Not good news I’m afraid you also had Goldun and Haxdoor as well as bagle and they were all kind of cooperating to stop you getting fixed. With this fix I am going to kill explorer so you may loose the desktop etc.

Start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says “Paste fix here” and then click the Run Fix button.

[Kill Explorer] [Win32 Services - Non-Microsoft Only] YY -> (W) W [Win32_Own | Disabled | Stopped] -> D:\TEMP\W.exe [Driver Services - Non-Microsoft Only] YY -> (Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> YY -> (abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> YY -> (adpu160m) adpu160m [Kernel | Disabled | Stopped] -> YY -> (Aha154x) Aha154x [Kernel | Disabled | Stopped] -> YY -> (aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> YY -> (aic78xx) aic78xx [Kernel | Disabled | Stopped] -> YY -> (AliIde) AliIde [Kernel | Disabled | Stopped] -> YY -> (amsint) amsint [Kernel | Disabled | Stopped] -> YY -> (asc) asc [Kernel | Disabled | Stopped] -> YY -> (asc3350p) asc3350p [Kernel | Disabled | Stopped] -> YY -> (asc3550) asc3550 [Kernel | Disabled | Stopped] -> YY -> (catchme) catchme [Kernel | On_Demand | Stopped] -> D:\TEMP\catchme.sys YY -> (cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> YY -> (Changer) Changer [Kernel | System | Stopped] -> YY -> (Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> YY -> (dac960nt) dac960nt [Kernel | Disabled | Stopped] -> YY -> (dpti2o) dpti2o [Kernel | Disabled | Stopped] -> YY -> (hpn) hpn [Kernel | Disabled | Stopped] -> YY -> (i2omgmt) i2omgmt [Kernel | System | Stopped] -> YY -> (i2omp) i2omp [Kernel | Disabled | Stopped] -> YY -> (ini910u) ini910u [Kernel | Disabled | Stopped] -> YY -> (kednl6) AVSearch service [Kernel | On_Demand | Stopped] -> %System32%\kednl6.sys YY -> (lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> YY -> (mmx432) MMX2 virtualization service [Kernel | Auto | Stopped] -> %System32%\mmx464.sys YY -> (mmx464) MMX virtualization service [Kernel | System | Stopped] -> %System32%\mmx464.sys YY -> (ql1080) ql1080 [Kernel | Disabled | Stopped] -> YY -> (Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> YY -> (ql12160) ql12160 [Kernel | Disabled | Stopped] -> YY -> (ql1240) ql1240 [Kernel | Disabled | Stopped] -> YY -> (ql1280) ql1280 [Kernel | Disabled | Stopped] -> YY -> (Simbad) Simbad [Kernel | Disabled | Stopped] -> YY -> (srosa) Megadrv3 [Kernel | System | Stopped] -> %System32%\drivers\srosa.sys YY -> (sw848b) sw848b [Kernel | Auto | Running] -> %System32%\drivers\sw848b.sys YY -> (sw878b) sw878b [Kernel | Auto | Running] -> %System32%\drivers\sw878b.sys YY -> (symc810) symc810 [Kernel | Disabled | Stopped] -> YY -> (symc8xx) symc8xx [Kernel | Disabled | Stopped] -> [Files/Folders - Created Within 30 days] NY -> wintems.exe.ren -> %System32%\wintems.exe.ren NY -> srosa.sys.ren -> %System32%\drivers\srosa.sys.ren [Files/Folders - Modified Within 30 days] NY -> DEBUGSM.INI -> %SystemRoot%\DEBUGSM.INI NY -> wintems.exe.ren -> %System32%\wintems.exe.ren NY -> srosa.sys.ren -> %System32%\drivers\srosa.sys.ren [File String Scan - Non-Microsoft Only] NY -> @Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable [Empty Temp Folders] [Start Explorer]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new WinPFind3u scan.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

THEN follow that up with a combofix run

Download ComboFix from Here or Here to your Desktop.

[*]Double click combofix.exe and follow the prompts.
[*]When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix’s window while its running. That may cause it to stall