ok im sorry i dont usually post on boards because im very very good with computers. the virus i have right now stuns me because its far too advanced and the virus that it matches up with is a simply removed virus. However, ive tried every virus scan known to man, hijack this, registry programs, adaware, you name it i have had it on this computer and NOTHING works. let me first introduce you to the virus. I have formatted about 10 times this week, i have about 6-8 hours before a complete takeover. The virus does not require an internet connection for a takeover, it does things on its own by creating a fake administration guest account and giving that account powers over me and my computer. The way the virus takes over has differed every time have reinstalled, and mind you its two different drives that ive totally wiped clean. now as for the exact virus im not sure how to locate it, my process tree is normal right now and always is. However i cant delete folders such as netmeeting because they are "in use". The virus itself starts somewhere in bios and im pretty sure its hkey_local_machine\system\currentcontrolset002
the virus then starts to log my documents and settings everywhere, my system restore is turned off but still remains active, so is the folder /recycler, where files that i delete which can me deleted by me which the virus uses are sent but once i delete for good they are restored and not actually deleted. ive also noticed an extension for files which addon to the regular exe msmsgs.exe.manifest for example. im not familiar with this but it wont hurt to add it in here. the funny thing is that i have no way of actually finding the virus because it only adds startup commands to the normal exe. my system.ini at one point was shell loading the explorer.exe target load.exe but as of this virus attempt it hasnt. i come here to inform and hopefully find a cure. By reading my computer logs i have found that it appears that my computer is totally normal with all the same files theres no fake exe running around called virus.exe but there is another user who isint even real logged into my computer taking over. Once again i remind you if youre gonna refer me to going to user accounts or networks connections or my control panel for help ive already tried it. my real only resort is to type my entire system. or to find it in bios and wipe it from there. the bios settings i noticed which is irregular is the "lanman" workstation, and many other folders, seems suspicious. the virus i noticed ended up on my computer about a month ago and then slowly began to take over by an internet user within the .net meeting folder as i noticed logs of his attempt to get through to my computer. ive read over almost every ini/log/txt/etc file on this computer and watched on how the virus uses simple microsoft technology to open my computers vunerabilities. and i note again that i have totally updated my system as it does no help its useless. if you need any more details please post here or email me since i have to reformat about every 8 hours. if you have any suggestions let me know please. right now im going to look for a log document of what it has done, ill let you know, but i dont have much time. its great when you sitting there talking to your friends on aim and about to go into your c drive when you just see it totally disappear =) you type c:\ into explorer by bar "drive does not exist" but youre still on aim haha.