See this recent discussion, Mike:
http://groups.google.com/group/micro...60cdcee6c44607
NB: As of this post, MBAM *cannot* clean this infection!
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin
http://aumha.net
DTS-L
http://dts-l.net/
DJMoneyMike wrote:
> About 2 weeks ago I noticed that I was not able to connect to Windows
> Update server using Windows Update. Windows Update reports that I have
> never checked for updates or never installed updates, which days before
> this problem I have. I didn't think much of the problem at the time.
> Lately I have noticed a drastic change in computer performance and
> popups, it worried me. I decided to update Ad-Aware 2008 and scan, but
> during update I received an error saying "No Connection To Download
> Server". I then try running avast! Antivirus and it finds nothing. Next
> I tried to go to Microsoft Update site and manually download updates, I
> get "Server Error in '/' Application". So I run UnHackMe and it finds a
> trojan on startup, I remove that. Next I run Malwarebytes' Anti-Malware
> and it finds multiple DNSchangers in the registry, I remove that.
> Finally I run Spybot - Search & Destroy and it finds multiple tracking
> cookies, I remove them.
>
> My computer performance is close to normal again, except for the fact I
> still cant connect to Windows Update or Ad-Aware Update server. I have a
> feeling that there is still more to the DNSchanger, maybe with a
> rootkit. I don't kno, I need help.
>
> Local Area Connections Properties TCP/IPv6 & v4 both are to obtain
> automatically.
> Running Windows Vista Ultimate Service Pack 1,
> avast! Antivirus,
> Malwarebytes' Anti-Malware,
> Ad-Aware,
> UnHackMe,
> Spybot - Search & Destroy.
>
> I can send the logs of the objects removed and a HijackThis log if
> needed.