Mark, please be very carefull with the Avenger. It works at the API level - lower than Window’s protection. That’s its strength - it almost never fails to delete the specified files. But that’s also what brings the risk - if the script is written incorrectly it’s possible to wipe your drive with this tool and Window’s won’t be able to stop you. I’m not saying what you ran was wrong, but we’ll try a more targeted path in a bit.

Open WinPFind again and Copy/Paste the information in the quotebox below into the pane where it says “Paste fix here” and then click the Run Fix button.

[Registry - Non-Microsoft Only] < Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup YN -> %AllUsersStartup%\WNSO.lnk -> %CommonProgramFiles%\RGGZS\WNSO.exe < ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks YN -> {733E9132-53CA-4C97-9AC9-145C4502FA20} [HKLM] -> %System32%\rqrqomm.dll [] < Internet Explorer Settings > -> YN -> HKLM: CustomizeSearch -> http://seek.3721.com/srchcust.htm [Files/Folders - Created Within 30 days] NY -> winshow.exe -> %SystemRoot%\winshow.exe NY -> bcwhocfi.exe -> %System32%\bcwhocfi.exe NY -> fnajvskc.ini -> %System32%\fnajvskc.ini NY -> lrfqotyx.ini -> %System32%\lrfqotyx.ini NY -> rrutv.bak2 -> %System32%\rrutv.bak2 NY -> xytoqfrl.dll -> %System32%\xytoqfrl.dll [Files/Folders - Modified Within 30 days] NY -> rrutv.ini -> %System32%\rrutv.ini

Post the results in your next response as you did before.

Now, having sufficiently scared you about the Avenger I’ll ask you to open it once again

Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

  1. Now, start The Avenger program by clicking on its icon on your desktop.
    Under “Script file to execute” choose “Input Script Manually”.

Now click on the Magnifying Glass icon which will open a new window titled “View/edit script”

Paste the text copied to clipboard into this window by pressing (Ctrl+V).

Then download ComboFix from Here or Here to your Desktop.

Double click combofix.exe and follow the prompts.

When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix’s window while its running. That may cause it to stall.