Thank you for the tip. The truth of the matter is that this program, besides placing itself in the \windows\prefetch area, registers itself as an exception to SP2 firewall and neither Symantec Enterprise, AVG, Avast, AdWare, Microsoft A/S detects them. The major payload is such that it "eats"...