In my post #40 I gave you detailed instructions for cleaning your System Restore files, and I also included a link in the information for doing this:
http://www.microsoft.com/windowsxp/u...s/mcgill1.mspx
This is the item your antivirus program is finding, it is a protected file and can only be removed by following the instructions I posted. Avira may try to delete it, but it cannot, and the item will continue to be identified until you clear your infected System Restore point.
C:\System Volume Information\_restore{17913FD4-45AD-4887-AA5D-26A9E19EBD19}\RP4\A0000605.exe
Make sure you have viewing all files and folders enabled so you can see this file which has been renamed and is benign:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
C:\WINDOWS\system32\cbXQiHBU.dll_old <<< navigate to that file and delete it.
Empty your Recycle Bin on the Desktop to clean it from there.
Disable TeaTimer, restart the computer
Download ResetTeaTimer.bat.
http://downloads.subratam.org/ResetTeaTimer.bat
Double click ResetTeaTimer.bat
That should remove the items from TT's memory, if the items (which are dead...not malware) appear again, then uninstall Spybot S&D completely, restart then go through those steps again. Then check the log to make sure they are gone. Then reinstall Spybot S&D and reactivate TT if you use it.
Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:
O2 - BHO: (no name) - {6D35C75F-7BAF-4B9D-8BF1-DCCC655BF6CF} - (no file)
O2 - BHO: (no name) - {A98D0065-7326-41B5-B8D9-C5B692CDB82F} - (no file)
O2 - BHO: (no name) - {B87DB383-2A35-40A6-89E3-09F694B14884} - (no file)
O4 - HKCU\..\RunOnce: [SpybotDeletingB2474] command /c del "C:\WINDOWS\system32\cbXQiHBU.dll_old"
O20 - Winlogon Notify: geBuUlLE - C:\WINDOWS\
O21 - SSODL: VolumeRam - {205e4f97-849e-4a84-98eb-c1c1ac0c5bdc} - (no file)
Close all programs but HJT and all browser windows, then click on "Fix Checked"
Would not hurt to run clean manager:
http://spyware-free.us/tutorials/cleanmgr/
Remember...when an item is an infected System Restore file it will start like this: C:\System Volume Information\_restore
Thanks