I am quite an advanced user, I only use a Windows Admin account for Admin task which makes it harder for viruses to take hold and I usually spot them.
However, the other day a popup launched from a website and run an Exe file from the web, it was stange in that the EXE file had the same name as much PC Machine name. I later found it in the progam data folder and nuked it wilt Malwarebytes
So I have noticed some strange behaviour and wanted to know if anyone else has seen this or is it normal windows operations
I noticed this EXE running in TaskManager with the same name as my Windows User Account, so if my account was A1 or B2 it woulld be
Now it did not seem to be doing much but I have never seen it before and I am always watching my processes so I know what is usual
I scanned all partitions of my disk and can find no exe file of this name
I ran Malwarebytes on all partitions, it found nothing
So I went into Talk Manager and launched Resource Monitor to see what this sucker is up to, this image shows all the reg keys and files it is accessing.
What sticks out is a ZONE access which might suggest it is trying to redirect net traffic and I also saw it is accessing a file in winsxs, which is strange as that
I am able to zap the thing without it being recreated but when I start my PC thers is this delay and then I notice the process in Task Manager.
The only other system change I made was installing a print driver from Brother, not software just the native win driver.
Am I being ultra paranoid or is this some new Win7 feature?
Anyone got any ideas?