Hope it doesn't make a difference, I kind of accidentally ran your recommendations out of order--my goof. I did the notepad/Combofix deal first and then went back to clear java cahce, run ccleaner (already had it) and uninstall/update the new version of java second. Again--hope it doesn't make a difference.
So, here's the results of the Combofix log:
ComboFix 11-12-10.01 - Kenton S. Lime 12/10/2011 6:41.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2048.946 [GMT -7:00]
Running from: c:\users\Kenton S. Lime\Desktop\PROGRAMS\ComboFix.exe
Command switches used :: c:\users\Kenton S. Lime\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Application Updater
c:\program files (x86)\Application Updater\config.ini
c:\program files (x86)\Common Files\Spigot
c:\program files (x86)\Common Files\Spigot\Search Settings\baidu_ff.xml
c:\program files (x86)\Common Files\Spigot\Search Settings\baidu_ie.xml
c:\program files (x86)\Common Files\Spigot\Search Settings\config.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1031.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1033.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1034.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1036.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1040.ini
c:\program files (x86)\Common Files\Spigot\Search Settings\yahoo_ff.xml
c:\program files (x86)\Common Files\Spigot\Search Settings\yahoo_ie.xml
c:\program files (x86)\Common Files\Spigot\Search Settings\yandex_ff.xml
c:\program files (x86)\Common Files\Spigot\Search Settings\yandex_ie.xml
c:\program files (x86)\Common Files\Spigot\wtxpcom\chrome.manifest
c:\program files (x86)\Common Files\Spigot\wtxpcom\components\IFBHOHelperWidgiToolbar.xpt
c:\program files (x86)\Common Files\Spigot\wtxpcom\components\IFBHOWidgiToolbar.xpt
c:\program files (x86)\Common Files\Spigot\wtxpcom\install.rdf
c:\program files (x86)\CPU Speed Pro
c:\program files (x86)\CPU Speed Pro\settings.ini
c:\programdata\Uniblue
.
.
((((((((((((((((((((((((( Files Created from 2011-11-10 to 2011-12-10 )))))))))))))))))))))))))))))))
.
.
2011-12-10 13:55 . 2011-12-10 13:55 -------- dc----w- c:\users\Default\AppData\Local\temp
2011-12-09 14:29 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43394420-49DF-411F-9D80-E3515C7EDAB6}\mpengine.dll
2011-12-06 15:48 . 2011-12-06 15:48 -------- dc----w- c:\program files (x86)\Common Files\Adobe AIR
2011-12-06 15:47 . 2011-12-06 15:47 -------- dc----w- c:\programdata\McAfee Security Scan
2011-12-06 15:47 . 2011-12-06 15:47 -------- dc----w- c:\programdata\McAfee
2011-12-06 15:47 . 2011-12-06 15:47 -------- dc----w- c:\program files (x86)\McAfee Security Scan
2011-11-29 18:07 . 2011-11-29 18:07 -------- dc----w- c:\program files (x86)\ESET
2011-11-29 00:48 . 2011-11-29 00:48 388096 -c--a-r- c:\users\Kenton S. Lime\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-29 00:48 . 2011-11-29 00:48 -------- dc----w- c:\program files (x86)\Trend Micro
2011-11-28 02:18 . 2011-11-28 11:39 -------- dc----w- c:\users\Kenton S. Lime\.thinupload
2011-11-28 02:18 . 2011-11-28 02:18 -------- dc----w- c:\windows\Sun
2011-11-25 11:54 . 2011-11-30 12:03 -------- dc----w- C:\Downloads
2011-11-25 11:54 . 2011-12-10 13:56 -------- dc----w- c:\users\Kenton S. Lime\AppData\Roaming\BitComet
2011-11-25 11:53 . 2011-11-25 11:54 -------- dc----w- c:\program files (x86)\BitComet
2011-11-25 03:38 . 2011-11-25 03:38 -------- dc----w- c:\program files\iPod
2011-11-25 03:38 . 2011-11-25 03:38 -------- dc----w- c:\program files\iTunes
2011-11-25 03:38 . 2011-11-25 03:38 -------- dc----w- c:\program files (x86)\iTunes
2011-11-25 03:36 . 2011-11-25 03:36 -------- dc----w- c:\program files (x86)\Apple Software Update
2011-11-25 03:36 . 2011-11-25 03:36 -------- dc----w- c:\program files\Common Files\Apple
2011-11-25 03:36 . 2011-11-25 03:36 -------- dc----w- c:\program files\Bonjour
2011-11-25 03:36 . 2011-11-25 03:36 -------- dc----w- c:\program files (x86)\Bonjour
2011-11-20 12:15 . 2011-11-20 12:16 -------- dc----w- C:\Intel
2011-11-20 12:14 . 2011-11-20 12:14 -------- dc----w- c:\users\KENTON~1~LIM
2011-11-20 12:08 . 2011-11-20 12:10 -------- dc----w- c:\users\Kenton S. Lime\AppData\Roaming\SystemRequirementsLab
2011-11-20 11:12 . 2011-11-20 11:15 -------- dc----w- c:\users\Kenton S. Lime\AppData\Local\IM
2011-11-20 11:12 . 2011-11-20 11:14 -------- dc----w- c:\programdata\IM
2011-11-20 11:12 . 2011-11-20 11:12 -------- dc----w- c:\programdata\IncrediMail
2011-11-20 10:15 . 2011-11-20 10:15 -------- dc----w- c:\program files\IDT
2011-11-20 10:15 . 2009-06-25 21:59 160768 -c--a-w- c:\windows\system32\AESTAC64.dll
2011-11-20 10:15 . 2009-05-21 21:57 436224 -c--a-w- c:\windows\system32\AESTEC64.dll
2011-11-20 10:15 . 2009-03-02 20:58 68608 ----a-w- c:\windows\system32\AESTAR64.dll
2011-11-20 10:15 . 2009-07-22 01:33 564224 -c--a-w- c:\windows\system32\idt64mp1.exe
2011-11-20 10:15 . 2009-07-22 01:33 450048 -c--a-w- c:\windows\sttray64.exe
2011-11-20 10:15 . 2009-07-22 01:33 3593216 -c--a-w- c:\windows\system32\stlang64.dll
2011-11-20 10:15 . 2009-07-22 01:33 12158464 -c--a-w- c:\windows\system32\idtcpl64.cpl
2011-11-20 10:15 . 2009-03-02 20:47 90624 -c--a-w- c:\windows\system32\AESTCo64.dll
2011-11-20 10:15 . 2011-11-20 10:15 -------- dc----w- c:\program files\LSI SoftModem
2011-11-20 07:50 . 2011-11-20 07:50 -------- dc----w- c:\users\Kenton S. Lime\AppData\Local\Skyrim
2011-11-19 03:34 . 2011-11-19 04:18 -------- dcsh--w- c:\windows\SysWow64\AI_RecycleBin
2011-11-19 03:34 . 2011-11-19 03:34 18944 -c--a-r- c:\users\Kenton S. Lime\AppData\Roaming\Microsoft\Installer\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}\IconBB6A16301.exe
2011-11-19 03:27 . 2011-11-19 03:27 -------- dc----w- c:\program files\Jnes 0.6
2011-11-11 11:25 . 2011-11-18 03:05 -------- dc----r- c:\users\Kenton S. Lime\Dropbox
2011-11-11 11:22 . 2011-11-20 09:14 -------- dc----w- c:\users\Kenton S. Lime\AppData\Roaming\Dropbox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 22:27 . 2011-10-18 08:37 3350 -csha-w- c:\programdata\KGyGaAvL.sys
2011-11-08 17:42 . 2011-11-08 17:42 3141120 ----a-w- c:\windows\system32\win32k.sys
2011-11-08 17:41 . 2011-11-08 17:41 1897328 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-18 08:37 . 2011-10-18 08:37 8 -csh--r- c:\programdata\CE648E5CC5.sys
2011-10-13 19:14 . 2011-10-13 19:14 162584 -c--a-w- c:\windows\system32\igfxtray.exe
2011-10-13 19:14 . 2011-10-13 19:14 510232 -c--a-w- c:\windows\system32\igfxsrvc.exe
2011-10-13 19:14 . 2011-10-13 19:14 417560 -c--a-w- c:\windows\system32\igfxpers.exe
2011-10-13 19:14 . 2011-10-13 19:14 224024 -c--a-w- c:\windows\system32\igfxext.exe
2011-10-13 19:14 . 2011-10-13 19:14 386840 -c--a-w- c:\windows\system32\hkcmd.exe
2011-10-13 19:14 . 2011-10-13 19:14 3157784 -c--a-w- c:\windows\system32\GfxUI.exe
2011-10-13 19:14 . 2011-10-13 19:14 152856 -c--a-w- c:\windows\system32\difx64.exe
2011-10-13 19:10 . 2011-10-13 19:10 90112 -c--a-w- c:\windows\system32\igfxCoIn_v2555.dll
2011-10-13 19:05 . 2011-10-13 19:05 6549504 -c--a-w- c:\windows\system32\igdumd64.dll
2011-10-13 19:05 . 2011-10-13 19:05 10629184 -c--a-w- c:\windows\system32\drivers\igdkmd64.sys
2011-10-13 19:01 . 2009-06-03 19:09 4967424 ----a-w- c:\windows\SysWow64\igdumd32.dll
2011-10-13 18:58 . 2009-06-03 19:03 571904 ----a-w- c:\windows\SysWow64\igdumdx32.dll
2011-10-13 18:57 . 2009-06-03 19:01 4722176 ----a-w- c:\windows\system32\igd10umd64.dll
2011-10-13 18:55 . 2010-08-26 02:23 4411392 -c--a-w- c:\windows\SysWow64\igd10umd32.dll
2011-10-13 18:50 . 2011-10-13 18:50 15546880 -c--a-w- c:\windows\system32\ig4icd64.dll
2011-10-13 18:42 . 2011-10-13 18:42 11405312 -c--a-w- c:\windows\SysWow64\ig4icd32.dll
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrsky.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrtrk.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrslv.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88576 -c--a-w- c:\windows\system32\igfxresn.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrrus.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrsve.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87040 -c--a-w- c:\windows\system32\igfxrtha.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrptg.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrplk.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrptb.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrnor.lrc
2011-10-13 18:38 . 2011-10-13 18:38 84992 -c--a-w- c:\windows\system32\igfxrkor.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88576 -c--a-w- c:\windows\system32\igfxrell.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrita.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrhun.lrc
2011-10-13 18:38 . 2011-10-13 18:38 86528 -c--a-w- c:\windows\system32\igfxrheb.lrc
2011-10-13 18:38 . 2011-10-13 18:38 84992 -c--a-w- c:\windows\system32\igfxrjpn.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88576 -c--a-w- c:\windows\system32\igfxrfra.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrnld.lrc
2011-10-13 18:38 . 2011-10-13 18:38 88064 -c--a-w- c:\windows\system32\igfxrdeu.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrfin.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87552 -c--a-w- c:\windows\system32\igfxrcsy.lrc
2011-10-13 18:38 . 2011-10-13 18:38 87040 -c--a-w- c:\windows\system32\igfxrdan.lrc
2011-10-13 18:38 . 2011-10-13 18:38 86528 -c--a-w- c:\windows\system32\igfxrara.lrc
2011-10-13 18:38 . 2011-10-13 18:38 83968 -c--a-w- c:\windows\system32\igfxrcht.lrc
2011-10-13 18:38 . 2011-10-13 18:38 83968 -c--a-w- c:\windows\system32\igfxrchs.lrc
2011-10-13 18:38 . 2011-10-13 18:38 122368 -c--a-w- c:\windows\system32\igfxcpl.cpl
2011-10-13 18:37 . 2011-10-13 18:37 244224 -c--a-w- c:\windows\system32\igfxpph.dll
2011-10-13 18:37 . 2011-10-13 18:37 380416 -c--a-w- c:\windows\system32\igfxTMM.dll
2011-10-13 18:37 . 2011-10-13 18:37 27648 -c--a-w- c:\windows\system32\igfxexps.dll
2011-10-13 18:37 . 2011-10-13 18:37 61952 -c--a-w- c:\windows\system32\igfxsrvc.dll
2011-10-13 18:36 . 2011-10-13 18:36 108544 -c--a-w- c:\windows\system32\hccutils.dll
2011-10-13 18:36 . 2011-10-13 18:36 119808 -c--a-w- c:\windows\system32\gfxSrvc.dll
2011-10-13 18:36 . 2011-10-13 18:36 4096 -c--a-w- c:\windows\system32\IGFXDEVLib.dll
2011-10-13 18:36 . 2011-10-13 18:36 272896 -c--a-w- c:\windows\system32\igfxdev.dll
2011-10-13 18:36 . 2011-10-13 18:36 87552 -c--a-w- c:\windows\system32\igfxrenu.lrc
2011-10-13 18:36 . 2011-10-13 18:36 142336 -c--a-w- c:\windows\system32\igfxdo.dll
2011-10-13 18:36 . 2011-10-13 18:36 830464 -c--a-w- c:\windows\system32\igfxress.dll
2011-10-13 18:32 . 2011-10-13 18:32 23552 -c--a-w- c:\windows\SysWow64\igfxexps32.dll
2011-10-13 18:31 . 2011-10-13 18:31 228864 -c--a-w- c:\windows\SysWow64\igfxdv32.dll
2011-10-13 18:30 . 2011-10-13 18:30 208896 -c--a-w- c:\windows\SysWow64\iglhsip32.dll
2011-10-13 18:30 . 2011-10-13 18:30 206336 -c--a-w- c:\windows\system32\iglhsip64.dll
2011-10-13 18:30 . 2011-10-13 18:30 188416 -c--a-w- c:\windows\system32\iglhcp64.dll
2011-10-13 18:30 . 2011-10-13 18:30 147456 -c--a-w- c:\windows\SysWow64\iglhcp32.dll
2011-10-12 04:26 . 2011-10-12 04:26 57856 ----a-w- c:\windows\system32\licmgr10.dll
2011-10-12 04:26 . 2011-10-12 04:26 44544 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-10-12 04:26 . 2011-10-12 04:26 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-10-12 04:26 . 2011-10-12 04:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-12 04:26 . 2011-10-12 04:26 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-10-12 04:26 . 2011-10-12 04:26 482816 ----a-w- c:\windows\system32\html.iec
2011-10-12 04:26 . 2011-10-12 04:26 386048 ----a-w- c:\windows\SysWow64\html.iec
2011-10-12 04:26 . 2011-10-12 04:26 1197568 ----a-w- c:\windows\system32\wininet.dll
2011-10-12 04:17 . 2011-10-12 04:17 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-12 04:17 . 2011-10-12 04:17 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 04:17 . 2011-10-12 04:17 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-10-12 04:17 . 2011-10-12 04:17 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 04:17 . 2011-10-12 04:17 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-10-12 04:17 . 2011-10-12 04:17 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-12 04:17 . 2011-10-12 04:17 288256 ----a-w- c:\windows\system32\MSNP.ax
2011-10-12 04:17 . 2011-10-12 04:17 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2011-10-12 04:17 . 2011-10-12 04:17 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 04:17 . 2011-10-12 04:17 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 04:17 . 2011-10-12 04:17 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 04:17 . 2011-10-12 04:17 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-12 04:17 . 2011-10-12 04:17 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 04:17 . 2011-10-12 04:17 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-29_00.37.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-11-29 00:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-12-10 13:58 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-12-10 13:58 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-29 00:38 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-10 13:58 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-29 00:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-09 07:02 . 2011-12-04 04:06 65856 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-12-07 05:44 64214 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-12-20 10:20 . 2011-12-07 05:44 14230 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1480369582-2274605798-2795022772-1001_UserData.bin
+ 2009-08-25 08:42 . 2011-12-04 09:48 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-25 08:42 . 2011-11-20 14:51 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-08-25 08:42 . 2011-12-04 09:48 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-08-25 08:42 . 2011-11-20 14:51 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-04 09:48 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-20 14:51 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-20 20:45 . 2011-12-10 13:59 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-20 20:45 . 2011-11-29 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:46 . 2011-11-29 01:09 80504 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-12-20 20:45 . 2011-12-10 13:59 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-20 20:45 . 2011-11-29 00:25 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-20 20:45 . 2011-12-10 13:59 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-20 20:45 . 2011-11-29 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-20 10:22 . 2011-12-10 13:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-20 10:22 . 2011-11-29 00:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-20 10:22 . 2011-12-10 13:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-20 10:22 . 2011-11-29 00:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-06 15:47 . 2011-12-06 15:47 32256 c:\windows\Installer\7ef6b7d.msi
+ 2011-06-06 19:55 . 2011-06-06 19:55 73624 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\wow_helper.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll
+ 2009-12-22 03:08 . 2011-12-10 13:57 7804 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2009-12-21 23:18 . 2011-12-09 03:25 2846 c:\windows\system32\wdi\{95c162b7-5b71-44f8-82e4-abfd3108f40f}.bin
- 2011-11-29 00:20 . 2011-11-29 00:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-12-10 13:57 . 2011-12-10 13:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-12-10 13:57 . 2011-12-10 13:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-11-29 00:20 . 2011-11-29 00:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-21 18:10 . 2011-12-07 18:05 338626 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2009-12-20 21:09 . 2011-12-09 11:57 407750 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-12-20 20:32 . 2011-05-25 01:14 270720 c:\windows\system32\MpSigStub.exe
- 2009-12-20 20:32 . 2011-05-25 02:14 270720 c:\windows\system32\MpSigStub.exe
- 2009-07-14 05:01 . 2011-11-27 11:24 444668 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-12-10 13:57 444668 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-06-06 19:55 . 2011-06-06 19:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll
+ 2011-06-06 20:45 . 2011-06-06 20:45 2318848 c:\windows\Installer\7ef6f1b.msi
+ 2011-11-29 00:47 . 2011-11-29 00:47 1402880 c:\windows\Installer\1a8152.msi
+ 2011-06-06 19:55 . 2011-06-06 19:55 2215312 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\rt3d.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 6543768 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\authplay.dll
+ 2011-06-06 19:55 . 2011-06-06 19:55 1240992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AdobeCollabSync.exe
+ 2011-06-06 19:55 . 2011-06-06 19:55 1480600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.exe
- 2009-07-14 02:34 . 2011-11-27 12:56 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-12-09 21:13 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-09-05 21:51 . 2011-09-05 21:51 13135872 c:\windows\Installer\7ef6f1c.msp
+ 2011-06-06 19:55 . 2011-06-06 19:55 24731544 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"WallpaperStyle"= 2
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-07-08 195336]
R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files (x86)\BitComet\tools\BitCometService.exe [2010-12-28 1296728]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2011-04-28 20336]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\Drivers\motoandroid.sys [x]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [x]
R3 NETw1v64;Intel(R) Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw1v64.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 Prot6Flt;Prot6Flt;c:\windows\system32\DRIVERS\Prot6Flt.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2011-03-23 33184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2011-03-23 21328]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-06-16 249648]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-03-02 89600]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2011-06-01 821080]
S2 MotoHelper;MotoHelper Service;c:\program files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-04-26 223088]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1480369582-2274605798-2795022772-1001Core.job
- c:\users\Kenton S. Lime\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-01 13:19]
.
2011-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1480369582-2274605798-2795022772-1001UA.job
- c:\users\Kenton S. Lime\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-01 13:19]
.
2011-12-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1480369582-2274605798-2795022772-1001.job
- c:\program files (x86)\Real\RealUpgrade\realupgrade.exe [2011-08-11 22:22]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-10-13 162584]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-10-13 386840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-10-13 417560]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredimail.com/mb59?u=92260411316914272
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;192.168.*.*;*.local
IE: &D&ownload &with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddAllLink.htm
IE: Copy to &Lightning Note - c:\program files (x86)\Corel\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Open with WordPerfect - c:\program files (x86)\Corel\WordPerfect Office X5\Programs\WPLauncher.hta
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{B99CB406-3B0C-4FCA-8D3B-3D9A6DEE8328}\26C61636B696E686F6C6C69777F6F646D27657563747: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Kenton S. Lime\AppData\Roaming\Mozilla\Firefox\Profiles\f89i1o35.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=hp
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=642886&p=
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs
*/
FF - user.js: app.update.lastUpdateTime.addon-background-update-timer - 1316113400
FF - user.js: app.update.lastUpdateTime.background-update-timer - 1316113640
FF - user.js: app.update.lastUpdateTime.blocklist-background-update-timer - 1316113520
FF - user.js: app.update.lastUpdateTime.search-engine-update-timer - 1316113280
FF - user.js: browser.bookmarks.restore_default_bookmarks - false
FF - user.js: browser.cache.disk.capacity - 1048576
FF - user.js: browser.cache.disk.smart_size.first_run - false
FF - user.js: browser.cache.disk.smart_size_cached_value - 1048576
FF - user.js: browser.download.lastDir - c:\\Users\\Kenton S. Lime\\Pictures\\b\\Raff-Ruse
FF - user.js: browser.migration.version - 5
FF - user.js: browser.places.smartBookmarksVersion - 2
FF - user.js: browser.rights.3.shown - true
FF - user.js: browser.search.defaultenginename - Yahoo
FF - user.js: browser.search.param.yahoo-fr - chr-greentree_ff&type=642886
FF - user.js: browser.search.selectedEngine - Yahoo
FF - user.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=hp
FF - user.js: browser.startup.homepage_override.buildID - 20110902133214
FF - user.js: browser.startup.homepage_override.mstone - rv:6.0.2
FF - user.js: browser.syncPromoViewsLeft - 0
FF - user.js: browser.taskbar.lastgroupid - Mozilla.Firefox.6.0.2
FF - user.js: extensions.blocklist.pingCountTotal - 3
FF - user.js: extensions.blocklist.pingCountVersion - 3
FF - user.js: extensions.bootstrappedAddons - {}
FF - user.js: extensions.databaseSchema - 4
FF - user.js: extensions.enabledAddons - {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3,{972ce4c6-7e08-4474-a285-3208198ce6fd}:6.0.2
FF - user.js: extensions.installCache - [{\name\:\winreg-app-global\,\addons\:{\
[email protected]\:{\descriptor\:\c:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\,\mtime\:1249808016692},\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\:{\descriptor\:\c:\\\\Program Files (x86)\\\\Adobe\\\\Adobe Contribute CS5\\\\Plugins\\\\FirefoxPlugin\\\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\,\mtime\:1313106896190},\{ABDE892B-13A8-4d1b-88E6-365A6E755758}\:{\descriptor\:\c:\\\\ProgramData\\\\Real\\\\RealPlayer\\\\BrowserRecordPlugin\\\\Firefox\\\\Ext\,\mtime\:1316119510933}}},{\name\:\app-global\,\addons\:{\{972ce4c6-7e08-4474-a285-3208198ce6fd}\:{\descriptor\:\c:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\,\mtime\:1315795338052}}},{\name\:\winreg-app-user\,\addons\:{\{D6F92668-6844-4F05-9502-8941F43B531D}\:{\descriptor\:\c:\\\\Users\\\\Kenton S. Lime\\\\AppData\\\\Local\\\\{D6F92668-6844-4F05-9502-8941F43B531D}\,\mtime\:1286575876662}}}]
FF - user.js: extensions.lastAppVersion - 6.0.2
FF - user.js: extensions.lastPlatformVersion - 6.0.2
FF - user.js: extensions.pendingOperations - false
FF - user.js: idle.lastDailyNotification - 1315799333
FF - user.js: intl.charsetmenu.browser.cache - ISO-8859-1, UTF-8
FF - user.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=642886&p=
FF - user.js: network.cookie.prefsMigrated - true
FF - user.js: places.database.lastMaintenance - 1315799333
FF - user.js: places.history.expiration.transient_current_max_pages - 93591
FF - user.js: privacy.sanitize.migrateFx3Prefs - true
FF - user.js: storage.vacuum.last.index - 0
FF - user.js: storage.vacuum.last.places.sqlite - 1315799333
FF - user.js: urlclassifier.keyupdatetime.hxxps://sb-ssl.google.com/safebrowsing/newkey - 1318387376
FF - user.js: xpinstall.whitelist.add -
FF - user.js: xpinstall.whitelist.add.36 -
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
c:\program files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
**************************************************************************
.
Completion time: 2011-12-10 07:06:13 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-10 14:06
ComboFix2.txt 2011-12-03 05:25
ComboFix3.txt 2011-11-29 00:46
.
Pre-Run: 172,533,374,976 bytes free
Post-Run: 172,729,405,440 bytes free
.
- - End Of File - - 0D2A62C8154C40F57AA567D47AA4F2CD
I dropped the notepad txt file (with what was pasted on it) before running--although Combofix had to download an update before the real scan began. I can't make heads or tails of the log info, so I suppose I'll leave it for you to tell me if it did any good.
I'll keep my eye out on my CPU activity as I have been--it still has fits, but it's not a constant thing anymore, which is a step in the right direction. If anything, it'll just run really high for an hour or two, tops, before settling back down again and rnning normal. For instance, right now it's hovering between 15-20%; RAM at 63% (steady). I've taken screenshots of taskmanager before when the CPU runs hot--really nothing much to speak of in terms of processes. But I'll take more screencaps again in the future when/if it happens and post them here.
Again, appreciate your efforts, sir! You're doing God's work.