Well ... I've been having the same old problem this thing (although McAfee STINGER reports it as Virut.n.gen Avast! says it is Win32:Vitro). I've read almost half of the post, when I quit reading it ... After seeing something to what I've done (afterwards), I decided to post ...
So let me tell you a little bit of a story ...
This laptop operated for about 3 - 4 days with the virus. In the beginning, it cut IE with addons off, then updates wouldn't be downloaded, rundll32.exe would crash, and everything else collapsed afterwards ...
Now, nothing can boot next to the login screen ...
I had a UBCD built in 09-Sep, I run it, using STINGER / Avast!Virus Cleaner / Avira
Avast! was unable to track anything down.
Avira tracked a whole lot of viruses/Trojans, but nothing was fixable.
STINGER suprisingally, traced the Virun.n.gen, and could repair them.
So, I first run STINGER which cleansed the heck out of more than 1700 *.exes (I couldn't save the logs ...
)
Then Avira found 2 traces of the virus, plus a lot of Trojans, everything quarantined (Full quarantine was copied over to a Hidden TrueCrypt volume prior to shutdown, flash memory was thouroughly checked + runned FlashDisinfector) - (Full log is pertained and attathced
Finally, Avast! couldn't trace a thing ...
Nevertheless, prior to copying over explorer.exe (because I can't find it anywhere on the OEM Disks), I tried to boot the system ...
No difference whatsoever, everything kept crushing - but the Microsoft Report Program kept "Searching for solutions" ...
I rebooted with UBCD, I searched everything, from tip to toe with these programs (well, yeah, outdated - but I can't get the internet support up and running and I don't know why ...) but nothing else pops-up (Joke/Stressreducer only and I know this program)
So ... any suggestions? Because this system is not mine, I would prefer to keep it as intact as possible ... and complete format is almost out-of-the-question (OEM system, with internal repair partition). But I'd like to hear any aspect of solution ...