hmmm...i don't now what to do with tftp?
its already deleted on both machines, server and client....
and bboy will log me and sent to their chat all data

however,i got it working by doin a
'site exec todo.cmd' via ftp!
the cmd file only contains 'sysclean /nogui /silent /y'

tried on the server,too .. and succeed...

but i would not recomment using trendmicros tool with /nogui parameter if you have one

btw. first you have to delete the shares and/or kick the network.

o.k. it removed two worms but i have to scan there a little bit on net .
any idea wich ports are used? may be 6666 ???

[edit]
found 2 virii,

oooohh....ca.10% of the machines using the same gateway seem to be compromised or hijacked
>> now i do understand ppl creating worms to clean up other worms...
('cos i am unable to reach the hosts..)