Wees maar blij met die melding, als je die NU namelijk NIET zou krijgen heb je waarschijnlijk het “W32/Yaha.aa@MM” virus. Is eigenlijk een WORM.
Je virusscanner heeft dat bestand dus fijn gewist en nu staat er ergens bij het opstarten nog ergens een verwijzing naar die file. Dit gebeurt in je REGISTRY.
Dus even met REGEDIT op de commandline (RUN onder START) zoeken naar de file(s) en verwijderen. Tip : Maak EERST een backup van je registry (zowieso altijd handig!)
Helaas even in het Engels, maar dat moet je maar even in het NL vertalen :
Citaat:
When executed on the local system, it runs silently, no gui message boxes appear and it is also not visible in the windows task manager process list. It copies itself , for example on a Win2000 system, to
c:\winnt\system32\cmde32.exe
c:\winnt\system32\mexplore.exe
To call itself at startup registry entries are made under
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
To enable the running of the viral code, whenever a regular executable file is called, it changed the content of
HKCR\exefile\shell\open\command
Strings within the worm suggest outgoing messages are intended to contain two Internet Explorer vulnerabilities (IFRAME and incorrect MIME header) in order to run itself when the recipient previews the email (on unpatched systems). See Microsoft Security Bulletin MS01-020 for more information and a patch concerning these exploits.
Je kan alles verwijderen als je SYSTEM RESTORE even uitschakelt : Zie hier…