I have a little big problem on many PC's of my office.
It's difficult to exactly explain what happens but I try to ask your help.
I find in winnt directory (windows 2000 professional) a file named as random sequence of characters .exe, that is started on windows boot.
Infact when I search in registry I find this exe, present in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(example: hrzucas C:\WINNT\system32\ikrgyoe.exe r).
When I kill from taskmanager this file, at once it create a new one with a different name.
So, even if I remove the "infected" key from registry, when windows restarts, this key is created again and the "infected" process live.
- We have Symantec Antivirus running on all the PC's, daily updated.
- I analized and clean the PC's with hijackthis, RootkitRevealer, Prevx Gromozon Removal...
- I booted windows from setup CD and under C:\winnt I didn't find the "infected" executable.
I presume that this malware is created on windows startup but I'm not able to discover the creator.
Can Anyone help me?
Thanks in advance
PS. Sorry for my poor english