Is anyone aware of a worm that behaves as follows:
Somehow, a batch file, c.bat, and a file called " .pif" are present in the windows\system32 directory. The .pif file contains a script to ftp to a server ( in this case, it was a local machine on my network) and download a file called spsc.exe This is invoked through c.bat, after which point c.bat and .pif are deleted. I have yet to determine what, if any, harm is done by this worm.