okies! got the info!
VBS:Malware [Script]
C:\Windows\Temp\sp.html
C:\Windows\Temp\hp.html
also memory is infected...the .dll changes each time...this time it showed as:
Win32:Startpage-006[Trj]
C:\Windows\System\nhb.dll
VPSversion 0432-1,08/03/2004
Did you read and follow the information on the thread I gave the link for,
General Advice&Tools for virus/trojan/malware removal Much of the information and other links, etc. should help you. A search of this forum for Win32:Startpage-006 would return much information, this has been a thread topic before (many times).
In order to get into memory a program has to run to put it there, you need to disable that startup entry.
Programs like HijackThis can remove these entries and give you a head start.
1. Clear your temp directory.
2. Clear your browser cache.
3. Read the information (again) on the
General Advice&Tools for virus/trojan/malware removal thread that I gave you before. If you need more help, come back here with more info...