1) Here's my mbam log
Malwarebytes' Anti-Malware 1.41
Database version: 3172
Windows 5.1.2600 Service Pack 2
11/14/2009 8:28:15 PM
mbam-log-2009-11-14 (20-28-15).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 232496
Time elapsed: 1 hour(s), 22 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
2) Here are my SAS logs
a) My own account run in safe mode
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/15/2009 at 00:17 AM
Application Version : 4.29.1004
Core Rules Database Version : 4273
Trace Rules Database Version: 2154
Scan type : Complete Scan
Total Scan Time : 03:39:01
Memory items scanned : 221
Memory threats detected : 0
Registry items scanned : 7557
Registry threats detected : 0
File items scanned : 89667
File threats detected : 4
Adware.Tracking Cookie
C:\Documents and Settings\david\Cookies\david@sales.liveperson[2].txt
C:\Documents and Settings\david\Cookies\david@bellcan.adbureau[2].txt
C:\Documents and Settings\david\Cookies\david@atdmt[2].txt
C:\Documents and Settings\david\Cookies\david@17490713[2].txt

There was also an administrator account in safe mode which didn't have any definitions (core and trace) so I went back to safe mode with networking to download an update and ran on Quick Scan and found nothing.
c) My sister also has a user account but her account wasn't there in safe mode and it was also the first time using SAS in that account and found 100 cookies (I'll edit this post when I switch to her acccount to copy and paste the results)
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/15/2009 at 11:44 AM
Application Version : 4.29.1004
Core Rules Database Version : 4274
Trace Rules Database Version: 2154
Scan type : Complete Scan
Total Scan Time : 02:40:58
Memory items scanned : 730
Memory threats detected : 0
Registry items scanned : 7238
Registry threats detected : 0
File items scanned : 111374
File threats detected : 100
Adware.Tracking Cookie
C:\Documents and Settings\Ivy.D\Cookies\ivy@atwola[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@bluestreak[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad.ieurop[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@canadapost.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adcentriconline[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@tribalfusion[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@partner2profit[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ehg-hollywoodmedia.hitbox[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@azjmp[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.addynamix[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@viacomedycentralrl.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ehg-telecomitalia.hitbox[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@stats.oecd[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@serving-sys[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@s[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@stats.canalblog[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ehg-bestbuy.hitbox[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ehg-corusentertainment.hitbox[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@3.adbrite[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adserver.tqs[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@zedo[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@weborama[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@tacoda[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@insightexpressai[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@rocku.adbureau[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@bs.serving-sys[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@aimfar.solution.weborama[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@52773316[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@statse.webtrendslive[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@vitamine.networldmedia[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@eyewonder[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.networldmedia[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@xiti[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@trafficmp[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@casalemedia[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@questionmarket[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@atdmt[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@hitbox[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@statcounter[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adopt.euroclick[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@1072496990[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@media.adrevolver[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad.yieldmanager[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@www.clickmanage[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@masexualite[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@advertising[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@valueclick[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@workopolis.122.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@gostats[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@eas.apm.emediate[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad.flux[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@doubleclick[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@indextools[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@revsci[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@estat[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.pointroll[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.bridgetrack[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@tradedoubler[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.bleublancrouge[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@airmilesrewardprogram.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@bellcan.adbureau[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ehg-cineplex.hitbox[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@a[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adinterax[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adviva[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adecn[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adserver[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@specificclick[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@eb.adbureau[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@brightcove.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adtech[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@richmedia.yahoo[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@nielsen.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@smartadserver[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@z.blogads[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@videoegg.adbureau[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad.zanox[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@maxserving[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@stats.african-road-safari[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@fl01.ct2.comclick[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@CM[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@cgi-bin[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@server.iad.liveperson[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@f.blogads[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adbrite[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@divx.112.2o7[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@media.vlzserver[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.monster[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@mediaplex[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adopt.specificclick[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@apmebf[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ad.ntv.co[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@adserver.illicotravel[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@track.effiliation[1].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@nextstat[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@fastclick[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@banner.goldenpalacepoker[2].txt
C:\Documents and Settings\Ivy.D\Cookies\ivy@ads.vlaze[1].txt
3) My win32kdiag.exe log
Running from: C:\Documents and Settings\david\Desktop\Win32kDiag.exe
Log file at : C:\Documents and Settings\david\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
Finished!
4) Here's the log.txt
Volume in drive C has no label.
Volume Serial Number is C4FD-1983
Directory of C:\WINDOWS\$NtUninstallKB968389$
08/10/2004 05:00 AM 407,040 netlogon.dll
1 File(s) 407,040 bytes
Directory of C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e
04/13/2008 07:12 PM 181,248 scecli.dll
Directory of C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e
04/13/2008 07:12 PM 407,040 netlogon.dll
Directory of C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e
04/13/2008 07:11 PM 56,320 eventlog.dll
3 File(s) 644,608 bytes
Directory of C:\WINDOWS\system32
08/10/2004 05:00 AM 180,224 scecli.dll
Directory of C:\WINDOWS\system32
02/06/2009 01:46 PM 408,064 netlogon.dll
Directory of C:\WINDOWS\system32
08/10/2004 05:00 AM 55,808 eventlog.dll
3 File(s) 644,096 bytes
Directory of C:\WINDOWS\system32\dllcache
02/06/2009 01:46 PM 408,064 netlogon.dll
1 File(s) 408,064 bytes
Total Files Listed:
8 File(s) 2,103,808 bytes
0 Dir(s) 83,570,421,760 bytes free