Hi,

After system cleaning, I discover in c:\users\UserName\AppData\Local\Temp a
..exe file of 258048 bytes (252 KB exactly)

Without problem, I override this file using eraser, but another file with
another name appears (a .dll file this time)

Each time, the filename looks like a windows system name, (dmintf.dll,
WlS0WndH.dll, kbdur1.dll .......). The names seems to be taken randomely
from system32.

I have submitted today one of these files to virustotal, and I got nothing.

I ran processexplorer, and this tool show me that these files in my tempdir
are hooked to winMail.



Does anyone have the same behavior ??

/Philippe