Hi Beau, here is a link to the Symantec remover; http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.t.html W32.Korgo.T is a variant of W32.Korgo.N. This worm attempts to propagate by= exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability= (described in Microsoft Security Bulletin MS04-011) on TCP port 445. It= also listens on TCP ports 113, 5111, and a random port between 256 and= 8191. Mike ~ one of the Moderators It is a good day if I learned something new. Editor MikesWhatsNews http://www.mwn.ca/ ******* Mike's REPLY SEPARATOR ********* On 3/22/2005 at 5:45 PM beau thompson wrote: hi group I have a friend that has a pc with xp home W32/Korgo.T.worm virus is there a small program that can be used to remove this thanks beau -- <Please delete this line and everything below.> To unsub or change your email settings: //www.freelists.org/webpage/pctechtalk To access our Archives: http://groups.yahoo.com/group/PCTechTalk/messages/ //www.freelists.org/archives/pctechtalk/ For more info: //www.freelists.org/cgi-bin/list?list_id=pctechtalk