hi
huh there is still loads of nasties :(
lets try this utility in safe mode
download doctor webs cureit utility from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
once saved right click it to extract it to its own folder
then reboot to safe mode
open the folder where you extracted cureit and doubleclick on drweb32w.exe
once its initial startup scan is over, click file> scan path. browse to your c:\ drive and click OK
the scan will launch
allow it to clean all infections
the report will be at your documents and settings\your userprofile\localsettings\drweb folder. id like to see its contents if possible
after scan is finished and all viruses are cleaned reboot back to normal mode, post the cureit report and a fresh hjt log
also i need these other logs:
1.) Download Blacklight Beta from here:
http://www.f-secure.com/blacklight/try.shtml
Accept agreement which takes you to download page.
Save the file to your desktop.
Close all browser windows and any open programs/folders.
Double click blbeta.exe
Wait a few seconds.....
Check the "I agree"
Click "scan"
Wait for scan to finish
Once done; hit "next" then "close"
Do not use this app to rename files! Sometimes there are legit hidden items.
Post results of log file on desktop called fsbl***.txt (*** is numbers)
2.) Download WinPFind from here:
http://www.bleepingcomputer.com/file...r/WinPFind.zip
Save file and unzip it to C:\
Restart to SAFE mode
Log into your account.
Open c:\WinPFind folder and double click WinPFind.exe
click "configure scan options"
Under "Run ad-ons" checkmark:
"Qoologic.def"
Hit "Apply"
Click "start scan"
This will take a while so please be patient.
It may appear to hang at times cus it is scanning several folders. As long as the hdd light is still flashing....app is working OK.
Once done (it will tell you) a log is created in WinPFind folder called WinPFind.txt
Boot back up to normal windows and post result of log.
Thanks
3.) Prepare for next step:
Download Pocket Killbox from here:
http://www.bleepingcomputer.com/file...re/KillBox.zip
Unzip it to a convenient location.
Don't do anything with it yet. I'll let you what next when you post logs.
good luck