Hi, Sorry to hijack the thread, I am facing the same problem, and the virus is spreading like crazy on our network as people share USB's. I did what you said below and this is what the output shows. Can you please giude me what to do next? Seems like this virus is no joke, infected PC's take the whole network down by sending an unbelievable amount of information through the NIC card. Once the machine is unplugged, our network is back up again. See the output below, thanks, Ben p.s. I also noticed that by ending the "explorer" task and restarting it, I am able to delete all contects from the USB drive. However upon reinserting, all comes back. Also when I restart the explorer task, windll.exe shows up in the list of tasks