You're still actively getting malware after 3 weeks of cleaning. We can't get a virus scan, so please do the following- we need to consider that you may have a file infector:
- Make sure to use Internet Explorer for this
- Please go to VirSCAN.org free on-line scan service
- Copy and paste each of the following file paths into the "Suspicious files to scan" box on the top of the page, one at a time:
c:\windows\system32\userinit.exe
c:\windows\explorer.exe
c:\window\system32\svchost.exe
- Click on the Upload button
- If a pop-up appears saying the file has been scanned already, please select the ReScan button.
- Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
- Paste the contents of the Clipboard in your next reply.
**************
Bobbeye, Here you go: the results from virscan.org:
VirSCAN.org Scanned Report :
Scanned time : 2007/12/18 17:56:20 (GMT)
Scanner results: 3% Scanner(s) (1/36) found malware!
File Name : userinit.exe
File Size : 24576 byte
File Type : MS-DOS executable (EXE), OS/2 or MS Windows
MD5 : 39b1ffb03c2296323832acbae50d2aff
SHA1 : e5aedcbe25a97c89101f1f3860ff846e94d70445
Online report :
http://r.virscan.org/62673f4534c08297ca39ada792786a86
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 3.0.0.126 2007.12.17 2007-12-17 3.50 -
AhnLab V3 2007.12.18.00 2007.12.18 2007-12-18 3.22 -
AntiVir 7.6.0.45 7.0.1.117 2007-12-18 10.48 -
Arcavir 1.0.4 200712180958 2007-12-18 14.54 -
AVAST! 1.0.8 071217-0 2007-12-17 4.00 -
AVG 7.5.49.442 269.17.1/1183 2007-12-13 5.05 -
BitDefender 7.60825.960468 7.16370 2007-12-19 16.07 -
CA (VET) 9.0.0.143 31.3.5385 2007-12-18 10.61 -
ClamAV 0.91.2 5172 2007-12-19 0.21 -
Comodo 2.11 2.0.0.377 2007-12-18 0.83 -
CP Secure 1.1.0.655 2007.12.18 2007-12-18 23.80 -
Dr.Web 4.44.0.9170 2007.12.18 2007-12-18 17.12 -
ewido 4.0.0.2 2007.12.18 2007-12-18 1.98 -
F-Prot 4.4.1.52 20071217 2007-12-17 5.50 -
F-Secure 5.51.6100 2007.12.18.06 2007-12-18 22.40 -
Fortinet 2.81-3.11 8.449 2007-12-03 0.29 -
ViRobot 20071218 2007.12.18 2007-12-18 0.43 -
Ikarus T3.1.01.15 2007.12.18.70010 2007-12-18 1.46 -
JiangMin 10.00.650 2007.12.17 2007-12-17 1.33 -
Kaspersky 5.5.10 2007.12.18 2007-12-18 23.20 -
KingSoft 2007.6.20.249 2007.12.19 2007-12-19 1.41 -
McAfee 5.2.00 5187 2007-12-17 8.22 -
mks_vir 2.01 2007.12.18 2007-12-18 23.59 -
NOD32 2.70.10 2730 2007-12-18 0.01 -
Norman 5.91.08 5.90 2007-12-17 32.34 -
Panda 9.04.03.0001 2007.12.17 2007-12-17 3.12 -
Trend Micro 8.500-1001 4.894.08 2007-12-18 0.04 -
Prevx V2 20071218 2007-12-18 7.65 TROJAN.DOWNLOADER.GEN
Quick Heal 9.00 2007.12.17 2007-12-17 2.66 -
Rising 19.0 20.23.12.00 2007-12-18 1.84 -
Sophos 2.49.1 4.21 2007-12-13 27.54 -
Symantec 1.3.0.24 20071217.003 2007-12-17 0.23 -
nProtect 2007-12-18.00 1094216 2007-12-18 4.84 -
The Hacker 6.2.9 v00162 2007-12-17 1.71 -
VBA32 3.12.2.5 20071218.1224 2007-12-18 7.16 -
VirusBuster 4.3.19:9 9.117.6/11.0 2007-12-18 14.01 -
*************************************************************************
VirSCAN.org Scanned Report :
Scanned time : 2011/07/19 14:04:28 (BST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 1032192 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a0732187050030ae399b241436565e64
SHA1 : 69f33740413da112630be73ebb805a23b69f2f7f
Online report :
http://r.virscan.org/a19605ad9cedaacbceed0c762a76ffc9
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.3 20110719205213 2011-07-19 10.43 -
AhnLab V3 2011.07.19.00 2011.07.19 2011-07-19 17.24 -
AntiVir 8.2.6.16 7.11.11.208 2011-07-19 0.53 -
Antiy 2.0.18 20110718.11225872 2011-07-18 0.02 -
Arcavir 2011 201107140423 2011-07-14 0.01 -
Authentium 5.1.1 201107190026 2011-07-19 2.53 -
AVAST! 4.7.4 110719-0 2011-07-19 0.07 -
AVG 8.5.850 271.1.1/3774 2011-07-19 0.27 -
BitDefender 7.90123.8559723 7.38349 2011-07-19 4.23 -
ClamAV 0.97.1 13329 2011-07-19 0.01 -
Comodo 4.0 9429 2011-07-18 10.16 -
CP Secure 1.3.0.5 2011.07.18 2011-07-18 0.00 -
Dr.Web 5.0.2.3300 2011.07.19 2011-07-19 14.01 -
F-Prot 4.6.2.117 20110718 2011-07-18 1.65 -
F-Secure 7.02.73807 2011.07.18.05 2011-07-18 0.21 -
Fortinet 4.2.257 13.455 2011-07-19 0.58 -
GData 22.1346 20110716 2011-07-16 0.11 -
ViRobot 20110719 2011.07.19 2011-07-19 0.41 -
Ikarus T3.1.32.20.0 2011.07.19.78866 2011-07-19 4.67 -
JiangMin 13.0.900 2011.07.18 2011-07-18 19.97 -
Kaspersky 5.5.10 2011.07.19 2011-07-19 0.25 -
KingSoft 2009.2.5.15 2011.7.19.9 2011-07-19 6.01 -
McAfee 5400.1158 6411 2011-07-18 17.99 -
Microsoft 1.7000 2011.07.19 2011-07-19 4.18 -
NOD32 3.0.21 6303 2011-07-18 0.01 -
Norman 6.07.10 6.07.00 2011-07-18 16.57 -
Panda 9.05.01 2011.07.18 2011-07-18 3.33 -
Trend Micro 9.200-1012 8.298.09 2011-07-19 0.04 -
Quick Heal 11.00 2011.07.19 2011-07-19 1.56 -
Rising 20.0 23.67.01.05 2011-07-19 0.40 -
Sophos 3.20.2 4.66 2011-07-19 7.06 -
Sunbelt 3.9.2497.2 9900 2011-07-18 0.78 -
Symantec 1.3.0.24 20110718.017 2011-07-18 0.11 -
nProtect 20110719.01 3568544 2011-07-19 9.55 -
The Hacker 6.7.0.1 v00257 2011-07-18 0.77 -
VBA32 3.12.16.4 20110718.1959 2011-07-18 7.67 -
VirusBuster 5.3.0.4 14.0.129.0/56582802011-07-19 0.00 -
*****************************************************************************************
VirSCAN.org Scanned Report :
Scanned time : 2007/08/23 00:04:49 (BST)
Scanner results: 3% Scanner(s) (1/29) found malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : MS-DOS executable (EXE), OS/2 or MS Windows
MD5 : 8f078ae4ed187aaabc0a305146de6716
SHA1 : da39a3ee5e6b4b0d3255bfef95601890afd80709
Online report :
http://r.virscan.org/8f078ae4ed187aaabc0a305146de6716
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 3.0.0.123 2007.08.22 2007-08-22 5.41 Trojan.Win32.Patched.aa
AntiVir 7.4.1.63 6.39.1.34 2007-08-22 2.32 -
Arcavir 1.0.4 200708221242 2007-08-22 1.17 -
AVAST! 1.0.8 000767-4 2007-08-22 3.04 -
AVG 7.5.48.442 269.12.2/967 2007-08-22 1.39 -
BitDefender 7.60825.814226 7.14452 2007-08-23 2.94 -
CA (VET) 8.4.0.24 31.1.5080 2007-08-22 0.83 -
ClamAV 0.91.1 4032 2007-08-23 0.01 -
Dr.Web 4.33 2007.08.23 2007-08-23 4.74 -
ewido 4.0.0.2 2007.08.22 2007-08-22 2.08 -
F-Prot 3.16.16 2007.08.22 2007-08-22 0.41 -
F-Secure 5.51.6100 2007.08.22.09 2007-08-22 2.40 -
Ikarus T3.1.1.12 2007.08.22.69383 2007-08-22 1.30 -
JiangMin 10.00.650 2007.08.21 2007-08-21 0.70 -
Kaspersky 5.5.10 2007.08.23 2007-08-23 0.03 -
KingSoft 2007.6.20.249 2007.8.22 2007-08-22 0.82 -
McAfee 5.1.00 5103 2007-08-22 0.71 -
mks_vir 2.01 2007.08.23 2007-08-23 1.85 -
NOD32 2.70.8 2476 2007-08-22 0.01 -
Norman 5.91.04 5.90 2007-08-22 3.01 -
Panda 9.00.00 2007.08.22 2007-08-22 4.05 -
Trend Micro 8.500-1001 4.665.00 2007-08-21 0.04 -
Quick Heal 9.00 2007.08.22 2007-08-22 2.21 -
Rising 19.0 19.37.22.00 2007-08-22 1.43 -
Sophos 2.47.0 4.19 2007-08-23 2.81 -
Symantec 1.3.0.24 20070822.009 2007-08-22 0.24 -
nProtect 2007-08-22.01 36942 2007-08-22 9.61 -
VBA32 3.12.2.2 20070822.0417 2007-08-22 0.69 -
VirusBuster 4.3.19:9 9.099.1/11.0 2007-08-22 0.92 -