You have an infection, perhaps with different name, but still.
Please download in my signature special avz, put it in new folder on desktop.
Please execute this script in avz: ( http://virusinfo.info/showthread.php?t=9207)
(Do remember to disable antivirus and firewall, disconnect from internet & disable system restore before lunching an avz)
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\Downloaded Program Files\ieatgpc.dll','');
DelBHO('{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}');
QuarantineFile('C:\WINDOWS\system32\winconfig.dll','');
QuarantineFile('C:\WINDOWS\system32\Drivers\cdudf_xp.sys','');
TerminateProcessByName('c:\windows\temp\yded7d.exe');
QuarantineFile('c:\windows\temp\yded7d.exe','');
DeleteFile('c:\windows\temp\yded7d.exe');
DeleteFile('C:\WINDOWS\system32\winconfig.dll');
DeleteFile('C:\WINDOWS\Downloaded Program Files\ieatgpc.dll');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
BC_Activate;
RebootWindows(true);
end.
Read appendix#3 of the rules http://virusinfo.info/showthread.php?t=9184
Please upload quarantine by http://virusinfo.info/upload_virus_eng.php?tid=40067
make a new logs according to rules http://virusinfo.info/showthread.php?t=9184 and attach them to your next post.