--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D298}]
2013-02-04 03:21330160----a-w-c:\program files (x86)\QvodPlayer\QvodExtend\5.0.83.0\QvodExtend_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ .netdiskExt0]
@="{8A8BC1BD-D897-4CE7-9F60-F93990548F3D}"
[HKEY_CLASSES_ROOT\CLSID\{8A8BC1BD-D897-4CE7-9F60-F93990548F3D}]
2013-02-19 03:582661528----a-w-c:\users\DXK\AppData\Roaming\baidu\BaiduYun\NetdiskExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ .netdiskExt1]
@="{6E2D25A2-5272-4B77-9A1E-6BE1AA5CFCEE}"
[HKEY_CLASSES_ROOT\CLSID\{6E2D25A2-5272-4B77-9A1E-6BE1AA5CFCEE}]
2013-02-19 03:582661528----a-w-c:\users\DXK\AppData\Roaming\baidu\BaiduYun\NetdiskExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ .netdiskExt2]
@="{24606D69-91E1-4370-BA41-53174339C1C3}"
[HKEY_CLASSES_ROOT\CLSID\{24606D69-91E1-4370-BA41-53174339C1C3}]
2013-02-19 03:582661528----a-w-c:\users\DXK\AppData\Roaming\baidu\BaiduYun\NetdiskExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-06-03 19:41261744----a-w-c:\users\DXK\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-06-03 19:41261744----a-w-c:\users\DXK\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-06-03 19:41261744----a-w-c:\users\DXK\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58133840----a-w-c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DownloadIcon]
@="{A8502600-B272-4F68-A67B-A0305D46D298}"
[HKEY_CLASSES_ROOT\CLSID\{A8502600-B272-4F68-A67B-A0305D46D298}]
2013-02-04 03:21330160----a-w-c:\program files (x86)\QvodPlayer\QvodExtend\5.0.83.0\QvodExtend_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36164016----a-w-c:\users\DXK\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36164016----a-w-c:\users\DXK\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36164016----a-w-c:\users\DXK\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36164016----a-w-c:\users\DXK\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-04-16 20:10776144----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-04-16 20:10776144----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-04-16 20:10776144----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-04-16 20:10776144----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [N/A]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"CCBCertificate"="c:\program files\CCBComponents\DMWZ\CCBCertificate.exe" [2012-10-31 717728]
"wdcertm_ccb"="c:\windows\system32\WatchData\Watchdata CCB OCL CSP v3.2\WDCertM_CCB.exe" [2012-09-13 1229192]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2013-01-16 1425408]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
.
------- 而外的扫描 -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.snap.do/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=e64745ae-910c-48ee-9795-84c3fd9cfa99&searchtype=ds&q={searchTerms}&installDate=25/04/2013
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &使用115优蛋 3下载 - c:\program files (x86)\115\UDown\getUrl.htm
IE: &使用115优蛋 3下载全部链接 - c:\program files (x86)\115\UDown\getAllUrl.htm
IE: Download by easyMule - c:\program files (x86)\easyMule\IE2EM.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: 使用迅雷精简版下载 - c:\program files (x86)\Thunder Network\MiniThunder\BHO\minixlgeturl.htm
IE: 使用迅雷精简版下载全部链接 - c:\program files (x86)\Thunder Network\MiniThunder\BHO\minixlgetAllurl.htm
IE: 导出到 Microsoft Excel(&X) - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: 添加为阿里旺旺表情 - c:\program files (x86)\AliWangWang\7.20.12C\AddNewEmotion.htm
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: ccb.cn\b2b
Trusted Zone: ccb.com\*
Trusted Zone: ccb.com\www
Trusted Zone: ccb.com.cn\*
Trusted Zone: ccb.com.cn\ca2
Trusted Zone: ccb.com.cn\ca3
Trusted Zone: ccb.com.cn\ibsbjstar
Trusted Zone: ccb.com.cn\mybank
Trusted Zone: ecitic.com
Trusted Zone: ecitic.com\b2c.bank
Trusted Zone: ecitic.com\creditcard
Trusted Zone: ecitic.com\e.bank
Trusted Zone: ecitic.com\enterprise.bank
Trusted Zone: icbc.com.cn
Trusted Zone: taobao.com
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{5351E026-3925-4166-9A7B-6420A249B55A}: NameServer = 216.146.35.240,216.146.36.240,192.168.1.1
TCP: Interfaces\{DED27151-0FDE-42A2-BCE8-EFB48BB51C06}: NameServer = 192.168.1.1
TCP: Interfaces\{DED27151-0FDE-42A2-BCE8-EFB48BB51C06}\4496E676E2C4F6E23557E6E2755696: NameServer = 192.168.1.1
TCP: Interfaces\{DED27151-0FDE-42A2-BCE8-EFB48BB51C06}\A69616E676368656E676: NameServer = 218.2.2.2,218.4.4.4
DPF: {BC878AFA-767A-47D8-B61E-AD96F210833A} - hxxps://mybank.icbc.com.cn/icbc/newperbank/icbcEnvCtrl.cab
DPF: {C391E12A-EAF1-45F1-8425-6E513C0D553C} - hxxps://pbank.95559.com.cn/personbank/ocx/x6432.cab
FF - ProfilePath - c:\users\DXK\AppData\Roaming\Mozilla\Firefox\Profiles\yooqx1et.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3290973&CUI=UN10031956291469529&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://
www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - ExtSQL: !HIDDEN! 2013-01-14 21:34;
50ef4ddd94086@50ef4ddd940c0.com; c:\users\DXK\AppData\Roaming\Mozilla\Firefox\Profiles\yooqx1et.default\extensions\
50ef4ddd94086@50ef4ddd940c0.com
FF - user.js: general.useragent.extra.brc - BRI/1
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{117752a6-0a02-4048-a184-55e95a55e47f} - (no file)
BHO-{47CEEE9C-3B9B-492C-95CA-1AC3A99D154C} - (no file)
BHO-{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} - c:\program files (x86)\Tencent\QQPCMgr\7.2.7224.210\TSWebMon.dat
BHO-{E8B180DB-11F7-5680-4C4B-58A23338278C} - c:\programdata\Browse2save\50ef4ddd9421b.dll
BHO-{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - (no file)
BHO-{EEE6C35C-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-10 - (no file)
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll
Toolbar-10 - (no file)
AddRemove-AlipaySecControl - c:\windows\system32\aliedit\3.3.0.0\uninst.exe
AddRemove-MixiDJ_V18 Toolbar - c:\program files (x86)\MixiDJ_V18\uninstall.exe
AddRemove-SearchProtect - c:\program files (x86)\SearchProtect\bin\uninstall.exe
AddRemove-Ziperello - c:\program files (x86)\Ziperello\uninst.exe
AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\Browse2save\uninstall.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
AddRemove-UnityWebPlayer - c:\users\DXK\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90,
43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87
"{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}"=hex:51,66,7a,6c,4c,1d,38,12,bd,d8,1e,
0e,73,28,d7,05,f8,29,f8,9d,23,88,85,5a
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}"=hex:51,66,7a,6c,4c,1d,38,12,0c,e0,e4,
3d,b8,cc,34,0e,c3,b9,18,39,ba,81,ae,74
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}"=hex:51,66,7a,6c,4c,1d,38,12,00,8b,83,
81,be,a2,af,06,dc,3a,a7,82,b5,e8,7d,4f
"{889D2FEB-5411-4565-8998-1DD2C5261283}"=hex:51,66,7a,6c,4c,1d,38,12,85,2c,8e,
8c,23,1a,0b,00,f6,8e,5e,92,c0,78,56,97
"{A8502600-B272-4F68-A67B-A0305D46D297}"=hex:51,66,7a,6c,4c,1d,38,12,6e,25,43,
ac,40,fc,06,0a,d9,6d,e3,70,58,18,96,83
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f,
aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04
"{C37F9D60-975D-41F2-A745-4DC934D319AA}"=hex:51,66,7a,6c,4c,1d,38,12,0e,9e,6c,
c7,6f,d9,9c,04,d8,53,0e,89,31,8d,5d,be
"{C8CBC109-B04A-4DDA-956E-BFFE0360DADD}"=hex:51,66,7a,6c,4c,1d,38,12,67,c2,d8,
cc,78,fe,b4,08,ea,78,fc,be,06,3e,9e,c9
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{F30648AB-3E9F-8736-6C03-D90E16EA1500}"=hex:51,66,7a,6c,4c,1d,38,12,c5,4b,15,
f7,ad,70,58,c2,13,15,9a,4e,13,b4,51,14
"{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84,
f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:6f,67,c8,d6,4f,00,cd,01
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\ACD Systems\EditLib\Presets\+R *2*]
"加亮阴影"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,45,78,70,6f,73,75,72,65,4c,65,\
"上次使用"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,45,78,70,6f,73,75,72,65,4c,65,\
"调暗"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,3c,
63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,45,78,70,6f,73,75,72,65,4c,65,76,\
"只是调和"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,45,78,70,6f,73,75,72,65,4c,65,\
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\ACD Systems\EditLib\Presets\陙≧輋IQ *2*]
"提高对比度"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,
3e,3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,45,78,70,6f,73,75,72,65,41,\
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\ACD Systems\EditLib\Presets\翀jR *2*]
"上次使用"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,43,72,6f,70,3c,2f,6e,61,6d,65,\
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\ACD Systems\EditLib\Presets\宼e'Y\ *2*]
"1/2 大小"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
"1024x768"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
"640x480"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
"800x600"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
"上次使用"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
"双倍大小"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,52,65,73,69,7a,65,3c,2f,6e,61,\
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\Microsoft\Office\12.0\Common\Open Find\Microsoft Office Word\Settings\Sb*_]
"ClientGUID"=hex:ff,ce,9d,e9,f3,bd,db,49,af,8a,6e,06,55,fa,7a,c3
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.xmp"
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000_Classes\.*?柼扂e鷈6e剉颯憉噀鯪]
@Allowed: (Read) (RestrictedCode)
@="AliFileCheck.File"
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000_Classes\Applications\YoukuDesktop.exe\shell\O(uOw憿[7b飠 *Sb*_\command]
@="\"c:\\Program Files (x86)\\YouKu\\YoukuClient\\YoukuDesktop.exe\" iku://|explorer|%1|"
.
[HKEY_USERS\S-1-5-21-1906198180-1849361612-3852044266-1000_Classes\SystemFileAssociations\.kux\Shell\O(uOw憿[7b飠 *Sb*_\Command]
@="\"c:\\Program Files (x86)\\YouKu\\YoukuClient\\YoukuDesktop.exe\" iku://|explorer|%1|"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:bb,cd,81,c1,f6,21,58,87,bf,1e,30,df,15,2d,02,c6,f1,85,1d,29,c6,
68,3a,c1,9c,55,34,bb,39,89,34,ec,e9,96,8a,ac,78,81,12,02,0b,87,33,81,8b,b6,\
.
[HKEY_LOCAL_MACHINE\software\Classes\FlashVideo\Shell\O(uOw憿[7b飠 *Sb*_\Command]
@="\"c:\\Program Files (x86)\\YouKu\\YoukuClient\\YoukuDesktop.exe\" iku://|explorer|%1|"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\YoukuVideo\Shell\O(uOw憿[7b飠 *Sb*_\Command]
@="\"c:\\Program Files (x86)\\YouKu\\YoukuClient\\YoukuDesktop.exe\" iku://|explorer|%1|"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="??捁楴敶?汐杵湩愠摮??敗?汐杵湩 v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="??捁楴敶?汐杵湩愠摮??敗?汐杵湩 v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\-N齎鷁緥鰯L圗*飴*俀鰯塠hQ膥鯪塠艌z廭]
"DisplayName"="中国建设银行E路护航网银安全组件 1.0.2.14"
"UninstallString"="c:\\Program Files\\CCBComponents\\uninst.exe"
"DisplayIcon"="c:\\Program Files (x86)\\CCBComponents\\Detector\\index.ico"
"DisplayVersion"="1.0.2.14"
"URLInfoAbout"="
http://www.ccb.com"
"Publisher"="China Construction Bank"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:bb,cd,81,c1,f6,21,58,87,bf,1e,30,df,15,2d,02,c6,f1,85,1d,29,c6,
68,3a,c1,9c,55,34,bb,39,89,34,ec,e9,96,8a,ac,78,81,12,02,0b,87,33,81,8b,b6,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Q*Q*8nb]
"DisplayName"="QQ游戏"
"UninstallString"="c:\\Program Files (x86)\\Tencent\\QQGame\\Uninstall.EXE"
"Publisher"="腾讯公司"
"DisplayIcon"="c:\\Program Files (x86)\\Tencent\\QQGame\\QQGame.EXE"
"DisplayVersion"="3.0.109.60"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\'Yf擭2m *鷁L圦鰯]
"DisplayName"="大明五洲 建行网银盾"
"DisplayIcon"="c:\\Program Files (x86)\\CCBComponents\\DMWZ\\uninst.exe"
"DisplayVersion"="2.0.18.2"
"URLInfoAbout"="
http://www.bdtech.com.cn"
"Publisher"="Beijing Daming Wuzhou science and technology Co.,Ltd"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ 其他运行进程 ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Sendori\SendoriUp.exe
c:\program files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
c:\program files\Tablet\Wacom\WacomHost.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
完成时间: 2013-06-23 17:41:07 - 电脑已重新启动
ComboFix-quarantined-files.txt 2013-06-23 21:41
.
Pre-Run: 14,705,659,904 bytes free
Post-Run: 16,705,609,728 bytes free
.
- - End Of File - - B6F270392A91F0012760A002B605011E
D41D8CD98F00B204E9800998ECF8427E