And I have quite same issue as Smithy 2009
I did some action and I am looking for help now:
- first I disconnect the internet connection leaving le PC in stand alone and run a complete Norton analysis (no virus found) and highjackthis
- then with an other PC I did research on internet and download "Malwarebyte" from your site
- and i intalled it from a usb key to the infected PC.
- but after correct intallation nothing happened when I run it.
At this point, I tried several thing unsuccessfull with "Malwarebyte"
- reconnect to internet and install it
- boot PC in safe mode install it
- install an other anti malware like "spyware doctor"
- even "spyboat SD" already installed can't be run!
- of course I had continuously "malware defense" windows pop-up
- And I noticed that firefox was not anymore the default navigator
- after a while things were getting worse,"Malware defense" started to down load something so I promptly disconnect internet wire before the end.
Therefore, I tried some internal action to stop but not to cure.
- I discover from Hijacklog that all the stuff is in C:\Documents and Settings\Propriétaire\Local Settings\Temp
- I uninstall "Malware defense" with windows add/supp program
- I zipped separatly and copied ...\Local Settings\Temp\ files on usb key and erased files , except "wscsvc32" and "richtx64" (they are locked)
- I disabled "richtx64" from startup list with "msconfig"
Now I look the "test.reg" vicius files , it is still regenerated from nowhere ! and it seems changing registerDB deeply.
So coming back to the begining could you give me a help in order to run "Malwarebyte"
I attached hjt log ( see line 26-27 and 51-52-53) and the test.reg ( see lot of register about IE)