This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adknowledge Malware Removal?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 6/21/2013 6:34:43 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\David\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1011.88 Mb Total Physical Memory | 348.40 Mb Available Physical Memory | 34.43% Memory free
2.37 Gb Paging File | 1.74 Gb Available in Paging File | 73.36% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.05 Gb Total Space | 129.34 Gb Free Space | 91.05% Space Free | Partition Type: NTFS

Computer Name: ACER-925BE1910B | User Name: David | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/21 06:34:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\David\Desktop\OTL (2).exe
PRC - [2013/06/20 23:52:31 | 000,212,992 | —- | M] (Realtek Semiconductor Corp.) – C:\Documents and Settings\David\Local Settings\Temp\RtkBtMnt.exe
PRC - [2013/06/14 18:28:44 | 000,825,808 | —- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013/05/09 01:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 01:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/11/13 14:08:12 | 003,487,240 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
PRC - [2012/11/13 14:08:08 | 003,825,176 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2012/11/13 14:07:20 | 001,369,624 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2012/11/13 14:07:16 | 001,103,392 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2009/02/19 18:52:20 | 000,817,672 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2009/01/10 20:24:38 | 000,565,248 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\AcerVCM.exe
PRC - [2008/11/27 12:00:58 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/11/10 00:43:44 | 000,345,336 | —- | M] (QUALCOMM, Inc.) – C:\QUALCOMM\QDLService\QDLService.exe
PRC - [2008/09/12 15:01:28 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/09/12 15:01:24 | 000,182,808 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 05:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2013/06/21 05:11:35 | 002,089,984 | —- | M] () – C:\Program Files\AVAST Software\Avast\defs\13062102\algo.dll
MOD - [2013/06/20 14:28:41 | 002,089,984 | —- | M] () – C:\Program Files\AVAST Software\Avast\defs\13062005\algo.dll
MOD - [2013/06/14 18:28:42 | 000,393,168 | —- | M] () – C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppgooglenaclpluginchrome.dll
MOD - [2013/06/14 18:28:40 | 004,051,408 | —- | M] () – C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll
MOD - [2013/06/14 18:27:48 | 001,597,392 | —- | M] () – C:\Program Files\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll
MOD - [2012/11/13 14:06:32 | 000,158,624 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2012/11/13 14:06:30 | 000,108,960 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2012/11/13 14:06:28 | 000,554,400 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
MOD - [2012/11/13 14:06:28 | 000,528,288 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl
MOD - [2012/11/13 14:06:28 | 000,416,160 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2012/08/23 09:38:24 | 000,574,840 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Spybot – (SDWSCService)
SRV - File not found [Auto | Running] – C:\Program Files\Spybot – (SDUpdateService)
SRV - File not found [Auto | Running] – C:\Program Files\Spybot – (SDScannerService)
SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc)
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2013/05/09 01:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV - [2008/11/27 12:00:58 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/11/10 00:43:44 | 000,345,336 | —- | M] (QUALCOMM, Inc.) [Auto | Running] – C:\QUALCOMM\QDLService\QDLService.exe – (QDLService)
SRV - [2008/09/12 15:01:28 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts5161ccid.sys – (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts516xIR.sys – (Rts516xIR)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – c:\acernb\int15.sys – (int15.sys)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\David\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2013/05/09 01:59:10 | 000,765,736 | —- | M] (AVAST Software) [File_System | System | Running] – C:\WINDOWS\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2013/05/09 01:59:10 | 000,368,944 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP)
DRV - [2013/05/09 01:59:10 | 000,174,664 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\aswVmm.sys – (aswVmm)
DRV - [2013/05/09 01:59:10 | 000,056,080 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2013/05/09 01:59:10 | 000,049,376 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\aswRvrt.sys – (aswRvrt)
DRV - [2013/05/09 01:59:09 | 000,066,336 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswMonFlt.sys – (aswMonFlt)
DRV - [2013/05/09 01:59:09 | 000,049,760 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswRdr.sys – (AswRdr)
DRV - [2013/05/09 01:59:08 | 000,029,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2009/02/23 20:22:48 | 000,038,400 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2009/02/02 23:42:30 | 000,162,816 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/01/20 03:53:06 | 005,027,840 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2008/12/30 05:02:32 | 001,346,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2008/11/10 16:37:34 | 000,103,680 | —- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\qcusbserGAD.sys – (qcusbserGAD)
DRV - [2008/11/10 00:37:34 | 000,115,200 | —- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\qcusbnetGAD.sys – (qcusbnetGAD)
DRV - [2008/11/10 00:37:34 | 000,005,248 | —- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\qcfilterGAD.sys – (QCFilterGAD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…AW_enUS526US526
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Social Privacy\FF\


========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - Extension: Google Drive = C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/06/20 23:49:55 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FF42509-5EF7-4B0D-8576-1233DBB74867}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/26 15:56:05 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/21 06:34:15 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\David\Desktop\OTL (2).exe
[2013/06/20 23:49:29 | 000,000,000 | —D | C] – C:\_OTL
[2013/06/20 20:33:55 | 000,000,000 | —D | C] – C:\Documents and Settings\David\Application Data\Malwarebytes
[2013/06/20 20:31:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/06/20 20:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/06/20 20:31:25 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/06/20 20:31:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/06/20 20:09:55 | 000,368,944 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2013/06/20 20:09:55 | 000,029,816 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2013/06/20 20:09:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2013/06/20 20:09:54 | 000,765,736 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2013/06/20 20:09:54 | 000,056,080 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2013/06/20 20:09:54 | 000,049,760 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2013/06/20 20:09:52 | 000,229,648 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2013/06/20 20:09:52 | 000,066,336 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013/06/20 20:08:49 | 000,041,664 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2013/06/20 20:08:01 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/20 20:07:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2013/06/20 19:33:32 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/06/20 19:33:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2013/06/20 19:30:45 | 000,000,000 | –SD | C] – C:\uninstall
[2013/06/19 22:15:58 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2013/06/19 06:49:48 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/06/19 06:40:11 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/06/19 06:38:24 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/06/18 06:38:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\David\My Documents\My Videos
[2013/06/18 06:38:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2013/06/18 06:38:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\David\Start Menu\Programs\Administrative Tools
[2013/05/25 19:28:49 | 000,000,000 | —D | C] – C:\Config.Msi

========== Files - Modified Within 30 Days ==========

[2013/06/21 06:34:10 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\David\Desktop\OTL (2).exe
[2013/06/21 06:34:03 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/21 06:34:02 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/20 23:55:59 | 000,434,670 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/06/20 23:55:59 | 000,068,790 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/06/20 23:51:34 | 000,000,314 | -H– | M] () – C:\WINDOWS\tasks\avast! Emergency Update.job
[2013/06/20 23:51:25 | 000,000,620 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/20 23:51:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/06/20 23:51:14 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2013/06/20 23:49:55 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2013/06/20 23:29:19 | 000,021,057 | —- | M] () – C:\Documents and Settings\David\Desktop\Screen_Capture.jpg
[2013/06/20 23:28:42 | 000,018,432 | -H– | M] () – C:\Documents and Settings\David\Desktop\photothumb.db
[2013/06/20 20:31:29 | 000,000,806 | —- | M] () – C:\Documents and Settings\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/06/20 20:09:55 | 000,001,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2013/06/20 20:09:52 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2013/06/20 19:19:17 | 000,001,738 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/06/19 06:40:16 | 000,000,355 | RHS- | M] () – C:\boot.ini
[2013/06/17 06:32:36 | 000,002,884 | —- | M] () – C:\WINDOWS\wininit.ini
[2013/06/16 22:54:09 | 000,064,509 | —- | M] () – C:\Documents and Settings\David\Desktop\Shop CCS.pdf
[2013/06/15 23:53:50 | 000,000,245 | —- | M] () – C:\Boot.bak
[2013/06/15 22:59:02 | 000,447,129 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20130617-063107.backup
[2013/06/13 06:13:35 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/06/09 23:35:48 | 000,078,770 | —- | M] () – C:\Documents and Settings\David\Desktop\SINGLE PAYMENT - SCL or SPU.pdf
[2013/06/09 23:25:53 | 000,138,821 | —- | M] () – C:\Documents and Settings\David\Desktop\Comcast _ My Account _ Ecobill® Online Bill Pay _ Help & Support.pdf
[2013/06/02 17:31:31 | 000,204,285 | —- | M] () – C:\Documents and Settings\David\Desktop\Make a Payment.pdf
[2013/05/30 18:24:28 | 002,081,978 | —- | M] () – C:\Documents and Settings\David\Desktop\CYCLADES_rules_US_150dpi.zip
[2013/05/22 20:09:49 | 003,342,243 | —- | M] () – C:\Documents and Settings\David\Desktop\Basic_Actions-22may.pdf
[2013/05/22 20:09:17 | 002,982,896 | —- | M] () – C:\Documents and Settings\David\Desktop\characters-22may.pdf
[2013/05/22 19:36:03 | 000,122,511 | —- | M] () – C:\Documents and Settings\David\Desktop\Marvel_Excel.xps

========== Files Created - No Company Name ==========

[2013/06/20 23:29:19 | 000,021,057 | —- | C] () – C:\Documents and Settings\David\Desktop\Screen_Capture.jpg
[2013/06/20 20:31:29 | 000,000,806 | —- | C] () – C:\Documents and Settings\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/06/20 20:09:55 | 000,001,693 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2013/06/20 20:09:54 | 000,174,664 | —- | C] () – C:\WINDOWS\System32\drivers\aswVmm.sys
[2013/06/20 20:09:53 | 000,049,376 | —- | C] () – C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013/06/20 20:09:53 | 000,000,314 | -H– | C] () – C:\WINDOWS\tasks\avast! Emergency Update.job
[2013/06/20 19:19:17 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/06/20 19:19:17 | 000,001,738 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/06/19 06:40:16 | 000,000,245 | —- | C] () – C:\Boot.bak
[2013/06/19 06:40:14 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/06/16 22:54:05 | 000,064,509 | —- | C] () – C:\Documents and Settings\David\Desktop\Shop CCS.pdf
[2013/06/09 23:25:53 | 000,138,821 | —- | C] () – C:\Documents and Settings\David\Desktop\Comcast _ My Account _ Ecobill® Online Bill Pay _ Help & Support.pdf
[2013/05/30 18:24:27 | 002,081,978 | —- | C] () – C:\Documents and Settings\David\Desktop\CYCLADES_rules_US_150dpi.zip
[2013/05/22 20:09:49 | 003,342,243 | —- | C] () – C:\Documents and Settings\David\Desktop\Basic_Actions-22may.pdf
[2013/05/22 20:09:17 | 002,982,896 | —- | C] () – C:\Documents and Settings\David\Desktop\characters-22may.pdf
[2013/05/22 19:36:01 | 000,122,511 | —- | C] () – C:\Documents and Settings\David\Desktop\Marvel_Excel.xps
[2013/03/12 21:07:20 | 000,002,884 | —- | C] () – C:\WINDOWS\wininit.ini
[2013/03/06 19:27:29 | 000,005,120 | —- | C] () – C:\Documents and Settings\David\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/06 07:16:27 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll

========== ZeroAccess Check ==========

[2009/02/26 15:59:51 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 05:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 05:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 05:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

C:\Documents and Settings\David\My Documents\Downloads\Photoscape_Setup.exe


Delete this file. The others will be removed when we uninstall combofix later.

Then we can do the cleanup - if you are facing any issues, report that immediately.

Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
# AdwCleaner v2.303 - Logfile created 06/23/2013 at 19:28:00 # Updated 08/06/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : David - ACER-925BE1910B # Boot Mode : Normal # Running from : C:\Documents and Settings\David\Desktop\adwcleaner (1).exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Google Chrome v27.0.1453.116 File : C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [856 octets] - [23/06/2013 19:11:55] AdwCleaner[S2].txt - [777 octets] - [23/06/2013 19:28:00] ########## EOF - C:\AdwCleaner[S2].txt - [836 octets] ##########
Results of screen317's Security Check version 0.99.67
Windows XP Service Pack 3 x86
Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Free Antivirus
ESET Online Scanner v3
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.116
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 9%
````````````````````End of Log``````````````````````
I don´t know why these old replys occured again. Sorry you did the scans again.


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :regfind
    adknowledge
    :folderfind
    adknowledge
    :filefind
    adknowledge
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 30.07.11 by jpshortstuff Log created at 18:05 on 24/06/2013 by David Administrator - Elevation successful ========== regfind ========== Searching for "adknowledge" [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603] "001"="adknowledge" [HKEY_USERS\S-1-5-21-3895304184-1815002781-3652652152-1005\Software\Microsoft\Search Assistant\ACMru\5603] "001"="adknowledge" ========== folderfind ========== Searching for "adknowledge" No folders found. ========== filefind ========== Searching for "adknowledge" No files found. -= EOF =-
Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :REG
    [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
    "001"=-
    [HKEY_USERS\S-1-5-21-3895304184-1815002781-3652652152-1005\Software\Microsoft\Search Assistant\ACMru\5603]
    "001"=-

  • Return to OTL, right click in the "Custom Scans/Fixes" section and choose Paste.
  • Click the red Run Fix button.
  • OTL may ask to reboot the machine. Please do so.
  • If OTL did not reboot the machine, click OK and the log will open. Post the contents of the log in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

Tell me if that worked for you.
========== REGISTRY ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\\001 deleted successfully. Registry value HKEY_USERS\S-1-5-21-3895304184-1815002781-3652652152-1005\Software\Microsoft\Search Assistant\ACMru\5603\\001 not found. OTL by OldTimer - Version 3.2.69.0 log created on 06252013_183321
Do they apper in any browser or just in some?
The screenshots you´ve posted look like normal browser ads - on your computer is no malware to find.


Let´s do another rootkit check.


Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
The ads appear in Google Chrome and IE. They are definately not normal. I don't see these ads when I use other computers to this site. I've never had banner ads with sound before either. They all appear to originate from Adknowledge. When you click the i with a circle around it it takes you to the Adknowledge website, but there is no way to opt out. Some of the ads are offensive like for young Asian women or Russian Brides others are annoying with flash video and sound with bogus alerts that my computer needs updating. I've tried clearing my cache and cookies and history and they still are there.
No malware found. ********************* Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.06.28.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 David :: ACER-925BE1910B [administrator] 6/28/2013 5:59:43 PM mbar-log-2013-06-28 (17-59-43).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 197596 Time elapsed: 11 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI