For a while, I'd noticed my anti-virus/malware program of choice, TrendMicro Internet Security, acting a little flaky. I felt a vague uneasiness about it but didn't follow up with any action. Then a few days ago, the XP Antivirus 2012 rogue showed up. I attempted to manually clean it, part of which was implementing fixNCR.reg, and it appears to be cleaned. However, I'm now noticing the following: Random web page redirects Ping frequently showing up in Task Manager I've been running full scans of TrendMicro the last several days, but it looks like it's not catching all of it. Before reading the 5-step Viruses/Spyware/Malware Preliminary Removal Instructions, I ran the ESETOnlineScan. The ESET scan provided the following results: C:\WINDOWS\system32\drivers\mrxsmb.sys a variant of Win32/Rootkit.Kryptik.GG trojan C:\WINDOWS\Temp\gggf0.3063122403800338.exe a variant of Win32/Kryptik.XEQ trojan C:\WINDOWS\Temp\nnnv0.5353880183464179.exe a variant of Win32/Kryptik.XEQ trojan C:\WINDOWS\Temp\ogogbk\setup.exe a variant of Win32/TrojanDownloader.Delf.POH trojan E:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\37\303814a5-654be69d multiple threats E:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\53\78e403b5-55d6c4a9 a variant of Win32/Kryptik.WZK trojan E:\Documents and Settings\Mark\My Documents\Downloads\Nero-188.8.131.52_eng_trial.exe Win32/Toolbar.AskSBar application E:\Documents and Settings\Mark\My Documents\Downloads\Nero-184.108.40.206_eng_update.exe Win32/Toolbar.AskSBar application Operating memory multiple threats I'm working on the Malwarebytes, GMER, and DDS scans now and will provide them in my next reply.