First off, go to c:\windows\prefetch (XP) and see if any
files there contain downloadware in their filename. If
so, shred them using a FREE file shredder from
download.com. If you have Window Washer from Webroot
(webroot.com), you can create a new folder in the
prefetch folder and place all of the offending files
there, right-click on that folder, select Shred (Wash
with Bleach), and press Enter. If you are running 2000
or NT, search for *.pf in the c:\winnt folder.
If this doesn't help, try running a full system scan in
Safe Mode (F8 before Windows screen during bootup). You
might even want to use Ad-Aware (download.com) as well.
FYI: The reason behind the prefetch folder is to store
code that allows programs to startp quicker.
Unfortunately, spyware/malware, virus, etc. writers have
become wise to the existance of this folder and are
storing code there that is linked to another application,
such as IE. When the main app is launched, all the code
linked to it is also launched, causing the infection
to "reappear."
I'd like top see Microsoft add a checkpoint to one of the
Real-time Protection agents that checks the prefetch
folder and makes certain that no spyware/malware programs
are trying to store code there. I feel this will greatly
reduce the problmes many people are having trying to
remove these stubborn infections.
Alan