Ok I got areply and they say the PV log looks clean and this is his suggestion !!
To manually check for hidden infection:
Start | Run (type) "regedit (no quotes)
Navigate to:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
Highlight the Windows key (left pane)
Right-click on "AppInit_Dlls" (right pane)
Right click and select: "Modify Binary Data"
Note: the default (hidden value = 0000 00 00)
If the above is not the default = hidden dll to reinstall the hijack.
You should be able to see the "path" to the infected dll.
Make a note of the filename and location (folder)
post it here. It will look funny like this if you are infected:
Value name:
AppInit_DLLs
Value Data:
0000 00 00 3A 00 77 00 ..:.\w.
0008 69 00 6E 00 6F 00 i.n.d.o.
0010 77 00 73 00 73 00 w.s.\.s.
0018 79 00 73 00 65 00 y.s.t.e.
0020 6D 00 33 00 5C 00 m.3.2.\.
0028 63 00 6F 00 2E 00 c.o.m...
0030 64 00 6C 00 00 00 d.l.l...
0038