Four days ago, behind a locked wifi network on an XP machine, I was using Firefox normally, Googling away. Within 10 minutes, the fake AV popups started (AVSecuritySuite). I checked and was still firewalled, in addition to running Norton Corporate edition (virus definitions last updated 3 or 4 days prior). I immediately disconnected from the network and tried to close the programs, but was prevented from even opening msconfig. I rebooted normal and immediately opened msconfig (it seems there's a delay before the malware runs after a reboot.) I booted into safemode, ran a full AV scan, but nothing was found. I ran spybot and AVSuite, Virtumonde and smitfraud were found. I "removed" through spybot, followed Norton's instructions on how to remove lingering elements (disable sys restore, update virus definitions, run full av scan, deleted the added values to the registry.) I have yet to reenable the system restore because, after those steps, I got google redirects to ad sites. After a few more scans, some noodling around, and a dozen reboots in and out of safe mode, the redirects have stopped, as have the pop-ups. I'd like to get my system safe enough to reenable the system restore point. If you could help me, I would really appreciate it. I followed your 6 removal instructions and the logs are attached. Thanks in advance for your help!