Here are the logs you requested

.
ComboFix 10-04-14.04 - Brian 04/15/2010 15:23:55.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.382 [GMT -7:00]
Running from: c:\documents and settings\Brian\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Brian\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\docume~1\alluse~1\applic~1\8SOejo8n.exe"
"c:\documents and settings\All Users\Application Data\58q7uu.dat"
"c:\documents and settings\Brian\Desktop\usmc\SKELTON (F)\Autorun.inf"
"c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe"
"c:\program files\Common Files\Java\Java Update\jusched.exe"
"c:\program files\Common Files\Real\Update_OB\realsched.exe"
"c:\program files\iTunes\iTunesHelper.exe"
"c:\program files\QuickTime\qttask.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\alluse~1\applic~1\8SOejo8n.exe
c:\documents and settings\All Users\Application Data\58q7uu.dat
c:\documents and settings\All Users\Application Data\8SOejo8n.exe
c:\documents and settings\Brian\Desktop\usmc\SKELTON (F)\Autorun.inf
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\windows\Tasks\At1.job
.
((((((((((((((((((((((((( Files Created from 2010-03-15 to 2010-04-15 )))))))))))))))))))))))))))))))
.
2010-04-13 06:00 . 2010-04-14 07:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\AskToolbar
2010-04-13 05:59 . 2010-04-13 05:59 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Conduit
2010-04-13 05:59 . 2010-04-13 06:00 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Online_Sharing
2010-04-12 21:20 . 2010-04-12 21:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-04-11 03:45 . 2010-04-11 03:45 -------- d-----w- c:\program files\iPod
2010-04-11 03:45 . 2010-04-11 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-11 03:42 . 2010-04-11 03:42 -------- d-----w- c:\program files\Apple Software Update
2010-04-09 06:37 . 2010-04-15 22:23 -------- d-----w- c:\program files\Inbox
2010-04-09 06:10 . 2010-04-14 04:11 -------- d-----w- c:\documents and settings\Brian\Tracing
2010-04-09 05:59 . 2010-04-09 05:59 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-04-09 05:52 . 2010-04-09 05:52 -------- d-----w- c:\program files\Microsoft
2010-04-09 05:52 . 2010-04-09 05:52 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-04-09 05:44 . 2010-04-09 05:44 -------- d-----w- c:\program files\Common Files\Windows Live
2010-04-08 16:16 . 2010-04-08 16:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-08 16:14 . 2010-04-08 16:14 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-04-06 23:59 . 2010-04-06 23:59 125952 ----a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Temp\Update.exe
2010-04-06 23:50 . 2010-04-07 22:02 32032 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-04-06 23:50 . 2010-04-07 22:01 5350944 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-04-06 23:45 . 2010-04-07 22:12 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2010-04-06 23:31 . 2010-04-07 21:49 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-04-06 23:31 . 2010-04-07 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2010-04-06 23:30 . 2010-04-06 23:30 -------- d-----w- c:\documents and settings\Brian\Local Settings\Application Data\Downloaded Installations
2010-04-06 22:52 . 2010-04-06 22:54 -------- d-----w- c:\documents and settings\Brian\Application Data\GetRightToGo
2010-04-06 22:49 . 2010-04-06 23:14 79488 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_19\gtapi.dll
2010-04-06 22:49 . 2010-04-06 23:14 152576 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_19\lzma.dll
2010-04-06 21:21 . 2010-04-14 07:42 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-04-06 11:57 . 2010-04-06 11:57 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-04-06 11:56 . 2010-04-06 11:57 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-06 09:00 . 2010-04-06 09:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-04-06 04:16 . 2010-04-08 15:39 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-06 01:30 . 2010-04-07 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Pixela
2010-04-06 01:27 . 2010-04-06 01:28 -------- d-----w- c:\program files\PIXELA
2010-04-05 10:20 . 2010-04-05 10:20 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2010-04-01 07:35 . 2010-04-01 07:59 -------- d-----w- c:\program files\Project64 1.6
2010-04-01 04:14 . 2010-04-01 04:14 61440 ----a-w- c:\documents and settings\Others\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-72781112-n\decora-sse.dll
2010-04-01 04:14 . 2010-04-01 04:14 503808 ----a-w- c:\documents and settings\Others\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-70ee7950-n\msvcp71.dll
2010-04-01 04:14 . 2010-04-01 04:14 499712 ----a-w- c:\documents and settings\Others\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-70ee7950-n\jmc.dll
2010-04-01 04:14 . 2010-04-01 04:14 348160 ----a-w- c:\documents and settings\Others\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-70ee7950-n\msvcr71.dll
2010-04-01 04:14 . 2010-04-01 04:14 12800 ----a-w- c:\documents and settings\Others\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-72781112-n\decora-d3d.dll
2010-03-31 18:28 . 2010-03-31 18:28 50192 ----a-w- c:\documents and settings\Others\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-31 17:52 . 2010-03-31 17:52 -------- d-----w- c:\documents and settings\Others\Local Settings\Application Data\Mozilla
2010-03-31 17:32 . 2010-03-31 17:32 -------- d-----w- c:\documents and settings\Others\Application Data\SMART Technologies Inc
2010-03-31 17:32 . 2010-03-31 17:32 -------- d-----w- c:\documents and settings\Others\Local Settings\Application Data\Apple Computer
2010-03-31 17:32 . 2010-03-31 17:32 -------- d-----w- c:\documents and settings\Others\Local Settings\Application Data\SupportSoft
2010-03-31 17:12 . 2010-03-31 17:12 -------- d-----w- c:\documents and settings\Guest\Application Data\SMART Technologies Inc
2010-03-29 23:46 . 2010-04-12 20:22 -------- d-----w- c:\program files\DISCIPLINE
2010-03-29 19:44 . 2010-04-12 20:20 -------- d-----w- c:\program files\Kira Kira
2010-03-29 09:50 . 2010-03-29 09:50 -------- d-----w- c:\program files\directx
2010-03-29 09:37 . 2008-03-05 23:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2010-03-29 09:35 . 2010-03-29 09:35 -------- d-----w- c:\windows\Logs
2010-03-26 08:48 . 2010-03-26 08:48 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-24 17:12 . 2010-04-02 19:59 -------- d-----w- c:\program files\Will
2010-03-18 22:30 . 2010-03-29 20:49 -------- d-----w- c:\program files\ZyX
2010-03-18 10:09 . 2010-03-18 10:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-18 10:09 . 2010-03-18 10:09 -------- d-----w- c:\program files\MSBuild
2010-03-18 10:08 . 2010-03-18 10:08 -------- d-----w- c:\program files\Reference Assemblies
2010-03-18 10:08 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-18 10:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-18 10:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-18 10:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-18 10:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-18 10:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-18 10:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-18 10:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-18 10:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-18 10:07 . 2010-03-18 10:08 -------- d-----w- C:\171eaa7061309267e3f8a3d06a4eb1fd
2010-03-18 10:04 . 2010-03-18 10:04 -------- d-----w- c:\program files\Essentials Codec Pack
2010-03-18 06:12 . 2010-03-18 06:12 -------- d-----w- c:\documents and settings\Brian\Application Data\Freedom Scientific
2010-03-18 06:11 . 2010-03-18 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Freedom Scientific
2010-03-18 06:11 . 2010-03-18 06:11 -------- d-----w- c:\program files\ssce
2010-03-18 06:00 . 2006-02-10 04:58 256512 ----a-w- c:\windows\system32\dcmc0d0.dll
2010-03-18 06:00 . 2010-03-18 06:11 -------- d--h--w- c:\program files\Freedom Scientific Installation Information
2010-03-18 06:00 . 2010-03-18 06:00 -------- d-----w- c:\windows\system32\HJSMEM
2010-03-18 06:00 . 2010-03-18 06:11 -------- d-----w- c:\program files\Freedom Scientific
2010-03-18 05:54 . 2010-03-18 05:54 -------- d-----w- c:\program files\Bonjour
2010-03-18 05:42 . 2010-03-18 05:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskshare
2010-03-18 05:40 . 2010-03-18 05:40 -------- d-----w- c:\windows\XSxS
2010-03-18 05:40 . 2010-03-18 05:40 -------- d-----w- c:\program files\Xenocode
2010-03-18 05:40 . 2010-03-18 05:40 -------- d-----w- c:\documents and settings\Brian\Local Settings\Application Data\Xenocode
2010-03-18 05:39 . 2010-03-18 05:39 -------- d-----w- c:\program files\Common Files\DeskShare Shared
2010-03-18 05:39 . 2010-03-18 05:39 -------- d-----w- c:\program files\Deskshare
2010-03-18 05:38 . 2010-03-18 05:39 -------- d-----w- c:\windows\speech
2010-03-18 05:38 . 2010-03-18 05:38 -------- d-----w- c:\program files\ATTNaturalVoices
2010-03-17 09:29 . 2010-03-17 09:34 -------- d-----w- c:\program files\BBLACK
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-14 20:33 . 2009-03-16 17:33 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-14 20:21 . 2008-08-20 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-04-14 19:06 . 2009-12-12 19:51 -------- d-----w- c:\program files\QuickTime
2010-04-14 19:03 . 2010-03-06 19:54 -------- d-----w- c:\program files\iTunes
2010-04-14 10:02 . 2007-12-20 09:47 56 --sh--r- c:\windows\system32\0E64EFB052.sys
2010-04-14 10:02 . 2007-12-20 09:47 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-04-14 00:40 . 2007-12-06 23:56 -------- d-----w- c:\program files\dl_Cats
2010-04-13 19:56 . 2007-10-30 21:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-13 05:29 . 2004-08-10 12:00 36352 ----a-w- c:\windows\system32\drivers\disk.sys
2010-04-13 00:34 . 2004-08-10 12:00 96512 ------w- c:\windows\system32\drivers\atapi.sys
2010-04-12 20:21 . 2010-03-16 08:00 -------- d-----w- c:\program files\Amorous Professor Cherry
2010-04-12 20:20 . 2010-03-16 08:34 -------- d-----w- c:\program files\Yin-Yang
2010-04-11 03:45 . 2008-01-05 21:26 -------- d-----w- c:\program files\Common Files\Apple
2010-04-09 06:01 . 2007-12-07 00:44 50776 ----a-w- c:\documents and settings\Brian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-09 06:00 . 2008-03-03 19:41 -------- d-----w- c:\program files\Windows Live
2010-04-09 05:59 . 2007-12-10 01:52 -------- d-----w- c:\program files\Windows Live Toolbar
2010-04-08 15:50 . 2008-08-20 00:19 -------- d-----w- c:\program files\AVG
2010-04-07 21:55 . 2009-06-25 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-04-06 23:50 . 2010-04-06 23:50 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-04-06 23:50 . 2010-04-06 23:50 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-04-06 22:53 . 2008-12-15 17:17 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-06 22:43 . 2008-03-05 17:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-06 02:05 . 2007-10-30 20:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-06 01:19 . 2009-01-03 20:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-06 01:19 . 2009-01-15 06:40 5918776 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-05 09:52 . 2008-11-11 22:35 1 ----a-w- c:\documents and settings\Brian\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-30 07:46 . 2009-01-03 20:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 07:45 . 2009-01-03 20:22 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 07:08 . 2008-02-07 18:42 -------- d-----w- c:\documents and settings\Brian\Application Data\Jasc Software Inc
2010-03-18 22:15 . 2008-03-25 03:09 -------- d-----w- c:\program files\CCleaner
2010-03-18 22:01 . 2008-05-22 16:37 -------- d-----w- c:\documents and settings\Brian\Application Data\Uniblue
2010-03-18 20:43 . 2009-01-10 08:32 -------- d-----w- c:\program files\VideoLAN
2010-03-18 06:25 . 2008-04-23 18:40 2000000 ----atw- c:\windows\system32\HJSMEM.DAT
2010-03-18 05:55 . 2009-09-06 23:53 -------- d-----w- c:\program files\Safari
2010-03-16 09:59 . 2010-03-16 09:59 29926 ----a-r- c:\documents and settings\Brian\Application Data\Microsoft\Installer\{394BE3D9-7F57-4638-A8D1-1D88671913B7}\_18be6784.exe
2010-03-16 09:59 . 2010-03-16 09:59 29422 ----a-r- c:\documents and settings\Brian\Application Data\Microsoft\Installer\{394BE3D9-7F57-4638-A8D1-1D88671913B7}\_294823.exe
2010-03-16 07:58 . 2010-03-16 07:36 -------- d-----w- c:\documents and settings\Brian\Application Data\DAEMON Tools Lite
2010-03-16 07:37 . 2010-03-16 07:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-16 07:36 . 2010-03-16 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-11 10:03 . 2008-10-19 07:58 -------- d-----w- c:\program files\ffdshow
2010-03-11 10:03 . 2008-05-22 16:19 -------- d-----w- c:\program files\Free Offers from Freeze.com
2010-03-10 21:19 . 2007-12-07 05:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SupportSoft
2010-03-10 06:15 . 2004-08-10 12:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-05 11:47 . 2008-10-10 19:00 -------- d-----w- c:\documents and settings\Brian\Application Data\Move Networks
2010-03-04 11:45 . 2007-12-09 20:35 -------- d-----w- c:\program files\DivX
2010-03-04 11:43 . 2009-10-27 02:16 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-04 11:00 . 2010-03-04 11:00 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-02 05:33 . 2009-06-23 04:32 315736 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-03-02 05:33 . 2009-06-23 04:32 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2010-03-02 05:33 . 2009-06-23 04:32 173408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-03-02 05:33 . 2009-06-02 04:33 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-03-02 05:33 . 2009-06-23 04:32 350544 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-03-02 05:33 . 2009-06-23 04:32 303456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-03-02 05:33 . 2009-06-23 04:32 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-03-02 05:33 . 2009-06-02 04:33 89952 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-03-02 05:33 . 2009-06-02 04:32 254832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-03-02 05:32 . 2009-06-23 04:32 671592 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-03-02 05:32 . 2009-06-02 04:32 45408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-03-02 05:32 . 2009-09-29 04:32 3701760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-03-02 05:32 . 2009-06-23 04:32 566648 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-03-02 05:32 . 2009-06-23 04:32 567144 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-03-02 05:32 . 2009-06-23 04:32 2357064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-03-02 05:32 . 2009-06-23 04:32 524632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-03-02 05:32 . 2009-06-23 04:32 1029456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-03-01 05:41 . 2010-03-01 05:41 -------- d-----w- c:\program files\NaturalSoft
2010-02-25 06:24 . 2004-08-10 12:00 916480 ------w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-10 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 13:45 . 2010-02-22 22:10 7 ----a-w- c:\windows\sbacknt.bin
2010-02-23 06:28 . 2010-02-23 05:58 -------- d-----w- c:\documents and settings\Brian\Application Data\Toolbar4
2010-02-23 05:40 . 2010-02-23 05:40 -------- d-----w- c:\program files\Conduit
2010-02-23 05:40 . 2010-02-23 05:40 -------- d-----w- c:\program files\Online_Sharing
2010-02-17 00:11 . 2007-10-30 21:09 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-16 14:08 . 2004-08-10 12:00 2146304 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 18:46 . 2010-02-12 18:46 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-02-12 18:46 . 2010-02-12 18:46 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-02-12 04:33 . 2004-08-10 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-10 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-04 17:01 . 2010-03-29 09:38 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-02-04 17:01 . 2010-03-29 09:38 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-02-04 17:01 . 2010-03-29 09:38 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-02-04 17:01 . 2010-03-29 09:38 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-01-27 08:08 . 2008-10-19 07:58 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 05:38 . 2010-01-27 05:38 348160 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4f12d232-n\msvcr71.dll
2010-01-27 05:38 . 2010-01-27 05:38 61440 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-126fe1bb-n\decora-sse.dll
2010-01-27 05:38 . 2010-01-27 05:38 503808 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4f12d232-n\msvcp71.dll
2010-01-27 05:38 . 2010-01-27 05:38 499712 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4f12d232-n\jmc.dll
2010-01-27 05:38 . 2010-01-27 05:38 12800 ----a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-126fe1bb-n\decora-d3d.dll
.
Code:
<pre>
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\iTunes\iTunesHelper .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer .exe
c:\windows\ime\imjp8_1\IMJPMIG .exe
c:\windows\ime\imkr6_1\IMEKRMIG .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-04-13_19.49.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-15 21:45 . 2010-04-15 21:45 16384 c:\windows\Temp\Perflib_Perfdata_78c.dat
+ 2010-01-13 14:01 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
+ 2004-08-10 12:00 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
+ 2009-12-22 03:09 . 2009-12-22 03:09 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\ViewerPS.dll
+ 2009-12-22 08:57 . 2009-12-22 08:57 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\reader_sl.exe
+ 2009-12-22 03:02 . 2009-12-22 03:02 79280 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\PDFPrevHndlr.dll
+ 2009-12-22 06:21 . 2009-12-22 06:21 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\eula.exe
+ 2009-12-11 22:57 . 2009-12-11 22:57 70584 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\adobeextractfiles.dll
+ 2009-12-22 06:37 . 2009-12-22 06:37 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrotextextractor.exe
+ 2009-12-22 01:39 . 2009-12-22 01:39 15288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32Info.exe
+ 2009-12-22 01:27 . 2009-12-22 01:27 75200 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acroiehelpershim.dll
+ 2009-12-22 01:27 . 2009-12-22 01:27 61888 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroIEHelper.dll
+ 2004-08-10 12:00 . 2009-12-24 06:59 177664 c:\windows\system32\wintrust.dll
+ 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
- 2008-05-09 10:53 . 2009-03-08 11:33 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2008-05-09 10:53 . 2010-03-10 06:15 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2008-06-20 11:08 . 2010-02-11 12:02 226880 c:\windows\system32\dllcache\tcpip6.sys
+ 2008-11-11 19:24 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys
+ 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2009-12-11 22:57 . 2009-12-11 22:57 326056 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\readerupdater.exe
+ 2009-12-22 01:35 . 2009-12-22 01:35 378264 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\pdfshell.dll
+ 2009-12-22 03:05 . 2009-12-22 03:05 116168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\PDFPrevHndlrShim.exe
+ 2009-12-22 01:34 . 2009-12-22 01:34 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\nppdf32.dll
+ 2009-11-10 02:18 . 2009-11-10 02:18 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\JP2KLib.dll
+ 2009-12-22 03:02 . 2009-12-22 03:02 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AdobeCollabSync.exe
+ 2009-12-11 22:57 . 2009-12-11 22:57 948672 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\adobearm.exe
+ 2009-12-22 01:43 . 2009-12-22 01:43 120240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRdIF.dll
+ 2009-12-22 08:57 . 2009-12-22 08:57 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.exe
+ 2009-12-22 01:15 . 2009-12-22 01:15 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroPDF.dll
+ 2009-12-22 02:32 . 2009-12-22 02:32 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrobroker.exe
+ 2009-12-11 22:57 . 2009-12-11 22:57 326056 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrobatupdater.exe
+ 2009-12-22 02:15 . 2009-12-22 02:15 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\a3dutility.exe
+ 2010-04-15 08:49 . 2009-03-08 11:33 420352 c:\windows\ie8updates\KB981332-IE8\vbscript.dll
+ 2010-04-15 08:49 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB981332-IE8\spuninst\updspapi.dll
+ 2010-04-15 08:49 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB981332-IE8\spuninst\spuninst.exe
+ 2008-11-11 19:24 . 2010-02-24 13:11 455680 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-10-15 07:53 . 2010-02-17 16:10 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-10-15 07:53 . 2010-02-16 13:25 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 07:53 . 2010-02-16 13:25 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-15 07:53 . 2010-02-16 14:08 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2010-04-14 20:33 . 2010-04-14 20:33 3940352 c:\windows\Installer\a527e.msi
+ 2009-12-22 01:29 . 2009-12-22 01:29 2409880 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\rt3d.dll
+ 2009-10-28 03:34 . 2009-10-28 03:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
+ 2009-12-22 06:31 . 2009-12-22 06:31 5713920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AGM.dll
+ 2008-10-15 07:53 . 2010-02-17 16:10 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-15 07:53 . 2010-02-16 13:25 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-15 07:53 . 2010-02-16 13:25 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 07:53 . 2010-02-16 14:08 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2007-12-06 21:48 . 2010-04-06 17:52 31971272 c:\windows\system32\MRT.exe
+ 2010-04-04 06:54 . 2010-04-04 06:54 11850240 c:\windows\Installer\a5326.msp
+ 2009-12-22 06:21 . 2009-12-22 06:21 20436408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8567a644-e36c-470c-86cf-9c5b4f37db81}]
2009-12-31 19:53 2349080 ----a-w- c:\program files\Online_Sharing\tbOnli.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 21:03 1230080 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{8567a644-e36c-470c-86cf-9c5b4f37db81}"= "c:\program files\Online_Sharing\tbOnli.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{8567a644-e36c-470c-86cf-9c5b4f37db81}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8567A644-E36C-470C-86CF-9C5B4F37DB81}"= "c:\program files\Online_Sharing\tbOnli.dll" [2009-12-31 2349080]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{8567a644-e36c-470c-86cf-9c5b4f37db81}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr .exe" [N/A]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [N/A]
"LxrAutorun"="c:\documents and settings\Brian\Local Settings\Application Data\Lexar Media\LxrAutorun.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QUICKCARE"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2006-11-08 192512]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2001-08-23 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [N/A]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
c:\documents and settings\Brian\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2009-6-24 803176]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor Ver.4.5.lnk - c:\program files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe [2010-4-5 406896]
SMART Board Tools.lnk - c:\program files\SMART Technologies Inc\SMART Board Software\SMARTBoardTools.exe [2007-11-2 4519176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 19:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2006-02-10 05:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlccmon.exe]
2005-07-22 19:03 425984 ----a-w- c:\program files\Dell Photo AIO Printer 924\dlccmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 21:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-06-16 14:03 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-06-16 14:03 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
c:\program files\iTunes\iTunesHelper.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
c:\program files\Windows Live\Messenger\msnmsgr.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QUICKCARE]
2006-11-08 04:07 192512 ----a-w- c:\program files\Qwest\QuickCare\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
c:\program files\QuickTime\qttask.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-23 01:20 339968 ----a-w- c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files\Common Files\Real\Update_OB\realsched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
2008-08-28 17:18 3660848 ----a-w- c:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"SPF4"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"dlcc_device"=3 (0x3)
"BOCore"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Guild Wars\\Gw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/31/2009 10:32 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/3/2009 12:41 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/3/2009 12:41 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/3/2009 12:41 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/3/2009 12:41 PM 297752]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [9/24/2009 8:15 PM 72672]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\program files\VMLaunch\BuddyVM.sys --> c:\program files\VMLaunch\BuddyVM.sys [?]
S2 gupdate1ca56ab8e11c5ea;Google Update Service (gupdate1ca56ab8e11c5ea);c:\program files\Google\Update\GoogleUpdate.exe [10/26/2009 7:16 PM 133104]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [10/30/2007 12:56 PM 20160]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 2:34 PM 1029456]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [6/17/2009 5:20 AM 12648]
S3 SMART Web Server;SMART Web Server;c:\program files\SMART Technologies Inc\SMART Board Software\WebServer.exe [11/2/2007 6:48 AM 767240]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/16/2010 12:37 AM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-04-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 05:32]
2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
2010-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 02:16]
2010-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 02:16]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.live.com/
mStart Page = hxxp://www.bigseekpro.com/webscout/{213687C0-A8F8-4791-AD1C-94B40145C34C}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Inbox Search - tbr:iemenu
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Inbox\ctbr.dll
FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\x3ydlwy6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15153&l=dis
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Inbox\firefox\components\xcomm.dll
FF - component: c:\program files\Inbox\firefox\components\xshared.dll
FF - component: c:\program files\Inbox\firefox\components\xsupport.dll
FF - plugin: c:\documents and settings\Brian\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Brian\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-15 15:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5d,1a,f6,c6,ac,aa,3a,48,98,4a,c9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5d,1a,f6,c6,ac,aa,3a,48,98,4a,c9,\
.
Completion time: 2010-04-15 15:34:47
ComboFix-quarantined-files.txt 2010-04-15 22:34
ComboFix2.txt 2010-04-14 16:20
ComboFix3.txt 2010-04-14 08:00
ComboFix4.txt 2010-04-13 19:56
Pre-Run: 20,810,625,024 bytes free
Post-Run: 20,934,029,312 bytes free
- - End Of File - - 54025F6D09E1D8F850210427F0038D40
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3993
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/15/2010 3:02:14 PM
mbam-log-2010-04-15 (15-02-14).txt
Scan type: Quick scan
Objects scanned: 134219
Time elapsed: 8 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
DDS log to follow.