Kristy, my apologies, I missed an important line with my cut and paste.... I have corrected the instruction, and taken the opp to add more files:
-you must be in an Administrator-privileged account to run this procedure...
Start Avenger; select “Input script manually” and then click the magnifying glass icon. Paste into the box these lines as one block:-
Files to delete:
C:\WINDOWS\system32\ogycsrw.exe
C:\WINDOWS\system32\hzhkhdet.exe
C:\WINDOWS\IFinst27.exe
C:\3b10545d3d62bb28bf60f37c
C:\WINDOWS\system32\pmbvkxh_nav.dat
C:\WINDOWS\system32\linkprd.exe
C:\WINDOWS\system32\ycbeg.ini2
C:\WINDOWS\system32\ycbeg.bak2
C:\WINDOWS\system32\ycbeg.bak1
C:\WINDOWS\system32\mlkkj.bak2
C:\WINDOWS\system32\mlkkj.ini2
C:\WINDOWS\system32\mlkkj.bak1
C:\WINDOWS\system32\f3pssavr.scr
C:\DOCUME~1\Kristy\APPLIC~1\bbbconfig.dat
C:\\DOCUME~1\\Kristy\\MYDOCU~1\\SCURIT~1\\TTRIB~1.EXE
C:\WINDOWS\WSYS049.SYS
C:\WINDOWS\system\tnebli.tmp
C:\WINDOWS\system32\ihhkj.tmp
C:\WINDOWS\system32\mlkkj.tmp
C:\WINDOWS\system32\ttvwa.tmp
C:\WINDOWS\system32\ycbeg.tmp
...and click Done, and finally the green light.
Follow promps to reboot your machine.
[The files, etc., that you asked Avenger to delete are zipped to C:\avenger\backup.zip.]
Avenger creates a log file that should open with the results of its actions. This file is located at C:\avenger.txt
===I want you to do a manual search for this file ; if you find it, delete it:
w03a1090.dll
Next do a Scan Only with hijackthis and check these two entries for fixing, and press Fix Checked:
O4 - Startup: .protected
O4 - Global Startup: .protected
See how you go..