Okay, gone thru it all, and I have a few things to touch upon.
First, I noticed that OTL couldn't really run fully on a fix. It worked okay for the initial scan, just not the removal of entries. Having said that, some files/folders have gone over the pages, so I think it did work, even though no log was produced.
Now, I do want to make sure some of the things I was concerned about, have gone.
So, using SystemLook again, like you did before, can you run it with the following code, and post the log:
Code:
:dir
c:\windows\temp
c:\documents and settings\michelle\localsettings\temp
:filefind
*Bomgar*
:folderfind
*Bomgar*
:regfind
proxy.uconn
Bomgar
:reg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\System\CCS\Services\Tcpip\Parameters
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14C63AB7-91F2-4939-82A0-88C6628A5C31}
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23E4F7C4-7DC6-489A-9574-0FF705F312F3}
---------------
Now, looking in the previous installed programs, you have the following. Did you install them?
LogMeIn
TeamViewer
If you did install them, and you definatly don't have anyone prompting you to run them, then that's okay. The two programs above are used for remote viewing of computers. Totally legal tools, but some people may not want then installed.
Now, the following program was showing as installed, but not in AddRemove Programs, least not that I could see:
Bomgar Support Customer Client
This again enables remote connection of computers. What makes me single this one out, is that its not seen in your installed programs, yet it is running. Again, legit tool, but do you know anything about it?
Pretty sure you installed these two, and if so, I'll leave them be:
Domain Name Analyzer
iLinc
-------
You have a few things running from the temp folder, so I've put the search in the above SystemLook code
-------------------
If you can work on the above first, I'll make sure its all okay, then look at rootkit scanners
