Page 2 of 2

Posted: Mon Aug 16, 2004 15:49
by Jeremy_
by the way,
- this can happened.
- it's easy to clean.
- I'm sure that Bart and Edwin will solve this issue very quickly !

Posted: Mon Aug 16, 2004 15:54
by goebish_
PURGE YOUR NAVIGATOR CACHE BEFORE DOWNLOADING THE NEW FILE !!!

Posted: Mon Aug 16, 2004 15:56
by thomas_
got it!

Posted: Mon Aug 16, 2004 16:05
by Jeremy_
GOT IT TOO !!

- I confirm: no more virus.
and congratulation to Bart and Edwin for solving the W32/Pate.b issue so quickly.

Posted: Mon Aug 16, 2004 21:34
by metaprofessor_
if the registry key is not present (windows xp), does that mean my system is definitely NOT infected? i also scanned the installer i d.l.'d with the latest symantec AV.

Posted: Mon Aug 16, 2004 21:54
by Jeremy_
metaprof'

if you download the installer after 16h30
(amsterdam time) you should not have any problems.

the key:
HKEY_CURRENT_USERSoftwareMicrosoftWindows
CurrentVersionExplorerPINF
is a proof that you are infected.
but not having the key, does not mean that you do not have W32/Pate.b on your HDD.
only a full Scan inluded the PE and UPX can tell you if you are or not infected.

you can download for free the Stinger tool from McAfee:
http://www.mcafee.com > entreprises > security HQ
> tools > Utilities > Stinger v2.3.9
Stinger is small. does not need an installation.
GOOD advice:
1. configure stinger to not clean the virus but just inform you about it.
This will inform you about the gravity of your issue.
2. make a list of the possible file to restore.
3. second scan with a clean option.

But I will be very surprise, that you've get infected if you had download the file after 16h30.
Bart and Edwin did a great job to have this issue solve very quickly.

For info: There is NO MORE virus on the installer available for download at this time.

Posted: Tue Aug 17, 2004 04:27
by metaprofessor_
i did an SHA hash of the file i downloaded and one for the new installer, and they're identical. leads me to believe i don't have the virus. i'm gong to d.l. the stinger thing now. thanks!