Michael, run this scan and post the log so that we may see the items to fix. We are a bit blind atm..
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Michael, you have what appears to be a vundo infection, and probably it changes filenames at each startup. So let's try this tool first:
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
Post with a fresh hijackthis log, please.
[Malware reg entries and running files:]
O4 - HKLM\..\Run: [lphcvepj0el1n] C:\WINDOWS\System32\lphcvepj0el1n.exe
O4 - HKLM\..\Run: [SMrhcrepj0el1n] C:\Program Files\rhcrepj0el1n\rhcrepj0el1n.exe
C:\WINDOWS\System32\lphcvepj0el1n.exe
C:\Program Files\rhcrepj0el1n\rhcrepj0el1n.exe
C:\WINDOWS\System32\pphcvepj0el1n.exe
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300