exe - Dangerous

%sysdir%\readme.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%sysdir%\readme.exe
We suggest you to remove %SysDir%\readme.exe from your computer as soon as possible.
%SysDir%\readme.exe is W32.Racita.A.
W32.Racita.A is a worm that copies itself to mapped drives D through H. It also attempts to lower security settings on the compromised computer.
Related files:
Temp%\[RANDOM FILE NAME].bat
%Windir%\system32\readme.exe
C:\Documents and Settings\All Users\Application Data\foto.jpg
%DriveLetter%\foto.jpg
%DriveLetter%\desktop.ini
Kill the process %SysDir%\readme.exe and remove %SysDir%\readme.exe from Windows startup.

Remove readme.exe now!