rachel_UFO
Posts: 31 +0
I am having a situation very similar to this post:
https://www.techspot.com/community/topics/update-flash-player-virus.202629/
windows7, chrome
----------------------------------------------------------------------------------
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 7/7/2014 15:27:22, SYSTEM, RACHEL-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.7.3.1,
Update, 7/7/2014 15:27:25, SYSTEM, RACHEL-PC, Manual, Malware Database, 2014.3.4.9, 2014.7.7.1,
Error, 7/7/2014 18:16:48, SYSTEM, RACHEL-PC, Protection, StartServiceCtrlDispatcher, 1063,
Error, 7/7/2014 18:16:49, SYSTEM, RACHEL-PC, scheduler, StartServiceCtrlDispatcher, 1063,
(end)
-----------------------------------------------------------------------------------
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126 BrowserJavaVersion: 10.60.2
Run by Rachel at 18:22:48 on 2014-07-07
Microsoft Windows 7 家用進階版 6.1.7601.1.950.852.3076.18.4061.2459 [GMT 8:00]
.
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe
C:\Windows\SysWOW64\svchost.exe -k SDDUpdate
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\svchost -k XLServicePlatform
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AliWangWang\AliIM.exe
C:\Program Files (x86)\alipay\SafeTransaction\TaobaoProtect.exe
C:\Program Files (x86)\alipay\SafeTransaction\Alipaybsm.exe
C:\Program Files (x86)\QvodPlayer\QvodWebBase\1.0.0.47\QvodWebService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\Monitor.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\program files (x86)\avira\antivir desktop\ipmGui.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uProxyOverride = local;<local>
mWinlogon: Userinit = userinit.exe
BHO: {074C1DC5-9320-4A9A-947D-C042949C6216} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: WebDetectorBHO Class: {43BEAFD9-E005-483D-A367-146BA6C8A32E} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: {889D2FEB-5411-4565-8998-1DD2C5261283} - <orphaned>
BHO: QvodExtend: {A8502600-B272-4F68-A67B-A0305D46D297} - C:\Program Files (x86)\QvodPlayer\QvodExtend\5.0.97.0\QvodExtend.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: 捃濘狟婥盓厥郪璃: {DE05CF4A-7B0A-4775-B5E5-396244938679} - C:\Program Files (x86)\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll
uRun: [Akamai NetSession Interface] "C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe"
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
uRun: [BAIDUMEDIA] C:\Program Files (x86)\Baidu\BaiduPlayer\1.19.0.57\BaiduPlayer.exe minimize
uRun: [hsscp.EXE] C:\Users\Rachel\AppData\Roaming\Hotspot Shield\bin\hsscp.EXE -nonadmin
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
mRun: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
mRun: [Ulead AutoDetector v2] C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [kxesc] "c:\program files (x86)\kingsoft\kingsoft antiviruskxetray.exe" -autorun
mRun: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [EaseUS EPM tray] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EpmNews.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &使用&迅雷下? - <no file>
IE: &使用&迅雷下?全部?接 - <no file>
IE: &使用115优蛋 3下? - <no file>
IE: &使用115优蛋 3下?全部?接 - <no file>
IE: &妏蚚&捃濘燭盄狟婥 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\OfflineDownload.htm
IE: &妏蚚&捃濘狟婥 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\geturl.htm
IE: &妏蚚&捃濘狟婥窒蟈諉 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\GetAllUrl.htm
IE: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
IE: 添加?前?到迅雷看看播放器?? - <no file>
LSP: C:\Program Files (x86)\YouKu\common\ikutm.dll
Trusted Zone: alipay.com
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
Trusted Zone: taobao.com
Trusted Zone: alipay.com
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: alisoft.com
Trusted Zone: gogobox.com.tw
Trusted Zone: gogobox.com.tw
Trusted Zone: taobao.com
Trusted Zone: taobao.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
TCP: NameServer = 218.102.32.134 219.76.98.66
TCP: Interfaces\{AE90874A-C851-4864-9C4D-3EBC134868C5} : DHCPNameServer = 218.102.32.134 219.76.98.66
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: 捃濘狟婥盓厥: {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} - C:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.18.4724.dll
x64-BHO: QvodExtend: {A8502600-B272-4F68-A67B-A0305D46D298} - C:\Program Files (x86)\QvodPlayer\QvodExtend\5.0.97.0\QvodExtend_x64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-6-23 55280]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-5-4 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-1-31 283200]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-6-24 92160]
R2 AlipaySecSvc;Alipay security service;C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [2014-6-4 540032]
R2 AntiVirSchedulerService;Avira 排程管理員;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-5-4 430160]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-5-4 430160]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-5-4 112080]
R2 DeviceHealth;Microsoft Device Health Machine Service;C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe [2014-6-6 85664]
R2 SDDUpdate;SDDUpdate;C:\Windows\System32\svchost.exe -k SDDUpdate [2009-7-14 27136]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-6-23 660800]
R2 XLServicePlatform;XLServicePlatform;C:\Windows\System32\svchost -k XLServicePlatform --> C:\Windows\System32\svchost -k XLServicePlatform [?]
R2 YLMFVDISK;YLMF Virtual Diskette V1;C:\Windows\System32\drivers\VirtDisk64.sys [2012-2-3 23896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2010-6-24 138752]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-7-7 122584]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-24 236544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2014-5-8 108800]
S3 FsUsbExDisk;FsUsbExDisk;C:\Windows\SysWOW64\FsUsbExDisk.Sys [2013-2-14 37344]
S3 HaozipVirtualCDBus;HaoZip Virtual Bus Driver;C:\Windows\System32\drivers\HaoZipVirtualCDBus.sys [2012-7-24 204888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2011-5-10 22528]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2014-5-8 206080]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-2 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 VMUVC;Vimicro Camera Service VMUVC;C:\Windows\System32\drivers\vmuvc.sys [2011-4-23 198400]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;C:\Windows\System32\drivers\vvftUVC.sys [2011-4-23 303616]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-8-2 18216]
S3 WatAdminSvc;Windows 啟用技術服務;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-2 1255736]
S3 WsAudio_Device;WsAudio_Device;C:\Windows\System32\drivers\VirtualAudio.sys [2013-11-1 31080]
S4 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-5-29 1039952]
.
=============== File Associations ===============
.
FileExt: .reg: regfile=regedit.exe "%1" [UserChoice]
FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [UserChoice]
.js: <filetype is not registered>
.
=============== Created Last 30 ================
.
2014-07-07 07:27:18 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-07-07 07:26:38 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-07-07 07:26:38 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-07-07 07:26:38 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-07-07 07:26:37 -------- d-----w- C:\ProgramData\Malwarebytes
2014-07-07 06:51:34 -------- d-----w- C:\ProgramData\Oracle
2014-07-07 06:50:42 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-07 06:24:55 -------- d-----w- C:\Users\Rachel\AppData\Roaming\TaobaoProtect
2014-07-07 06:24:26 -------- d-----w- C:\Program Files (x86)\Microsoft Device Health
2014-07-07 05:45:41 -------- d-----w- C:\Users\Rachel\AppData\Roaming\alipay
2014-06-20 05:48:48 10779000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E19A4B97-11A4-41D6-AC0A-F1DD1B49B05A}\mpengine.dll
2014-06-16 14:38:01 2278912 ----a-w- C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll
2014-06-12 09:21:00 -------- d-----w- C:\Program Files (x86)\Funmily
2014-06-12 09:06:39 -------- d---a-w- C:\Program Files (x86)\HYZGOnline
2014-06-12 07:51:46 -------- d-----w- C:\Users\Rachel\AppData\Roaming\BitCometLite
2014-06-12 07:14:30 5203984 ----a-w- C:\Windows\SysWow64\GameMon.des
2014-06-12 07:14:16 -------- d-----w- C:\Program Files\Common Files\INCA Shared
2014-06-11 15:52:41 506368 ----a-w- C:\Windows\System32\aepdu.dll
2014-06-11 15:52:41 424448 ----a-w- C:\Windows\System32\aeinv.dll
.
==================== Find3M ====================
.
2014-06-04 03:39:19 112080 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2014-05-30 10:02:37 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-05-30 10:02:09 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-05-30 09:39:43 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-05-30 09:39:23 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-05-30 09:38:29 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-05-30 09:21:23 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-05-30 09:21:05 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-05-30 09:20:36 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-05-30 09:11:24 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-05-30 09:08:22 5782528 ----a-w- C:\Windows\System32\jscript9.dll
2014-05-30 09:02:39 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-05-30 08:55:36 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-05-30 08:44:28 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-05-30 08:43:06 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-05-30 08:42:16 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-05-30 08:28:33 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-05-30 08:27:56 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-05-30 08:24:19 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-05-30 08:23:22 2040832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-05-30 08:10:46 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-30 07:56:56 2266112 ----a-w- C:\Windows\System32\wininet.dll
2014-05-30 07:56:50 4244992 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-05-30 07:50:09 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-05-30 07:49:38 1964544 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-05-30 07:21:10 1790976 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-04-25 02:34:59 801280 ----a-w- C:\Windows\System32\usp10.dll
2014-04-25 02:06:17 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2014-04-12 02:22:05 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2014-04-12 02:22:05 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-04-12 02:19:38 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2014-04-12 02:19:38 136192 ----a-w- C:\Windows\System32\sspicli.dll
2014-04-12 02:19:37 28160 ----a-w- C:\Windows\System32\secur32.dll
2014-04-12 02:19:32 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-04-12 02:19:05 31232 ----a-w- C:\Windows\System32\lsass.exe
2014-04-12 02:12:06 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-04-12 02:10:56 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-04-10 05:40:09 159032 ----a-w- C:\Windows\System32\atl90.dll
2014-04-10 05:40:07 655872 ----a-w- C:\Windows\System32\msvcr90.dll
2014-04-10 05:40:07 568832 ----a-w- C:\Windows\System32\msvcp90.dll
2014-04-08 15:30:10 286352 ----a-w- C:\Windows\System32\libbluray.dll
2014-04-08 15:29:48 238736 ----a-w- C:\Windows\SysWow64\libbluray.dll
.
============= FINISH: 18:24:46.74 ===============
-----------------------------------------------------------------------------------------------------------------
ATTACH.txt
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 家用進階版
Boot Device: \Device\HarddiskVolume2
Install Date: 1/7/2010 14:41:52
System Uptime: 7/7/2014 17:15:34 (1 hours ago)
.
Motherboard: Dell Inc. | | 0K83V0
Processor: Pentium(R) Dual-Core CPU E5500 @ 2.80GHz | CPU 1 | 2803/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 290 GiB total, 52.364 GiB free.
D: is CDROM ()
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP724: 26/6/2014 14:00:52 - Removed MSXML 4.0 SP2 (KB954430)
RP725: 26/6/2014 14:03:43 - Removed MSXML 4.0 SP2 (KB973688)
RP726: 26/6/2014 17:01:47 - 已移除 MSXML 4.0 SP3 Parser (KB2721691)
RP727: 7/7/2014 14:49:24 - Installed Java 7 Update 60
.
==== Installed Programs ======================
.
???????????
ACDSee
Adobe AIR
Adobe Anchor Service CS4
Adobe Asset Services CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Recommended Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Contribute CS4
Adobe Creative Suite 4 Web Standard
Adobe CSI CS4
Adobe CSI CS4 x64
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Drive CS4 x64
Adobe Dynamiclink Support
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Fireworks CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI others
Adobe Flash CS4 STI-other
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Importer
Adobe Output Module
Adobe PDF Library Files CS4
Adobe PDistiller
Adobe Reader XI - Chinese Traditional
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Version Cue CS4 Server
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Akamai NetSession Interface
AlipayDHC 1.1.0.0
Audacity 1.3.12 (Unicode)
Avira Free Antivirus
BLACK WOLVES SAGA -Bloody Nightmare-
Bonjour
ComicStudio EX Demo 4.0TC
Connect
Corel VideoStudio Pro Title Pack
DAEMON Tools Lite
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell Edoc Viewer
Dell Support Center (Support Software)
FileMenu Tools
Finale NotePad 2008
Free Studio version 2013
Google Chrome
Google Update Helper
HetaOni ENGLISH Version 15.0
iKu 2
Intel(R) Graphics Media Accelerator Driver
IntelR Matrix Storage Manager
Java 7 Update 60
Java 7 Update 7 (64-bit)
Java Auto Updater
kuler
Malwarebytes Anti-Malware version 2.0.2.1012
Mega Manager
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft AppLocale
Microsoft Choice Guard
Microsoft Office 2000 Professional
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft Windows Application Compatibility Database
Microsoft WSE 3.0 Runtime
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
MPC-HC 1.7.4 (64-bit)
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSXML 4.0 SP3 Parser (KB2758694)
MyFreeCodec
openCanvas4.5.09e Plus
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
RaySource 2.2.0.1
Realtek High Definition Audio Driver
Roxio Burn
SafeTransaction 5.13.0.0
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Suite Shared Configuration CS4
swMSM
Ulead PhotoImpact 11
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 執行階段 3.0
VOCALOID2 Expression DB (Standard)
VOCALOID2 Voice DB (Miku)
Watson
Windows Live Communications Platform
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live 程式集
Windows Live 影像中心
Windows Media Encoder 9 Series
WinRAR 5.10 beta 4 (64-bit)
百度云管家
快播 5.19.185
迅雷看看播放器
阿里旺旺2013Beta2
捃濘7
盓葆惘杅趼痐抎郪璃 2.4.0.0
盓葆惘假諷璃 3.23.0.0
盓葆惘假諷璃 3.8.0.0
雅?~MIYAKO~月詠?夢
微???健康助手
新幻月之歌 Online
歡樂派登入器 版本 1.0
.
==== End Of File ===========================
I have some application in chinese, please ask if there are any problems. Thank you so much.
https://www.techspot.com/community/topics/update-flash-player-virus.202629/
windows7, chrome
----------------------------------------------------------------------------------
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 7/7/2014 15:27:22, SYSTEM, RACHEL-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.7.3.1,
Update, 7/7/2014 15:27:25, SYSTEM, RACHEL-PC, Manual, Malware Database, 2014.3.4.9, 2014.7.7.1,
Error, 7/7/2014 18:16:48, SYSTEM, RACHEL-PC, Protection, StartServiceCtrlDispatcher, 1063,
Error, 7/7/2014 18:16:49, SYSTEM, RACHEL-PC, scheduler, StartServiceCtrlDispatcher, 1063,
(end)
-----------------------------------------------------------------------------------
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126 BrowserJavaVersion: 10.60.2
Run by Rachel at 18:22:48 on 2014-07-07
Microsoft Windows 7 家用進階版 6.1.7601.1.950.852.3076.18.4061.2459 [GMT 8:00]
.
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe
C:\Windows\SysWOW64\svchost.exe -k SDDUpdate
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\svchost -k XLServicePlatform
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AliWangWang\AliIM.exe
C:\Program Files (x86)\alipay\SafeTransaction\TaobaoProtect.exe
C:\Program Files (x86)\alipay\SafeTransaction\Alipaybsm.exe
C:\Program Files (x86)\QvodPlayer\QvodWebBase\1.0.0.47\QvodWebService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\Monitor.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\program files (x86)\avira\antivir desktop\ipmGui.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uProxyOverride = local;<local>
mWinlogon: Userinit = userinit.exe
BHO: {074C1DC5-9320-4A9A-947D-C042949C6216} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: WebDetectorBHO Class: {43BEAFD9-E005-483D-A367-146BA6C8A32E} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: {889D2FEB-5411-4565-8998-1DD2C5261283} - <orphaned>
BHO: QvodExtend: {A8502600-B272-4F68-A67B-A0305D46D297} - C:\Program Files (x86)\QvodPlayer\QvodExtend\5.0.97.0\QvodExtend.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: 捃濘狟婥盓厥郪璃: {DE05CF4A-7B0A-4775-B5E5-396244938679} - C:\Program Files (x86)\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll
uRun: [Akamai NetSession Interface] "C:\Users\Rachel\AppData\Local\Akamai\netsession_win.exe"
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
uRun: [BAIDUMEDIA] C:\Program Files (x86)\Baidu\BaiduPlayer\1.19.0.57\BaiduPlayer.exe minimize
uRun: [hsscp.EXE] C:\Users\Rachel\AppData\Roaming\Hotspot Shield\bin\hsscp.EXE -nonadmin
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
mRun: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
mRun: [Ulead AutoDetector v2] C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [kxesc] "c:\program files (x86)\kingsoft\kingsoft antiviruskxetray.exe" -autorun
mRun: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [EaseUS EPM tray] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EpmNews.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &使用&迅雷下? - <no file>
IE: &使用&迅雷下?全部?接 - <no file>
IE: &使用115优蛋 3下? - <no file>
IE: &使用115优蛋 3下?全部?接 - <no file>
IE: &妏蚚&捃濘燭盄狟婥 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\OfflineDownload.htm
IE: &妏蚚&捃濘狟婥 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\geturl.htm
IE: &妏蚚&捃濘狟婥窒蟈諉 - C:\Program Files (x86)\Thunder Network\Thunder\BHO\GetAllUrl.htm
IE: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
IE: 添加?前?到迅雷看看播放器?? - <no file>
LSP: C:\Program Files (x86)\YouKu\common\ikutm.dll
Trusted Zone: alipay.com
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
Trusted Zone: taobao.com
Trusted Zone: alipay.com
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: alisoft.com
Trusted Zone: gogobox.com.tw
Trusted Zone: gogobox.com.tw
Trusted Zone: taobao.com
Trusted Zone: taobao.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
TCP: NameServer = 218.102.32.134 219.76.98.66
TCP: Interfaces\{AE90874A-C851-4864-9C4D-3EBC134868C5} : DHCPNameServer = 218.102.32.134 219.76.98.66
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: 捃濘狟婥盓厥: {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} - C:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.18.4724.dll
x64-BHO: QvodExtend: {A8502600-B272-4F68-A67B-A0305D46D298} - C:\Program Files (x86)\QvodPlayer\QvodExtend\5.0.97.0\QvodExtend_x64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-6-23 55280]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-5-4 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-1-31 283200]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-6-24 92160]
R2 AlipaySecSvc;Alipay security service;C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [2014-6-4 540032]
R2 AntiVirSchedulerService;Avira 排程管理員;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-5-4 430160]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-5-4 430160]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-5-4 112080]
R2 DeviceHealth;Microsoft Device Health Machine Service;C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe [2014-6-6 85664]
R2 SDDUpdate;SDDUpdate;C:\Windows\System32\svchost.exe -k SDDUpdate [2009-7-14 27136]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-6-23 660800]
R2 XLServicePlatform;XLServicePlatform;C:\Windows\System32\svchost -k XLServicePlatform --> C:\Windows\System32\svchost -k XLServicePlatform [?]
R2 YLMFVDISK;YLMF Virtual Diskette V1;C:\Windows\System32\drivers\VirtDisk64.sys [2012-2-3 23896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2010-6-24 138752]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-7-7 122584]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-24 236544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2014-5-8 108800]
S3 FsUsbExDisk;FsUsbExDisk;C:\Windows\SysWOW64\FsUsbExDisk.Sys [2013-2-14 37344]
S3 HaozipVirtualCDBus;HaoZip Virtual Bus Driver;C:\Windows\System32\drivers\HaoZipVirtualCDBus.sys [2012-7-24 204888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2011-5-10 22528]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2014-5-8 206080]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-2 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 VMUVC;Vimicro Camera Service VMUVC;C:\Windows\System32\drivers\vmuvc.sys [2011-4-23 198400]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;C:\Windows\System32\drivers\vvftUVC.sys [2011-4-23 303616]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-8-2 18216]
S3 WatAdminSvc;Windows 啟用技術服務;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-2 1255736]
S3 WsAudio_Device;WsAudio_Device;C:\Windows\System32\drivers\VirtualAudio.sys [2013-11-1 31080]
S4 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-5-29 1039952]
.
=============== File Associations ===============
.
FileExt: .reg: regfile=regedit.exe "%1" [UserChoice]
FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [UserChoice]
.js: <filetype is not registered>
.
=============== Created Last 30 ================
.
2014-07-07 07:27:18 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-07-07 07:26:38 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-07-07 07:26:38 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-07-07 07:26:38 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-07-07 07:26:37 -------- d-----w- C:\ProgramData\Malwarebytes
2014-07-07 06:51:34 -------- d-----w- C:\ProgramData\Oracle
2014-07-07 06:50:42 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-07 06:24:55 -------- d-----w- C:\Users\Rachel\AppData\Roaming\TaobaoProtect
2014-07-07 06:24:26 -------- d-----w- C:\Program Files (x86)\Microsoft Device Health
2014-07-07 05:45:41 -------- d-----w- C:\Users\Rachel\AppData\Roaming\alipay
2014-06-20 05:48:48 10779000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E19A4B97-11A4-41D6-AC0A-F1DD1B49B05A}\mpengine.dll
2014-06-16 14:38:01 2278912 ----a-w- C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll
2014-06-12 09:21:00 -------- d-----w- C:\Program Files (x86)\Funmily
2014-06-12 09:06:39 -------- d---a-w- C:\Program Files (x86)\HYZGOnline
2014-06-12 07:51:46 -------- d-----w- C:\Users\Rachel\AppData\Roaming\BitCometLite
2014-06-12 07:14:30 5203984 ----a-w- C:\Windows\SysWow64\GameMon.des
2014-06-12 07:14:16 -------- d-----w- C:\Program Files\Common Files\INCA Shared
2014-06-11 15:52:41 506368 ----a-w- C:\Windows\System32\aepdu.dll
2014-06-11 15:52:41 424448 ----a-w- C:\Windows\System32\aeinv.dll
.
==================== Find3M ====================
.
2014-06-04 03:39:19 112080 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2014-05-30 10:02:37 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-05-30 10:02:09 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-05-30 09:39:43 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-05-30 09:39:23 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-05-30 09:38:29 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-05-30 09:21:23 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-05-30 09:21:05 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-05-30 09:20:36 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-05-30 09:11:24 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-05-30 09:08:22 5782528 ----a-w- C:\Windows\System32\jscript9.dll
2014-05-30 09:02:39 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-05-30 08:55:36 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-05-30 08:44:28 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-05-30 08:43:06 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-05-30 08:42:16 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-05-30 08:28:33 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-05-30 08:27:56 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-05-30 08:24:19 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-05-30 08:23:22 2040832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-05-30 08:10:46 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-30 07:56:56 2266112 ----a-w- C:\Windows\System32\wininet.dll
2014-05-30 07:56:50 4244992 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-05-30 07:50:09 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-05-30 07:49:38 1964544 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-05-30 07:21:10 1790976 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-04-25 02:34:59 801280 ----a-w- C:\Windows\System32\usp10.dll
2014-04-25 02:06:17 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2014-04-12 02:22:05 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2014-04-12 02:22:05 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-04-12 02:19:38 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2014-04-12 02:19:38 136192 ----a-w- C:\Windows\System32\sspicli.dll
2014-04-12 02:19:37 28160 ----a-w- C:\Windows\System32\secur32.dll
2014-04-12 02:19:32 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-04-12 02:19:05 31232 ----a-w- C:\Windows\System32\lsass.exe
2014-04-12 02:12:06 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-04-12 02:10:56 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-04-10 05:40:09 159032 ----a-w- C:\Windows\System32\atl90.dll
2014-04-10 05:40:07 655872 ----a-w- C:\Windows\System32\msvcr90.dll
2014-04-10 05:40:07 568832 ----a-w- C:\Windows\System32\msvcp90.dll
2014-04-08 15:30:10 286352 ----a-w- C:\Windows\System32\libbluray.dll
2014-04-08 15:29:48 238736 ----a-w- C:\Windows\SysWow64\libbluray.dll
.
============= FINISH: 18:24:46.74 ===============
-----------------------------------------------------------------------------------------------------------------
ATTACH.txt
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 家用進階版
Boot Device: \Device\HarddiskVolume2
Install Date: 1/7/2010 14:41:52
System Uptime: 7/7/2014 17:15:34 (1 hours ago)
.
Motherboard: Dell Inc. | | 0K83V0
Processor: Pentium(R) Dual-Core CPU E5500 @ 2.80GHz | CPU 1 | 2803/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 290 GiB total, 52.364 GiB free.
D: is CDROM ()
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP724: 26/6/2014 14:00:52 - Removed MSXML 4.0 SP2 (KB954430)
RP725: 26/6/2014 14:03:43 - Removed MSXML 4.0 SP2 (KB973688)
RP726: 26/6/2014 17:01:47 - 已移除 MSXML 4.0 SP3 Parser (KB2721691)
RP727: 7/7/2014 14:49:24 - Installed Java 7 Update 60
.
==== Installed Programs ======================
.
???????????
ACDSee
Adobe AIR
Adobe Anchor Service CS4
Adobe Asset Services CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Recommended Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Contribute CS4
Adobe Creative Suite 4 Web Standard
Adobe CSI CS4
Adobe CSI CS4 x64
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Drive CS4 x64
Adobe Dynamiclink Support
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Fireworks CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI others
Adobe Flash CS4 STI-other
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Importer
Adobe Output Module
Adobe PDF Library Files CS4
Adobe PDistiller
Adobe Reader XI - Chinese Traditional
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Version Cue CS4 Server
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Akamai NetSession Interface
AlipayDHC 1.1.0.0
Audacity 1.3.12 (Unicode)
Avira Free Antivirus
BLACK WOLVES SAGA -Bloody Nightmare-
Bonjour
ComicStudio EX Demo 4.0TC
Connect
Corel VideoStudio Pro Title Pack
DAEMON Tools Lite
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell Edoc Viewer
Dell Support Center (Support Software)
FileMenu Tools
Finale NotePad 2008
Free Studio version 2013
Google Chrome
Google Update Helper
HetaOni ENGLISH Version 15.0
iKu 2
Intel(R) Graphics Media Accelerator Driver
IntelR Matrix Storage Manager
Java 7 Update 60
Java 7 Update 7 (64-bit)
Java Auto Updater
kuler
Malwarebytes Anti-Malware version 2.0.2.1012
Mega Manager
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft AppLocale
Microsoft Choice Guard
Microsoft Office 2000 Professional
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft Windows Application Compatibility Database
Microsoft WSE 3.0 Runtime
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
MPC-HC 1.7.4 (64-bit)
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSXML 4.0 SP3 Parser (KB2758694)
MyFreeCodec
openCanvas4.5.09e Plus
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
RaySource 2.2.0.1
Realtek High Definition Audio Driver
Roxio Burn
SafeTransaction 5.13.0.0
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Suite Shared Configuration CS4
swMSM
Ulead PhotoImpact 11
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 執行階段 3.0
VOCALOID2 Expression DB (Standard)
VOCALOID2 Voice DB (Miku)
Watson
Windows Live Communications Platform
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live 程式集
Windows Live 影像中心
Windows Media Encoder 9 Series
WinRAR 5.10 beta 4 (64-bit)
百度云管家
快播 5.19.185
迅雷看看播放器
阿里旺旺2013Beta2
捃濘7
盓葆惘杅趼痐抎郪璃 2.4.0.0
盓葆惘假諷璃 3.23.0.0
盓葆惘假諷璃 3.8.0.0
雅?~MIYAKO~月詠?夢
微???健康助手
新幻月之歌 Online
歡樂派登入器 版本 1.0
.
==== End Of File ===========================
I have some application in chinese, please ask if there are any problems. Thank you so much.