Denne har gjort det for mig:
Removal instructions:
If your system is infected with the worm first please download this REG file and install it (by double-clicking on it):
ftp://ftp.europe.f-secure.com/anti-virus/tools/sirc_dis.reg This will remove the worm\'s reference from the EXE file startup key and the main worm\'s startup key in the Registry.
Warning! The system might become unusable if the worm\'s file is deleted without modifying the EXE file startup key first.
After that the system can be safely disinfected with F-Secure Anti-Virus. If for some reason the worm\'s file can\'t be deleted from Windows (locked file), then you have to exit to pure DOS and delete the worm\'s file manually or use a DOS-based scanner (F-Prot for DOS for example). Note that for 100% disinfection all worm\'s files needs to be deleted and Registry should be fixed (see above).
Additional Note: If a workstation was infected trough a network share \'\\windows\\run32.exe\' has to be renamed back to \'\\windows\\rundll32.exe\' after disinfection.
The extra line in \'autoexec.bat\' file that starts the worm from \\recycled\\ folder should be removed also.
Network infection prevention:
If a network is infected and it is not possible to take it down to disinfect all workstations, the following method can prevent the worm from spreading to clean workstations:
In the \\Recycled\\ folder of a drive where Windows is installed, it is needed to create a dummy file with SIRC32.EXE name and read-only attribute.
NanoQ