Hi
Thanks for those reports. the mystery file is still remaining/reloading, as you can see. As PAS is reporting so many infections we will try two general/Trojan cleaners.
Make sure you have exposed all Hidden Files & Folders.
To enable the viewing of Hidden files follow these steps:
1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.
***********************
Go back to my earlier post about Killbox. Get it from this link instead ....
http://www.majorgeeks.com/Pocket_KillBox_d4709.htmlNow work through the procedure as I explained before BUT, this time, the file name has changed to ...
C:\WINDOWS\TEMP\LC3D79.EXEHopefully this will allow you to kill off the file.
***********************
If you are on Windows 2000 or XP
Download Ewido/AVG Anti Spyware from here ….
http://www.ewido.net/en/It has a fully working 30 day trial period.
Install it and update it to the latest definitions.
NOW REBOOT to safe mode. Here’s a “how to” if you’re not sure ..
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406When in safe mode run a full system scan with AVGAS and let it fix what it wants to.
REMEMBER TO SAVE THE SCAN REPORT and also remember
where you saved it.
Reboot to normal mode and use the computer as you would usually do.
[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].
***********************
Now download TrojanHunter from here ....
http://www.misec.net/Again, this is a fully working trial version.
Install it and update it to the latest definitions.
Scan your system with it. Let it fix anything it wants to.
Re-hide system files & folders by taking the reverse procedure to that at the start of this post when you exposed them.
Please post back the reports and a fresh HJT log.
OJ