Hi Andrew, On Friday, November 30, 2001, Andrew P Stenz wrote:
APS> When the Bat checks mail, it creates a temp file in APS> Documents and settings>"Name">Local Internet..>Temp [...] APS> found no other viruses. it only appers during those few secs APS> when checking mail. APS> Any ideas? What Markus said is one solution, but it's one that doesn't work for me. One account receives over 10 mb of mail a day, so that is polled every 5 minutes otherwise the inbox om the server is full. :( I have the same problem and I've been looking at the account that receives the virusses. In the log it says: +30-11-2001, 19:48:32: FETCH - connected to POP3 server +30-11-2001, 19:48:36: FETCH - authenticated (plain) *30-11-2001, 19:48:38: FETCH - 1 messages in the mailbox, 1 new !30-11-2001, 19:48:50: FETCH - [Inbox] could not store message (file name - C:\WINDOWS\TEMP\bat260.TMP) +30-11-2001, 19:48:51: FETCH - connection finished - 1 messages received *30-11-2001, 20:03:32: FETCH - receiving mail messages +30-11-2001, 20:03:32: FETCH - connected to POP3 server +30-11-2001, 20:03:32: FETCH - authenticated (plain) *30-11-2001, 20:03:33: FETCH - 1 messages in the mailbox, 1 new !30-11-2001, 20:03:34: FETCH - [Inbox] could not store message (file name - C:\WINDOWS\TEMP\bat3212.TMP) +30-11-2001, 20:03:34: FETCH - connection finished - 1 messages received And the log of mcAfee says: 30-11-2001 19:03 Infected Marcel C:\WINDOWS\TEMP\BAT31F4.TMP W32/BadTrans@MM 30-11-2001 19:19 Infected Marcel C:\WINDOWS\TEMP\BAT21E5.TMP W32/BadTrans@MM 30-11-2001 19:33 Infected Marcel C:\WINDOWS\TEMP\BAT1202.TMP W32/BadTrans@MM 30-11-2001 19:33 Infected Marcel C:\WINDOWS\TEMP\BAT1202.TMP W32/BadTrans@MM 30-11-2001 19:38 Deleted Marcel C:\WINDOWS\TEMP\BAT31F4.TMP W32/BadTrans@MM 30-11-2001 19:38 Deleted Marcel C:\WINDOWS\TEMP\BAT21E5.TMP W32/BadTrans@MM 30-11-2001 19:38 Deleted Marcel C:\WINDOWS\TEMP\BAT1202.TMP W32/BadTrans@MM 30-11-2001 19:38 Delete Error Marcel C:\WINDOWS\TEMP\BAT1202.TMP W32/BadTrans@MM 30-11-2001 19:48 Infected Marcel C:\WINDOWS\TEMP\BAT260.TMP W32/BadTrans@MM 30-11-2001 19:48 Deleted Marcel C:\WINDOWS\TEMP\BAT260.TMP W32/BadTrans@MM 30-11-2001 20:03 Infected Marcel C:\WINDOWS\TEMP\BAT3212.TMP W32/BadTrans@MM 30-11-2001 20:03 Infected Marcel C:\WINDOWS\TEMP\BAT3212.TMP W32/BadTrans@MM 30-11-2001 20:03 Deleted Marcel C:\WINDOWS\TEMP\BAT3212.TMP W32/BadTrans@MM 30-11-2001 20:03 Delete Error Marcel C:\WINDOWS\TEMP\BAT3212.TMP W32/BadTrans@MM So mcAfee sees the virus in the On-Access-Scan, blocks the file, The Bat can't import the temp-file and ignores it, and then the temp file if deleted. I was worried too, but it seems that On-Access-Scanning and the bat are working well together <grin> I received over 50 infected mails in the last two days on only one account and thank God these two programs are doing their job. Yesterday one mail slipped by, but ZoneAlarm already renamed the extension, so no harm could be done :)) Hope this answers your question. -- Cheers, Marcel... ________________________________________________________ PGP Key ID: 0xADB5413E PGP Key: mailto:[EMAIL PROTECTED]?Subject=SendPGPKey ... Some people lose their head just as easy as their hat. ________________________________________________________ Using TB! v1.53d on Windows 98 4.90 Build 3000 (ME) -- ________________________________________________________ Archives : http://tbudl.thebat.dutaint.com Moderators : mailto:[EMAIL PROTECTED] TBTech List: mailto:[EMAIL PROTECTED] Unsubscribe: mailto:[EMAIL PROTECTED] Latest Vers: 1.53d FAQ : http://faq.thebat.dutaint.com

