Anyone seen this malware? Name is all numbers
Posted on 2011-10-06
I boot into safe mode (without networking). I have a process running named 513554315:1959289825.exe. That is the only odd looking name in the list of processes. I can't find a file with a similar name. I did find 2 entries in the registry and deleted them, restarted into safe mode and it is still there.
I can't kill the process.
As soon as I try to run Malwarebytes, ComboFix or RKill (even RKill named iexplore.exe), the shortcut for that program turns to the white page, as if the file with the icon can't be found.
I'm hoping to determine how to clean this up, as I recently reformatted a different computer due to a similar looking malware.
Any help is much appreciated.