It's very insidious and even pops up bogus windows when I try to log into my bank account to try and get my credit card and ssn. The file in question is kfmsfb.sys in windows\system32\drivers. Of course I can "find" the rootkit with malwarebytes and at least one other spyware program, but they can't remove it. I saw how Broni helped someone else get rid of a similar rootkit on another thread. I have already run combofix and can post it when someone is available. I know I will need help pasting the right information from that in to a text file to run against combofix again. I can see the locked registry keys in the log. Anyway, hope someone can jump in on this. Next step is reinstalling the OS if I can't get rid of this.