According to ADMN, this virus was found on 11 of 56 systems on my company’s weekly scan last night. The infection has been consistent: 1-3 copies of kernel32.dll on the system that wasn’t the in-use system32 copy. If it was a false positive, I would believe it would’ve appeared on most to all of the systems. The fact that it also infected files not in use is also telling, as well as the fact that Google searches on this virus indicate the false positive outbreak occurring back in January, not April. Use of Firefox vs. IE appears to not be a factor either, unless they tried to run something.

???