Hi,

please

  • read the link “VirusRemoval” belwo in my sig
  • post the hijackthis-log
  • report the exact results of onlinescans with Trend, RAV & KAV on the suspicious file(s)/the whole PC

read here:
SdBot-545

This strongly suggests that you

  • don’t have all Windowsupdates applied and/or
  • use insecure passwords and/or
  • are careless with IRC or FileSharing/P2P

:wink: