Ok that looks licke the nasty has been remove.Just check that this file has been deleted
Hi...
Please
download The Avenger to your
Desktop and unzip it.
Copy
all the text contained in the code box below
( including the words "files to delete" ) by highlighting it and right clicking and selecting "Copy"
Files to delete:
C:\WINDOWS\system32\lzx32.sys
C:\WINDOWS\system32\MRT.exe
C:\WINDOWS\TEMP\85B5E5BA.exe
C:\WINDOWS\system32\csrs.exe
C:\WINDOWS\system32\lexplore.exe
Now, start The Avenger program by clicking on its icon on your desktop. Look under "Script file to execute" and click on "Input Script Manually". Next click on the Magnifying Glass icon and a blank dialogue box will open called "View/Edit script". Position your mouse inside the box, rightclick and choose Paste. All the text above in the code box should now appear there. Click Done and click on the Green Light to begin execution of the script. Answer "Yes" twice when prompted.
The Avenger will restart your computer. (if the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
When you have rebooted, a black command window briefly opens on your desktop, this is normal. A logfile will be created that records all actions that The Avenger performed. This log file is saved to C:\avenger.txt. The deleted files will be backed up and saved to C:\avenger\backup.zip.
Once your computer has rebooted, please post back the contents of C:\avenger.txt, a new Hijack This log.
Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.
O2 - BHO: (no name) - {371EE1EF-F177-1390-7807-08525DC0E55C} - blank (file missing)
O2 - BHO: (no name) - {FD389CBD-2424-06AF-7F20-7DC2B72246E4} - (no file)
O4 - HKLM\..\Run: [winconf] C:\WINDOWS\TEMP\85B5E5BA.exe
O4 - HKLM\..\Run: [Microsoft USB Service] csrs.exe
O4 - HKLM\..\Run: [lexplore] lexplore.exe
O4 - HKLM\..\RunServices: [lexplore] lexplore.exe
O4 - HKLM\..\RunServices: [Microsoft USB Service] csrs.exe
Reboot and post a new
HJT log