Hello, I found a service on my system that I couldn’t identify:
WWZS (screenshot)
and a startup driver WZS (screenshot)
The only info I could find is the MS page: http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDropper:Win32/Koobface.N&ThreatID=153386
As far as I can tell the files that MS lists in that page have been removed by Malwarebytes:
\drivers\wzs.sys
\wsz.dll
And I manually removed the wzs driver from hidden devices in device manager.
So if I remove the registry entries as shown in the MS page will that get rid of the service and startup entry?
ps. LivePCsupport did not help resolve this as it was explained how services are generated from the registry but not if this service was malware related or not.
Thanks!
[attachment deleted by admin]