Here is the combofix log...I ran the Eset for 3 hours and was not given any prompt to view or save a log...and after it was finished scanning the window just closed. There was 24 threats, however...I remember seing trojans and something with the word "hot" in it. I can redo it, but this is what I have so far:
[FONT=Courier New]ComboFix 12-05-10.04 - Gary 05/10/2012 21:29:22.1.2 - x64[/FONT]
[FONT=Courier New]Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4026.2673 [GMT -4:00][/FONT]
[FONT=Courier New]Running from: c:\users\Gary\Desktop\ComboFix.exe[/FONT]
[FONT=Courier New]SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]c:\program files (x86)\Hotspot Shield\HssIE\HsSIe.dll[/FONT]
[FONT=Courier New]c:\programdata\ED3BB1D5FB.sys[/FONT]
[FONT=Courier New]c:\users\Gary\AppData\Local\Temp\onhfg.dll[/FONT]
[FONT=Courier New]c:\users\Gary\AppData\Roaming\Cyumn[/FONT]
[FONT=Courier New]c:\users\Gary\AppData\Roaming\Cyumn\antol.exe[/FONT]
[FONT=Courier New]c:\users\Gary\AppData\Roaming\Ycom[/FONT]
[FONT=Courier New]c:\users\Gary\AppData\Roaming\Ycom\xesya.ypu[/FONT]
[FONT=Courier New]c:\windows\system32\consrv.dll[/FONT]
[FONT=Courier New]c:\windows\System64[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]((((((((((((((((((((((((( Files Created from 2012-04-11 to 2012-05-11 )))))))))))))))))))))))))))))))[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-11 01:36 . 2012-05-11 01:36-------- d-----w- c:\users\Default\AppData\Local\temp[/FONT]
[FONT=Courier New]2012-05-10 21:41 . 2012-05-10 21:41-------- d-sh--w- c:\windows\SysWow64\%APPDATA%[/FONT]
[FONT=Courier New]2012-05-10 21:40 . 2012-05-10 21:40-------- d-----w- c:\games\Windows Journal[/FONT]
[FONT=Courier New]2012-05-10 21:17 . 2012-05-11 00:25-------- d-----w- C:\TDSSKiller_Quarantine[/FONT]
[FONT=Courier New]2012-05-10 15:22 . 2012-03-17 07:5575632----a-w- c:\windows\system32\drivers\partmgr.sys[/FONT]
[FONT=Courier New]2012-05-10 15:22 . 2012-03-30 11:091895280 ----a-w- c:\windows\system32\drivers\tcpip.sys[/FONT]
[FONT=Courier New]2012-05-10 15:22 . 2012-04-02 05:241367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll[/FONT]
[FONT=Courier New]2012-05-10 15:22 . 2012-04-02 04:40936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll[/FONT]
[FONT=Courier New]2012-05-07 02:32 . 2012-05-10 23:27-------- d-----w- c:\programdata\Spybot - Search & Destroy[/FONT]
[FONT=Courier New]2012-05-06 19:54 . 2012-05-06 19:54-------- d-----w- c:\users\Gary\AppData\Roaming\Malwarebytes[/FONT]
[FONT=Courier New]2012-05-06 19:54 . 2012-05-06 19:54-------- d-----w- c:\programdata\Malwarebytes[/FONT]
[FONT=Courier New]2012-05-06 19:54 . 2012-04-04 19:5624904----a-w- c:\windows\system32\drivers\mbam.sys[/FONT]
[FONT=Courier New]2012-05-06 15:38 . 2012-05-10 21:290 --sha-w- c:\windows\system32\dds_trash_log.cmd[/FONT]
[FONT=Courier New]2012-05-04 12:50 . 2012-05-04 13:12-------- d-----w- c:\users\Gary\AppData\Roaming\mIRC[/FONT]
[FONT=Courier New]2012-05-04 01:18 . 2012-05-04 01:18-------- d-----w- c:\users\Gary\AppData\Local\{0046A5D1-9587-11E1-826D-B8AC6F996F26}[/FONT]
[FONT=Courier New]2012-05-03 21:57 . 2012-05-03 21:57418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe[/FONT]
[FONT=Courier New]2012-05-03 21:57 . 2012-05-03 21:57-------- d-----w- c:\windows\system32\Macromed[/FONT]
[FONT=Courier New]2012-05-03 21:46 . 2012-05-07 19:19-------- d-----w- c:\users\Gary\AppData\Roaming\Edudy[/FONT]
[FONT=Courier New]2012-05-03 21:46 . 2012-05-07 12:55-------- d-----w- c:\users\Gary\AppData\Roaming\Irdeg[/FONT]
[FONT=Courier New]2012-05-03 21:46 . 2012-05-03 21:46-------- d-----w- c:\users\Gary\AppData\Roaming\Osnyw[/FONT]
[FONT=Courier New]2012-05-03 21:46 . 2012-05-03 21:46-------- d-----w- c:\users\Gary\AppData\Local\Search[/FONT]
[FONT=Courier New]2012-05-03 21:46 . 2012-05-06 14:59-------- d-----w- c:\users\Gary\AppData\Roaming\Veyba[/FONT]
[FONT=Courier New]2012-05-03 20:24 . 2012-05-03 20:24-------- d-----w- c:\users\Gary\AppData\Local\Bugsplat[/FONT]
[FONT=Courier New]2012-04-27 16:46 . 2012-04-27 16:46-------- d-----w- c:\users\Gary\AppData\Local\CRE[/FONT]
[FONT=Courier New]2012-04-27 16:46 . 2012-05-11 01:26-------- d-----w- c:\users\Gary\AppData\Local\Conduit[/FONT]
[FONT=Courier New]2012-04-25 20:26 . 2009-07-14 01:41258048 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfppw73.dll[/FONT]
[FONT=Courier New]2012-04-23 13:15 . 2012-04-13 08:468917360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C9777565-BF43-4BDF-8B2F-7F598B9529D9}\mpengine.dll[/FONT]
[FONT=Courier New]2012-04-15 02:29 . 2012-04-15 02:29-------- d-----w- c:\games\iPod[/FONT]
[FONT=Courier New]2012-04-15 02:29 . 2012-04-15 02:29-------- d-----w- c:\games\iTunes[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 06:5422896----a-w- c:\windows\system32\drivers\fs_rec.sys[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 06:4080896----a-w- c:\windows\system32\imagehlp.dll[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 05:49172544 ----a-w- c:\windows\SysWow64\wintrust.dll[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 05:45158720 ----a-w- c:\windows\SysWow64\imagehlp.dll[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 06:45220672 ----a-w- c:\windows\system32\wintrust.dll[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 06:355120 ----a-w- c:\windows\system32\wmi.dll[/FONT]
[FONT=Courier New]2012-04-13 07:00 . 2012-03-01 05:405120 ----a-w- c:\windows\SysWow64\wmi.dll[/FONT]
[FONT=Courier New]2012-04-12 18:54 . 2012-04-12 18:54-------- d-----w- c:\program files (x86)\Common Files\Skype[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New](((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-03 21:57 . 2011-06-27 01:0070304----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl[/FONT]
[FONT=Courier New]2012-02-23 14:18 . 2010-01-09 17:10279656 ------w- c:\windows\system32\MpSigStub.exe[/FONT]
[FONT=Courier New]2012-02-15 15:01 . 2012-02-15 15:0152736----a-w- c:\windows\system32\drivers\usbaapl64.sys[/FONT]
[FONT=Courier New]2012-02-15 15:01 . 2012-02-15 15:014547944 ----a-w- c:\windows\system32\usbaaplrc.dll[/FONT]
[FONT=Courier New]2012-02-15 06:27 . 2012-03-14 03:231031680 ----a-w- c:\windows\system32\rdpcore.dll[/FONT]
[FONT=Courier New]2012-02-15 05:44 . 2012-03-14 03:23826368 ----a-w- c:\windows\SysWow64\rdpcore.dll[/FONT]
[FONT=Courier New]2012-02-15 04:47 . 2012-03-14 03:23204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys[/FONT]
[FONT=Courier New]2012-02-15 04:46 . 2012-03-14 03:2323552----a-w- c:\windows\system32\drivers\tdtcp.sys[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]*Note* empty entries & legit default entries are not shown [/FONT]
[FONT=Courier New]REGEDIT4[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/FONT]
[FONT=Courier New]"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2010-11-14 222496][/FONT]
[FONT=Courier New]"Rainlendar2"="c:\program files (x86)\Rainlendar2\Rainlendar2.exe" [2011-08-12 2433024][/FONT]
[FONT=Courier New]"SearchGatherer"="c:\users\Gary\AppData\Local\Search\SearchGatherer.exe" [2012-05-03 40032][/FONT]
[FONT=Courier New]"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run][/FONT]
[FONT=Courier New]"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-08-18 1157640][/FONT]
[FONT=Courier New]"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2009-08-21 244480][/FONT]
[FONT=Courier New]"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-04 103720][/FONT]
[FONT=Courier New]"VMware hqtray"="c:\program files (x86)\VMware\VMware Player\hqtray.exe" [2010-09-21 64048][/FONT]
[FONT=Courier New]"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run][/FONT]
[FONT=Courier New]"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\[/FONT]
[FONT=Courier New]Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-9-18 102912][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system][/FONT]
[FONT=Courier New]"ConsentPromptBehaviorAdmin"= 0 (0x0)[/FONT]
[FONT=Courier New]"ConsentPromptBehaviorUser"= 3 (0x3)[/FONT]
[FONT=Courier New]"EnableLUA"= 0 (0x0)[/FONT]
[FONT=Courier New]"EnableUIADesktopToggle"= 0 (0x0)[/FONT]
[FONT=Courier New]"PromptOnSecureDesktop"= 0 (0x0)[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384][/FONT]
[FONT=Courier New]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576][/FONT]
[FONT=Courier New]R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-21 135664][/FONT]
[FONT=Courier New]R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856][/FONT]
[FONT=Courier New]R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-03 253088][/FONT]
[FONT=Courier New]R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x][/FONT]
[FONT=Courier New]R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832][/FONT]
[FONT=Courier New]R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x][/FONT]
[FONT=Courier New]R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x][/FONT]
[FONT=Courier New]R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072][/FONT]
[FONT=Courier New]R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-21 135664][/FONT]
[FONT=Courier New]R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x][/FONT]
[FONT=Courier New]R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x][/FONT]
[FONT=Courier New]R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x][/FONT]
[FONT=Courier New]R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x][/FONT]
[FONT=Courier New]R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x][/FONT]
[FONT=Courier New]R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x][/FONT]
[FONT=Courier New]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x][/FONT]
[FONT=Courier New]S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x][/FONT]
[FONT=Courier New]S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x][/FONT]
[FONT=Courier New]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x][/FONT]
[FONT=Courier New]S2 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [2010-07-23 296808][/FONT]
[FONT=Courier New]S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2009-08-06 844320][/FONT]
[FONT=Courier New]S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-06-04 1150496][/FONT]
[FONT=Courier New]S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136][/FONT]
[FONT=Courier New]S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704][/FONT]
[FONT=Courier New]S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2009-08-21 62720][/FONT]
[FONT=Courier New]S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160][/FONT]
[FONT=Courier New]S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x][/FONT]
[FONT=Courier New]S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-09-21 539184][/FONT]
[FONT=Courier New]S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x][/FONT]
[FONT=Courier New]S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x][/FONT]
[FONT=Courier New]S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x][/FONT]
[FONT=Courier New]S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]Contents of the 'Scheduled Tasks' folder[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job[/FONT]
[FONT=Courier New]- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-03 21:57][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job[/FONT]
[FONT=Courier New]- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-21 13:24][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]2012-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job[/FONT]
[FONT=Courier New]- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-21 13:24][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]--------- x86-64 -----------[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}][/FONT]
[FONT=Courier New]2010-09-22 19:19 284208 ----a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][/FONT]
[FONT=Courier New]"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112][/FONT]
[FONT=Courier New]"Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2009-08-06 828960][/FONT]
[FONT=Courier New]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 159232][/FONT]
[FONT=Courier New]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 380928][/FONT]
[FONT=Courier New]"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 358912][/FONT]
[FONT=Courier New]"combofix"="c:\combofix\CF7932.3XE" [2009-07-14 344576][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler][/FONT]
[FONT=Courier New]"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2010-06-22 253288][/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows][/FONT]
[FONT=Courier New]"LoadAppInit_DLLs"=0x0[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs[/FONT]
[FONT=Courier New]penrendezvous[/FONT]
[FONT=Courier New]Invoker[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]------- Supplementary Scan -------[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]uStart Page = hxxp://
www.google.com/[/FONT]
[FONT=Courier New]uLocal Page = c:\windows\system32\blank.htm[/FONT]
[FONT=Courier New]mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=nv78&r=273611094545l03g4z175a48n2v23s[/FONT]
[FONT=Courier New]mLocal Page = c:\windows\SysWOW64\blank.htm[/FONT]
[FONT=Courier New]uInternet Settings,ProxyOverride = *.local[/FONT]
[FONT=Courier New]IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000[/FONT]
[FONT=Courier New]IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html[/FONT]
[FONT=Courier New]LSP: c:\program files (x86)\VMware\VMware Player\vsocklib.dll[/FONT]
[FONT=Courier New]TCP: DhcpNameServer = 192.168.1.1[/FONT]
[FONT=Courier New]FF - ProfilePath - c:\users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\fz1nryxo.default\[/FONT]
[FONT=Courier New]FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[/FONT]
[FONT=Courier New]FF - Ext: ChaCha Guide App Toolbar:
chachaguidebar@chacha.com - %profile%\extensions\
chachaguidebar@chacha.com[/FONT]
[FONT=Courier New]FF - Ext: Clippings: {91aa5abe-9de4-4347-b7b5-322c38dd9271} - %profile%\extensions\{91aa5abe-9de4-4347-b7b5-322c38dd9271}[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]- - - - ORPHANS REMOVED - - - -[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)[/FONT]
[FONT=Courier New]URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)[/FONT]
[FONT=Courier New]BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)[/FONT]
[FONT=Courier New]Toolbar-Locked - (no file)[/FONT]
[FONT=Courier New]Wow6432Node-HKCU-Run-Wywefyezep - c:\users\Gary\AppData\Roaming\Cyumn\antol.exe[/FONT]
[FONT=Courier New]SafeBoot-21077156.sys[/FONT]
[FONT=Courier New]SafeBoot-42131801.sys[/FONT]
[FONT=Courier New]SafeBoot-43011556.sys[/FONT]
[FONT=Courier New]Toolbar-Locked - (no file)[/FONT]
[FONT=Courier New]WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)[/FONT]
[FONT=Courier New]WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)[/FONT]
[FONT=Courier New]HKLM-Run-SynTPEnh - c:\games\Synaptics\SynTP\SynTPEnh.exe[/FONT]
[FONT=Courier New]AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe[/FONT]
[FONT=Courier New]AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Gary\AppData\Roaming\Macromedia\Flash Player\[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]--------------------- LOCKED REGISTRY KEYS ---------------------[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}][/FONT]
[FONT=Courier New]@Denied: (A 2) (Everyone)[/FONT]
[FONT=Courier New]@="FlashBroker"[/FONT]
[FONT=Courier New]"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation][/FONT]
[FONT=Courier New]"Enabled"=dword:00000001[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32][/FONT]
[FONT=Courier New]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib][/FONT]
[FONT=Courier New]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}][/FONT]
[FONT=Courier New]@Denied: (A 2) (Everyone)[/FONT]
[FONT=Courier New]@="Shockwave Flash Object"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32][/FONT]
[FONT=Courier New]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"[/FONT]
[FONT=Courier New]"ThreadingModel"="Apartment"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus][/FONT]
[FONT=Courier New]@="0"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID][/FONT]
[FONT=Courier New]@="ShockwaveFlash.ShockwaveFlash.11"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32][/FONT]
[FONT=Courier New]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib][/FONT]
[FONT=Courier New]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version][/FONT]
[FONT=Courier New]@="1.0"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID][/FONT]
[FONT=Courier New]@="ShockwaveFlash.ShockwaveFlash"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}][/FONT]
[FONT=Courier New]@Denied: (A 2) (Everyone)[/FONT]
[FONT=Courier New]@="Macromedia Flash Factory Object"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32][/FONT]
[FONT=Courier New]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"[/FONT]
[FONT=Courier New]"ThreadingModel"="Apartment"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID][/FONT]
[FONT=Courier New]@="FlashFactory.FlashFactory.1"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32][/FONT]
[FONT=Courier New]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib][/FONT]
[FONT=Courier New]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version][/FONT]
[FONT=Courier New]@="1.0"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID][/FONT]
[FONT=Courier New]@="FlashFactory.FlashFactory"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}][/FONT]
[FONT=Courier New]@Denied: (A 2) (Everyone)[/FONT]
[FONT=Courier New]@="IFlashBroker4"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32][/FONT]
[FONT=Courier New]@="{00020424-0000-0000-C000-000000000046}"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib][/FONT]
[FONT=Courier New]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"[/FONT]
[FONT=Courier New]"Version"="1.0"[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings][/FONT]
[FONT=Courier New]@Denied: (A) (Users)[/FONT]
[FONT=Courier New]@Denied: (A) (Everyone)[/FONT]
[FONT=Courier New]@Allowed: (B 1 2 3 4 5) (S-1-5-20)[/FONT]
[FONT=Courier New]"BlindDial"=dword:00000000[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security][/FONT]
[FONT=Courier New]@Denied: (Full) (Everyone)[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]------------------------ Other Running Processes ------------------------[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[/FONT]
[FONT=Courier New]c:\windows\SysWOW64\vmnat.exe[/FONT]
[FONT=Courier New]c:\program files (x86)\VMware\VMware Player\vmware-authd.exe[/FONT]
[FONT=Courier New]c:\windows\SysWOW64\vmnetdhcp.exe[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]**************************************************************************[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]Completion time: 2012-05-10 21:44:37 - machine was rebooted[/FONT]
[FONT=Courier New]ComboFix-quarantined-files.txt 2012-05-11 01:44[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]Pre-Run: 162,983,120,896 bytes free[/FONT]
[FONT=Courier New]Post-Run: 162,400,514,048 bytes free[/FONT]
[FONT=Courier New].[/FONT]
[FONT=Courier New]- - End Of File - - 585CF697A94B3C4734FD15ABB2DBC594[/FONT]