It worked so far because after I used it, the problem went away.

As you can probably see our HijackThis Team is incredibly busy at the moment, but I apologise for the delay you have experienced.

Hello,My system has been

Windows has detected spyware..."I scanned with AVG Ant-Virus Free and removed something called sheur 2 trojan, but am still having problems. Any ideas?Thanks

System detected a potential hazard (TrojanSPM/LX) on your computer|that may infect executable files. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".The tool may need to restart your computer to finish the cleaning process; I am only able to boot by choosing the option for booting with the most recent settings that worked.

I fear that there may be others as well.Would someone please talk me through the steps of getting rid of it, as my ZoneAlarm (Virus and Spyware Scanner) does not remove I downloaded HJT and here is the logfile.HJT LogfileLogfile of HijackThis v1.99.1Scan saved at 10:16:12 AM, on 5/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16441)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exeC:\Program Files\Symantec_Client_Security\Symantec

so how do i get rid of the message?Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 3:49:27 PM, on 4/10/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\SYSTEM32\SVCHOST.EXEC:\WINDOWS\SYSTEM32\SPOOLSV.EXEC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\PROMon.exeC:\WINDOWS\SOUNDMAN.EXEC:\Program I had one virus search said i have a backdoor TrojanSPM/LX I have Norton 2006 and it is not finding a trace of nothing saying system is good.

Logfile of HijackThis v1.99.1Scan saved at 11:14:26 AM, on 12/13/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec They opened an attachment and got all sorts of warnings and pop ups.

but i still have the flashing icon and get warnings about trojans.

Re: Trojan SPM/LX secured2k Nov 30, 2009 9:50 AM (in response to secured2k) 2009.11.30 15:45:55 (UTC)AntivirusVersionLast UpdateResulta-squared4.5.0.432009.11.30Trojan.Win32.Agent!IKAntiVir7.9.1.792009.11.30TR/Agent.dcsmAntiy-AVL2.0.3.72009.11.30Trojan/Win32.AgentAvast4.8.1351.02009.11.30Win32:Trojan-genAVG8.5.0.4262009.11.30Agent2.AAZBBitDefender7.22009.11.30Trojan.Generic.2777164CAT-QuickHeal10.002009.11.30Trojan.Agent.dcsmComodo30902009.11.30Heur.SuspiciousDrWeb5.0.0.121822009.11.30Trojan.Fakealert.7842eSafe7.0.17.02009.11.30Win32.TRAgent.DcsmGData192009.11.30Trojan.Generic.2777164IkarusT3.!94BB33DE79C0McAfee-GW-Edition6.8.52009.11.30Trojan.Agent.dcsmMicrosoft1.53022009.11.30TrojanDownloader:Win32/FakeinitNOD3246492009.11.30Win32/TrojanDownloader.FakeAlert.AEDPanda10.0.2.22009.11.29Trj/CI.APCTools7.0.3.52009.11.30Trojan.FakeAVPrevx3.02009.11.30Medium Risk MalwareRising22.24.00.092009.11.30Trojan.Win32.FakeVir.thSophos4.48.02009.11.30Mal/Generic-ASunbelt3.2.1858.22009.11.29Trojan.Win32.Generic!BTSymantec1.4.4.122009.11.30Trojan.FakeAV Additional informationFile size: 25360 bytesMD5...: 94bb33de79c05fdc05aa282c9f121283SHA1..: a76f1d88f9b22b4bc69ccb8d2d7cd43139f79103SHA256: 51bea781613e1b0fc40998d6afc3c8ff109cd0440b788805d2df1e334a7131c3ssdeep: 768:cbN3pAVLCeUUVME4GLDGO89FOrZd0D2Mf:emVZUw4GLDGO87OrIfPEiD..: -PEInfo: PE Structure Generated Wed, 01 Feb 2017 02:23:00 GMT by s_nt6 (squid/3.5.23) ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: Connection When I go to run system restore I cannot activate software.Your McAfee software does not detect it, I have downloaded the lates up-dates.I hope there is a easy solition to fixing

I am fairly computer literate and can follow instructions well.

I get a blue screen if I try to boot in safe mode. here's the HJ log:Logfile of HijackThis v1.99.1Scan saved at 5:50:43 PM, on 7/18/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet If you cannot copy files to your usb drive, make sure it is not "Write Protected".Please download Rkill by Grinler and save it to your desktop.Link 2Link 3Link 4Double-click on the It found a few files and deleted them, though not the ones it should have.I can still boot from the disk, but that's not really helping me get anywhere.I cannot boot

I have also had a Yellow Yield Sign with a "!" inside of it, blinking, in the lower right hand section of my screen. (Running Microsoft Windows XP, I forget what

Could someone please help me? You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to I had one virus search said i have a backdoor TrojanSPM/LX I have Norton 2006 and it is not finding a trace of nothing saying system is good.

Can you help?Sandy Levey I have been getting popups and computer acting strange.

