C:\WINDOWS\Temp\opre0.37781660428866637.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\slp8756694722552590810.tmp (Exploit.Drop.3P) -> Quarantined and deleted successfully. S Choi (1993). I have a feeling that this is only a sign of a continued, possibly major, infection. http://mseedsoft.com/trojan-horse/trojan-horse-backdoor-generic14-cgsu.html

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file.

Watch the safety status of any website. Retrieved 2012-04-05. ^ "Trojan Horse: [coined By MIT-hacker-turned-NSA-spook Dan Edwards] N.".

Feb 23, 2012 #4 Broni Malware Annihilator Posts: 53,119 +349 Welcome aboard Please, observe following rules: Read all of my instructions very carefully. C:\WINDOWS\Temp\p9pl6036382084791057691.tmp (Exploit.Drop.3P) -> Quarantined and deleted successfully.

It took me more than one try, but I am in safe mode and now scanning (FULL SCAN) with the updated version of MalwareBytes. Also, so you know, I did attempt more than once using Windows system restore without any luck. C:\WINDOWS\Temp\kolf0.9185119622408099.exe (Trojan.Exploit.Drop.THPM) -> Quarantined and deleted successfully.

I will run anothet AVG scan and see what comes up. Retrieved 2012-04-05. ^ "Trojan horse". I cannot remember the last time I had to run ComboFix on this.

Error: (12/05/2011 07:27:48 AM) (Source: Windows Search Service) (User: ) Description: The entry in the hash map cannot be updated. C:\WINDOWS\Temp\p9pl5886707554905581717.tmp (Exploit.Drop.3P) -> Quarantined and deleted successfully.

Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 10/9/2009 4:36:24 PM System Uptime: 2/23/2012 1:41:18 PM (3 hours ago) . Thank you so much for your help.----------------------------------------------AVG 2012 Anti-Virus command line scannerCopyright (c) 1992 - 2011 AVG TechnologiesProgram version 2012.0.1873, engine 2012.0.2102Virus Database: Version 2102/4668 2011-12-08C:\013b8c719fd71fec6eb8\i386\ Locked file.

C:\WINDOWS\Temp\p9pl3053999797587620231.tmp (Exploit.Drop.3P) -> Quarantined and deleted successfully. Using the site is easy and fun. I am attempting a second time and so far it made it farther than the first attempt.

This worries me because I can't figure out why I was continually having results from AVG saying I have "trojan backdoor.generic14.bzsz" and would claim that it was unable to remove it.

Formatting disks, destroying all contents. Worldwide Virus Detections PC Threats Mobile detections Check File for Viruses Is a file safe? Any help?

C:\WINDOWS\system32\config\SAM.LOG Locked file. C:\WINDOWS\Temp\slp537113348159386514.tmp (Exploit.Drop.3P) -> Quarantined and deleted successfully. MiniToolBox by Farbar Ran by My Computer (administrator) on 12-12-2011 at 20:12:15 Microsoft Windows XP Professional Service Pack 3 (X86) *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the

If I closed your topic and you need it to be reopened, simply PM me. ================================================================= Are you saying that you don't have internet connection as of now? For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has I know, stupid of me huh? C:\pagefile.sys Locked file.

Registry Values Infected: HKEY_CLASSES_ROOT\ah\Content Type (Rogue.MultipleAV) -> Value: Content Type -> Quarantined and deleted successfully. Registry Values Detected: 2 HKCR\ah|Content Type (Rogue.MultipleAV) -> Data: application/x-msdownload -> Quarantined and deleted successfully.

C:\System Volume Information\ Locked file. RP818: 11/25/2011 10:46:23 PM - System Checkpoint RP819: 11/26/2011 11:58:22 PM - System Checkpoint RP820: 11/28/2011 12:46:21 AM - System Checkpoint RP821: 11/29/2011 12:58:21 AM - System Checkpoint RP822: 11/30/2011 2:01:13