S
sjb
Hi all,
I'm at my wits end on this one...does anyone know how the above virus is
transmitted? And how to prevent it from coming back?
I have a client whose machine I have cleaned of this virus...but it keeps on
coming back. She has XP, using IE6. I have run updates (16 of them including
SP1). Symantec states that the way it gets in is through a port opening, so
I figured that running the updates would take care of that. It shows up with
Norton detecting it in the windows\system32\....IE\temp folder, but it
cannot clean or quarantine it~ (access denied)! I find many occurances of
the wkspatch.exe (which is the virus itself) and manually remove them, also
the svchost.exe payload (for lack of a better term) and delete them~! I have
run the removal tool supplied by Symantec of which it finds the virus also
and removes it. I can run a complete system scan and come up with NOTHING,
yet later that afternoon, or the next day, she will have the virus again!
Note: her pattern of the virus showing up seems to be when she is on the New
York Times web site...hence my suspicions that it is coming in via the web.
Any input someone can supply would be GREATLY appreciated!
Sincerely,
Scott
I'm at my wits end on this one...does anyone know how the above virus is
transmitted? And how to prevent it from coming back?
I have a client whose machine I have cleaned of this virus...but it keeps on
coming back. She has XP, using IE6. I have run updates (16 of them including
SP1). Symantec states that the way it gets in is through a port opening, so
I figured that running the updates would take care of that. It shows up with
Norton detecting it in the windows\system32\....IE\temp folder, but it
cannot clean or quarantine it~ (access denied)! I find many occurances of
the wkspatch.exe (which is the virus itself) and manually remove them, also
the svchost.exe payload (for lack of a better term) and delete them~! I have
run the removal tool supplied by Symantec of which it finds the virus also
and removes it. I can run a complete system scan and come up with NOTHING,
yet later that afternoon, or the next day, she will have the virus again!
Note: her pattern of the virus showing up seems to be when she is on the New
York Times web site...hence my suspicions that it is coming in via the web.
Any input someone can supply would be GREATLY appreciated!
Sincerely,
Scott