Steve N. wrote:
Just to add to Steve's good advice - run HijackThis. If you are pretty
computer savvy, you can look at the log yourself. Otherwise, post it to
one of the following forums (not here, please):
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net/viewforum.php?f=30
http://castlecops.com/forum67.html
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/
A very useful tool included in HijackThis (you have to look around for
it - press Config and look for Tools) is a startup list. I've seen it
catch malware that was set to rename itself and start. The startup list
gives enough detail that you can track down the "guard" .dll or
executable and from where the startup instructions are coming so you
can kill it.
Malke