I have a virus/worm on my laptop (Dell Inspiron 3800, Windows 2000 Pro, Celeron, 296MB RAM). It came from a spam email, from a ZIP attachment that had an exe inside. Stupid, I know. It was from ...@cia.gov, and it went something like this: "Your IP address has been linked to 30 illegal websites" and said a questionnaire was attached. Of course most of you here would delete this as spam instantly, but just to let you know. So here's what it's done: a folder was created inside WINNT called WinSecurity. Inside this folder are copies of 3 services: services.exe, lsass.exe, csrss.exe, maybe another one, and some other files like .dli or something. 2 registry keys have been created, one in Local Machine/Software/Microsoft/Current Version/Run, the other in Current User and same path. They are: run WINNT/WinSecurity/services.exe. If I delete these keys, they return immediately. Tiny Personal Firewall keeps popping up saying: "...Noticed that the file lsass.exe has been replaced. Do you accept this?" Over and over. And a window saying "Windows could not open the file LSASS.exe". I can operate the computer otherwise; I have to move these. In the task manager, I see "lsass.exe" and "LSASS.exe" and the same for the others. Which one is the fake one? One of them tried to connect to something in the UK but Tiny stopped it. So, as Windows thinks these executables are services, I can't stop them via Task Manager and I can't delete them. Antivirus: I have the Avast! free home version, latest virus updates 20.11 (Nov. 20th) and apparently this virus isn't in it, as it didn't pick it up in a scan. I could wait until Avast updates next, which could a few days, or somehow remove these **** things manually, but I don't know how. Any advice would be greatly appreciated.