It is a Java Script file that copies itself throughout the C drive of the infected computer. It overwrites Autoexec.bat, as well as .vbs and .cmd files. The worm contains a mass-mailing routine and can also spread via mIRC, Pirch98, and vIRC.
Overwrites Autoexec.bat so that %Windir%\wigun.js is executed.
Copies itself to various folders.
Creates lpmvh.vbs, which is a mass-mailing routine.
Adds the value:
"stmha" = "%Windir%\wkfxi.js"
to Windows startup registry keys.
Sends itself by e-mail.
Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.
Delete the worm's files from hard disk.