
I dealt with the Google Redirect virus on Vista a while back with little problem but it has now infected my XP operating PC. I have taken all the beginning steps as listed in the Malware and Spyware Removal Guide thread. I also know that I have the infamous wdmaud.drv file in my system32. I can rename or delete but it just returns and no spyware software I have tried can seem to nab it. Here is my OTL log from the most recent scan as set by the guide's instruction (MBAM and GMER follow seperately):
OTL logfile created on: 09/08/2010 11:51:20 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Ernie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 63.46 Gb Free Space | 42.60% Space Free | Partition Type: NTFS
Drive D: | 17.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GAME-RIG
Current User Name: Ernie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/08/01 15:14:31 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ernie\My Documents\Downloads\OTL.exe
PRC - [2010/06/02 20:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009/08/25 08:23:04 | 000,368,640 | ---- | M] () -- C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
PRC - [2008/11/07 12:43:36 | 000,809,488 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/11/07 12:39:36 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/13 23:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/26 01:21:22 | 000,537,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxddcoms.exe
PRC - [2006/08/15 11:47:58 | 001,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
========== Modules (SafeList) ==========
MOD - [2010/08/01 15:14:31 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ernie\My Documents\Downloads\OTL.exe
MOD - [2009/07/12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008/11/07 12:41:46 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2008/04/13 23:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2010/01/05 13:12:06 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/02/11 15:12:38 | 000,167,936 | ---- | M] () [Auto | Stopped] -- C:\Program Files\TRENDnet\TEW-424UB\WLSVC.exe -- (WLSVC)
SRV - [2008/11/07 12:40:52 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007/04/26 01:21:22 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxddcoms.exe -- (lxdd_device)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009/11/12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008/09/26 05:52:00 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2008/09/10 14:39:08 | 000,176,640 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2008/02/27 06:54:00 | 000,020,480 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\WLNdis50.sys -- (WLNdis50)
DRV - [2008/02/15 09:12:06 | 005,854,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007/07/18 20:40:08 | 000,264,576 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2006/08/15 11:48:00 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.achewood.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.2
FF - prefs.js..extensions.enabledItems: {477c4c36-24eb-11da-94d4-00e08161165f}:2.7.6
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.7.8
FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.4.8
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/31 17:57:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/01 20:36:45 | 000,000,000 | ---D | M]
[2010/07/31 17:52:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Extensions
[2010/08/07 00:00:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions
[2010/07/31 18:02:47 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/07/31 18:02:47 | 000,000,000 | ---D | M] (Grab and Drag) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{477c4c36-24eb-11da-94d4-00e08161165f}
[2010/08/05 13:52:35 | 000,000,000 | ---D | M] (Fire.fm) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
[2010/07/31 18:02:47 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/07/31 18:02:46 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/05 13:59:51 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/07/31 18:02:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\e26ohhe1.default\extensions\[email protected]
[2010/08/07 00:00:44 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/03/28 21:53:19 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2010/04/30 14:56:09 | 000,001,798 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apulegacud] C:\WINDOWS\ehopidura.DLL File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Lexmark 1200 Series] C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Aim] C:\Program Files\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [couexof] C:\Documents and Settings\Ernie\couexof.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = [binary data]
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Ernie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ernie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/05 11:48:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5240bb84-80a0-11df-aa59-0014d16d84cb}\Shell - "" = AutoRun
O33 - MountPoints2\{5240bb84-80a0-11df-aa59-0014d16d84cb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5240bb84-80a0-11df-aa59-0014d16d84cb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co....thors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 90 Days ==========
[2010/08/06 14:57:26 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ernie\Recent
[2010/08/02 16:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\My Documents\AIMLogger
[2010/08/01 15:12:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Desktop\gmer
[2010/08/01 04:32:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/07/31 17:51:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Mozilla
[2010/07/31 17:51:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Application Data\Mozilla
[2010/07/31 15:31:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/07/31 15:30:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/07/31 15:13:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/31 15:13:40 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/07/30 17:26:12 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2010/07/29 21:02:34 | 000,000,000 | ---D | C] -- C:\Avenger
[2010/07/29 20:46:13 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/07/29 05:26:12 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/07/29 04:49:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Sunbelt Software
[2010/07/29 04:48:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/07/28 04:27:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Installer2260
[2010/07/28 04:17:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Installer3084
[2010/07/27 23:50:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\moosoft
[2010/07/27 20:52:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Application Data\thecleaner
[2010/07/27 20:51:58 | 000,000,000 | ---D | C] -- C:\Program Files\The Cleaner
[2010/07/27 13:44:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Installer2520
[2010/07/27 08:42:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/23 17:36:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/23 17:33:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/23 12:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/23 12:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/22 21:23:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\{C06FA2E1-DFAE-41FF-9711-557FB8FEB5B0}
[2010/07/13 13:19:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2010/07/08 15:38:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010/07/08 15:29:39 | 000,000,000 | ---D | C] -- C:\Program Files\Western Digital Corp
[2010/07/04 09:35:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2010/07/01 02:25:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\My Documents\Dungeons and Dragons Online
[2010/07/01 01:53:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Application Data\Turbine
[2010/07/01 01:53:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Turbine
[2010/07/01 01:52:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\ApplicationHistory
[2010/07/01 01:50:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2010/07/01 01:28:31 | 000,000,000 | ---D | C] -- C:\Program Files\Turbine
[2010/06/30 22:56:15 | 000,000,000 | ---D | C] -- C:\Program Files\Alarm Clock
[2010/06/25 18:24:50 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010/06/14 21:54:07 | 000,000,000 | ---D | C] -- C:\Program Files\Lionhead Studios
[2010/06/13 17:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/06/13 17:23:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ALM
[2010/06/13 17:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/06/13 14:36:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\My Documents\AdobeStockPhotos
[2010/06/06 15:06:05 | 000,442,368 | ---- | C] (On2.com) -- C:\WINDOWS\System32\vp6vfw.dll
[2010/05/31 15:25:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ernie\Local Settings\Application Data\Noteworthy Software
[2010/05/31 15:25:28 | 000,000,000 | ---D | C] -- C:\Program Files\Noteworthy Software
[2010/02/03 00:08:46 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\LXDDhcp.dll
[2010/02/03 00:08:44 | 000,999,424 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddusb1.dll
[2010/02/03 00:08:44 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddinpa.dll
[2010/02/03 00:08:44 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddiesc.dll
[2010/02/03 00:08:43 | 001,232,896 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddserv.dll
[2010/02/03 00:08:43 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddpmui.dll
[2010/02/03 00:08:43 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddlmpm.dll
[2010/02/03 00:08:43 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddprox.dll
[2010/02/03 00:08:43 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddpplc.dll
[2010/02/03 00:08:42 | 000,700,416 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddhbn3.dll
[2010/02/03 00:08:39 | 000,425,984 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcomm.dll
[2010/02/03 00:08:38 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcomc.dll
[4 C:\Documents and Settings\Ernie\*.tmp files -> C:\Documents and Settings\Ernie\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/08/08 05:26:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/08 02:08:45 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/06 22:00:53 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2010/08/06 14:59:36 | 000,000,302 | -HS- | M] () -- C:\WINDOWS\tasks\CUXYDAT.job
[2010/08/06 14:59:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/06 14:59:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/06 14:59:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/06 14:59:31 | 1600,270,336 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/03 03:15:46 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ernie\ntuser.ini
[2010/08/03 03:15:45 | 004,194,304 | -H-- | M] () -- C:\Documents and Settings\Ernie\NTUSER.DAT
[2010/08/02 11:57:07 | 000,420,388 | ---- | M] () -- C:\Documents and Settings\Ernie\Desktop\42256.pdf
[2010/07/29 21:01:07 | 000,000,000 | ---- | M] () -- C:\backup.reg
[2010/07/29 21:00:56 | 000,135,168 | ---- | M] () -- C:\zip.exe
[2010/07/29 21:00:56 | 000,019,286 | ---- | M] () -- C:\cleanup.exe
[2010/07/29 21:00:56 | 000,000,574 | ---- | M] () -- C:\cleanup.bat
[2010/07/29 10:47:14 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Axafupoqoxevuq.dat
[2010/07/29 05:26:12 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/07/29 04:38:03 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Tvamafojocetuw.bin
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\WINDOWS.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\WD Sync Data.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Video.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Templates.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Start Menu.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\SendTo.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Recent.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\PrivacIE.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\PrintHood.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Pictures.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Passwords.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\nsnB7F.tmp.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\nsjB82.tmp.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\New Folder.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\NetHood.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\My Documents.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Music.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Local Settings.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\IETldCache.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Favorites.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Documents.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Desktop.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Cookies.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\Application Data.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\7zSBA0.tmp.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\7ZipSfx.001.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\7ZipSfx.000.lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\..lnk
[2010/07/28 13:12:50 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Ernie\...lnk
[2010/07/28 13:00:19 | 000,025,600 | ---- | M] () -- C:\Documents and Settings\Ernie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/22 21:20:35 | 000,156,160 | RHS- | M] () -- C:\WINDOWS\System32\hlink1.dll
[2010/07/14 03:03:23 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/08 15:51:33 | 000,520,410 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/08 15:51:33 | 000,440,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/07/08 15:51:33 | 000,071,002 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/07/01 01:53:36 | 000,000,128 | ---- | M] () -- C:\Documents and Settings\Ernie\Local Settings\Application Data\fusioncache.dat
[2010/06/13 17:41:15 | 000,069,360 | ---- | M] () -- C:\Documents and Settings\Ernie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/13 17:32:31 | 003,762,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 20:58:08 | 000,000,631 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/11 20:58:08 | 000,000,257 | ---- | M] () -- C:\WINDOWS\system.ini
[4 C:\Documents and Settings\Ernie\*.tmp files -> C:\Documents and Settings\Ernie\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/02 11:57:07 | 000,420,388 | ---- | C] () -- C:\Documents and Settings\Ernie\Desktop\42256.pdf
[2010/07/31 15:36:14 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/07/29 21:01:07 | 000,000,000 | ---- | C] () -- C:\backup.reg
[2010/07/29 21:00:56 | 000,135,168 | ---- | C] () -- C:\zip.exe
[2010/07/29 21:00:56 | 000,019,286 | ---- | C] () -- C:\cleanup.exe
[2010/07/29 21:00:56 | 000,000,574 | ---- | C] () -- C:\cleanup.bat
[2010/07/29 05:29:30 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\WINDOWS
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\WD Sync Data
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Video.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Templates
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Start Menu
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\SendTo
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Recent
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\PrivacIE
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\PrintHood
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Pictures.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Passwords.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\nsnB7F.tmp
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\nsjB82.tmp
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\New Folder.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\NetHood
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\My Documents
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Music.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Local Settings
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\IETldCache
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Favorites
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Documents.lnk
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Desktop
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Cookies
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\Application Data
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\7zSBA0.tmp
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\7ZipSfx.001
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\7ZipSfx.000
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\.
[2010/07/27 13:24:41 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Ernie\..
[2010/07/22 21:23:04 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Axafupoqoxevuq.dat
[2010/07/22 21:23:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Tvamafojocetuw.bin
[2010/07/22 21:20:37 | 000,000,302 | -HS- | C] () -- C:\WINDOWS\tasks\CUXYDAT.job
[2010/07/22 21:20:35 | 000,156,160 | RHS- | C] () -- C:\WINDOWS\System32\hlink1.dll
[2010/07/01 01:53:36 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Ernie\Local Settings\Application Data\fusioncache.dat
[2010/04/06 08:54:18 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/02/03 00:26:36 | 000,000,076 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2010/02/03 00:24:46 | 000,000,100 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2010/02/03 00:24:11 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxczvs.dll
[2010/02/03 00:23:52 | 000,000,270 | ---- | C] () -- C:\WINDOWS\System32\lxczcoin.ini
[2010/02/03 00:08:47 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\LXDDinst.dll
[2010/02/03 00:08:41 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxddgrd.dll
[2010/02/01 18:11:18 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\drivers\WLNdis50.sys
[2010/01/06 13:09:15 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/01/05 11:52:25 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\M2000Twn.dll
[2010/01/05 11:52:25 | 000,182,275 | ---- | C] () -- C:\WINDOWS\System32\d3d10core.dll
[2010/01/05 11:52:25 | 000,169,984 | ---- | C] () -- C:\WINDOWS\System32\glut32.dll
[2010/01/05 11:52:25 | 000,169,984 | ---- | C] () -- C:\WINDOWS\System32\glut.dll
[2010/01/05 11:52:25 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\CompressATI2.dll
[2010/01/05 11:52:08 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/01/05 11:52:07 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/01/05 11:52:04 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/01/05 11:52:04 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/01/05 11:52:03 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010/01/05 11:52:01 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/01/05 11:52:01 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/01/05 11:43:59 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\libpng13.dll
[2010/01/05 11:43:58 | 000,394,752 | ---- | C] () -- C:\WINDOWS\System32\cygwinb19.dll
[2010/01/05 11:43:57 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2010/01/05 11:28:06 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/29 15:55:24 | 000,000,468 | ---- | C] () -- C:\WINDOWS\System32\Oeminfo.ini
[2003/01/07 11:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/02/01 18:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2010/04/06 08:54:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/01/08 08:47:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/02/01 20:31:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2010/07/28 04:15:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\moosoft
[2010/06/30 23:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/06/13 17:46:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/01/27 10:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Ableton
[2010/02/01 18:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\acccore
[2010/04/06 08:54:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Canneverbe Limited
[2010/01/07 17:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\DAEMON Tools
[2010/01/08 09:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\DAEMON Tools Lite
[2010/04/15 11:30:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\EDFbrowser
[2010/01/05 16:14:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Leadertech
[2010/04/15 11:00:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Polyman
[2010/07/27 20:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\thecleaner
[2010/07/01 01:53:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\Turbine
[2010/07/27 21:52:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ernie\Application Data\uTorrent
[2010/08/08 05:26:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/08/06 14:59:36 | 000,000,302 | -HS- | M] () -- C:\WINDOWS\Tasks\CUXYDAT.job
[2010/08/08 02:08:45 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/08/06 22:00:53 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/07/31 13:58:03 | 000,001,660 | ---- | M] () -- C:\aaw7boot.log
[2010/01/05 11:48:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/07/29 21:02:34 | 000,007,590 | ---- | M] () -- C:\avenger.txt
[2010/07/29 21:01:07 | 000,000,000 | ---- | M] () -- C:\backup.reg
[2010/01/05 11:42:29 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/07/29 21:00:56 | 000,000,574 | ---- | M] () -- C:\cleanup.bat
[2010/07/29 21:00:56 | 000,019,286 | ---- | M] () -- C:\cleanup.exe
[2010/01/05 11:48:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/08/06 14:59:31 | 1600,270,336 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/05 11:48:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/03/29 15:06:31 | 000,000,914 | -H-- | M] () -- C:\IPH.PH
[2010/01/05 11:48:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/04/13 16:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 18:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/06 14:59:27 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/07/29 20:51:23 | 000,035,086 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_29.07.2010_20.51.00_log.txt
[2010/07/29 21:00:56 | 000,135,168 | ---- | M] () -- C:\zip.exe
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/01/05 11:47:34 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/19 13:33:38 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2007/04/09 09:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/01/05 11:25:12 | 000,061,440 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010/01/05 11:25:12 | 001,073,152 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010/01/05 11:25:12 | 000,827,392 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"AutoInstallMinorUpdates" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-03 07:00:36
< End of report >

Here is my most recent MBAM log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4375
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
31/07/2010 15:21:31
mbam-log-2010-07-31 (15-21-31).txt
Scan type: Quick scan
Objects scanned: 136022
Time elapsed: 5 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)

And lastly, the GMER log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-05 23:40:13
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Ernie\LOCALS~1\Temp\kftyqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9318F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0156B833
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 0156C549
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0156C25D
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0156C465
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 0156B779
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!recv 71AB676F 5 Bytes JMP 0156C300
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0156C3A7
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 0156BBA6
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0156C7A9
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0156CCD1
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0156C6DF
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0156CBEF
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0156D07C
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0156D143
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 0156BC7E
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0156CB0A
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0156C94C
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0156C5D4
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0156C873
.text C:\Program Files\Mozilla Firefox\firefox.exe[440] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0156CA25
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[860] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1044721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0xF0 0x2A 0xAD 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\[email protected] 0xAA 0x23 0x6A 0x56 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x14 0x7B 0x87 0xFF ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0xF0 0x2A 0xAD 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\[email protected] 0xAA 0x23 0x6A 0x56 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x14 0x7B 0x87 0xFF ...
---- EOF - GMER 1.0.15 ----

Thanks again for taking the time to look through these logs. I wouldn't be asking for your time if I could have figured this thing out on my own.