Hi mauserme,
Especially when the malware does not seem to come out of the book, it is an evolving process. Also hijackthis is an ever changing tool, well anyway it better stays that way. You have various online databases for executables, processes, dll's etc. etc. to check and re-check. What I like especially and always renders best results is co-operation in a cleansing procedure. You would not believe how much I learned from simple being into it. The so-called experts had to go through the very same routines, and if they can almost "sniff out" the baddies only comes with time and experience. You must be very accurate, and keep to the prescribed routines,
polonus