Had to get away from it for a while, but it's time to fix this thing. I restarted the computer which is automatically set to run Spyware Doctor upon start-up. This time, there were only 10 infections (in lieu of the 11 infections I was getting last week) Here are the results of the scan:
Scan Results
There are 1 threat(s) and 10 infection(s) in your computer
Threats - High - Trojen.Generic (10 infections)
Process
-alg.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-pctsSvc.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-jusched.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-jqs.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-spoolsv.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-svchost.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-svchost.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-svchost.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
-svchost.exe (\\?\globalroot\Device\_max++>\BDE7E0D0.dll)
File
Trojan.Generic detected in \\?\GLOBALROOT\DEVICE\_MAX++\BDE7E0D0.DLL
Upon completion of the scan, I get the message:
Restart Required
Smart Update needs to restart Spyware Doctor in order to install new updates, do you wish to continue Yes/No
This occurs before I have the opportunity "Fix Checked" so I have to decide weather to update or fix virus infections! Aghhh!!!
Here goes...
1. Select [No] to Restart request - Message box closes normally
2. Select Fix Checked (No Restore Point requested) - SD reports that all infections successfully removed! At this point, another message window pops up and again warns:
Reboot Required
Spyware Doctor requires a Windows Reboot to complete the removal of some infections. Would you like to reboot now?
3. Select [Yes] to Reboot Request... System appears to reboot normally, and Spyware Doctor begins it's intelli-scan on system boot.
4. Before SD finishes Intelli-scan, the Restart Required pop-up appears - select [No]
5. This time there is 1 threat (Trojan.Generic) and 12 infections.
The File has changed to \\?\GLOBALROOT\DEVICE\_MAX++\EE5347D0.x86.dll,
...and two new processes have been added to the list, Update.exe and TFService.exe.
6. Select [Fix Checked] - Once again, the SD app says all infections successfully removed, and again the Reboot Required pop-up has returned.
I could continue this circle all week, but it isn't getting me any closer to fixing this problem.
7. Select [No] to Reboot Request. - Select [Finish] and close Spyware Doctor.
8. Load Internet Exporer and check for Windows Updates... when I attempt to go to update page, the page can't be found... press F5 to reload the page, and I'm redirected to various other paid sites! (btbar.com, etc) Obviously being redirected.
Finally got Automatic Updates App to pop-up for about 5 seconds, then disappear.
The update.exe process is visable in Task Manager, but if I try to End this process, it immediately returns, so I assume this is one of the infected processes detected by SD earlier.
9. Close Task Manager, and rerun SD - SD still wants to reboot, but I will re-scan first...
This time, there is tne threat (Trojan.Generic) and 6 infections. The root file is still EE5347D0.x86.dll, and the processes are spoolsv.exe, pctsSvc.exe, and 3 svchost.exe processes.
Select [Fix Checked] - Same results... successful removal... reboot required.
Exit SD without rebooting.
Attempt to run HJT... program loads, looks as though the program is compiling the list, but before anything can be written, the program crashes, and it's like it never ran. If I try to re-run HJT, I get
C:\Program Files\Trend Micro\HijackThis.exe.
Windows cannot access the specified device, path, or file. You might not have th appropriate permissions to access the item.
This is very frustrating. Won't someone please give me an idea of where to turn next? I've spent many hours on this computer, and am feeling beaten for the first time! HELP!