What was the name of the vir*s?  If Norton caught it, then you
should not be having any problems.  I can't find that file name
anywhere, so it must be some randomly created name by the v*rus.
I'd scan your PC here, http://housecall.trendmicro.com/  and also
boot off the Norton AV floppy disk.  Let those methods see if
they can clean it up.  I do find a winexec32 file and looks yours
might be a back door Trojan, at least it appears to be in this
case:
http://www.megasecurity.org/trojans/m/mosucker/Mosucker3.0a.html

See if you can find any keys in the registry with winexec32 in
them.  What OS is this?

You need to be sure Norton is running AT ALL TIMES, except for
when you scandisk, defrag, or install something.  Before anything
is installed and you're not familiar with the software, it should
be scanned.  All AV programs should be set to "scan ALL files"
and not just program files.  Most are set to ONLY scan program
files by default with their "real time scanner".  Most are set to
'scan all files' by default for manual scanning (like when you
right click and scan the file).
-Clint

God Bless Us All
Clint Hamilton, Owner
Want to exchange links with us?
http://OrpheusComputing.com �

----- Original Message -----
From: "Mike H" <[EMAIL PROTECTED]>

Long story short ok?
The kids loaded a program and Norton caught a vi*us. No problem
but the
program left behind a file in windows directory called
winexec32.com. Zone
alarm stop it from being a server and accessing the internet but
I'd like to
get rid of it. Of course it loads it's self even if I go into the
system
configuration utility and uncheck it. It has it's self as a
system file and
I can't change that. Went into dos and tried to change it with
"attrib" but
it can never find the file.

Wow any ideas? It is appreciated.

Thanks Mike
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to