readme.exe - Dangerous
%sysdir%\readme.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
%SysDir%\readme.exe is W32.Racita.A.
W32.Racita.A is a worm that copies itself to mapped drives D through H. It also attempts to lower security settings on the compromised computer.
Related files:
Temp%\[RANDOM FILE NAME].bat
%Windir%\system32\readme.exe
C:\Documents and Settings\All Users\Application Data\foto.jpg
%DriveLetter%\foto.jpg
%DriveLetter%\desktop.ini
Kill the process %SysDir%\readme.exe and remove %SysDir%\readme.exe from Windows startup.