[Inactive]New User, Please help remove Tvm.exe

Ok i finally got around to doing all that i was told to do on the HJT post so here is my results cause i'm still having the same problem. Heh this is the 2nd time i had to edit the post sorry.

Kaspersky results:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Documents\SNES\cspmario.zip/spmario.exe/data Infected: Trojan.Win32.StartPage.oz skipped

C:\Documents and Settings\All Users\Documents\SNES\cspmario.zip/spmario.exe Infected: Trojan.Win32.StartPage.oz skipped

C:\Documents and Settings\All Users\Documents\SNES\cspmario.zip ZIP: infected - 2 skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\3pmgol.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\3pmsmw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\3pmsnd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\3pmyalp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\agvbk.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\agvevaw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\aluelitu.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bacbv.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bacpa.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bacptf.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bacsab.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bdcca.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bdmoc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.h skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bdofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bdptf.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bewcvsm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bewniw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bkgmi.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bkvrd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\bvsp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\caksid.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\canib.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cayalp.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cbdos.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ccacp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ccod.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cfm3pm.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cfmsys.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cksid.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cmgmi.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\coddvd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\codmoc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\codniam.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\codxaf.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cpa.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cpcvsm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cplru.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\csii.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ctts.exe Infected: Trojan-Spy.Win32.VBStat.a skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsavaj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsdvd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsmitna.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsmofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsmvrs.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsnur.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\cvsrvs.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\dacod.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\dasys.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\dmcbk.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\dmclld.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\drah.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\drahbk.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\drahptf.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\dvdofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\elocfm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\eloger.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\eloniam.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\elopi.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\elosmw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\elow.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\evawc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\evawpxe.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\evawtac.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\evawva.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gepj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gepjva.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gersm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gmigepj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gmiksid.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\gmitun.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\golcca.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\golsar.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\goltnof.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\History\History.IE5\MSHist012006112420061125\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ipatcp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ipatxaf.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\itnacbdo.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\itnarc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.h skipped

C:\Documents and Settings\Owner\Local Settings\Temp\itnasmw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ksids.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ksidten.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\litupi.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lituw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldbac.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldca.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldgmi.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldsar.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldsnd.dat Infected: Trojan-Spy.Win32.Agent.ce skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lldsod.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lmxpct.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lrudrah.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lrugmi.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\lruteni.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\mocksid.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\moclitu.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\mocrba.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\niamcfm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nibbew.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nibcvs.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\niblmx.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nibsm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nucfm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nugmi.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nur3pm.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nurcvs.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nurmoc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nurofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nurpa.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nurpxe.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\nursp.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ofnievaw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ofnigmi.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ofnissv.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\payalp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pctsm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pctsmw.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pctyalp.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\piw.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ptfelo.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ptfger.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ptfpxe.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ptfteni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ptftun.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pxecfm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pxesab.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\pxesys.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rbaelo.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rbassv.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rc.dat Infected: Trojan-Spy.Win32.Agent.ce skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rcdmc.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rvsbac.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rvsbv.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rvss.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rvssnd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\rvstac.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sabbk.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sabyalp.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\saelo.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.h skipped

C:\Documents and Settings\Owner\Local Settings\Temp\samoc.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sarba.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sarevaw.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sargol.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\saritna.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sarkab.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sarksid.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sarvrd.dat Infected: Trojan-Spy.Win32.Agent.ce skipped

C:\Documents and Settings\Owner\Local Settings\Temp\siicm.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\siiipat.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\slmx.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smcm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwavaj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwc.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwger.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwlld.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwlmx.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\smwpct.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sndbac.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sndbk.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sodnib.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sps.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sptnof.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\spxaf.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ssvlru.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ssvpi.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ssvrc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.h skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ssvsab.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\ssvyek.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sys.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sysipat.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sysnib.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tacbd.dat Infected: Trojan-Spy.Win32.Agent.ce skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tacnu.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tacptf.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr1918 Infected: Trojan-Downloader.Win32.Zlob.gu skipped

C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tenger.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\teniavaj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\teniksid.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tenilld.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tenipat.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tenptf.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tensod.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tnofavaj.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tunbd.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tuncca.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tuncm.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tuncod.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tunpi.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.h skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tunssv.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\vaofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\vrdc.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\vrsksid.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\vrslru.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\vrsxaf.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\wc.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.j skipped

C:\Documents and Settings\Owner\Local Settings\Temp\wca.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\welo.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\wksid.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\wniw.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\yalpbk.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temp\yalpcod.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\yalpofni.dat Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\Owner\Local Settings\Temp\yekcfm.dat Infected: not-a-virus:AdWare.Win32.Virtumonde.m skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

HighJackThis Results:
Logfile of HijackThis v1.99.1
Scan saved at 3:56:05 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://thesearchmall.com/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - _{A045DC85-FC44-45be-8A50-E4F9C62C9A84} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {4B8F38C7-62FC-4762-B9A0-27E63F768167} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CCEAD9D3-F7CC-48D1-803D-3826E5ACEAA5}: NameServer = 68.94.156.1 68.94.157.1
O18 - Filter: text/html - {2DE94081-9FE6-4227-BC59-B7A80CC8308C} - c:\program files\clientman\run\searchrepe44a84f2.dll
O20 - Winlogon Notify: binsys - C:\DOCUME~1\Owner\LOCALS~1\Temp\sysnib.dat
O20 - Winlogon Notify: vbmp3 - C:\WINDOWS\Registration\vbmp3.dll

Comments

  • TroganTrogan London, UK
    edited November 2006
    Hi SoySauce! Welcome to Short-Media Forums! :)

    You have a few things going on in the HijackThis log. The HijackThis log also looks incomplete. Please make sure you post a Full Log in your next.

    Do you have an active Anti-Virus or Firewall?

    Need to see some logs:

    Scan a file to find out what it is:
    • Go to VirusTotal
    • Copy and paste the following file path into the Search Box at the top of the page:
    • C:\DOCUME~1\Owner\LOCALS~1\Temp\sysnib.dat
    • Click on the Send button
    • Please post the results in your next reply.
    ______________________
    • Run Hijackthis.
    • Click on Open the Misc Tools section.
    • Next click on Open uninstall manager.
    • Press the Save list button.
    • Save the file to your desktop, with the default name of uninstall_list
    • Copy & Paste the entire contents of that file in your in your next post.
    ______________________

    Download SmitfraudFix (by S!Ri) to your Desktop.
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ______________________

    Please post the following:

    1) Scan results
    2) Uninstall list
    3) Contents of C:\rapport.txt
    4) New Complete HijackThis log
  • edited November 2006
    Thanks for havin a look Trogan_1000 i just updated it right now. Sorry it took so long and thanks for the reply
  • TroganTrogan London, UK
    edited November 2006
    I need you to follow the instructions from my last post please.
  • TroganTrogan London, UK
    edited December 2006
    Whilst we appreciate that you may be busy, it has been 14 days or more since we heard from you.

    Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Spyware & Virus Removal Forum

    If you wish this topic reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.
    If you are not the user who started this thread, you must start a new Thread instead :)
This discussion has been closed.