ComboFix 13-02-07.02 - hp 08/02/13 14:59:35.1.4 - x86
Microsoft Windows 7 Starter 6.1.7601.1.950.852.1033.18.1012.70 [GMT -5:00]
執行位置: c:\users\hp\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\bidconfig_v1.2.dat
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\collecttask_v1.2.dat
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\domainreg_v1.1.dat
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi191F.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi287C.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi29EF.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi3A72.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi3FE.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi5417.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi5782.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi6880.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi7423.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi810.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi8754.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exi95C4.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiA443.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiB937.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiB977.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiBF0D.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiC92D.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiD33D.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiDCAC.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiE9A5.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\exiFE52.tmp
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\repairtp_v1.1.dat
c:\users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\template1_v1.1.zip
c:\users\hp\AppData\Roaming\022C27D7EC0685
c:\users\hp\Documents\~WRL3644.tmp
.
.
((((((((((((((((((((((((( 2013-01-08 至 2013-02-08 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2013-02-08 20:52 . 2013-02-08 20:56--------d-----w-c:\users\hp\AppData\Local\temp
2013-02-08 20:52 . 2013-02-08 20:52--------d-----w-c:\users\Default\AppData\Local\temp
2013-02-08 18:18 . 2013-02-08 18:1829904----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F10273D4-BCB4-4B9F-A38C-78A59AF82751}\MpKsl193fced7.sys
2013-02-08 08:16 . 2013-02-08 08:16--------d-----w-c:\users\hp\AppData\Local\Bart_Ubing
2013-02-08 08:01 . 2013-02-08 08:0129904----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F10273D4-BCB4-4B9F-A38C-78A59AF82751}\MpKsl918c735f.sys
2013-02-08 05:06 . 2013-02-08 05:07142152----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2013-02-08 03:49 . 2013-02-08 03:4931560----a-w-c:\windows\system32\drivers\430E2B08.sys
2013-02-08 03:48 . 2013-02-08 03:48142152----a-w-c:\windows\system32\drivers\07D17247.sys
2013-02-08 03:48 . 2013-02-08 03:4831560----a-w-c:\windows\system32\drivers\457357F5.sys
2013-02-06 03:29 . 2013-02-04 00:3251144----a-w-c:\windows\system32\drivers\Soluto.sys
2013-02-06 03:29 . 2013-02-06 03:29--------d-----w-c:\program files\Soluto
2013-02-06 03:24 . 2013-01-08 04:576991832------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F10273D4-BCB4-4B9F-A38C-78A59AF82751}\mpengine.dll
2013-02-02 14:16 . 2013-01-08 04:576991832------w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-02 03:48 . 2013-02-02 03:48--------d-----w-c:\program files\Common Files\Java
2013-02-02 03:41 . 2013-02-02 03:3994112----a-w-c:\windows\system32\WindowsAccessBridge.dll
2013-01-25 16:45 . 2013-01-25 16:452551808----a-w-c:\programdata\Microsoft\BingDesktop\Updater\BingDesktop.msi
2013-01-20 23:59 . 2012-06-01 04:37154624----a-w-c:\windows\system32\iisRtl.dll
2013-01-20 23:59 . 2012-06-01 04:3550688----a-w-c:\windows\system32\admwprox.dll
2013-01-20 23:59 . 2012-06-01 04:3415360----a-w-c:\windows\system32\iisreset.exe
2013-01-20 23:59 . 2012-06-01 04:4010752----a-w-c:\windows\system32\wamregps.dll
2013-01-20 23:59 . 2012-06-01 04:3526624----a-w-c:\windows\system32\ahadmin.dll
2013-01-20 23:59 . 2012-06-01 04:378192----a-w-c:\windows\system32\iisrstap.dll
2013-01-18 04:38 . 2013-01-18 04:38--------d-----w-C:\inetpub
2013-01-14 02:08 . 2012-11-22 04:45626688----a-w-c:\windows\system32\usp10.dll
2013-01-14 02:08 . 2012-11-09 04:43492032----a-w-c:\windows\system32\win32spl.dll
2013-01-14 02:06 . 2012-11-30 04:453072---ha-w-c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-14 02:02 . 2012-11-01 04:471389568----a-w-c:\windows\system32\msxml6.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-08 00:11 . 2012-04-10 05:43697712----a-w-c:\windows\system32\FlashPlayerApp.exe
2013-02-08 00:11 . 2012-01-29 05:1274096----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-02 03:39 . 2012-06-13 23:59861088----a-w-c:\windows\system32\npdeployJava1.dll
2013-02-02 03:39 . 2011-04-27 09:51782240----a-w-c:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2012-01-27 17:17232336------w-c:\windows\system32\MpSigStub.exe
2013-01-25 01:49 . 2012-09-29 04:0131576----a-w-c:\windows\system32\drivers\avgtpx86.sys
2012-12-27 07:34 . 2012-12-27 07:343072----a-w-c:\windows\system32\drivers\fr-FR\nfsrdr.sys.mui
2012-12-27 07:33 . 2012-12-27 07:3314336----a-w-c:\windows\system32\drivers\fr-FR\vpcvmm.sys.mui
2012-12-27 07:33 . 2012-12-27 07:337168----a-w-c:\windows\system32\drivers\fr-FR\rdvgkmd.sys.mui
2012-12-27 07:33 . 2012-12-27 07:332048----a-w-c:\windows\system32\drivers\fr-FR\vpcnfltr.sys.mui
2012-12-27 07:33 . 2012-12-27 07:333584----a-w-c:\windows\system32\drivers\fr-FR\vpchbus.sys.mui
2012-12-27 07:33 . 2012-12-27 07:334608----a-w-c:\windows\system32\drivers\fr-FR\tsusbhub.sys.mui
2012-12-27 07:33 . 2012-12-27 07:332048----a-w-c:\windows\system32\drivers\fr-FR\vpcuxd.sys.mui
2012-12-27 07:33 . 2012-12-27 07:332048----a-w-c:\windows\system32\drivers\fr-FR\vpcusb.sys.mui
2012-12-27 04:42 . 2012-12-27 04:422048----a-w-c:\windows\system32\drivers\zh-TW\usbrpm.sys.mui
2012-12-27 04:41 . 2012-12-27 04:417680----a-w-c:\windows\system32\drivers\zh-TW\fvevol.sys.mui
2012-12-27 04:39 . 2012-12-27 04:392048----a-w-c:\windows\system32\drivers\UMDF\zh-TW\WpdMtpDr.dll.mui
2012-12-27 04:36 . 2012-12-27 04:369728----a-w-c:\windows\system32\drivers\zh-TW\nwifi.sys.mui
2012-12-27 04:36 . 2012-12-27 04:362560----a-w-c:\windows\system32\drivers\zh-TW\qwavedrv.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\Spool\prtprocs\w32x86\zh-TW\LXKPTPRC.DLL.mui
2012-12-27 04:34 . 2012-12-27 04:348704----a-w-c:\windows\system32\drivers\zh-TW\E1G60I32.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344096----a-w-c:\windows\system32\drivers\zh-TW\e100b325.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343584----a-w-c:\windows\system32\drivers\zh-TW\bcm4sbxp.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3430720----a-w-c:\windows\system32\drivers\zh-TW\yk62x86.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3410752----a-w-c:\windows\system32\drivers\zh-TW\k57nd60x.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3410752----a-w-c:\windows\system32\drivers\zh-TW\b57nd60x.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3410240----a-w-c:\windows\system32\drivers\zh-TW\e1y6032.sys.mui
2012-12-27 04:34 . 2012-12-27 04:346144----a-w-c:\windows\system32\drivers\zh-TW\e1q6032.sys.mui
2012-12-27 04:34 . 2012-12-27 04:346144----a-w-c:\windows\system32\drivers\zh-TW\e1k6032.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\getn62.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3410240----a-w-c:\windows\system32\drivers\zh-TW\e1e6032.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345120----a-w-c:\windows\system32\drivers\zh-TW\ltmdmnt.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345120----a-w-c:\windows\system32\drivers\zh-TW\BrSerId.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345120----a-w-c:\windows\system32\drivers\zh-TW\BrSerIb.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\MTConfig.sys.mui
2012-12-27 04:34 . 2012-12-27 04:349728----a-w-c:\windows\system32\drivers\zh-TW\battc.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345120----a-w-c:\windows\system32\drivers\zh-TW\serial.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344096----a-w-c:\windows\system32\drivers\zh-TW\wacompen.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343584----a-w-c:\windows\system32\drivers\zh-TW\IPMIDrv.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\tpm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\parvdm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\parport.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\ataport.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\amdide.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\umbus.sys.mui
2012-12-27 04:34 . 2012-12-27 04:349728----a-w-c:\windows\system32\drivers\zh-TW\volsnap.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345632----a-w-c:\windows\system32\drivers\zh-TW\acpi.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3423552----a-w-c:\windows\system32\drivers\zh-TW\usbport.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3420992----a-w-c:\windows\system32\drivers\zh-TW\viac7.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3420992----a-w-c:\windows\system32\drivers\zh-TW\processr.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3420992----a-w-c:\windows\system32\drivers\zh-TW\intelppm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3420992----a-w-c:\windows\system32\drivers\zh-TW\amdppm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3420992----a-w-c:\windows\system32\drivers\zh-TW\amdk8.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\wd.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\disk.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\cdrom.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3411776----a-w-c:\windows\system32\drivers\zh-TW\usbhub.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\GAGP30KX.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\UAGP35.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:3411776----a-w-c:\windows\system32\drivers\zh-TW\ohci1394.sys.mui
2012-12-27 04:34 . 2012-12-27 04:3411776----a-w-c:\windows\system32\drivers\zh-TW\1394ohci.sys.mui
2012-12-27 04:34 . 2012-12-27 04:345120----a-w-c:\windows\system32\drivers\zh-TW\i8042prt.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\vhdmp.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\mouclass.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\mouhid.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343584----a-w-c:\windows\system32\drivers\zh-TW\sermouse.sys.mui
2012-12-27 04:34 . 2012-12-27 04:346144----a-w-c:\windows\system32\drivers\zh-TW\pci.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\vdrvroot.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\mssmbios.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\kbdclass.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\isapnp.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\ULIAGPKX.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\VIAAGP.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\SISAGP.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\NV_AGP.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\kbdhid.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\AMDAGP.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\AGP440.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344096----a-w-c:\windows\system32\drivers\zh-TW\hdaudbus.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\vwifibus.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344608----a-w-c:\windows\system32\drivers\zh-HK\bthport.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-HK\BTHUSB.SYS.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-HK\bthenum.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\atikmdag.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\pnpmem.sys.mui
2012-12-27 04:34 . 2012-12-27 04:346656----a-w-c:\windows\system32\drivers\zh-TW\msdsm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344608----a-w-c:\windows\system32\drivers\UMDF\zh-TW\WUDFUsbccidDriver.dll.mui
2012-12-27 04:34 . 2012-12-27 04:3432768----a-w-c:\windows\system32\drivers\zh-TW\mpio.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\pcmcia.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\pscr.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-HK\hidbth.sys.mui
2012-12-27 04:34 . 2012-12-27 04:344608----a-w-c:\windows\system32\drivers\zh-TW\bthpan.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343584----a-w-c:\windows\system32\drivers\zh-TW\HdAudio.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\serscan.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342560----a-w-c:\windows\system32\drivers\zh-TW\Dot4usb.sys.mui
2012-12-27 04:34 . 2012-12-27 04:342048----a-w-c:\windows\system32\drivers\zh-TW\BrParwdm.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343584----a-w-c:\windows\system32\drivers\zh-TW\portcls.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\tsusbflt.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\rndismpx.sys.mui
2012-12-27 04:34 . 2012-12-27 04:343072----a-w-c:\windows\system32\drivers\zh-TW\rndismp6.sys.mui
.
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{00000ADA-7E0D-47C1-986C-F017D09C4304}]
2012-11-20 21:30518096----a-w-c:\users\Public\Thunder Network\XMP4\Core\Program\VideoUrlSniffer.2.0.3.100.(349).dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
2011-05-09 08:49176936----a-w-c:\program files\uTorrentBar_FR\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-01-25 01:491883824----a-w-c:\program files\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}]
2012-01-11 14:29241872----a-w-c:\program files\Softonic\softonic\1.5.11.5\bh\softonic.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5018CFD2-804D-4C99-9F81-25EAEA2769DE}"= "c:\program files\Softonic\softonic\1.5.11.5\softonicTlbr.dll" [2012-01-11 250064]
"{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-05-09 176936]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll" [2013-01-25 1883824]
.
[HKEY_CLASSES_ROOT\clsid\{5018cfd2-804d-4c99-9f81-25eaea2769de}]
[HKEY_CLASSES_ROOT\Softonic.dskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\Softonic.dskBnd]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AAADesktopTips]
@="{4562B511-62E9-4533-B7B2-56A8BB10B482}"
[HKEY_CLASSES_ROOT\CLSID\{4562B511-62E9-4533-B7B2-56A8BB10B482}]
2012-11-14 11:32251856----a-w-c:\program files\Common Files\Thunder Network\Kankan\xappex.1.1.1.62.(368).dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\hp\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\hp\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\hp\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32129272----a-w-c:\users\hp\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPS Accelerator"="c:\program files\PPStream\ppsap.exe" [2010-02-24 214408]
"PPAP"="c:\program files\Common Files\PPLiveNetwork\PPAP.exe" [2012-08-15 250784]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-02 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-02 150552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-10-14 2299176]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"IME14 CHT Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 81200]
"IME14 JPN Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 81200]
"IME14 KOR Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 81200]
"IME14 CHS Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2012-03-14 81200]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2012-03-14 1138780]
"BingDesktop"="c:\program files\Microsoft\BingDesktop\BingDesktop.exe" [2013-01-25 2127896]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-11-11 997320]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"WD Drive Unlocker"="c:\program files\Western Digital\WD Apps\WDDriveAutoUnlock.exe" [2011-12-16 1687968]
"WD Quick View"="c:\program files\Western Digital\WD SmartWare\WDDMStatus.exe" [2011-12-15 3998616]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-11-29 151952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Soluto"="c:\program files\soluto\soluto.exe" [2013-02-04 1229280]
.
c:\users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\hp\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Ginger.lnk - c:\windows\Installer\{4715760F-AF61-494C-A699-7DF5D29A03A8}\GingerClientStartu_A2F7C7DB989E489495DD2D78EDBE914A.exe [2013-1-20 90112]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-1-25 984408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00f0404]
IME FileREG_SZ IMTCJ14.IME
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-12-18 14:2838112----a-w-c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Quick Launch]
2010-11-09 22:20586296----a-w-c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
2011-02-15 23:4994264----a-w-c:\program files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPOSD]
2011-01-27 19:38318520----a-w-c:\program files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
2011-04-08 08:1378904----a-w-c:\program files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x32.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 Sage Simply Accounting Transaction Manager 2012 - CDN;Sage Simply Accounting Transaction Manager 2012 - CDN;c:\program files\Winsim\TransactionManager2012 - CDN\Sage_SA.TransactionManager.exe [x]
R3 Simply Accounting Database Connection Manager;Simply Accounting Database Connection Manager;c:\program files\Winsim\ConnectionManager\SimplyConnectionManager.exe [x]
R3 SolutoRemoteService;Soluto Remote Service;c:\program files\Soluto\SolutoRemoteService.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [x]
R4 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [x]
R4 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
R4 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
R4 HPWMISVC;HPWMISVC;c:\program files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S1 MpKsl193fced7;MpKsl193fced7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F10273D4-BCB4-4B9F-A38C-78A59AF82751}\MpKsl193fced7.sys [x]
S1 MpKsl918c735f;MpKsl918c735f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F10273D4-BCB4-4B9F-A38C-78A59AF82751}\MpKsl918c735f.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\aestsrv.exe [x]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x]
S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files\Microsoft\BingDesktop\BingDesktopUpdater.exe [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S2 persdwmsrv;Personalization Panel DWM controller;c:\program files\winaero.com\Personalization Panel DWM Controller\persdwmsrv.exe [x]
S2 PPTVService;PPTVService;c:\windows\System32\svchost.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;c:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [x]
S2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [x]
S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WDDMService.exe [x]
S2 WDDriveService;WD Drive Manager;c:\program files\Western Digital\WD Drive Manager\WDDriveService.exe [x]
S2 WDFMEService;WDFME;c:\program files\Western Digital\WD SmartWare\WDFME.exe [x]
S2 WDRulesService;WDRules;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S2 XLServicePlatform;XLServicePlatform;c:\windows\system32\svchost [x]
S3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x32.sys [x]
S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL193FCED7
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonationREG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
XLServicePlatformREG_MULTI_SZ XLServicePlatform
PPTVServiceGroupREG_MULTI_SZ PPTVService
GPSvcGroupREG_MULTI_SZ GPSvc
iissvcsREG_MULTI_SZ w3svc was
apphostREG_MULTI_SZ apphostsvc
.
‘計劃任務’ 文件夾 裡的內容
.
2013-02-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-10 00:11]
.
2013-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2174158749-396340439-4157524416-1000Core.job
- c:\users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-30 15:43]
.
2013-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2174158749-396340439-4157524416-1000UA.job
- c:\users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-30 15:43]
.
2012-12-11 c:\windows\Tasks\HPCeeScheduleForhp.job
- c:\program files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2013-02-08 c:\windows\Tasks\ROC_JAN2013_TB_rmv.job
- c:\program files\AVG Secure Search\PostInstall\ROC.exe [2013-01-25 01:49]
.
.
------- 而外的掃描 -------
.
uStart Page = hxxp://
www.155.com/?id=2012
uInternet Settings,ProxyOverride = *.local
IE: &妏蚚&捃濘燭盄狟婥 - c:\program files\Thunder Network\Thunder\BHO\OfflineDownload.htm
IE: &妏蚚&捃濘狟婥 - c:\program files\Thunder Network\Thunder\BHO\geturl.htm
IE: &妏蚚&捃濘狟婥窒蟈諉 - c:\program files\Thunder Network\Thunder\BHO\GetAllUrl.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: 使用迅雷看看播放器播放 - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
IE: {{019c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
IE: {{119c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm
TCP: DhcpNameServer = 172.18.0.36 172.18.0.37
Handler: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\progra~1\KUGOU2~1\KUGOO3~1.OCX
Handler: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\progra~1\KUGOU2~1\KUGOO3~1.OCX
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
AddRemove-PPSGame - d:\pps.tv\PPSGame\unppsgame.exe
AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\SAMSUNG\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\SAMSUNG\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\SAMSUNG\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\SAMSUNG\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\SAMSUNG\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\SAMSUNG\USB Drivers\25_escape\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏甒競腤eZ]
@="c:\\Program Files\\Thunder Network\\Thunder\\BHO\\OfflineDownload.htm"
"Name"="xl_offlinedownload"
"Contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏腤eZ]
@="c:\\Program Files\\Thunder Network\\Thunder\\BHO\\geturl.htm"
"Name"="xl_geturl"
"Contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏腤eZ蘙??]
@="c:\\Program Files\\Thunder Network\\Thunder\\BHO\\GetAllUrl.htm"
"Name"="xl_getallurl"
"Contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (S-1-5-21-2174158749-396340439-4157524416-1000)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (S-1-5-21-2174158749-396340439-4157524416-1000)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (S-1-5-21-2174158749-396340439-4157524416-1000)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (S-1-5-21-2174158749-396340439-4157524416-1000)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (S-1-5-21-2174158749-396340439-4157524416-1000)
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2174158749-396340439-4157524416-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
完成時間: 2013-02-08 16:03:25
ComboFix-quarantined-files.txt 2013-02-08 21:03
.
Pre-Run: 127?635?922?944 bytes free
Post-Run: 128?544?309?248 bytes free
.
- - End Of File - - 0EF878D7CF8A208C5823598609C47998