OK srosa has reared it’s head again but it is now deeply hidden
Please download F-Secure Blacklight (fsbl.exe) and save to your C:\ drive.
[*]Open a command window by going to Start > Run and typing: cmd
[*]Copy/paste or type the following in the command window: C:\fsbl.exe /expert
[*]Hit “Enter” to start the program and then close the cmd box.
[*]Accept the user agreement and click “Next”.
[*]Click “Scan”.
[*]After the scan is complete, click “Next”, then “Exit”.
[*]BlackLight will create a log in C:\ drive named “fsbl-xxxxxxx.log” (the xxxxxxx will be the date and time of the scan).
[*]The log will have a list of all items found. Do not choose to rename any yet!
I want to see the log first because legitimate items can also be present…like “wbemtest.exe” and "tcptest.exe.
[*]Exit Blacklight and post the contents of the log in your next reply.
Thanks for the info on that file