Possible SMART HDD aftermath cleanup

Hi all

Got myself a virus the other day from an unknown source (honest! dunno where from) and have been wrestling with it the last few days. I kind of figured it was like the SMART HDD virus, in that it hid all my desktop items, start menu, and changed folder permissions.

However, hacking away at it with HijackThis led me to kill off most of it, I think. I’ve regained all my desktop and permissions, but I still have some strange new entries in HijackThis which I can’t get rid of. So, just wondering if there’s anyone reading that’s seen this before and can give some advice on it or point out some tools to root out what’s left of it (if there’s a rootkit, pun not intended).

Here’s HijackThis log (apologies if this isnt the way you’re meant to post them, I couldn’t find any rules in the stickies about how to do so)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:49:53 PM, on 2/04/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\notepad.exe
C:\Windows\SysWOW64\regedit.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM..\Run: [VirtualCloneDrive] “C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe” /s
O4 - HKLM..\Run: [avast] “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui
O4 - HKLM..\Run: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
O4 - HKLM..\Run: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM..\Run: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
O4 - HKLM..\Run: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
O4 - HKUS\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - Startup: RocketDock.lnk = C:\Program Files (x86)\RocketDock\RocketDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


End of file - 6882 bytes

Cheers all

A qualified malware remover should be online soon.

At the moment jeffce and essexboy is offline :slight_smile:

Anthony :slight_smile:

Hi,

Please visit the page here >> http://forum.avast.com/index.php?topic=53253.0

Run OTL, aswMBR and Malwarebytes using the instructions on that page and then attach the logs into your next reply.

OTL logfile created on: 3/04/2012 7:16:41 AM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\HijackThis
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

8.00 Gb Total Physical Memory | 6.61 Gb Available Physical Memory | 82.67% Memory free
16.00 Gb Paging File | 14.44 Gb Available in Paging File | 90.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 652.11 Gb Free Space | 70.01% Space Free | Partition Type: NTFS

Computer Name: TINNERSPC | User Name: Andrew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/22 21:20:58 | 000,593,920 | ---- | M] (OldTimer Tools) – C:\HijackThis\OTL.exe
PRC - [2012/03/22 16:28:43 | 000,924,600 | ---- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/09/07 06:45:30 | 003,722,416 | ---- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/07/29 10:50:28 | 000,049,664 | ---- | M] (Advanced Micro Devices, Inc.) – C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
PRC - [2011/06/07 05:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010/06/07 20:35:35 | 000,618,496 | ---- | M] () – C:\Windows\Samsung\PanelMgr\SSMMgr.exe
PRC - [2008/06/30 08:01:01 | 000,052,168 | ---- | M] (Elaborate Bytes AG) – C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe
PRC - [2007/09/03 06:58:52 | 000,495,616 | ---- | M] () – C:\Program Files (x86)\RocketDock\RocketDock.exe

========== Modules (No Company Name) ==========

MOD - [2012/03/22 16:28:43 | 001,969,080 | ---- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/02/20 20:29:04 | 000,087,912 | ---- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 20:28:42 | 001,242,472 | ---- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/06/07 20:35:35 | 000,618,496 | ---- | M] () – C:\Windows\Samsung\PanelMgr\SSMMgr.exe
MOD - [2007/09/03 06:58:52 | 000,495,616 | ---- | M] () – C:\Program Files (x86)\RocketDock\RocketDock.exe
MOD - [2007/09/03 06:57:36 | 000,069,632 | ---- | M] () – C:\Program Files (x86)\RocketDock\RocketDock.dll

========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/09/07 06:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Stopped] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2011/07/29 07:35:34 | 000,204,288 | ---- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/07/14 11:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/14 11:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012/03/22 16:29:23 | 000,489,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/06/07 05:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2010/03/19 06:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 07:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)

========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/15 10:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/09/07 06:38:18 | 000,601,944 | ---- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2011/09/07 06:38:16 | 000,301,912 | ---- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2011/09/07 06:36:41 | 000,058,200 | ---- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2011/09/07 06:36:41 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr.sys – (aswRdr)
DRV:64bit: - [2011/09/07 06:36:30 | 000,065,368 | ---- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2011/09/07 06:36:14 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2011/07/29 08:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2011/07/29 08:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2011/07/29 06:54:10 | 000,309,248 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2011/07/06 20:12:50 | 000,367,976 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)

DRV:64bit: - [2010/11/20 23:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 23:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 23:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2010/11/20 21:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 21:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 20:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010/07/12 23:49:14 | 000,072,648 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ftdibus.sys – (FTDIBUS)
DRV:64bit: - [2010/07/12 23:48:50 | 000,085,320 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ftser2k.sys – (FTSER2K)
DRV:64bit: - [2010/01/27 19:25:42 | 001,584,640 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/07/14 11:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 11:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 11:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2009/07/14 11:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/11 06:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/06/11 06:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/11 06:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/11 06:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/11 06:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/19 06:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/05/09 18:14:20 | 000,015,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nuidfltr.sys – (NuidFltr)
DRV:64bit: - [2008/09/24 20:29:20 | 000,035,840 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VClone.sys – (VClone)
DRV:64bit: - [2008/07/21 22:11:56 | 000,032,200 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ElbyCDIO.sys – (ElbyCDIO)
DRV - [2011/01/27 21:06:50 | 000,015,664 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2009/07/29 10:55:42 | 000,011,576 | ---- | M] (Samsung Electronics) [Kernel | Auto | Stopped] – C:\Windows\SysWOW64\drivers\SSPORT.SYS – (SSPORT)
DRV - [2009/07/14 11:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU..\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = *.local

========== FireFox ==========

FF - prefs.js…browser.search.useDBForOrder: true
FF - prefs.js…browser.startup.homepage: “https://ssologin.unsw.edu.au/cas/login?service=https://lms-blackboard.telt.unsw.edu.au/webapps/login
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/04/02 21:16:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/22 16:28:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/09/12 05:51:43 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Andrew\AppData\Roaming\Mozilla\Extensions
[2011/09/12 05:51:43 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Andrew\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2012/04/02 21:13:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\r71l6xt3.default\extensions
[2012/04/02 21:16:51 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\r71l6xt3.default\extensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/09/12 06:20:42 | 000,004,855 | -H-- | M] () – C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\r71l6xt3.default\searchplugins\google-images.xml
[2011/09/12 06:19:33 | 000,005,551 | -H-- | M] () – C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\r71l6xt3.default\searchplugins\google-maps.xml
[2011/09/14 12:27:30 | 000,002,323 | -H-- | M] () – C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\r71l6xt3.default\searchplugins\youtube-ssl.xml
[2012/03/22 16:28:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) – C:\USERS\ANDREW\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71L6XT3.DEFAULT\EXTENSIONS{3D7EB24F-2740-49DF-8937-200B1CC08F8A}.XPI
() (No name found) – C:\USERS\ANDREW\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71L6XT3.DEFAULT\EXTENSIONS{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\ANDREW\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71L6XT3.DEFAULT\EXTENSIONS{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\ANDREW\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71L6XT3.DEFAULT\EXTENSIONS\AUTOPAGER@MOZILLA.ORG.XPI
[2012/03/22 16:28:43 | 000,097,208 | ---- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/22 16:28:41 | 000,002,252 | ---- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/22 16:28:41 | 000,002,040 | ---- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM…\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM…\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM…\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM…\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM…\Run: [VirtualCloneDrive] C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - Startup: C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RocketDock.lnk = C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces{336BEEE2-D972-4DA0-92FA-54C20FFB1906}: DhcpNameServer = 116.250.255.18 116.250.255.19 203.8.183.1 192.189.54.17
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces{CE362FE2-7DAA-4C0F-9B5F-4D18B21062E1}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2{8f03945f-d931-11e0-adf8-806e6f6e6963}\Shell - “” = AutoRun
O33 - MountPoints2{8f03945f-d931-11e0-adf8-806e6f6e6963}\Shell\AutoRun\command - “” = D:\setup.exe
O33 - MountPoints2{ac3a1f14-d9cd-11e0-afb9-00241d2bd190}\Shell - “” = AutoRun
O33 - MountPoints2{ac3a1f14-d9cd-11e0-afb9-00241d2bd190}\Shell\AutoRun\command - “” = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk )
O35:64bit: - HKLM..comfile [open] – “%1” %

O35:64bit: - HKLM..exefile [open] – “%1” %*
O35 - HKLM..comfile [open] – “%1” %*
O35 - HKLM..exefile [open] – “%1” %*
O37:64bit: - HKLM.…com [@ = comfile] – “%1” %*
O37:64bit: - HKLM.…exe [@ = exefile] – “%1” %*
O37 - HKLM.…com [@ = comfile] – “%1” %*
O37 - HKLM.…exe [@ = exefile] – “%1” %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/03 07:14:50 | 004,731,392 | ---- | C] (AVAST Software) – C:\Users\Andrew\Desktop\aswMBR.exe
[2012/04/03 07:14:35 | 000,593,920 | ---- | C] (OldTimer Tools) – C:\Users\Andrew\Desktop\OTL.exe
[2012/04/02 20:49:21 | 000,000,000 | —D | C] – C:\HijackThis
[2012/04/02 20:23:06 | 000,388,608 | ---- | C] (Trend Micro Inc.) – C:\Users\Andrew\Desktop\HijackThis.exe
[2012/04/02 20:00:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sophos Anti-Rootkit
[2012/04/01 23:33:18 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2012/04/01 22:59:55 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\backups
[2012/03/29 18:26:36 | 000,000,000 | -H-D | C] – C:\Users\Andrew\Documents\NewStartMusicMW4_data
[2012/03/28 14:35:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mechwarrior
[2012/03/28 14:33:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\MTX
[2012/03/27 20:35:55 | 000,000,000 | —D | C] – C:\Program Files\Blue Coat K9 Web Protection
[2012/03/25 12:39:16 | 000,000,000 | -H-D | C] – C:\Users\Andrew\Documents\Square Enix
[2012/03/25 11:57:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\MechCommander2
[2012/03/23 06:09:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/03/23 06:09:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2012/03/21 19:49:42 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\AP
[2012/03/20 10:12:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Egosoft
[2012/03/20 10:03:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\X Plugin Manager
[2012/03/19 21:50:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Egosoft
[2012/03/18 08:24:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/03/18 08:24:10 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/03/18 08:24:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/03/18 08:24:10 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/03/18 08:22:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/03/18 08:22:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2012/03/18 08:21:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/03/18 08:21:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/03/17 14:46:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Valve
[2012/03/17 14:31:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Portal 2
[2012/03/16 00:32:55 | 001,942,552 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2012/03/16 00:32:55 | 001,493,528 | ---- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2012/03/16 00:32:55 | 000,540,688 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2012/03/16 00:32:55 | 000,467,984 | ---- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2012/03/16 00:32:54 | 004,992,520 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll

[2012/03/16 00:32:54 | 003,851,784 | ---- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2012/03/15 22:54:03 | 001,544,192 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/03/15 21:32:39 | 001,112,064 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/03/15 21:32:39 | 001,031,680 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2012/03/15 21:32:39 | 000,826,880 | ---- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2012/03/15 21:32:33 | 000,149,504 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/03/15 21:32:33 | 000,009,216 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/03/15 21:32:32 | 000,077,312 | ---- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/03/15 19:12:39 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012/03/12 20:45:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nehrim - At Fate’s Edge
[2012/03/12 20:41:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nehrim
[2012/03/12 20:32:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nehrim - At Fate’s Edge
[2012/03/12 20:31:25 | 000,000,000 | -H-D | C] – C:\Users\Andrew\AppData\Local\Oblivion
[2012/03/12 20:20:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\RADVideo
[2012/03/12 12:22:43 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\Semester 1 2012
[2012/03/07 15:54:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\X-Ray CoP SDK
[2012/03/07 15:52:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\X-Ray CoP SDK
[2012/03/06 21:42:21 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat
[2012/03/06 21:36:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\S.T.A.L.K.E.R. - Call of Pripyat
[2012/03/06 09:24:40 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\microsoft
[2012/03/06 09:24:35 | 000,000,000 | —D | C] – C:\Users\Andrew\Documents\CAPCOM
[2012/03/06 09:18:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Resident Evil 5
[2012/03/06 09:18:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2012/03/06 09:17:32 | 000,000,000 | —D | C] – C:\Windows\SysWow64\xlive
[2012/03/06 09:17:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2012/03/04 16:40:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Earth 2150 Lost Souls
[2012/03/04 07:44:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Myth II - Soulblighter

========== Files - Modified Within 30 Days ==========

[2012/04/03 07:12:24 | 000,017,168 | -H-- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/03 07:12:24 | 000,017,168 | -H-- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/03 07:09:27 | 000,793,514 | ---- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/03 07:09:27 | 000,673,822 | ---- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/03 07:09:27 | 000,129,712 | ---- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/03 07:04:50 | 000,067,584 | --S- | M] () – C:\Windows\bootstat.dat
[2012/04/03 07:04:43 | 2146,295,807 | -HS- | M] () – C:\hiberfil.sys
[2012/04/02 19:59:28 | 000,000,036 | ---- | M] () – C:\Users\Andrew\AppData\Local\housecall.guid.cache
[2012/03/29 18:27:09 | 060,244,420 | -H-- | M] () – C:\Users\Andrew\Documents\NewStartMusicMW4.wav
[2012/03/29 18:26:37 | 000,023,007 | -H-- | M] () – C:\Users\Andrew\Documents\NewStartMusicMW4.aup
[2012/03/28 14:05:25 | 000,007,605 | -H-- | M] () – C:\Users\Andrew\AppData\Local\Resmon.ResmonCfg
[2012/03/23 06:06:00 | 022,259,528 | ---- | M] () – C:\Users\Andrew\Desktop\vlc-2.0.1-win32.exe
[2012/03/22 21:20:58 | 000,593,920 | ---- | M] (OldTimer Tools) – C:\Users\Andrew\Desktop\OTL.exe
[2012/03/20 10:12:53 | 000,001,310 | ---- | M] () – C:\Users\Andrew\Desktop\Package Explorer.lnk
[2012/03/20 10:12:53 | 000,001,288 | ---- | M] () – C:\Users\Andrew\Desktop\Package Creator.lnk
[2012/03/20 10:12:52 | 000,001,241 | ---- | M] () – C:\Users\Andrew\Desktop\X-Universe Plugin Manager Advanced.lnk
[2012/03/20 10:12:52 | 000,001,219 | ---- | M] () – C:\Users\Andrew\Desktop\X-Universe Plugin Manager Lite.lnk
[2012/03/18 08:24:23 | 000,001,783 | ---- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/03/17 14:46:18 | 000,001,880 | ---- | M] () – C:\Users\Public\Desktop\Portal 2.lnk
[2012/03/16 12:42:43 | 000,416,024 | ---- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/03/14 05:14:15 | 004,731,392 | ---- | M] (AVAST Software) – C:\Users\Andrew\Desktop\aswMBR.exe
[2012/03/12 20:45:52 | 000,001,907 | ---- | M] () – C:\Users\Andrew\Desktop\Nehrim - At Fate’s Edge.lnk
[2012/03/07 14:57:55 | 000,006,617 | -H-- | M] () – C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx

========== Files Created - No Company Name ==========

[2012/04/02 19:59:28 | 000,000,036 | ---- | C] () – C:\Users\Andrew\AppData\Local\housecall.guid.cache
[2012/03/29 18:27:07 | 060,244,420 | -H-- | C] () – C:\Users\Andrew\Documents\NewStartMusicMW4.wav
[2012/03/29 18:26:37 | 000,023,007 | -H-- | C] () – C:\Users\Andrew\Documents\NewStartMusicMW4.aup
[2012/03/29 15:49:46 | 000,000,433 | ---- | C] () – C:\Users\Andrew\Desktop\edgecolor.m
[2012/03/26 16:04:15 | 000,007,605 | -H-- | C] () – C:\Users\Andrew\AppData\Local\Resmon.ResmonCfg
[2012/03/25 11:05:28 | 625,905,558 | ---- | C] () – C:\Users\Andrew\Desktop\MechCommander2.zip
[2012/03/23 06:05:29 | 022,259,528 | ---- | C] () – C:\Users\Andrew\Desktop\vlc-2.0.1-win32.exe
[2012/03/20 10:12:53 | 000,001,310 | ---- | C] () – C:\Users\Andrew\Desktop\Package Explorer.lnk
[2012/03/20 10:12:53 | 000,001,288 | ---- | C] () – C:\Users\Andrew\Desktop\Package Creator.lnk
[2012/03/20 10:12:52 | 000,001,241 | ---- | C] () – C:\Users\Andrew\Desktop\X-Universe Plugin Manager Advanced.lnk
[2012/03/20 10:12:52 | 000,001,219 | ---- | C] () – C:\Users\Andrew\Desktop\X-Universe Plugin Manager Lite.lnk
[2012/03/20 10:12:51 | 001,236,992 | ---- | C] () – C:\Windows\SysWow64\spk.dll
[2012/03/20 10:12:51 | 000,175,616 | ---- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/03/18 08:24:23 | 000,001,783 | ---- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/03/17 14:46:18 | 000,001,880 | ---- | C] () – C:\Users\Public\Desktop\Portal 2.lnk
[2012/03/12 20:45:52 | 000,001,907 | ---- | C] () – C:\Users\Andrew\Desktop\Nehrim - At Fate’s Edge.lnk
[2012/03/06 22:35:33 | 000,006,617 | -H-- | C] () – C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
[2011/09/15 11:36:54 | 000,409,600 | ---- | C] () – C:\Windows\SysWow64\gltext.dll
[2011/09/15 11:36:54 | 000,245,760 | ---- | C] () – C:\Windows\SysWow64\glew32.dll
[2011/09/15 11:36:54 | 000,221,184 | ---- | C] () – C:\Windows\SysWow64\glut32.dll
[2011/09/14 02:18:48 | 000,778,982 | ---- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/13 04:48:32 | 000,482,408 | ---- | C] () – C:\Windows\ssndii.exe
[2011/09/07 19:15:04 | 000,000,000 | ---- | C] () – C:\Windows\ativpsrm.bin
[2011/03/18 03:51:44 | 000,003,929 | ---- | C] () – C:\Windows\SysWow64\atipblag.dat

< End of report >

attach the log.…not copy and paste, or it will take 10 posts

Whoops, noted.

aswMBR did not work properly;
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-03 07:43:05

07:43:05.617 OS Version: Windows x64 6.1.7601 Service Pack 1
07:43:05.617 Number of processors: 2 586 0x170A
07:43:05.618 ComputerName: TINNERSPC UserName: Andrew
07:43:07.201 Initialize success
07:44:44.716 AVAST engine error: 2
07:45:47.872 The log file has been saved successfully to “C:\HijackThis\aswMBR.txt”

I’ve also just noticed that AVAST Free installed on my comp has also not initialised properly. Will try a reinstall this evening. I did a System Restore before, would that interrupt normal Avast working in any way?

Hi,

Go ahead and run aswMBR in Safe Mode and then attach the log that is created. :slight_smile:

I did a System Restore before, would that interrupt normal Avast working in any way?
yes...avast does not like system restore. it is usually solved with the uninstall tool and a reinstall