You guys might also want to try locating the current "rogue .exe" and uploading it for analysis here ---> http://www.kaspersky.com/remoteviruschk.html

I think Jotti is down, but you should try it as well --> http://virusscan.jotti.org/

It might give you an idea of what "family" of baddie you have here. Reminds me a bit of Vundo or WebNexus.....

Best Luck
PP