Randomly named file in system32 directory

  • Thread starter Thread starter Jeffrey Parker
  • Start date Start date
J

Jeffrey Parker

It appears my machine has been hijacked by some kind of
Browser hijacker. I have popups like mad and nothing from
spyware info or any of the anti spyware programs seem to
eliminate this program. The program has the following
characteristics:

Its in the system32 directory
its a randomly named exe file
its 449KB in size
If i delete the file it regenerates itself with a new
random name.
it adds itself to the HKLM\SOFTWARE\Microsoft\Current
Version\Run key
if i delete the key manually it regenerates itself within
seconds

It appears to allow an automatic popup system to function.

If you've seen this or have any ideas about how to
eliminate it, I'd really appreciate the advice. BTW the
way I've posted this in this group as I have no idea what
the security impilcations of this behavior are, but they
seem pretty bad.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top