F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe tapi.nfo beforeglav
F2 - REG:system.ini: UserInit=C:\WINDOWS.0\system32\userinit.exe,C:\WINDOWS.0\system32\sdra64.exe,
So sorry to be the bearer of bad news, but you have a nasty backdoor trojan with rootkit components.
This thing is far worse than Windows Police Pro - If you do any sort of online banking, there is a good chance your info has been compromised. Definitely check your banks, credit cards, etc. and change any passwords.
In cases such as this, I generally recommend a re-format because, even if we are able to clean the machine, you'll never be able to trust it......
PP
Last edited by PhilliePhan; Aug 31st, 2009 at 10:55 pm.
Reputation Points: 169
Solved Threads: 106
Central Scrutinizer
Offline 1,576 posts
since Dec 2006