I'll try that. But I'm gonna need all the programs I can find. This seems very "strong" and "consistent". I can't seem to find the stuff to delete.
If it's a RAT, try to kill explorer.exe and/or iexplorer.exe/firefox.exe and make sure they don't appear again. Now go on a hunt in the Win/sys32 map for latest changed files, look for something which shouldn't be there.
Then go and check the registry at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components."
Here you must be really careful what you doing, check carefully on every key with ONLY a value named "stubpath".
Last option: AV, it's not reliable to 100% but you might have some luck. I'd recommend you to use NOD32 or KAV. Also a great FW like Agnitum Outpost would be great.
If this trojan does not delete, and close up, try to restore your computer to a earlier time. That may work. It will, and it will delete it forcefully. It will force it to leave. Needless to say, you may still have some leftover files in there from the trojan. So, I say download a Virus scanner, free, and scan your computer, and delete everything it finds.
Download "spyware terminator" for free. Enable AV Clam Antivirus, and then scan your FULL computer. EVERY FILE! Not just efectable files. Now these days, the technology is growing, and more people are trying to find out on how to effect a computer without using a effectable files. Some are succeding on this. You have to SEARCH every file on your computer. Plug in your USB if applicable. Your USB may be the effected drive. A file, on the USB may be effected, and every computer that is be used with this USB or Camera, or flash drive, PSP, iPod, etc, will be effected. Like I said, Technology is growing, and that can do that stuff.
Best of luck!
Hey Guissmo, was the problem sorted out ?
No replies from you yet ???
HijackThis would give a report of the changed settings, so you can post it here for all of us to analyse.
Good luck
If you still have the problem go and download AOL Active Virus Shield. It is a freeware using Kaspersky engine. That should fix the problem.