it seems fixed, heres the log:
ComboFix 10-07-14.01 - nathan 07/14/2010 14:50:04.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1655 [GMT -5:00]
Running from: c:\documents and settings\nathan\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\nathan\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TWXYHN
-------\Service_NPF
-------\Service_twxyhn
((((((((((((((((((((((((( Files Created from 2010-06-14 to 2010-07-14 )))))))))))))))))))))))))))))))
.
2010-07-10 16:52 . 2010-07-10 16:52 -------- d-----w- c:\windows\Sun
2010-07-10 16:52 . 2010-07-10 16:52 503808 ----a-w- c:\documents and settings\nathan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3b9d3c3b-n\msvcp71.dll
2010-07-10 16:52 . 2010-07-10 16:52 499712 ----a-w- c:\documents and settings\nathan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3b9d3c3b-n\jmc.dll
2010-07-10 16:52 . 2010-07-10 16:52 348160 ----a-w- c:\documents and settings\nathan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3b9d3c3b-n\msvcr71.dll
2010-07-10 16:52 . 2010-07-10 16:52 61440 ----a-w- c:\documents and settings\nathan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3679756a-n\decora-sse.dll
2010-07-10 16:52 . 2010-07-10 16:52 12800 ----a-w- c:\documents and settings\nathan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3679756a-n\decora-d3d.dll
2010-07-10 16:52 . 2010-07-10 16:51 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-10 16:14 . 2009-05-05 17:00 632576 ----a-w- c:\windows\system32\drivers\bcmwlhigh5.sys
2010-07-10 16:14 . 2008-11-14 22:35 196608 ----a-w- c:\windows\system32\wps_api.dll
2010-07-06 14:48 . 2010-07-06 14:48 -------- d-----w- c:\documents and settings\nathan\Application Data\Malwarebytes
2010-07-06 14:48 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-06 14:48 . 2010-07-06 14:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-06 14:48 . 2010-07-06 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-06 14:48 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-17 00:01 . 2007-12-14 09:31 57408 ----a-w- c:\windows\system32\drivers\wsimd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 16:51 . 2007-11-16 21:36 -------- d-----w- c:\program files\Java
2010-07-10 16:13 . 2007-11-16 21:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-10 16:10 . 2010-06-13 16:11 -------- d-----w- c:\program files\Atheros
2010-07-08 17:01 . 2007-12-30 19:10 -------- d-----w- c:\documents and settings\nathan\Application Data\U3
2010-07-06 13:47 . 2007-11-16 21:48 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-17 01:02 . 2010-06-13 16:03 -------- d-----w- c:\program files\NETGEAR
2010-06-13 16:05 . 2010-06-13 16:05 -------- d--h--r- c:\documents and settings\All Users\Application Data\Atheros
2010-06-13 16:03 . 2010-06-13 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\NETGEAR
2010-06-06 14:26 . 2010-05-09 14:59 -------- d-----w- c:\documents and settings\nathan\Application Data\Softros Messenger
2010-06-02 00:37 . 2010-06-02 00:37 -------- d-----w- c:\program files\TeamViewer
2010-05-30 15:28 . 2010-05-30 15:28 -------- d-----w- c:\documents and settings\nathan\Application Data\TeamViewer
2010-05-16 14:18 . 2010-05-16 14:18 -------- d-----w- c:\documents and settings\kim\Application Data\Softros Messenger
2010-05-05 00:40 . 2010-05-05 00:40 212 ----a-w- c:\program files\Setup.log
2010-05-05 00:40 . 2010-05-05 00:40 127 ----a-w- c:\program files\PanaHDS.ini
2010-05-02 14:58 . 2010-05-02 14:58 0 ----a-w- c:\windows\nsreg.dat
2007-04-16 15:52 . 2004-08-10 18:51 155936 --sha-r- c:\windows\system32\vlmlrxni.dll
.
(((((((((((((((((((((((((((((
[email protected]_17.09.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-14 19:53 . 2010-07-14 19:53 16384 c:\windows\temp\Perflib_Perfdata_788.dat
+ 2009-08-07 00:24 . 2009-08-07 00:24 44768 c:\windows\system32\wups2.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 35552 c:\windows\system32\wups.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 53472 c:\windows\system32\wuauclt.exe
+ 2010-07-10 14:40 . 2009-08-07 00:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-10 18:50 . 2009-08-07 00:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2004-08-10 18:50 . 2009-08-07 00:24 96480 c:\windows\system32\cdm.dll
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut9_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut9_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut8_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut8_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut6_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut6_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut5_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut5_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut4_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut4_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut23_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut23_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut22_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut22_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut21_C0100D9E237245E2BDA5BD18F9B03298.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut21_C0100D9E237245E2BDA5BD18F9B03298.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut2_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut2_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut19_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut19_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut18_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut18_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut17_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut17_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut16_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut16_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut15_C0100D9E237245E2BDA5BD18F9B03298.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut15_C0100D9E237245E2BDA5BD18F9B03298.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut14_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut14_385FFF305DB34C18B1F9D7793D1B9A0B.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut13_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut13_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut11_C0100D9E237245E2BDA5BD18F9B03298.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 4710 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut11_C0100D9E237245E2BDA5BD18F9B03298.exe
- 2010-06-13 16:03 . 2010-06-17 00:01 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut1_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2010-06-13 16:03 . 2010-07-10 16:10 3638 c:\windows\Installer\{C0100D9E-2372-45E2-BDA5-BD18F9B03298}\NewShortcut1_385FFF305DB34C18B1F9D7793D1B9A0B.exe
+ 2004-08-10 19:02 . 2009-08-07 00:24 209632 c:\windows\system32\wuweb.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 327896 c:\windows\system32\wucltui.dll
+ 2004-08-10 19:02 . 2009-08-07 00:23 575704 c:\windows\system32\wuapi.dll
+ 2007-11-16 21:36 . 2010-07-10 16:51 153376 c:\windows\system32\javaws.exe
+ 2007-11-16 21:36 . 2010-07-10 16:51 145184 c:\windows\system32\javaw.exe
+ 2007-11-16 21:36 . 2010-07-10 16:51 145184 c:\windows\system32\java.exe
+ 2004-08-10 19:02 . 2009-08-07 00:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2004-08-10 19:02 . 2009-08-07 00:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2004-08-10 19:02 . 2009-08-07 00:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2010-07-10 16:52 . 2010-07-10 16:52 180224 c:\windows\Installer\796dad.msi
+ 2010-07-10 16:51 . 2010-07-10 16:51 576000 c:\windows\Installer\796da8.msi
+ 2004-08-10 19:02 . 2009-08-07 00:23 1929952 c:\windows\system32\wuaueng.dll
+ 2004-08-10 19:02 . 2009-08-07 00:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2010-06-13 16:03 . 2010-07-10 16:11 15243776 c:\windows\Downloaded Installations\{3030A6B7-BF78-4AB1-A229-C01653E34F81}\WNDA3100.msi
- 2010-06-13 16:03 . 2010-06-17 00:00 15243776 c:\windows\Downloaded Installations\{3030A6B7-BF78-4AB1-A229-C01653E34F81}\WNDA3100.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-30 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"Acrobat Speed Launch"="c:\program files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe" [2006-10-23 46200]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"BtcMouseMaestro"="c:\program files\HP Wireless 4 Button Laser Mouse\KMaestro.exe" [2007-08-24 344064]
c:\documents and settings\kim\Start Menu\Programs\Startup\
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2007-11-28 474808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-11-16 24576]
Launch Softros Messenger.lnk - c:\program files\Softros Systems\Softros Messenger\Messenger.exe [2010-5-9 1457896]
NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2010-6-16 3272704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2007-11-16 21:52 227328 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 15:00 1116920 ----a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GoogleDesktopManager"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Panasonic\\TrapMonitor\\Trapmnnt.exe"=
"c:\\Program Files\\Panasonic\\Panasonic-DMS\\LRecvTrap\\LRecvTrap.exe"=
"c:\\Program Files\\Softros Systems\\Softros Messenger\\Messenger.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5803:TCP"= 5803:TCP:koxhuqo
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [3/17/2006 6:25 PM 65536]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [4/16/2010 2:18 AM 173352]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [7/10/2010 11:14 AM 632576]
S2 WSWNDA3100;WSWNDA3100;c:\program files\NETGEAR\WNDA3100v2\WifiSvc.exe [7/10/2010 11:14 AM 278528]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 12:10 PM 17149]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3071116
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\nathan\Application Data\Mozilla\Firefox\Profiles\klhjl7o8.default\
FF - prefs.js: browser.startup.homepage - camaro5.com
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-14 14:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Panasonic\TrapMonitor\Trapmnnt.exe
c:\program files\TeamViewer\Version5\TeamViewer.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2010-07-14 14:57:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-14 19:57
ComboFix2.txt 2010-07-09 17:38
ComboFix3.txt 2010-07-08 17:12
Pre-Run: 64,226,222,080 bytes free
Post-Run: 64,222,781,440 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - E71D6C029F51B86C56B61500B8CECC17