Hi,
After system cleaning, I discover in c:\users\UserName\AppData\Local\Temp a
..exe file of 258048 bytes (252 KB exactly)
Without problem, I override this file using eraser, but another file with
another name appears (a .dll file this time)
Each time, the filename looks like a windows system name, (dmintf.dll,
WlS0WndH.dll, kbdur1.dll .......). The names seems to be taken randomely
from system32.
I have submitted today one of these files to virustotal, and I got nothing.
I ran processexplorer, and this tool show me that these files in my tempdir
are hooked to winMail.
Does anyone have the same behavior ??
/Philippe


Reply With Quote