Hi Rejzor,
how come ?

"crap while without AV "means malware ?
how about some useful info, like virus- & filename, HJT-Log ?
Trojan-Check-Report, or report from AutoStartViewer by diamond-CS ?
which WIN ? XP ? Home or Pro ?
All Updates ? What user-rights does this happen under ?
Must I point to the link in my sig ?
*
to business:
apart form the above reports, which might give us some useful hints (e.g. botched-up exefile/shellOpen entries..):
- what about the avast CLEANER ?
- try start -> run -> gpedit.msc (Group-policy) if all else fails..
