PPRuNe Forums - View Single Post - w32/badtrans/mm
Thread: w32/badtrans/mm
View Single Post
Old 1st December 2001 | 18:42
  #17 (permalink)  
fobotcso
 
Joined: Jun 2000
Posts: 1,003
Likes: 0
From: Geriatrica, UK
Thumbs down

I've just dis-infected a Win98SE PC running Norton Anti-Virus that hadn't been updated for two years! It was badly infected and had e-mailed dozens of victims, some of who were telephoning to complain. There were 40 automatic returns from Servers of e-mails this PC had sent out.

Norton was too unfriendly so I put McAfee in its place and it worked like a dream; ran a scan on all files and it found the culprit in Kernel32.dll. Couldn't clean it so it (McAfee) deleted it (as it claimed). Found the file still there when I tried to load a fresh version into the \System folder.

I can't normally delete a system file in use by the system so can McAfee have done so? Didn't have time to rescan the disk but that would show if the file was still infected.

The mail Servers appear to have caught up now and the flood of these e-mails is drying up.
fobotcso is offline