I'm assuming you wanted me to post the log? lol. If not, there's no har in doing so I suppose.
ComboFix 11-05-18.04 - Aaron 05/23/2011 12:07:38.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.531 [GMT -7:00]
Running from: c:\documents and settings\Aaron\Desktop\ComboFix_N.exe
Command switches used :: c:\documents and settings\Aaron\Desktop\CFScript.txt
.
file zipped: C:\gf.bin
file zipped: C:\ToDel
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\gf.bin
C:\ToDel
.
.
((((((((((((((((((((((((( Files Created from 2011-04-23 to 2011-05-23 )))))))))))))))))))))))))))))))
.
.
2011-05-22 09:08 . 2011-05-22 09:08 -------- d-----w- c:\program files\Common Files\Adobe
2011-05-22 09:07 . 2011-05-22 09:07 -------- d-----w- c:\program files\Common Files\Java
2011-05-21 10:09 . 2011-05-21 10:09 -------- d-----w- c:\documents and settings\Aaron\Application Data\Malwarebytes
2011-05-21 10:08 . 2011-05-21 10:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-21 10:08 . 2010-12-21 01:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-21 10:08 . 2011-05-21 10:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-21 10:08 . 2010-12-21 01:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-18 11:17 . 2011-05-18 11:17 -------- d-----w- c:\program files\ERUNT
2011-05-15 12:45 . 2011-05-15 12:45 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-10 03:46 . 2011-05-10 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2011-05-09 01:20 . 2011-05-09 01:20 -------- d-----w- c:\documents and settings\Aaron\Local Settings\Application Data\LAG
2011-05-09 01:20 . 2011-05-09 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\LAG
2011-05-09 01:19 . 2011-05-09 01:19 -------- d-----w- c:\program files\AGEIA Technologies
2011-05-09 01:19 . 2011-05-09 01:19 -------- d-----w- c:\windows\system32\AGEIA
2011-05-08 07:52 . 2011-05-08 07:52 -------- d-----w- c:\program files\NCH Swift Sound
2011-05-08 07:44 . 2011-05-08 07:44 -------- d-----w- c:\program files\MSBuild
2011-05-08 07:43 . 2011-05-08 07:43 -------- d-----w- c:\windows\system32\XPSViewer
2011-05-08 07:43 . 2011-05-08 07:43 -------- d-----w- c:\program files\Reference Assemblies
2011-05-08 07:43 . 2007-03-23 03:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-05-08 07:42 . 2006-06-29 20:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-04-30 23:56 . 2011-05-04 12:50 -------- d-----w- c:\program files\Diablo II
2011-04-30 22:42 . 2011-04-30 23:53 -------- d-----w- c:\program files\D2-1.12A-enUS
2011-04-30 22:24 . 2011-04-30 22:40 -------- d-----w- c:\program files\D2LOD-1.12A-enUS
2011-04-30 21:24 . 2011-04-30 21:24 -------- d-----w- c:\documents and settings\Aaron\Local Settings\Application Data\Blizzard Entertainment
2011-04-30 18:49 . 2011-05-04 22:24 -------- d-----w- c:\program files\World of Warcraft
2011-04-30 11:38 . 2011-04-30 11:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2011-04-30 11:37 . 2011-04-30 11:37 -------- d-----w- c:\program files\World of Warcraft Installer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-22 09:06 . 2010-10-22 10:44 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-22 09:06 . 2010-10-22 10:44 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-08 11:28 . 2011-04-08 11:28 41872 ----a-w- c:\windows\system32\xfcodec.dll
2011-03-07 05:33 . 2010-10-14 20:38 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 12:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-04 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-30 11:55 . 2011-04-13 07:46 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-19_16.39.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-23 19:15 . 2011-05-23 19:15 16384 c:\windows\temp\Perflib_Perfdata_730.dat
+ 2010-11-10 19:49 . 2010-11-10 19:49 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\ViewerPS.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\reader_sl.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 84896 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\PDFPrevHndlr.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\eula.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acrotextextractor.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32Info.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 62376 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acroiehelpershim.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroIEHelper.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\Acrofx32.dll
+ 2011-05-22 09:06 . 2011-05-22 09:06 157472 c:\windows\system32\javaws.exe
- 2010-10-22 10:44 . 2011-02-03 04:40 157472 c:\windows\system32\javaws.exe
+ 2011-05-22 09:06 . 2011-05-22 09:06 145184 c:\windows\system32\javaw.exe
- 2010-10-22 10:44 . 2011-02-03 04:40 145184 c:\windows\system32\javaw.exe
- 2010-10-22 10:44 . 2011-02-03 04:40 145184 c:\windows\system32\java.exe
+ 2011-05-22 09:06 . 2011-05-22 09:06 145184 c:\windows\system32\java.exe
+ 2011-05-22 09:07 . 2011-05-22 09:07 180224 c:\windows\Installer\dd1cc2f.msi
+ 2011-05-22 09:06 . 2011-05-22 09:06 677376 c:\windows\Installer\dd1cc1f.msi
+ 2010-11-10 19:49 . 2010-11-10 19:49 390552 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\pdfshell.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 101288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\PDFPrevHndlrShim.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 135568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\nppdf32.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 681872 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\JP2KLib.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AiodLite.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 702352 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroPDF.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 294808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acrobroker.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\a3dutils.dll
+ 2011-05-22 09:16 . 2011-05-22 09:16 319488 c:\windows\ERDNT\5-22-2011\Users\00000002\UsrClass.dat
+ 2011-05-22 09:16 . 2005-10-20 19:02 163328 c:\windows\ERDNT\5-22-2011\ERDNT.EXE
+ 2011-05-22 09:09 . 2011-05-22 09:09 2283008 c:\windows\Installer\dd1cde4.msi
+ 2010-11-10 19:49 . 2010-11-10 19:49 2207632 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\rt3d.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 6222744 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\authplay.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 5503368 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AGM.dll
+ 2010-11-10 19:49 . 2010-11-10 19:49 1216416 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AdobeCollabSync.exe
+ 2010-11-10 19:49 . 2010-11-10 19:49 1289624 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32.exe
+ 2011-05-22 09:16 . 2011-05-22 09:16 6856704 c:\windows\ERDNT\5-22-2011\Users\00000001\NTUSER.DAT
+ 2011-01-30 20:44 . 2011-01-30 20:44 12425728 c:\windows\Installer\dd1cde5.msp
+ 2010-11-10 19:49 . 2010-11-10 19:49 23724952 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-12-18 395640]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-01-31 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-26 98304]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 718688]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WPN311 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WPN311 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WPN311 Smart Wizard.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 19:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-10-30 13:01 136176 ----atw- c:\documents and settings\Aaron\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2010-12-06 16:31 1910152 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-09 13:45 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-12-18 12:36 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2009-06-27 00:21 757248 ----a-w- c:\windows\vVX3000.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-01-31 00:46 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Hamachi2Svc"=2 (0x2)
"osppsvc"=3 (0x3)
"ose"=3 (0x3)
"gupdate"=2 (0x2)
"Bonjour Service"=2 (0x2)
"ACS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Documents and Settings\\Aaron\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\softnyxGame\\GunboundIS\\GunBound.gme"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\softnyxGame\\GunboundIS\\NyxLauncher.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\BYOND\\bin\\byond.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\guild wars\\Gw.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\lead and gold gangs of the wild west\\lag_win32_public_dev.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\audiosurf\\engine\\QuestViewer.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58357:TCP"= 58357:TCP

ando Media Booster
"58357:UDP"= 58357:UDP

ando Media Booster
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
.
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2/28/2010 3:33 AM 821664]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [4/24/2010 2:10 AM 483688]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [12/2/2009 11:23 PM 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [12/2/2009 11:23 PM 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [12/2/2009 11:23 PM 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [12/2/2009 11:23 PM 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [4/24/2010 2:10 AM 209768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/26/2010 7:52 AM 136176]
S3 apf001;apf001;c:\program files\softnyxGame\GunboundIS\apf001.sys [1/16/2011 8:39 PM 10872]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/26/2010 7:52 AM 136176]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [12/6/2010 9:31 AM 1238408]
S4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 10:37 PM 4640000]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\debutShakeIcon.job
- c:\program files\NCH Software\Debut\debut.exe [2011-04-18 22:08]
.
2011-05-13 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2011-05-08 07:52]
.
2011-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-26 14:52]
.
2011-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-26 14:52]
.
2011-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-2052111302-725345543-1004Core.job
- c:\documents and settings\Aaron\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-30 13:01]
.
2011-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-2052111302-725345543-1004UA.job
- c:\documents and settings\Aaron\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-30 13:01]
.
2011-04-28 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2011-04-18 22:09]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
TCP: {F9A2A8D7-6BD0-4AA3-9882-889B95A8B74A} = 8.8.8.8,8.8.4.4
TCP: {FE9F6D91-2DCB-44E7-A1D8-F2397800F99D} = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\documents and settings\Aaron\Application Data\Mozilla\Firefox\Profiles\cp50h5s6.default\
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-23 12:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-448539723-2052111302-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2055B3A4-F8EE-CD83-8B35-A97175B8709E}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaebejlgpklckcciph"=hex:66,61,63,70,6b,6b,61,6f,67,6a,63,6b,00,69
"fafpihkhjpib"=hex:62,61,65,6f,00,fb
"kacpklmjbodgdemckmjpkp"=hex:62,61,68,6f,00,fb
"iakopgaemaeaeilpnl"=hex:62,61,68,6f,00,fb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(548)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(1868)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-05-23 12:19:22 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-23 19:19
ComboFix2.txt 2011-05-19 16:42
.
Pre-Run: 7,049,351,168 bytes free
Post-Run: 7,071,469,568 bytes free
.
- - End Of File - - 53DADCE3C6CE1C239FDB931ADD91EB25
Upload was successful