Disregard last post. Saw in another post reference to getting stuck at Combo-Fix will now reboot your machine" etc. I never got that. The machine just rebooted. Figuring the machine had crashed, I re-ran ComboFix. Everything worked right this time, and the "ComboFix" folder I mentioned before is gone.
Here's the log.
ComboFix 12-07-31.06 - Chris 08/03/2012 18:43:52.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3198.2630 [GMT -5:00]
Running from: c:\documents and settings\Chris\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Free Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Chris\Application Data\Adobe\plugs
c:\documents and settings\Chris\Application Data\Adobe\shed
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\addon.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\amazon_ie.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\bing.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DefaultTabStart.exe
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DefaultTabWrap.dll
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DT.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DTUpdate.exe
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\facebook_ie.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\google.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\search_here_ie.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\searchhere.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\twitter_ie.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\uninstalldt.exe
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\wikipedia_ie.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\yahoo.ico
c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\youtube_ie.ico
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome.manifest
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\background.html
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\browser.xul
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\crossrider.js
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\crossriderapi.js
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\dialog.js
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\options.js
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\options.xul
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\search_dialog.xul
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\chrome\content\update.html
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\defaults\preferences\prefs.js
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\install.rdf
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\locale\en-US\translations.dtd
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\button1.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\button2.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\button3.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\button4.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\button5.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\crossrider_statusbar.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\icon128.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\icon16.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\icon24.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\icon48.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\panelarrow-up.png
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\popup.css
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\popup.html
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\popup_binding.xml
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\skin.css
c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\361jeeys.default\extensions\
crossriderapp4639@crossrider.com\skin\update.css
c:\documents and settings\Chris\Application Data\Qwiklinx\QwIKlinx.dll
c:\documents and settings\Chris\My Documents\ShopToWin
c:\documents and settings\Chris\Start Menu\178.lnk
c:\documents and settings\Chris\WINDOWS
c:\program files\SavingsApp
c:\program files\SavingsApp\SavingsApp.ico
c:\windows\system32\SET4A.tmp
c:\windows\system32\SET4D.tmp
c:\windows\system32\SET51.tmp
c:\windows\system32\SET59.tmp
c:\windows\system32\SET5B.tmp
c:\windows\system32\SET9C.tmp
c:\windows\system32\SET9E.tmp
c:\windows\system32\SETA0.tmp
c:\windows\system32\SETA1.tmp
F:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
-------\Legacy_DefaultTabUpdate
-------\Legacy_DefaultTabUpdate
-------\Service_DefaultTabUpdate
-------\Service_DefaultTabUpdate
.
.
((((((((((((((((((((((((( Files Created from 2012-07-04 to 2012-08-04 )))))))))))))))))))))))))))))))
.
.
2012-08-03 06:32 . 2012-08-03 06:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-03 06:32 . 2012-07-03 18:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-02 05:56 . 2012-08-02 05:56 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\visi_coupon
2012-08-02 03:51 . 2012-08-02 03:51 -------- d-----w- c:\documents and settings\Administrator.VADER.000\Local Settings\Application Data\Mozilla
2012-08-01 04:11 . 2012-07-03 16:21 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-01 04:11 . 2012-07-03 16:21 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-01 04:11 . 2012-07-03 16:21 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-01 04:11 . 2012-07-03 16:21 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-01 04:11 . 2012-07-03 16:21 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-01 04:11 . 2012-07-03 16:21 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-01 04:11 . 2012-07-03 16:21 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-01 04:11 . 2012-07-03 16:21 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-01 04:10 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
2012-08-01 04:10 . 2012-07-03 16:21 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-01 04:10 . 2012-08-01 04:10 -------- d-----w- c:\program files\AVAST Software
2012-08-01 04:10 . 2012-08-01 04:10 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-07-31 05:41 . 2012-08-03 23:57 -------- d-----w- c:\documents and settings\Chris\Application Data\Qwiklinx
2012-07-31 05:41 . 2012-07-31 05:41 -------- d-----w- c:\program files\Qwiklinx
2012-07-31 05:41 . 2012-07-31 05:41 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\SavingsApp
2012-07-31 05:41 . 2012-07-31 05:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2012-07-31 05:41 . 2012-07-31 05:41 -------- d-----w- c:\program files\DefaultTab
2012-07-31 05:41 . 2012-08-03 23:58 -------- d-----w- c:\documents and settings\Chris\Application Data\DefaultTab
2012-07-31 05:40 . 2012-07-31 05:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2012-07-31 05:40 . 2012-07-31 05:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2012-07-12 04:46 . 2012-07-12 04:47 -------- d-----w- c:\program files\Gardenscapes - Mansion Makeover
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 04:04 . 2011-12-12 07:40 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-03-21 1523512]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\INTELAUDIOSTUDIO.exe" [2004-06-20 6828032]
"SoundMan"="SOUNDMAN.EXE" [2004-06-17 69632]
"AlcWzrd"="ALCWZRD.EXE" [2004-06-17 2550272]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-04 198160]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-10 73360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-10 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-10 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-10 1634112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-09-01 03:34 136176 ----atw- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2012-02-10 03:04 15494464 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2012-02-10 04:10 1634112 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\bin_ship\\DAOrigins.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\docs\\EA Help\\Electronic_Arts_Technical_Support.htm"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\tools\\DragonAgeToolset.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\tools\\RPU.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\tools\\lightmapper\\eclipseRay.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\tools\\GffEditor.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dragon age origins\\tools\\ErfEditor.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\shattered_horizon\\client_exe\\shattered_horizon.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"57752:TCP"= 57752:TCP

ando Media Booster
"57752:UDP"= 57752:UDP

ando Media Booster
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/31/2012 11:11 PM 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/31/2012 11:11 PM 353688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/31/2012 11:11 PM 21256]
R2 DefaultTabSearch;DefaultTabSearch;c:\program files\DefaultTab\DefaultTabSearch.exe [5/18/2012 4:00 AM 563200]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [11/3/2011 9:44 AM 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [11/3/2011 9:44 AM 497280]
R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 7:29 PM 29293408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2/27/2012 11:11 PM 2348352]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [12/29/2011 9:18 PM 123712]
S3 bfastfao;bfastfao;\??\c:\docume~1\Chris\LOCALS~1\Temp\bfastfao.sys --> c:\docume~1\Chris\LOCALS~1\Temp\bfastfao.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [7/16/2010 2:00 PM 25832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2012-08-04 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-08-01 16:21]
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-682003330-1003Core.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-01 03:34]
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-682003330-1003UA.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-01 03:34]
.
2012-08-03 c:\windows\Tasks\User_Feed_Synchronization-{859C40AD-15BA-44EC-919C-A902C727BC80}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
TCP: DhcpNameServer = 65.32.5.111 65.32.5.112
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.1.0/GarminAxControl.CAB
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{7F6AFBF1-E065-4627-A2FD-810366367D01} - c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-09756421.sys
AddRemove-DefaultTab - c:\documents and settings\Chris\Application Data\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-03 19:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1202660629-583907252-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:41,f9,c5,28,d9,ab,98,11,93,c7,24,4c,9d,a6,2b,f7,1f,e3,a2,59,6e,
d6,a1,42,c4,81,a2,85,1e,e9,a8,47,6f,87,00,54,8d,84,96,51,9e,7a,34,cf,60,4b,\
"rkeysecu"=hex:4f,f9,4e,06,a7,95,c7,ec,3e,32,0a,1b,0c,f8,69,28
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(792)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(852)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(2332)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\SOUNDMAN.EXE
c:\windows\ALCWZRD.EXE
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Completion time: 2012-08-03 19:08:29 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-04 00:08
.
Pre-Run: 79,540,932,608 bytes free
Post-Run: 80,832,507,904 bytes free
.
- - End Of File - - 5F6040AD00D35C3DFE47BF00330523FB