See:
http://securityresponse.symantec.com...love.4099.html for an explanation.
What's most likely happening is that the virus had initially spread to other machines, either via the network or by shared media, and the cleansed machines are now getting reinfected from a source or sources that didn't get properly/thoroughly cleansed.
In other words, you probably missed something; you should go back and thoroughly scan all possible media onto which the virus could have copied itself. This could include floppies or CD that have been distributed, backup media, etc.
Remember that the virus bypasses normal filesystem security and can modify the kernel itself, so don't assume that the virus couldn't possible have gotten into a given location.
Reputation Points: 221
Solved Threads: 369
Wombat At Large
Offline 6,439 posts
since Dec 2003