Restart in 'Safe' mode and run Regedit to remove the 'Run' key. Run 'Malwarebytes' to remove the infection, deleting all found files. Also ran SP3 update from a previous download.
Restart and attempt to install AVG, midway through install Zone Alarm pops up a warning a file is attempting to connect out, I Deny it, the Defender icon reappears on the desktop, the Defender window opens, killing the AVG install, and I'm back at square one.
Where is the 'Run' key that I missed?
Where is the source of the infection that Malwarebytes misses?
Looking at your posting http://www.bleepingcomputer.com/forums/topic34773.html and will try running DDS Tool to see what it finds immediately after next round, will run in Safe after Malwarebytes, then again after normal restart to compare the two.
If he didn't already have schoolwork on it I would Reformat and start over clean.
Any assistance will be greatly appreciated.
Edited by hamluis, 10 August 2011 - 09:43 AM.
Moved to Am I Infected from XP.