Axast says Everything is clean but Ade is blocked.., ..After running combo fix I can't click on anything without it saying the registry file is marked for deletion...
__________________________________________________________________________________
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-12-04 14:31:06
-----------------------------
14:31:06.370 OS Version: Windows 6.0.6002 Service Pack 2
14:31:06.371 Number of processors: 2 586 0xF0D
14:31:06.372 ComputerName: TMOSS-PC UserName:
14:31:52.993 Initialize success
14:31:53.299 AVAST engine defs: 11120401
14:32:12.166 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
14:32:12.168 Disk 0 Vendor: FUJITSU_ 0085 Size: 152627MB BusType: 3
14:32:12.182 Disk 0 MBR read successfully
14:32:12.184 Disk 0 MBR scan
14:32:12.187 Disk 0 Windows VISTA default MBR code
14:32:12.192 Disk 0 scanning sectors +312578048
14:32:12.265 Disk 0 scanning C:\Windows\system32\drivers
14:32:20.317 Service scanning
14:32:20.883 Modules scanning
14:32:21.125 Disk 0 trace - called modules:
14:32:21.170 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
14:32:21.173 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85963ac8]
14:32:21.176 3 CLASSPNP.SYS[883ce8b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84a03030]
14:32:21.715 AVAST engine scan C:\Windows
14:32:23.957 AVAST engine scan C:\Windows\system32
14:33:58.471 AVAST engine scan C:\Windows\system32\drivers
14:34:07.425 AVAST engine scan C:\Users\Administrator.TMoss-PC
14:34:35.848 AVAST engine scan C:\ProgramData
14:34:59.544 Scan finished successfully
14:39:31.764 Disk 0 MBR has been saved successfully to "C:\Users\Administrator.TMoss-PC\Desktop\MBR.dat"
14:39:32.012 The log file has been saved successfully to "C:\Users\Administrator.TMoss-PC\Desktop\aswMBR.txt"
________________________________________________________________________
ComboFix 11-12-04.03 - Administrator 12/04/2011 14:59:10.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2045.888 [GMT -5:00]
Running from: c:\users\Administrator.TMoss-PC\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Documents.lnk
c:\programdata\Roaming
c:\users\TMoss\{96742679-5970-43C1-98B0-2776BDDFEA29}.tmp
c:\users\TMoss\{DD5CC897-60C5-448D-9192-8B7E10017E3D}.tmp
c:\users\TMoss\~DF14CC.tmp
c:\users\TMoss\~DF51F0.tmp
c:\users\TMoss\~DF52FB.tmp
c:\users\TMoss\~DF58B1.tmp
c:\users\TMoss\~DF6607.tmp
c:\users\TMoss\~DF7579.tmp
c:\users\TMoss\~DFABBA.tmp
c:\users\TMoss\~DFC262.tmp
c:\users\TMoss\~DFE03B.tmp
c:\users\TMoss\~DFE189.tmp
c:\users\TMoss\~DFF2FA.tmp
c:\users\TMoss\34B.tmp
c:\users\TMoss\DMI29D7.tmp
c:\users\TMoss\E2D0.tmp
c:\users\TMoss\F871.tmp
c:\users\TMoss\install_flashplayer11x32_mssd_aih.exe
c:\users\TMoss\install_flashplayer11x32_mssd_aih_1.exe
c:\users\TMoss\tmp1279.tmp
c:\users\TMoss\tmp1815.tmp
c:\users\TMoss\tmp2057.tmp
c:\users\TMoss\tmp2AED.tmp
c:\users\TMoss\tmp30AE.tmp
c:\users\TMoss\tmp3AF5.tmp
c:\users\TMoss\tmp4C03.tmp
c:\users\TMoss\tmp5393.tmp
c:\users\TMoss\tmp5B28.tmp
c:\users\TMoss\tmp6221.tmp
c:\users\TMoss\tmp67F.tmp
c:\users\TMoss\tmp822A.tmp
c:\users\TMoss\tmp94EF.tmp
c:\users\TMoss\tmpACA0.tmp
c:\users\TMoss\tmpD25F.tmp
c:\users\TMoss\tmpED9B.tmp
c:\users\TMoss\tmpFC4D.tmp
c:\users\TMoss\tmpFF5E.tmp
c:\users\TMoss\wbk1293.tmp
c:\users\TMoss\wbk1A5C.tmp
c:\users\TMoss\wbk1F26.tmp
c:\users\TMoss\wbk3DA6.tmp
c:\users\TMoss\wbk7227.tmp
c:\users\TMoss\wbk734E.tmp
c:\users\TMoss\wbk7CCF.tmp
c:\users\TMoss\wbkCFCF.tmp
c:\users\TMoss\wbkF646.tmp
c:\windows\system32\config\systemprofile\GUR1C65.tmp
c:\windows\system32\config\systemprofile\GUR2902.tmp
c:\windows\system32\config\systemprofile\GUR8880.tmp
c:\windows\system32\config\systemprofile\GURAE48.tmp
c:\windows\system32\config\systemprofile\GURB4DD.tmp
c:\windows\system32\config\systemprofile\GURBB81.tmp
c:\windows\system32\config\systemprofile\GURC30.tmp
c:\windows\system32\config\systemprofile\sig88CE.tmp
c:\windows\system32\config\systemprofile\sig9405.tmp
c:\windows\system32\config\systemprofile\sig9445.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 20:11 . 2011-12-04 20:11 -------- d-----w- c:\users\UpdatusUser.TMoss-PC\AppData\Local\temp
2011-12-04 20:11 . 2011-12-04 20:11 -------- d-----w- c:\users\UpdatusUser.TMoss-PC.000\AppData\Local\temp
2011-12-04 20:11 . 2011-12-04 20:11 -------- d-----w- c:\users\TMoss\AppData\Local\temp
2011-12-04 20:11 . 2011-12-04 20:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-04 17:23 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-12-04 17:23 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-12-04 17:23 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-04 17:23 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-12-04 17:23 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-12-04 17:23 . 2011-11-28 17:52 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-12-04 17:23 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2011-12-04 17:23 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-12-04 17:22 . 2011-12-04 17:22 -------- d-----w- c:\programdata\AVAST Software
2011-12-04 17:22 . 2011-12-04 17:22 -------- d-----w- c:\program files\AVAST Software
2011-12-04 01:59 . 2011-12-04 01:59 -------- d-----w- c:\users\TMoss\WPDNSE
2011-12-04 01:59 . 2011-12-04 01:59 -------- d-----w- c:\users\TMoss\ArcUpdater
2011-12-01 05:06 . 2011-12-01 05:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-01 05:06 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 20:29 . 2011-11-28 20:29 -------- d-----w- c:\windows\system32\config\systemprofile\TfsStore
2011-11-25 20:51 . 2011-12-03 04:31 -------- d-----w- c:\windows\system32\NtmsData
2011-11-25 17:37 . 2011-11-25 17:37 -------- d--h--w- c:\windows\PIF
2011-11-25 04:32 . 2011-12-01 03:13 -------- d-----w- c:\programdata\Avira
2011-11-23 09:28 . 2011-11-23 09:28 -------- d-----w- c:\users\TMoss\OneNote
2011-11-22 23:27 . 2011-11-22 23:27 -------- d-----w- c:\users\TMoss\New Folder
2011-11-22 16:21 . 2011-10-20 03:16 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2011-11-18 05:19 . 2011-11-18 05:19 -------- d-----w- c:\users\TMoss\AppData\Local\ElevatedDiagnostics
2011-11-18 05:18 . 2011-11-18 05:19 -------- d-----w- c:\users\TMoss\msdtadmin
2011-11-18 05:18 . 2011-11-18 05:19 -------- d-----w- c:\users\TMoss\MATS-Temp
2011-11-17 22:05 . 2011-11-17 22:05 -------- d-----w- c:\users\TMoss\Temp3_ivdf_fusebundle_nt_en.zip
2011-11-17 22:04 . 2011-11-17 22:04 -------- d-----w- c:\users\TMoss\Temp1_manifest.zip
2011-11-17 22:04 . 2011-11-17 22:04 -------- d-----w- c:\users\TMoss\Temp1_rdrmessage.zip
2011-11-17 22:04 . 2011-11-17 22:04 -------- d-----w- c:\users\TMoss\Temp1_PROCESSLISTRELATED.ZIP
2011-11-17 22:04 . 2011-11-17 22:04 -------- d-----w- c:\users\TMoss\Temp1_PROCESSLIST.ZIP
2011-11-17 22:03 . 2011-11-17 22:04 -------- d-----w- c:\users\TMoss\Temp2_ivdf_fusebundle_nt_en.zip
2011-11-17 22:02 . 2011-11-17 22:03 -------- d-----w- c:\users\TMoss\Temp1_ivdf_fusebundle_nt_en.zip
2011-11-17 21:33 . 2011-11-18 04:15 -------- d-----w- c:\users\TMoss\plugtmp-3
2011-11-17 19:16 . 2009-06-03 23:56 675152 ----a-w- c:\windows\system32\gpprefcl.dll
2011-11-17 05:44 . 2011-11-17 05:44 -------- d-----w- c:\users\TMoss\AppData\Roaming\ArcSoft
2011-11-16 20:23 . 2011-11-16 20:23 -------- d-----w- c:\users\TMoss\CR_1F2CC.tmp
2011-11-16 19:20 . 2011-11-16 19:20 -------- d-----w- c:\users\TMoss\OIS
2011-11-16 14:54 . 2011-11-16 14:54 -------- d-----w- c:\users\TMoss\E2D0.dir
2011-11-16 07:48 . 2011-11-16 07:48 -------- d-----w- c:\users\TMoss\msohtmlclip
2011-11-16 02:58 . 2011-11-16 03:21 -------- d-----w- c:\users\TMoss\plugtmp-2
2011-11-16 02:10 . 2011-11-16 02:10 -------- d-----w- c:\users\TMoss\VBE
2011-11-15 21:39 . 2011-11-15 22:13 -------- d-----w- c:\users\TMoss\plugtmp-1
2011-11-15 20:59 . 2011-11-15 21:36 -------- d-----w- c:\users\TMoss\plugtmp
2011-11-13 01:11 . 2011-11-17 20:59 -------- d-----w- c:\users\TMoss\mozilla-media-cache
2011-11-13 01:10 . 2011-11-17 15:40 -------- d-----w- c:\users\TMoss\Low
2011-11-13 00:29 . 2011-11-13 00:30 -------- d-----w- c:\windows\system32\config\systemprofile\Google Toolbar
2011-11-12 22:00 . 2011-12-02 15:05 -------- d-----w- c:\users\Administrator.TMoss-PC
2011-11-10 16:42 . 2011-11-30 00:38 -------- d-----w- c:\users\Guest
2011-11-10 16:18 . 2011-11-10 16:18 -------- d-----w- c:\windows\system32\config\systemprofile\HP
2011-11-09 05:26 . 2011-10-17 11:41 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-11-09 05:26 . 2011-09-20 21:02 913280 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 05:26 . 2011-09-20 13:44 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-11-09 05:26 . 2011-09-30 15:57 707584 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-07 13:02 . 2011-11-07 13:02 -------- d-----w- c:\users\TMoss\AppData\Roaming\PeerNetworking
2011-11-05 17:34 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-18 15:45 . 2011-07-29 09:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-03 09:04 . 2011-11-03 09:04 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-11-03 09:02 . 2011-11-03 09:02 81408 ----a-w- c:\windows\system32\wevtfwd.dll
2011-11-03 09:02 . 2011-11-03 09:02 79872 ----a-w- c:\windows\system32\wecutil.exe
2011-11-03 09:02 . 2011-11-03 09:02 56320 ----a-w- c:\windows\system32\wecapi.dll
2011-11-03 09:02 . 2011-11-03 09:02 54272 ----a-w- c:\windows\system32\WsmRes.dll
2011-11-03 09:02 . 2011-11-03 09:02 40448 ----a-w- c:\windows\system32\winrs.exe
2011-11-03 09:02 . 2011-11-03 09:02 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2011-11-03 09:02 . 2011-11-03 09:02 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-11-03 09:02 . 2011-11-03 09:02 241152 ----a-w- c:\windows\system32\winrscmd.dll
2011-11-03 09:02 . 2011-11-03 09:02 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2011-11-03 09:02 . 2011-11-03 09:02 20480 ----a-w- c:\windows\system32\winrshost.exe
2011-11-03 09:02 . 2011-11-03 09:02 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2011-11-03 09:02 . 2011-11-03 09:02 201184 ----a-w- c:\windows\system32\winrm.vbs
2011-11-03 09:02 . 2011-11-03 09:02 146944 ----a-w- c:\windows\system32\wecsvc.dll
2011-11-03 09:02 . 2011-11-03 09:02 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2011-11-03 09:02 . 2011-11-03 09:02 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2011-11-03 09:02 . 2011-11-03 09:02 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2011-11-03 09:02 . 2011-11-03 09:02 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2011-11-03 09:02 . 2011-11-03 09:02 10240 ----a-w- c:\windows\system32\winrssrv.dll
2011-11-03 09:02 . 2011-11-03 09:02 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
2011-10-04 18:44 . 2006-11-02 08:11 40960 ----a-w- c:\windows\system32\cliconfg.rll
2011-10-04 18:43 . 2006-11-02 06:37 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-10-04 18:41 . 2009-04-13 01:39 102400 ----a-w- c:\windows\system32\stacsv.exe
2011-10-04 18:41 . 2009-04-13 01:38 4947968 ----a-w- c:\windows\system32\stacgui.cpl
2011-10-04 18:41 . 2009-04-13 01:38 1601536 ----a-w- c:\windows\system32\stlang.dll
2011-10-04 18:41 . 2008-02-21 12:12 90112 ----a-w- c:\windows\system32\snymsico.dll
2011-10-04 18:41 . 2008-02-21 11:49 5976064 ----a-w- c:\windows\system32\SETE54F.tmp
2011-10-04 18:41 . 2008-02-21 11:49 520192 ----a-w- c:\windows\system32\SETDD79.tmp
2011-10-04 18:41 . 2008-02-21 11:47 430080 ----a-w- c:\windows\system32\PRODUCTRED.scr
2011-10-04 18:41 . 2009-06-16 19:59 151552 ----a-w- c:\windows\system32\nvcod155.dll
2011-10-04 18:41 . 2009-01-30 13:12 135168 ----a-w- c:\windows\system32\nvcod138.dll
2011-10-04 18:41 . 2008-02-21 12:12 167936 ----a-w- c:\windows\system32\nvccoin.dll
2011-10-04 18:41 . 2008-02-21 11:49 36864 ----a-w- c:\windows\system32\nvcod100.dll
2011-10-04 18:41 . 2008-02-21 12:12 684032 ----a-w- c:\windows\system32\NETw4c32.dll
2011-10-04 18:41 . 2008-02-21 12:12 2772992 ----a-w- c:\windows\system32\NETw4r32.dll
2011-10-04 18:41 . 2008-02-21 04:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-10-04 18:41 . 2008-02-21 04:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-10-04 18:41 . 2008-02-21 04:32 1060864 ----a-w- c:\windows\system32\MFC71.DLL
2011-10-04 18:41 . 2007-06-06 14:38 237568 ----a-w- c:\windows\system32\KPDPMUI.dll
2011-10-04 18:41 . 2007-06-06 14:38 344064 ----a-w- c:\windows\system32\KPDPM.dll
2011-10-04 18:41 . 2007-06-06 14:18 196608 ----a-w- c:\windows\system32\KPDRES.DLL
2011-10-04 18:41 . 2008-02-21 04:34 126976 ----a-w- c:\windows\system32\Imsmudlg.exe
2011-10-04 18:41 . 2004-08-09 12:04 73728 ----a-w- c:\windows\system32\ISUSPM.cpl
2011-10-04 18:40 . 2006-11-02 08:42 65536 ----a-w- c:\windows\system32\drivers\IPMIDrv.sys
2011-10-04 18:40 . 2006-11-02 10:25 200704 ----a-w- c:\windows\system32\drivers\e1e6032.sys
2011-10-04 18:40 . 2006-11-02 08:55 12288 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-10-04 18:40 . 2006-11-02 08:51 20480 ----a-w- c:\windows\system32\drivers\flpydisk.sys
2011-10-04 18:40 . 2006-11-02 08:30 40960 ----a-w- c:\windows\system32\drivers\amdk8.sys
2011-10-04 18:40 . 2008-02-21 12:12 811008 ----a-w- c:\windows\system32\cximage.dll
2011-10-04 18:40 . 2008-02-21 12:12 36864 ----a-w- c:\windows\system32\CtCamMgr.dll
2011-10-04 18:38 . 2006-11-02 10:25 573440 ----a-w- c:\windows\system32\atiumdva.dll
2011-10-04 18:38 . 2006-11-02 10:25 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-10-04 18:38 . 2009-04-13 01:39 647168 ----a-w- c:\windows\system32\aestecap.dll
2011-10-04 18:38 . 2009-04-13 01:39 131072 ----a-w- c:\windows\system32\aestacap.dll
2011-10-04 18:19 . 2008-02-21 12:12 90112 ----a-w- c:\windows\CtDrvIns.exe
2011-09-12 23:14 . 2011-10-16 21:17 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{36D3B948-6529-481A-BA8E-C690C6DA1E72}\mpengine.dll
2011-09-06 13:30 . 2011-10-16 21:05 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 06:53 . 2011-05-16 03:04 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-10-04 159744]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Google Desktop Search"="c:\program files\google\google desktop search\googledesktop.exe" [2008-02-21 1838592]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2011-10-04 221184]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-08-03 309352]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
c:\users\Administrator.TMoss-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"disableCAD"= 1 (0x1)
"DisableStatusMessages"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 05:04 86528 ----a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
2007-04-17 04:50 49168 ----a-w- c:\program files\Fingerprint Reader Suite\launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
R1 MpKsl1df80b25;MpKsl1df80b25;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BD577C2D-8561-4964-B5E2-CC8198010596}\MpKsl1df80b25.sys [x]
R1 MpKsld7277ef1;MpKsld7277ef1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D99EA361-4946-4B19-A3CE-DFEBA5C663E0}\MpKsld7277ef1.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\ianvstor.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-12-03 73728]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-11-28 55128]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
S2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 NETwLv32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETwLv32.sys [2010-10-07 6639616]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWMBR
*NewlyCreated* - ASWMONFLT
*NewlyCreated* - ASWRDR
*NewlyCreated* - ASWSNX
*NewlyCreated* - ASWSP
*NewlyCreated* - ASWTDI
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
rsmsvcs REG_MULTI_SZ ntmssvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-04 01:58]
.
2011-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-04 01:58]
.
2011-11-23 c:\windows\Tasks\User_Feed_Synchronization-{CEB27D76-DC5F-4C92-96A8-72AEA390B0B6}.job
- c:\windows\system32\msfeedssync.exe [2011-03-17 17:11]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.4Loot.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Administrator.TMoss-PC\AppData\Roaming\Mozilla\Firefox\Profiles\wplzfdlp.default\
FF - prefs.js: browser.startup.homepage -
www.4Loot.com
FF - user.js: accessibility.blockautorefresh - true
FF - user.js: app.update.auto - false
FF - user.js: app.update.disable_button.showUpdateHistory - false
FF - user.js: app.update.lastUpdateTime.addon-background-update-timer - 1321938616
FF - user.js: app.update.lastUpdateTime.background-update-timer - 1321938856
FF - user.js: app.update.lastUpdateTime.blocklist-background-update-timer - 1321938736
FF - user.js: app.update.lastUpdateTime.search-engine-update-timer - 1321963275
FF - user.js: browser.cache.disk.capacity - 1048576
FF - user.js: browser.cache.disk.smart_size.first_run - false
FF - user.js: browser.cache.disk.smart_size_cached_value - 1048576
FF - user.js: browser.display.use_document_fonts - 0
FF - user.js: browser.migration.version - 5
FF - user.js: browser.places.importBookmarksHTML - false
FF - user.js: browser.places.smartBookmarksVersion - 2
FF - user.js: browser.preferences.advanced.selectedTabIndex - 2
FF - user.js: browser.privatebrowsing.autostart - true
FF - user.js: browser.rights.3.shown - true
FF - user.js: browser.shell.checkDefaultBrowser - false
FF - user.js: browser.startup.homepage_override.buildID - 20111104165243
FF - user.js: browser.startup.homepage_override.mstone - rv:8.0
FF - user.js: browser.urlbar.autocomplete.enabled - false
FF - user.js: dom.event.contextmenu.enabled - false
FF - user.js: extensions.blocklist.pingCountTotal - 4
FF - user.js: extensions.blocklist.pingCountVersion - 4
FF - user.js: extensions.bootstrappedAddons - {}
FF - user.js: extensions.databaseSchema - 6
FF - user.js: extensions.enabledAddons - {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}:5.0
FF - user.js: extensions.installCache - [{\name\:\app-global\,\addons\:{\{972ce4c6-7e08-4474-a285-3208198ce6fd}\:{\descriptor\:\c:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\,\mtime\:1321144850386},\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\:{\descriptor\:\c:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\,\mtime\:1321631140430}}},{\name\:\app-profile\,\addons\:{\{FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}\:{\descriptor\:\c:\\\\Users\\\\Administrator.TMoss-PC\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\wplzfdlp.default\\\\extensions\\\\{FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}.xpi\,\mtime\:1321805383513}}}]
FF - user.js: extensions.lastAppVersion - 8.0
FF - user.js: extensions.lastPlatformVersion - 8.0
FF - user.js: extensions.pendingOperations - false
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: font.default.x-user-def - serif
FF - user.js: font.language.group - x-armn
FF - user.js: font.minimum-size.x-user-def - 12
FF - user.js: font.name.serif.x-western - Arial
FF - user.js: font.size.fixed.x-user-def - 14
FF - user.js: font.size.variable.x-user-def - 14
FF - user.js: general.skins.selectedSkin - Aeon_Clouds
FF - user.js: idle.lastDailyNotification - 1321940893
FF - user.js: intl.accept_languages - en-us
FF - user.js: intl.charset.default - armscii-8
FF - user.js: intl.charsetmenu.browser.cache - windows-1250, UTF-16, ISO-8859-1, UTF-8
FF - user.js: network.cookie.prefsMigrated - true
FF - user.js: places.database.lastMaintenance - 1321940893
FF - user.js: places.history.expiration.transient_current_max_pages - 64340
FF - user.js: plugin.disable_full_page_plugin_for_types -
FF - user.js: pref.advanced.javascript.disable_button.advanced - false
FF - user.js: pref.browser.language.disable_button.remove - false
FF - user.js: pref.browser.language.disable_button.up - false
FF - user.js: pref.downloads.disable_button.edit_actions - false
FF - user.js: pref.general.disable_button.default_browser - false
FF - user.js: pref.privacy.disable_button.view_passwords - false
FF - user.js: pref.privacy.disable_button.view_passwords_exceptions - false
FF - user.js: privacy.sanitize.migrateFx3Prefs - true
FF - user.js: security.OCSP.disable_button.managecrl - false
FF - user.js: security.disable_button.openCertManager - false
FF - user.js: security.disable_button.openDeviceManager - false
FF - user.js: services.sync.clients.lastSync - 0
FF - user.js: services.sync.clients.lastSyncLocal - 0
FF - user.js: services.sync.migrated - true
FF - user.js: services.sync.tabs.lastSync - 0
FF - user.js: services.sync.tabs.lastSyncLocal - 0
FF - user.js: storage.vacuum.last.index - 1
FF - user.js: storage.vacuum.last.places.sqlite - 1321450834
FF - user.js: toolkit.telemetry.prompted - true
FF - user.js: urlclassifier.keyupdatetime.hxxps://sb-ssl.google.com/safebrowsing/newkey - 1324395828
FF - user.js: xpinstall.whitelist.add -
FF - user.js: xpinstall.whitelist.add.103 -
FF - user.js: xpinstall.whitelist.add.36 -
FF - user.js: browser.startup.homepage -
www.4Loot.com
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DellSupportCenter - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-!SASWinLogon - c:\program files\SUPERAntiSpyware\SASWINLO.DLL
SafeBoot-IMFservice
MSConfigStartUp-Advanced SystemCare 5 - c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-04 15:11
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{CA6319C0-31B7-401E-A518-A07C3DB8F777}"=hex:51,66,7a,6c,4c,1d,38,12,ae,1a,70,
ce,85,7f,70,05,da,0e,e3,3c,38,e6,b3,63
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,
36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:ba,6e,ee,09,f0,99,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,75,ac,4d,b2,b0,9e,6a,4e,9e,07,37,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,75,ac,4d,b2,b0,9e,6a,4e,9e,07,37,\
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,3b,1b,a1,de,0c,
39,57,19,bf,59,81,17,5f,cc,20,e0,8d,54
"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,3b,1b,9a,57,14,
28,9b,14,8c,0b,9e,e6,df,d4,3f,c5,d5,02
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,82,11,
e5,68,9c,45,06,a5,34,c9,b5,2e,93,15,18
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c2,fe,
a7,57,92,bb,59,a6,e2,5f,fc,ce,4f,f5,14
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,14,cb,
02,9f,b8,e8,0a,bf,99,a5,0b,8b,6b,fd,d8
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,3b,1b,48,f1,4c,
b0,ef,51,fa,05,99,3c,90,4c,50,31,33,ec
"{CA6319C0-31B7-401E-A518-A07C3DB8F777}"=hex:51,66,7a,6c,4c,1d,3b,1b,d0,05,77,
d0,85,61,75,08,bf,17,ff,20,3a,fd,b7,6c
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1c,dc,
c1,77,f4,30,0b,a6,7b,c3,79,c6,80,c8,b2
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,60,16,
ce,78,45,0d,08,bb,a2,1d,1f,df,57,34,5b
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:fe,46,4e,3e,9b,a1,cc,01
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,b1,f2,e9,91,39,02,4b,bc,fb,09,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,b1,f2,e9,91,39,02,4b,bc,fb,09,\
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1033_1033_MTOC_WINWORD_COL\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\wordpad.exe"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.avi"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.contact\UserChoice]
@Denied: (2) (Administrator)
"Progid"="contact_wab_auto_file"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.HxH\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\Winword.exe"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\Winword.exe"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M3U"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-263534564-1765753400-3299622415-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
- - - - - - - > 'Explorer.exe'(1808)
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
Completion time: 2011-12-04 15:16:57
ComboFix-quarantined-files.txt 2011-12-04 20:16
.
Pre-Run: 90,386,669,568 bytes free
Post-Run: 90,321,354,752 bytes free
.
- - End Of File - - 14EBD6F94C91D7672A2E3C7869850152