Sorry, I'm not an expert on cleaning. Let me suggest the general cleaning procedure...
If a virus is replicant (coming and coming again), you could follow the general cleaning procedure:
1. Clean your temporary files. You can use CleanUp
2. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode
(repeatedly press F8 while booting).
If avast does not detect it, you can try DrWeb CureIT!
3. It will be good if you download, install, update and run MBAM
or even SpywareTerminator
If any infection is detected, it is better and safer to send the infected file(s) to quarantine (Chest), rather than simply deleting them.
4. If you still detecting any strange behavior or even you're sure you're not clean, maybe it will be good to test your machine with anti-rootkit applications
. I suggest avast! antirootkit
or Trend Micro RootkitBuster
for XP/Vista. For XP only: Panda
5. Also, if you still detecting strange behaviors or you want to be sure you're clean, maybe making a HijackThis
log to post here or this analysis site
. Or even submit the RunScanner
log to to on-line analysis.
6. Browser hijacking and problems with antivirus update could be managed in some scenarios by cleaning the hosts file (at C:\windows\system32\drivers\etc folder). The file does not have an extention, it's simply hosts.
The default file consists of a number of example lines preceded with # The only required line is
You can get a good replacement with HostsMan that keep it clean (avoid infections) and updated: http://www.abelhadigital.com
7. After you're clean, disable System Restore on Windows ME
. System Restore is not available in Windows 9x and 2k. After disabling you can enable it again.
8. Use the immunization of SpywareBlaster
9. Finally, when you're clean, check for insecure applications with Secunia Software Inspector
to update insecure applications and avoid reinfection.