SUPERAntiSpyware Free Edition did not find any infections
GWER always makes me log out, I don't know if its bugged or something.
Malwarebytes' Anti-Malware log
Malwarebytes' Anti-Malware 1.36
Database version: 2127
Windows 5.1.2600 Service Pack 3
5/13/2009 7:46:48 PM
mbam-log-2009-05-13 (19-46-37).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 226340
Time elapsed: 2 hour(s), 37 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\Dad\Application Data\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log (Rogue.ErrorSmart) -> No action taken.
Files Infected:
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Log\2008 Aug 30 - 08_51_46 PM_375.log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-24_02-51-48.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-24_03-15-28.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-27_18-51-18.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-27_18-51-50.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log\2008 Aug 29 - 06_35_42 PM_750.log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log\2008 Aug 29 - 08_50_09 PM_593.log (Rogue.ErrorSmart) -> No action taken.
I have error smart pro for awhile now, I really don't think its infecting my PC.
HiJack This log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:41 PM, on 5/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dad\Desktop\Programs\PC Tools\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
--
End of file - 3268 bytes
This is a report from my AVG 08' residental shield findings as of May 13th
Resident Shield detection
"Infection";"Object";"Result";"Detection time";"Object Type";"Process"
"Virus identified Win32/Hidrag.A";"C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP33\A0007406.exe";"Moved to Virus Vault";"5/13/2009, 2:57:02 PM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Win32/Hidrag.A";"C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP33\A0007406.exe";"Infected";"5/12/2009, 10:15:36 PM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Win32/Hidrag.A";"C:\Documents and Settings\Dad\My Documents\Downloads\Counter-Strike Source FULL [October 15 2007] DiGiTALZonE\CSS_FULL_Oct-15-07_DiGiTALZonE_2FINISH.exe";"Deleted";"5/12/2009, 6:02:49 PM";"file";"C:\Documents and Settings\Dad\Desktop\Programs\Apps\uTorrent.exe"