hey ppl, i got a case when my frens got this new virus both my frens were 800km away though (as i remember win32mobler in removeitpro) i installed avast and avg antivirus but neither could detect them, so i use simpler method, remove it pro from incodesolutions.com and it detect that the virus was in the hidden folder system32\12053 named svchost.exe and lsass.exe and also other exes. then i delete the folder with unlocker and successfully *heal* the laptop. but then i found out in the services.msc that, most of the services were stopped and disabled, so i *auto* them with the reference to my healthy pc. no problem, but theres 2 symtomps were seen and i believe they aren't virus. first: theres a note (like VB) in the beginning before entering the password in the welcome screen second: in the main infected account, i still couldnt do RUN and SEARCH also couldnt set the folder option to *show hidden files and some few options. basically, i think that theres an unchecked option i left and i need to delete a file in order to delete the *welcome note* anyone have idea??