ComboFix 10-08-16.03 - Chan 08/17/2010 1:05.3.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3326.2397 [GMT -7:00]
Running from: c:\users\Chan\Desktop\New folder\ComboFix.exe
Command switches used :: c:\users\Chan\Desktop\New folder\CFScript.txt.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-07-17 to 2010-08-17 )))))))))))))))))))))))))))))))
.
2010-08-17 09:36 . 2009-07-14 01:26 21584 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-08-17 08:15 . 2010-08-17 08:39 -------- d-----w- c:\users\Chan\AppData\Local\temp
2010-08-17 08:15 . 2010-08-17 08:15 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-17 08:15 . 2010-08-17 08:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-17 08:03 . 2010-08-17 08:03 -------- d-----w- C:\Device
2010-08-16 10:15 . 2010-08-16 10:15 8432064 ----a-w- c:\users\Chan\AppData\Roaming\Azureus\tmp\AZU6186427272018498426.tmp\Vuze_4.5.0.2a_win32.exe
2010-08-11 22:43 . 2010-08-16 02:38 -------- d-----w- c:\users\Chan\AppData\Roaming\vlc
2010-08-11 07:21 . 2010-08-13 20:49 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2010-08-11 06:54 . 2010-08-11 06:54 -------- d-----w- c:\program files\Sun
2010-08-11 06:36 . 2010-08-11 06:36 -------- d-----w- c:\windows\system32\MustBeRandomlyNamed
2010-08-10 06:30 . 2010-08-10 06:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-09 02:33 . 2010-08-09 02:33 -------- d-----w- c:\users\Chan\AppData\Local\GamersFirst LIVE!
2010-08-09 02:33 . 2010-08-10 06:56 -------- d-----w- c:\users\Chan\AppData\Local\PMB Files
2010-08-09 02:33 . 2010-08-10 06:22 -------- d-----w- c:\programdata\PMB Files
2010-08-09 02:18 . 2010-08-09 02:33 -------- d-----w- c:\program files\GamersFirst
2010-08-04 22:24 . 2010-08-04 22:29 -------- d-----w- c:\program files\Disable Spyware
2010-08-04 20:29 . 2010-08-11 08:17 -------- d-----w- c:\program files\Warcraft III
2010-08-04 20:18 . 2010-08-04 20:18 -------- d-----w- c:\program files\Microsoft.NET
2010-08-04 18:57 . 2010-08-04 18:57 188152 ----a-w- c:\users\Chan\AppData\Roaming\Mozilla\Firefox\Profiles\s04jin69.default\FlashGot.exe
2010-08-04 18:54 . 2010-08-04 18:54 0 ----a-w- c:\windows\nsreg.dat
2010-08-04 18:53 . 2010-08-15 01:05 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 2
2010-08-01 03:06 . 2010-08-01 03:06 -------- d-----w- c:\program files\Paradox Interactive
2010-08-01 02:52 . 2010-08-10 07:51 -------- d-----w- c:\program files\StarCraft II
2010-07-29 22:39 . 2010-07-29 22:39 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-07-29 22:09 . 2009-11-24 22:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-07-29 22:09 . 2009-11-24 22:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-07-29 22:09 . 2009-11-24 22:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-07-29 22:09 . 2009-11-24 22:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-07-29 22:09 . 2009-11-24 22:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-29 22:08 . 2009-11-24 22:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-07-29 22:08 . 2009-11-24 22:49 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-07-29 22:08 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-07-29 22:08 . 2010-07-29 22:08 -------- d-----w- c:\program files\Alwil Software
2010-07-29 08:43 . 2010-07-29 08:43 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-07-29 07:36 . 2010-08-08 18:32 -------- d-----w- c:\users\Chan\AppData\Local\PokerStars
2010-07-29 07:36 . 2010-07-31 00:17 -------- d-----w- c:\program files\PokerStars
2010-07-29 05:55 . 2010-07-31 02:20 -------- d-----w- c:\users\Chan\AppData\Local\Adobe
2010-07-29 01:02 . 2010-07-29 22:40 -------- d-----w- c:\users\Chan\AppData\Local\AIM
2010-07-29 01:02 . 2010-07-29 01:02 -------- d-----w- c:\users\Chan\AppData\Local\AOL
2010-07-29 00:48 . 2010-07-29 00:48 47364 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-07-29 00:04 . 2010-07-29 00:04 -------- d-----w- c:\program files\Common Files\Java
2010-07-29 00:04 . 2010-07-29 00:25 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-27 08:17 . 2010-01-11 02:40 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-07-27 08:11 . 2010-08-10 07:46 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-27 08:11 . 2010-07-27 08:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-22 22:56 . 2010-07-22 23:03 -------- d-----w- c:\program files\GameKiss
2010-07-21 22:06 . 2010-07-21 22:06 -------- d-----w- c:\program files\MegaDev
2010-07-21 10:10 . 2010-07-21 10:10 -------- d-----w- c:\programdata\Big Fish Games
2010-07-20 17:49 . 2010-07-20 17:49 -------- d-----w- c:\windows\Sun
2010-07-20 17:48 . 2010-08-02 04:06 -------- d-----w- c:\users\Chan\AppData\Roaming\Tropico 3
2010-07-20 17:35 . 2010-08-04 20:59 -------- d-----w- c:\program files\Kalypso
2010-07-19 17:25 . 2010-07-19 17:25 -------- d-----w- c:\users\Chan\AppData\Local\Ironclad Games
2010-07-19 17:25 . 2010-07-19 17:25 -------- d-----w- c:\programdata\Ironclad Games
2010-07-19 14:38 . 2010-07-19 15:16 -------- d-----w- c:\program files\Dragon Age
2010-07-19 07:24 . 2010-07-19 07:25 16820376 ----a-w- c:\programdata\Muzzy Lane\Client Installers\MakingHistoryIISetup-1.0.11.11972.exe
2010-07-19 07:09 . 2010-07-19 07:09 -------- d-----w- c:\users\Chan\AppData\Roaming\PE Explorer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 10:24 . 2010-01-10 13:35 -------- d-----w- c:\users\Chan\AppData\Roaming\Azureus
2010-08-14 16:18 . 2010-02-22 11:28 -------- d-----w- c:\program files\Heroes of Newerth
2010-08-13 23:19 . 2010-04-04 23:20 -------- d-----w- c:\program files\Steam
2010-08-11 22:47 . 2010-04-04 23:20 -------- d-----w- c:\program files\Common Files\Steam
2010-08-11 09:15 . 2010-07-07 08:47 -------- d-----w- c:\program files\StarCraft Brood War by Monikon
2010-08-11 06:52 . 2010-01-10 13:42 -------- d-----w- c:\program files\Java
2010-08-09 02:33 . 2010-05-28 03:25 -------- d-----w- c:\program files\Pando Networks
2010-08-08 18:31 . 2010-02-03 01:04 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-08-04 21:00 . 2010-05-30 03:05 -------- d-----w- c:\program files\Veetle
2010-08-04 19:15 . 2010-01-09 20:02 -------- d-----w- c:\program files\World of Warcraft
2010-08-01 03:02 . 2010-03-03 09:28 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-07-31 07:06 . 2010-01-10 13:50 1 ----a-w- c:\users\Chan\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-31 01:38 . 2010-03-06 05:25 0 ----a-w- c:\users\Chan\AppData\Local\prvlcl.dat
2010-07-29 22:39 . 2010-01-10 12:20 -------- d-----w- c:\program files\AIM
2010-07-29 08:43 . 2010-03-10 01:51 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-07-29 08:41 . 2010-03-10 01:51 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-29 01:01 . 2010-03-03 09:28 -------- d-----w- c:\program files\StarCraft II Beta
2010-07-28 23:44 . 2010-03-03 02:00 -------- d-----w- c:\program files\Opera
2010-07-28 23:36 . 2010-07-09 11:27 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 1
2010-07-27 08:27 . 2010-07-12 06:03 -------- d-----w- c:\program files\CCleaner
2010-07-22 23:03 . 2010-01-10 11:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-20 15:01 . 2010-01-10 20:47 -------- d-----w- c:\programdata\avg9
2010-07-20 03:54 . 2010-01-10 11:10 -------- d-----w- c:\program files\AGEIA Technologies
2010-07-20 03:53 . 2010-01-10 11:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-20 03:44 . 2010-07-15 10:21 -------- d-----w- c:\program files\Activision
2010-07-19 15:24 . 2010-05-01 23:25 -------- d-----w- c:\programdata\BioWare
2010-07-19 14:55 . 2010-04-06 08:58 -------- d-----w- c:\programdata\Media Center Programs
2010-07-19 14:55 . 2010-05-01 22:55 -------- d-----w- c:\program files\Common Files\BioWare
2010-07-17 23:14 . 2010-07-08 20:27 -------- d-----w- c:\programdata\Muzzy Lane
2010-07-17 23:13 . 2010-07-17 23:12 16820360 ----a-w- c:\programdata\Muzzy Lane\Client Installers\MakingHistoryIISetup-1.0.10.11963.exe
2010-07-17 19:19 . 2010-07-17 18:30 -------- d-----w- c:\program files\Empire Total War
2010-07-17 13:41 . 2010-07-17 13:41 56440 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\74\1\.cp\lib\sef3x1Controller.dll
2010-07-17 13:34 . 2010-07-17 13:34 1772664 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\41\1\.cp\lib\BHQ.dll
2010-07-17 13:34 . 2010-07-17 13:34 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\41\1\.cp\lib\BHQFlash.dll
2010-07-17 13:34 . 2010-07-17 13:34 81016 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\70\1\.cp\lib\S1SLEngineWrapper.dll
2010-07-17 13:34 . 2010-07-17 13:34 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\60\1\.cp\lib\MemStickFlash.dll
2010-07-17 13:33 . 2010-07-17 13:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2010-07-17 13:33 . 2010-07-17 13:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf
2010-07-17 13:33 . 2010-07-17 13:33 101496 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\82\1\.cp\lib\USBFlash.dll
2010-07-17 13:30 . 2010-07-17 13:30 109752 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\66\1\.cp\lib\osds.dll
2010-07-17 13:30 . 2010-07-17 13:30 89208 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\80\1\.cp\lib\UAC.dll
2010-07-17 13:30 . 2010-07-17 13:30 57344 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\4\1\.cp\lib\serialio.dll
2010-07-17 13:30 . 2010-07-17 13:30 323648 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DIFxAPI.dll
2010-07-17 13:30 . 2010-07-17 13:30 216184 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\68\1\.cp\lib\RegistryReader.dll
2010-07-17 13:30 . 2010-07-17 13:30 158840 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DriverInstaller.exe
2010-07-17 13:30 . 2010-07-17 13:30 154744 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\8\1\.cp\lib\win32\DeviceRemover.exe
2010-07-17 13:30 . 2010-07-17 13:30 117880 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\6\1\.cp\lib\DeviceManager.dll
2010-07-17 13:28 . 2010-07-17 13:28 -------- d-----w- c:\program files\Common Files\Sony Ericsson
2010-07-17 13:28 . 2010-07-17 13:18 -------- d-----w- c:\program files\Sony Ericsson
2010-07-17 13:28 . 2010-07-17 13:18 -------- d-----w- c:\programdata\Sony Ericsson
2010-07-17 13:20 . 2010-07-17 13:20 -------- d-----w- c:\programdata\BVRP Software
2010-07-15 15:09 . 2010-01-10 20:48 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 15:09 . 2010-07-15 15:09 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 15:09 . 2010-01-10 20:48 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-15 02:11 . 2010-07-15 02:11 -------- d-----w- c:\program files\MSXML 4.0
2010-07-14 20:17 . 2010-04-23 07:47 -------- d-----w- c:\program files\Mount&Blade Warband
2010-07-13 12:37 . 2010-04-08 10:05 -------- d-----w- c:\program files\Electronic Arts
2010-07-13 12:34 . 2010-05-10 22:24 -------- d-----w- c:\program files\LucasArts
2010-07-13 12:26 . 2010-02-06 09:19 -------- d-----w- c:\program files\Free Window Registry Repair
2010-07-13 11:29 . 2010-01-10 11:11 -------- d-----w- c:\programdata\NVIDIA
2010-07-13 03:48 . 2010-01-10 11:40 72064 ----a-w- c:\users\Chan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-12 23:19 . 2009-07-14 04:52 -------- d-----w- c:\program files\Microsoft Games
2010-07-12 23:18 . 2010-01-10 11:08 -------- d-----w- c:\program files\Common Files\InstallShield
2010-07-12 10:20 . 2010-07-12 10:20 65536 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\NewShortcut7_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 65536 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\NewShortcut4_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 65536 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\Manual_UK_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 65536 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\Manual_FR_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 65536 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\Manual_DE_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 45056 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\S11Launcher.exeE_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:20 . 2010-07-12 10:20 45056 ----a-r- c:\users\Chan\AppData\Roaming\Microsoft\Installer\{64893225-ADBA-469E-B114-F3B2C1FBBA77}\S11Launcher.exe_64893225ADBA469EB114F3B2C1FBBA77.exe
2010-07-12 10:19 . 2010-07-12 10:19 -------- d-----w- c:\program files\Koei
2010-07-12 06:04 . 2010-01-10 20:28 -------- d-----w- c:\users\Chan\AppData\Roaming\Media Player Classic
2010-07-12 06:03 . 2010-07-12 06:03 -------- d-----w- c:\program files\Defraggler
2010-07-09 08:58 . 2010-01-22 10:37 -------- d-----w- c:\program files\Microsoft Silverlight
2010-07-08 20:36 . 2010-07-08 20:35 16695072 ----a-w- c:\programdata\Muzzy Lane\Client Installers\MakingHistoryIISetup-1.0.9.exe
2010-07-08 20:29 . 2010-03-10 06:34 -------- d-----w- c:\program files\Muzzy Lane Software
2010-06-25 10:12 . 2010-06-25 10:12 -------- d-----w- c:\users\Chan\AppData\Roaming\LolClient
2010-06-25 03:08 . 2010-06-25 03:05 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-22 05:16 . 2010-05-14 02:17 -------- d-----w- c:\programdata\Electronic Arts
2010-06-22 05:15 . 2010-05-17 12:38 -------- d-----w- c:\program files\Graboid
2010-06-22 04:51 . 2010-06-22 04:51 -------- d-----w- c:\programdata\ATI
2010-06-22 04:51 . 2010-04-29 01:04 -------- d-----w- c:\program files\ATI Technologies
2010-06-22 01:46 . 2010-06-22 01:46 -------- d-----w- c:\program files\MPC HomeCinema
2010-06-02 16:35 . 2010-01-10 20:48 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 04:04 . 2010-05-28 04:04 98304 ----a-w- c:\programdata\NexonUS\NGM\npNxGameUS.dll
2010-05-28 04:04 . 2010-05-28 04:04 765952 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2010-05-28 04:04 . 2010-05-28 04:04 401408 ----a-w- c:\programdata\NexonUS\NGM\NGMResource.dll
2010-05-28 04:04 . 2010-05-28 04:04 258352 ----a-w- c:\programdata\NexonUS\NGM\unicows.dll
2010-05-28 04:04 . 2010-05-28 04:04 172032 ----a-w- c:\programdata\NexonUS\NGM\NGM.exe
2010-05-28 04:04 . 2010-05-28 04:04 126976 ----a-w- c:\programdata\NexonUS\NGM\nxgameus.dll
2010-05-27 17:38 . 2010-05-27 17:38 5586432 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-05-27 17:05 . 2010-05-27 17:05 15180800 ----a-w- c:\windows\system32\atioglxx.dll
2010-05-27 17:02 . 2010-05-27 17:02 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-05-27 17:02 . 2010-04-07 02:16 511488 ----a-w- c:\windows\system32\aticfx32.dll
2010-05-27 17:00 . 2010-05-27 17:00 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-05-27 16:59 . 2010-05-27 16:59 376832 ----a-w- c:\windows\system32\atieclxx.exe
2010-05-27 16:59 . 2010-05-27 16:59 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-05-27 16:58 . 2010-05-27 16:58 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-05-27 16:58 . 2010-05-27 16:58 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-05-27 16:58 . 2010-05-27 16:58 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 20:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
backup=c:\windows\pss\GamersFirst LIVE!.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Chan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Chan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-03-04 21:31 311296 ----a-w- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F5D9050]
2006-02-14 22:19 1531904 ----a-w- c:\program files\Belkin\F5D9050\Belkinwcui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 22:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-08-09 02:33 2937528 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2010-05-27 19:34 98304 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-08 11:08 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 18:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-12-21 05:45 39424 ----a-w- c:\program files\Winamp\winampa.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ALSysIO;ALSysIO;c:\users\Chan\AppData\Local\Temp\ALSysIO.sys [x]
R3 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-20 921952]
R3 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
R3 BKNDIS5;BKNDIS5 NDIS Protocol Driver;c:\progra~1\Belkin\F5D9050\BKNDIS5.SYS [2005-03-02 15872]
R3 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-07-02 306296]
R3 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-07-02 162936]
R3 GarenaPEngine;GarenaPEngine;c:\users\Chan\AppData\Local\Temp\FLX804C.tmp [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2009-04-06 13224]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 netr73;Belkin Wireless G Plus MIMO USB Network Adapter Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2007-11-12 468480]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-29 1343400]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-05-27 176128]
R4 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R4 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-07-29 691696]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-08-13 41816]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
S1 aswSP;avast! Self Protection; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-15 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-15 243024]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2010-07-28 1935656]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-03-31 20968]
S3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2010-06-28 71008]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-05-27 5586432]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-05-27 209920]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclock.sys [2009-09-15 38248]
S3 StreamSurge;StreamSurge Driver (miniport);c:\windows\system32\DRIVERS\ss.sys [2005-06-18 19968]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.commStart Page =
hxxp://www.yahoo.comFF - ProfilePath - c:\users\Chan\AppData\Roaming\Mozilla\Firefox\Profiles\s04jin69.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x86C41B4C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
SecurityProcedure -> 0x859e47b8
QueryNameProcedure -> 0x85974810
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\GarenaPEngine]
"ImagePath"="\??\c:\users\Chan\AppData\Local\Temp\FLX804C.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Adobe\Reader 9.0\Reader\AcroRd32.exe
.
**************************************************************************
.
Completion time: 2010-08-17 01:44:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-17 08:44
ComboFix2.txt 2010-08-10 06:21
ComboFix3.txt 2010-07-29 00:21
Pre-Run: 96,067,010,560 bytes free
Post-Run: 95,560,896,512 bytes free
- - End Of File - - 6D6D51FFB41829DE261A62041E13EAB7
Still getting redirects. Thanks for the assistance so far tho, much appreciated.