I recently got tagged with a huge influx of viruses embedded in an ad from a trusted site.
Suspicious.MH690
Hacktool.Rootkit
Trojan.Vundo
Trojan Horse
W32.SillyP2P
Those were the ones NAV detected and stopped/deleted.
I immediatly Sys Restored to an earlier point (2 days prior) and did a scan.
It popped up with 10 Suspicious.MH690 in my C:\Documents and Settings\Owner\Local Settings\Temp\ folder
C:\Documents and Settings\Owner\Local Settings\Temp\winlogon.exe
C:\Documents and Settings\Owner\Local Settings\Temp\winamp.exe
C:\Documents and Settings\Owner\Local Settings\Temp\smss.exe
C:\Documents and Settings\Owner\Local Settings\Temp\notepad.exe
C:\Documents and Settings\Owner\Local Settings\Temp\services.exe
C:\Documents and Settings\Owner\Local Settings\Temp\setup.exe
C:\Documents and Settings\Owner\Local Settings\Temp\login.exe
C:\Documents and Settings\Owner\Local Settings\Temp\mdm.exe
C:\Documents and Settings\Owner\Local Settings\Temp\install.exe
C:\Documents and Settings\Owner\Local Settings\Temp\debug.exe
Does that mean all of those .exe files were replaced with infected files and since some of those are required processes, does that mean I need to do a full destructive Sys Restore to get rid of them?