Well for starters no more .exe files from any P2P's and Limewire is a name that will go down in infamy but I shall digress. SF has entrusted the chronicling of our adventure to me but I will freely admit it was his brains and not my fingers that got us through this.
As soon as I realised I had a problem I tried to access some online spyware and virus scanners but the bug was blocking access even through a proxy. So I turned to the Milforum for help. I read this thread and went through all the steps and advice from SF and his signature bar... adaware, spyware hunter killer etc. To no avail.
I was online and talking to IG when I told him I was about to just reformat the ":cen:ing thing" and he said no no no and put me in contact with SF. We went through and checked all the obvious things and under his guidance I went through the motions again... now he was "mad".
We went to Hijack This and I ran it and he looked at the log but NOTHING. It wasn't picking it up and the only thing Ad-aware was finding was Look2Me.Topconverting, but couldn't delete it, even on reboot. So we downloaded Killbox and DllCompare and then even when I fed the file to Killbox...nothing. Tried it on reboot with dummy and NOTHING, still being hijacked. So on dll compare we ran the log a couple times... we tried regedit but it would vanish, the box would open and disappear instantly... clever bastard.
So then we kill the 4 new dll files that showed on the DLL Compare log and download VX2 killer for Ad-aware but nothing... it wasnt Look2Me, it wasn't VX2... I apparently, according to SF, got the newest, brightest and nastiest VX2 version. It has no cure yet and it doesn't show up on any of the scans... none of them. We aren't completely finished as IG came wandering in on messenger and wouldn't stop with the questions... nah, truth is my wife was pissed it was 1:40 in the morning and I was still up "playing on the computer".
Tomorrow we will finish disinfecting the machine but at least the heart of the beast has been removed as I am no longer being hijacked and the dll compare logs are clean. I don't understand what we did, any technical questions have got to go to the man, the one the only Swordfish 13.
All hail the mighty Fish!!!