ComboFix 13-02-07.02 - Kitty Tsang 02/2013 週五 17:08:58.3.4 - x64
Microsoft Windows 7 家用進階版 6.1.7601.1.950.852.3076.18.4007.2382 [GMT -5:00]
執行位置: c:\users\Kitty Tsang\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\favoritevideo\InvisibleFolder
c:\favoritevideo\InvisibleFolder\20121231182941_yingchao121231zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130201170743_xinmenghuanzhicheng130201zhuhuanchong15s1.swf
c:\favoritevideo\InvisibleFolder\20130201170821_xinmenghuanzhicheng130201zhuhuanchong15s2.swf
c:\favoritevideo\InvisibleFolder\20130201171914_chuangshisanguo130201zhuhuanchong15s3.swf
c:\favoritevideo\InvisibleFolder\20130201172152_chuangshisanguo130201yixingqipao3.swf
c:\favoritevideo\InvisibleFolder\20130204171757_itongyisucai130204zhuhc.swf
c:\favoritevideo\InvisibleFolder\20130204172217_rtongyisucai130204zhuhc.swf
c:\favoritevideo\InvisibleFolder\20130205112159_dongfengrichan130205zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130205170435_guangqichuanqi130205zhuhuanchong15snew.swf
c:\favoritevideo\InvisibleFolder\20130205170523_guangqichuanqi130205zhuztnew.swf
c:\favoritevideo\InvisibleFolder\20130206115102_37wan130208zhuztA.swf
c:\favoritevideo\InvisibleFolder\20130206140659_37wan130212zhuztA.swf
c:\favoritevideo\InvisibleFolder\20130206140702_37wan130212zhuztB.swf
c:\favoritevideo\InvisibleFolder\20130206152917_baidu130207zhuhc.swf
c:\favoritevideo\InvisibleFolder\20130206154843_shenjiangsanguo130206zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130206154911_shenjiangsanguo130206zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130206154950_shenjiangsanguo130206zhuhc3.swf
c:\favoritevideo\InvisibleFolder\20130206155125_shenjiangsanguo130206qipao1.swf
c:\favoritevideo\InvisibleFolder\20130206155204_shenjiangsanguo130206qipao3.swf
c:\favoritevideo\InvisibleFolder\20130206155912_qingshiqiyuan130206zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130206160016_qingshiqingyuan130206qipao1.swf
c:\favoritevideo\InvisibleFolder\20130206160046_qingshiqiyuan130206qipao2.swf
c:\favoritevideo\InvisibleFolder\20130206161355_tianxingjian130206zhuhuanchong15s3.swf
c:\favoritevideo\InvisibleFolder\20130206161626_tianxingjian130206yixingqipao2.swf
c:\favoritevideo\InvisibleFolder\20130206161648_tianxingjian130206yixingqipao3.swf
c:\favoritevideo\InvisibleFolder\20130206162100_fanrenxiuzhen130206zhuhuanchong15s1.swf
c:\favoritevideo\InvisibleFolder\20130206171511_qinmeiren130211zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130206171539_qinmeiren130211zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130206171840_qinmeiren130211qipao2.swf
c:\favoritevideo\InvisibleFolder\20130206171907_qinmeiren130211qipao3.swf
c:\favoritevideo\InvisibleFolder\20130206172942_liehuozhanshen130206zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130206173215_liehuozhanshen130206zhuhc3.swf
c:\favoritevideo\InvisibleFolder\20130206173355_liehuozhanshen130206qipao1.swf
c:\favoritevideo\InvisibleFolder\20130206174028_chuangshi130206zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130206174241_chuangshi130206qipao1.swf
c:\favoritevideo\InvisibleFolder\20130206174256_chuangshi130206qipao2.swf
c:\favoritevideo\InvisibleFolder\20130207102810_tulong130207zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130207102958_tulong130207zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130207103154_tulong130207qipao1.swf
c:\favoritevideo\InvisibleFolder\20130207103213_tulong130207qipao2.swf
c:\favoritevideo\InvisibleFolder\20130207104822_jiangshen130207zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130207104837_jiangshen130207zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130207104900_jiangshen130207zhuhc3.swf
c:\favoritevideo\InvisibleFolder\20130207105011_jiangshen130207qipao1.swf
c:\favoritevideo\InvisibleFolder\20130207105043_jiangshen130207qipao2.swf
c:\favoritevideo\InvisibleFolder\20130207105104_jiangshen130207qipao3.swf
c:\favoritevideo\InvisibleFolder\20130207105728_shenxiandao130207zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130207105838_shenxiandao130207zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130207105940_shenxiandao130207qipao1.swf
c:\favoritevideo\InvisibleFolder\20130207110003_shenxiandao130207qipao2.swf
c:\favoritevideo\InvisibleFolder\20130207110920_sanguoyanyi130207zhuhc1.swf
c:\favoritevideo\InvisibleFolder\20130207110941_sanguoyanyi130207zhuhc2.swf
c:\favoritevideo\InvisibleFolder\20130207111034_sanguoyanyi130207qipao1.swf
c:\favoritevideo\InvisibleFolder\20130207111044_sanguoyanyi130207qipao2.swf
c:\favoritevideo\InvisibleFolder\20130207111845_xuanxianchuanqi130207zhuhuanchong15s2.swf
c:\favoritevideo\InvisibleFolder\20130207112257_xuandongchuanqi130207yixingqipao2.swf
c:\favoritevideo\InvisibleFolder\20130207113037_daxiazhuan130207zhuhuanchong15s1.swf
c:\favoritevideo\InvisibleFolder\20130207113125_daxiazhuan130207zhuhuanchong15s2.swf
c:\favoritevideo\InvisibleFolder\20130207113159_daxiazhuan130207yixingqipao1.swf
c:\favoritevideo\InvisibleFolder\20130207113217_daxiazhuan130207yixingqipao2.swf
c:\favoritevideo\InvisibleFolder\20130207140814_ntongyisucai130207zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130207141617_qtongyisucai130207zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130207143046_20130204171817_itongyisucai130204zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130207143253_tongyi130207zhuhc.swf
c:\favoritevideo\InvisibleFolder\20130207144237_stongyisucai130204zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130207145134_20130204172242_rtongyisucai130204zhuzt.swf
c:\favoritevideo\InvisibleFolder\20130207161808_ntongyisucai130207newzhuhc.swf
c:\favoritevideo\InvisibleFolder\20130207165555_pptvlogo.jpg
c:\favoritevideo\InvisibleFolder\20130207170435_tulongchuanshuo130207zhuhc3.swf
c:\favoritevideo\InvisibleFolder\20130207170559_tulongchuanshuo130207qipao3.swf
c:\favoritevideo\InvisibleFolder\peer.dll
c:\favoritevideo\InvisibleFolder\pptv_jiejisanguo_130130.exe
c:\favoritevideo\InvisibleFolder\pptv_qinshiqingyuan_130130.exe
c:\favoritevideo\InvisibleFolder\productupdate.dll
c:\favoritevideo\InvisibleFolder\tipsbubble.dll
c:\favoritevideo\InvisibleFolder\tipsclient.dll
c:\program files (x86)\DealPly
c:\program files (x86)\DealPly\DealPly.crx
c:\program files (x86)\DealPly\DealPly.xpi
c:\program files (x86)\DealPly\DealPlyIE.dll
c:\program files (x86)\DealPly\DealPlyUpdate.exe
c:\program files (x86)\DealPly\DealPlyUpdateRun.exe
c:\program files (x86)\DealPly\icon.ico
c:\program files (x86)\DealPly\uninst.exe
.
.
((((((((((((((((((((((((( 2013-01-08 至 2013-02-08 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2013-02-08 22:30 . 2013-02-08 22:30--------d-----w-c:\users\user\AppData\Local\temp
2013-02-08 22:30 . 2013-02-08 22:30--------d-----w-c:\users\TEMP\AppData\Local\temp
2013-02-08 22:30 . 2013-02-08 22:30--------d-----w-c:\users\Default\AppData\Local\temp
2013-02-08 08:07 . 2013-02-08 21:33--------d-----w-c:\programdata\Tarma Installer
2013-02-08 07:54 . 2013-02-08 07:54--------d-----w-c:\program files (x86)\Conduit
2013-02-08 07:53 . 2013-02-08 07:53--------d-----w-c:\users\Kitty Tsang\AppData\Local\Conduit
2013-02-08 07:53 . 2013-02-08 07:53--------d-----w-c:\users\Kitty Tsang\AppData\Local\Bart_Ubing
2013-02-08 07:53 . 2013-02-08 08:14--------d-----w-c:\program files (x86)\VisualBee_V.1
2013-02-08 07:52 . 2013-02-08 07:52--------d-----w-c:\users\Kitty Tsang\AppData\Local\CRE
2013-02-08 07:51 . 2013-02-08 07:52--------d-----w-c:\users\Kitty Tsang\AppData\Local\VisualBeeClient
2013-02-08 07:51 . 2013-02-08 07:51--------d-----w-c:\users\Kitty Tsang\AppData\Local\VisualBeeExe
2013-02-08 07:50 . 2013-02-08 07:50--------d-----w-c:\programdata\VisualBee
2013-02-07 05:24 . 2013-02-07 05:24--------d-----w-c:\programdata\Tencent
2013-02-07 05:23 . 2013-02-07 05:23--------d-----w-c:\users\Kitty Tsang\AppData\Local\Tencent
2013-02-07 05:20 . 2013-02-07 05:2061440----a-r-c:\users\Kitty Tsang\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\NewShortcut2_E88611396FF84AFCB2EE5C1594058E02.exe
2013-02-07 05:20 . 2013-02-07 05:2061440----a-r-c:\users\Kitty Tsang\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\ARPPRODUCTICON.exe
2013-02-07 05:20 . 2013-02-07 05:20106496----a-r-c:\users\Kitty Tsang\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\NewShortcut311_0951773981FA4AB2BC21B7DCEC95892A.exe
2013-02-07 05:20 . 2013-02-07 05:20106496----a-r-c:\users\Kitty Tsang\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\NewShortcut31_2F252077BA3F4362913955273A708467.exe
2013-02-07 05:20 . 2013-02-07 05:20106496----a-r-c:\users\Kitty Tsang\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\NewShortcut1_EDD4ABB1C1B34A9D84CE33FBFB5D3639.exe
2013-02-07 04:52 . 2013-02-08 07:15--------d-----w-c:\users\Kitty Tsang\AppData\Roaming\Tencent
2013-02-06 15:35 . 2013-02-06 15:35--------d-----w-c:\windows\ERUNT
2013-02-06 15:35 . 2013-02-06 15:35--------d-----w-C:\JRT
2013-02-02 20:45 . 2013-02-02 20:45--------d-----w-c:\users\user\AppData\Roaming\FreeFixer
2013-02-02 20:45 . 2013-02-02 20:45--------d-----w-c:\users\user\AppData\Local\FreeFixer
2013-02-02 20:45 . 2013-02-02 20:45--------d-----w-c:\program files\FreeFixer
2013-01-30 02:54 . 2005-03-12 05:0787040----a-w-c:\windows\system32\pdfcmnnt.dll
2013-01-30 02:54 . 1998-06-24 05:00137000----a-w-c:\windows\SysWow64\MSMAPI32.OCX
2013-01-30 02:54 . 2013-01-30 02:55--------d-----w-c:\program files (x86)\PDFCreator
2013-01-30 02:54 . 1998-07-06 05:0023552----a-w-c:\windows\SysWow64\MSMPIDE.DLL
2013-01-30 02:52 . 2013-01-30 02:52--------d-----w-c:\users\Kitty Tsang\AppData\Local\Updater21802
2013-01-30 02:11 . 2013-01-30 02:21--------d-----w-c:\program files (x86)\Logon Loader
2013-01-24 19:44 . 2013-01-24 19:44--------d-----w-C:\found.002
2013-01-12 02:11 . 2013-01-12 02:11--------d-----w-c:\windows\system32\ARFC
2013-01-12 02:11 . 2012-10-02 15:201261936----a-w-c:\windows\system32\dmwu.exe
2013-01-12 02:11 . 2012-10-02 15:1935328----a-w-c:\windows\system32\ImHttpComm.dll
2013-01-12 02:10 . 2013-01-12 02:10--------d-----w-c:\users\Kitty Tsang\AppData\Local\PutLockerDownloader
2013-01-12 02:09 . 2013-01-12 02:09--------d-----w-c:\program files (x86)\PutLockerDownloader
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-08 10:44 . 2012-04-07 05:39697712----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2013-02-08 10:44 . 2011-07-19 13:0074096----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-07 05:17 . 2011-07-18 02:4018760----a-w-c:\windows\SysWow64\QQVistaHelper.dll
2013-01-24 15:02 . 2012-08-14 02:5837720----a-w-c:\windows\system32\drivers\avgtpx64.sys
2013-01-15 21:56 . 2012-06-15 03:02477616----a-w-c:\windows\SysWow64\npdeployJava1.dll
2013-01-15 21:56 . 2012-03-20 23:15473520----a-w-c:\windows\SysWow64\deployJava1.dll
2013-01-09 21:25 . 2011-07-17 14:5767599240----a-w-c:\windows\system32\MRT.exe
2012-12-25 04:31 . 2012-12-25 04:31505312----a-w-c:\windows\SysWow64\PPTVSvc.dll
2012-12-25 04:31 . 2012-12-25 04:31399968----a-w-c:\windows\SysWow64\PPTVLauncher.exe
2012-12-25 04:31 . 2012-12-25 04:31399968----a-w-c:\windows\system32\PPTVLauncher.exe
2012-12-25 04:31 . 2012-12-25 04:312299360----a-w-c:\windows\SysWow64\kindling.dll
2012-12-25 04:31 . 2012-10-30 02:572585056----a-w-c:\windows\system32\kindling.dll
2012-12-16 17:11 . 2012-12-21 06:3246080----a-w-c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-21 06:32367616----a-w-c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 06:32295424----a-w-c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-21 06:3234304----a-w-c:\windows\SysWow64\atmlib.dll
2012-12-14 21:49 . 2011-07-18 02:3324176----a-w-c:\windows\system32\drivers\mbam.sys
2012-12-07 13:20 . 2013-01-09 18:20441856----a-w-c:\windows\system32\Wpc.dll
2012-12-07 13:15 . 2013-01-09 18:202746368----a-w-c:\windows\system32\gameux.dll
2012-12-07 12:26 . 2013-01-09 18:20308736----a-w-c:\windows\SysWow64\Wpc.dll
2012-12-07 12:20 . 2013-01-09 18:202576384----a-w-c:\windows\SysWow64\gameux.dll
2012-12-07 11:20 . 2013-01-09 18:2030720----a-w-c:\windows\system32\usk.rs
2012-12-07 11:20 . 2013-01-09 18:2043520----a-w-c:\windows\system32\csrr.rs
2012-12-07 11:20 . 2013-01-09 18:2023552----a-w-c:\windows\system32\oflc.rs
2012-12-07 11:20 . 2013-01-09 18:2045568----a-w-c:\windows\system32\oflc-nz.rs
2012-12-07 11:20 . 2013-01-09 18:2044544----a-w-c:\windows\system32\pegibbfc.rs
2012-12-07 11:20 . 2013-01-09 18:2020480----a-w-c:\windows\system32\pegi-fi.rs
2012-12-07 11:20 . 2013-01-09 18:2020480----a-w-c:\windows\system32\pegi-pt.rs
2012-12-07 11:19 . 2013-01-09 18:2020480----a-w-c:\windows\system32\pegi.rs
2012-12-07 11:19 . 2013-01-09 18:2046592----a-w-c:\windows\system32\fpb.rs
2012-12-07 11:19 . 2013-01-09 18:2040960----a-w-c:\windows\system32\cob-au.rs
2012-12-07 11:19 . 2013-01-09 18:2021504----a-w-c:\windows\system32\grb.rs
2012-12-07 11:19 . 2013-01-09 18:2015360----a-w-c:\windows\system32\djctq.rs
2012-12-07 11:19 . 2013-01-09 18:2055296----a-w-c:\windows\system32\cero.rs
2012-12-07 11:19 . 2013-01-09 18:2051712----a-w-c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 18:2043520----a-w-c:\windows\SysWow64\csrr.rs
2012-12-07 10:46 . 2013-01-09 18:2030720----a-w-c:\windows\SysWow64\usk.rs
2012-12-07 10:46 . 2013-01-09 18:2045568----a-w-c:\windows\SysWow64\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 18:2044544----a-w-c:\windows\SysWow64\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 18:2020480----a-w-c:\windows\SysWow64\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 18:2023552----a-w-c:\windows\SysWow64\oflc.rs
2012-12-07 10:46 . 2013-01-09 18:2020480----a-w-c:\windows\SysWow64\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 18:2046592----a-w-c:\windows\SysWow64\fpb.rs
2012-12-07 10:46 . 2013-01-09 18:2020480----a-w-c:\windows\SysWow64\pegi.rs
2012-12-07 10:46 . 2013-01-09 18:2021504----a-w-c:\windows\SysWow64\grb.rs
2012-12-07 10:46 . 2013-01-09 18:2040960----a-w-c:\windows\SysWow64\cob-au.rs
2012-12-07 10:46 . 2013-01-09 18:2015360----a-w-c:\windows\SysWow64\djctq.rs
2012-12-07 10:46 . 2013-01-09 18:2055296----a-w-c:\windows\SysWow64\cero.rs
2012-12-07 10:46 . 2013-01-09 18:2051712----a-w-c:\windows\SysWow64\esrb.rs
2012-11-30 05:45 . 2013-01-09 18:19362496----a-w-c:\windows\system32\wow64win.dll
2012-11-30 05:45 . 2013-01-09 18:19243200----a-w-c:\windows\system32\wow64.dll
2012-11-30 05:45 . 2013-01-09 18:1913312----a-w-c:\windows\system32\wow64cpu.dll
2012-11-30 05:45 . 2013-01-09 18:19215040----a-w-c:\windows\system32\winsrv.dll
2012-11-30 05:43 . 2013-01-09 18:1916384----a-w-c:\windows\system32\ntvdm64.dll
2012-11-30 05:41 . 2013-01-09 18:20424448----a-w-c:\windows\system32\KernelBase.dll
2012-11-30 05:41 . 2013-01-09 18:191161216----a-w-c:\windows\system32\kernel32.dll
2012-11-30 05:38 . 2013-01-09 18:196144---ha-w-c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194608---ha-w-c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194608---ha-w-c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194096---ha-w-c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194096---ha-w-c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:195120---ha-w-c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194096---ha-w-c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193584---ha-w-c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:194096---ha-w-c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 18:193072---ha-w-c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-11-30 04:54 . 2013-01-09 18:195120----a-w-c:\windows\SysWow64\wow32.dll
2012-11-30 04:53 . 2013-01-09 18:20274944----a-w-c:\windows\SysWow64\KernelBase.dll
2012-11-30 04:45 . 2013-01-09 18:194608---ha-w-c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:194096---ha-w-c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:194096---ha-w-c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:194096---ha-w-c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:194096---ha-w-c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193584---ha-w-c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193072---ha-w-c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193072---ha-w-c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 18:193072---ha-w-c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
.
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVis0.dll" [2012-11-06 183112]
.
[HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{00000ADA-7E0D-47C1-986C-F017D09C4304}]
2012-11-20 21:30518096----a-w-c:\users\Public\Thunder Network\XMP4\Core\Program\VideoUrlSniffer.2.0.3.100.(401).dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0EA37B17-6B8B-4085-8257-F3A4AA69C27A}]
2012-09-13 03:1588080----a-w-c:\program files (x86)\Thunder Network\Thunder\BHO\XlBrowserAddin1.0.8.71.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4BF2CB0E-658A-442B-AC83-A64EC2150BFC}]
2012-09-24 06:58427912----a-w-c:\programdata\PPBrowserHelper\BHO\TipsBHO.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7aeae561-714b-45f6-ace3-4a8aed6e227b}]
2012-11-06 12:01183112----a-w-c:\program files (x86)\VisualBee_V.1\prxtbVis0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F1AF26F8-1828-4279-ABCE-074EF3235BD7}]
2012-11-06 16:19244328----a-w-c:\program files (x86)\PutLockerDownloader\smarterdownloader.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVis0.dll" [2012-11-06 183112]
.
[HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AAADesktopTips]
@="{4562B511-62E9-4533-B7B2-56A8BB10B482}"
[HKEY_CLASSES_ROOT\CLSID\{4562B511-62E9-4533-B7B2-56A8BB10B482}]
2012-11-14 11:32251856----a-w-c:\program files (x86)\Common Files\Thunder Network\Kankan\xappex.1.1.1.62.(402).dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPS Accelerator"="c:\program files (x86)\PPStream\PPSAP.exe" [2010-02-24 214408]
"PPAP"="c:\program files (x86)\Common Files\PPLiveNetwork\PPAP.EXE" [2012-12-25 251896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RotateImage"="c:\program files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" [2008-10-30 55808]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2011-02-03 1522536]
"ACTray"="c:\program files (x86)\Lenovo\Access Connections\ACTray.exe" [2010-12-27 431464]
"ConnectionManager"="c:\program files (x86)\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe" [2011-12-21 99656]
"UIExec"="c:\program files (x86)\one2free Next G Connection Manager\UIExec.exe" [2010-11-30 138584]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"IME14 CHT Setup"="c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 81200]
"Olympus ib"="c:\program files (x86)\Olympus\ib\olycamdetect.exe" [2010-09-30 93360]
"MDS_Menu"="c:\program files (x86)\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2010-07-01 220336]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-11-18 623880]
"NokiaInternetModem_AppStart.exe"="c:\program files (x86)\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe" [2010-05-06 140288]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-12-22 295072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Z1"="c:\users\Kitty Tsang\Desktop\mbar\mbar.exe" [2013-02-05 1363528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\Resources\Themes\XP萌化-伏八-乙荏製作\XP登入畫面-伏八.exe"
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00d0404]
IME FileREG_SZ IMTCC14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00e0404]
IME FileREG_SZ IMTCQ14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00f0404]
IME FileREG_SZ IMTCJ14.IME
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
R0 Soluto;Soluto;c:\windows\system32\Drivers\Soluto.sys [x]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-16 5814904]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [2010-12-03 116072]
R2 KMService;KMService;c:\windows\system32\srvany.exe [x]
R2 PPTVService;PPTVService;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-01-31 3289208]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [2012-03-20 571936]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-11-10 167264]
R3 btusb64h;BUFFALO TurboUSB for HD Filter;c:\windows\system32\drivers\btusb64h.sys [2009-06-24 28728]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-10-29 11776]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 340240]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 nokia_cs1x_cdc_acm;Nokia Internet Stick CDC-ACM driver;c:\windows\system32\DRIVERS\nokia_cs1x_cdc_acm.sys [2010-04-22 98304]
R3 nokia_cs1x_cdc_ecm;nokia_cs1x_cdc_ecm;c:\windows\system32\DRIVERS\nokia_cs1x_cdc_ecm.sys [2010-04-22 53760]
R3 nokia_cs1x_cpo;Nokia Internet Stick Mass Storage Device;c:\windows\system32\DRIVERS\nokia_cs1x_cpo.sys [2010-04-22 13824]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-02-03 79208]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Sage Simply Accounting Transaction Manager 2012 - CDN;Sage Simply Accounting Transaction Manager 2012 - CDN;c:\program files (x86)\Winsim\TransactionManager2012 - CDN\Sage_SA.TransactionManager.exe [2011-12-21 46408]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 tcphoc;tcphoc;c:\program files (x86)\Thunder Network\Thunder\XLDoctor\7.1.4.2104_1\Program\tcphoc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 UI Assistant Service;UI Assistant Service;c:\program files (x86)\one2free Next G Connection Manager\AssistantServices.exe [2010-11-30 252784]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]
R3 WatAdminSvc;Windows 啟用技術服務;c:\windows\system32\Wat\WatAdminSvc.exe [2011-07-17 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-11-16 111968]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [2011-01-13 23664]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2013-01-24 37720]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [2010-12-03 31592]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2010-12-17 198784]
S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2011-01-27 40808]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2010-11-24 45496]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-01-27 59240]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-30 38608]
S2 risdxc;risdxc;c:\windows\system32\DRIVERS\risdxc64.sys [2010-12-15 98816]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe [x]
S2 Simply Accounting Database Connection Manager;Simply Accounting Database Connection Manager;c:\program files (x86)\Winsim\ConnectionManager\SimplyConnectionManager.exe [2011-12-21 21320]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2010-12-03 114024]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2010-12-02 64440]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
S2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [2013-01-24 945328]
S2 XLServicePlatform;XLServicePlatform;c:\windows\system32\svchost [x]
S3 5U877;USB Video Device;c:\windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2010-12-18 425000]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-12-18 39464]
S3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
S3 nokia_cs1x_dc_enum;Nokia Internet Stick DC Enumerator;c:\windows\system32\DRIVERS\nokia_cs1x_dc_enum.sys [2010-04-22 97280]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-12-07 412776]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
XLServicePlatformREG_MULTI_SZ XLServicePlatform
DoctorServiceREG_MULTI_SZ XLDoctor Service
PPTVServiceGroupREG_MULTI_SZ PPTVService
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-05 21:061607120----a-w-c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
‘計劃任務’ 文件夾 裡的內容
.
2013-02-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 10:44]
.
2013-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-05 21:06]
.
2013-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-05 21:06]
.
2013-02-06 c:\windows\Tasks\Norton Security Scan for Kitty Tsang.job
- c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe [2012-05-16 09:45]
.
2013-01-30 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\uaclauncher.exe [2011-06-27 15:06]
.
2013-02-08 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\uaclauncher.exe [2011-06-27 15:06]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E}]
2012-09-13 03:15628240----a-w-c:\program files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.2.10.3694.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32162552----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32162552----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32162552----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32162552----a-w-c:\users\Kitty Tsang\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2011-01-14 380776]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-10 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-10 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-10 418840]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2011-01-27 41320]
"ALCKRESI.EXE"="c:\program files\Lenovo\AutoLock\ALCKRESI.EXE" [2010-12-17 281448]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2010-12-27 31592]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-11-02 1933584]
"IME14 CHT Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 110896]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2011-04-26 310912]
"ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056]
"Soluto"="c:\program files\Soluto\soluto.exe" [2012-03-20 1712688]
.
------- 而外的掃描 -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN21556502532854319&ctid=CT3284023
IE: &使用&迅雷下? - c:\program files (x86)\Thunder Network\Thunder\BHO\GetUrl.htm
IE: &使用&迅雷下?全部?接 - c:\program files (x86)\Thunder Network\Thunder\BHO\GetAllUrl.htm
IE: &妏蚚&捃濘燭盄狟婥 - c:\program files (x86)\Thunder Network\Thunder\BHO\OfflineDownload.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: 使用迅雷看看播放器播放 - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
IE: 添加?前?到迅雷看看播放器?? - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenuAddStoreTab.htm
IE: 發送圖像至藍牙裝置(B)... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: 發送頁面至藍牙裝置(B)... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {{0000016b-c524-4050-81a0-243669a86b9f} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
IE: {{0000026b-c524-4050-81a0-243669a86b9f} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm
IE: {{5D578929-E74E-46A2-A810-4F33D011DC52} - c:\program files (x86)\Common Files\Thunder Network\Kankan\XLStartKankan.exe
TCP: DhcpNameServer = 204.197.191.194 38.117.85.2
Handler: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\progra~2\KuGou\KGMusic\KUGOO3~1.OCX
Handler: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\progra~2\KuGou\KGMusic\KUGOO3~1.OCX
DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} - hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab
.
.
------- 文件類型 -------
.
inifile=c:\windows\SysWow64\NOTEPAD.EXE %1
txtfile=c:\windows\notepad.exe %1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - c:\program files (x86)\DealPly\DealPlyIE.dll
BHO-{ADA05D0E-4A32-6CD5-C5D8-CBAC01D8B468} - c:\program files (x86)\QvodPlayer\AddIn\{ADA05D0E-4A32-6CD5-C5D8-CBAC01D8B468}\QvodAddr.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-BaiduPlayer - c:\program files (x86)\Baidu\BaiduPlayer\1.16.0.73\uninst.exe
AddRemove-DealPly - c:\program files (x86)\DealPly\uninst.exe
AddRemove-QQMusic - c:\program files (x86)\Tencent\QQMusic\QQMusicUninst.exe
AddRemove-Adobe Connect Add-in - c:\users\Kitty Tsang\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\connectaddin\connectaddin.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2354949678-1773501639-2422343938-1003\Software\Microsoft\Internet Explorer\MenuExt\&*O(u&*??N}
@Allowed: (Read) (RestrictedCode)
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\GetUrl.htm"
"Contexts"=dword:00000022
"Name"="xl_geturl"
.
[HKEY_USERS\S-1-5-21-2354949678-1773501639-2422343938-1003\Software\Microsoft\Internet Explorer\MenuExt\&*O(u&*??N}Q??卉]
@Allowed: (Read) (RestrictedCode)
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\GetAllUrl.htm"
"Contexts"=dword:000000f3
"Name"="xl_getallurl"
.
[HKEY_USERS\S-1-5-21-2354949678-1773501639-2422343938-1003\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏甒競腤eZ]
@Allowed: (Read) (RestrictedCode)
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\OfflineDownload.htm"
"Name"="xl_offlinedownload"
"Contexts"=dword:00000022
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
完成時間: 2013-02-08 18:01:54
ComboFix-quarantined-files.txt 2013-02-08 23:01
.
Pre-Run: 166,337,814,528 bytes free
Post-Run: 165,936,148,480 bytes free
.
- - End Of File - - 298AEAFAFC22E9813D21661BED93FD71