Adware.QoolAid got it's little hooks into a WinXP system and launched Windows Media Player during startup. Media Player's program file was a little off: gbzpzwj.exe
A few other notable items:
- ntud.exe - kept appearing in All Users' Startup
- joqaab.exe - appeared in System32 repeatedly
- Norman API-Hooking Helper had registry keys with permissions set to deny removal
for some reason, computer management fails to open. i got around it by opening MMC.EXE and then opening the item required.
this particular system has had other techs start cleaning it, but adware remained. no telling what all has been damaged during the infection/cleaning processes.
( )