I have picked up a virus which puts Messenger Service warnings on my screen. The virus operates by putting an .EXE file in the WINNT temp diretory the .EXE is named a variation on cf8se3.exe. I can stop its operation for one cycle by changing the .exe to another form ie. .dud but the next reboot the exe has been regenerated as another variation on the name and registry have been accordingly changed and I have to do it again. I don't have the tool to track what file generates the .exe and registry entry. Can you give me any advice? What is this and how do you clean it. Trend office, spybot and adaware all miss it. Thanks