I'm having the same problem so far. I'm currently running the Microsoft Safety Scanner as well as Trend Micro Titanium. Both Full Scans. Afterward I'm going to run the RKill and Malwarebytes. I just installed some Windows 7 updates and I noticed the Action Center informing me about the Windows Firewall. That's how this all started. I'll post a reply with my results. I'm hoping I don't have to do a clean install seeing as how I have over a TB of media on my PC and no way to get a larger HD.
Well, my PC restarted with no problems after the scans. It seems like I may have the same problem with a different cause. I'm gonna continue researching it.
Code:
Rkill was run on 05/23/2012 at 22:23:24.
Operating System: Windows 7 Professional
Processes terminated by Rkill or while it was running:
C:\ProgramData\adob\copy.exe
C:\ProgramData\adob\svchost.exe
C:\Users\Guardian\AppData\Local\Temp\6F45.tmp\rundll32.exe
Rkill completed on 05/23/2012 at 22:23:40.
Code:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.24.01
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Guardian :: G222-ELITE [administrator]
5/23/2012 10:27:19 PM
mbam-log-2012-05-24 (00-12-12).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 360734
Time elapsed: 1 hour(s), 29 minute(s),
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Adob (Trojan.Banker) -> Data: C:\ProgramData\adob\color.vbs -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|adobe (Trojan.Banker) -> Data: C:\ProgramData\adob\color.vbs -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\ProgramData\adob\color.vbs (Trojan.Banker) -> No action taken.
(end)