Hi,
The trojan is not fully removed, and I noticed several other entries in your AVG log that said 'ignored'.
You may wish to copy and paste these instructions in notepad for easier reference.
Please go to
Viruses/Spyware/Malware, preliminary removal instructions and download ComboFix. Also download CCleaner from
HERE.
Then, follow the instructions for Vundofix again,
but this time enter this filepath:
C:\WINDOWS\system32\tmp13.tmp.dll
Next, boot into safe mode again, and unhide your files and folders.
Go to Start > Run and type services.msc. Press Enter. Search for the following processes and disable them (if found):
RaMaint.exe
LogMeIn.exe
LMIinit.dll
Open Task Manager, and search for and close the following processes, if found:
RaMaint.exe
LogMeIn.exe
UERS_0001_N91M2007NetInstaller.exe
LMIinit.dll
Next Run HijackThis and fix these entries:
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tmp13.tmp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logmein.com/activex/ractrl.cab?lmi=100
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
Close HJT.
Navigate in windows explorer to these files and folders listed in bold and delete them (only those in bold):
C:\Program Files\
LogMeIn\
C:\WINDOWS\system32\
tmp13.tmp.dll
C:\WINDOWS\Downloaded Program Files\
UERS_0001_N91M2007NetInstaller.exe
C:\WINDOWS\system32\
LMIinit.dll
Run CCleaner and place a 'tick' for "System" under the Windows tab. Click Analyze, then Run Cleaner to clear all your temporary internet files.
Reboot into normal mode and rehide your OS files.
Now run ComboFix with no other programs running.
When you are done, please post fresh HJT, ComboFix and AVG Antispyware logs as attachments to this thread. Do not copy and paste the logs as they will be ignored and/or removed by the moderators.
Regards,
Your friendly Momok =)