Gurus,
I've been fighting a spyware infection of some kind for the past couple of days, but I cannot run Spybot, HiJack This, or ComboFix on the machine. In addition, Symantec Antivirus has not updated since January. The machine is currently disconnected from the network, and even in Safe Mode, something prevents any of these programs from running.
Task Manager shows a brief bump in processing time for explorer.exe when I attempt to run Spybot, so I suspect that the infected DLL may be one of the many DLLs supporting that process. (Then again, this could just be explorer.exe's normal processing while it attempts to locate the file. Thoughts?)
In regard to Spybot specifically, whatever process monitors the program renames the SpybotSD.exe, SBupdate.exe, and TeaTimer.exe files to random filenames with the extension .SCR and then marks them as hidden. This happens no matter what folder I install to.
Following the suggestions in other messages, I have run the miniremoval_coolwebsearch_smartkiller.exe tool, and it finds no trace of CWS. I have also run the CWSshredder.exe app and the problem still persists. Unfortunately, since I can't run HiJack This, I can't provide a log.
I did run the Webroot Spysweeper evaluation program, which detected "trojan-relayer-highport." I removed that manually.
Any suggestions would be greatly appreciated.
Thanks,
Stace Johnson