Hi.

Spybot reported Elitum.Elitebar.Pokapoka on a scan some days ago. The item that was found:
Documents and Settings\name\Local Settings\Temp\~setuptmp0\irsetup.exe.

Spybot removed irsetup.exe. After the next bootup, I had a look in the temp folder. The removed file was back! Now it had a slightly different location:
Documents and Settings\name\Local Settings\Temp\irsetup.exe.
The file was signed Indogo Rose Corporation, and "Setup Factory 6.0 Runtime Module" was mentioned in its properties.

I deleted it.


I experienced something else recently which I find strange: A shortcut to Skype was created on the desktop. No one else had physically access to this pc...