Hello everyone and although I've been using the wonder that is 'Malwarebytes Anti-Malware' for quite some time, I only joined this forum today. The reason being is due to the fact that I ran a full Malwarebytes Anti-Malware scan today and it picked up a worm virus that just won't go away. (I do hope I'm posting in the right section, if not I'm sure you'll move me to the appropriate place.) I've deactivated system restore and tried running a full system scan three times, but the virus remains. It shows up as: - Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3985 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 13/04/2010 23:29:45 mbam-log-2010-04-13 (23-29-45).txt Scan type: Full scan (C:\|D:\|E:\|F:\|) Objects scanned: 48174 Time elapsed: 19 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb (Worm.Waledac) -> Delete on reboot. And going by a few threads I take it the 'Waledac' botnet is well known? http://forums.malwarebytes.org/index.php?s...&hl=Waledac http://forums.malwarebytes.org/index.php?s...&hl=Waledac I'm still not sure how I got infected (I was clean a few days ago), I only use Yahoo Mail and I don't open attachments from anyone I don't know and I've not opened any for ages. So could I have picked this up from a website? Oh and when I've hit the delete button on Malwarebytes, apart from requesting a reboot it also states that it couldn't remove all the files. My HijackThis report appears to be in order though. Apart from that I'd appreciate any advice on how to get it kicked off my computer once and for all.