Author Topic: infected kernel32.exe  (Read 1476 times)

Anonymous

  • Guest
infected kernel32.exe
« on: December 12, 2001, 08:14:41 PM »
have infected files of kernel32.exe and kdll.dll on my drive.
how can i delete/remove and replace with clean files,and where can i dowmload from?

i think i can get dll from dll star,but the .exe,i`m at a loss.

came along with badtrans

 any help would be mucho appreciated

Offline rdc

  • enthusiast
  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 372
  • Karma: +0/-0
    • View Profile
infected kernel32.exe
« Reply #1 on: December 13, 2001, 03:00:32 AM »
Read this link and you\'ll find the answer to your  question :
Badtrans.b details .
http://vil.mcafee.com/dispVirus.asp?virus_k=99069&

Offline The_Flames

  • enthusiast
  • Sr. Member
  • ****
  • Posts: 290
  • Karma: +0/-0
    • View Profile
infected kernel32.exe
« Reply #2 on: December 13, 2001, 06:40:03 AM »
when dealing with a virus it\'s usally a good idea to supply the virus name if you have it, the method you got infected if known, and what antivirus package found it http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Offline rdc

  • enthusiast
  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 372
  • Karma: +0/-0
    • View Profile
infected kernel32.exe
« Reply #3 on: December 13, 2001, 08:27:35 AM »
Reading his message I see Badtrans , that is supposed to be the virus (most probably badtrans.b )
The two files he refers to do not belong ito his OS  but to the virus (see my link) .

Lurker

  • Guest
infected kernel32.exe
« Reply #4 on: December 17, 2001, 11:01:57 AM »
Just had that one at work a few days ago.  It is BadTrans, a key logging virus.  Just delete those files, no need to replace.  They were never actually windows systems files.  And delete the key in the Run folder for windows in the registry.

Or just go to symatec and download the removal tool that will do it all for you.