ComboFix 13-04-14.01 - Thomas Paine 04/14/2013 9:56.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8184.3950 [GMT -7:00]
Running from: c:\users\Thomas Paine\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Thomas Paine\AppData\Roaming\.#
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-03-14 to 2013-04-14 )))))))))))))))))))))))))))))))
.
.
2013-04-14 17:03 . 2013-04-14 17:03 -------- d-----w- c:\users\Test\AppData\Local\temp
2013-04-14 17:03 . 2013-04-14 17:03 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-04-14 17:03 . 2013-04-14 17:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-04-14 17:03 . 2013-04-14 17:03 -------- d-----w- c:\users\AppData\AppData\Local\temp
2013-04-14 02:33 . 2013-04-14 13:47 -------- d-----w- c:\users\Thomas Paine\AppData\Roaming\vlc
2013-04-10 07:51 . 2013-03-01 03:36 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-04-10 07:50 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 07:50 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 07:50 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-10 07:50 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-04-10 07:50 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-04-10 07:50 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe
2013-04-10 07:50 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-20 14:21 . 2013-04-13 21:50 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-03-20 14:21 . 2013-03-20 14:22 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2013-03-17 21:34 . 2013-03-17 21:34 -------- d-----w- c:\users\Thomas Paine\AppData\Roaming\dvdcss
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-13 13:32 . 2012-04-28 14:37 691592 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-04-13 13:32 . 2011-05-17 00:55 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-10 10:02 . 2010-07-18 18:04 72702784 ----a-w- c:\windows\system32\MRT.exe
2013-04-04 21:50 . 2012-12-24 18:28 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-13 02:17 . 2013-03-13 02:17 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-03-13 02:17 . 2013-03-13 02:17 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-03-13 02:17 . 2013-03-13 02:17 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-03-13 02:17 . 2013-03-13 02:17 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-03-13 02:17 . 2013-03-13 02:17 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-03-13 02:17 . 2013-03-13 02:17 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-03-13 02:17 . 2013-03-13 02:17 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-03-13 02:17 . 2013-03-13 02:17 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-03-13 02:17 . 2013-03-13 02:17 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-13 02:16 . 2013-03-13 02:16 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-03-13 02:16 . 2013-03-13 02:16 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-03-13 02:16 . 2013-03-13 02:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-03-13 02:16 . 2013-03-13 02:16 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-03-13 02:16 . 2013-03-13 02:16 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-03-13 02:16 . 2013-03-13 02:16 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-03-13 02:16 . 2013-03-13 02:16 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-03-13 02:16 . 2013-03-13 02:16 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-03-13 02:16 . 2013-03-13 02:16 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-03-13 02:16 . 2013-03-13 02:16 216064 ----a-w- c:\windows\system32\msls31.dll
2013-03-13 02:16 . 2013-03-13 02:16 197120 ----a-w- c:\windows\system32\msrating.dll
2013-03-13 02:16 . 2013-03-13 02:16 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-03-13 02:16 . 2013-03-13 02:16 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-03-13 02:16 . 2013-03-13 02:16 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-03-13 02:16 . 2013-03-13 02:16 81408 ----a-w- c:\windows\system32\icardie.dll
2013-03-13 02:16 . 2013-03-13 02:16 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-03-13 02:16 . 2013-03-13 02:16 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-03-13 02:16 . 2013-03-13 02:16 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-03-13 02:16 . 2013-03-13 02:16 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-03-13 02:16 . 2013-03-13 02:16 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-03-13 02:16 . 2013-03-13 02:16 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-03-13 02:16 . 2013-03-13 02:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-03-13 02:16 . 2013-03-13 02:16 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-03-13 02:16 . 2013-03-13 02:16 441856 ----a-w- c:\windows\system32\html.iec
2013-03-13 02:16 . 2013-03-13 02:16 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-03-13 02:16 . 2013-03-13 02:16 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-03-13 02:16 . 2013-03-13 02:16 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-03-13 02:16 . 2013-03-13 02:16 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-03-13 02:16 . 2013-03-13 02:16 235008 ----a-w- c:\windows\system32\url.dll
2013-03-13 02:16 . 2013-03-13 02:16 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-03-13 02:16 . 2013-03-13 02:16 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-03-13 02:16 . 2013-03-13 02:16 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-03-13 02:16 . 2013-03-13 02:16 149504 ----a-w- c:\windows\system32\occache.dll
2013-03-13 02:16 . 2013-03-13 02:16 144896 ----a-w- c:\windows\system32\wextract.exe
2013-03-13 02:16 . 2013-03-13 02:16 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-03-13 02:16 . 2013-03-13 02:16 13824 ----a-w- c:\windows\system32\mshta.exe
2013-03-13 02:16 . 2013-03-13 02:16 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-03-13 02:16 . 2013-03-13 02:16 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-03-13 02:16 . 2013-03-13 02:16 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-03-13 02:16 . 2013-03-13 02:16 102912 ----a-w- c:\windows\system32\inseng.dll
2013-03-06 23:33 . 2013-02-28 20:38 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-06 23:33 . 2013-02-28 20:38 178624 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-06 23:33 . 2012-12-24 18:19 377920 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-03-06 23:33 . 2012-12-24 18:19 70992 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-03-06 23:33 . 2012-12-24 18:19 68920 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-03-06 23:33 . 2012-12-24 18:19 1025808 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-06 23:33 . 2012-12-24 18:19 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-03-06 23:33 . 2012-12-24 18:19 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-06 23:32 . 2012-12-24 18:18 41664 ----a-w- c:\windows\avastSS.scr
2013-03-06 23:32 . 2012-12-24 18:19 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-03-06 00:46 . 2013-03-06 00:46 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-06 00:46 . 2012-08-28 11:05 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-03-06 00:46 . 2010-07-17 11:38 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-03-05 16:49 . 2013-03-05 16:49 310688 ----a-w- c:\windows\system32\javaws.exe
2013-03-05 16:49 . 2013-03-05 16:49 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-03-05 16:49 . 2013-03-05 16:49 188832 ----a-w- c:\windows\system32\javaw.exe
2013-03-05 16:49 . 2013-03-05 16:49 188320 ----a-w- c:\windows\system32\java.exe
2013-03-05 16:49 . 2012-09-02 13:29 963488 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-05 16:49 . 2012-09-02 13:29 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-12 05:45 . 2013-03-13 01:57 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-13 01:57 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-13 01:57 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 05:45 . 2013-03-13 01:57 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 04:48 . 2013-03-13 01:57 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-13 01:57 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-12 04:12 . 2013-03-13 02:08 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-30 02:15 . 2013-01-30 02:15 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
2013-01-30 02:15 . 2013-01-30 02:15 828872 ----a-w- c:\windows\system32\msvcr110.dll
2013-01-30 02:15 . 2013-01-30 02:15 661448 ----a-w- c:\windows\system32\msvcp110.dll
2013-01-30 02:15 . 2013-01-30 02:15 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
2013-01-30 02:15 . 2013-01-30 02:15 354264 ----a-w- c:\windows\system32\vccorlib110.dll
2013-01-30 02:15 . 2013-01-30 02:15 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
2013-01-30 02:15 . 2013-01-30 02:15 50800 ----a-w- c:\windows\system32\drivers\point64.sys
2013-01-30 02:15 . 2013-01-30 02:15 2177664 ----a-w- c:\windows\system32\coin93.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Z1"="c:\users\Thomas Paine\Desktop\mbar-1.05.0.1001\mbar\mbar.exe" [2013-04-14 1398856]
.
c:\users\Thomas Paine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Calendar.lnk - c:\program files (x86)\WebbIE\Calendar.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 aswVmm;aswVmm; [x]
R3 CTV1W;Cisco CTV1W Driver;c:\windows\system32\DRIVERS\CTV1W.sys [2010-04-20 1118048]
R3 FSUSBCAM;Freedom Scientific USB Camera;c:\windows\system32\drivers\fsUsbCam.sys [x]
R3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-09-17 23536]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-09-29 695400]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-17 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-07 14464]
S0 ahcix64s;ahcix64s;c:\windows\system32\DRIVERS\ahcix64s.sys [2009-10-06 230456]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/02/22 18:44];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2009-09-18 01:41 146928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-26 237056]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-07-04 361984]
S2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-09-19 122880]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-06 53888]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-03-06 80816]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [2008-07-11 145448]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2012-11-27 75904]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-12-13 36720]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2013-01-30 50800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-12-29 412776]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-28 13:32]
.
2013-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-555829191-1849574639-2068614983-1001Core.job
- c:\users\Thomas Paine\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-25 02:37]
.
2013-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-555829191-1849574639-2068614983-1001UA.job
- c:\users\Thomas Paine\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-25 02:37]
.
2013-04-07 c:\windows\Tasks\HPCeeScheduleForThomas Paine.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2013-01-22 c:\windows\Tasks\PCDRScheduledMaintenance.job
- c:\program files\PC-Doctor for Windows\pcdrcui.exe [2009-09-18 07:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 23:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-09-15 610360]
"PC-Doctor for Windows localizer"="c:\program files\PC-Doctor for Windows\localizer.exe" [2009-09-17 95728]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.kirotv.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: google.com\www
TCP: DhcpNameServer = 192.168.1.1 74.40.74.40
FF - ProfilePath - c:\users\Thomas Paine\AppData\Roaming\Mozilla\Firefox\Profiles\my1bpawy.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.kirotv.com/
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Belarc Advisor - c:\progra~2\Belarc\Advisor\Uninstall.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus\1]
@="131473"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-04-14 10:15:51
ComboFix-quarantined-files.txt 2013-04-14 17:15
.
Pre-Run: 763,631,075,328 bytes free
Post-Run: 763,404,001,280 bytes free
.
- - End Of File - - 0E536F2F596E06801588C852F6BA03FC