In addition, I revisited my original thread and followed Steamwiz's instructions he passed. I've also used the Blacklight rootkit tool, and the Rootkit Revealer. I was able to track down a couple of issues, and I was able to move into SafeMode and remove them, but as it is now there is something on my system that none of these steps has been able to resolve or remove. My AVG will pop up with a virus detected in my Temp Internet folders/content.ie5 and even though I remove it, heal it, quarantine it, a few minutes later it will reappear.
Not only that, but my IE has been hijacked since I use Firefox and set my homepage on IE to blank. it sends me to: http://www.yoursecuritysystem.com/
I have fixed the BHO setting as per the additional spyware instructions for Ads234, Midaddle, or Netspry spyware pieces and still nothing.
Here is my Hijackthis log, and I will be re-running both Blacklight and Rootkit and posting those logs in a moment.
*Edit* I've been doing some work to try and get rid of this problem. I'm going to update my logs:
Logfile of HijackThis v1.99.1
Scan saved at 3:16:14 AM, on 1/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s0 12/18/2005 9:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s1 12/18/2005 9:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s2 12/18/2005 9:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\g0 12/18/2005 9:14 AM 32 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\h0 12/18/2005 9:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 12/22/2005 3:30 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\#SharedObjects 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\#SharedObjects\AW8N9RR8 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\macromedia.com 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\macromedia.com\support 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys 1/22/2006 3:31 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 1/22/2006 3:31 AM 348 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Microsoft\MSN Messenger\1969937433\MapFile\TFR1B9.dat 12/10/2005 12:13 AM 9.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Microsoft\MSN Messenger\1969937433\MapFile\TFR7.dat 1/22/2006 3:34 AM 10.18 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Microsoft\MSN Messenger\1969937433\UserTile\TFR6.dat 1/22/2006 3:34 AM 20.83 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\0039C971d01 1/22/2006 3:45 AM 248 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\00A03AE2d01 1/22/2006 3:42 AM 49.30 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\038C266Dd01 1/22/2006 3:45 AM 8.03 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\05222A81d01 1/22/2006 3:45 AM 6.65 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\05232A81d01 1/22/2006 3:45 AM 9.53 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\05242A81d01 1/22/2006 3:45 AM 8.25 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\05252A81d01 1/22/2006 3:49 AM 8.11 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\0D6E67C7d01 1/22/2006 3:31 AM 33.40 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\128EAF41d01 1/22/2006 3:43 AM 71.53 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\15FA5885d01 1/22/2006 3:31 AM 40.05 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\175D2038d01 1/22/2006 3:41 AM 32.05 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\1EF111ABd01 1/22/2006 3:31 AM 57.41 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\280083A6d01 1/22/2006 3:31 AM 47.96 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\2840402Ad01 1/22/2006 3:31 AM 53.09 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\28C679A0d01 1/22/2006 3:31 AM 37.49 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\2A0901BCd01 1/22/2006 3:49 AM 45.50 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\2B4DB991d01 1/22/2006 3:45 AM 109.11 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\2BC4878Fd01 1/22/2006 3:31 AM 41.28 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\3163C129d01 1/22/2006 3:31 AM 36.28 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\396FE9E1d01 1/22/2006 3:51 AM 40.97 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\3B19977Fd01 1/22/2006 3:31 AM 42.68 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\411B82C4d01 1/22/2006 3:52 AM 10.74 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\411B85C5d01 1/22/2006 3:49 AM 10.74 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\41AF8EA6d01 1/22/2006 3:31 AM 93.65 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\4356F911d01 1/22/2006 3:45 AM 72.48 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\44A9779Bd01 1/22/2006 3:46 AM 21.57 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\45F94B96d01 1/22/2006 3:52 AM 101.13 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\4F0F882Ad01 1/22/2006 3:31 AM 53.68 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\4FF54F9Bd01 1/22/2006 3:41 AM 19.53 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\545D65A5d01 1/22/2006 3:31 AM 7.12 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\545E65A5d01 1/22/2006 3:31 AM 4.36 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\54E8E939d01 1/22/2006 3:52 AM 6.23 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\59F7643Cd01 1/22/2006 3:31 AM 38.33 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\5C610BDFd01 1/22/2006 3:31 AM 35.46 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\5CF65DCCd01 1/22/2006 3:31 AM 33.07 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\5D020423d01 1/22/2006 3:31 AM 64.51 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\5DA47DCDd01 1/22/2006 3:31 AM 30.32 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\63150996d01 1/22/2006 3:51 AM 85.09 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\644B2730d01 1/22/2006 3:45 AM 1.11 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\645D8B3Ad01 1/22/2006 3:41 AM 92.87 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\6B013529d01 1/22/2006 3:31 AM 38.46 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\6C251CEBd01 1/22/2006 3:48 AM 45.79 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\6D38E36Dd01 1/22/2006 3:45 AM 1.38 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\77610869d01 1/22/2006 3:46 AM 44.14 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\77AB3538d01 1/22/2006 3:31 AM 37.97 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\7E0857B5d01 1/22/2006 3:31 AM 46.52 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\8A016EC9d01 1/22/2006 3:31 AM 63.78 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\8D353529d01 1/22/2006 3:31 AM 40.66 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\9709357Ed01 1/22/2006 3:31 AM 52.01 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\98CC9788d01 1/22/2006 3:31 AM 71.23 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\9A3808EEd01 1/22/2006 3:31 AM 34.55 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\9FE3A4F1d01 1/22/2006 3:50 AM 43.61 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\A4F164EDd01 1/22/2006 3:45 AM 5.67 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\A5F931E5d01 1/22/2006 3:51 AM 9.46 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\A5F937E4d01 1/22/2006 3:52 AM 9.46 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\A70B8EBFd01 1/22/2006 3:45 AM 11.19 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\AC14A396d01 1/22/2006 3:31 AM 50.95 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\BBE0C2B3d01 1/22/2006 3:42 AM 37.29 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\BD97C810d01 1/22/2006 3:31 AM 32.96 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\BEBDCE08d01 1/22/2006 3:43 AM 23.72 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\C12C39B9d01 1/22/2006 3:52 AM 104.77 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\C152627Dd01 1/22/2006 3:31 AM 70.16 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\C9AB1FBAd01 1/22/2006 3:43 AM 84.62 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\CCA59722d01 1/22/2006 3:45 AM 106.05 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\DA04AF02d01 1/22/2006 3:41 AM 53.24 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\DC9648F9d01 1/22/2006 3:31 AM 70.90 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\DEFD1B10d01 1/22/2006 3:42 AM 41.41 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E00D3E25d01 1/22/2006 3:31 AM 36.85 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E371E727d01 1/22/2006 3:52 AM 4.45 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E378E727d01 1/22/2006 3:50 AM 4.85 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E37AE727d01 1/22/2006 3:49 AM 4.51 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E37BE727d01 1/22/2006 3:49 AM 4.79 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E37CE727d01 1/22/2006 3:45 AM 4.46 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E37DE727d01 1/22/2006 3:45 AM 4.45 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\E37FE727d01 1/22/2006 3:45 AM 4.45 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\EA10B6F1d01 1/22/2006 3:45 AM 4.98 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\EAD83615d01 1/22/2006 3:49 AM 102.90 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\EC9FEFA8d01 1/22/2006 3:31 AM 31.92 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\F47851F8d01 1/22/2006 3:31 AM 52.66 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\F54D627Fd01 1/22/2006 3:45 AM 26.03 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\F6059BFAd01 1/22/2006 3:42 AM 90.97 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\F8C83CF5d01 1/22/2006 3:41 AM 59.31 KB Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\FA34B368d01 1/22/2006 3:43 AM 33.18 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\FAA7BD19d01 1/22/2006 3:48 AM 43.86 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Application Data\Mozilla\Firefox\Profiles\s7sq7jj3.Default User\Cache\FFCF6206d01 1/22/2006 3:43 AM 21.79 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Local Settings\Temp\plugtmp 1/22/2006 3:48 AM 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Recent\MSN Messenger.lnk 1/22/2006 3:34 AM 540 bytes Hidden from Windows API.
C:\Documents and Settings\Layna.RU2K5-Y6BK8X80Q\Recent\tachikoma.lnk 1/22/2006 3:34 AM 722 bytes Hidden from Windows API.
C:\Program Files\MSN Messenger\tachikoma.jpg 1/22/2006 3:32 AM 47.96 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\LD7F9E.TMP-13EAB219.pf 1/22/2006 3:39 AM 18.00 KB Hidden from Windows API.
C:\WINDOWS\system32\1024\ld7F9E.tmp 1/22/2006 3:38 AM 5.68 KB Visible in Windows API, but not in MFT or directory index.
#1 BMG - I am not running both sets of AVs. The Norton AV stuff listed is for System Works.
#2 I already did exactly what you suggested 5 times now. The temp file name changes in my sys32 folder, nvctrl returns, mssearchnet.exe won't stay deleted, and folder 1024 keeps returning too. This last time the annoying windows update/stop sign icon appeared in my system tray, even in SafeMode.
I've already installed and run Ewido, and I'm looking over the forums for the latest information. I've even looked through my registry while in SafeMode.
Thank you for the assistance. Any other suggestions?
*Edit* I've already tried the removal of the trojan.zlob and have turned off System Restore until this is removed.
Okay. I've spent some time and had to manually edit my registry and delete files. There was much google searching involved, and hopefully with the new Zonealarm firewall and other systray things it will help to avoid many problems in the future.
Ewigo, Hijackthis, AVG were all extremely valuable tools in assisting to relieve me of my problem.
Hard to believe a girl can edit her own registry huh? =)
Don't want to close this thread just yet. I will leave it open a few days incase the problem comes back.
On my comment about Norton/Symantec services: They have so many versions really hard to tell exactly what you have. If you look at your log, you can see how many entries that are Norton/Symantec.
If you are going to stay with AVG and Zone alarm, I would get rid of every relating to Norton/Symantec. My personal opinion, shared by many here, "Norton" is nothing more than a resources hog. However there are people that like it. I used it for 2 years, then dumped it.
Every thing you need is available for free, which is all I use, here: