Hi, I'm in the process of killing off a very sneaky slippery bugger of a Root Kit virus.
Virus protection seem to notice and block when it tries to make changes, but when I go to kill the virus, it backs itself up with randomly named ".tmp" files...
I could block those ".tmp" files using process blocker, but every time the ".tmp" files are executed, they are named differently!
I'm wondering... Is there a way to block the file extension ".tmp" from being executed?
