I checked Task Manager and noticed that there were at least four seperate instances of Firefox.exe running, and an instance of Excel.exe running even though MS Excel wasn't open anywhere. These instances even ran upon starting up in Safe Mode which started to worry me.
I checked Regedit and browsed to the Winlogon section, and checked the Userinit key. The value was set to "C:\Windows\system32\userinit.exe,,C:\Program Files\ejbatyvw\mpsmhyfn.exe". I tried booting up with a UBCD disc and deleting the registry key and removing the file from the hard drive, however upon rebooting the file was immediately recreated and added to the registry again.
I decided to back up the data on the computer and do a full reinstall of Windows XP, after checking on a seperate computer that the files weren't infected themselves, and that machine seems to be running fine after several restarts and such so I'm feeling fairly safe in that regard. I proceeded to fully format and reinstall on the Thinkpad, but after completing the installation it took only a few minutes before I noticed that several instances of iexplore.exe were running in Task Manager. I checked the registry and lo and behold the random userinit key had been added once more.
This leads me to beleive that there's a virus in the laptop's BIOS or something similarly unaffected by formatting the hard drive. I've already tried downloading and running the BIOS update for that model but the flash utility states "nothing needs done at this time, cancelling the operation".
I'm at my wit's end, and seriously concerned about what I can do now. Any help would be greatly appreciated.
Thanks for your time
Edited by Jeebus, 26 March 2011 - 03:56 PM.