Worm W32/Dumaru.j@MM. You are infected by e-mail when you clicked on the attached file. This worm constructs messages using its own SMTP engine. Target e-mail addresses are extracted from files on your computer. A password-stealing trojan is also dropped by the worm: %WinDir%\GUID32.DLL (4096 bytes) WinDir is the "c:\windows" on default. Removal: Delete the next files: %WinDir%\DLLREG.EXE %SysDir%\LOAD32.EXE %SysDir%\VXDMGR32.EXE %WinDir%\Start Menu\Programs\Startup\RUNDLLW.EXE
Sysdir is the Windows\System or Windows\System32 folder.