Hi and welcome to TSF.
Let's see if we can restore a bit of normality first, then we'll tackle the rest.
Firstly, let's reset System Restore, so that we have something to fall back on, just in case.
To turn off System Restore click Start > Right Click My Computer > Properties. Click the System Restore tab and
Check "Turn off System Restore" or
"Turn off System Restore on all drives" Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.
To turn on System Restore by Clicking Start. Right-click My Computer, and then click Properties. Click the System Restore tab.
Uncheck "Turn off System Restore" or
"Turn off System Restore on all drives." Click Apply, and then OK.
This will create a new Restore Point.
This tool should be run in Normal Mode - it's very simple and fairly quick - just follow the instructions.
Please download
combofix.exe to your
desktop.
IMPORTANT - You must place combofix on your desktop!!
Double click
combofix.exe & follow the prompts.
When finished, the tool will produce a log for you at
c:\combofix.txt.
Post that log in your next reply.
Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.
One of your infections is hiding and we need to make it visible. So, before producing your next HijackThis Log, please follow these instructions:
I'd like you to
rename HijackThis.exe (the actual
.exe file itself) to
glasgow.exe.
- Navigate to C:\hjt\HijackThis.exe (or wherever HJT is located - if it's in a Temp file then move it))
- Right click on HijackThis.exe
- Select 'Rename'
- Type in glasgow.exe
- Press Enter.
Now run a scan and save a log as normal.
Please post back with
c:\combofix.txt and a fresh,
renamed HijackThis log.