responding to Kento(and thank you), I am using windows 2000 and startlog.com does not exist. the affected file is in winnt\system32\windrv32.exe and I found it in the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and I looked at the data in windrv32 using notepad :
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe /logon"
"3c1807pd"="C:\\WINNT\\SYSTEM32\\3cmlink.exe RunServices \\Device\\3cpipe-3c1807pd"
"AVG_CC"="C:\\PROGRA~1\\Grisoft\\AVG6\\avgcc32.exe /STARTUP"
"NeroCheck"="C:\\WINNT\\system32\\NeroCheck.exe"
"WinampAgent"="\"C:\\Program Files\\Winamp\\Winampa.exe\""
"WINDRV32"="WINDRV32.EXE"
"Tweak UI"="RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp"
"TkBellExe"="C:\\Program Files\\Common Files\\Real\\Update_OB\\evntsvc.exe -osboot"
"acocash"="C:\\Program Files\\fastdownload2\\fastdown.exe -auto"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\PC-cillin 2002\\pccguide.exe\""
"PCCClient.exe"="\"C:\\Program Files\\Trend Micro\\PC-cillin 2002\\PCCClient.exe\""
"Pop3trap.exe"="\"C:\\Program Files\\Trend Micro\\PC-cillin 2002\\Pop3trap.exe\""
"tcactive"=""
"tcmonitor"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
does any of this help?
I have run the following antivirus programs:
AVG--which continues to find the virus in windrv32.exe
PC-cillin which found nothing
Trend Micro Housecall which found 3 viruses-and cleaned them, but not the trojan backdoor bionet
I loaded The Cleaner from MooLive but it would not start up.
thanks for listening and any advice is welcome