This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hider.mpr Trojan [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Hope someone can help.
AVG has detected hider.mpr on my system, all access to antivirus sites seems to be blocked and I cant remove the file. I have used Malware Bytes to scan the system and it detects a number of files which after deleting come back after reboot. I removed AVG and installed Avast but it couldnt connect to the server to update.

I have read the need help topic and here are my log files from OTL:

OTL logfile created on: 02/03/2012 15:50:53 - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1015.36 Mb Total Physical Memory | 431.69 Mb Available Physical Memory | 42.52% Memory free
2.38 Gb Paging File | 1.98 Gb Available in Paging File | 83.08% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 50.50 Gb Total Space | 25.69 Gb Free Space | 50.87% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.68 Gb Free Space | 12.68% Space Free | Partition Type: FAT32
Drive Y: | 913.09 Gb Total Space | 900.46 Gb Free Space | 98.62% Space Free | Partition Type: NTFS

Computer Name: OFFICELAPTOP | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\SMINST\Scheduler.exe ()
PRC - C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\12022301\algo.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\SMINST\Scheduler.exe ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (Micorsoft Windows Service) – File not found
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (AswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500) – C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (GTIPCI21) – C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (Accelerometer) – C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (hpdskflt) – C:\WINDOWS\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.8
FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:7.3.0.0
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/03/02 14:53:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/27 11:35:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/27 11:35:37 | 000,000,000 | —D | M]

[2010/07/20 07:53:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2012/03/02 09:01:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions
[2012/01/12 08:46:48 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/27 11:44:42 | 000,000,000 | —D | M] (iMacros for Firefox) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2012/01/27 08:55:56 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/20 13:42:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2012/03/02 09:01:25 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jp37e6xt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/02/27 11:35:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\JP37E6XT.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
[2012/02/16 14:40:42 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/06/14 11:03:21 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/16 10:42:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/16 10:42:53 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/03/02 13:30:26 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [FghHjcjw] C:\Documents and Settings\Administrator\Local Settings\Application Data\wapuyyag\fghhjcjw.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1251916970215 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E20227C-293A-4DED-AAFF-3DEB6462506F}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Administrator\Local Settings\Application Data\wapuyyag\fghhjcjw.exe) - C:\Documents and Settings\Administrator\Local Settings\Application Data\wapuyyag\fghhjcjw.exe File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 23:07:00 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/02 15:19:47 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/03/02 14:54:22 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/03/02 14:54:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
[2012/03/02 14:54:17 | 000,337,112 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2012/03/02 14:54:17 | 000,020,696 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/03/02 14:54:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/03/02 14:54:16 | 000,610,648 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/03/02 14:54:16 | 000,053,848 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/03/02 14:54:16 | 000,035,672 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/03/02 14:54:15 | 000,095,704 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/03/02 14:54:15 | 000,089,048 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2012/03/02 14:54:15 | 000,024,920 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/03/02 14:53:48 | 000,201,352 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2012/03/02 14:53:48 | 000,041,184 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2012/03/02 14:53:28 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/03/02 14:53:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/03/02 13:21:26 | 000,000,000 | —D | C] – C:\ComboFix
[2012/03/02 11:35:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2012/03/02 11:35:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/02 11:35:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/03/02 11:35:04 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/03/02 11:35:04 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/02 11:19:20 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/03/02 11:19:20 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/03/02 11:19:20 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/03/02 11:19:20 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/03/02 11:19:07 | 000,000,000 | —D | C] – C:\Qoobox
[2012/03/02 10:38:31 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/03/02 10:35:56 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/03/02 10:35:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
[2012/03/02 09:34:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/03/02 09:34:30 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2012/03/02 09:34:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/02/28 10:35:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegAce
[2012/02/28 10:35:43 | 000,000,000 | —D | C] – C:\WINDOWS\RegAce
[2012/02/27 09:50:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\wapuyyag
[2012/02/22 14:11:06 | 000,000,000 | —D | C] – C:\Config.Msi
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/02 15:07:51 | 000,097,712 | -H– | M] () – C:\Documents and Settings\Administrator\uWybQGL
[2012/03/02 15:07:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/02 15:07:40 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/02 15:07:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/02 15:07:18 | 1064,751,104 | -HS- | M] () – C:\hiberfil.sys
[2012/03/02 15:02:51 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/02 14:54:18 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/03/02 14:54:15 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/03/02 13:30:26 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/02 11:35:06 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/02 11:15:22 | 003,536,352 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/02 11:04:01 | 000,000,951 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/03/02 10:38:35 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/02/28 11:06:50 | 000,000,030 | —- | M] () – C:\WINDOWS\System32\MAPISVC.INF
[2012/02/28 10:36:00 | 000,000,388 | —- | M] () – C:\WINDOWS\tasks\RegAce Scheduled Scan - Administrator.job
[2012/02/27 11:35:47 | 000,000,742 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/27 11:35:47 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 16:23:26 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2012/02/23 16:23:21 | 000,201,352 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2012/02/23 16:12:28 | 000,610,648 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/02/23 16:12:16 | 000,337,112 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2012/02/23 16:10:46 | 000,035,672 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/02/23 16:10:39 | 000,053,848 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/02/23 16:10:25 | 000,095,704 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/02/23 16:10:22 | 000,089,048 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2012/02/23 16:10:16 | 000,020,696 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/02/23 16:07:33 | 000,024,920 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/02/23 08:42:34 | 000,485,850 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/23 08:42:34 | 000,088,030 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/23 08:36:57 | 000,000,792 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/02/23 08:33:35 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/02 15:07:51 | 000,097,712 | -H– | C] () – C:\Documents and Settings\Administrator\uWybQGL
[2012/03/02 14:54:33 | 000,000,900 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/02 14:54:33 | 000,000,896 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/02 14:54:18 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/03/02 11:35:06 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/02 11:19:20 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/03/02 11:19:20 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/03/02 11:19:20 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/03/02 11:19:20 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/03/02 11:19:20 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/03/02 10:38:35 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/03/02 10:38:31 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/03/02 09:34:41 | 000,000,951 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/02/28 10:36:00 | 000,000,388 | —- | C] () – C:\WINDOWS\tasks\RegAce Scheduled Scan - Administrator.job
[2012/02/27 11:35:47 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/15 10:01:18 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/15 10:01:18 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/06/14 15:15:24 | 000,005,632 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/13 08:32:08 | 000,000,132 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Adobe PNG Format CS5 Prefs
[2011/04/12 11:35:47 | 000,038,481 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Comma Separated Values (DOS).ADR
[2011/04/12 11:19:54 | 000,009,371 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Comma Separated Values (DOS).EML
[2011/03/10 09:59:53 | 000,000,132 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Adobe GIF Format CS5 Prefs
[2011/03/10 09:55:26 | 000,001,456 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2011/02/15 11:47:03 | 000,002,828 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/02/15 11:47:03 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\71A40280F0.sys
[2010/11/30 12:06:07 | 000,202,048 | —- | C] () – C:\WINDOWS\System32\AVLibrary.dll
[2010/10/25 09:49:43 | 000,000,021 | —- | C] () – C:\WINDOWS\mtagree07011993t.dat
[2010/10/14 12:38:43 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2010/07/20 07:53:27 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/26 16:39:36 | 000,000,243 | —- | C] () – C:\WINDOWS\ActiveAct.INI

========== LOP Check ==========

[2010/09/14 14:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/11/15 09:15:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Electronic Arts
[2011/02/28 17:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\gtk-2.0
[2010/12/23 12:01:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Opera
[2011/09/19 13:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\salesforce.com
[2006/07/17 09:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SampleView
[2011/02/08 11:22:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SmartDraw
[2010/09/14 15:51:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/03/02 14:53:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/02/28 10:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegAce
[2011/01/21 11:37:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2009/09/03 09:17:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sage
[2012/02/28 10:36:00 | 000,000,388 | —- | M] () – C:\WINDOWS\Tasks\RegAce Scheduled Scan - Administrator.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/09/03 02:27:05 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/03/02 10:38:35 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/06/14 11:04:27 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2012/03/02 15:07:18 | 1064,751,104 | -HS- | M] () – C:\hiberfil.sys
[2010/03/25 15:11:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/03/25 15:11:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2009/09/02 23:45:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/03/02 15:07:17 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2011/03/11 17:04:07 | 000,001,353 | —- | M] () – C:\Rescued document.txt
[2009/09/02 19:36:14 | 000,000,479 | —- | M] () – C:\sghmmail.ECF

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/07 13:02:30 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/02/23 16:23:26 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/09/03 02:37:42 | 000,001,506 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/07 05:52:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/07 05:52:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/09/02 23:53:15 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/09/03 10:11:12 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/07 13:08:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/03/02 09:27:19 | 004,831,232 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2012/03/02 13:51:00 | 074,920,720 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\avast_free_antivirus_setup.exe
[2012/03/02 09:25:21 | 004,424,671 | R— | M] (Swearware) – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/03/02 10:28:44 | 009,502,424 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/02 11:07:17 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/03/02 15:16:28 | 000,879,700 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\SecurityCheck.exe
[2008/11/12 15:40:29 | 015,083,520 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\Desktop\spybotsd160.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-24 03:01:14

< End of report >


OTL Extras logfile created on: 02/03/2012 15:50:53 - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1015.36 Mb Total Physical Memory | 431.69 Mb Available Physical Memory | 42.52% Memory free
2.38 Gb Paging File | 1.98 Gb Available in Paging File | 83.08% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 50.50 Gb Total Space | 25.69 Gb Free Space | 50.87% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.68 Gb Free Space | 12.68% Space Free | Partition Type: FAT32
Drive Y: | 913.09 Gb Total Space | 900.46 Gb Free Space | 98.62% Space Free | Partition Type: NTFS

Computer Name: OFFICELAPTOP | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler – ()
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2F0D3C9E-4FB6-4A14-B0C4-42328F570177}" = Fingerprint Sensor Minimum Install
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.00 E2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = HP Backup and Recovery Manager Installer
"{48CF6549-B45D-4313-9927-EFCCC8A3493F}" = TIPCI
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75ECB75A-522C-4312-8DE7-597CDA9D96A3}" = HP Mobile Data Protection System
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E0DBC47C-ED3F-4A1B-A929-9A26DAAA14B3}" = Application Installer 4.00.B5
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E7485CE5-C004-44D6-AA3E-7EE4DFE2B70E}" = HP Support Phone Numbers
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F9329C54-11AF-4A17-B2D8-C019B81AA1B4}" = Accounts
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"avast" = avast! Free Antivirus
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"E.M. PowerPoint Video Converter_is1" = E.M. PowerPoint Video Converter 3.20
"ie8" = Windows Internet Explorer 8
"InstallShield_{48CF6549-B45D-4313-9927-EFCCC8A3493F}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{F9329C54-11AF-4A17-B2D8-C019B81AA1B4}" = Sage Instant Accounts v14
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.457
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 02/03/2012 04:53:09 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 15 time(s).

Error - 02/03/2012 04:53:15 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 16 time(s).

Error - 02/03/2012 04:53:25 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 17 time(s).

Error - 02/03/2012 04:53:29 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 18 time(s).

Error - 02/03/2012 04:53:35 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 19 time(s).

Error - 02/03/2012 04:53:39 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 20 time(s).

Error - 02/03/2012 04:53:59 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 23 time(s).

Error - 02/03/2012 04:54:25 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 27 time(s).

Error - 02/03/2012 04:54:29 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 28 time(s).

Error - 02/03/2012 05:04:34 | Computer Name = OFFICELAPTOP | Source = Service Control Manager | ID = 7034
Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It
has done this 148 time(s).


< End of report >
Hi letterman,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI