Malware...My logs

This next one will produce the necessary shortcut links which you can cut and paste into the start menu folder

To use this download the attached txt file
The attached file needs to be renamed from repair.txt to repair VBS
Run the repair.vbs
It will ask for a folder name call it recovery
The tool will let you know when it is finished
On the desktop will be a recovery folder
Open the folder
Cut and Paste the links that you want to C:\documents and settings[i]your name[/i]\start menu

http://i1224.photobucket.com/albums/ee362/Essexboy3/recoverxp1.gif

http://i1224.photobucket.com/albums/ee362/Essexboy3/recoverxp2.gif

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.

As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.

http://img.photobucket.com/albums/v706/ried7/RC1.png

[*]Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

[*]Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Ok, here’s the latest:
I ended up copying all of the folders to my start menu. It left a big mess, but I figure I can always clean that up later. (I care less about the installed programs that are inaccessible and more about my files that have already been recovered. Thank you!)
I used Combofix and attached the log. After it detected a rootkit, it restarted and continued to finish. It did one last reboot, and while preparing the log, Avast popped up (because when I disabled it initially I told it to turn on again after a reboot). Avast wanted me to start the program in sandbox. So I turned Avast off again, but later it popped up with a message that said a rootkit had been found. (This was while Avast was disabled.) The log finished.
Next I tried opening Microsoft Word–which after the recovery is now called ‘WinWord.exe’. The computer froze, and I did a manual reboot.
Now I continue to get messages popping up. From Malwarebytes: C:windows/temp/explorer.exe (trojan.agent)
Microsoft Visual C++ Program C:/windows/system32/svchost.exe (This application has requested the runtime to terminate in an unusual way. Please contact the application’s support team for more information.)
Also, odd “charity sites” are opening in their own windows. Initially I thought I hit something by mistake, but it’s happend two or three times. Now I can’t recall what they were exactly, but they looked like legitimate websites for something like diabetes or women’s health.

Looks like you also have TDL3 -

Lets confirm and kill now

Please read carefully and follow these steps.

[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillermain.png

[*]If an infected file is detected, the default action will be Cure, click on Continue.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMal-1.png

[*]If a suspicious file is detected, the default action will be Skip, click on Continue.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerSuspicious.png

[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerCompleted.png

[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.

The log was too large to copy/paste, so it’s attached.
Things are going well otherwise!! I really appreciate all the help!! :smiley:

Ok what problems remain ?