hello,
i have a problem with a virus which simply won't go away..
the virus (assuming it's only 1 virus) at first installed a "desktimer" application (in Chinese, shows date/time on the desktop) and also open web-sites in Chinese, some of which it made my home-page.
i installed nis 2009 (at firs 2008, then updated) and been keeping it up and running so it can get as many updates as possible.
the first time it found like 14 threats, but now most scans i run it finds usually 1-2 threats- if any, usually a tracing cookie, or something like that..
now, as for the "desktimer" crap- i could remove it after that first/second scan.. but the problem is the virus is still there.
i can see the explorer windows (of those sites) in the task-manager, although not on the desktop, and several "svchost" processes.
also, once i reboot/shutdown and (i assume) the nis closes before leaving the windows session i see those web-sites for a second (just before actual leave from the OS).
i've read that these processes might be the virus, but imm not sure.
also, i keep getting a notice from nis about attack-blocks from a certain site, even though i changed my ip since NIS removed the lateset threat.
on top of that i get constant messages on the NIS history about IEXPLORER on (c:\program files\internet explorer) in hours the pc was not in use, and sometimes "brose exploit block", on the same explorer..
for the record - im using xp sp2, and explorer 6.
i'll appriciat the help,
Eithan