Lazy to PM, just do as stated....
First set of instructions
Quit Internet Explorer, all browsers and quit any instances of Windows Explorer.For Internet Explorer 4.x and Up
[*]Click Start, click Control Panel, and then double-click Internet Options.
[*]On the General tab, click Delete Files under Temporary Internet Files.
[*]In the Delete Files dialog box, tick the Delete all offline content check box, and then click OK.
[*]On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
[*]Click OK.
______________________________
Open ADS Spy and if present delete : (it's probably harmless but it will not hurt)
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SHYBKPU7\autosandvehicles;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Autos++Vehicles;kracy=NEW;ord=5166737735907760[1].s : ùw (77 bytes)
______________________________
Don't know if related but I would like to delete a temp file ... and see another file (same as dll but upd)
Download the Killbox by Option^Explicit to your Desktop or to your usual Download Folder.
http://www.downloads.subratam.org/KillBox.zipUnzip it to your desktop or a convenient folder.
Double-click
Killbox.exe to run it.
Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Enter or Copy&Paste each of the following into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be Rebooted until the last item has been entered:
C:\Documents and Settings\Administrator\Local Settings\Temp\ZLT00d44.TMP
C:\WINDOWS\jltgu1.updWhen the last item has been entered and you are prompted to reboot, ALLOW Pocket KillBox to Reboot your computer. If Killbox fails to Reboot your machine, do it yourself manually.
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
______________________________
Run Gmer
on the first tab (process) click
Safe, your pc will restart into Gmer Safe Mode
once gmer loads > click the
cmd tab
type in the bolded line below then over to the right click
runtype nul > "C:\WINDOWS : zapotlq.bmp"You should see a command suceeded message,
click the first tab in gmer (process)
now click
restart on the right side.
Doublecheck with ADS Spy to see if C:\WINDOWS : zapotlq.bmp is gone. If not post the ADS Spy log please.