Thanks for responding Tux,
I've emptied the temp folder and done the seek and destroy tactic with
wmplayer.exe, except the rogue version is named slightly different
mplayer.exe, and even has the old media player 2 name and icon in the properties.
I've used FileAlyzer to look it over and it's been disguised very well as genuine Microsoft material (not surprising, as they've simply rewritten part of it to serve their purpose).
Problem, as with most of these, is that I delete and watch it instantly reappear towards the bottom of the list in the C:\Windows folder, so I'm thinking it has to be linked to something else in my system. The question is: What?
I don't know if any of these have any thing to do with it but, they're from the notepad list I exported from FileAlyzer on the mplayer.exe. Could you tell me your thoughts on these or if there's anything specific you'd like me to look for in the list (the remainder is various code commands I'm not familiar with, but maybe one has a clue to the whereabouts to this thing's friends?):
Export table
Import table (libraries: 7)
KERNEL32.dll (imports: 69)
USER32.dll (imports: 133)
GDI32.dll (imports: 47)
COMCTL32.dll (imports: 3)
SHELL32.dll (imports: 6)
WINMM.dll (imports: 6)
ADVAPI32.dll (imports: 7)
How about any of the other files listed above or the registry fixes, Merijn's variant list states that some registry editing is needed along with replacing wmplayer?