I’ve tried removing it using MBAM but my Avast! still detected it after rebooting. I’ve the OTL logs and gonna paste it here, I really hope you guys can help me thanks. And I’m sure there are more malware/trojan infecting my computer. But I don’t know how to look for it. Thanks alot.
========== Processes (SafeList) ==========
PRC - [2010/07/26 09:06:12 | 000,574,976 | ---- | M] (OldTimer Tools) – C:\Users\John\Desktop\OTL.exe
PRC - [2010/07/26 03:17:49 | 000,208,896 | ---- | M] () – C:\Users\John\AppData\Roaming\MrPoserRAT.exe
PRC - [2010/07/25 13:10:04 | 000,014,808 | ---- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/07/25 13:10:03 | 000,910,296 | ---- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/07/25 12:21:47 | 000,167,424 | ---- | M] (Microsoft Inc.) – C:\Users\John\My Documents\System32\svhost.exe
PRC - [2010/07/24 12:14:35 | 000,512,000 | ---- | M] (x31S29H9V48u95ka) – C:\Users\John\AppData\Roaming\bot.exe
PRC - [2010/07/24 09:29:49 | 000,072,704 | RHS- | M] (Microsoft Corporation) – C:\Users\John\AppData\Roaming\galaxy.exe
PRC - [2010/06/30 14:52:22 | 000,836,464 | ---- | M] (Opera Software) – C:\Program Files\Opera\opera.exe
PRC - [2010/06/29 04:57:18 | 002,837,864 | ---- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/06/29 04:57:15 | 000,040,384 | ---- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/06/10 21:39:52 | 000,185,800 | ---- | M] (PPLive Corporation) – C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/02 03:49:16 | 000,322,352 | ---- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/05/26 21:03:07 | 003,220,912 | ---- | M] (Tonec Inc.) – C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2010/05/25 21:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) – C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2010/04/29 02:15:02 | 002,633,976 | ---- | M] (Veoh Networks) – C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
PRC - [2009/12/10 10:27:26 | 000,357,384 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
PRC - [2009/12/10 10:25:16 | 003,203,080 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
PRC - [2009/12/10 10:01:22 | 000,498,696 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
PRC - [2009/12/10 10:01:12 | 000,477,704 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
PRC - [2009/12/10 10:00:42 | 001,573,384 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
PRC - [2009/12/10 10:00:32 | 000,522,760 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
PRC - [2009/12/10 10:00:22 | 000,523,784 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
PRC - [2009/12/10 10:00:12 | 000,676,360 | ---- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
PRC - [2009/11/20 19:17:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/10/31 13:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/10/22 05:00:04 | 000,395,824 | ---- | M] (VMware, Inc.) – C:\Windows\System32\vmnat.exe
PRC - [2009/10/22 04:59:58 | 000,113,200 | ---- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009/10/22 04:59:48 | 000,334,384 | ---- | M] (VMware, Inc.) – C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/10/22 04:59:24 | 000,129,584 | ---- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
PRC - [2009/10/22 03:47:54 | 000,563,760 | ---- | M] (VMware, Inc.) – C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009/09/30 19:58:42 | 000,026,464 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2009/07/14 09:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2008/05/22 18:57:49 | 000,483,328 | ---- | M] (Motive Communications, Inc.) – C:\Program Files\Common Files\Motive\MotiveBrowser.exe
========== Modules (SafeList) ==========
MOD - [2010/07/26 09:06:12 | 000,574,976 | ---- | M] (OldTimer Tools) – C:\Users\John\Desktop\OTL.exe
MOD - [2009/07/14 09:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\sspicli.dll
MOD - [2009/07/14 09:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\sechost.dll
MOD - [2009/07/14 09:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\samcli.dll
MOD - [2009/07/14 09:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\profapi.dll
MOD - [2009/07/14 09:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\netutils.dll
MOD - [2009/07/14 09:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\KernelBase.dll
MOD - [2009/07/14 09:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\dwmapi.dll
MOD - [2009/07/14 09:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\devobj.dll
MOD - [2009/07/14 09:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\cryptbase.dll
MOD - [2009/07/14 09:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/14 09:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
MOD - [2009/07/14 09:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll