Not sure if you wanted me to copy & paste or to upload the .txt file so I did both.
.
((((((((((((((((((((((((( Files Created from 2010-11-08 to 2010-12-08 )))))))))))))))))))))))))))))))
.
2010-12-08 00:03 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F6BFF48-DB4F-4E24-8A97-E82825183199}\mpengine.dll
2010-11-21 21:52 . 2010-11-21 21:52 -------- d-----w- c:\program files\Trend Micro
2010-11-21 04:49 . 2010-11-21 04:49 -------- d-----w- c:\users\susie\AppData\Roaming\Locktime
2010-11-21 04:44 . 2010-11-21 04:44 -------- d-----w- c:\programdata\Locktime
2010-11-21 04:44 . 2010-11-21 04:44 -------- d-----w- c:\program files\NetLimiter 2 Pro
2010-11-20 06:03 . 2010-11-20 20:43 -------- d-----w- c:\program files\SoftPerfect Bandwidth Manager
2010-11-20 04:42 . 2010-11-20 04:52 -------- d-----w- C:\CCProxy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 18:41 . 2009-10-02 16:39 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-28 03:27 . 2010-09-28 03:27 356352 ----a-w- c:\windows\eSellerateEngine.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-03 2937528]
"Aim"="c:\program files\AIM\aim.exe" [2010-04-19 3972440]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-04-28 2633976]
"Google Update"="c:\users\susie\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-06-02 136176]
"Steam"="c:\program files\steam\steam.exe" [2010-11-17 1242448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"="FactoryMode" [X]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-13 178712]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-20 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-20 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-20 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"SnapfishMediaDetector"="c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe" [2007-03-02 1441792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-28 118784]
"OEM05Mon.exe"="c:\windows\OEM05Mon.exe" [2007-05-08 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]
c:\users\susie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
0oee2yt.exe [2010-7-9 43520]
6a7vpkk.exe [2010-7-10 43520]
79k0faa.exe [2010-7-13 43520]
a1pkaa1k0f.exe [2010-7-13 43520]
aavpp6kfaa7.exe [2010-7-16 43520]
dysndny1y2.exe [2010-7-12 43520]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
vpffap9k0f.exe [2010-7-10 43520]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snapfish Media Detector.lnk - c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe [2007-3-2 1441792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 29696]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-02-24 3432444]
R3 OEM05Afx;Provides a software interface to control audio effects of OEM005 camera.;c:\windows\system32\Drivers\OEM05Afx.sys [2007-06-07 141376]
R3 OEM05Vfx;Creative Camera OEM005 Video VFX Driver;c:\windows\system32\DRIVERS\OEM05Vfx.sys [2007-03-05 7424]
R3 OEM05Vid;Creative Camera OEM005 Driver;c:\windows\system32\DRIVERS\OEM05Vid.sys [2007-07-19 235616]
R3 XDva296;XDva296;c:\windows\system32\XDva296.sys [x]
S1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2010-03-16 82872]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2007-04-09 959104]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\system32\DRIVERS\livecamv.sys [2007-01-16 31616]
.
Contents of the 'Scheduled Tasks' folder
2010-12-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3028532644-920559856-4189036104-1001Core.job
- c:\users\susie\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-02 01:16]
2010-12-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3028532644-920559856-4189036104-1001UA.job
- c:\users\susie\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-02 01:16]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktopuInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:62848
IE: Add to QQ Customized Emoticons - c:\program files\Tencent\QQ\AddEmotion.htm
IE: Add to QQ Customized Panel - c:\program files\Tencent\QQ\AddPanel.htm
IE: Add to QQ Emotions - c:\program files\Tencent\QQ\AddEmotion.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send picture by MMS - c:\program files\Tencent\QQ\SendMMS.htm
IE: Send Picture with QQ MMS - c:\program files\Tencent\QQ\SendMMS.htm
IE: Upload to QQ Network Hard Disk - c:\program files\Tencent\QQ\AddToNetDisk.htm
IE: ¥ÎQQ±m«Hµo°e¸Ó¹Ï¤ù - c:\program files\Tencent\QQ\SendMMS.htm
IE: ²K¥[¨ìQQ¦Û©w¸q±ªO - c:\program files\Tencent\QQ\AddPanel.htm
IE: ²K¥[¨ìQQªí±¡ - c:\program files\Tencent\QQ\AddEmotion.htm
IE: ???QQ?? - c:\program files\Tencent\QQ\AddEmotion.htm
FF - ProfilePath - c:\users\susie\AppData\Roaming\Mozilla\Firefox\Profiles\73etj48o.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62848
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGlbNMFFUpdater.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGlbNMNetmarbleDownload.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGlbNMStarter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGlbNMSystemInformer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGlbNMWebMessengerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\susie\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-HPAdvisor - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
HKCU-Run-aslcomm - c:\windows\system32\wallmsp.exe
HKCU-Run-qscmdll - c:\windows\system32\ssmcdsw.exe
HKCU-Run-wiue32 - c:\windows\system32\oissdmmp.exe
HKCU-Run-itjdnssm - c:\windows\system32\qppsmcw.exe
HKCU-Run-kvmspls - c:\windows\system32\bchdikms.exe
HKCU-Run-prodcmmp - c:\windows\system32\ikddmch.exe
HKCU-Run-udccndw2 - c:\windows\system32\psiomcp.exe
HKCU-Run-jncontmon - c:\windows\system32\ssjitsys32.exe
HKCU-Run-ncstatsc - c:\windows\system32\lsnccq.exe
HKCU-Run-qisdrmss - c:\windows\system32\qodesnaq.exe
HKCU-Run-iejdsmm - c:\windows\system32\yhsgmmw.exe
HKCU-Run-pqezlr32 - c:\windows\system32\eyclcm.exe
HKCU-Run-fqavqqv - c:\windows\system32\a6qkqkqa.exe
HKCU-Run-afavv8 - c:\windows\system32\kak4aav5a.exe
HKCU-Run-kkffa - c:\windows\system32\kaa1k0ff.exe
HKCU-Run-fvvpff - c:\windows\system32\1pf9aav.exe
HKCU-Run-vpffa - c:\windows\system32\kf9aavp9k.exe
HKCU-Run-ffaavpp - c:\windows\system32\faavkkfvkaa.exe
HKCU-Run-pkaav1p - c:\windows\system32\5aavkkf.exe
HKCU-Run-vkkfvvp - c:\windows\system32\k1vvppka.exe
HKCU-Run-appka - c:\windows\system32\k0faav1p.exe
HKCU-Run-ppkffaa - c:\windows\system32\2ffappk.exe
HKCU-Run-yyiddi7 - c:\windows\system32\iidt1i1tnd.exe
HKCU-Run-ppkkfvv - c:\windows\system32\vkkfvkaa1k.exe
HKCU-Run-vkkfvka - c:\windows\system32\2vv1ffa.exe
HKCU-Run-ffavkaa - c:\windows\system32\pkkfvkaa1k.exe
HKCU-Run-fvvqq - c:\windows\system32\5q1faqq.exe
HKCU-Run-alaqffa - c:\windows\system32\q7lfaa7vq.exe
HKCU-Run-lffaavq - c:\windows\system32\aavlaqq1a.exe
HKCU-Run-fappkaa - c:\windows\system32\kk1vvppkaav.exe
HKCU-Run-iyyti0 - c:\windows\system32\n6idyy7tn.exe
HKCU-Run-vkkffap - c:\windows\system32\vvpf5a1pka.exe
HKCU-Run-kzzpu - c:\windows\system32\7ffzz2p.exe
HKCU-Run-zppzkfz - c:\windows\system32\uup1pkff7.exe
HKCU-Run-lffaqq - c:\windows\system32\1aqql1f.exe
HKCU-Run-faqql - c:\windows\system32\vfv9qqlf9a.exe
HKCU-Run-qqllfa - c:\windows\system32\fvvqffaav.exe
HKCU-Run-qqllf - c:\windows\system32\0vvqf9a.exe
HKCU-Run-avll1v - c:\windows\system32\lfaa7vqllf5.exe
HKCU-Run-vla0v - c:\windows\system32\aqqlaavl.exe
HKCU-Run-vvqqla - c:\windows\system32\f2vvqffaavl.exe
HKCU-Run-qqlf9a - c:\windows\system32\a38avlaqq1a.exe
HKCU-Run-vppkaa - c:\windows\system32\avppk2avk.exe
HKCU-Run-kkff6p - c:\windows\system32\pfvvppkaav.exe
HKCU-Run-kfvv1 - c:\windows\system32\fvvpf9aa.exe
HKCU-Run-favkaa1 - c:\windows\system32\vkkfvv1ffaa.exe
HKCU-Run-fvvpf9a - c:\windows\system32\2ffappk.exe
HKCU-Run-vvpf5 - c:\windows\system32\pf9aavp9k0f.exe
HKCU-Run-aavkkff - c:\windows\system32\fv5pffappkk.exe
HKCU-Run-avvpffa - c:\windows\system32\5pffapp.exe
HKCU-Run-avkaa1 - c:\windows\system32\k7favvp5fa.exe
HKCU-Run-tjjoyto - c:\windows\system32\jdd2td82.exe
HKCU-Run-aavvpff - c:\windows\system32\v7pkf9aavp.exe
HKCU-Run-kaavk0f - c:\windows\system32\v3vvpf9aavp.exe
HKCU-Run-tjjey - c:\windows\system32\jettjyyeoyj.exe
HKCU-Run-alvlgaa - c:\windows\system32\0aagaqa.exe
HKCU-Run-snccxxs - c:\windows\system32\sic1iccicsc.exe
HKCU-Run-xnns2n - c:\windows\system32\1i2snsn.exe
HKCU-Run-nncssxn - c:\windows\system32\ni6ci6xxss2.exe
HKCU-Run-ffappk2 - c:\windows\system32\vkkfvv1ffaa.exe
HKCU-Run-avkkffa - c:\windows\system32\faavkkfv.exe
HKCU-Run-kfvvp - c:\windows\system32\5p6kfaa.exe
HKCU-Run-fappk - c:\windows\system32\pkk7favv.exe
HKCU-Run-llff6q - c:\windows\system32\5lfv5q1.exe
HKCU-Run-avvqql - c:\windows\system32\lf5vqqlff6.exe
HKCU-Run-pkkfv - c:\windows\system32\avkkfvkaa1.exe
HKCU-Run-kkfvvpf - c:\windows\system32\kk7favvp5fa.exe
HKCU-Run-kkffa1 - c:\windows\system32\v1pkkfvkaa.exe
HKCU-Run-fvvppk - c:\windows\system32\avv1ffaa.exe
HKCU-Run-wrhhbb - c:\windows\system32\hwwrhhbr9.exe
HKCU-Run-hwmm1 - c:\windows\system32\bb6wrmm7hb.exe
HKCU-Run-faav1 - c:\windows\system32\a6vvpf5a1.exe
HKCU-Run-vvqf5a - c:\windows\system32\vpf5a1pka.exe
HKCU-Run-jjeezo - c:\windows\system32\7ztoo7j.exe
HKCU-Run-llggbr - c:\windows\system32\lb5w1lgww1g.exe
HKCU-Run-ggaqql1 - c:\windows\system32\1a0vvqf.exe
HKCU-Run-laqgga - c:\windows\system32\7vql98g.exe
HKCU-Run-qqllgaa - c:\windows\system32\f6qqlaavll.exe
HKCU-Run-avllgvv - c:\windows\system32\q70a0vqql1g.exe
HKCU-Run-vqql1 - c:\windows\system32\9qqlf9a.exe
HKCU-Run-aavvqff - c:\windows\system32\9a0vqql.exe
HKCU-Run-nhxxssn - c:\windows\system32\css1c0xxsh9.exe
HKCU-Run-xnccxx - c:\windows\system32\sc8sn1hccxn.exe
HKCU-Run-wwrrlbb - c:\windows\system32\6rrlb5b.exe
HKCU-Run-gwwr1l - c:\windows\system32\b2wrggwwl7.exe
HKCU-Run-gbbwwrl - c:\windows\system32\rrl5bwggwwr.exe
HKCU-Run-ssnni - c:\windows\system32\1siid1x.exe
HKCU-Run-aqffaa - c:\windows\system32\qqkaavlaqq1.exe
HKCU-Run-faqql1 - c:\windows\system32\qq1lfvvqf9.exe
HKCU-Run-kaau0p - c:\windows\system32\a0u0pkkf1.exe
HKCU-Run-iddxnni - c:\windows\system32\6i7dxss.exe
HKCU-Run-kfv5p - c:\windows\system32\vvpf9aav.exe
HKCU-Run-cssnnh - c:\windows\system32\ccxc3hxhcxx.exe
HKCU-Run-pkaavk0 - c:\windows\system32\21k0ffa.exe
HKCU-Run-faavvpk - c:\windows\system32\9aavp9k.exe
HKCU-Run-pffaavp - c:\windows\system32\kvkappkkf.exe
HKCU-Run-pffap9 - c:\windows\system32\31pkaa1.exe
HKCU-Run-vqgga0 - c:\windows\system32\6gga2ql.exe
HKCU-Run-gbq0l - c:\windows\system32\l9ggbv9q.exe
HKCU-Run-kff6p - c:\windows\system32\2av5pff.exe
HKCU-Run-appk0f - c:\windows\system32\vfvkaa1k0.exe
HKCU-Run-pkkfvv1 - c:\windows\system32\pffap9k0faa.exe
HKCU-Run-avvp5 - c:\windows\system32\faavkkfv.exe
HKCU-Run-qqkkf - c:\windows\system32\ppkkfvvpf9.exe
HKCU-Run-nniyyt1 - c:\windows\system32\tnd9yytn.exe
HKCU-Run-ppkaavk - c:\windows\system32\6aavkkf.exe
HKCU-Run-kvkaqq - c:\windows\system32\pkf9aavp9k0.exe
HKCU-Run-vfvka - c:\windows\system32\vkaa1k0f.exe
HKCU-Run-vppka - c:\windows\system32\kfvvpf9aav.exe
HKCU-Run-ppk2a - c:\windows\system32\vppk2avkk1v.exe
HKCU-Run-pkkfvka - c:\windows\system32\pkk7favv.exe
HKCU-Run-vpkkf - c:\windows\system32\pkkfvv1f.exe
HKCU-Run-appkk - c:\windows\system32\vp9k0faav.exe
HKCU-Run-pkkfv5 - c:\windows\system32\4f2avkk.exe
HKCU-Run-vpkk7 - c:\windows\system32\vpp6kfaa.exe
HKCU-Run-iidyy7 - c:\windows\system32\5yytiid.exe
HKCU-Run-ttotoii - c:\windows\system32\iiddynniid.exe
HKCU-Run-ntnddy - c:\windows\system32\dnt92d5i.exe
HKCU-Run-faavvp - c:\windows\system32\fv5pffappkk.exe
HKCU-Run-vvpkk - c:\windows\system32\p5faavpp6k.exe
HKCU-Run-kaa1k - c:\windows\system32\avvp5faav.exe
HKCU-Run-faavkk1 - c:\windows\system32\kffappkkf.exe
HKCU-Run-pkffapp - c:\windows\system32\v1pkkfvk.exe
HKCU-Run-aavpp6k - c:\windows\system32\v1pkaa1k0.exe
HKCU-Run-vvppk - c:\windows\system32\1ffaavk.exe
HKCU-Run-llfvvq - c:\windows\system32\f6qqk2avl.exe
HKCU-Run-kkfv5q - c:\windows\system32\favkaa1kkff.exe
HKCU-Run-qqkkfa - c:\windows\system32\k0faav1qkk.exe
HKCU-Run-aavpp6 - c:\windows\system32\v1pkaa1k0.exe
HKCU-Run-kffa0 - c:\windows\system32\p2ffappkkfv.exe
HKCU-Run-nddty - c:\windows\system32\y3tntdynni.exe
HKCU-Run-pkkfaa - c:\windows\system32\v3vvpf9aavp.exe
HKCU-Run-kfvvqf9 - c:\windows\system32\k0faav1qkk.exe
HKCU-Run-avvq1 - c:\windows\system32\aa7vqkkf.exe
HKCU-Run-faav1q - c:\windows\system32\5v6f5a2.exe
HKCU-Run-vpffaav - c:\windows\system32\5faavpp.exe
HKCU-Run-kffap9k - c:\windows\system32\38kfvka.exe
HKCU-Run-vpkkfvk - c:\windows\system32\aavpp6kf.exe
HKCU-Run-vvp5f - c:\windows\system32\favvp5faavp.exe
HKCU-Run-aaavvqk - c:\windows\system32\qkk1vvqq.exe
HKCU-Run-qqkfvv - c:\windows\system32\vkaqqkkfvv.exe
HKCU-Run-bbwwrgg - c:\windows\system32\rrl5bwwrll6.exe
HKCU-Run-fvkaa1k - c:\windows\system32\6kfaa7v.exe
HKCU-Run-kkffap - c:\windows\system32\k8av1pkkfvk.exe
HKCU-Run-pffa1 - c:\windows\system32\appkkfvv.exe
HKCU-Run-kkffav - c:\windows\system32\ap9k0faav1p.exe
HKCU-Run-aavp9 - c:\windows\system32\5a1pkaa.exe
HKCU-Run-avkkfv - c:\windows\system32\vkkfvkaa1k.exe
HKCU-Run-didttn - c:\windows\system32\tnndd2yt5y.exe
HKCU-Run-nntdy - c:\windows\system32\y9y1yttiiyn.exe
HKCU-Run-kfvvpf - c:\windows\system32\ppk2avkk1.exe
HKCU-Run-vvpffa - c:\windows\system32\vppkaav1pkk.exe
HKCU-Run-pkkfaav - c:\windows\system32\p6kfaa7vp.exe
HKCU-Run-akaav1p - c:\windows\system32\vvp5faav.exe
HKCU-Run-kkfaa7v - c:\windows\system32\5vpf5a1.exe
HKCU-Run-ffapp - c:\windows\system32\kfv5pffa.exe
HKCU-Run-yyydy1 - c:\windows\system32\syssiy6d.exe
HKCU-Run-lgg7b - c:\windows\system32\5lggbww.exe
HKCU-Run-wqllgw - c:\windows\system32\wqq1bbww.exe
HKCU-Run-gwwq0 - c:\windows\system32\gwwqggb1.exe
HKCU-Run-qqlbbw - c:\windows\system32\gwwqggb1.exe
HKCU-Run-ffaav - c:\windows\system32\kappkkfvvp.exe
HKCU-Run-ffaavq0 - c:\windows\system32\v1qkkfv98q.exe
HKCU-Run-vkkfvvq - c:\windows\system32\ffaq0k0faa.exe
HKCU-Run-gvvq0 - c:\windows\system32\bvvqggb1.exe
HKCU-Run-vvqql - c:\windows\system32\bvvqggb1vqq.exe
HKCU-Run-bvllgvv - c:\windows\system32\lgbbv5lggbv.exe
HKCU-Run-vllffaq - c:\windows\system32\0llfv9q.exe
HKCU-Run-ffaqq - c:\windows\system32\l7fav9qqlf.exe
HKCU-Run-avvpf9a - c:\windows\system32\5pffapp.exe
HKCU-Run-kaav1p - c:\windows\system32\2kf5a1p.exe
HKCU-Run-avkk1v - c:\windows\system32\vkappkkfvv.exe
HKCU-Run-vppk0 - c:\windows\system32\aavpp6kfaa7.exe
HKCU-Run-ppkaa - c:\windows\system32\p6kfaa7vp.exe
HKCU-Run-ppkkfaa - c:\windows\system32\ppkaav1pk.exe
HKCU-Run-yoojy - c:\windows\system32\toddyytj.exe
HKCU-Run-dttoojd - c:\windows\system32\oojd9y0to.exe
HKCU-Run-jddyyto - c:\windows\system32\jyytjj1ttoo.exe
HKCU-Run-pffaa - c:\windows\system32\p6aavkkfvv.exe
HKCU-Run-kkfvk - c:\windows\system32\vppkaav1.exe
HKCU-Run-upkkfu - c:\windows\system32\ffz5pkkf.exe
HKCU-Run-ppkkf - c:\windows\system32\pkkfz9u0pk.exe
HKCU-Run-kkfvv - c:\windows\system32\7pkf9aa.exe
HKCU-Run-vppkaa1 - c:\windows\system32\fav5pffa.exe
HKCU-Run-aavvpkk - c:\windows\system32\aavkkfvka.exe
HKCU-Run-llgaa - c:\windows\system32\l1gaavl98.exe
HKCU-Run-kaav1 - c:\windows\system32\kaav1qkkfv.exe
HKCU-Run-vqf5a - c:\windows\system32\4v2qkaa.exe
HKCU-Run-aavvqkk - c:\windows\system32\0vq0k0f.exe
HKCU-Run-ffa1p - c:\windows\system32\kf5a1pkaa1k.exe
HKCU-Run-vvpkk7 - c:\windows\system32\pkkfvv1f.exe
HKCU-Run-aavppk0 - c:\windows\system32\pkk7favv.exe
HKCU-Run-rrlbbw1 - c:\windows\system32\lb9wwrl9g0b.exe
HKCU-Run-kffa1p - c:\windows\system32\431pkaa.exe
HKCU-Run-vvpp6 - c:\windows\system32\6a7vpkk.exe
HKCU-Run-aavvq1f - c:\windows\system32\avvqf9a0vq.exe
HKCU-Run-pvvpkk7 - c:\windows\system32\fappkkfv.exe
HKCU-Run-bgqbbv - c:\windows\system32\qqvqg6vbvbl.exe
HKCU-Run-lvqll7v - c:\windows\system32\qllqa5la1v.exe
HKCU-Run-kkfaa - c:\windows\system32\6a7vpkk.exe
HKCU-Run-ytiid - c:\windows\system32\tiidtiyy1i.exe
HKCU-Run-kfaa7 - c:\windows\system32\av1pkkfv.exe
HKCU-Run-pkaavkk - c:\windows\system32\faavkkfv.exe
HKCU-Run-yyiddit - c:\windows\system32\tn1tyidtidy.exe
HKCU-Run-kffav - c:\windows\system32\f2vv1ffaavk.exe
HKCU-Run-appkaa - c:\windows\system32\fvkaa1k0ff.exe
HKCU-Run-ddiydyt - c:\windows\system32\ntd3yynni1.exe
HKCU-Run-vvqkkf - c:\windows\system32\aavkkfv98qk.exe
HKCU-Run-fqf9a - c:\windows\system32\q1qkkfv9.exe
HKCU-Run-kkeezuu - c:\windows\system32\21eezzu.exe
HKCU-Run-xssnc - c:\windows\system32\xnc0xxsh9.exe
HKCU-Run-vkkff - c:\windows\system32\k0ffap9k0.exe
HKCU-Run-faavkkf - c:\windows\system32\v1pkkfvkaa.exe
HKCU-Run-ppffap9 - c:\windows\system32\vk0ffap9k0.exe
HKCU-Run-pffap9k - c:\windows\system32\ffap9k0f.exe
HKCU-Run-fappk2a - c:\windows\system32\4f2avkk.exe
HKCU-Run-favvp5f - c:\windows\system32\21k0ffa.exe
HKCU-Run-ccxmmh - c:\windows\system32\cxx6h5c2.exe
HKCU-Run-faavk - c:\windows\system32\p6aavkkfvv.exe
HKCU-Run-hrhhcc - c:\windows\system32\mcc1m0hhcr9.exe
HKCU-Run-kfaavk - c:\windows\system32\avvp5faav.exe
HKCU-Run-kffap - c:\windows\system32\kappkkfvvp.exe
HKCU-Run-fpf9a - c:\windows\system32\fvvpf9aavp9.exe
HKCU-Run-vkaavk0 - c:\windows\system32\p6kfaa7vp.exe
HKCU-Run-vppk0f - c:\windows\system32\p2av5pff.exe
HKCU-Run-ppkf9a - c:\windows\system32\fv5pffappkk.exe
HKCU-Run-favv1 - c:\windows\system32\fvv1p2ffa.exe
HKCU-Run-pffaavk - c:\windows\system32\2kf5a1p.exe
HKCU-Run-ppkaav1 - c:\windows\system32\0aav1pk.exe
HKCU-Run-ojjdy - c:\windows\system32\o6idyy7to.exe
HKCU-Run-ggb5v - c:\windows\system32\gbbvl9ggbv.exe
HKCU-Run-ysiid1 - c:\windows\system32\6iids4n.exe
HKCU-Run-xnnsnn - c:\windows\system32\ssnns7sni0.exe
HKCU-Run-aavvp - c:\windows\system32\pffappkkf.exe
HKCU-Run-avkkf - c:\windows\system32\ffaavpp6kv.exe
HKCU-Run-kkfvvqq - c:\windows\system32\pkk7favv.exe
HKCU-Run-hhcrrm0 - c:\windows\system32\5mmhx5r.exe
HKCU-Run-hcxmcc1 - c:\windows\system32\hxmcc1m0h.exe
HKCU-Run-pfvvppk - c:\windows\system32\ppkkfvv1ffa.exe
HKCU-Run-kkff6q - c:\windows\system32\9k0faav.exe
HKCU-Run-pkkfvvp - c:\windows\system32\0vvpf9a.exe
HKCU-Run-avllf - c:\windows\system32\faavll1vvq.exe
HKCU-Run-pappk0f - c:\windows\system32\kffap9k0faa.exe
HKCU-Run-appk2 - c:\windows\system32\kk7favvp5fa.exe
HKCU-Run-vkkfv - c:\windows\system32\1kkfvvp.exe
HKCU-Run-dttiy - c:\windows\system32\3idyydt.exe
HKCU-Run-lmggbww - c:\windows\system32\ggbrrlb9wwr.exe
HKCU-Run-dttod9 - c:\windows\system32\t9oojd9y0to.exe
HKCU-Run-qffaavq - c:\windows\system32\p6aavk4fvv.exe
HKCU-Run-qkffaqq - c:\windows\system32\av5q1faqqkk.exe
HKCU-Run-didtd - c:\windows\system32\ttiy0odood.exe
HKCU-Run-avvpk - c:\windows\system32\f9aavp9k0fa.exe
HKCU-Run-tdnniy - c:\windows\system32\id1tint7d.exe
HKCU-Run-dydnyyd - c:\windows\system32\483tntn.exe
HKCU-Run-pffaav - c:\windows\system32\ppffap9k0.exe
HKCU-Run-ttytjjd - c:\windows\system32\ojddjyd6t1.exe
HKCU-Run-kkfaav - c:\windows\system32\5pffapp.exe
HKCU-Run-vqqk0 - c:\windows\system32\kfvvqf9a.exe
HKCU-Run-fav5q - c:\windows\system32\qkaa1kkffaq.exe
HKCU-Run-avvqf5 - c:\windows\system32\1qkkfv9.exe
HKCU-Run-kffaq0 - c:\windows\system32\vvqkkffa7.exe
HKCU-Run-qkkfv - c:\windows\system32\f5a2qkaa1.exe
HKCU-Run-zppkz - c:\windows\system32\kk7fzuu7pkf.exe
HKCU-Run-ufuupup - c:\windows\system32\kfuupff1.exe
HKCU-Run-fvvqqkf - c:\windows\system32\k0faav1q.exe
HKCU-Run-kkffaq0 - c:\windows\system32\vv6f5a2qka.exe
HKCU-Run-vvqffa0 - c:\windows\system32\a1kkffaq0.exe
HKCU-Run-kvkkfv - c:\windows\system32\kff6ppk2.exe
HKCU-Run-fvkaa - c:\windows\system32\fav5pffa.exe
HKCU-Run-avvpf - c:\windows\system32\vpf9aavp.exe
HKCU-Run-vvpf5a - c:\windows\system32\avkkfvka.exe
HKCU-Run-aavvpk - c:\windows\system32\fpf9aavp9k.exe
HKCU-Run-favvq1f - c:\windows\system32\k0faav1qkk.exe
HKCU-Run-avkkff - c:\windows\system32\pf9aavp9k.exe
HKCU-Run-vkapp - c:\windows\system32\1ap9k0f.exe
HKCU-Run-kfaav - c:\windows\system32\vvp5faav.exe
HKCU-Run-vvkkp - c:\windows\system32\ppfkfk76a.exe
HKCU-Run-qkkfaav - c:\windows\system32\0aav1qk.exe
HKCU-Run-vfvvp - c:\windows\system32\1pf9aav.exe
HKCU-Run-fvkkffa - c:\windows\system32\kaavkkfv.exe
HKCU-Run-vqqkaa1 - c:\windows\system32\a1pkaa1kkf.exe
HKCU-Run-avvqff - c:\windows\system32\fvkaa1kkffa.exe
HKCU-Run-nddyyt - c:\windows\system32\dtytn5dyytn.exe
HKCU-Run-fpfukk - c:\windows\system32\pp6zzu2kfu.exe
HKCU-Run-upff1p - c:\windows\system32\u0pkkf1z.exe
HKCU-Run-kffaa - c:\windows\system32\vvp5faavpp6.exe
HKCU-Run-vpf5a - c:\windows\system32\av1pkkfvkaa.exe
HKCU-Run-kkffap9 - c:\windows\system32\9kkfvka.exe
HKCU-Run-vkkfvv1 - c:\windows\system32\kffap9k0faa.exe
HKCU-Run-tnnyt5 - c:\windows\system32\dt6i6ny1.exe
HKCU-Run-yniddi - c:\windows\system32\dt6ty7nyy1d.exe
HKCU-Run-dydyttn - c:\windows\system32\tiyy1tndd.exe
HKCU-Run-ffkv1 - c:\windows\system32\ffkv1kavpff.exe
HKCU-Run-appkkfa - c:\windows\system32\0vvpf9a.exe
HKCU-Run-ffap9k - c:\windows\system32\faavpp6kf.exe
HKCU-Run-fap9k - c:\windows\system32\pkkfvvpf9.exe
HKCU-Run-wwrrm1 - c:\windows\system32\r5m1bwmm.exe
HKCU-Run-aavkk1v - c:\windows\system32\pf9aavp9k.exe
HKCU-Run-yysii - c:\windows\system32\snniyyssn.exe
HKCU-Run-dssnni - c:\windows\system32\s0nniy0s0.exe
HKCU-Run-wwqqlg - c:\windows\system32\llbbwl9g0.exe
HKCU-Run-cxxs1h - c:\windows\system32\xxs1hssx.exe
HKCU-Run-ddydydn - c:\windows\system32\dnytnnyi.exe
HKCU-Run-qkkfaa - c:\windows\system32\k0faav1qkk.exe
HKCU-Run-fappkkf - c:\windows\system32\fappkkfvvp.exe
HKCU-Run-vpf9a - c:\windows\system32\k8av1pkkfvk.exe
HKCU-Run-avppkaa - c:\windows\system32\pkkfvkaa1k.exe
HKCU-Run-uuoee - c:\windows\system32\oeujzz1uoo.exe
HKCU-Run-uuoj9e - c:\windows\system32\ujzz1uoo.exe
HKCU-Run-faavp - c:\windows\system32\kf5a1pkaa.exe
HKCU-Run-iniyidy - c:\windows\system32\td2ttyti6.exe
HKCU-Run-kaavkk1 - c:\windows\system32\kaa1k0ffap9.exe
HKCU-Run-tytnytn - c:\windows\system32\i1ynyiy1nd.exe
HKCU-Run-ddtitdd - c:\windows\system32\ddttti6ddn.exe
HKCU-Run-pkkfvv - c:\windows\system32\v1pkaa1k0.exe
HKCU-Run-ccmxrmc - c:\windows\system32\rmmrhm3r.exe
HKCU-Run-crrxx1r - c:\windows\system32\h5cxrhhx.exe
HKCU-Run-kkfvvq - c:\windows\system32\avvqffaav.exe
HKCU-Run-vqkkfv9 - c:\windows\system32\kkff6qqk2.exe
HKCU-Run-kffa2q - c:\windows\system32\av1pkkfvkaa.exe
HKCU-Run-aavvqk - c:\windows\system32\v1qkkfv98q.exe
HKCU-Run-kkffaq - c:\windows\system32\faqqkkfvvq.exe
HKCU-Run-ddyytno - c:\windows\system32\d9yytn9i0dy.exe
HKCU-Run-vppkaav - c:\windows\system32\a1k0ffap9.exe
HKCU-Run-ytiidt - c:\windows\system32\5iidt5n.exe
HKCU-Run-newsecureapp70700.exe - c:\users\susie\AppData\Roaming\BE8B3FC6258474AD6D04DC97C4A6889B\newsecureapp70700.exe
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-07 16:43
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\1e70acc0]
"imagepath"="\??\c:\windows\TEMP\BBD7.tmp"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3028532644-920559856-4189036104-1001\Software\Kingsoft\Ñ‘q\ë_Ñ‹ *2*0*0*2*\Option]
"ProfDictID"=dword:ffffffff
"UseDictionary"=dword:00000000
"CurrentCode"=dword:ffffffff
"UseSystemFont"=dword:00000000
"AutoHideBar"=dword:00000001
"DictHotkey"=dword:00030070
"TransHotkey"=dword:00020078
"InterfaceHotkey"=dword:0002007a
"RestoreEnglishHotkey"=dword:00020079
"PackageHotkey"=dword:00020077
"UseDFKC"=dword:00000000
"DFKCPath"=""
"UseUserDict"=dword:00000000
"UseChnEngMenu"=dword:00000000
"InterfaceType"=dword:00000000
"UseGameTrans"=dword:00000001
"InterfaceStyle"=dword:00000000
"ShowNavBar"=dword:00000000
"ShowTrackBar"=dword:00000000
[HKEY_USERS\S-1-5-21-3028532644-920559856-4189036104-1001\Software\Microsoft\Internet Explorer\MenuExt\ûm R0RQ*Q*hˆÅ`]
@="c:\\Program Files\\Tencent\\QQ\\AddEmotion.htm"
"contexts"=dword:00000002
[HKEY_USERS\S-1-5-21-3028532644-920559856-4189036104-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Q*Q*8nb]
"Order"=hex:08,00,00,00,02,00,00,00,10,01,00,00,01,00,00,00,02,00,00,00,7e,00,
00,00,00,00,00,00,70,00,00,00,41,75,67,4d,04,00,00,00,01,00,00,00,00,00,01,\
.
Completion time: 2010-12-07 16:48:45
ComboFix-quarantined-files.txt 2010-12-08 00:48
Pre-Run: 151,857,508,352 bytes free
Post-Run: 152,536,801,280 bytes free
- - End Of File - - 13B1E821F4E1621C6A82D57F8D827038