Sure, I'll do that and see if it pulls anything out, when I'm done running MSE (already done symantec online scan and avg 2013 scan so far).
The way I got rid of it by hand was to login to administrator in safe mode and search my harddrive with * wildcard, sort by date, and I was able to pinpoint a collection of files at the time of infection (including the scare html file that took over my display, which I viewed in a text editor). But I wonder if viruses are able to manipulate the system clock so that this is not always reliable?
What has me worried is how a java plugin got turned on again in the first place... I thought I turned it off the last time I got an infection. Don't they ever release a secure version of java browser plugins?
Anyway, assuming I am rid of the infection, is there a way to trace what's causing the shut down when logging in to my normal user account?
I've found the following events but they don't tell me much:
Quote:
- System
- Provider
[ Name] Microsoft-Windows-Winlogon
[ Guid] {DBE9B383-7CF3-4331-91CC-A3CB16A3B538}
EventID 7001
Version 0
Level 4
Task 1101
Opcode 0
Keywords 0x2000000000000000
- TimeCreated
[ SystemTime] 2012-12-03T22:20:20.302069100Z
EventRecordID 274529
Correlation
- Execution
[ ProcessID] 2380
[ ThreadID] 2096
Channel System
Computer Contuter
- Security
[ UserID] S-1-5-18
- EventData
TSId 2
UserSid S-1-5-21-3021841014-1162341245-2895752552-1000
Quote:
- System
- Provider
[ Name] Application Popup
- EventID 26
[ Qualifiers] 16384
Level 4
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2012-12-03T22:20:21.000000000Z
EventRecordID 274530
Channel System
Computer Contuter
Security
- EventData
Windows
Other people are logged on to this computer. Restarting Windows might cause them to lose data. Do you want to continue restarting?