Please help me with an infection that just occurred (I have the file). As soon as I attempted an install of a downloaded program, AVG warned me about the infection and the files were/are being recreated continuously and each is considered an infection.
My system is Windows 7, x64 (AMD).
I am in the process of following the steps outlined in "Readme Before Posting".
Files are being continuously being created and deleted in C:\Users\Gary\AppData\\Local\Temp. Also, in c:\Windows\SysWos64, there are random 6-character .exe files being created and not deleted. TaskMgr shows they are executing briefly and then terminating as each starts up a new one (according to procmon). All files have the same timestamp of 8/3/2009 1:39pm. Also, there is one explorer.exe with the same timestamp. In /Windows, there is an explorer.exe stamped with the same date but earlier time. I submitted both explorers to jotti online scan and they are flagged as not infected. They are different sizes.
I will provide the requested files when I have them ready.