Tried AVG, Spybot S&D, Spyware Doctor, Malwarebytes, ComboFix...varying success, seems to have crippled the virus to the point that it's barely (if any) doing anything. I didn't run them all at the same time to avoid any problems they might have with each other
RootkitRevealer still shows a hidden registry listing called ovfsthxxyiqxfai under HKLM\SYSTEM\ControlSet001\Services and HKLM\SYSTEM\ControlSet002\Services
Right after ComboFix finishes running (ie. after the reboot part of it), I'm able to find a few files inside Windows\system32\ with the same naming scheme (ovfsthxlrepapja.dll, ovfsthxslrrvruk.dll, and ovfsthxfqsipjnd.sys) that disappears after a reboot if ComboFix wasn't the one rebooting. They are all "in use" and can't seem to be removed.
I've been getting redirected to a besttopnet and a poiskin.ru site with half my links in google search results, but it seems rather random at which one gets redirected and I had no problems getting to any antivirus sites so far
I got the virus after installing an infected file (it showed clean when I scanned it before installing) 2 days ago, scanned and killed it off for the most part (minus what's been listed), and I figured it was just crippled remains that won't can't anything since scans aren't picking up any more alterations and HijackThis didn't pick up any hidden processes. Yesterday I had a popup saying a1.exe has encountered an error when trying to run (found that file in Windows\system32\ shortly after, very recently created.) Since I wasn't running anything at the time other than more repeat scans, I'm seeing if I can try and clear off the remains too.
Edit: Moved topic from XP to the more appropriate forum. ~ Animal
Edited by Animal, 21 April 2009 - 05:08 PM.