Sorry for the delay.
the avast detections where infected system restore oint. The restore point shouldn't be a problem unless you use them. We'll clean then put in a bit.
Open Spybot and make sure teatimer is disabled, we will re-enable afterwards. To do so do the following
Click mode
click Advanced mode
if you get a warning answer "yes"
click tools
click resident
uncheck resident "teatimer" and SDHelper if installed
click allow change
reboot
Download and Unzip to your Desktop:
http://www.techsupportforum.com/sectools/ResetTeaTimer.zip Double click ResetTeaTimer.bat to remove all entries set by TeaTimer.
reboot
Please submit these files for analysis
To submit a file to virustotal, please click on this link
www.virustotal.comcopy and paste the following into the upload a file box (one at a time if more than one file is listed)
C:\WINDOWS\b116old.exe
C:\WINDOWS\b122old.exe
C:\os350142.bin scroll down a bit and click "send file", wait for the results and post then in your next reply.
Open HJT, run a system scan only, check mark these lines if present
O2 - BHO: (no name) - {31FB794C-2E47-4CB1-BA77-5346D843F0B7} - C:\Program Files\Windows Media Player\hokevC:\WINDOWS\System32\ecw8\renamd83122.exe.dll (file missing)
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} - ms-its:mhtml:file://c:\\nores.mht!http://adxrnet.net/code/chm/xpre.chm::/xpreload.ocx
Close all other browsers/windows, click fix, close HJT.
Open a new Notepad session (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Copy and paste all the text in the quote box below into Notepad.
Click File, Save as..., and set the location to your Desktop, and enter (including quotation marks) as the filename: "CFscript.txt" . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.
File::
C:\Temp\gwLsx9101.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
Folder::
C:\WINDOWS\system32\ecw8
C:\Program Files\Dot1XCfg
C:\WINDOWS\system32\pie2
C:\WINDOWS\system32\nGpxx01
C:\Temp\gTiis19
C:\Temp\cXzz9
This will start ComboFix again.
Close all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log.