heres the combofix log
ComboFix 11-06-27.01 - shane 06/27/2011 22:27:33.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2813.1789 [GMT -4:00]
Running from: c:\users\shane\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Drop Down Deals
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\users\shane\AppData\Local\{3044C1ED-EC6A-4827-8663-174047833550}
c:\users\shane\AppData\Local\{3044C1ED-EC6A-4827-8663-174047833550}\chrome\content\overlay.xul
c:\users\shane\AppData\Local\{3044C1ED-EC6A-4827-8663-174047833550}\install.rdf
c:\users\shane\AppData\Local\{90F0C07D-9B14-4607-9CA4-D0C76664074A}
c:\users\shane\AppData\Local\{90F0C07D-9B14-4607-9CA4-D0C76664074A}\chrome.manifest
c:\users\shane\AppData\Local\{90F0C07D-9B14-4607-9CA4-D0C76664074A}\chrome\content\_cfg.js
c:\users\shane\AppData\Local\{90F0C07D-9B14-4607-9CA4-D0C76664074A}\chrome\content\overlay.xul
c:\users\shane\AppData\Local\{90F0C07D-9B14-4607-9CA4-D0C76664074A}\install.rdf
c:\users\shane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic
c:\users\shane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic\Hard Drive Diagnostic.lnk
c:\users\shane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic\Uninstall Hard Drive Diagnostic.lnk
c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\extensions\{f7b58d08-7a74-48af-ba4d-d4d1b30517cc}
c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\extensions\{f7b58d08-7a74-48af-ba4d-d4d1b30517cc}\chrome.manifest
c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\extensions\{f7b58d08-7a74-48af-ba4d-d4d1b30517cc}\chrome\xulcache.jar
c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\extensions\{f7b58d08-7a74-48af-ba4d-d4d1b30517cc}\defaults\preferences\xulcache.js
c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\extensions\{f7b58d08-7a74-48af-ba4d-d4d1b30517cc}\install.rdf
c:\windows\system32\Filters
c:\windows\system32\Filters\AviSplitter.ax
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_78er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_doppelte_99er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_einfache_99er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's Heavy Compression Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's High Quality Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\CG-Animation Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-best-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-better-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-good-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\MPEG.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\pvcd.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V3.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V5.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Standard.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Ultimate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Ultra Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Very Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\dict\Czech.dic
c:\windows\system32\Filters\ffdshow\dict\dicts.txt
c:\windows\system32\Filters\ffdshow\dict\Greek.dic
c:\windows\system32\Filters\ffdshow\dict\Polski.dic
c:\windows\system32\Filters\ffdshow\ff_kernelDeint.dll
c:\windows\system32\Filters\ffdshow\ff_liba52.dll
c:\windows\system32\Filters\ffdshow\ff_libdts.dll
c:\windows\system32\Filters\ffdshow\ff_libfaad2.dll
c:\windows\system32\Filters\ffdshow\ff_libmad.dll
c:\windows\system32\Filters\ffdshow\ff_realaac.dll
c:\windows\system32\Filters\ffdshow\ff_samplerate.dll
c:\windows\system32\Filters\ffdshow\ff_theora.dll
c:\windows\system32\Filters\ffdshow\ff_tremor.dll
c:\windows\system32\Filters\ffdshow\ff_unrar.dll
c:\windows\system32\Filters\ffdshow\ff_wmv9.dll
c:\windows\system32\Filters\ffdshow\ff_x264.dll
c:\windows\system32\Filters\ffdshow\ffdshow.ax
c:\windows\system32\Filters\ffdshow\ffdshow.ax.manifest
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1028.tc
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1029.cz
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1031.de
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1033.en
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1034.es
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1036.fr
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1038.hu
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1040.it
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.ja
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.jp
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1045.pl
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1046.br
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1049.ru
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1051.sk
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1053.se
c:\windows\system32\Filters\ffdshow\languages\ffdshow.2052.sc
c:\windows\system32\Filters\ffdshow\libavcodec.dll
c:\windows\system32\Filters\ffdshow\libmpeg2_ff.dll
c:\windows\system32\Filters\ffdshow\libmplayer.dll
c:\windows\system32\Filters\ffdshow\reg\ffdshow.reg
c:\windows\system32\Filters\ffdshow\reg\reg.exe
c:\windows\system32\Filters\ffdshow\reg\rempc.reg
c:\windows\system32\Filters\ffdshow\TomsMoComp_ff.dll
c:\windows\system32\Filters\FLVSplitter.ax
c:\windows\system32\Filters\MatroskaSplitter.ax
c:\windows\system32\Filters\MP4Splitter.ax
c:\windows\system32\Filters\Quicktime.ax
c:\windows\system32\Filters\RealMediaSplitter.ax
c:\windows\system32\Filters\VSFilter.dll
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-05-28 to 2011-06-28 )))))))))))))))))))))))))))))))
.
.
2011-06-28 02:36 . 2011-06-28 02:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-23 23:17 . 2011-06-23 23:17 -------- d-----w- c:\users\Default\AppData\Roaming\IObit
2011-06-21 21:14 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-21 21:14 . 2010-10-15 13:48 1205080 ----a-w- c:\windows\system32\ntdll.dll
2011-06-21 21:14 . 2010-10-15 14:08 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-21 21:14 . 2010-10-15 14:08 3600272 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-21 21:14 . 2011-03-10 16:12 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-06-21 21:14 . 2011-03-10 16:12 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2011-06-21 21:14 . 2011-02-18 13:31 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-21 21:14 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-06-21 21:14 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-06-21 21:14 . 2011-04-21 13:16 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-21 21:13 . 2011-03-03 12:53 2040832 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 21:13 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-06-21 21:13 . 2010-12-20 15:39 563200 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-21 20:08 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-21 20:08 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-06-21 20:08 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-06-21 20:08 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-06-21 20:08 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-06-21 20:02 . 2010-12-29 17:41 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-06-21 20:00 . 2011-04-29 12:49 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-21 20:00 . 2011-04-29 12:49 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-21 19:58 . 2011-05-02 16:00 766464 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-06-21 19:58 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2011-06-21 19:58 . 2011-03-03 14:56 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-06-21 19:58 . 2011-03-03 13:01 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-06-21 19:57 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2011-06-21 19:57 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2011-06-21 19:57 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
2011-06-21 19:57 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
2011-06-21 19:55 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2011-06-21 01:17 . 2011-01-05 01:07 723456 ----a-w- c:\windows\system32\sbe.dll
2011-06-21 01:17 . 2011-01-05 01:07 605184 ----a-w- c:\windows\system32\CPFilters.dll
2011-06-21 01:17 . 2011-01-05 01:06 190976 ----a-w- c:\windows\system32\mpg2splt.ax
2011-06-21 01:17 . 2011-05-02 15:58 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-21 01:15 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2011-06-21 01:15 . 2011-04-29 12:49 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-21 01:15 . 2011-04-29 12:49 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-21 01:15 . 2011-04-29 12:49 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-21 01:15 . 2011-05-02 12:00 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-21 01:14 . 2010-12-17 16:43 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-06-21 01:14 . 2010-12-17 15:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-06-13 02:36 . 2011-06-13 02:36 -------- d-----w- c:\program files\ConduitEngine
2011-06-13 02:36 . 2011-06-13 02:36 -------- d-----w- c:\program files\Sendspace_Bar
2011-06-12 03:03 . 2011-06-12 03:03 -------- d-----w- c:\users\shane\AppData\Roaming\IObit
2011-06-12 03:03 . 2011-02-23 20:52 16184 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-06-12 03:03 . 2011-02-23 20:52 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-06-12 03:03 . 2011-06-12 03:04 -------- d-----w- C:\Smart Defrag 2
2011-06-12 02:06 . 2011-06-13 02:36 -------- d-----w- c:\users\shane\AppData\Local\Conduit
2011-06-12 02:05 . 2011-06-12 02:06 -------- d-----w- c:\users\shane\AppData\Roaming\SendSpace
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 13:11 . 2011-02-12 01:50 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 13:11 . 2011-02-12 01:50 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-24 23:14 . 2009-10-03 00:15 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-10 12:10 . 2011-01-07 03:41 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:10 . 2011-01-07 03:41 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-10 12:03 . 2011-05-12 21:51 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 12:03 . 2011-01-07 03:42 307928 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-10 12:02 . 2011-01-07 03:42 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-10 11:59 . 2011-01-07 03:42 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-10 11:59 . 2011-01-07 03:42 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-05-10 11:59 . 2011-01-07 03:42 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-31 15:53 . 2009-11-30 22:46 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}"= "c:\program files\Sendspace_Bar\prxtbSend.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 20:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}]
2011-01-17 20:54 175912 ----a-w- c:\program files\Sendspace_Bar\prxtbSend.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-16 21:22 1144712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-16 1144712]
"{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}"= "c:\program files\Sendspace_Bar\prxtbSend.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-16 1144712]
"{5570F0A0-580C-4C69-808F-8B2AAA2AA93C}"= "c:\program files\Sendspace_Bar\prxtbSend.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{5570f0a0-580c-4c69-808f-8b2aaa2aa93c}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 135680]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-02-18 160592]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-22 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-06-14 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-22 61440]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-13 6965792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-18 1451304]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-03-07 468320]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2009-03-09 55160]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-12-18 448376]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-03-23 729088]
"NDSTray.exe"="c:\program files\TOSHIBA\ConfigFree\NDSTray.exe" [2009-05-13 299008]
"cfFncEnabler.exe"="c:\program files\TOSHIBA\ConfigFree\cfFncEnabler.exe" [2009-03-24 16384]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-04-15 1318912]
"TANU"="c:\program files\TOSHIBA\TANU\TANU.exe" [2009-03-28 263560]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-03-24 1007616]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-31 30192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"MRT"="c:\windows\system32\MRT.exe" [2011-06-03 47716296]
.
c:\users\shane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-22 135664]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-31 30192]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-22 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 TipCtrl;TipCtrl;c:\users\shane\Desktop\uTIPu\TipCtrl.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\DRIVERS\rtlprot.sys [2007-04-23 25896]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-04-22 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-05-10 53592]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\RSelect\RSelSvc.exe [2009-02-19 57344]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-04-15 176128]
S2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-03-17 73728]
S3 dfmirage;dfmirage;c:\windows\system32\DRIVERS\dfmirage.sys [2008-03-26 34128]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-22 01:43]
.
2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-22 01:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2795644
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\shane\AppData\Roaming\Mozilla\Firefox\Profiles\bqlt7ree.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
FF - Ext: SeekService: {86009AEF-9162-4EBC-B698-FF71D7B6B049} - c:\program files\Mozilla Firefox\extensions\{86009AEF-9162-4EBC-B698-FF71D7B6B049}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-27 22:36
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-06-27 22:38:28
ComboFix-quarantined-files.txt 2011-06-28 02:38
.
Pre-Run: 160,581,595,136 bytes free
Post-Run: 160,523,554,816 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,11
- - End Of File - - 446D82E4EB3A4D5889BABE7CD7B0D784