I'm sorting through our HJT log DB and I'm finding this process quite a bit but we have it defined as unknown currently... do any of you know what this is? The only references I'm finding it with are logs that have had a trojan so is this something installed by another baddy?