My wife's PC is obviously infected. Our first clue was that Firefox would throw up a "Untrusted Connection" warning when trying to access Gmail. Then when I tried doing a search to understand exactly what that meant, I was redirected.
I run MS's Windows Live OneCare and Avast as my security protection. Neither found the virus. After doing some searching, I found suggestions to run Malware Bytes and Combofix, which I did. Below are the Combofix logs.
I've already backed up all the individual important files (personal pics and documents) to an external HDD, and I'm just about ready for a format/reinstall. Posting here is pretty much my last ditch effort to avoid that.

But even if I still end up having to format/reinstall... What's my best way to ensure my external HDD is clean?
Thanks in advance,
--John
========================================
ComboFix 10-07-15.01 - Black 07/15/2010 20:28:34.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3053.1824 [GMT -7:00]
Running from: c:\users\Black\Downloads\ComboFix.exe
AV: Windows Live OneCare *On-access scanning enabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *enabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Windows Live OneCare *enabled* (Updated) {CC7E50BA-BA8C-4DDE-B5AC-EA53BC38D01B}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-06-16 to 2010-07-16 )))))))))))))))))))))))))))))))
.
2010-07-16 03:35 . 2010-07-16 03:35 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2010-07-16 03:35 . 2010-07-16 03:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-12 04:33 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-07-11 15:17 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-07-11 15:17 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-11 15:17 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-07-11 15:17 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-07-11 15:17 . 2010-06-28 20:32 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-07-11 15:16 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-07-11 15:16 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-07-11 15:16 . 2010-07-11 15:16 -------- d-----w- c:\programdata\Alwil Software
2010-07-11 15:16 . 2010-07-11 15:16 -------- d-----w- c:\program files\Alwil Software
2010-07-11 14:32 . 2010-07-11 14:32 -------- d-----w- c:\users\Black\AppData\Roaming\Malwarebytes
2010-07-11 14:29 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-11 14:29 . 2010-07-11 14:29 -------- d-----w- c:\programdata\Malwarebytes
2010-07-11 14:29 . 2010-07-11 14:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-11 14:29 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-11 12:45 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-07-11 12:43 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2010-07-11 12:43 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2010-07-11 12:43 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
2010-07-11 12:43 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
2010-07-11 12:43 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2010-07-11 12:43 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\winrssrv.dll
2010-07-11 12:43 . 2009-10-09 21:56 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
2010-07-11 12:43 . 2009-10-09 21:55 79872 ----a-w- c:\windows\system32\wecutil.exe
2010-07-11 12:43 . 2009-10-09 21:55 54272 ----a-w- c:\windows\system32\WsmRes.dll
2010-07-11 12:43 . 2009-10-09 21:55 146944 ----a-w- c:\windows\system32\wecsvc.dll
2010-07-11 12:43 . 2009-10-09 21:55 81408 ----a-w- c:\windows\system32\wevtfwd.dll
2010-07-11 12:43 . 2009-10-09 21:55 56320 ----a-w- c:\windows\system32\wecapi.dll
2010-07-11 12:42 . 2009-08-01 06:27 201184 ----a-w- c:\windows\system32\winrm.vbs
2010-07-11 12:42 . 2009-10-09 21:56 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2010-07-11 12:42 . 2009-10-09 21:56 241152 ----a-w- c:\windows\system32\winrscmd.dll
2010-07-11 12:42 . 2009-10-09 21:56 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2010-07-11 12:42 . 2009-10-09 21:56 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2010-07-11 12:42 . 2009-10-09 21:56 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2010-07-11 12:42 . 2009-10-09 21:55 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2010-07-11 12:35 . 2010-07-11 12:36 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-24 10:04 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-06-24 10:04 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-06-24 10:03 . 2009-11-08 17:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 10:03 . 2009-11-08 17:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 10:03 . 2009-11-08 17:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 10:03 . 2009-11-08 17:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 10:03 . 2009-11-08 17:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 21:36 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 21:36 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-22 18:10 . 2010-06-22 18:10 -------- d-----w- c:\program files\iPod
2010-06-22 18:10 . 2010-06-22 18:11 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-22 18:10 . 2010-06-22 18:11 -------- d-----w- c:\program files\iTunes
2010-06-22 18:07 . 2010-06-22 18:08 -------- d-----w- c:\program files\QuickTime
2010-06-22 18:03 . 2010-06-22 18:03 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-22 18:02 . 2010-06-22 18:02 -------- d-----w- c:\program files\Safari
2010-06-22 18:01 . 2010-06-22 18:01 71992 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-20 06:54 . 2010-06-20 06:54 50354 ----a-w- c:\users\Black\AppData\Roaming\Facebook\uninstall.exe
2010-06-20 06:53 . 2010-06-20 06:54 -------- d-----w- c:\users\Black\AppData\Roaming\Facebook
2010-06-20 06:00 . 2010-06-20 06:14 -------- d-----w- c:\users\Black\AppData\Roaming\Nikon
2010-06-20 05:51 . 2010-06-20 05:51 49152 ----a-r- c:\users\Black\AppData\Roaming\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2010-06-20 05:50 . 2010-06-20 05:50 335872 ----a-r- c:\users\Black\AppData\Roaming\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2010-06-20 05:50 . 2010-06-20 05:50 57344 ----a-r- c:\users\Black\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2010-06-20 05:48 . 2010-06-20 05:48 -------- d-----w- c:\programdata\Automator
2010-06-20 05:46 . 2010-06-20 06:00 -------- d-----w- c:\programdata\ArcSoft
2010-06-20 05:46 . 2010-06-20 05:46 -------- d-----w- c:\users\Black\AppData\Local\ArcSoft
2010-06-20 05:46 . 2010-06-20 05:46 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-06-20 05:46 . 2010-06-20 05:46 -------- d-----w- c:\program files\ArcSoft
2010-06-20 05:45 . 2010-06-20 05:46 -------- d-----w- c:\users\Black\AppData\Roaming\ArcSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-16 03:29 . 2007-12-28 03:15 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2010-07-16 03:18 . 2009-06-15 21:41 34901 ----a-w- c:\programdata\nvModes.dat
2010-07-11 14:18 . 2007-12-23 05:03 124224 ----a-w- c:\users\Black\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-11 12:45 . 2008-12-16 20:22 -------- d-----w- c:\programdata\Microsoft Help
2010-07-11 12:39 . 2008-12-16 20:27 -------- d-----w- c:\program files\Microsoft Works
2010-07-11 12:36 . 2007-12-23 06:08 -------- d-----w- c:\programdata\NVIDIA
2010-06-25 10:03 . 2008-12-16 20:25 -------- d-----w- c:\program files\Microsoft.NET
2010-06-22 18:10 . 2007-12-24 02:33 -------- d-----w- c:\program files\Common Files\Apple
2010-06-22 18:04 . 2008-02-10 04:38 -------- d-----w- c:\program files\Bonjour
2010-06-20 06:14 . 2010-06-20 05:48 20 ---h--w- c:\programdata\PKP_DLdw.DAT
2010-06-20 06:06 . 2010-06-20 05:47 20 ---h--w- c:\programdata\PKP_DLdu.DAT
2010-06-20 06:01 . 2007-12-23 07:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-20 05:51 . 2010-06-20 05:47 -------- d-----w- c:\program files\Common Files\Nikon
2010-06-20 05:49 . 2010-06-20 05:47 -------- d-----w- c:\program files\Nikon
2010-06-20 05:48 . 2010-06-20 05:47 -------- d-----w- c:\programdata\Ultima_T15
2010-06-20 05:48 . 2010-06-20 05:47 -------- d-----w- c:\programdata\EnterNHelp
2010-06-20 05:47 . 2010-06-20 05:47 -------- d-----w- c:\program files\Common Files\muvee Technologies
2010-06-20 05:47 . 2010-06-20 05:47 -------- d-----w- c:\programdata\Nikon
2010-06-20 05:47 . 2010-06-20 05:47 -------- d-----w- c:\programdata\Analog Pad
2010-06-20 05:47 . 2003-03-19 19:05 106496 ----a-w- c:\windows\system32\ATL71.DLL
2010-06-20 05:47 . 2007-12-23 05:47 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-20 05:45 . 2008-04-14 09:46 -------- d-----w- c:\program files\RivaTuner v2.08
2010-06-20 05:42 . 2009-08-12 02:50 -------- d-----w- c:\program files\World of Warcraft
2010-06-20 05:41 . 2008-10-10 04:08 -------- d-----w- c:\program files\MySpace
2010-06-20 05:40 . 2007-12-26 06:21 -------- d-----w- c:\program files\DivX
2010-06-20 05:40 . 2007-12-28 03:18 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-06-20 05:39 . 2007-12-26 07:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-20 05:39 . 2009-08-25 23:15 -------- d-----w- c:\program files\Pando Networks
2010-06-20 00:49 . 2008-04-30 14:52 -------- d-----w- c:\program files\Fizzy
2010-06-20 00:49 . 2009-05-26 01:12 -------- d-----w- c:\program files\Drum Machine
2010-06-20 00:46 . 2008-04-13 23:02 -------- d-----w- c:\program files\Steam
2010-06-20 00:44 . 2008-03-04 01:39 -------- d-----w- c:\program files\Google
2010-06-20 00:39 . 2008-12-20 06:44 36864 ----a-w- c:\programdata\Temp\{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}\PostBuild.exe
2010-06-10 10:27 . 2008-03-03 09:39 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-10 10:25 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\users\Black\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
2010-06-04 17:53 . 2010-06-04 17:53 -------- d-----w- c:\program files\MozyHome
2010-05-26 16:16 . 2010-06-09 20:37 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:25 . 2010-06-09 20:37 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-18 23:35 . 2010-05-18 23:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 23:39 . 2010-06-04 17:53 54776 ----a-w- c:\windows\system32\drivers\mozy.sys
2010-05-04 05:59 . 2010-07-11 12:46 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-07-11 12:46 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-07-11 12:46 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-07-11 12:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 13:53 . 2010-06-09 20:37 2036224 ----a-w- c:\windows\system32\win32k.sys
2010-05-01 08:30 . 2010-04-15 08:30 439816 ----a-w- c:\users\Black\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-04-24 06:16 . 2010-04-24 06:16 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-04-23 13:55 . 2010-05-25 22:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-20 03:47 . 2010-04-20 03:47 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 03:47 . 2010-04-20 03:47 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2008-05-08 01:08 . 2008-05-08 01:08 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2010-05-13 23:39 2224440 ----a-w- c:\program files\MozyHome\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2010-05-13 23:39 2224440 ----a-w- c:\program files\MozyHome\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2010-02-06 65256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-02-13 409600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-16 479232]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
MozyHome Status.lnk - c:\program files\MozyHome\mozystat.exe [2010-5-13 2407224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Forget Me Not.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Forget Me Not.lnk
backup=c:\windows\pss\Forget Me Not.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Black^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Black\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2009-08-13 23:51 177440 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2008-05-08 01:08 29744 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 23:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-07 01:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-19 05:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-07-14 20:55 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-05-08 29744]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
S2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [2010-02-06 26120]
S2 WebCamHelper;WebCamHelper;c:\progra~1\AVWEBC~1\WebCamHelper.sys [2007-07-06 2688]
.
Contents of the 'Scheduled Tasks' folder
2010-07-16 c:\windows\Tasks\User_Feed_Synchronization-{0AA2134A-412C-4F3F-8FFD-C450C432E147}.job
- c:\windows\system32\msfeedssync.exe [2010-07-11 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://music.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Black\AppData\Roaming\Mozilla\Firefox\Profiles\sddv0rg7.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NpPopup.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Black\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Aim6 - c:\program files\AIM6\aim6.exe
MSConfigStartUp-CurseClient - c:\program files\Curse\CurseClient.exe
MSConfigStartUp-MySpaceIM - c:\program files\MySpace\IM\MySpaceIM.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-Zune Launcher - c:\program files\Zune\ZuneLauncher.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-15 20:36
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-908085295-199798096-2270000034-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5f,40,e9,f2,34,e5,96,5b,2c,c8,51,9f,dd,df,fb,53,cc,a0,61,a2,7b,cf,95,
29,09,ec,3e,10,31,21,e6,83,3a,c0,53,b5,00,5a,b3,b2,b5,c1,fe,4b,11,50,a7,7f,\
"??"=hex:19,ba,59,ea,19,57,ef,1e,db,35,28,3a,74,e6,dd,04
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4860)
c:\program files\MozyHome\mozyshell.dll
c:\program files\MozyHome\LIBEAY32.dll
.
Completion time: 2010-07-15 20:39:53
ComboFix-quarantined-files.txt 2010-07-16 03:39
Pre-Run: 4,754,087,936 bytes free
Post-Run: 4,255,006,720 bytes free
- - End Of File - - 02AA93BD010FB36D879447B2674D3523