Installed all XP security updates, ran Vundofix. I manually wiped out as many of the files and registry items as I could find, which at least opened up the use of Malware Bytes, SuperAntiSpyware and Spybot for me. It was time for a clean wipe anyway.

The other thing I wonder about is what anti virus are you running, as I do not see any AV installed, just firewalls and anti spyware cleaners.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\iifcbsri -> No action taken.

C:\WINDOWS\system32\ddcBTMEW.dll (Trojan.Vundo.H) -> No action taken.

I went through the process you listed (thank you!) and everything appeared to run smoothly - the programs ran exactly as they should and the .reg file was added successfully

Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_152e7382f3bd50c6.manifest.Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc.manifest.

Any assistance is greatly appreciated.

The Avenger will automatically do the following:It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will

The Avenger2. I went through the entire "Read & Run Me First Process" (including uninstalling old versions and reinstalling from scratch). C:\WINDOWS\system32\khfCvUMG.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\ijouucfx.ini (Trojan.Vundo.H) -> No action taken. Most infected wounds (79%) had an immature epidermis (types 0-2) while most noninfected wounds (75%) had a mature epidermis (types 3 or 4); chi2 and chi2 for linearity both p <

I downloaded Symantec's Vundo removal tool, but after running the scan for a half hour it declared that there was no Vundo infection, which is BS.

There are some great products nowadays, such as Acronis TrueImage, ShadowProtect Desktop, and Windows Home Server.

It only runs during the browser session in which I initiated the TransactionGuard. (I wish I'd had Avast from the beginning - I was running AVG, but it

Error - 3/14/2009 12:13:56 AM | Computer Name = Med-Station | Source = Application Error | ID = 1000Description = Faulting application TrueImageMonitor.exe, version, time stamp 0x4727649a, faulting module MSVCR71.dll,

I think it's better you take your necessary backup and go for a fresh install of Windows.

After clicking Fix, exit HJT. Plus it is not detecting any real problems. Choose from the menu File => Standard scripts and mark the 3.

RenV logs

HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfcvumg (Trojan.Vundo.H) -> No action taken.

Vundofix Have you tried this as well?

You deserve a medal for actually going out of your way to link all of this info, my google searches turned up garbage.