Hi,
Got nailed with a whole series of virus and spyware crap a few weeks back. Have managed to remove almost all of it, but now have something that does not look right.
Every time I boot up, a new tmp file is created with a random name and it starts as a process and immediately tries to get internet access. File is always a 3 or 4 letter/number combination name with a .tmp file type and sits in the c:\windows\temp directory. I have tried to kill it with process task manager and process explorer but neither can. I can rename the file but not delete it directly from the directory. The parent process is the winlogin.exe and its user is the NT Authority System. The file is recreated with the same date 16 March (the infection date) and size 40kb - After a bit of googling this sounds like a worm but not sure.
Have run spybot, adaware and norton antivirus but they have not identified this as an issue, but I seem to get messages about smitfraud.c everytime even though it is 'removed' after each check. At least Zone Alarm is stopping the internet connection...
Any ideas?
Got nailed with a whole series of virus and spyware crap a few weeks back. Have managed to remove almost all of it, but now have something that does not look right.
Every time I boot up, a new tmp file is created with a random name and it starts as a process and immediately tries to get internet access. File is always a 3 or 4 letter/number combination name with a .tmp file type and sits in the c:\windows\temp directory. I have tried to kill it with process task manager and process explorer but neither can. I can rename the file but not delete it directly from the directory. The parent process is the winlogin.exe and its user is the NT Authority System. The file is recreated with the same date 16 March (the infection date) and size 40kb - After a bit of googling this sounds like a worm but not sure.
Have run spybot, adaware and norton antivirus but they have not identified this as an issue, but I seem to get messages about smitfraud.c everytime even though it is 'removed' after each check. At least Zone Alarm is stopping the internet connection...
Any ideas?