These instructions came from the Mcafee Virus Information Page:
W32/Jitux.worm
-- Update 31st December 2003 --
This threat is considered to be a Low-Profiled risk due to media attention at:
http://www.web-user.co.uk/news/47502.html
This detection is for a worm intended to propagate via MSN Messenger instant messaging. The worm is written in Visual Basic.
It propagates by sending messages to the MSN messenger contact list. The messages contain a link to the worm itself:
http://www.home.no/( removed )/jituxramon.exe
When the link is clicked, the worm is downloaded to the target machine.
Note: at the time of writing the the worm was unavailable from this URL.
Indications of Infection
Receipt of a MSN messenger message containing a link to the worm as detailed above.
Removal Instructions
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Aliases
Win32/HLLW.Retgeek (GeCAD)
minnie the pink