What a nasty little bug you've gotten there.
btw, wauclt.exe should be Windows AutoUpdate service, (unless that virus replaced it, which doesn't sound entirely unlikely since you indicate the virus apparently replaced your cthelper.exe, which is part of Creative Labs software package).
Bitdefender has taken a very strong interest in this new bug which their best efforts cannot cure. They are calling it a variant of Trojan Downloader.Agent .AE
and until now it has only been identified in China and Hong Kong, and S.Korea but here is no bug killer for it yet.
It comes in through infected e-mail or Cd rom's and then sets itself up to execute at the very first time you strike the delete key on it. There it sends itself to the C:\Recycled and C:\SystemVolume Information\_restore files.
Every time you boot up it lanches a program and sets itself in Documets and Settings\AllUsers which downloads bugs on start-up.
It then attempts to change the registry while you are on-line or booted up. It installs folders in Docs & Settings and there it loads dummy progs that launch icons and messages saying automatic downloads are taking place, click ok.
It's the same little globe icon that Microsoft uses.
If you click ok you'll notice that there might be two little globes in your taskbar. I clicked away the inactive globe thinking it was left open from last-time or just a glitch.
That was my mistake.
Now in the taskmngr there are two wcault.exe's...one is WCAULT.EXE running from HKEY-HKEY_LOCAL_MACHINE\Software\Microsoft\WINDOWS\Current Version\Run and Run Services
The other from C:\Docs&Settings\Local User\Standard\....
and as soon as it loads it brings tskmger.exe with it..and that is a v rus program.
The only thing protecting the machine right now is Diamond's Registry protector which alerts me whenever a change is being attempted in the registry. So I can deny the virus access to the sytem but I cannot kill it.
Dell is coming to pick it up and see what the problem is...install a new registry or HDD..[its a Dimension XPS and doesn't have IDE so they can't diagnose it without bringing it back to the UK..since the Dutch don't know anything about the new Dimensions....]
Will let you know how it goes.
Thanks again.
-Zohar
will let you know.