I'd like help to remove a very persistent virus that have been on my sons computer since early this summer and I just can't find how to remove it.
I found on the Internet the it is called W32/Sdbot-ZN as I found this wdfmrg.exe in WINNT/system32 folder
You can't find the process in Task-manager and you can't remove the file, not even in fail safe mode.
also When I check with Security Task manager I find it running two instances of Explorer.exe both in the winnt directory.
One is named Explorer.EXE and the other explorer.exe as you can see there is some difference in lower case nothing else.
When I looked in the WINNT directory I can only see one "explorer.exe" and then something called only "Explorer" that in type says "Windows explorer command" could that be something ?
I wouldn't want to remove it without knowing what I'm doing. :o
Also when I look in task manager - processes I find a CMD.exe running and you get a "access denied" if you try to end it.
The thing is that some virus makes this computer cuts off all network connections to our other computers on out LAN after a few minutes.
But the Internet connection ok stays though. Still it's also makes the computer very slack and everything opens very slow.
Serious help is appreciated :o