I found this little blue box last week in the upper left corner of my display on my PC at work. Once I dragged it to the open desktop, it appears to be a "window" roughly 1/4 inch wide and 1/2 inch deep. After researching my task manager, I was able to link it to iexplore.exe; of course, I wasn't running the browser at that time. This has now been found on nearly 300 PCs in my company over the past 7 days. It's evading my antivirus signatures. It evades Spybot. I've found nothing recent about this on any website. These infected PCs have exe files stored in the D&S\Username\Application Data folder. There are various names but all are 404,992 bytes. Some of the names are:
Lsas.exe
Event.exe
Svchosts.exe
Helper.exe
Upnpsvc.exe
Service.exe
Rundll.exe
Msiexeca.exe
Logon.exe
Dumpreport.exe
Sound.exe
Taskmon.exe
Once I stop IExplore and delete the file(s), it doesn't appear to come back. Does anyone know if this is a 2008 recurrance of an old issue?
Thanks in advance.
Lsas.exe
Event.exe
Svchosts.exe
Helper.exe
Upnpsvc.exe
Service.exe
Rundll.exe
Msiexeca.exe
Logon.exe
Dumpreport.exe
Sound.exe
Taskmon.exe
Once I stop IExplore and delete the file(s), it doesn't appear to come back. Does anyone know if this is a 2008 recurrance of an old issue?
Thanks in advance.