This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Broswer redirects randomly

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI,

When I google something, a lot of the time when I click on a link, it will redirect me elsewhere. Same thing with other search engines. Occasionally random tabs will open to these random websites, which vary each time. Help will be greatly appreciated!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:26:37 PM, on 6/3/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Datalode\Torchlight\encore_reg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Rashad\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GR469A~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [20090604] C:\Program Files\Common Files\Datalode\Torchlight\encore_reg.exe /r "C:\Program Files\Common Files\Datalode\Torchlight\encore_reg.rpd"
O4 - HKCU\..\Run: [QZAIB7KITK] C:\Windows\Uguwua.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{35D0D68B-7A89-4F0D-921A-6D26C1558453}: NameServer = 93.188.163.12,93.188.161.172
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.12,93.188.161.172
O17 - HKLM\System\CS1\Services\Tcpip\..\{35D0D68B-7A89-4F0D-921A-6D26C1558453}: NameServer = 93.188.163.12,93.188.161.172
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.163.12,93.188.161.172
O17 - HKLM\System\CS2\Services\Tcpip\..\{35D0D68B-7A89-4F0D-921A-6D26C1558453}: NameServer = 93.188.163.12,93.188.161.172
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.12,93.188.161.172
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 6159 bytes
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.


NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Thanks for your help!

OTL.txt


OTL logfile created on: 6/3/2010 10:16:08 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Rashad\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 507.82 Gb Free Space | 85.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RASHAD-PC
Current User Name: Rashad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Rashad\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
PRC - C:\Program Files\Common Files\Datalode\Torchlight\encore_reg.exe (DataLode, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Rashad\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\Windows\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ElbyCDIO) – C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (VClone) – C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 32 F8 22 50 46 00 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en&source=iglk"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/05/30 11:10:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/30 18:21:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/31 19:04:35 | 000,000,000 | —D | M]

[2010/05/26 18:54:04 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2010/05/26 18:54:04 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/05/22 08:01:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\dxrgz2xe.default\extensions
[2010/06/03 19:02:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/31 19:04:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/31 19:04:21 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [20090604] C:\Program Files\Common Files\Datalode\Torchlight\encore_reg.exe (DataLode, Inc.)
O4 - HKCU..\Run: [QZAIB7KITK] C:\Windows\Uguwua.exe File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.12,93.188.161.172
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\Users\Rashad\AppData\Roaming\emorunzxbl.exe) - C:\Users\Rashad\AppData\Roaming\emorunzxbl.exe File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/13 22:37:08 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/03 22:15:01 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Rashad\Desktop\OTL.exe
[2010/05/31 19:04:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/31 19:04:35 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/05/31 19:04:35 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/05/31 19:04:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/05/31 19:04:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/05/31 19:01:21 | 000,000,000 | —D | C] – C:\Windows\System32\appmgmt
[2010/05/30 11:13:38 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/05/30 11:11:02 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/05/30 11:11:00 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/30 11:10:59 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2010/05/30 11:10:42 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/05/30 11:10:42 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/05/30 11:08:45 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\WinRAR
[2010/05/29 20:00:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\runic games
[2010/05/29 19:59:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Datalode
[2010/05/29 19:59:02 | 000,000,000 | —D | C] – C:\Program Files\Runic Games
[2010/05/29 19:53:57 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\ElevatedDiagnostics
[2010/05/29 18:51:34 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2010/05/26 22:17:22 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/05/26 18:54:09 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\LimeWire
[2010/05/26 18:53:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\LimeWire
[2010/05/26 18:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/05/26 18:52:51 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/26 18:52:28 | 000,000,000 | —D | C] – C:\Program Files\LimeWire
[2010/05/26 18:51:29 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/05/21 21:01:47 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2010/05/21 20:59:58 | 000,000,000 | —D | C] – C:\HP LJ1320 PCL5 Driver
[2010/05/21 20:53:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/05/21 20:53:01 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/05/21 20:52:58 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010/05/21 20:52:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/05/21 20:52:35 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Adobe
[2010/05/21 20:52:30 | 000,000,000 | —D | C] – C:\ProgramData\NOS
[2010/05/16 16:11:09 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\vlc
[2010/05/16 10:18:10 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Macromedia
[2010/05/16 10:18:10 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Adobe
[2010/05/16 10:18:08 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/05/15 23:51:01 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/05/15 23:14:50 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/15 23:00:29 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/05/15 22:52:23 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/05/15 22:51:53 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II Beta
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II Beta
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Blizzard Entertainment
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2010/05/15 22:02:20 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard
[2010/05/15 21:29:05 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2010/05/15 21:28:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2010/05/15 21:28:09 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/05/15 21:28:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/05/15 21:28:00 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/05/15 21:28:00 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/05/15 21:26:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/05/15 21:25:41 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Microsoft Help
[2010/05/15 21:25:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/05/15 21:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2010/05/15 21:25:16 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/05/15 21:17:22 | 000,000,000 | —D | C] – C:\Users\Rashad\StarCraft II Beta enUS 13891 Installer
[2010/05/15 21:15:46 | 000,000,000 | —D | C] – C:\Program Files\Stunlock Studios
[2010/05/15 21:15:45 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/05/15 21:14:58 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2010/05/15 21:14:58 | 000,069,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/05/15 21:14:57 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2010/05/15 21:14:57 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2010/05/15 21:14:57 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2010/05/15 21:14:57 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2010/05/15 21:14:57 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2010/05/15 21:14:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft XNA
[2010/05/15 21:07:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Steam
[2010/05/15 21:07:49 | 000,000,000 | —D | C] – C:\Program Files\Steam
[2010/05/15 21:07:38 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/15 21:07:21 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2010/05/15 20:58:38 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Apple Computer
[2010/05/15 20:58:38 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Apple Computer
[2010/05/15 20:58:35 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/05/15 20:58:34 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2010/05/15 20:58:27 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/05/15 20:58:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/05/15 20:58:26 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/15 20:58:00 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/05/15 20:58:00 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/05/15 20:57:56 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Apple
[2010/05/15 20:57:55 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/05/15 20:57:47 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/05/15 20:57:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/05/15 20:57:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/05/15 20:56:22 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/05/15 20:36:39 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\School
[2010/05/15 20:33:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Mozilla
[2010/05/15 20:33:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Mozilla
[2010/05/15 20:32:46 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/05/15 20:24:12 | 000,000,000 | R–D | C] – C:\Users\Rashad\Searches
[2010/05/15 20:24:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Identities
[2010/05/15 20:24:03 | 000,000,000 | R–D | C] – C:\Users\Rashad\Contacts
[2010/05/15 20:24:00 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\VirtualStore
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\Temporary Internet Files
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Templates
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Start Menu
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\SendTo
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Recent
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\PrintHood
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\NetHood
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Videos
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Pictures
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Music
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\My Documents
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Local Settings
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\History
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Cookies
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Application Data
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\Application Data
[2010/05/15 20:23:58 | 000,000,000 | –SD | C] – C:\Users\Rashad\AppData\Roaming\Microsoft
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Videos
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Saved Games
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Pictures
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Music
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Links
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Favorites
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Downloads
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\My Documents
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Desktop
[2010/05/15 20:23:58 | 000,000,000 | -H-D | C] – C:\Users\Rashad\AppData
[2010/05/15 20:23:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Temp
[2010/05/15 20:23:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Microsoft
[2010/05/15 20:23:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Media Center Programs
[2010/05/15 20:23:47 | 000,000,000 | -HSD | C] – C:\Recovery

========== Files - Modified Within 30 Days ==========

[2010/06/03 22:17:10 | 002,359,296 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT
[2010/06/03 22:17:01 | 000,000,248 | -H– | M] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/03 22:14:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Rashad\Desktop\OTL.exe
[2010/06/03 22:05:01 | 000,000,290 | -H– | M] () – C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/03 17:17:13 | 060,681,562 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/06/03 17:11:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/03 06:11:22 | 000,014,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/03 06:11:22 | 000,014,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/03 06:10:33 | 000,717,892 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/03 06:10:33 | 000,618,026 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/03 06:10:33 | 000,104,340 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/03 06:06:22 | 000,000,246 | -H– | M] () – C:\Windows\tasks\MSWD-111d5cc5.job
[2010/06/03 06:06:14 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/03 06:05:58 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2010/06/02 22:20:42 | 001,991,017 | -H– | M] () – C:\Users\Rashad\AppData\Local\IconCache.db
[2010/05/31 19:04:21 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/05/31 19:04:21 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/05/31 19:04:21 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/05/31 19:04:21 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/05/30 18:21:47 | 000,001,885 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/30 11:11:03 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/30 11:11:03 | 000,001,812 | —- | M] () – C:\Users\Public\Desktop\AVG 9.0.lnk
[2010/05/30 11:11:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/05/30 11:11:01 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/29 19:59:33 | 000,002,039 | —- | M] () – C:\Users\Rashad\Desktop\Torchlight.lnk
[2010/05/29 18:51:58 | 000,001,208 | —- | M] () – C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010/05/26 18:54:10 | 000,001,819 | —- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
[2010/05/26 18:53:06 | 000,001,861 | —- | M] () – C:\Users\Rashad\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 15:22:29 | 000,002,645 | —- | M] () – C:\Users\Rashad\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/05/17 06:36:15 | 000,412,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/05/16 11:33:05 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/05/15 22:55:01 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2010/05/15 22:53:23 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2010/05/15 22:53:23 | 000,000,000 | —- | M] () – C:\Windows\System32\atiicdxx.dat
[2010/05/15 22:30:11 | 000,001,096 | —- | M] () – C:\Users\Public\Desktop\StarCraft II Beta.lnk
[2010/05/15 22:00:07 | 000,108,824 | —- | M] () – C:\Users\Rashad\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/15 21:26:04 | 000,000,478 | —- | M] () – C:\Windows\win.ini
[2010/05/15 21:16:54 | 000,001,351 | —- | M] () – C:\Users\Rashad\Desktop\Sticky Notes.lnk
[2010/05/15 21:16:12 | 000,002,353 | —- | M] () – C:\Users\Public\Desktop\Bloodline Champions.lnk
[2010/05/15 21:15:55 | 000,001,024 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/05/15 21:14:55 | 000,000,875 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2010/05/15 20:58:36 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/05/15 20:29:31 | 000,524,288 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/05/15 20:29:31 | 000,524,288 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 20:29:31 | 000,065,536 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/05/15 20:23:59 | 000,000,020 | -HS- | M] () – C:\Users\Rashad\ntuser.ini
[2010/05/06 13:36:38 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2010/05/30 18:21:47 | 000,001,885 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/30 11:11:03 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/30 11:11:03 | 000,001,812 | —- | C] () – C:\Users\Public\Desktop\AVG 9.0.lnk
[2010/05/30 11:10:59 | 060,681,562 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/05/30 10:33:49 | 000,000,248 | -H– | C] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/05/29 20:17:04 | 000,000,290 | -H– | C] () – C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/05/29 20:17:03 | 000,000,246 | -H– | C] () – C:\Windows\tasks\MSWD-111d5cc5.job
[2010/05/29 19:59:33 | 000,002,039 | —- | C] () – C:\Users\Rashad\Desktop\Torchlight.lnk
[2010/05/29 18:51:58 | 000,001,208 | —- | C] () – C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010/05/26 18:54:10 | 000,001,819 | —- | C] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
[2010/05/26 18:53:06 | 000,001,861 | —- | C] () – C:\Users\Rashad\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 15:22:29 | 000,002,645 | —- | C] () – C:\Users\Rashad\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/05/16 11:33:05 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/05/15 22:53:23 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/05/15 22:53:23 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/05/15 22:51:53 | 2616,057,856 | -HS- | C] () – C:\hiberfil.sys
[2010/05/15 22:28:16 | 000,001,096 | —- | C] () – C:\Users\Public\Desktop\StarCraft II Beta.lnk
[2010/05/15 21:16:54 | 000,001,351 | —- | C] () – C:\Users\Rashad\Desktop\Sticky Notes.lnk
[2010/05/15 21:16:12 | 000,002,353 | —- | C] () – C:\Users\Public\Desktop\Bloodline Champions.lnk
[2010/05/15 21:15:55 | 000,001,024 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/05/15 21:07:49 | 000,000,875 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2010/05/15 20:58:36 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/05/15 20:23:59 | 000,524,288 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/05/15 20:23:59 | 000,524,288 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 20:23:59 | 000,262,144 | -HS- | C] () – C:\Users\Rashad\ntuser.dat.LOG1
[2010/05/15 20:23:59 | 000,065,536 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/05/15 20:23:59 | 000,000,020 | -HS- | C] () – C:\Users\Rashad\ntuser.ini
[2010/05/15 20:23:59 | 000,000,000 | -HS- | C] () – C:\Users\Rashad\ntuser.dat.LOG2
[2010/05/15 20:23:58 | 002,359,296 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/06/03 06:07:00 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\LimeWire
[2010/05/29 20:00:46 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\runic games
[2010/06/03 22:11:58 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2010/06/03 06:06:22 | 000,000,246 | -H– | M] () – C:\Windows\Tasks\MSWD-111d5cc5.job
[2010/06/02 22:20:51 | 000,005,616 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/03 22:17:01 | 000,000,248 | -H– | M] () – C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/03 22:05:01 | 000,000,290 | -H– | M] () – C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/06/03 06:05:58 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2010/06/03 06:06:00 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 21:15:13 | 000,346,112 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/07/13 21:15:13 | 000,215,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/30 11:11:01 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/12/17 18:25:12 | 000,026,024 | —- | M] (Elaborate Bytes AG) – C:\Windows\System32\drivers\ElbyCDIO.sys
[2010/04/16 08:33:36 | 000,041,472 | —- | M] (Apple, Inc.) – C:\Windows\System32\drivers\usbaapl.sys

< End of report >
Here's the extra's.txt. I'll post the rest of what you asked for as soon as I can.

OTL Extras logfile created on: 6/3/2010 10:16:08 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Rashad\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 507.82 Gb Free Space | 85.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RASHAD-PC
Current User Name: Rashad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\Rashad\AppData\Roaming\emorunzxbl.exe" = C:\Users\Rashad\AppData\Roaming\emorunzxbl.exe:*:Enabled:6y645tyy – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{BC90276B-BE38-451C-8E4D-FF28FF08ABF6}" = Bloodline Champions Beta
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG 9.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ENTERPRISE" = Microsoft Office Enterprise 2007
"LimeWire" = LimeWire 5.5.8
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Runic Games Torchlight" = Torchlight
"StarCraft II Beta" = StarCraft II Beta
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.0.5
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/2/2010 10:20:39 PM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 476: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/2/2010 10:20:39 PM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/2/2010 10:20:39 PM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 196: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/2/2010 10:20:39 PM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 448: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 6:27:48 AM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 240: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 6:27:48 AM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 476: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 6:27:48 AM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 6:27:48 AM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 484: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 6:27:48 AM | Computer Name = Rashad-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/3/2010 7:05:55 AM | Computer Name = Rashad-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 5/20/2010 4:51:08 PM | Computer Name = Rashad-PC | Source = bowser | ID = 8003
Description =

Error - 5/27/2010 7:42:50 AM | Computer Name = Rashad-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 5/28/2010 7:42:32 AM | Computer Name = Rashad-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 5/29/2010 8:17:32 PM | Computer Name = Rashad-PC | Source = Service Control Manager | ID = 7000
Description = The Application Experience service failed to start due to the following
error: %%776

Error - 5/29/2010 8:30:25 PM | Computer Name = Rashad-PC | Source = Service Control Manager | ID = 7000
Description = The WinHTTP Web Proxy Auto-Discovery Service service failed to start
due to the following error: %%776

Error - 5/30/2010 10:42:27 AM | Computer Name = Rashad-PC | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 5/31/2010 9:24:26 AM | Computer Name = Rashad-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 6/2/2010 7:07:27 AM | Computer Name = Rashad-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 6/2/2010 10:20:51 PM | Computer Name = Rashad-PC | Source = Service Control Manager | ID = 7031
Description = The Background Intelligent Transfer Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
60000 milliseconds: Restart the service.

Error - 6/3/2010 7:18:21 AM | Computer Name = Rashad-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.


< End of report >
3. Gmer.log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-03 22:29:13
Windows 6.1.7600
Running: ntq7jkln.exe; Driver: C:\Users\Rashad\AppData\Local\Temp\uwryqpow.sys


—- System - GMER 1.0.15 —-

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2EAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2E104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2E3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C172D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C16898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2E1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2E958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2E6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2EF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2F1A8

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82847579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8286BF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91235000, 0x227A14, 0xE8000020]
.text peauth.sys 99418C9D 28 Bytes [9E, 26, 26, 52, AF, 4B, 78, …]
.text peauth.sys 99418CC1 28 Bytes [9E, 26, 26, 52, AF, 4B, 78, …]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtProtectVirtualMemory 77D25360 5 Bytes JMP 004F000A
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!NtWriteVirtualMemory 77D25EE0 5 Bytes JMP 0050000A
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!KiUserExceptionDispatcher 77D26448 5 Bytes JMP 004E000A
.text C:\Windows\system32\svchost.exe[1000] ole32.dll!CoCreateInstance 761D57FC 5 Bytes JMP 005F000A
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!GetCursorPos 7797C198 5 Bytes JMP 0069000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!NtProtectVirtualMemory 77D25360 5 Bytes JMP 0065000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!NtWriteVirtualMemory 77D25EE0 5 Bytes JMP 0066000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!KiUserExceptionDispatcher 77D26448 5 Bytes JMP 0015000A

—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI_HAL \Device\00000045 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 865B4EC5

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-







4.) My computer behaves exactly the same as when I first reported the problem. I appreciate you trying to help me with this and I hope we can work this out!
[external image: Posted Image] One or more of the identified infections is a backdoor trojan and password stealer.

This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.


I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?



NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
ComboFix 10-06-03.01 - Rashad 06/04/2010 17:37:16.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3326.2446 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job Infected copy of c:\windows\system32\DRIVERS\mssmbios.sys was found and disinfected Restored copy from - Kitty ate it :P . ((((((((((((((((((((((((( Files Created from 2010-05-04 to 2010-06-04 ))))))))))))))))))))))))))))))) . 2010-06-04 21:40 . 2010-06-04 21:41 ——– d—–w- c:\users\Rashad\AppData\Local\temp 2010-06-04 21:40 . 2010-06-04 21:40 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-06-04 21:35 . 2010-06-04 21:35 ——– d—–w- C:\Device 2010-06-04 21:29 . 2010-06-04 21:30 ——– d—–w- C:\32788R22FWJFW 2010-05-31 23:04 . 2010-05-31 23:04 ——– d—–w- c:\program files\Common Files\Java 2010-05-31 23:04 . 2010-05-31 23:04 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-05-30 15:13 . 2010-05-30 15:13 ——– d—–w- C:\$AVG 2010-05-30 15:11 . 2010-05-30 15:11 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2010-05-30 15:11 . 2010-05-30 15:11 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-05-30 15:11 . 2010-05-30 15:11 12464 —-a-w- c:\windows\system32\avgrsstx.dll 2010-05-30 15:11 . 2010-05-30 15:11 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-05-30 15:10 . 2010-06-04 21:21 ——– d—–w- c:\windows\system32\drivers\Avg 2010-05-30 15:10 . 2010-05-30 15:10 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-05-30 15:10 . 2010-05-30 15:41 ——– d—–w- c:\programdata\avg9 2010-05-30 15:10 . 2010-05-30 15:10 ——– d—–w- c:\program files\AVG 2010-05-30 00:00 . 2010-05-30 00:00 ——– d—–w- c:\users\Rashad\AppData\Roaming\runic games 2010-05-29 23:59 . 2010-05-29 23:59 ——– d—–w- c:\program files\Common Files\Datalode 2010-05-29 23:59 . 2010-05-29 23:59 ——– d—–w- c:\program files\Runic Games 2010-05-29 23:53 . 2010-05-29 23:53 ——– d—–w- c:\users\Rashad\AppData\Local\ElevatedDiagnostics 2010-05-29 22:51 . 2010-05-29 22:51 ——– d—–w- c:\program files\Elaborate Bytes 2010-05-27 02:17 . 2010-05-27 02:17 ——– d—–w- c:\windows\Sun 2010-05-26 22:53 . 2010-06-04 10:21 ——– d—–w- c:\users\Rashad\AppData\Roaming\LimeWire 2010-05-26 22:52 . 2010-05-26 22:52 ——– d—–w- c:\program files\Java 2010-05-26 22:52 . 2010-05-26 22:53 ——– d—–w- c:\program files\LimeWire 2010-05-26 22:51 . 2010-05-26 22:50 378368 —-a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\Rar.exe 2010-05-26 22:51 . 2010-05-26 22:50 1037312 —-a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.exe 2010-05-22 01:01 . 2010-05-22 01:01 ——– d—–w- c:\programdata\Hewlett-Packard 2010-05-22 01:01 . 2008-04-05 01:01 272896 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpcpp5r1.DLL 2010-05-22 00:59 . 2010-05-22 00:59 ——– d—–w- C:\HP LJ1320 PCL5 Driver 2010-05-22 00:53 . 2010-05-22 00:53 ——– d—–w- c:\program files\Common Files\Adobe 2010-05-22 00:53 . 2010-02-01 01:45 38784 —-a-w- c:\users\Rashad\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-22 00:52 . 2010-02-01 01:45 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-22 00:52 . 2010-05-22 00:52 ——– d—–w- c:\program files\Common Files\Adobe AIR 2010-05-22 00:52 . 2010-05-22 00:54 ——– d—–w- c:\users\Rashad\AppData\Local\Adobe 2010-05-22 00:52 . 2010-05-22 00:52 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2010-05-22 00:52 . 2010-05-22 11:59 ——– d—–w- c:\programdata\NOS 2010-05-16 20:11 . 2010-06-04 00:02 ——– d—–w- c:\users\Rashad\AppData\Roaming\vlc 2010-05-16 14:18 . 2010-05-16 14:18 ——– d—–w- c:\windows\system32\Macromed 2010-05-16 03:51 . 2010-05-16 00:23 ——– d—–w- c:\windows\Panther 2010-05-16 03:14 . 2010-05-06 17:36 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-05-16 03:01 . 2010-06-04 10:27 ——– d—–w- c:\windows\system32\wbem\Performance 2010-05-16 02:53 . 2010-05-16 02:53 0 —-a-w- c:\windows\system32\atiicdxx.dat 2010-05-16 02:53 . 2010-05-16 02:53 0 —-a-w- c:\windows\ativpsrm.bin 2010-05-16 02:28 . 2010-05-18 21:41 ——– d—–w- c:\program files\StarCraft II Beta 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\users\Rashad\AppData\Local\Blizzard Entertainment 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\programdata\Blizzard Entertainment 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment 2010-05-16 02:02 . 2010-05-16 02:02 ——– d—–w- c:\programdata\Blizzard 2010-05-16 01:29 . 2006-10-26 23:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll 2010-05-16 01:29 . 2006-10-26 23:56 32592 —-a-w- c:\windows\system32\msonpmon.dll 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\program files\Microsoft Works 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\windows\PCHEALTH 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\program files\Microsoft.NET 2010-05-16 01:26 . 2010-05-16 01:26 ——– d—–w- c:\program files\Microsoft Visual Studio 8 2010-05-16 01:25 . 2010-05-16 01:25 ——– d—–w- c:\users\Rashad\AppData\Local\Microsoft Help 2010-05-16 01:25 . 2010-05-16 01:29 ——– d—–w- c:\programdata\Microsoft Help 2010-05-16 01:25 . 2010-05-16 01:25 ——– d—–r- C:\MSOCache 2010-05-16 01:17 . 2010-05-16 02:02 ——– d—–w- c:\users\Rashad\StarCraft II Beta enUS 13891 Installer 2010-05-16 01:15 . 2010-05-16 01:15 ——– d—–w- c:\program files\Stunlock Studios 2010-05-16 01:15 . 2010-05-16 01:15 ——– d—–w- c:\program files\VideoLAN 2010-05-16 01:14 . 2009-03-16 18:18 69448 —-a-w- c:\windows\system32\XAPOFX1_3.dll 2010-05-16 01:14 . 2009-03-16 18:18 517448 —-a-w- c:\windows\system32\XAudio2_4.dll 2010-05-16 01:14 . 2009-03-16 18:18 235352 —-a-w- c:\windows\system32\xactengine3_4.dll 2010-05-16 01:14 . 2009-03-16 18:18 22360 —-a-w- c:\windows\system32\X3DAudio1_6.dll 2010-05-16 01:14 . 2007-04-04 22:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll 2010-05-16 01:14 . 2007-03-12 20:42 3495784 —-a-w- c:\windows\system32\d3dx9_33.dll 2010-05-16 01:14 . 2006-09-28 20:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll 2010-05-16 01:14 . 2010-05-16 01:14 ——– d—–w- c:\program files\Microsoft XNA 2010-05-16 01:07 . 2010-05-16 01:14 ——– d—–w- c:\program files\Common Files\Steam 2010-05-16 01:07 . 2010-06-04 10:21 ——– d—–w- c:\program files\Steam 2010-05-16 01:07 . 2010-05-16 01:07 ——– d—–w- c:\program files\uTorrent 2010-05-16 01:07 . 2010-06-04 21:33 ——– d—–w- c:\users\Rashad\AppData\Roaming\uTorrent 2010-05-16 00:58 . 2010-05-25 02:20 ——– d—–w- c:\users\Rashad\AppData\Roaming\Apple Computer 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\users\Rashad\AppData\Local\Apple Computer 2010-05-16 00:56 . 2010-05-31 23:04 ——– d-sh–w- c:\windows\Installer 2010-05-16 00:33 . 2010-05-16 00:33 ——– d—–w- c:\users\Rashad\AppData\Local\Mozilla 2010-05-16 00:27 . 2010-05-16 02:00 108824 —-a-w- c:\users\Rashad\AppData\Local\GDIPFONTCACHEV1.DAT 2010-05-16 00:24 . 2010-05-16 00:24 ——– d—–w- c:\users\Rashad\AppData\Local\VirtualStore . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-16 15:33 . 2010-05-16 15:33 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-05-16 15:33 . 2010-05-16 00:57 ——– d—–w- c:\programdata\Apple 2010-05-16 01:28 . 2009-07-14 04:52 ——– d—–w- c:\program files\MSBuild 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\iTunes 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\iPod 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\programdata\Apple Computer 2010-05-16 00:58 . 2010-05-16 00:57 ——– d—–w- c:\program files\Common Files\Apple 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\QuickTime 2010-05-16 00:57 . 2010-05-16 00:57 ——– d—–w- c:\program files\Apple Software Update 2010-05-16 00:57 . 2010-05-16 00:57 ——– d—–w- c:\program files\Bonjour 2010-04-28 19:45 . 2010-04-28 19:45 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe 2010-04-16 12:33 . 2010-04-16 12:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2010-04-16 12:33 . 2010-04-16 12:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll 2010-04-08 17:20 . 2010-04-08 17:20 91424 —-a-w- c:\windows\system32\dnssd.dll 2010-04-08 17:20 . 2010-04-08 17:20 107808 —-a-w- c:\windows\system32\dns-sd.exe 2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-05-16 322352] "Steam"="c:\program files\Steam\Steam.exe" [2010-05-16 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] c:\users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-3-23 503808] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys] @="FSFilter System Recovery" S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-05-30 52872] S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-05-30 216200] S1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-05-30 242896] S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-05-30 308064] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] . Contents of the 'Scheduled Tasks' folder . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\dxrgz2xe.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source;=iglk FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - HKCU-Run-QZAIB7KITK - c:\windows\Uguwua.exe SafeBoot-dmboot.sys SafeBoot-dmio.sys SafeBoot-dmload.sys SafeBoot-dmadmin SafeBoot-dmserver SafeBoot-SRService . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\taskhost.exe c:\windows\system32\sppsvc.exe c:\windows\system32\conhost.exe c:\program files\AVG\AVG9\avgam.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\iPod\bin\iPodService.exe c:\program files\AVG\AVG9\avgcsrvx.exe . ************************************************************************** . Completion time: 2010-06-04 17:43:24 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-04 21:43 Pre-Run: 544,377,372,672 bytes free Post-Run: 544,411,242,496 bytes free - - End Of File - - 8E63F41B7A18F11EEB694061DA8F68BD
Hello,

Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]


NEXT:



OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.



NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the MalwareBytes' Anti-Malware scan.
3. The log that was produced after running the ESET Online Virus Scanner.
4. The log that was produced after running the OTL scan.
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Cheers,
SweetTech.
ComboFix 10-06-03.01 - Rashad 06/04/2010 17:37:16.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3326.2446 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job Infected copy of c:\windows\system32\DRIVERS\mssmbios.sys was found and disinfected Restored copy from - Kitty ate it :P . ((((((((((((((((((((((((( Files Created from 2010-05-04 to 2010-06-04 ))))))))))))))))))))))))))))))) . 2010-06-04 21:40 . 2010-06-04 21:41 ——– d—–w- c:\users\Rashad\AppData\Local\temp 2010-06-04 21:40 . 2010-06-04 21:40 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-06-04 21:35 . 2010-06-04 21:35 ——– d—–w- C:\Device 2010-06-04 21:29 . 2010-06-04 21:30 ——– d—–w- C:\32788R22FWJFW 2010-05-31 23:04 . 2010-05-31 23:04 ——– d—–w- c:\program files\Common Files\Java 2010-05-31 23:04 . 2010-05-31 23:04 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-05-30 15:13 . 2010-05-30 15:13 ——– d—–w- C:\$AVG 2010-05-30 15:11 . 2010-05-30 15:11 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2010-05-30 15:11 . 2010-05-30 15:11 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-05-30 15:11 . 2010-05-30 15:11 12464 —-a-w- c:\windows\system32\avgrsstx.dll 2010-05-30 15:11 . 2010-05-30 15:11 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-05-30 15:10 . 2010-06-04 21:21 ——– d—–w- c:\windows\system32\drivers\Avg 2010-05-30 15:10 . 2010-05-30 15:10 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-05-30 15:10 . 2010-05-30 15:41 ——– d—–w- c:\programdata\avg9 2010-05-30 15:10 . 2010-05-30 15:10 ——– d—–w- c:\program files\AVG 2010-05-30 00:00 . 2010-05-30 00:00 ——– d—–w- c:\users\Rashad\AppData\Roaming\runic games 2010-05-29 23:59 . 2010-05-29 23:59 ——– d—–w- c:\program files\Common Files\Datalode 2010-05-29 23:59 . 2010-05-29 23:59 ——– d—–w- c:\program files\Runic Games 2010-05-29 23:53 . 2010-05-29 23:53 ——– d—–w- c:\users\Rashad\AppData\Local\ElevatedDiagnostics 2010-05-29 22:51 . 2010-05-29 22:51 ——– d—–w- c:\program files\Elaborate Bytes 2010-05-27 02:17 . 2010-05-27 02:17 ——– d—–w- c:\windows\Sun 2010-05-26 22:53 . 2010-06-04 10:21 ——– d—–w- c:\users\Rashad\AppData\Roaming\LimeWire 2010-05-26 22:52 . 2010-05-26 22:52 ——– d—–w- c:\program files\Java 2010-05-26 22:52 . 2010-05-26 22:53 ——– d—–w- c:\program files\LimeWire 2010-05-26 22:51 . 2010-05-26 22:50 378368 —-a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\Rar.exe 2010-05-26 22:51 . 2010-05-26 22:50 1037312 —-a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.exe 2010-05-22 01:01 . 2010-05-22 01:01 ——– d—–w- c:\programdata\Hewlett-Packard 2010-05-22 01:01 . 2008-04-05 01:01 272896 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpcpp5r1.DLL 2010-05-22 00:59 . 2010-05-22 00:59 ——– d—–w- C:\HP LJ1320 PCL5 Driver 2010-05-22 00:53 . 2010-05-22 00:53 ——– d—–w- c:\program files\Common Files\Adobe 2010-05-22 00:53 . 2010-02-01 01:45 38784 —-a-w- c:\users\Rashad\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-22 00:52 . 2010-02-01 01:45 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-22 00:52 . 2010-05-22 00:52 ——– d—–w- c:\program files\Common Files\Adobe AIR 2010-05-22 00:52 . 2010-05-22 00:54 ——– d—–w- c:\users\Rashad\AppData\Local\Adobe 2010-05-22 00:52 . 2010-05-22 00:52 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2010-05-22 00:52 . 2010-05-22 11:59 ——– d—–w- c:\programdata\NOS 2010-05-16 20:11 . 2010-06-04 00:02 ——– d—–w- c:\users\Rashad\AppData\Roaming\vlc 2010-05-16 14:18 . 2010-05-16 14:18 ——– d—–w- c:\windows\system32\Macromed 2010-05-16 03:51 . 2010-05-16 00:23 ——– d—–w- c:\windows\Panther 2010-05-16 03:14 . 2010-05-06 17:36 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-05-16 03:01 . 2010-06-04 10:27 ——– d—–w- c:\windows\system32\wbem\Performance 2010-05-16 02:53 . 2010-05-16 02:53 0 —-a-w- c:\windows\system32\atiicdxx.dat 2010-05-16 02:53 . 2010-05-16 02:53 0 —-a-w- c:\windows\ativpsrm.bin 2010-05-16 02:28 . 2010-05-18 21:41 ——– d—–w- c:\program files\StarCraft II Beta 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\users\Rashad\AppData\Local\Blizzard Entertainment 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\programdata\Blizzard Entertainment 2010-05-16 02:28 . 2010-05-16 02:30 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment 2010-05-16 02:02 . 2010-05-16 02:02 ——– d—–w- c:\programdata\Blizzard 2010-05-16 01:29 . 2006-10-26 23:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll 2010-05-16 01:29 . 2006-10-26 23:56 32592 —-a-w- c:\windows\system32\msonpmon.dll 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\program files\Microsoft Works 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\windows\PCHEALTH 2010-05-16 01:28 . 2010-05-16 01:28 ——– d—–w- c:\program files\Microsoft.NET 2010-05-16 01:26 . 2010-05-16 01:26 ——– d—–w- c:\program files\Microsoft Visual Studio 8 2010-05-16 01:25 . 2010-05-16 01:25 ——– d—–w- c:\users\Rashad\AppData\Local\Microsoft Help 2010-05-16 01:25 . 2010-05-16 01:29 ——– d—–w- c:\programdata\Microsoft Help 2010-05-16 01:25 . 2010-05-16 01:25 ——– d—–r- C:\MSOCache 2010-05-16 01:17 . 2010-05-16 02:02 ——– d—–w- c:\users\Rashad\StarCraft II Beta enUS 13891 Installer 2010-05-16 01:15 . 2010-05-16 01:15 ——– d—–w- c:\program files\Stunlock Studios 2010-05-16 01:15 . 2010-05-16 01:15 ——– d—–w- c:\program files\VideoLAN 2010-05-16 01:14 . 2009-03-16 18:18 69448 —-a-w- c:\windows\system32\XAPOFX1_3.dll 2010-05-16 01:14 . 2009-03-16 18:18 517448 —-a-w- c:\windows\system32\XAudio2_4.dll 2010-05-16 01:14 . 2009-03-16 18:18 235352 —-a-w- c:\windows\system32\xactengine3_4.dll 2010-05-16 01:14 . 2009-03-16 18:18 22360 —-a-w- c:\windows\system32\X3DAudio1_6.dll 2010-05-16 01:14 . 2007-04-04 22:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll 2010-05-16 01:14 . 2007-03-12 20:42 3495784 —-a-w- c:\windows\system32\d3dx9_33.dll 2010-05-16 01:14 . 2006-09-28 20:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll 2010-05-16 01:14 . 2010-05-16 01:14 ——– d—–w- c:\program files\Microsoft XNA 2010-05-16 01:07 . 2010-05-16 01:14 ——– d—–w- c:\program files\Common Files\Steam 2010-05-16 01:07 . 2010-06-04 10:21 ——– d—–w- c:\program files\Steam 2010-05-16 01:07 . 2010-05-16 01:07 ——– d—–w- c:\program files\uTorrent 2010-05-16 01:07 . 2010-06-04 21:33 ——– d—–w- c:\users\Rashad\AppData\Roaming\uTorrent 2010-05-16 00:58 . 2010-05-25 02:20 ——– d—–w- c:\users\Rashad\AppData\Roaming\Apple Computer 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\users\Rashad\AppData\Local\Apple Computer 2010-05-16 00:56 . 2010-05-31 23:04 ——– d-sh–w- c:\windows\Installer 2010-05-16 00:33 . 2010-05-16 00:33 ——– d—–w- c:\users\Rashad\AppData\Local\Mozilla 2010-05-16 00:27 . 2010-05-16 02:00 108824 —-a-w- c:\users\Rashad\AppData\Local\GDIPFONTCACHEV1.DAT 2010-05-16 00:24 . 2010-05-16 00:24 ——– d—–w- c:\users\Rashad\AppData\Local\VirtualStore . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-16 15:33 . 2010-05-16 15:33 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-05-16 15:33 . 2010-05-16 00:57 ——– d—–w- c:\programdata\Apple 2010-05-16 01:28 . 2009-07-14 04:52 ——– d—–w- c:\program files\MSBuild 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\iTunes 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\iPod 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\programdata\Apple Computer 2010-05-16 00:58 . 2010-05-16 00:57 ——– d—–w- c:\program files\Common Files\Apple 2010-05-16 00:58 . 2010-05-16 00:58 ——– d—–w- c:\program files\QuickTime 2010-05-16 00:57 . 2010-05-16 00:57 ——– d—–w- c:\program files\Apple Software Update 2010-05-16 00:57 . 2010-05-16 00:57 ——– d—–w- c:\program files\Bonjour 2010-04-28 19:45 . 2010-04-28 19:45 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe 2010-04-16 12:33 . 2010-04-16 12:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2010-04-16 12:33 . 2010-04-16 12:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll 2010-04-08 17:20 . 2010-04-08 17:20 91424 —-a-w- c:\windows\system32\dnssd.dll 2010-04-08 17:20 . 2010-04-08 17:20 107808 —-a-w- c:\windows\system32\dns-sd.exe 2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-05-16 322352] "Steam"="c:\program files\Steam\Steam.exe" [2010-05-16 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] c:\users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-3-23 503808] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys] @="FSFilter System Recovery" S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-05-30 52872] S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-05-30 216200] S1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-05-30 242896] S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-05-30 308064] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] . Contents of the 'Scheduled Tasks' folder . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\dxrgz2xe.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source;=iglk FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - HKCU-Run-QZAIB7KITK - c:\windows\Uguwua.exe SafeBoot-dmboot.sys SafeBoot-dmio.sys SafeBoot-dmload.sys SafeBoot-dmadmin SafeBoot-dmserver SafeBoot-SRService . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\taskhost.exe c:\windows\system32\sppsvc.exe c:\windows\system32\conhost.exe c:\program files\AVG\AVG9\avgam.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\iPod\bin\iPodService.exe c:\program files\AVG\AVG9\avgcsrvx.exe . ************************************************************************** . Completion time: 2010-06-04 17:43:24 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-04 21:43 Pre-Run: 544,377,372,672 bytes free Post-Run: 544,411,242,496 bytes free - - End Of File - - 8E63F41B7A18F11EEB694061DA8F68BD
Oh yeah, sorry. I'll post the logs in separate posts as soon as they finish. Here's the first one you asked for. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4169 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 6/4/2010 8:39:37 PM mbam-log-2010-06-04 (20-39-37).txt Scan type: Quick scan Objects scanned: 124163 Time elapsed: 2 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Second. C:\Qoobox\Quarantine\C\Windows\system32\Drivers\mssmbios.sys.vir Win32/Olmarik.ZC trojan C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\5a3d7b8a-56b5c445 Java/TrojanDownloader.Agent.AF trojan C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\20bdd891-6405f57a a variant of Java/Exploit.Agent.F trojan C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\690b50ac-1b329dce multiple threats C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\696d2fac-63cc2730 a variant of Java/Exploit.Agent.F trojan C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\1192d4f9-7eff8373 multiple threats C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\fd18ba-3dd7bb52 a variant of Java/Exploit.Agent.F trojan C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\53d361fc-25294fa7 multiple threats C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\35aace80-18310f1b multiple threats C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\24b191f7-50ec4198 a variant of Java/Exploit.Agent.F trojan
And the final one:

OTL logfile created on: 6/4/2010 8:42:13 PM - Run 2
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Rashad\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 506.85 Gb Free Space | 85.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RASHAD-PC
Current User Name: Rashad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Rashad\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\VideoLAN\VLC\vlc.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)


========== Modules (SafeList) ==========

MOD - C:\Users\Rashad\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\Windows\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ElbyCDIO) – C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (VClone) – C:\Windows\System32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 32 F8 22 50 46 00 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en&source=iglk"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/05/30 11:10:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/30 18:21:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/31 19:04:35 | 000,000,000 | —D | M]

[2010/05/26 18:54:04 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2010/05/26 18:54:04 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/05/22 08:01:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\dxrgz2xe.default\extensions
[2010/06/04 19:13:30 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/31 19:04:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/31 19:04:21 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/04 17:41:25 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/13 22:37:08 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/04 19:40:05 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/04 19:23:34 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Malwarebytes
[2010/06/04 19:23:28 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/04 19:23:27 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/06/04 19:23:27 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/04 19:23:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/04 19:22:49 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Users\Rashad\Desktop\mbam-setup.exe
[2010/06/04 17:43:26 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/06/04 17:41:46 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/06/04 17:40:10 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\temp
[2010/06/04 17:35:40 | 000,000,000 | —D | C] – C:\Device
[2010/06/04 17:30:13 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/06/04 17:30:13 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/06/04 17:30:13 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/06/04 17:29:52 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/04 17:29:51 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/06/04 17:29:16 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/06/04 17:29:02 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/03 22:15:01 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Rashad\Desktop\OTL.exe
[2010/05/31 19:04:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/31 19:04:35 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/05/31 19:04:35 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/05/31 19:04:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/05/31 19:04:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/05/31 19:01:21 | 000,000,000 | —D | C] – C:\Windows\System32\appmgmt
[2010/05/30 11:13:38 | 000,000,000 | —D | C] – C:\$AVG
[2010/05/30 11:11:02 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/05/30 11:11:00 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/30 11:10:59 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2010/05/30 11:10:42 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/05/30 11:10:42 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/05/30 11:08:45 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\WinRAR
[2010/05/29 20:00:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\runic games
[2010/05/29 19:59:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Datalode
[2010/05/29 19:59:02 | 000,000,000 | —D | C] – C:\Program Files\Runic Games
[2010/05/29 19:53:57 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\ElevatedDiagnostics
[2010/05/29 18:51:34 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2010/05/26 22:17:22 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/05/26 18:54:09 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\LimeWire
[2010/05/26 18:53:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\LimeWire
[2010/05/26 18:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/05/26 18:52:51 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/26 18:52:28 | 000,000,000 | —D | C] – C:\Program Files\LimeWire
[2010/05/26 18:51:29 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/05/21 21:01:47 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2010/05/21 20:59:58 | 000,000,000 | —D | C] – C:\HP LJ1320 PCL5 Driver
[2010/05/21 20:53:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/05/21 20:53:01 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/05/21 20:52:58 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010/05/21 20:52:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/05/21 20:52:35 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Adobe
[2010/05/21 20:52:30 | 000,000,000 | —D | C] – C:\ProgramData\NOS
[2010/05/16 16:11:09 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\vlc
[2010/05/16 10:18:10 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Macromedia
[2010/05/16 10:18:10 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Adobe
[2010/05/16 10:18:08 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/05/15 23:51:01 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/05/15 23:14:50 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/15 23:00:29 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/05/15 22:52:23 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/05/15 22:51:53 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II Beta
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II Beta
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Blizzard Entertainment
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2010/05/15 22:28:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2010/05/15 22:02:20 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard
[2010/05/15 21:29:05 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2010/05/15 21:28:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2010/05/15 21:28:09 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/05/15 21:28:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/05/15 21:28:00 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/05/15 21:28:00 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/05/15 21:26:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/05/15 21:25:41 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Microsoft Help
[2010/05/15 21:25:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/05/15 21:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2010/05/15 21:25:16 | 000,000,000 | R–D | C] – C:\MSOCache
[2010/05/15 21:17:22 | 000,000,000 | —D | C] – C:\Users\Rashad\StarCraft II Beta enUS 13891 Installer
[2010/05/15 21:15:46 | 000,000,000 | —D | C] – C:\Program Files\Stunlock Studios
[2010/05/15 21:15:45 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/05/15 21:14:58 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2010/05/15 21:14:58 | 000,069,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/05/15 21:14:57 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2010/05/15 21:14:57 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2010/05/15 21:14:57 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2010/05/15 21:14:57 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2010/05/15 21:14:57 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2010/05/15 21:14:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft XNA
[2010/05/15 21:07:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Steam
[2010/05/15 21:07:49 | 000,000,000 | —D | C] – C:\Program Files\Steam
[2010/05/15 21:07:38 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/15 21:07:21 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2010/05/15 20:58:38 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Apple Computer
[2010/05/15 20:58:38 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Apple Computer
[2010/05/15 20:58:35 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/05/15 20:58:34 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2010/05/15 20:58:27 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/05/15 20:58:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/05/15 20:58:26 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/15 20:58:00 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/05/15 20:58:00 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/05/15 20:57:56 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Apple
[2010/05/15 20:57:55 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/05/15 20:57:47 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/05/15 20:57:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/05/15 20:57:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/05/15 20:56:22 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/05/15 20:36:39 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\School
[2010/05/15 20:33:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Mozilla
[2010/05/15 20:33:46 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Mozilla
[2010/05/15 20:32:46 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/05/15 20:24:12 | 000,000,000 | R–D | C] – C:\Users\Rashad\Searches
[2010/05/15 20:24:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Identities
[2010/05/15 20:24:03 | 000,000,000 | R–D | C] – C:\Users\Rashad\Contacts
[2010/05/15 20:24:00 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\VirtualStore
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\Temporary Internet Files
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Templates
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Start Menu
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\SendTo
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Recent
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\PrintHood
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\NetHood
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Videos
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Pictures
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Documents\My Music
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\My Documents
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Local Settings
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\History
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Cookies
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\Application Data
[2010/05/15 20:23:59 | 000,000,000 | -HSD | C] – C:\Users\Rashad\AppData\Local\Application Data
[2010/05/15 20:23:58 | 000,000,000 | –SD | C] – C:\Users\Rashad\AppData\Roaming\Microsoft
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Videos
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Saved Games
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Pictures
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Music
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Links
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Favorites
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Downloads
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\My Documents
[2010/05/15 20:23:58 | 000,000,000 | R–D | C] – C:\Users\Rashad\Desktop
[2010/05/15 20:23:58 | 000,000,000 | -H-D | C] – C:\Users\Rashad\AppData
[2010/05/15 20:23:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Local\Microsoft
[2010/05/15 20:23:58 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Media Center Programs
[2010/05/15 20:23:47 | 000,000,000 | —D | C] – C:\Recovery

========== Files - Modified Within 30 Days ==========

[2010/06/04 20:42:32 | 002,359,296 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT
[2010/06/04 19:23:30 | 000,000,979 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/04 19:22:53 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Rashad\Desktop\mbam-setup.exe
[2010/06/04 17:46:18 | 000,014,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/04 17:46:18 | 000,014,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/04 17:46:11 | 000,717,892 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/04 17:46:11 | 000,618,026 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/04 17:46:11 | 000,104,340 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/04 17:41:27 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/06/04 17:41:25 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/06/04 17:41:13 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/04 17:41:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/04 17:41:09 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2010/06/04 17:25:20 | 003,702,826 | R— | M] () – C:\Users\Rashad\Desktop\ComboFix.exe
[2010/06/04 17:21:02 | 060,704,886 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/06/03 22:41:01 | 002,454,770 | -H– | M] () – C:\Users\Rashad\AppData\Local\IconCache.db
[2010/06/03 22:14:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Rashad\Desktop\OTL.exe
[2010/05/31 19:04:21 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/05/31 19:04:21 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/05/31 19:04:21 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/05/31 19:04:21 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/05/30 18:21:47 | 000,001,885 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/30 11:11:03 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/30 11:11:03 | 000,001,812 | —- | M] () – C:\Users\Public\Desktop\AVG 9.0.lnk
[2010/05/30 11:11:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/05/30 11:11:01 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/29 19:59:33 | 000,002,039 | —- | M] () – C:\Users\Rashad\Desktop\Torchlight.lnk
[2010/05/29 18:51:58 | 000,001,208 | —- | M] () – C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010/05/26 18:54:10 | 000,001,819 | —- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
[2010/05/26 18:53:06 | 000,001,861 | —- | M] () – C:\Users\Rashad\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 15:22:29 | 000,002,645 | —- | M] () – C:\Users\Rashad\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/05/17 06:36:15 | 000,412,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/05/16 11:33:05 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/05/15 22:55:01 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2010/05/15 22:53:23 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2010/05/15 22:53:23 | 000,000,000 | —- | M] () – C:\Windows\System32\atiicdxx.dat
[2010/05/15 22:30:11 | 000,001,096 | —- | M] () – C:\Users\Public\Desktop\StarCraft II Beta.lnk
[2010/05/15 22:00:07 | 000,108,824 | —- | M] () – C:\Users\Rashad\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/15 21:26:04 | 000,000,478 | —- | M] () – C:\Windows\win.ini
[2010/05/15 21:16:54 | 000,001,351 | —- | M] () – C:\Users\Rashad\Desktop\Sticky Notes.lnk
[2010/05/15 21:16:12 | 000,002,353 | —- | M] () – C:\Users\Public\Desktop\Bloodline Champions.lnk
[2010/05/15 21:15:55 | 000,001,024 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/05/15 21:14:55 | 000,000,875 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2010/05/15 20:58:36 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/05/15 20:29:31 | 000,524,288 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/05/15 20:29:31 | 000,524,288 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 20:29:31 | 000,065,536 | -HS- | M] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/05/15 20:23:59 | 000,000,020 | -HS- | M] () – C:\Users\Rashad\ntuser.ini
[2010/05/06 13:36:38 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2010/06/04 19:23:30 | 000,000,979 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/04 17:30:13 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/06/04 17:30:13 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/06/04 17:30:13 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/06/04 17:30:13 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/06/04 17:30:13 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/06/04 17:25:16 | 003,702,826 | R— | C] () – C:\Users\Rashad\Desktop\ComboFix.exe
[2010/05/30 18:21:47 | 000,001,885 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/30 11:11:03 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/30 11:11:03 | 000,001,812 | —- | C] () – C:\Users\Public\Desktop\AVG 9.0.lnk
[2010/05/30 11:10:59 | 060,704,886 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/05/29 19:59:33 | 000,002,039 | —- | C] () – C:\Users\Rashad\Desktop\Torchlight.lnk
[2010/05/29 18:51:58 | 000,001,208 | —- | C] () – C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010/05/26 18:54:10 | 000,001,819 | —- | C] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
[2010/05/26 18:53:06 | 000,001,861 | —- | C] () – C:\Users\Rashad\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 15:22:29 | 000,002,645 | —- | C] () – C:\Users\Rashad\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/05/16 11:33:05 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/05/15 22:53:23 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/05/15 22:53:23 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/05/15 22:51:53 | 2616,057,856 | -HS- | C] () – C:\hiberfil.sys
[2010/05/15 22:28:16 | 000,001,096 | —- | C] () – C:\Users\Public\Desktop\StarCraft II Beta.lnk
[2010/05/15 21:16:54 | 000,001,351 | —- | C] () – C:\Users\Rashad\Desktop\Sticky Notes.lnk
[2010/05/15 21:16:12 | 000,002,353 | —- | C] () – C:\Users\Public\Desktop\Bloodline Champions.lnk
[2010/05/15 21:15:55 | 000,001,024 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/05/15 21:07:49 | 000,000,875 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2010/05/15 20:58:36 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/05/15 20:23:59 | 000,524,288 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/05/15 20:23:59 | 000,524,288 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 20:23:59 | 000,262,144 | -HS- | C] () – C:\Users\Rashad\ntuser.dat.LOG1
[2010/05/15 20:23:59 | 000,065,536 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/05/15 20:23:59 | 000,000,020 | -HS- | C] () – C:\Users\Rashad\ntuser.ini
[2010/05/15 20:23:59 | 000,000,000 | -HS- | C] () – C:\Users\Rashad\ntuser.dat.LOG2
[2010/05/15 20:23:58 | 002,359,296 | -HS- | C] () – C:\Users\Rashad\NTUSER.DAT
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/06/04 17:43:25 | 000,014,877 | —- | M] () – C:\ComboFix.txt
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/06/04 17:41:09 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2010/06/04 17:41:10 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/30 11:11:01 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/05/30 11:10:59 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/30 11:11:02 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/30 11:11:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/12/17 18:25:12 | 000,026,024 | —- | M] (Elaborate Bytes AG) – C:\Windows\System32\drivers\ElbyCDIO.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/16 08:33:36 | 000,041,472 | —- | M] (Apple, Inc.) – C:\Windows\System32\drivers\usbaapl.sys

< End of report >



Also, I have not noticed the re-directing problem lately but I haven't been surfing much. Thanks!
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :Files
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\5a3d7b8a-56b5c445
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\20bdd891-6405f57a
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\690b50ac-1b329dce
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\696d2fac-63cc2730
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\1192d4f9-7eff8373
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\fd18ba-3dd7bb52
    C:\Users\Rashad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\53d361fc-25294fa7
    C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\35aace80-18310f1b
    C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\24b191f7-50ec4198
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI