Hi,
First a quick update of my computer status. After running the 3 recommended tools and installed BitDefender AV my computer has not crashed. Many thanks.
One thing that is a little unsettling about ComboFix is that it deleted about 5 of my own files, that is, these are files that I created by myself. Why?
And here's the ComboFix log (please note, I've edited [myUserName] to [justme] )
ComboFix 14-05-13.01 - justme 05/14/2014 17:52:28.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3933.1241 [GMT -4:00]
Running from: c:\users\justme\Downloads\ComboFix.exe
AV: Bitdefender Antivirus *Enabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Bitdefender Firewall *Enabled* {A23392FD-84B9-F933-2C71-81E751F6EF46}
SP: Bitdefender Antispyware *Enabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1400034555.bdinstall.bin
c:\users\justme\1of3.txt
c:\users\justme\2013.ods
c:\users\justme\2013.txt
c:\users\justme\2013.xls
c:\users\justme\305.txt
c:\users\justme\5_cn.png
c:\users\justme\811.txt
c:\users\justme\coreftplite.exe
c:\users\justme\fciv.exe
c:\users\justme\g2mdlhlpx.exe
c:\users\justme\hosts
c:\users\justme\KnowledgeNoteBook_g2v1mw.exe
c:\users\justme\KnowledgeNoteBook_g2v45_win7.exe
c:\users\justme\KnowledgeNoteBook_g2v45a.exe
c:\users\justme\KnowledgeNoteBook_g2v45buyD.exe
c:\users\justme\KnowledgeNoteBook_g2v45buyV.exe
c:\users\justme\KnowledgeNoteBook_g2v45trial2.exe
c:\users\justme\KnowledgeNoteBook_g2v55bd.exe
c:\users\justme\KnowledgeNoteBook_g2v55cn_s.exe
c:\users\justme\KnowledgeNoteBook_g2v55cn1.exe
c:\users\justme\KnowledgeNoteBook_g2v55p.exe
c:\users\justme\KnowledgeNoteBook_g2v60p.exe
c:\users\justme\KnowledgeNoteBook_g2v60p_good.exe
c:\users\justme\KnowledgeNoteBook_g2v60v.exe
c:\users\justme\KnowledgeNoteBook_g2v65MT.exe
c:\users\Public\AlexaNSISPlugin.3520.dll
c:\windows\SysWow64\wocdsodsini.dll
.
.
((((((((((((((((((((((((( Files Created from 2014-04-14 to 2014-05-14 )))))))))))))))))))))))))))))))
.
.
2014-05-14 22:11 . 2014-05-14 22:11 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2014-05-14 22:11 . 2014-05-14 22:11 -------- d-----w- c:\users\postgres\AppData\Local\temp
2014-05-14 22:11 . 2014-05-14 22:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-14 22:11 . 2014-05-14 22:11 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-05-14 03:33 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-14 03:33 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-14 03:33 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-14 03:33 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-14 03:24 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll
2014-05-14 03:24 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-05-14 03:24 . 2014-03-25 02:43 14175744 ----a-w- c:\windows\system32\shell32.dll
2014-05-14 03:09 . 2014-05-14 03:09 76944 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2014-05-14 03:09 . 2014-05-14 03:09 74512 ----a-w- c:\windows\system32\bdsandboxuiskin32.dll
2014-05-14 02:36 . 2013-11-04 20:47 82824 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2014-05-14 02:36 . 2013-11-04 20:47 74512 ----a-w- c:\windows\SysWow64\bdsandboxuiskin32.dll
2014-05-14 02:36 . 2013-02-22 23:46 93600 ----a-w- c:\windows\system32\drivers\BdfNdisf6.sys
2014-05-14 02:36 . 2013-12-02 16:58 635392 ----a-w- c:\windows\system32\drivers\avckf.sys
2014-05-14 02:36 . 2013-12-02 16:56 893440 ----a-w- c:\windows\system32\drivers\avc3.sys
2014-05-14 02:34 . 2014-05-14 02:34 -------- d-----w- c:\users\justme\AppData\Roaming\Bitdefender
2014-05-14 02:34 . 2013-08-13 17:38 3271472 ---ha-w- C:\bdr-bz01
2014-05-14 02:29 . 2014-05-14 02:38 -------- d-----w- c:\programdata\Bitdefender
2014-05-14 02:29 . 2013-11-04 20:47 84848 ----a-w- c:\windows\system32\BDSandBoxUISkin.dll
2014-05-14 02:29 . 2013-11-04 20:46 34384 ----a-w- c:\windows\system32\BDSandBoxUH.dll
2014-05-14 02:29 . 2013-08-23 17:48 150256 ----a-w- c:\windows\system32\drivers\gzflt.sys
2014-05-14 02:29 . 2013-08-07 17:46 389240 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-05-14 02:13 . 2014-05-14 02:13 -------- d-----w- c:\program files (x86)\Seagate
2014-05-13 22:17 . 2014-05-14 21:09 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-13 22:17 . 2014-05-13 22:17 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-13 22:17 . 2014-05-13 22:17 -------- d-----w- c:\programdata\Malwarebytes
2014-05-13 22:17 . 2014-04-03 13:51 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-13 22:17 . 2014-04-03 13:51 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-13 22:17 . 2014-04-03 13:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-05-13 21:00 . 2010-08-30 12:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-05-13 20:59 . 2014-05-13 22:04 -------- d-----w- C:\AdwCleaner
2014-05-13 20:46 . 2014-05-13 20:46 -------- d-----w- c:\windows\ERUNT
2014-05-13 12:42 . 2014-04-17 09:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1A53BA39-B8C0-40DF-BF92-CF386484F1B4}\mpengine.dll
2014-05-10 20:36 . 2013-05-06 13:13 110176 ----a-w- c:\windows\system32\klfphc.dll
2014-05-10 20:34 . 2014-05-10 20:34 -------- d-----w- c:\windows\ELAMBKUP
2014-05-10 20:34 . 2014-05-13 23:07 -------- d-----w- c:\programdata\Kaspersky Lab
2014-05-10 20:34 . 2014-05-10 20:34 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2014-05-10 20:34 . 2014-03-26 15:00 625248 ----a-w- c:\windows\system32\drivers\klif.sys
2014-05-10 20:34 . 2014-03-26 15:00 115296 ----a-w- c:\windows\system32\drivers\klflt.sys
2014-05-06 03:43 . 2014-05-14 03:36 -------- d-s---w- c:\windows\system32\CompatTel
2014-05-02 17:54 . 2014-05-02 17:54 -------- d-----w- C:\bma
2014-04-29 19:35 . 2014-04-29 19:35 -------- d-----w- c:\users\justme\AppData\Roaming\JGsoft
2014-04-29 19:35 . 2014-04-29 19:35 -------- d-----w- c:\program files\Just Great Software
2014-04-29 15:48 . 2014-04-29 19:15 -------- d-----w- c:\programdata\vedit
2014-04-29 15:47 . 2014-04-29 19:29 -------- d-----w- c:\program files (x86)\vedit
2014-04-28 20:01 . 2014-04-28 20:01 -------- d-----w- c:\program files (x86)\XML Notepad 2007
2014-04-26 23:27 . 2014-04-26 23:27 480 ----a-w- c:\windows\system32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD.tmp
2014-04-26 03:00 . 2014-05-14 02:14 -------- d-----w- c:\programdata\Package Cache
2014-04-25 01:16 . 2014-04-25 01:16 -------- d-----w- C:\E
2014-04-24 18:45 . 2014-04-25 01:11 -------- d-----w- c:\program files\Perfect Uninstaller
2014-04-22 18:34 . 2014-04-22 18:34 -------- d-----w- c:\program files (x86)\Apache Software Foundation
2014-04-21 18:38 . 2014-04-26 14:54 -------- d-----w- C:\ODBTP
2014-04-21 17:45 . 2014-04-21 17:59 -------- d-----w- C:\WWebserver with PHP 5.4.3
2014-04-21 17:09 . 2014-04-21 17:09 875472 ----a-w- c:\windows\SysWow64\msvcr110.dll
2014-04-21 17:09 . 2014-04-21 17:09 849360 ----a-w- c:\windows\system32\msvcr110.dll
2014-04-21 17:07 . 2014-04-21 17:07 -------- d-----w- c:\programdata\Logs
2014-04-21 16:07 . 2014-04-21 16:07 356 ----a-w- c:\users\justme\configPHP2.bat
2014-04-21 15:39 . 2014-04-21 15:39 368 ----a-w- c:\users\justme\configPHP.bat
2014-04-21 15:17 . 2014-04-21 15:17 -------- d-----w- c:\program files\runphp
2014-04-21 15:16 . 2014-04-21 15:43 -------- d-----w- c:\program files\IIS Express
2014-04-21 15:16 . 2014-04-21 15:18 -------- d-----w- c:\program files (x86)\IIS Express
2014-04-19 03:20 . 2014-04-26 23:11 -------- d-----w- c:\users\DefaultAppPool
2014-04-18 22:54 . 2012-06-01 05:36 192000 ----a-w- c:\windows\system32\iisRtl.dll
2014-04-18 22:54 . 2012-06-01 05:34 55296 ----a-w- c:\windows\system32\admwprox.dll
2014-04-18 22:54 . 2012-06-01 04:37 154624 ----a-w- c:\windows\SysWow64\iisRtl.dll
2014-04-18 22:54 . 2012-06-01 04:35 50688 ----a-w- c:\windows\SysWow64\admwprox.dll
2014-04-18 22:54 . 2012-06-01 05:35 60928 ----a-w- c:\windows\system32\ahadmin.dll
2014-04-18 22:54 . 2012-06-01 05:33 16896 ----a-w- c:\windows\system32\iisreset.exe
2014-04-18 22:54 . 2012-06-01 04:34 15360 ----a-w- c:\windows\SysWow64\iisreset.exe
2014-04-18 22:54 . 2012-06-01 05:39 14848 ----a-w- c:\windows\system32\wamregps.dll
2014-04-18 22:54 . 2012-06-01 04:40 10752 ----a-w- c:\windows\SysWow64\wamregps.dll
2014-04-18 22:54 . 2012-06-01 04:35 26624 ----a-w- c:\windows\SysWow64\ahadmin.dll
2014-04-18 22:54 . 2012-06-01 05:36 11264 ----a-w- c:\windows\system32\iisrstap.dll
2014-04-18 22:54 . 2012-06-01 04:37 8192 ----a-w- c:\windows\SysWow64\iisrstap.dll
2014-04-18 14:43 . 2014-04-18 14:43 -------- d-----w- c:\windows\SysWow64\BestPractices
2014-04-18 14:43 . 2014-04-18 14:43 -------- d-----w- c:\windows\system32\BestPractices
2014-04-18 14:43 . 2014-04-18 14:43 -------- d-----w- C:\inetpub
2014-04-18 14:19 . 2014-04-18 14:19 -------- d-----w- c:\program files\Microsoft
2014-04-17 18:42 . 2014-04-21 14:36 -------- d-----w- C:\php5
2014-04-16 14:20 . 2014-05-08 14:08 -------- d-----w- C:\cra360
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 03:27 . 2010-08-11 15:12 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-04-02 15:16 . 2013-01-02 02:39 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-02 15:16 . 2011-08-23 12:08 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-31 13:35 . 2010-01-28 20:23 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-26 15:00 . 2014-03-26 15:00 178272 ----a-w- c:\windows\system32\drivers\kneps.sys
2014-03-26 15:00 . 2014-03-26 15:00 458336 ----a-w- c:\windows\system32\drivers\kl1.sys
2014-03-26 15:00 . 2014-03-26 15:00 29792 ----a-w- c:\windows\system32\drivers\klim6.sys
2014-03-26 15:00 . 2014-03-26 15:00 29280 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2014-03-26 15:00 . 2014-03-26 15:00 29280 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2014-03-06 09:31 . 2014-04-12 03:44 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:59 . 2014-04-12 03:44 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-03-06 08:57 . 2014-04-12 03:44 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-03-06 08:57 . 2014-04-12 03:43 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-06 08:53 . 2014-04-12 03:43 2767360 ----a-w- c:\windows\system32\iertutil.dll
2014-03-06 08:40 . 2014-04-12 03:44 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-03-06 08:39 . 2014-04-12 03:44 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-03-06 08:32 . 2014-04-12 03:44 574976 ----a-w- c:\windows\system32\ieui.dll
2014-03-06 08:29 . 2014-04-12 03:44 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-06 08:29 . 2014-04-12 03:43 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-06 08:28 . 2014-04-12 03:44 752640 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-06 08:15 . 2014-04-12 03:43 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 08:11 . 2014-04-12 03:43 5784064 ----a-w- c:\windows\system32\jscript9.dll
2014-03-06 08:09 . 2014-04-12 03:44 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-03-06 08:03 . 2014-04-12 03:44 586240 ----a-w- c:\windows\system32\ie4uinit.exe
2014-03-06 08:02 . 2014-04-12 03:44 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-03-06 08:02 . 2014-04-12 03:44 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-06 08:01 . 2014-04-12 03:43 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56 . 2014-04-12 03:44 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 07:48 . 2014-04-12 03:44 195584 ----a-w- c:\windows\system32\msrating.dll
2014-03-06 07:46 . 2014-04-12 03:43 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-03-06 07:42 . 2014-04-12 03:44 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-03-06 07:38 . 2014-04-12 03:44 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-03-06 07:36 . 2014-04-12 03:43 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-03-06 07:21 . 2014-04-12 03:44 628736 ----a-w- c:\windows\system32\msfeeds.dll
2014-03-06 07:13 . 2014-04-12 03:44 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11 . 2014-04-12 03:43 2043904 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-06 06:53 . 2014-04-12 03:43 13551104 ----a-w- c:\windows\system32\ieframe.dll
2014-03-06 06:40 . 2014-04-12 03:43 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-03-06 06:22 . 2014-04-12 03:43 2260480 ----a-w- c:\windows\system32\wininet.dll
2014-03-06 05:58 . 2014-04-12 03:43 1400832 ----a-w- c:\windows\system32\urlmon.dll
2014-03-06 05:50 . 2014-04-12 03:43 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-03-06 05:41 . 2014-04-12 03:43 1789440 ----a-w- c:\windows\SysWow64\wininet.dll
2014-03-04 09:44 . 2014-04-09 13:16 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-09 13:16 243712 ----a-w- c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-09 13:16 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-04-09 13:16 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-09 13:16 1163264 ----a-w- c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-04-09 13:16 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-09 13:16 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-09 13:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-09 13:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-09 13:16 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-09 13:16 2048 ----a-w- c:\windows\SysWow64\user.exe
2014-03-02 15:07 . 2014-03-02 15:12 251 ----a-w- c:\program files\update.bat
2013-12-01 21:13 . 2013-12-01 21:40 2134 ----a-w- c:\program files\addDesktopIconKN_ch.bat
2013-12-01 21:12 . 2013-12-01 21:40 2125 ----a-w- c:\program files\addDesktopIconKN.bat
2013-11-27 19:39 . 2013-11-27 19:55 296 ----a-w- c:\program files\preinstall.bat
2012-09-14 13:52 . 2013-10-29 02:09 3310 ----a-w- c:\program files\Install_KN_Access.bat
2012-09-13 13:53 . 2013-10-29 02:09 1217 ----a-w- c:\program files\AddKNdesktopIcon.bat
2012-08-20 14:44 . 2012-08-20 14:44 57344 ----a-w- c:\program files\Shortcut2.exe
2010-07-01 05:15 . 2010-07-02 20:57 6823 ------w- c:\program files\canvas2image.js
2010-06-13 03:25 . 2010-05-25 21:46 1618 ------w- c:\program files\autoSaveEvery3Minutes.js
2010-06-13 03:15 . 2010-05-30 21:14 1206 ------w- c:\program files\autoSaveEveryMinute.js
2010-06-03 12:27 . 2013-10-29 02:09 172 ----a-w- c:\program files\PleaseWait.cmd
2010-05-25 03:27 . 2010-05-23 23:12 652 ------w- c:\program files\autoUpdateMay282008.js
2010-04-22 01:33 . 2013-10-29 02:09 155 ----a-w- c:\program files\KNcheck.bat
2009-03-12 20:03 . 2010-01-31 05:27 1024 ----a-w- c:\program files\showwin.exe
2005-07-04 05:11 . 2010-01-31 05:27 57344 ----a-w- c:\program files\Shortcut.exe
2006-05-03 09:06 163328 --sh--r- c:\windows\SysWOW64\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\SysWOW64\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\SysWOW64\nbDX.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2009-07-14 44544]
"ApacheTomcatMonitor6.0_Tomcat6"="c:\oc\tomcat\bin\Tomcat6w.exe" [2013-04-29 104448]
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-03-19 567888]
"Bitdefender Wallet"="c:\program files\Bitdefender\Bitdefender\pwdmanui.exe" [2014-03-15 1001536]
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-03-19 614232]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2009-08-05 244208]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-08-23 876832]
"Message Center Plus"="c:\program files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-03-19 567888]
"Bitdefender Wallet"="c:\program files\Bitdefender\Bitdefender\pwdmanui.exe" [2014-03-15 1001536]
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-03-19 614232]
.
c:\users\justme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Monitor Apache Servers.lnk - c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2013-7-10 41051]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisableLocalMachineRun"= 0 (0x0)
"DisableLocalMachineRunOnce"= 0 (0x0)
"DisableCurrentUserRun"= 0 (0x0)
"DisableCurrentUserRunOnce"= 0 (0x0)
"NoFile"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804]
Ime File REG_SZ GOOGLEPINYIN2.IME
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys;c:\windows\SYSNATIVE\Drivers\avgrkx64.sys [x]
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
R1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\system32\Drivers\avgldx64.sys;c:\windows\SYSNATIVE\Drivers\avgldx64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Railo 3.1 Server;Railo 3.1 Server;c:\program files\Railo\httpd.exe;c:\program files\Railo\httpd.exe [x]
R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [x]
R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [x]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [x]
R3 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [x]
R3 bdfwfpf_pc;bdfwfpf_pc;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [x]
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x]
R3 EraserUtilDrv11311;EraserUtilDrv11311;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
R3 ksapi64;ksapi64;c:\windows\system32\drivers\ksapi64.sys;c:\windows\SYSNATIVE\drivers\ksapi64.sys [x]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\DRIVERS\nwusbmdm_000.sys;c:\windows\SYSNATIVE\DRIVERS\nwusbmdm_000.sys [x]
R3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\DRIVERS\nwusbser_000.sys;c:\windows\SYSNATIVE\DRIVERS\nwusbser_000.sys [x]
R3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\DRIVERS\nwusbser2_000.sys;c:\windows\SYSNATIVE\DRIVERS\nwusbser2_000.sys [x]
R3 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [x]
R3 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms;c:\program files\pc-doctor\pcdsrvc_x64.pkms [x]
R3 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w [x]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [x]
R3 Prot6Flt;Prot6Flt;c:\windows\system32\DRIVERS\Prot6Flt.sys;c:\windows\SYSNATIVE\DRIVERS\Prot6Flt.sys [x]
R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [x]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [x]
R3 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 StreamingFSD;StreamingFSD;c:\programdata\Embarcadero\AppWaveBrowser\x64\StreamingFSD.sys;c:\programdata\Embarcadero\AppWaveBrowser\x64\StreamingFSD.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
R4 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe;c:\program files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe [x]
R4 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [x]
R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe [x]
R4 ColdFusion 10 .NET Service;ColdFusion 10 .NET Service;c:\coldfusion10\cfusion\jnbridge\CFDotNetsvc.exe;c:\coldfusion10\cfusion\jnbridge\CFDotNetsvc.exe [x]
R4 ColdFusion 10 Application Server;ColdFusion 10 Application Server;c:\coldfusion10\cfusion\bin\coldfusionsvc.exe;c:\coldfusion10\cfusion\bin\coldfusionsvc.exe [x]
R4 ColdFusion 10 ODBC Agent;ColdFusion 10 ODBC Agent;c:\coldfusion10\cfusion\db\slserver54\bin\swagent.exe ColdFusion 10 ODBC Agent;c:\coldfusion10\cfusion\db\slserver54\bin\swagent.exe ColdFusion 10 ODBC Agent [x]
R4 ColdFusion 10 ODBC Server;ColdFusion 10 ODBC Server;c:\coldfusion10\cfusion\db\slserver54\bin\swstrtr.exe ColdFusion 10 ODBC Server;c:\coldfusion10\cfusion\db\slserver54\bin\swstrtr.exe ColdFusion 10 ODBC Server [x]
R4 ColdFusion10JettyService;ColdFusion 10 Jetty Service;c:\coldfusion10\cfusion\jetty\jetty.exe;c:\coldfusion10\cfusion\jetty\jetty.exe [x]
R4 DDNIMSGService;DDNIMSGService;c:\program files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe;c:\program files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [x]
R4 DDNIService;DDNIService;c:\program files (x86)\DDNI\DIBS\DDNIService.exe;c:\program files (x86)\DDNI\DIBS\DDNIService.exe [x]
R4 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x]
R4 NvtlService;NovaCore SDK Service;c:\program files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe;c:\program files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [x]
R4 NWHelper;Novatel Wireless Device Helper ;c:\program files (x86)\Novatel Wireless\Drivers\NWHelper.exe;c:\program files (x86)\Novatel Wireless\Drivers\NWHelper.exe [x]
R4 ODBTPServer;ODBTP Server;c:\odbtp\odbtpsrv.exe;c:\odbtp\odbtpsrv.exe [x]
R4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [x]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x]
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys;c:\windows\SYSNATIVE\DRIVERS\ApsHM64.sys [x]
S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\system32\Drivers\avgmfx64.sys;c:\windows\SYSNATIVE\Drivers\avgmfx64.sys [x]
S1 AvgTdiA;AVG Network Redirector x64;c:\windows\system32\Drivers\avgtdia.sys;c:\windows\SYSNATIVE\Drivers\avgtdia.sys [x]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys;c:\windows\SYSNATIVE\DRIVERS\smiifx64.sys [x]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 Tomcat6;Apache Tomcat 6.0 Tomcat6;c:\oc\tomcat\bin\Tomcat6.exe;c:\oc\tomcat\bin\Tomcat6.exe [x]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [x]
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender\updatesrv.exe;c:\program files\Bitdefender\Bitdefender\updatesrv.exe [x]
S3 5U877;USB Video Device;c:\windows\system32\DRIVERS\5U877.sys;c:\windows\SYSNATIVE\DRIVERS\5U877.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x]
S3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-14 03:10 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.137\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-02 15:16]
.
2014-04-02 c:\windows\Tasks\DriverNavigator Scheduled Scan.job
- c:\program files\Easeware\DriverNavigator\DriverNavigator.exe [2014-04-01 22:56]
.
2014-05-14 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-62368681-3386562447-3805219642-1003.job
- c:\users\justme\AppData\Local\Citrix\GoToMeeting\1350\g2mupdate.exe [2014-04-09 16:52]
.
2014-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cf4dd18f3e2060.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-19 11:49]
.
2014-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cf4dd18f914aa8.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-19 11:49]
.
2014-04-29 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2013-04-06 c:\windows\Tasks\SidebarExecute.job
- c:\program files\Windows Sidebar\sidebar.exe [2011-06-23 13:25]
.
2014-05-14 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-07-09 380704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-08 365592]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-07 186904]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-08 387608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"Bdagent"="c:\program files\Bitdefender\Bitdefender\bdagent.exe" [2014-03-26 1742064]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:Tabs
mStart Page = hxxp://www.duba.com/?f=duba_lock&v=2013.50
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = expresstunnel.info:80
TCP: DhcpNameServer = 10.128.128.128
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\users\justme\AppData\Roaming\Mozilla\Firefox\Profiles\juvvssqi.default\
FF - ExtSQL: 2014-04-22 15:07;
[email protected]; c:\program files\Bitdefender\Bitdefender\Antispam32\ffpwdman
FF - ExtSQL: 2014-05-10 16:50;
[email protected]; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\
[email protected]
FF - ExtSQL: 2014-05-10 16:50;
[email protected]; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\
[email protected]
FF - ExtSQL: 2014-05-10 16:50;
[email protected]; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\
[email protected]
.
.
------- File Associations -------
.
inifile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
txtfile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
.reg=Regedit.Document
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Toolbar-!{5911488E-9D1E-40ec-8CBB-06B231CC153F} - (no file)
Wow6432Node-HKCU-Run-Mobilink3 - (no file)
SafeBoot-BsScanner
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Tesseract-OCR - c:\program files\Railo\Tesseract-OCR\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w"
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\services\MySQL]
"ImagePath"="\"c:\program files (x86)\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files (x86)\MySQL\MySQL Server 5.5\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet006\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-05-14 18:17:35
ComboFix-quarantined-files.txt 2014-05-14 22:17
.
Pre-Run: 333,665,697,792 bytes free
Post-Run: 335,219,650,560 bytes free
.
- - End Of File - - B4BCD48CE0FA950EF30D9DCEAF859FAF
5C616939100B85E558DA92B899A0FC36