Hi 125124,

Both FRST and GMER are very powerful, currently the best diagnostic tools, they record and format the generic reports using a varius techniques and heuristics. They mostly do not know what is legitimate and what malicius. It is on expert face to determine is the recorded entries related to some loaded malicious or legitimate software.

"Warning !!! GMER has found system modification caused by ROOTKIT activity"
GMER has been detected the avast! related drivers (because their driver behavior). Of course, detection is legitimate. There is not RootKit on your system. GMER log is clean.

Let’s proceed further with the system analysis …

Do you know for this progam?
AaaaaAAaaaAAAaaAAAAaAAAAA!!! for the Awesome (HKLM-x32.…\Steam App 15560) (Version: - Dejobaan Games, LLC)

PS: I would recommend to uninstall/remove the Pando Media Booster from your system. This isn’t malware, it’s legit tools so the choice is yours.

Next, you have been disable the “TP-LINK Wireless Configuration Utility” via MSConfig tool. My recommendation is to take it back.
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TP-LINK Wireless Configuration Utility.lnk => C:\Windows\pss\TP-LINK Wireless Configuration Utility.lnk.CommonStartup

Next, FRST shows the traces of possible USB - malware related infections. We shall use MCShield tool/software to check all USB’s devices. If malware exists on any USB device, MCShield shall clean it for you and provide the future protections.

Next, can you take a look at this folder?
C:\Users\SM\AppData\Roaming[b]rcru[/b]
If folder is empty (as it should be), you can delete this.

Every time I enter into bittorrent, opens the program and also trys to redirect my browser into:
I can not tell you why exactly avast! detects the bittorrent URL but judging by the rules, bittorrent is illegal actions, malicious action. So ...

Btw, posted FRST and GMER logs doesn’t show any trace of any malware. FRST log is clean as well. Your PC is malware free.
As I said before, according to FRST, we should check the USB device, just to make shure.


MCShield’s Scan


Please download MCShield from one of the following links:

MCShield -Official download link

[*]Double click on MCShield-Setup to install the application.
Next => I Agree => Next => Install … per installation click on Run! button.
[]Wait a few seconds to MCShield finish initial HDD scan…
[
]Connect all your USB storage devices to the computer one at a time. Scanning will be done automatically.
[*]When all scanning is done, you need to post a logreport that MCShield has created.

Under Logs tab (in Control Center) for AllScans.txt log section click on Save button. AllScanst.txt report shall be located on your Desktop.

=> Post here AllScanst.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.


Uninstall


We shall remove used diagnostic tools via DelFix.

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.