This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse Hider.MPR [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have unfortunately been infected with Trojan Horse Hider.MPR. It was picked up immediately by AVG, and although it says it is removed when I click remove all, both AVG and Malware Bytes Anti-Malware keep reporting problems if I scan again. And upon booting up I am always met with the same alert from AVG. I have not had issues getting on websites that are sometimes reported so I am hopeful not too much damage has been done yet. I also tried running both AVG and MBAM in windows safe mode and even though they both reported it gone after I removed it once, upon booting up normally it returns. Rebooting from a succesful scan to safe mode leads to nothing being found, but its obviously still there. Below is the DDS report. Let me know if you need anything else. Thanks in advance . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 21:35:05.86 on 05/11/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2300 [GMT 0:00] . AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG2013\avgrsx.exe C:\Program Files\AVG\AVG2013\avgcsrvx.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Napster\napster.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\rundll32.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\AVG\AVG2013\avgui.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Common Files\Apple\Internet Services\ubd.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\AVG\AVG2013\avgidsagent.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\AVG\AVG2013\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\AVG\AVG2013\avgnsx.exe C:\Program Files\AVG\AVG2013\avgemcx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\12.2.6\ScriptHelper.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\ATI Technologies\ATI.ACE\CORE-STATIC\CCC.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Administrator\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://home.bt.yahoo.com/ uInternet Settings,ProxyOverride = *.local uURLSearchHooks: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll mURLSearchHooks: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll mURLSearchHooks: H - No File mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\users\administrator\appdata\local\yrsnltir\hxhavtri.exe BHO: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [HxhAvtri] c:\users\administrator\appdata\local\yrsnltir\hxhavtri.exe uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; .NET4.0C; Creative AutoUpdate v1.40.01)" -"http://www8.agame.com/games/shockwave/h/horse_eventing_2/horse_eventing2_girlsgogames_co_uk.html" mRun: [NapsterShell] c:\program files\napster\napster.exe /systray mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [ROC_ROC_JULY_P1] "c:\program files\avg secure search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY mRun: [ROC_ROC_NT] "c:\program files\avg secure search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\startup\hxhavtri.exe StartupFolder: c:\users\admini~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\photof~1.lnk - c:\program files\panasonic\photofunstudio\PhAutoRun.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\12.2.6\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\pr5p6i5w.default\ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bf4dcc625-59e9-40ac-89f7-21591b3ab011%7D&mid=83c158a0f9bbc20850ad0e0872672375-4bc975ad2489380ad3122a27b680006ed5881374&ds=AVG&v=11.1.0.12&lang=en&pr=fr&d=2012-04-28%2011%3A29%3A23&sap=ku&q= FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff10.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff11.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff12.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff13.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff5.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff6.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff7.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff8.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff9.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.2.0\npsitesafety.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\administrator\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-9-21 55008] R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376] R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-10-5 93536] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552] R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2009-2-3 63096] R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2011-3-27 20384] R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-9-13 177504] R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 164832] R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-8-29 27496] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-7-27 63960] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-2-15 163328] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-10-2 5783672] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-2 193568] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files\common files\avg secure search\vtoolbarupdater\12.2.6\ToolbarUpdater.exe [2012-8-29 722528] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2012-2-15 9182208] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2012-2-15 264704] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-12-5 83472] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-7 250808] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2009-11-14 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-11-14 79360] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [2011-6-2 25832] S3 nenum13E;nenum13E;c:\users\admini~1\appdata\local\temp\nenum13E.sys [2011-1-2 31744] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] SUnknown Micorsoft Windows Service;Micorsoft Windows Service; [x] . =============== Created Last 30 ================ . 2072-04-03 13:13:14 607296 ——w- c:\program files\microsoft games\age of empires iii\deformerdllyD.dll 2067-05-21 20:35:22 106496 —-a-w- c:\program files\microsoft games\impossible creatures\Filesystem.dll 2012-11-05 20:42:11 ——– d—–w- c:\users\admini~1\appdata\local\{896A7C47-D14C-4C05-9D87-0404D0988D29} 2012-11-05 20:07:35 ——– d—–w- c:\program files\Spybot - Search & Destroy 2012-11-05 20:07:35 ——– d—–w- c:\progra~2\Spybot - Search & Destroy 2012-11-05 20:03:01 ——– d—–w- c:\users\admini~1\appdata\roaming\LavasoftStatistics 2012-11-05 20:02:21 ——– d—–w- c:\users\admini~1\appdata\roaming\Ad-Aware Antivirus 2012-11-05 19:41:35 203120 —-a-w- c:\windows\system32\drivers\PCTSD.sys 2012-11-05 19:41:35 ——– d—–w- c:\program files\common files\PC Tools 2012-11-05 19:40:52 ——– d—–w- c:\progra~2\PC Tools 2012-11-05 19:40:51 ——– d—–w- c:\users\admini~1\appdata\roaming\TestApp 2012-11-05 19:30:32 ——– d—–w- c:\program files\Enigma Software Group 2012-11-05 19:29:54 ——– d—–w- c:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP 2012-11-05 19:18:49 ——– d—–w- c:\users\admini~1\appdata\roaming\SpeedyPC Software 2012-11-05 19:18:49 ——– d—–w- c:\users\admini~1\appdata\roaming\DriverCure 2012-11-05 19:18:37 ——– d—–w- c:\progra~2\SpeedyPC Software 2012-11-04 20:58:53 ——– d—–w- c:\users\admini~1\appdata\local\{1F8B201A-026A-46C9-A78D-AA4B1638DC6C} 2012-11-04 19:18:58 ——– d—–w- c:\users\admini~1\appdata\local\yrsnltir 2012-11-04 08:42:52 ——– d—–w- c:\users\admini~1\appdata\local\{3588CFCE-C95E-4FA6-B0C6-293441FC2E52} 2012-11-03 10:26:38 ——– d—–w- c:\users\admini~1\appdata\local\{19B6AC01-D0EB-41CE-AE62-F1A271F56F9C} 2012-11-02 09:15:25 ——– d—–w- c:\users\admini~1\appdata\local\{010F65DF-3C3D-4BC7-BCE5-5E35F6C3C45D} 2012-11-01 12:45:57 ——– d—–w- c:\users\admini~1\appdata\local\{246916A8-9E89-40AE-B602-757CC602877C} 2012-11-01 09:06:04 ——– d—–w- c:\users\admini~1\appdata\local\{52C25F90-C724-41D2-821B-1CCE7DE8F2B0} 2012-11-01 08:43:47 ——– d—–w- c:\users\admini~1\appdata\local\{9AC4DEF3-AEC8-4123-90AC-31FAF1834005} 2012-10-31 14:36:26 ——– d—–w- c:\users\admini~1\appdata\local\{DCF21C74-61D0-488C-9E14-6E7211E6C377} 2012-10-30 09:36:05 ——– d—–w- c:\users\admini~1\appdata\local\{4B5115AD-FD7E-4D03-B36A-BF6371198162} 2012-10-29 05:54:31 ——– d—–w- c:\users\admini~1\appdata\local\{380AA61B-8719-4D5F-9ABE-D94538CFA24A} 2012-10-28 19:25:40 ——– d—–w- c:\users\admini~1\appdata\local\{897CD980-EE1E-4A98-B4DB-69DFEF88FB0E} 2012-10-27 21:47:01 ——– d—–w- c:\users\admini~1\appdata\local\{6072D39D-39C8-4DF8-A5D6-CDE978A763F5} 2012-10-27 09:46:25 ——– d—–w- c:\users\admini~1\appdata\local\{18BED22C-7398-4496-89B2-471047931B37} 2012-10-26 08:11:26 ——– d—–w- c:\users\admini~1\appdata\local\{9C5747C5-9D46-417E-BF3F-7529A773633D} 2012-10-25 11:32:14 ——– d—–w- c:\users\admini~1\appdata\local\{A505E34F-8EB0-402D-93AA-ED9F0EA2ED92} 2012-10-25 07:54:12 ——– d—–w- c:\users\admini~1\appdata\local\{3D85A6B5-4CA3-40D0-90B4-D427CA2FD24F} 2012-10-24 08:26:39 ——– d—–w- c:\users\admini~1\appdata\local\{8C311797-94DF-434D-AADE-C468DA461C5A} 2012-10-23 09:03:53 ——– d—–w- c:\users\admini~1\appdata\local\{FE82CFE6-A9C5-4783-A52F-62F823E3BBDE} 2012-10-22 08:14:04 ——– d—–w- c:\users\admini~1\appdata\local\{F0D9049B-9235-476C-AB55-9EA5B58B50CF} 2012-10-21 07:43:54 ——– d—–w- c:\users\admini~1\appdata\local\{58FE7224-5CD3-4F0D-9041-E937EE54D2DB} 2012-10-20 10:07:41 ——– d—–w- c:\users\admini~1\appdata\local\{93FF91D7-94FE-42A0-B0FB-1184F1B493F8} 2012-10-20 06:55:03 ——– d—–w- c:\users\admini~1\appdata\local\{5DF2335C-0F6A-40C4-888F-D8B84D02FF08} 2012-10-19 14:16:22 ——– d—–w- c:\users\admini~1\appdata\local\{0785D2AD-77F4-4E35-8FAB-6023BB7BBED3} 2012-10-18 21:50:59 ——– d—–w- c:\users\admini~1\appdata\local\{511F87C2-2C53-41E0-9B0D-7204620BB7F0} 2012-10-18 09:04:38 ——– d—–w- c:\users\admini~1\appdata\local\{25C23D01-0C72-4A16-981A-23B360708B9E} 2012-10-17 08:28:34 ——– d—–w- c:\users\admini~1\appdata\local\{048077EF-FF11-495C-BD09-34CBA39CABE4} 2012-10-16 14:33:02 ——– d—–w- c:\users\admini~1\appdata\local\{70454EFE-2D4C-479F-A498-38A247D8FC31} 2012-10-16 07:10:03 ——– d—–w- c:\users\admini~1\appdata\local\{605425D3-E364-44AA-8708-BC33DB1A20D4} 2012-10-15 07:57:50 ——– d—–w- c:\users\admini~1\appdata\local\{EC68A1B2-FC01-4CA2-9E91-F7A559CE1FCE} 2012-10-14 09:39:13 ——– d—–w- c:\users\admini~1\appdata\local\{05C798E2-7E52-4AFA-8FEC-10361B87EE8B} 2012-10-14 07:56:48 ——– d—–w- c:\users\admini~1\appdata\local\{C5E17C35-2126-4F3D-9F1D-B6D37944BE4A} 2012-10-13 12:50:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-13 12:49:02 ——– d—–w- c:\program files\iPod 2012-10-13 12:49:01 ——– d—–w- c:\progra~2\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-13 09:57:29 ——– d—–w- c:\users\admini~1\appdata\local\{B87D7276-A6E4-4D72-B5CE-9F75A3CF4CFD} 2012-10-12 08:48:48 ——– d—–w- c:\users\admini~1\appdata\local\{8A1BA2D4-DE99-4564-BCD4-4B52B5E049B4} 2012-10-11 09:29:53 ——– d—–w- c:\users\admini~1\appdata\local\{FC28620A-9B1D-4096-B34C-3096C4B2D8E9} 2012-10-10 09:19:49 985088 —-a-w- c:\windows\system32\crypt32.dll 2012-10-10 09:19:49 98304 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-10 09:19:49 133120 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-10 09:19:44 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-10-10 09:19:43 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-10 09:19:39 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-10 09:19:39 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-10-10 09:10:43 ——– d—–w- c:\users\admini~1\appdata\local\{F70BE33E-E552-418C-9409-D59E2D0ADA3C} 2012-10-09 09:09:37 ——– d—–w- c:\users\admini~1\appdata\local\{4D07CA71-4FEA-4448-B39B-0A9809102807} 2012-10-08 09:28:25 ——– d—–w- c:\users\admini~1\appdata\local\{77FAE026-4D5F-4B81-82C0-1DAD50BDD55F} 2012-10-07 07:44:28 ——– d—–w- c:\users\admini~1\appdata\local\{B9A11CD3-D19F-42EB-8C8A-8E79C4430338} . ==================== Find3M ==================== . 2012-10-09 11:38:10 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-09 11:38:10 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-09 19:47:28 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll 2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-21 12:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-08-14 18:58:36 21840 —-atw- c:\windows\system32\SIntfNT.dll 2012-08-14 18:58:36 17212 —-atw- c:\windows\system32\SIntf32.dll 2012-08-14 18:58:36 12067 —-atw- c:\windows\system32\SIntf16.dll . ============= FINISH: 21:36:06.40 ===============
Hi Jerry125, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download ComboFix from one of these locations:

Link 1

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. If after running should you recieve a message "Illegal operation on a registry key that has already been marked for deletion" or similar, reboot the compter.


4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
I have disabled AVG 2013 (There is no guide for 2013 on that page but it seems identical to the 2011 instructions) but Combofix has flashed up warning me that it is still active. This despite the fact that it is definitely disabled, the only option anywhere is to reenable protection. What should I do?
Also, should I be running Combofix in normal or safe mode? I booted in normal mode but as there is no cancel button on this warning popup that has appeared I'm afraid to reboot or turn off in case it does something.
Isn't this just typical, I left my PC on overnight but we had a powercut. When I booted up the infection seemed to have got a lot worse, and I can now no longer access sites like the official AVG site. Also Combofix won't run at all, I right click, choose run as administrator and nothing seems to happen. I left it like that for about an hour while keeping an eye on it in my room and nothing happened. Could that be down to the infection, or the fact that my computer rebooted after installing but before scanning with Combofix? Unfortunately I can't access the link above anymore so I can't redownload Combofix to make sure it installs properly. Thanks for advice so far, hopefully something will start going right soon!
Sorry, you can ignore that last message, managed to get it to run. Here is the combofix log:

ComboFix 12-11-06.03 - Administrator 07/11/2012 18:18:41.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2398 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\patch.exe
c:\programdata\epyks.pad
c:\users\Administrator\AppData\Local\bbegaqyt.log
c:\users\Administrator\AppData\Local\jubgkptc.log
c:\users\Administrator\AppData\Local\krqviaws.log
c:\users\Administrator\AppData\Local\nnrntldw.log
c:\users\Administrator\AppData\Local\thcshooc.log
c:\users\Administrator\AppData\Local\utuwiius.log
c:\users\Administrator\AppData\Local\wmlquhcv.log
c:\users\Administrator\AppData\Local\yhfeepai.log
c:\users\Administrator\AppData\Local\yrsnltir\hxhavtri.exe
c:\users\Administrator\AppData\Roaming\Roaming
c:\users\Administrator\AppData\Roaming\Roaming\Quest3D\ShipSimExtreme\channels.lst
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-07 to 2012-11-07 )))))))))))))))))))))))))))))))
.
.
2072-04-03 13:13 . 2008-03-21 14:46 607296 ——w- c:\program files\Microsoft Games\Age of Empires III\deformerdllyD.dll
2012-11-07 18:32 . 2012-11-07 18:32 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-11-05 20:07 . 2012-11-05 20:27 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2012-11-05 20:07 . 2012-11-05 20:08 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-11-05 20:03 . 2012-11-05 20:03 ——– d—–w- c:\users\Administrator\AppData\Roaming\LavasoftStatistics
2012-11-05 20:02 . 2012-11-05 20:02 ——– d—–w- c:\users\Administrator\AppData\Roaming\Ad-Aware Antivirus
2012-11-05 19:41 . 2012-11-05 20:40 ——– d—–w- c:\program files\Common Files\PC Tools
2012-11-05 19:41 . 2012-06-22 15:34 203120 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2012-11-05 19:40 . 2012-11-05 19:58 ——– d—–w- c:\programdata\PC Tools
2012-11-05 19:40 . 2012-11-05 19:40 ——– d—–w- c:\users\Administrator\AppData\Roaming\TestApp
2012-11-05 19:30 . 2012-11-05 19:30 ——– d—–w- c:\program files\Enigma Software Group
2012-11-05 19:29 . 2012-11-05 19:39 ——– d—–w- c:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP
2012-11-05 19:18 . 2012-11-05 19:18 ——– d—–w- c:\users\Administrator\AppData\Roaming\SpeedyPC Software
2012-11-05 19:18 . 2012-11-05 19:18 ——– d—–w- c:\users\Administrator\AppData\Roaming\DriverCure
2012-11-05 19:18 . 2012-11-05 19:36 ——– d—–w- c:\programdata\SpeedyPC Software
2012-10-27 10:05 . 2012-10-27 10:05 ——– d—–w- c:\programdata\McAfee
2012-10-13 12:50 . 2012-08-21 12:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-13 12:49 . 2012-10-13 12:49 ——– d—–w- c:\program files\iPod
2012-10-13 12:49 . 2012-10-13 12:49 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-13 10:04 . 2012-10-13 10:04 ——– d—–w- c:\users\Default\AppData\Roaming\TuneUp Software
2012-10-10 09:19 . 2012-06-02 00:02 985088 —-a-w- c:\windows\system32\crypt32.dll
2012-10-10 09:19 . 2012-06-02 00:02 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-10 09:19 . 2012-06-02 00:02 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 09:19 . 2012-08-24 15:53 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-10-10 09:19 . 2012-09-13 13:28 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-10 09:19 . 2012-08-29 11:27 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-10 09:19 . 2012-08-29 11:27 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-09 11:38 . 2012-05-07 16:11 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 11:38 . 2011-08-21 12:48 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl2012-10-05 02:26 . 2012-10-05 02:26 93536 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-10-02 02:30 . 2012-10-02 02:30 159712 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2012-09-29 19:54 . 2010-05-22 09:56 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-21 02:46 . 2012-09-21 02:46 164832 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2012-09-21 02:46 . 2012-09-21 02:46 177376 —-a-w- c:\windows\system32\drivers\avglogx.sys
2012-09-21 02:45 . 2012-09-21 02:45 19936 —-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2012-09-21 02:45 . 2012-09-21 02:45 55008 —-a-w- c:\windows\system32\drivers\avgidshx.sys
2012-09-14 02:05 . 2012-09-14 02:05 35552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2012-09-13 02:11 . 2012-09-13 02:11 177504 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2012-09-09 19:47 . 2011-07-21 20:08 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2012-08-29 14:40 . 2012-08-29 14:40 27496 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-08-24 06:59 . 2012-09-23 07:49 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-23 07:49 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-23 07:49 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-23 07:49 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-23 07:49 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-23 07:49 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-21 12:01 . 2010-08-29 16:04 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-08-14 18:58 . 2011-07-02 13:04 21840 —-atw- c:\windows\system32\SIntfNT.dll
2012-08-14 18:58 . 2011-07-02 13:04 17212 —-atw- c:\windows\system32\SIntf32.dll
2012-08-14 18:58 . 2011-07-02 13:04 12067 —-atw- c:\windows\system32\SIntf16.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0fc64d74-ea76-49a3-b606-7801b5013798}"= "c:\program files\GoldMember\tbGold.dll" [2009-07-15 2224152]
.
[HKEY_CLASSES_ROOT\clsid\{0fc64d74-ea76-49a3-b606-7801b5013798}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0fc64d74-ea76-49a3-b606-7801b5013798}]
2009-07-15 09:09 2224152 —-a-w- c:\program files\GoldMember\tbGold.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-09-30 20:35 1734240 —-a-w- c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0fc64d74-ea76-49a3-b606-7801b5013798}"= "c:\program files\GoldMember\tbGold.dll" [2009-07-15 2224152]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-09-30 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{0fc64d74-ea76-49a3-b606-7801b5013798}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{0FC64D74-EA76-49A3-B606-7801B5013798}"= "c:\program files\GoldMember\tbGold.dll" [2009-07-15 2224152]
.
[HKEY_CLASSES_ROOT\clsid\{0fc64d74-ea76-49a3-b606-7801b5013798}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"MobileDocuments"="c:\program files\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NapsterShell"="c:\program files\Napster\napster.exe" [2008-12-19 323216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"P17RunE"="P17RunE.dll" [2008-03-28 14848]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 636032]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-09-30 947808]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-10-10 3116152]
"ROC_ROC_NT"="c:\program files\AVG Secure Search\ROC_ROC_NT.exe" [2012-09-30 856160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
.
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
PHOTOfunSTUDIO.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe [2009-5-13 44176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,,c:\users\Administrator\AppData\Local\yrsnltir\hxhavtri.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-584275502-1596424334-3056331227-500]
"EnableNotificationsRef"=dword:00000001
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MICORSOFT_WINDOWS_SERVICE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-07 11:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://home.bt.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\pr5p6i5w.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bf4dcc625-59e9-40ac-89f7-21591b3ab011%7D&mid=83c158a0f9bbc20850ad0e0872672375-4bc975ad2489380ad3122a27b680006ed5881374&ds=AVG&v=11.1.0.12&lang=en&pr=fr&d=2012-04-28%2011%3A29%3A23&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-HxhAvtri - c:\users\Administrator\AppData\Local\yrsnltir\hxhavtri.exe
HKLM-Run-ROC_ROC_JULY_P1 - c:\program files\AVG Secure Search\ROC_ROC_JULY_P1.exe
AddRemove-Arabian Nights: Any XP - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights Any XP.exe
AddRemove-Arabian Nights: Civilization Objects - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights Civilization Objects.exe
AddRemove-Arabian Nights: Download First - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights Download First.exe
AddRemove-Arabian Nights: MM - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights MM.exe
AddRemove-Arabian Nights: MM Animals 1 - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights MM Animals 1.exe
AddRemove-Arabian Nights: MM Animals 2 - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal Arabian Nights MM Animals 2.exe
AddRemove-BattlEye - c:\program files\Bohemia Interactive\ArmA 2\BattlEye\UnInstallBE.exe
AddRemove-Zoo Tycoon 2 - c:\program files\Microsoft Games\Zoo Tycoon 2\UNINSTAL.EXE
AddRemove-Radical Remake - Part 1 - c:\program files\Microsoft Games\Zoo Tycoon 2\Uninstal.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-07 19:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hxhavtri.exe 101156 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\G*e*n*i*e*"!\FM Genie Scout 2009 XE]
"GameDir"="c:\\Users\\Administrator\\Documents\\Sports Interactive\\Football Manager 2009\\games"
"ShortlistDir"=""
"ScreenshotsDir"="c:\\Users\\Administrator\\Documents\\Sports Interactive\\Football Manager 2009"
"SaveDir"="c:\\Users\\Administrator\\Documents\\Sports Interactive\\Football Manager 2009\\"
"LangDB"="c:\\Program Files\\Sports Interactive\\Football Manager 2009\\data\\db\\900\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"SkinName"="Champions League"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000066
"UniqueID"="A5-E980-E49F"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"GraphStep"=dword:00000000
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,85,1f,
e2,6f,98,44,06,a3,32,c9,b5,2c,9c,16,1b
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c5,f0,
a0,50,96,ba,59,a0,e4,5f,fc,cc,40,f6,17
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,3b,1b,02,e8,b8,
21,5b,3b,39,03,ba,67,11,39,e1,dd,8b,d8
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,cf,2a,
8d,37,18,d5,02,92,c5,0e,38,73,42,20,de
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1b,d2,
c6,70,f0,31,0b,a0,7d,c3,79,c4,8f,cb,b1
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,3b,1b,8c,6e,ad,
88,4a,d8,9b,03,ad,6a,2c,34,4f,d9,71,2b
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:6c,b1,44,a3,97,0c,cc,01
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,de,16,c2,32,ab,5c,47,bf,d0,a5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,de,16,c2,32,ab,5c,47,bf,d0,a5,\
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aif"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aifc"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aiff"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.avi"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\MSPaint.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.cda"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.db\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\scalc.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.drv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gdb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\instclient.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gtl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="hdc_auto_file"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itms"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itpc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itpc"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u8\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u8"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4a"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4b"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4p"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4r\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4r"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4v"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.mp2"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.mp3"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pak\UserChoice]
@Denied: (2) (Administrator)
"Progid"="DUP5.Files"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcast\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pcast"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\AcroRd32.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pls"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\7zFM.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rcd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\soffice.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad.exe"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wav"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wave\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wave"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:fa,ec,3b,39,e9,d6,21,fd,90,51,c3,27,d4,b0,00,8e,b2,dc,6d,50,c7,2e,5b,
0b,0c,ed,e0,0e,06,d6,67,5d,c6,a6,a1,b6,52,da,68,d3,1c,ab,79,7d,a1,a9,b7,92,\
"??"=hex:59,e5,97,70,47,08,a5,1e,f6,13,83,cc,52,0d,a6,6c
.
[HKEY_USERS\S-1-5-21-584275502-1596424334-3056331227-500\Software\SecuROM\License information*]
"datasecu"=hex:f9,64,f2,99,d9,46,f2,dc,64,e9,5a,d7,88,32,19,8b,dc,fb,a4,0d,c2,
43,21,af,16,f4,fe,c5,f6,2b,04,3a,90,74,cd,a3,60,49,64,55,28,3e,c9,94,29,92,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2013\avgrsx.exe
c:\program files\AVG\AVG2013\avgcsrvx.exe
c:\windows\system32\atiesrxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AVG\AVG2013\avgidsagent.exe
c:\program files\AVG\AVG2013\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-11-07 19:34:43 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-07 19:34
.
Pre-Run: 23,770,988,544 bytes free
Post-Run: 35,300,802,560 bytes free
.
- - End Of File - - A7AAFA8CD8312C8A9900420FFB2DA690
Hi Jerry125,

I'm sorry to say that your computer is infected with Ramnit. Ramnit is a file infector with IRCBot functionality. It has the ability to download and run programs or commands. The only way to effectively clean this machine is to reformat and reinstall the Operating System. As you have seen with AVG and the combofix log, each time the infection is "removed" it respawns.

A Complete Reformat and Reinstall is the only way to clean the infection. This includes All Drives that contain .exe, .scr, .hlm, .html .dll files.
  • Backup all your documents and important items only.
    data/documents/pictures/movies/songs/etc..
  • DO NOT backup any executable files (,exe .scr .html or .htm) or .dll files
  • Do Not back up compressed files (zip/cab/rar) files that may contain these types of files
  • Reformat and Reinstall as outlined HERE

A CD would be best, but a blank USB device will work. Make sure there aren't any executable on it.

Be further advised that these infections have backdoor capabilities.

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
Feel free to ask any questions, but keep in mind a Reformat is the only way to clean this computer
Ahhh this is what I feared all along. I had some hope this morning as when I booted up and AVG detected nothing and when I ran an MBAM scan that came through clean too. Though I knew not to get my hopes up too much. I presumed these "clean" scans meant nothing by what I'd read about the infection though. Oh well, thanks for all your help anyway, and if you are absolutely certain nothing can be done I guess I'll have to get reformatting at the weekend. :(
Hi Jerry125,

*NewlyCreated* - MICORSOFT_WINDOWS_SERVICE

This is one of the items that will keep getting recreated. We could keep going after it for days but it would respawn on reboot. The log indicates that this service is created at reboot then removes itself but continues continues to run in memory. Here's an example to illustrate the futility. Keep in mind that the infection effects different computers in different ways. The symptoms may vary but the results are the same. In some cases continuing attempts to remove it have resulted in an unbootable computer.

Reformatting and reinstalling is not only the best method to deal with this but in most cases the time spent chasing it is a lot longer than the time the reinstall would take.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI