I've run SpyBot, AdAdware, and Avast without detecting anything specific. I did find a lot of redirection entries (like redirecting symantec.com to 127.0.0.1) in her hosts file and removed those by hand. The messages seem to have stopped, but its hard to tell if they've really stopped or we're just in between some kind of cycle. She's shut messenger off for now.
Following other instructions for cleaning this sort of thing up, I've run combofix, but didn't see anything in the log that looks funny to my untrained eye.
Currently the computer seems to be running fairly normally, except for two things. First, one set of instructions recommended running smitfraudfix from safe mode. I can't get the computer to start in safe mode. It will reboot after a few seconds back to the "sorry, Windows did not start properly" screen. The only option that works is "start windows normally." Second, the instructions for running combofix recommended disabling anti-virus. I disabled Avast with the toolbar command "stop on access protection". Now when I reboot, the Avast icon does not show in the toolbar, although Avast seems to be running based on the task manager and the Windows security console.
The OS is WinXP Pro SP3.
Could someone look at the attached HijackThis log and suggest what else I should do?
Edited by skyguy66, 17 August 2008 - 12:54 PM.