OK here's my new Combofix log....
7:24 PM 11/23/2008ComboFix 08-11-22.02 - Emory 2008-11-23 18:50:09.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1083 [GMT -6:00]
Running from: c:\documents and settings\Emory\My Documents\My Music\ComboFix.exe
Command switches used :: c:\documents and settings\Emory\My Documents\CFScript.txt
* Created a new restore point
FILE ::
c:\documents and settings\Emory\My Documents\My Music\Linkin Park\Collision Course\Jay-Z & Linkin Park - Collision Course\
00-we_got_the_hottest_music_on_the_net.m3u.exe
c:\documents and settings\Emory\My Documents\My Music\Linkin Park\Collision Course\Jay-Z & Linkin Park - Collision Course\The Bonus Tracks.exe
c:\documents and settings\Emory\My Documents\My Music\Linkin Park\Jay-Z____Linkin_Park_-_Collision_Course\Jay-Z & Linkin Park - Collision Course\
00-we_got_the_hottest_music_on_the_net.m3u.exe
c:\documents and settings\Emory\My Documents\My Music\Linkin Park\Jay-Z____Linkin_Park_-_Collision_Course\Jay-Z & Linkin Park - Collision Course\The Bonus Tracks.exe
c:\windows\vpc32.INI
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\vpc32.INI
.
((((((((((((((((((((((((( Files Created from 2008-10-24 to 2008-11-24 )))))))))))))))))))))))))))))))
.
2008-11-23 07:42 . 2008-11-23 07:42 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-23 00:06 . 2008-11-23 00:10 <DIR> d-------- C:\Lop SD
2008-11-22 23:46 . 2008-11-22 23:46 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-22 23:46 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-22 23:46 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-22 17:33 . 2008-11-22 17:33 <DIR> d-------- c:\program files\Trend Micro
2008-11-21 21:39 . 2008-11-21 21:39 <DIR> d-------- c:\program files\iPod
2008-11-21 21:38 . 2008-11-21 21:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 21:36 . 2008-11-21 21:37 <DIR> d-------- c:\program files\QuickTime
2008-11-20 13:50 . 2008-11-20 13:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-11-20 13:49 . 2008-11-20 13:49 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-11-20 13:49 . 2008-11-20 13:49 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-20 13:49 . 2008-11-20 13:49 <DIR> d-------- c:\documents and settings\Emory\Application Data\SUPERAntiSpyware.com
2008-11-15 21:02 . 2008-11-23 09:13 40 --a------ c:\windows\system32\profile.dat
2008-11-15 21:01 . 2008-11-15 21:01 <DIR> d-------- c:\program files\Symantec Client Security
2008-11-15 21:01 . 2008-11-15 21:01 <DIR> d-------- c:\program files\Symantec
2008-11-15 21:01 . 2006-01-31 13:29 107,696 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-15 21:01 . 2006-01-31 13:29 87,808 --a------ c:\windows\system32\S32EVNT1.DLL
2008-11-14 19:13 . 2008-11-22 17:35 2,078,818,304 --a------ c:\windows\MEMORY.DMP
2008-11-14 07:04 . 2008-11-15 21:17 <DIR> d-------- c:\program files\SpeedFan
2008-11-14 07:04 . 2008-11-14 07:04 45 --a------ c:\windows\system32\initdebug.nfo
2008-11-13 13:07 . 2006-02-28 06:00 10,096,640 --a--c--- c:\windows\system32\dllcache\hwxcht.dll
2008-11-13 13:05 . 2006-02-28 06:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-11-13 13:05 . 2008-11-13 13:05 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-13 13:05 . 2008-11-13 13:05 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-13 13:05 . 2008-11-13 13:05 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-13 13:05 . 2008-11-13 13:05 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-13 13:05 . 2008-11-13 13:05 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-13 12:56 . 2008-11-13 13:11 <DIR> d-------- c:\windows\NV888220.TMP
2008-11-13 12:56 . 2007-10-04 17:14 136,260 --a------ c:\windows\system32\nvapps.nvb
2008-11-13 12:52 . 2006-02-28 06:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-13 12:52 . 2006-02-28 06:00 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-13 12:52 . 2006-02-28 06:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-13 12:52 . 2006-02-28 06:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-11-13 11:28 . 2008-11-13 11:28 7,680 --ahs---- c:\windows\Thumbs.db
2008-11-05 22:38 . 2008-11-05 22:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-11-04 10:30 . 2008-11-04 10:30 90,112 --a------ c:\windows\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 --a------ c:\windows\system32\QuickTime.qts
2008-11-02 22:58 . 2008-11-02 22:58 <DIR> d-------- c:\program files\Alwil Software
2008-11-01 03:56 . 2008-11-02 22:53 <DIR> d-------- C:\1d085bb8ef03dd8ff89486702831
2008-10-31 11:11 . 2008-11-17 13:59 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-10-31 11:11 . 2008-11-17 13:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-31 11:01 . 2008-10-31 11:01 <DIR> d-------- c:\program files\Safer Networking
2008-10-30 06:55 . 2008-11-02 22:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-10-29 10:31 . 2008-10-29 10:31 <DIR> d-------- c:\documents and settings\Emory\Application Data\Malwarebytes
2008-10-29 10:30 . 2008-10-29 10:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-24 13:40 . 2008-10-24 13:40 <DIR> d-------- c:\program files\Windows Sidebar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 00:47 --------- d-----w c:\program files\LimeWire
2008-11-24 00:47 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-23 13:42 --------- d-----w c:\program files\Java
2008-11-23 05:45 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-23 01:54 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-11-22 03:39 --------- d-----w c:\program files\iTunes
2008-11-22 03:36 --------- d-----w c:\program files\Common Files\Apple
2008-11-20 22:40 --------- d-----w c:\program files\Google
2008-11-16 03:01 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-14 16:14 --------- d-----w c:\documents and settings\Emory\Application Data\LimeWire
2008-11-14 13:02 --------- d-----w c:\program files\Common Files\Ahead
2008-11-13 19:12 --------- d-----w c:\program files\McAfee
2008-11-03 04:59 --------- d-----w c:\program files\ATI
2008-11-03 04:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-03 04:58 --------- d-----w c:\program files\Lavasoft
2008-11-03 04:58 --------- d-----w c:\program files\ATI Technologies
2008-11-03 04:56 --------- d-----w c:\program files\Common Files\LightScribe
2008-11-03 04:56 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-10-29 05:40 --------- d-----w c:\program files\AIM6
2008-10-24 20:05 --------- d-----w c:\documents and settings\Emory\Application Data\Nero
2008-10-24 20:02 --------- d-----w c:\program files\Common Files\Nero
2008-10-22 19:49 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-22 19:49 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-22 19:49 --------- d-----w c:\program files\Common Files\xing shared
2008-10-22 19:49 --------- d-----w c:\program files\Common Files\Real
2008-10-21 20:59 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-21 19:25 --------- d-----w c:\program files\DivX
2008-10-18 17:52 --------- d-----w c:\program files\VstPlugins
2008-10-16 22:05 --------- d-----w c:\program files\Common Files\Logishrd
2008-10-16 22:04 --------- d-----w c:\program files\Logitech
2008-10-16 22:04 --------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 09:18 --------- d-----w c:\documents and settings\Emory\Application Data\Yahoo!
2008-10-15 18:44 262,144 ----a-w C:\ntuser.dat
2008-10-06 13:57 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-10-06 07:35 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-10-05 01:32 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-10-04 23:59 --------- d-----w c:\documents and settings\Emory\Application Data\J River
2008-10-04 19:42 --------- d-----w c:\documents and settings\Emory\Application Data\COWON
2008-10-04 18:44 --------- d-----w c:\program files\Common Files\MAGIX Shared
2008-10-03 12:25 --------- d-----w c:\documents and settings\All Users\Application Data\Citrix
2008-10-03 12:20 61,224 ----a-w c:\documents and settings\Emory\GoToAssistDownloadHelper.exe
2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-24 03:09 3,331,072 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-09-24 02:18 425,984 ----a-w c:\windows\system32\ATIDEMGX.dll
2008-09-24 02:17 311,296 ----a-w c:\windows\system32\ati2dvag.dll
2008-09-24 02:09 10,772,480 ----a-w c:\windows\system32\atioglxx.dll
2008-09-24 02:07 188,416 ----a-w c:\windows\system32\atipdlxx.dll
2008-09-24 02:06 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2008-09-24 02:06 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2008-09-24 02:06 143,360 ----a-w c:\windows\system32\Oemdspif.dll
2008-09-24 02:06 143,360 ----a-w c:\windows\system32\ati2evxx.dll
2008-09-24 02:05 593,920 ----a-w c:\windows\system32\ati2sgag.exe
2008-09-24 02:04 581,632 ----a-w c:\windows\system32\ati2evxx.exe
2008-09-24 02:03 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2008-09-24 01:56 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2008-09-24 01:54 4,008,864 ----a-w c:\windows\system32\ati3duag.dll
2008-09-24 01:38 2,399,744 ----a-w c:\windows\system32\ativvaxx.dll
2008-09-24 01:24 48,640 ----a-w c:\windows\system32\amdpcom32.dll
2008-09-24 01:20 380,928 ----a-w c:\windows\system32\atikvmag.dll
2008-09-24 01:19 39,424 ----a-w c:\windows\system32\atiadlxx.dll
2008-09-24 01:18 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2008-09-24 01:18 253,952 ----a-w c:\windows\system32\atiok3x2.dll
2008-09-24 01:18 17,408 ----a-w c:\windows\system32\atitvo32.dll
2008-09-24 01:12 573,440 ----a-w c:\windows\system32\ati2cqag.dll
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-08-29 15:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-08-29 14:53 61,440 ----a-w c:\windows\system32\dnssd.dll
2007-12-27 18:14 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-10-14 20:13 1,795,305 ----a-w c:\program files\WinRAR.zip
2008-06-02 23:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008060220080603\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\1d085bb8ef03dd8ff89486702831 ----
2008-11-01 03:56 788 --ah----- c:\1d085bb8ef03dd8ff89486702831\$shtdwn$.req
2006-10-30 03:06 189828 --a------ c:\1d085bb8ef03dd8ff89486702831\baseline.dat
2006-10-30 03:05 98412 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.2052.rtf
2006-10-30 03:05 96621 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1029.rtf
2006-10-30 03:05 9092 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1041.rtf
2006-10-30 03:05 82731 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1025.rtf
2006-10-30 03:05 75991 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1037.rtf
2006-10-30 03:05 75727 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1033.rtf
2006-10-30 03:05 620040 --a------ c:\1d085bb8ef03dd8ff89486702831\DW20.EXE
2006-10-30 03:05 5208 --a------ c:\1d085bb8ef03dd8ff89486702831\logo.bmp
2006-10-30 03:05 161383 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1049.rtf
2006-10-30 03:05 133833 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1036.rtf
2006-10-30 03:05 123784 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1044.rtf
2006-10-30 03:05 123052 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.2070.rtf
2006-10-30 03:05 122956 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1045.rtf
2006-10-30 03:05 122675 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1040.rtf
2006-10-30 03:05 122440 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1031.rtf
2006-10-30 03:05 120525 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1053.rtf
2006-10-30 03:05 119869 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1043.rtf
2006-10-30 03:05 116787 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1035.rtf
2006-10-30 03:05 11670 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1042.rtf
2006-10-30 03:05 111553 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1028.rtf
2006-10-30 03:05 110614 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1032.rtf
2006-10-30 03:05 109120 --a------ c:\1d085bb8ef03dd8ff89486702831\DWINTL20.DLL
2006-10-30 03:05 108352 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1055.rtf
2006-10-30 03:05 105811 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1030.rtf
2006-10-30 03:05 105466 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1046.rtf
2006-10-30 03:05 100476 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.3082.rtf
2006-10-30 03:05 100349 --a------ c:\1d085bb8ef03dd8ff89486702831\eula.1038.rtf
2006-10-30 03:04 557056 --a------ c:\1d085bb8ef03dd8ff89486702831\vs_setup.msi
2006-10-30 02:25 99600 --a------ c:\1d085bb8ef03dd8ff89486702831\DeleteTemp.exe
2006-10-30 02:25 365320 --a------ c:\1d085bb8ef03dd8ff89486702831\setup.exe
2006-10-30 02:25 194320 --a------ c:\1d085bb8ef03dd8ff89486702831\RebootStub.exe
2006-10-30 02:25 167176 --a------ c:\1d085bb8ef03dd8ff89486702831\runmsi.exe
2006-10-30 02:19 99840 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1045.dll
2006-10-30 02:19 99328 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1046.dll
2006-10-30 02:19 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1055.dll
2006-10-30 02:19 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1053.dll
2006-10-30 02:19 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1049.dll
2006-10-30 02:19 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1044.dll
2006-10-30 02:19 90624 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.2070.dll
2006-10-30 02:19 86528 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1045.dll
2006-10-30 02:19 84480 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1046.dll
2006-10-30 02:19 83968 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1053.dll
2006-10-30 02:19 83968 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1044.dll
2006-10-30 02:19 82944 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1049.dll
2006-10-30 02:19 82432 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1055.dll
2006-10-30 02:19 30644 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1045.ini
2006-10-30 02:19 29504 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1049.ini
2006-10-30 02:19 29392 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1046.ini
2006-10-30 02:19 29386 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.2070.ini
2006-10-30 02:19 29102 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1044.ini
2006-10-30 02:19 28950 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1053.ini
2006-10-30 02:19 28826 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1055.ini
2006-10-30 02:19 101376 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.2070.dll
2006-10-30 02:18 99840 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1043.dll
2006-10-30 02:18 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1042.dll
2006-10-30 02:18 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1041.dll
2006-10-30 02:18 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1037.dll
2006-10-30 02:18 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1035.dll
2006-10-30 02:18 91648 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1036.dll
2006-10-30 02:18 90112 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.3082.dll
2006-10-30 02:18 89600 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1038.dll
2006-10-30 02:18 88064 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1040.dll
2006-10-30 02:18 87040 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1043.dll
2006-10-30 02:18 82944 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1035.dll
2006-10-30 02:18 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1042.dll
2006-10-30 02:18 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1041.dll
2006-10-30 02:18 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1037.dll
2006-10-30 02:18 29928 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1038.ini
2006-10-30 02:18 29824 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1036.ini
2006-10-30 02:18 29778 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.3082.ini
2006-10-30 02:18 29298 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1040.ini
2006-10-30 02:18 29220 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1043.ini
2006-10-30 02:18 29118 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1035.ini
2006-10-30 02:18 28094 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1037.ini
2006-10-30 02:18 27620 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1041.ini
2006-10-30 02:18 27262 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1042.ini
2006-10-30 02:18 103424 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1036.dll
2006-10-30 02:18 102400 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.3082.dll
2006-10-30 02:18 102400 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1038.dll
2006-10-30 02:18 101376 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1040.dll
2006-10-30 02:17 99840 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1030.dll
2006-10-30 02:17 99840 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1029.dll
2006-10-30 02:17 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.2052.dll
2006-10-30 02:17 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1028.dll
2006-10-30 02:17 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1025.dll
2006-10-30 02:17 94208 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1032.dll
2006-10-30 02:17 89600 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1031.dll
2006-10-30 02:17 87040 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1030.dll
2006-10-30 02:17 86016 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1029.dll
2006-10-30 02:17 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.2052.dll
2006-10-30 02:17 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1028.dll
2006-10-30 02:17 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.1025.dll
2006-10-30 02:17 30116 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1032.ini
2006-10-30 02:17 29702 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1029.ini
2006-10-30 02:17 29526 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1031.ini
2006-10-30 02:17 29492 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1030.ini
2006-10-30 02:17 28746 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.3076.ini
2006-10-30 02:17 28666 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1025.ini
2006-10-30 02:17 26568 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.2052.ini
2006-10-30 02:17 26556 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.1028.ini
2006-10-30 02:17 104448 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1032.dll
2006-10-30 02:17 102400 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.1031.dll
2006-10-29 22:20 541184 --a------ c:\1d085bb8ef03dd8ff89486702831\vsbasereqs.dll
2006-10-29 22:19 1103872 --a------ c:\1d085bb8ef03dd8ff89486702831\WapUI.dll
2006-10-29 22:18 98816 --a------ c:\1d085bb8ef03dd8ff89486702831\WapRes.dll
2006-10-29 22:18 816128 --a------ c:\1d085bb8ef03dd8ff89486702831\vsscenario.dll
2006-10-29 22:18 590848 --a------ c:\1d085bb8ef03dd8ff89486702831\vs70uimgr.dll
2006-10-29 22:17 1054720 --a------ c:\1d085bb8ef03dd8ff89486702831\gencomp.dll
2006-10-29 22:16 1139712 --a------ c:\1d085bb8ef03dd8ff89486702831\vs_setup.dll
2006-10-29 22:15 80384 --a------ c:\1d085bb8ef03dd8ff89486702831\setupres.dll
2006-10-29 22:15 220672 --a------ c:\1d085bb8ef03dd8ff89486702831\dlmgr.dll
2006-10-29 22:15 1621504 --a------ c:\1d085bb8ef03dd8ff89486702831\SITSetup.dll
2006-10-29 22:14 163328 --a------ c:\1d085bb8ef03dd8ff89486702831\HtmlLite.dll
2006-10-29 21:18 856 --a------ c:\1d085bb8ef03dd8ff89486702831\deffactory.dat
2006-10-29 21:18 28746 --a------ c:\1d085bb8ef03dd8ff89486702831\LocData.ini
2006-10-29 21:18 127482 --a------ c:\1d085bb8ef03dd8ff89486702831\setup.sdb
2006-10-29 21:18 11130 --a------ c:\1d085bb8ef03dd8ff89486702831\vs_setup.pdi
---- Directory of c:\windows\NV888220.TMP ----
2007-10-04 17:14 91094 --a------ c:\windows\NV888220.TMP\nv3d.chm
2007-10-04 17:14 60357 --a------ c:\windows\NV888220.TMP\nvmobjpn.chm
2007-10-04 17:14 59261 --a------ c:\windows\NV888220.TMP\nvmobcht.chm
2007-10-04 17:14 59225 --a------ c:\windows\NV888220.TMP\nvmobtha.chm
2007-10-04 17:14 59100 --a------ c:\windows\NV888220.TMP\nvmobell.chm
2007-10-04 17:14 59061 --a------ c:\windows\NV888220.TMP\nvmobkor.chm
2007-10-04 17:14 58607 --a------ c:\windows\NV888220.TMP\nvmobchs.chm
2007-10-04 17:14 58340 --a------ c:\windows\NV888220.TMP\nvmobheb.chm
2007-10-04 17:14 57545 --a------ c:\windows\NV888220.TMP\nvmobsky.chm
2007-10-04 17:14 57512 --a------ c:\windows\NV888220.TMP\nvmobhun.chm
2007-10-04 17:14 57450 --a------ c:\windows\NV888220.TMP\nvmobtrk.chm
2007-10-04 17:14 57387 --a------ c:\windows\NV888220.TMP\nvmobcsy.chm
2007-10-04 17:14 57380 --a------ c:\windows\NV888220.TMP\nvmobslv.chm
2007-10-04 17:14 57376 --a------ c:\windows\NV888220.TMP\nvmobplk.chm
2007-10-04 17:14 57339 --a------ c:\windows\NV888220.TMP\nvmobrus.chm
2007-10-04 17:14 57328 --a------ c:\windows\NV888220.TMP\nvmobara.chm
2007-10-04 17:14 56934 --a------ c:\windows\NV888220.TMP\nvmobfin.chm
2007-10-04 17:14 56175 --a------ c:\windows\NV888220.TMP\nvmobita.chm
2007-10-04 17:14 56087 --a------ c:\windows\NV888220.TMP\nvmobfra.chm
2007-10-04 17:14 56087 --a------ c:\windows\NV888220.TMP\nvmobdeu.chm
2007-10-04 17:14 55992 --a------ c:\windows\NV888220.TMP\nvmobesm.chm
2007-10-04 17:14 55946 --a------ c:\windows\NV888220.TMP\nvmobptb.chm
2007-10-04 17:14 55845 --a------ c:\windows\NV888220.TMP\nvmobptg.chm
2007-10-04 17:14 55693 --a------ c:\windows\NV888220.TMP\nvmobsve.chm
2007-10-04 17:14 55669 --a------ c:\windows\NV888220.TMP\nvmobesn.chm
2007-10-04 17:14 55622 --a------ c:\windows\NV888220.TMP\nvmobdan.chm
2007-10-04 17:14 55525 --a------ c:\windows\NV888220.TMP\nvmobnor.chm
2007-10-04 17:14 55475 --a------ c:\windows\NV888220.TMP\nvmobnld.chm
2007-10-04 17:14 55103 --a------ c:\windows\NV888220.TMP\nvmobeng.chm
2007-10-04 17:14 54988 --a------ c:\windows\NV888220.TMP\nvmob.chm
2007-10-04 17:14 249426 --a------ c:\windows\NV888220.TMP\nvdspjpn.chm
2007-10-04 17:14 231666 --a------ c:\windows\NV888220.TMP\nvdspkor.chm
2007-10-04 17:14 228555 --a------ c:\windows\NV888220.TMP\nvdsptha.chm
2007-10-04 17:14 220343 --a------ c:\windows\NV888220.TMP\nvdspell.chm
2007-10-04 17:14 220295 --a------ c:\windows\NV888220.TMP\nvdspsky.chm
2007-10-04 17:14 220228 --a------ c:\windows\NV888220.TMP\nvdspchs.chm
2007-10-04 17:14 216870 --a------ c:\windows\NV888220.TMP\nvdspcht.chm
2007-10-04 17:14 216226 --a------ c:\windows\NV888220.TMP\nvdspheb.chm
2007-10-04 17:14 213703 --a------ c:\windows\NV888220.TMP\nvdsptrk.chm
2007-10-04 17:14 212753 --a------ c:\windows\NV888220.TMP\nvdsphun.chm
2007-10-04 17:14 212669 --a------ c:\windows\NV888220.TMP\nvdsprus.chm
2007-10-04 17:14 211309 --a------ c:\windows\NV888220.TMP\nvdspplk.chm
2007-10-04 17:14 209976 --a------ c:\windows\NV888220.TMP\nvdspslv.chm
2007-10-04 17:14 209813 --a------ c:\windows\NV888220.TMP\nvdspcsy.chm
2007-10-04 17:14 207242 --a------ c:\windows\NV888220.TMP\nvdspara.chm
2007-10-04 17:14 206448 --a------ c:\windows\NV888220.TMP\nvdspfin.chm
2007-10-04 17:14 204359 --a------ c:\windows\NV888220.TMP\nvdspptg.chm
2007-10-04 17:14 204223 --a------ c:\windows\NV888220.TMP\nvdspita.chm
2007-10-04 17:14 202745 --a------ c:\windows\NV888220.TMP\nvdspdeu.chm
2007-10-04 17:14 200730 --a------ c:\windows\NV888220.TMP\nvdspesn.chm
2007-10-04 17:14 198623 --a------ c:\windows\NV888220.TMP\nvdspsve.chm
2007-10-04 17:14 197183 --a------ c:\windows\NV888220.TMP\nvdspdan.chm
2007-10-04 17:14 195540 --a------ c:\windows\NV888220.TMP\nvdspesm.chm
2007-10-04 17:14 195053 --a------ c:\windows\NV888220.TMP\nvdspnld.chm
2007-10-04 17:14 194897 --a------ c:\windows\NV888220.TMP\nvdspptb.chm
2007-10-04 17:14 194807 --a------ c:\windows\NV888220.TMP\nvdspfra.chm
2007-10-04 17:14 194024 --a------ c:\windows\NV888220.TMP\nvdspnor.chm
2007-10-04 17:14 182638 --a------ c:\windows\NV888220.TMP\nvdspeng.chm
2007-10-04 17:14 170201 --a------ c:\windows\NV888220.TMP\nvdsp.chm
2007-10-04 17:14 130910 --a------ c:\windows\NV888220.TMP\nvcpljpn.chm
2007-10-04 17:14 128742 --a------ c:\windows\NV888220.TMP\nvcpltha.chm
2007-10-04 17:14 128443 --a------ c:\windows\NV888220.TMP\nv3djpn.chm
2007-10-04 17:14 128314 --a------ c:\windows\NV888220.TMP\nvcplsky.chm
2007-10-04 17:14 127960 --a------ c:\windows\NV888220.TMP\nvcplhun.chm
2007-10-04 17:14 127840 --a------ c:\windows\NV888220.TMP\nvcplell.chm
2007-10-04 17:14 127752 --a------ c:\windows\NV888220.TMP\nvcplheb.chm
2007-10-04 17:14 127604 --a------ c:\windows\NV888220.TMP\nvcpltrk.chm
2007-10-04 17:14 127314 --a------ c:\windows\NV888220.TMP\nvcplkor.chm
2007-10-04 17:14 127256 --a------ c:\windows\NV888220.TMP\nvcplsve.chm
2007-10-04 17:14 127102 --a------ c:\windows\NV888220.TMP\nvcplcsy.chm
2007-10-04 17:14 127072 --a------ c:\windows\NV888220.TMP\nvcplrus.chm
2007-10-04 17:14 126954 --a------ c:\windows\NV888220.TMP\nvcplfin.chm
2007-10-04 17:14 126400 --a------ c:\windows\NV888220.TMP\nvcplita.chm
2007-10-04 17:14 126298 --a------ c:\windows\NV888220.TMP\nvcplcht.chm
2007-10-04 17:14 126198 --a------ c:\windows\NV888220.TMP\nvcplara.chm
2007-10-04 17:14 126192 --a------ c:\windows\NV888220.TMP\nvcplesm.chm
2007-10-04 17:14 125970 --a------ c:\windows\NV888220.TMP\nvcpldeu.chm
2007-10-04 17:14 125912 --a------ c:\windows\NV888220.TMP\nvcplptg.chm
2007-10-04 17:14 125810 --a------ c:\windows\NV888220.TMP\nvcplslv.chm
2007-10-04 17:14 125794 --a------ c:\windows\NV888220.TMP\nvcplchs.chm
2007-10-04 17:14 125588 --a------ c:\windows\NV888220.TMP\nvcplfra.chm
2007-10-04 17:14 125360 --a------ c:\windows\NV888220.TMP\nvcplnld.chm
2007-10-04 17:14 125116 --a------ c:\windows\NV888220.TMP\nvcplptb.chm
2007-10-04 17:14 125104 --a------ c:\windows\NV888220.TMP\nvcplplk.chm
2007-10-04 17:14 124456 --a------ c:\windows\NV888220.TMP\nvcpldan.chm
2007-10-04 17:14 124300 --a------ c:\windows\NV888220.TMP\nvcplesn.chm
2007-10-04 17:14 123726 --a------ c:\windows\NV888220.TMP\nvcplnor.chm
2007-10-04 17:14 123008 --a------ c:\windows\NV888220.TMP\nvcpleng.chm
2007-10-04 17:14 121441 --a------ c:\windows\NV888220.TMP\nvcpl.chm
2007-10-04 17:14 119327 --a------ c:\windows\NV888220.TMP\nv3dtha.chm
2007-10-04 17:14 117303 --a------ c:\windows\NV888220.TMP\nv3dkor.chm
2007-10-04 17:14 116332 --a------ c:\windows\NV888220.TMP\nv3dell.chm
2007-10-04 17:14 115403 --a------ c:\windows\NV888220.TMP\nv3dchs.chm
2007-10-04 17:14 114839 --a------ c:\windows\NV888220.TMP\nv3dcht.chm
2007-10-04 17:14 114302 --a------ c:\windows\NV888220.TMP\nv3dheb.chm
2007-10-04 17:14 113801 --a------ c:\windows\NV888220.TMP\nv3dsky.chm
2007-10-04 17:14 113031 --a------ c:\windows\NV888220.TMP\nv3dplk.chm
2007-10-04 17:14 112777 --a------ c:\windows\NV888220.TMP\nv3dtrk.chm
2007-10-04 17:14 112172 --a------ c:\windows\NV888220.TMP\nv3dara.chm
2007-10-04 17:14 111436 --a------ c:\windows\NV888220.TMP\nv3desn.chm
2007-10-04 17:14 111318 --a------ c:\windows\NV888220.TMP\nv3drus.chm
2007-10-04 17:14 111216 --a------ c:\windows\NV888220.TMP\nv3dcsy.chm
2007-10-04 17:14 111050 --a------ c:\windows\NV888220.TMP\nv3desm.chm
2007-10-04 17:14 110880 --a------ c:\windows\NV888220.TMP\nv3dhun.chm
2007-10-04 17:14 110797 --a------ c:\windows\NV888220.TMP\nv3dslv.chm
2007-10-04 17:14 108595 --a------ c:\windows\NV888220.TMP\nv3dita.chm
2007-10-04 17:14 108012 --a------ c:\windows\NV888220.TMP\nv3dfin.chm
2007-10-04 17:14 107240 --a------ c:\windows\NV888220.TMP\nv3ddeu.chm
2007-10-04 17:14 106275 --a------ c:\windows\NV888220.TMP\nv3dfra.chm
2007-10-04 17:14 105772 --a------ c:\windows\NV888220.TMP\nv3dptg.chm
2007-10-04 17:14 105423 --a------ c:\windows\NV888220.TMP\nv3dptb.chm
2007-10-04 17:14 104618 --a------ c:\windows\NV888220.TMP\nv3ddan.chm
2007-10-04 17:14 104004 --a------ c:\windows\NV888220.TMP\nv3dsve.chm
2007-10-04 17:14 103709 --a------ c:\windows\NV888220.TMP\nv3dnld.chm
2007-10-04 17:14 102668 --a------ c:\windows\NV888220.TMP\nv3dnor.chm
2007-10-04 17:14 100759 --a------ c:\windows\NV888220.TMP\nv3deng.chm
---- Directory of c:\windows\TEMP\TMP00000014EAFA47CFF9E163FF ----
c:\windows\TEMP\TMP00000014EAFA47CFF9E163FF\
((((((((((((((((((((((((((((( snapshot@2008-11-22_23.45.00.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-23 04:54:26 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-23 18:04:13 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-23 04:54:26 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-23 18:04:13 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-10 06:21:01 135,168 ----a-w c:\windows\system32\java.exe
+ 2008-11-23 13:42:35 144,792 ----a-w c:\windows\system32\java.exe
- 2008-06-10 06:21:04 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-23 13:42:35 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-06-10 07:32:34 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-23 13:42:35 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-24 00:36:18 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_1248.dat
+ 2008-11-24 00:31:54 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_76c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"Google Update"="c:\documents and settings\Emory\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-26 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-22 185872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8491008]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-02-28 44032]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-04 81920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 53408]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-03-17 124656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-23 136600]
"nwiz"="nwiz.exe" [2007-10-04 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-02-01 8699904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Daisy.5THCOMPUTER^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Daisy.5THCOMPUTER\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 10:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-02-28 06:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eligmini]
--a------ 2008-04-03 07:56 487424 c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-02 11:53 133104 c:\documents and settings\Emory\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2006-07-07 17:15 600896 c:\program files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
--a------ 2006-07-07 17:14 576320 c:\program files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2008-06-09 09:16 2363392 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-07-25 15:02 563984 c:\program files\Common Files\Logishrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-07-25 15:06 2027792 c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\masqform.exe]
--a------ 2005-07-04 09:50 643072 c:\program files\PureEdge\Viewer 6.5\masqform.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Backup]
--a------ 2008-07-10 14:42 5129504 c:\program files\McAfee\MBK\McAfeeDataBackup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
--a------ 2008-07-11 17:48 641208 c:\program files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-02-01 14:32 8699904 c:\program files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-10-04 17:14 8491008 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-10-04 17:14 81920 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
--a------ 2008-10-07 09:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-08-01 14:23 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-09-26 15:04 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-22 13:49 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 18:20 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
--a------ 2008-10-07 09:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 2005-05-03 04:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-09-21 03:10 55824 c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-10-04 17:14 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2006-09-12 02:58 16264192 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-ra------ 2006-05-16 04:04 2879488 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 3"=2 (0x2)
"gusvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\GameHouse\\TextTwist\\TextTwist.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Destiny\\RadioDestiny Broadcaster\\RadioDestiny Broadcaster.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ubisoft\\Heroes of Might and Magic V - Tribes of the East\\bin\\H5_Game.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
S0 Spssys;Toshiba SPS Service;c:\windows\system32\drivers\spssys.sys []
S3 EWAVE;EWAVE;\??\c:\windows\system32\drivers\ew.sys [2008-02-02 1693344]
S3 FILESPY;FILESPY;\??\c:\windows\system32\drivers\FILESPY.sys [2008-02-02 26992]
S3 GP2MPM;GP2MPM;\??\c:\windows\system32\drivers\GP2MPM.SYS [2008-02-02 37600]
S3 NSTATION;NSTATION;\??\c:\windows\system32\drivers\nstation.sys [2008-02-02 19808]
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;c:\windows\system32\Drivers\tascusb2.sys [2008-02-02 396192]
S3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;c:\windows\system32\drivers\tscusb2m.sys [2008-02-02 10752]
S3 TASCAM_US144_WDM;TASCAM US-144 WDM;c:\windows\system32\drivers\tscusb2a.sys [2008-02-02 19904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-09-02 11:53]
2008-11-23 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Emory\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 11:53]
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]
2008-11-12 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]
2008-11-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2008-11-24 c:\windows\Tasks\User_Feed_Synchronization-{13EF8C67-315B-44CD-AF7A-29F1060B482C}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 17:36]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-23 18:54:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\rsaenh.dll
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\msprivs.dll
c:\windows\system32\rsaenh.dll
.
Completion time: 2008-11-23 18:56:06
ComboFix-quarantined-files.txt 2008-11-24 00:55:40
ComboFix2.txt 2008-11-23 05:45:34
Pre-Run: 286,640,705,536 bytes free
Post-Run: 286,726,991,872 bytes free
604 --- E O F --- 2008-11-12 06:17:16
BTW, I left the comp for about 15 mins. and it froze again..... Thanks.
Peace.
E