As stated in the topic I have been infected by Agend.BA, Conedex.B, Sirefef.AP
I have read and performed the 5 steps.
www.malwarebytes.org
Database version: v2012.08.22.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Roy Yip :: ROYYIP-PC [administrator]
Protection: Enabled
22/8/2012 8:21 AM
mbam-log-2012-08-22 (08-21-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 252629
Time elapsed: 2 minute(s), 24 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Windows\Installer\{05e0d007-0ba5-6505-bd5f-380e814a59a0}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Users\Roy Yip\Favorites\Free porn video.url (Rogue.Link) -> Quarantined and deleted successfully.
(end)
====================================================================
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-22 10:39:21
Windows 6.1.7601 Service Pack 1
Running: rpb7un5o.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001bdc0f4394
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001bdc0f4394@002548bd833f 0x1F 0x42 0x71 0xE5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF7 0xB5 0x51 0x14 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5B 0xCB 0x26 0x11 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0xB4 0x91 0x5E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD9 0x56 0xE0 0xF1 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001bdc0f4394 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001bdc0f4394@002548bd833f 0x1F 0x42 0x71 0xE5 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF7 0xB5 0x51 0x14 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x1A 0xDD 0xFC ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0xB4 0x91 0x5E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD9 0x56 0xE0 0xF1 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\Roy Yip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\x300a星海爭霸 II\x300b\\x300a星海爭霸 II\x300b.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\x300a星海爭霸 II\x300b\\x300a星海爭霸 II\x300b.lnk 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@8^(u#\xe46c}摸\0 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@?D} 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@琫\nN 0
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@?琫\0 0
Reg HKCU\Software\Microsoft\Windows Live\Companion\roy392003@yahoo.com.hk@d8816fb1e840ab0254a4dfada7f6c24c\r\n 0x11 0x06 0x50 0x6F ...
---- Files - GMER 1.0.15 ----
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.0.0.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.0.0.\Alcohol Soft Development Team@1.0.0..manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.7.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.7.\Alcohol Soft Development Team@1.9.7..manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.9.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.9.\Alcohol Soft Development Team@1.9.9..manifest 588 bytes
---- EOF - GMER 1.0.15 ----
====================================================================
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Roy Yip at 10:43:08 on 2012-08-22
Microsoft Windows 7 旗艦版 6.1.7601.1.950.852.3076.18.16376.13605 [GMT -7:00]
.
AV: ESET Smart Security 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: 個人防火牆 *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\PPS.tv\PPStream\PPSAP.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\NETGEAR\WN121T\wn121t.exe
C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe
C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\ytbb.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\Roy Yip\Desktop\rpb7un5o.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.charter.net/google/index.php?q=
uStart Page = hxxp://www.yahoo.com.hk/
uWindow Title = Powered by Charter Communications
uInternet Settings,ProxyOverride = local
uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
mWinlogon: Userinit=userinit.exe,
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
BHO: AC-Pro: {0fb6a909-6086-458f-bd92-1f8ee10042a0} - C:\Users\Roy Yip\AppData\Roaming\Complitly\AutocompletePro.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO: WebDetectorBHO Class: {43beafd9-e005-483d-a367-146ba6c8a32e} - C:\Program Files (x86)\Tudou\?速Tudou\tudouDetector.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID 登入協助程式: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
TB: {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [PPS Accelerator] C:\PPS.tv\PPStream\ppsap.exe
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [BiosNotice] C:\Program Files (x86)\BIOSTAR\BiosNotice\BiosNotice.exe
mRun: [PowerPanel Personal Edition User Interaction] C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
mRun: [Antiphishing Domain Advisor] "C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IME14 CHT Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /CHT /Log
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
dRun: [CtxfiReg] CTXFIREG.exe /FAIL1
StartupFolder: C:\Users\ROYYIP~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\速土豆~1.LNK -
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BIO-RE~1.LNK - C:\Program Files (x86)\BIOSTAR\BIO-Remote\BIO_Remote.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WN121T\wn121t.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &使用BitComet下載 - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &使用BitComet下載全部連結 - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: 傳送至 OneNote(&N) - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: 匯出至 Microsoft Excel(&X) - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
LSP: mswsock.dll
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C} : DhcpNameServer = 71.9.127.107 68.190.192.35 68.116.46.115
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C}\37471627771627 : DhcpNameServer = 71.9.127.107 68.190.192.35 68.116.46.115
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C}\A4F686E67237 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B8BC4DE1-5F10-49D7-91BA-A70F9A1960B4} : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
{02478D38-C3F9-4efb-9B51-7695ECA05670}
{0FB6A909-6086-458F-BD92-1F8EE10042A0}
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
{43BEAFD9-E005-483D-A367-146BA6C8A32E}
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9D425283-D487-4337-BAB6-AB8354A81457}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
{9D425283-D487-4337-BAB6-AB8354A81457}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
TB-X64: {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - No File
mRun-x64: [BiosNotice] C:\Program Files (x86)\BIOSTAR\BiosNotice\BiosNotice.exe
mRun-x64: [PowerPanel Personal Edition User Interaction] C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun-x64: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
mRun-x64: [Antiphishing Domain Advisor] "C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe"
mRun-x64: [CTxfiHlp] CTXFIHLP.EXE
mRun-x64: [IME14 CHT Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /CHT /Log
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
IE-X64: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
IE-X64: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE-X64: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE-X64: {92780B25-18CC-41C8-B9BE-3C9C571A8263}
IE-X64: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook
.
============= SERVICES / DRIVERS ===============
.
R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --> C:\Windows\system32\DRIVERS\ahcix64s.sys [?]
R0 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R1 BIOS;BIOS;C:\Windows\System32\drivers\BIOS64.sys [2011-2-20 14136]
R1 BS_I2cIo;BS_I2cIo;\??\C:\Windows\system32\drivers\BS_I2c64.sys --> C:\Windows\system32\drivers\BS_I2c64.sys [?]
R1 BS_TPIO;BS_TPIO;\??\C:\Windows\system32\drivers\BS_TPIO64.sys --> C:\Windows\system32\drivers\BS_TPIO64.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;C:\Windows\system32\DRIVERS\EpfwLWF.sys --> C:\Windows\system32\DRIVERS\EpfwLWF.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-4-5 361984]
R2 AMD_RAIDXpert;AMD RAIDXpert;C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe [2011-8-31 131320]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-9-9 974944]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-5-7 197976]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-22 655944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-6-13 386344]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-1-19 3027840]
R2 WDDMService;WDDMService;C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-12-15 319384]
R2 WDFMEService;WDFME;C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-12-15 1977224]
R2 WDRulesService;WDRules;C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2011-12-15 1338264]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\system32\DRIVERS\LVPr2M64.sys --> C:\Windows\system32\DRIVERS\LVPr2M64.sys [?]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
R3 LVUVC64;QuickCam Pro for Notebooks(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe --> C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-8-14 250056]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service --> C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service [?]
S3 BthAvrcp;Bluetooth AVRCP 組態檔;C:\Windows\system32\DRIVERS\BthAvrcp.sys --> C:\Windows\system32\DRIVERS\BthAvrcp.sys [?]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;\??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS --> C:\Windows\system32\drivers\BVRPMPR5a64.SYS [?]
S3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\system32\drivers\ha20x22k.sys --> C:\Windows\system32\drivers\ha20x22k.sys [?]
S3 MRV6X64U;Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x);C:\Windows\system32\DRIVERS\WN111x.sys --> C:\Windows\system32\DRIVERS\WN111x.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys --> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows 啟用技術服務;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
.
=============== Created Last 30 ================
.
2012-08-22 15:20:05 -------- d-----w- C:\Users\Roy Yip\AppData\Roaming\Malwarebytes
2012-08-22 15:19:54 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-22 15:19:53 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-22 15:19:53 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-22 12:07:31 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{ACF9169F-1CD1-476B-9C0E-F80B8C97D048}
2012-08-22 00:07:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{63490997-CB3E-4E78-B163-C32B984496FE}
2012-08-21 12:06:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{83052195-C2E3-4AB4-A076-15CB0473D700}
2012-08-21 00:06:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{199F1084-1D5D-4D1E-931F-9911B7D1F2C5}
2012-08-20 23:00:33 -------- d-----w- C:\ProgramData\Battle.net
2012-08-20 22:45:04 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-08-20 22:45:04 -------- d-----w- C:\Program Files (x86)\StarCraft II
2012-08-20 22:45:04 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-08-20 12:06:17 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9E110453-E715-4C7B-B6FF-A76CF897764D}
2012-08-20 00:06:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B6761FC3-3DEB-4381-8A9A-EEDE0D5154DA}
2012-08-19 12:05:52 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{DA031531-C94A-442D-A360-264AF0A932A3}
2012-08-19 00:05:39 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{0AA137AD-C40A-4AD5-8CA5-050F9B248690}
2012-08-18 12:05:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3BFA2964-9DED-4BBB-8054-50E500CC4866}
2012-08-18 00:04:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6690BC6B-96EE-4ED1-B71D-CFDDC28F1C28}
2012-08-17 09:30:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9EC34FF4-CB67-49EB-86D0-93088119888F}
2012-08-17 09:30:23 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{AFC381E6-0279-4172-8FA5-302343002404}
2012-08-16 21:31:09 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8DFE87C6-74F4-4C6B-B097-4E01745909D0}
2012-08-16 09:30:45 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{468A4D13-AFF7-4F7F-A100-1A0B899CE983}
2012-08-16 09:30:23 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4E723BBE-562C-40B8-B5D8-3A3A5335A358}
2012-08-15 21:29:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5D26C4F5-5E5C-4B72-B10B-A6F240D84A6C}
2012-08-15 21:29:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C49B059A-BAF3-41AD-838C-4D7971C2C11B}
2012-08-15 10:04:24 552960 ----a-w- C:\Windows\System32\drivers\bthport.sys
2012-08-15 07:42:42 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-08-15 00:58:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C4A47706-2335-4471-9710-0753847B01CB}
2012-08-15 00:58:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4A27EC3B-2E2F-4BC0-858F-6E7571AB69A3}
2012-08-14 14:18:30 -------- d-----w- C:\Program Files\CPUID
2012-08-14 14:06:07 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-14 14:06:07 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-08-14 12:57:58 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{7EAFAAB3-37CF-49BB-B510-BBAFB926ACBD}
2012-08-14 12:57:30 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F33E184B-C00A-4875-9CAB-7D7197DD62C4}
2012-08-14 05:53:24 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BF2D6CD0-83AA-46A6-9C0C-66309842971D}
2012-08-14 05:53:01 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{53C15148-8777-419E-A8D3-08647DDA1DEA}
2012-08-13 17:52:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5383E5EE-88AA-4D0D-864D-7A109AF2E69D}
2012-08-13 17:52:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{580633FE-07B6-4841-9D18-529FC6B6A7F4}
2012-08-13 05:51:37 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{12FC1627-06B6-4C4A-8C08-A4E9546F69F0}
2012-08-13 05:51:14 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{24C18583-5591-4F08-AF95-D24028FFC043}
2012-08-12 17:50:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4FB48938-E7F4-4F39-A448-F2A041A1F02C}
2012-08-12 17:50:24 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{211A0E65-9125-40B9-81D1-FF4F68D152A2}
2012-08-12 05:49:58 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{19EACD02-E456-41CF-B96C-811BB1DBBDF5}
2012-08-12 05:49:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3114121F-4A21-4368-AEA9-B67C8105F564}
2012-08-11 17:49:09 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{46DF1A1A-9B4E-4681-BDF9-738B987FD84D}
2012-08-11 17:48:47 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1A14E8CC-B835-4B80-A133-BBA51EFB1305}
2012-08-11 05:48:22 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{EE29170B-8606-48CF-9926-EFC984798AA6}
2012-08-11 05:47:59 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{26410040-5714-4C5B-86B7-A802FF2CB2D0}
2012-08-10 17:47:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5E19881C-8065-47AF-8B0F-3147ABA31138}
2012-08-10 17:47:12 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{320ECA2D-FB29-4252-9B96-F3377F1C788D}
2012-08-10 05:46:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D86488D1-47DC-4E59-9AA0-3FE52B3FABE1}
2012-08-10 05:46:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{CA0DFE5D-7F60-43F5-90EE-42EC7486DC1A}
2012-08-09 17:47:57 -------- d-----w- C:\Users\Roy Yip\AppData\Roaming\AnvSoft
2012-08-09 17:47:42 -------- d-----w- C:\Program Files (x86)\AnvSoft
2012-08-09 17:46:03 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6A4FA2EE-F8A2-44D4-891D-4756A76FF8AB}
2012-08-09 17:45:41 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{AD756DD4-7AFC-4B05-B980-F38C3A4DEB8E}
2012-08-09 05:45:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{15D45FC8-F6DC-4196-AB70-512D77539EF5}
2012-08-09 05:44:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A269BFEE-57F6-4269-AFDF-0A430673BF67}
2012-08-08 17:44:18 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A6C94227-D5B3-4BD5-A427-63648313CA94}
2012-08-08 17:43:56 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4C4041AA-ABB4-4B51-BC9C-DF420C34A27A}
2012-08-08 05:43:33 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B8102E89-BE15-4671-A263-347286D8A655}
2012-08-08 05:43:07 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6DC7EB9B-2BAE-4CF9-803A-F98D119E27CE}
2012-08-07 17:42:44 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B69473C5-54E4-4B0A-A0E2-2036816D061C}
2012-08-07 17:42:22 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B3276097-62A5-458C-9187-C5839BAE7C65}
2012-08-07 05:41:55 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6A1EA3BD-AECC-41DB-8BC6-B05D98064C65}
2012-08-07 05:41:43 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B35F87F6-1FFB-48AE-809D-572CBF197ED6}
2012-08-06 17:41:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{34AC9246-9773-45A0-BAFB-A3999F28D6CF}
2012-08-06 17:41:16 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{814BCCB6-CFD9-4DCC-B42A-E3F07CC21300}
2012-08-06 05:40:51 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{482494B0-E705-4609-B3ED-F93B07AB8570}
2012-08-06 05:40:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2804BC33-900A-49BA-BBEC-F014668D588F}
2012-08-05 17:40:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{24E514C4-1A8C-4F61-9EEC-BE763A1ECF14}
2012-08-05 17:39:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{611EE387-9777-47E3-8B65-0C1FB26A9911}
2012-08-05 05:39:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9AEF48F7-ADA8-44EB-8FA4-CE58C82CD304}
2012-08-05 05:38:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{79BDF927-A1DA-47F9-B3F6-F8EF0A07ACCC}
2012-08-04 17:38:33 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{696929C8-C2E0-408D-9F4C-DE90B77B0FFD}
2012-08-04 17:38:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D6AC97F9-A5E7-428F-AE59-4BC1B95B3FF5}
2012-08-04 05:37:48 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3E8E3C9F-4D2D-46B1-B3A1-4F259644D1DA}
2012-08-04 05:37:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A214482A-860D-4A06-8437-663F11A57B5D}
2012-08-03 17:36:50 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BCD290C9-9AFB-4F3E-9DDE-CCB5CF8E348C}
2012-08-03 17:36:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{EB935108-B16E-4FEF-A7F8-3EC0EC2427DC}
2012-08-03 05:36:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{E2933D49-5F64-494A-962C-1169877C9BCC}
2012-08-03 05:35:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8E29FA66-D960-4A1C-983C-DDF2694D8CD3}
2012-08-02 17:35:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2A82CBA1-64BA-4BC1-B6A6-B0BEC808F496}
2012-08-02 17:34:56 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{7DDF60BB-3401-416F-918D-81C5C0C7A0AF}
2012-08-02 07:40:55 16 ----a-w- C:\Windows\SysWow64\22AS6EJH.dll
2012-08-02 07:32:26 -------- d-----w- C:\Program Files (x86)\蜓樅毞狟5
2012-08-02 05:34:20 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F398C358-0CA3-4F9E-8A96-CE37D8AAC168}
2012-08-02 05:33:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{041500D4-9675-448F-863E-0DC5EAE31C8F}
2012-08-01 17:33:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1F7DD50A-71DF-4B38-918B-AB4BD2B28B7A}
2012-08-01 17:33:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2D52F759-7164-442B-B2E7-63F92CCC44DF}
2012-08-01 05:32:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6740FF7B-AE98-46BA-94EC-1184549B6D87}
2012-08-01 05:32:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4C8788E9-7913-4654-9110-517BB270DE8A}
2012-07-31 23:32:24 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2012-07-31 17:50:24 -------- d-----w- C:\Program Files\T-TIME
2012-07-31 17:31:51 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D54EE760-BDD9-4173-B4ED-111786DF56E7}
2012-07-31 17:31:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8A8770F0-CBA6-43E8-9B09-C3058DCD419E}
2012-07-31 05:30:52 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D51543CA-F39C-4DAF-AA55-62E4CE486436}
2012-07-31 05:30:30 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D293A778-7930-4435-A12D-DD820A46817B}
2012-07-30 17:30:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{372B8875-0C8A-4342-8E69-4082DD78A9C9}
2012-07-30 17:29:44 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{221A3F42-CC5F-4803-BC10-009149DCC753}
2012-07-30 10:28:04 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-07-30 10:28:04 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-07-30 05:29:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{78DBD22D-1789-4E5C-8629-34A5AD48B4BA}
2012-07-30 05:28:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{85A7A9A2-C6B6-4B15-AAC0-37B967D223D1}
2012-07-29 17:28:16 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{159B28E9-40B8-4E3D-980C-A1028B2C68D7}
2012-07-29 17:27:53 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{FD368396-22D8-433B-A101-DB914E0F4FA4}
2012-07-29 05:27:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{337544D9-2DC0-4292-8DC5-E427A13CD7DD}
2012-07-29 05:27:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C32A417E-BB2B-4EC9-90A2-5F60FAA62FEB}
2012-07-28 17:26:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6D265A40-49C3-4913-B258-30CDED8BB59A}
2012-07-28 17:26:20 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F7FE290C-8CDF-49B4-BCE6-F12A372E75CD}
2012-07-28 05:25:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9A47CB7C-0784-46BE-A9E7-E2BBA0B25A4B}
2012-07-28 05:25:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{023A6F4E-6699-4FB1-BFF7-E731F408D7C2}
2012-07-27 17:25:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{12DDA58D-A402-4ACF-9EE5-7526A8980E6A}
2012-07-27 17:24:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A75FDC00-1C9D-4B90-844C-C86E631735EF}
2012-07-27 05:24:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{755A5476-CC78-4FED-96A1-A8AC73D119C5}
2012-07-27 05:24:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D64988D1-197B-4D77-93F9-B2C97CA1D306}
2012-07-26 17:23:25 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{E583F511-51AE-4C5E-B341-090BFD6AE47D}
2012-07-26 17:23:02 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5845E1E4-95C3-41FB-B306-60F0CB7C2330}
2012-07-26 05:22:37 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F9A93FAB-66D4-461E-A574-515AFFBDA885}
2012-07-26 05:22:14 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{80738819-E7C1-4D7A-99DD-2FD5854D4673}
2012-07-25 17:21:50 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{190ED281-1CDC-4C6E-8294-811F5C5CB255}
2012-07-25 17:21:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1CD56FC7-9B7D-42E5-AD3D-92E95F83A251}
2012-07-25 05:21:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BB45A82B-434A-46F0-B3DD-172A8150116D}
2012-07-25 05:20:41 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{184DD765-30C2-47F4-872B-06287893CE27}
2012-07-24 17:20:18 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{67094822-F382-4425-BB4C-35BEBCA9AB8D}
2012-07-24 17:19:55 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C2D73A27-53E8-4541-8737-6E0FDC877954}
2012-07-24 05:19:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4CBEBC53-FB5A-43A2-AAB2-582064BA4ABF}
2012-07-24 05:19:00 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{834EBA7D-E67C-4C05-816A-43AEDBC1E554}
.
==================== Find3M ====================
.
2012-08-20 11:34:04 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-08-04 10:48:56 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-04 22:13:27 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-07-04 22:13:27 136704 ----a-w- C:\Windows\System32\browser.dll
2012-07-04 21:14:34 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-06-27 07:06:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-06-27 05:53:07 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-27 04:53:10 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-27 04:10:55 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-16 05:16:04 609792 ----a-w- C:\Windows\System32\vbscript.dll
2012-06-16 04:26:57 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-06-07 03:59:42 1070152 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 10:43:28.90 ===============
I have read and performed the 5 steps.
- Malwarebytes Anti-Malware log
- GMER log
- DDS logs: both DDS.txt and Attach.txt
www.malwarebytes.org
Database version: v2012.08.22.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Roy Yip :: ROYYIP-PC [administrator]
Protection: Enabled
22/8/2012 8:21 AM
mbam-log-2012-08-22 (08-21-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 252629
Time elapsed: 2 minute(s), 24 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Windows\Installer\{05e0d007-0ba5-6505-bd5f-380e814a59a0}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Users\Roy Yip\Favorites\Free porn video.url (Rogue.Link) -> Quarantined and deleted successfully.
(end)
====================================================================
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-22 10:39:21
Windows 6.1.7601 Service Pack 1
Running: rpb7un5o.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001bdc0f4394
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001bdc0f4394@002548bd833f 0x1F 0x42 0x71 0xE5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF7 0xB5 0x51 0x14 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5B 0xCB 0x26 0x11 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0xB4 0x91 0x5E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD9 0x56 0xE0 0xF1 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001bdc0f4394 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001bdc0f4394@002548bd833f 0x1F 0x42 0x71 0xE5 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF7 0xB5 0x51 0x14 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x1A 0xDD 0xFC ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFB 0xB4 0x91 0x5E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD9 0x56 0xE0 0xF1 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\Roy Yip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\x300a星海爭霸 II\x300b\\x300a星海爭霸 II\x300b.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\x300a星海爭霸 II\x300b\\x300a星海爭霸 II\x300b.lnk 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@8^(u#\xe46c}摸\0 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@?D} 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@琫\nN 0
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3074714069\Groups@?琫\0 0
Reg HKCU\Software\Microsoft\Windows Live\Companion\roy392003@yahoo.com.hk@d8816fb1e840ab0254a4dfada7f6c24c\r\n 0x11 0x06 0x50 0x6F ...
---- Files - GMER 1.0.15 ----
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.0.0.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.0.0.\Alcohol Soft Development Team@1.0.0..manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.7.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.7.\Alcohol Soft Development Team@1.9.7..manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.9.\Alcohol Soft Development Team.manifest 588 bytes
File C:\Users\Roy Yip\AppData\Local\Xenocode\Sandbox\LdR_Alcohol_r.exe\2.0.1.2033\2010.09.18T21.28\Virtual\SXS\Alcohol Soft Development Team@1.9.9.\Alcohol Soft Development Team@1.9.9..manifest 588 bytes
---- EOF - GMER 1.0.15 ----
====================================================================
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Roy Yip at 10:43:08 on 2012-08-22
Microsoft Windows 7 旗艦版 6.1.7601.1.950.852.3076.18.16376.13605 [GMT -7:00]
.
AV: ESET Smart Security 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: 個人防火牆 *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\CyberLink\Shared files\RichVideo64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\PPS.tv\PPStream\PPSAP.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\NETGEAR\WN121T\wn121t.exe
C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe
C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\ytbb.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\Roy Yip\Desktop\rpb7un5o.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.charter.net/google/index.php?q=
uStart Page = hxxp://www.yahoo.com.hk/
uWindow Title = Powered by Charter Communications
uInternet Settings,ProxyOverride = local
uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
mWinlogon: Userinit=userinit.exe,
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
BHO: AC-Pro: {0fb6a909-6086-458f-bd92-1f8ee10042a0} - C:\Users\Roy Yip\AppData\Roaming\Complitly\AutocompletePro.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO: WebDetectorBHO Class: {43beafd9-e005-483d-a367-146ba6c8a32e} - C:\Program Files (x86)\Tudou\?速Tudou\tudouDetector.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID 登入協助程式: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
TB: {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [PPS Accelerator] C:\PPS.tv\PPStream\ppsap.exe
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [BiosNotice] C:\Program Files (x86)\BIOSTAR\BiosNotice\BiosNotice.exe
mRun: [PowerPanel Personal Edition User Interaction] C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
mRun: [Antiphishing Domain Advisor] "C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IME14 CHT Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /CHT /Log
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
dRun: [CtxfiReg] CTXFIREG.exe /FAIL1
StartupFolder: C:\Users\ROYYIP~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\速土豆~1.LNK -
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BIO-RE~1.LNK - C:\Program Files (x86)\BIOSTAR\BIO-Remote\BIO_Remote.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WN121T\wn121t.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &使用BitComet下載 - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &使用BitComet下載全部連結 - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: 傳送至 OneNote(&N) - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: 匯出至 Microsoft Excel(&X) - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
LSP: mswsock.dll
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C} : DhcpNameServer = 71.9.127.107 68.190.192.35 68.116.46.115
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C}\37471627771627 : DhcpNameServer = 71.9.127.107 68.190.192.35 68.116.46.115
TCP: Interfaces\{09C5506C-D5CF-4F35-BCFC-9607CEEA793C}\A4F686E67237 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B8BC4DE1-5F10-49D7-91BA-A70F9A1960B4} : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
{02478D38-C3F9-4efb-9B51-7695ECA05670}
{0FB6A909-6086-458F-BD92-1F8EE10042A0}
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
{43BEAFD9-E005-483D-A367-146BA6C8A32E}
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9D425283-D487-4337-BAB6-AB8354A81457}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
{9D425283-D487-4337-BAB6-AB8354A81457}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
TB-X64: {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - No File
mRun-x64: [BiosNotice] C:\Program Files (x86)\BIOSTAR\BiosNotice\BiosNotice.exe
mRun-x64: [PowerPanel Personal Edition User Interaction] C:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun-x64: [YMailAdvisor] "C:\Program Files (x86)\Yahoo!\Common\YMailAdvisor.exe"
mRun-x64: [Antiphishing Domain Advisor] "C:\ProgramData\Antiphishing Domain Advisor\vmn3_5dn.exe"
mRun-x64: [CTxfiHlp] CTXFIHLP.EXE
mRun-x64: [IME14 CHT Uninstall] C:\Program Files (x86)\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE /Uninstall /CHT /Log
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
IE-X64: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
IE-X64: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE-X64: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files (x86)\Amazon\Add to Wish List IE Extension\run.htm
IE-X64: {92780B25-18CC-41C8-B9BE-3C9C571A8263}
IE-X64: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook
.
============= SERVICES / DRIVERS ===============
.
R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --> C:\Windows\system32\DRIVERS\ahcix64s.sys [?]
R0 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R1 BIOS;BIOS;C:\Windows\System32\drivers\BIOS64.sys [2011-2-20 14136]
R1 BS_I2cIo;BS_I2cIo;\??\C:\Windows\system32\drivers\BS_I2c64.sys --> C:\Windows\system32\drivers\BS_I2c64.sys [?]
R1 BS_TPIO;BS_TPIO;\??\C:\Windows\system32\drivers\BS_TPIO64.sys --> C:\Windows\system32\drivers\BS_TPIO64.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;C:\Windows\system32\DRIVERS\EpfwLWF.sys --> C:\Windows\system32\DRIVERS\EpfwLWF.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-4-5 361984]
R2 AMD_RAIDXpert;AMD RAIDXpert;C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe [2011-8-31 131320]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-9-9 974944]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-5-7 197976]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-22 655944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-6-13 386344]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-1-19 3027840]
R2 WDDMService;WDDMService;C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-12-15 319384]
R2 WDFMEService;WDFME;C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-12-15 1977224]
R2 WDRulesService;WDRules;C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2011-12-15 1338264]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\system32\DRIVERS\LVPr2M64.sys --> C:\Windows\system32\DRIVERS\LVPr2M64.sys [?]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
R3 LVUVC64;QuickCam Pro for Notebooks(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe --> C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-8-14 250056]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service --> C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service [?]
S3 BthAvrcp;Bluetooth AVRCP 組態檔;C:\Windows\system32\DRIVERS\BthAvrcp.sys --> C:\Windows\system32\DRIVERS\BthAvrcp.sys [?]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;\??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS --> C:\Windows\system32\drivers\BVRPMPR5a64.SYS [?]
S3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\system32\drivers\ha20x22k.sys --> C:\Windows\system32\drivers\ha20x22k.sys [?]
S3 MRV6X64U;Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x);C:\Windows\system32\DRIVERS\WN111x.sys --> C:\Windows\system32\DRIVERS\WN111x.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys --> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows 啟用技術服務;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
.
=============== Created Last 30 ================
.
2012-08-22 15:20:05 -------- d-----w- C:\Users\Roy Yip\AppData\Roaming\Malwarebytes
2012-08-22 15:19:54 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-22 15:19:53 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-22 15:19:53 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-22 12:07:31 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{ACF9169F-1CD1-476B-9C0E-F80B8C97D048}
2012-08-22 00:07:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{63490997-CB3E-4E78-B163-C32B984496FE}
2012-08-21 12:06:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{83052195-C2E3-4AB4-A076-15CB0473D700}
2012-08-21 00:06:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{199F1084-1D5D-4D1E-931F-9911B7D1F2C5}
2012-08-20 23:00:33 -------- d-----w- C:\ProgramData\Battle.net
2012-08-20 22:45:04 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-08-20 22:45:04 -------- d-----w- C:\Program Files (x86)\StarCraft II
2012-08-20 22:45:04 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-08-20 12:06:17 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9E110453-E715-4C7B-B6FF-A76CF897764D}
2012-08-20 00:06:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B6761FC3-3DEB-4381-8A9A-EEDE0D5154DA}
2012-08-19 12:05:52 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{DA031531-C94A-442D-A360-264AF0A932A3}
2012-08-19 00:05:39 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{0AA137AD-C40A-4AD5-8CA5-050F9B248690}
2012-08-18 12:05:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3BFA2964-9DED-4BBB-8054-50E500CC4866}
2012-08-18 00:04:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6690BC6B-96EE-4ED1-B71D-CFDDC28F1C28}
2012-08-17 09:30:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9EC34FF4-CB67-49EB-86D0-93088119888F}
2012-08-17 09:30:23 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{AFC381E6-0279-4172-8FA5-302343002404}
2012-08-16 21:31:09 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8DFE87C6-74F4-4C6B-B097-4E01745909D0}
2012-08-16 09:30:45 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{468A4D13-AFF7-4F7F-A100-1A0B899CE983}
2012-08-16 09:30:23 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4E723BBE-562C-40B8-B5D8-3A3A5335A358}
2012-08-15 21:29:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5D26C4F5-5E5C-4B72-B10B-A6F240D84A6C}
2012-08-15 21:29:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C49B059A-BAF3-41AD-838C-4D7971C2C11B}
2012-08-15 10:04:24 552960 ----a-w- C:\Windows\System32\drivers\bthport.sys
2012-08-15 07:42:42 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-08-15 00:58:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C4A47706-2335-4471-9710-0753847B01CB}
2012-08-15 00:58:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4A27EC3B-2E2F-4BC0-858F-6E7571AB69A3}
2012-08-14 14:18:30 -------- d-----w- C:\Program Files\CPUID
2012-08-14 14:06:07 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-14 14:06:07 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-08-14 12:57:58 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{7EAFAAB3-37CF-49BB-B510-BBAFB926ACBD}
2012-08-14 12:57:30 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F33E184B-C00A-4875-9CAB-7D7197DD62C4}
2012-08-14 05:53:24 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BF2D6CD0-83AA-46A6-9C0C-66309842971D}
2012-08-14 05:53:01 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{53C15148-8777-419E-A8D3-08647DDA1DEA}
2012-08-13 17:52:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5383E5EE-88AA-4D0D-864D-7A109AF2E69D}
2012-08-13 17:52:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{580633FE-07B6-4841-9D18-529FC6B6A7F4}
2012-08-13 05:51:37 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{12FC1627-06B6-4C4A-8C08-A4E9546F69F0}
2012-08-13 05:51:14 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{24C18583-5591-4F08-AF95-D24028FFC043}
2012-08-12 17:50:46 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4FB48938-E7F4-4F39-A448-F2A041A1F02C}
2012-08-12 17:50:24 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{211A0E65-9125-40B9-81D1-FF4F68D152A2}
2012-08-12 05:49:58 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{19EACD02-E456-41CF-B96C-811BB1DBBDF5}
2012-08-12 05:49:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3114121F-4A21-4368-AEA9-B67C8105F564}
2012-08-11 17:49:09 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{46DF1A1A-9B4E-4681-BDF9-738B987FD84D}
2012-08-11 17:48:47 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1A14E8CC-B835-4B80-A133-BBA51EFB1305}
2012-08-11 05:48:22 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{EE29170B-8606-48CF-9926-EFC984798AA6}
2012-08-11 05:47:59 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{26410040-5714-4C5B-86B7-A802FF2CB2D0}
2012-08-10 17:47:35 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5E19881C-8065-47AF-8B0F-3147ABA31138}
2012-08-10 17:47:12 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{320ECA2D-FB29-4252-9B96-F3377F1C788D}
2012-08-10 05:46:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D86488D1-47DC-4E59-9AA0-3FE52B3FABE1}
2012-08-10 05:46:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{CA0DFE5D-7F60-43F5-90EE-42EC7486DC1A}
2012-08-09 17:47:57 -------- d-----w- C:\Users\Roy Yip\AppData\Roaming\AnvSoft
2012-08-09 17:47:42 -------- d-----w- C:\Program Files (x86)\AnvSoft
2012-08-09 17:46:03 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6A4FA2EE-F8A2-44D4-891D-4756A76FF8AB}
2012-08-09 17:45:41 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{AD756DD4-7AFC-4B05-B980-F38C3A4DEB8E}
2012-08-09 05:45:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{15D45FC8-F6DC-4196-AB70-512D77539EF5}
2012-08-09 05:44:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A269BFEE-57F6-4269-AFDF-0A430673BF67}
2012-08-08 17:44:18 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A6C94227-D5B3-4BD5-A427-63648313CA94}
2012-08-08 17:43:56 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4C4041AA-ABB4-4B51-BC9C-DF420C34A27A}
2012-08-08 05:43:33 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B8102E89-BE15-4671-A263-347286D8A655}
2012-08-08 05:43:07 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6DC7EB9B-2BAE-4CF9-803A-F98D119E27CE}
2012-08-07 17:42:44 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B69473C5-54E4-4B0A-A0E2-2036816D061C}
2012-08-07 17:42:22 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B3276097-62A5-458C-9187-C5839BAE7C65}
2012-08-07 05:41:55 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6A1EA3BD-AECC-41DB-8BC6-B05D98064C65}
2012-08-07 05:41:43 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{B35F87F6-1FFB-48AE-809D-572CBF197ED6}
2012-08-06 17:41:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{34AC9246-9773-45A0-BAFB-A3999F28D6CF}
2012-08-06 17:41:16 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{814BCCB6-CFD9-4DCC-B42A-E3F07CC21300}
2012-08-06 05:40:51 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{482494B0-E705-4609-B3ED-F93B07AB8570}
2012-08-06 05:40:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2804BC33-900A-49BA-BBEC-F014668D588F}
2012-08-05 17:40:05 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{24E514C4-1A8C-4F61-9EEC-BE763A1ECF14}
2012-08-05 17:39:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{611EE387-9777-47E3-8B65-0C1FB26A9911}
2012-08-05 05:39:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9AEF48F7-ADA8-44EB-8FA4-CE58C82CD304}
2012-08-05 05:38:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{79BDF927-A1DA-47F9-B3F6-F8EF0A07ACCC}
2012-08-04 17:38:33 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{696929C8-C2E0-408D-9F4C-DE90B77B0FFD}
2012-08-04 17:38:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D6AC97F9-A5E7-428F-AE59-4BC1B95B3FF5}
2012-08-04 05:37:48 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{3E8E3C9F-4D2D-46B1-B3A1-4F259644D1DA}
2012-08-04 05:37:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A214482A-860D-4A06-8437-663F11A57B5D}
2012-08-03 17:36:50 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BCD290C9-9AFB-4F3E-9DDE-CCB5CF8E348C}
2012-08-03 17:36:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{EB935108-B16E-4FEF-A7F8-3EC0EC2427DC}
2012-08-03 05:36:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{E2933D49-5F64-494A-962C-1169877C9BCC}
2012-08-03 05:35:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8E29FA66-D960-4A1C-983C-DDF2694D8CD3}
2012-08-02 17:35:19 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2A82CBA1-64BA-4BC1-B6A6-B0BEC808F496}
2012-08-02 17:34:56 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{7DDF60BB-3401-416F-918D-81C5C0C7A0AF}
2012-08-02 07:40:55 16 ----a-w- C:\Windows\SysWow64\22AS6EJH.dll
2012-08-02 07:32:26 -------- d-----w- C:\Program Files (x86)\蜓樅毞狟5
2012-08-02 05:34:20 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F398C358-0CA3-4F9E-8A96-CE37D8AAC168}
2012-08-02 05:33:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{041500D4-9675-448F-863E-0DC5EAE31C8F}
2012-08-01 17:33:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1F7DD50A-71DF-4B38-918B-AB4BD2B28B7A}
2012-08-01 17:33:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{2D52F759-7164-442B-B2E7-63F92CCC44DF}
2012-08-01 05:32:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6740FF7B-AE98-46BA-94EC-1184549B6D87}
2012-08-01 05:32:27 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4C8788E9-7913-4654-9110-517BB270DE8A}
2012-07-31 23:32:24 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2012-07-31 17:50:24 -------- d-----w- C:\Program Files\T-TIME
2012-07-31 17:31:51 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D54EE760-BDD9-4173-B4ED-111786DF56E7}
2012-07-31 17:31:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{8A8770F0-CBA6-43E8-9B09-C3058DCD419E}
2012-07-31 05:30:52 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D51543CA-F39C-4DAF-AA55-62E4CE486436}
2012-07-31 05:30:30 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D293A778-7930-4435-A12D-DD820A46817B}
2012-07-30 17:30:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{372B8875-0C8A-4342-8E69-4082DD78A9C9}
2012-07-30 17:29:44 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{221A3F42-CC5F-4803-BC10-009149DCC753}
2012-07-30 10:28:04 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-07-30 10:28:04 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-07-30 05:29:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{78DBD22D-1789-4E5C-8629-34A5AD48B4BA}
2012-07-30 05:28:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{85A7A9A2-C6B6-4B15-AAC0-37B967D223D1}
2012-07-29 17:28:16 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{159B28E9-40B8-4E3D-980C-A1028B2C68D7}
2012-07-29 17:27:53 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{FD368396-22D8-433B-A101-DB914E0F4FA4}
2012-07-29 05:27:29 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{337544D9-2DC0-4292-8DC5-E427A13CD7DD}
2012-07-29 05:27:06 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C32A417E-BB2B-4EC9-90A2-5F60FAA62FEB}
2012-07-28 17:26:42 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{6D265A40-49C3-4913-B258-30CDED8BB59A}
2012-07-28 17:26:20 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F7FE290C-8CDF-49B4-BCE6-F12A372E75CD}
2012-07-28 05:25:57 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{9A47CB7C-0784-46BE-A9E7-E2BBA0B25A4B}
2012-07-28 05:25:34 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{023A6F4E-6699-4FB1-BFF7-E731F408D7C2}
2012-07-27 17:25:11 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{12DDA58D-A402-4ACF-9EE5-7526A8980E6A}
2012-07-27 17:24:49 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{A75FDC00-1C9D-4B90-844C-C86E631735EF}
2012-07-27 05:24:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{755A5476-CC78-4FED-96A1-A8AC73D119C5}
2012-07-27 05:24:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{D64988D1-197B-4D77-93F9-B2C97CA1D306}
2012-07-26 17:23:25 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{E583F511-51AE-4C5E-B341-090BFD6AE47D}
2012-07-26 17:23:02 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{5845E1E4-95C3-41FB-B306-60F0CB7C2330}
2012-07-26 05:22:37 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{F9A93FAB-66D4-461E-A574-515AFFBDA885}
2012-07-26 05:22:14 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{80738819-E7C1-4D7A-99DD-2FD5854D4673}
2012-07-25 17:21:50 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{190ED281-1CDC-4C6E-8294-811F5C5CB255}
2012-07-25 17:21:28 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{1CD56FC7-9B7D-42E5-AD3D-92E95F83A251}
2012-07-25 05:21:04 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{BB45A82B-434A-46F0-B3DD-172A8150116D}
2012-07-25 05:20:41 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{184DD765-30C2-47F4-872B-06287893CE27}
2012-07-24 17:20:18 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{67094822-F382-4425-BB4C-35BEBCA9AB8D}
2012-07-24 17:19:55 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{C2D73A27-53E8-4541-8737-6E0FDC877954}
2012-07-24 05:19:26 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{4CBEBC53-FB5A-43A2-AAB2-582064BA4ABF}
2012-07-24 05:19:00 -------- d-----w- C:\Users\Roy Yip\AppData\Local\{834EBA7D-E67C-4C05-816A-43AEDBC1E554}
.
==================== Find3M ====================
.
2012-08-20 11:34:04 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-08-04 10:48:56 107832 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-04 22:13:27 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-07-04 22:13:27 136704 ----a-w- C:\Windows\System32\browser.dll
2012-07-04 21:14:34 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-06-27 07:06:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-06-27 05:53:07 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-27 04:53:10 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-27 04:10:55 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-16 05:16:04 609792 ----a-w- C:\Windows\System32\vbscript.dll
2012-06-16 04:26:57 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-06-07 03:59:42 1070152 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 10:43:28.90 ===============