c:\users\Dean\AppData\Local\Microsoft\Windows\Temporary Internet Files\update_v1.3.dat
c:\users\Dean\AppData\Roaming\baidu\hao123
c:\windows\apppatch\AppLoc.exe
c:\windows\Downloaded Program Files\52623099
c:\windows\Downloaded Program Files\52623099\BaiduSetupAx_0.dll
c:\windows\Downloaded Program Files\52623099\npxbdsetup.dll
c:\windows\Downloaded Program Files\655368
c:\windows\Downloaded Program Files\655368\SetupAx.dll
c:\windows\Downloaded Program Files\749023
c:\windows\Downloaded Program Files\749023\BaiduSetupAx_0.dll
c:\windows\Downloaded Program Files\749023\npxbdsetup.dll
c:\windows\PFRO.log
c:\windows\SysWow64\html
c:\windows\SysWow64\html\calendar.html
c:\windows\SysWow64\html\calendarbottom.html
c:\windows\SysWow64\html\calendartop.html
c:\windows\SysWow64\html\crystalexportdialog.htm
c:\windows\SysWow64\html\crystalprinthost.html
c:\windows\SysWow64\images
c:\windows\SysWow64\images\toolbar\calendar.gif
c:\windows\SysWow64\images\toolbar\crlogo.gif
c:\windows\SysWow64\images\toolbar\export.gif
c:\windows\SysWow64\images\toolbar\export_over.gif
c:\windows\SysWow64\images\toolbar\exportd.gif
c:\windows\SysWow64\images\toolbar\First.gif
c:\windows\SysWow64\images\toolbar\first_over.gif
c:\windows\SysWow64\images\toolbar\Firstd.gif
c:\windows\SysWow64\images\toolbar\gotopage.gif
c:\windows\SysWow64\images\toolbar\gotopage_over.gif
c:\windows\SysWow64\images\toolbar\gotopaged.gif
c:\windows\SysWow64\images\toolbar\grouptree.gif
c:\windows\SysWow64\images\toolbar\grouptree_over.gif
c:\windows\SysWow64\images\toolbar\grouptreed.gif
c:\windows\SysWow64\images\toolbar\grouptreepressed.gif
c:\windows\SysWow64\images\toolbar\Last.gif
c:\windows\SysWow64\images\toolbar\last_over.gif
c:\windows\SysWow64\images\toolbar\Lastd.gif
c:\windows\SysWow64\images\toolbar\Next.gif
c:\windows\SysWow64\images\toolbar\next_over.gif
c:\windows\SysWow64\images\toolbar\Nextd.gif
c:\windows\SysWow64\images\toolbar\Prev.gif
c:\windows\SysWow64\images\toolbar\prev_over.gif
c:\windows\SysWow64\images\toolbar\Prevd.gif
c:\windows\SysWow64\images\toolbar\print.gif
c:\windows\SysWow64\images\toolbar\print_over.gif
c:\windows\SysWow64\images\toolbar\printd.gif
c:\windows\SysWow64\images\toolbar\Refresh.gif
c:\windows\SysWow64\images\toolbar\refresh_over.gif
c:\windows\SysWow64\images\toolbar\refreshd.gif
c:\windows\SysWow64\images\toolbar\Search.gif
c:\windows\SysWow64\images\toolbar\search_over.gif
c:\windows\SysWow64\images\toolbar\searchd.gif
c:\windows\SysWow64\images\toolbar\up.gif
c:\windows\SysWow64\images\toolbar\up_over.gif
c:\windows\SysWow64\images\toolbar\upd.gif
c:\windows\SysWow64\images\tree\begindots.gif
c:\windows\SysWow64\images\tree\beginminus.gif
c:\windows\SysWow64\images\tree\beginplus.gif
c:\windows\SysWow64\images\tree\blank.gif
c:\windows\SysWow64\images\tree\blankdots.gif
c:\windows\SysWow64\images\tree\dots.gif
c:\windows\SysWow64\images\tree\lastdots.gif
c:\windows\SysWow64\images\tree\lastminus.gif
c:\windows\SysWow64\images\tree\lastplus.gif
c:\windows\SysWow64\images\tree\Magnify.gif
c:\windows\SysWow64\images\tree\minus.gif
c:\windows\SysWow64\images\tree\minusbox.gif
c:\windows\SysWow64\images\tree\plus.gif
c:\windows\SysWow64\images\tree\plusbox.gif
c:\windows\SysWow64\images\tree\singleminus.gif
c:\windows\SysWow64\images\tree\singleplus.gif
c:\windows\SysWow64\networkdlllsp.dll
e:\favoritevideo\InvisibleFolder
.
.
((((((((((((((((((((((((((((((((((((((( 驅動/服務 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_TESSAFE
-------\Service_TesSafe
.
.
((((((((((((((((((((((((( 2014-10-03 至 2014-11-03 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2014-11-03 03:33 . 2014-11-03 03:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-11-03 01:30 . 2014-11-03 02:17 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-11-03 00:57 . 2014-11-03 00:57 34808 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-11-03 00:57 . 2014-11-03 00:57 -------- d-----w- c:\programdata\RogueKiller
2014-11-02 09:25 . 2014-11-02 09:26 -------- d-----w- c:\program files (x86)\WinPcap
2014-11-02 09:24 . 2014-11-02 12:05 -------- d-----w- c:\users\Dean\AppData\Roaming\Wireshark
2014-11-02 09:19 . 2014-11-02 09:26 -------- d-----w- c:\program files\Wireshark
2014-11-01 13:18 . 2014-11-01 13:18 -------- d-----w- c:\windows\system32\vbox
2014-11-01 13:18 . 2014-11-01 13:18 -------- d-----w- c:\windows\SysWow64\vbox
2014-11-01 13:17 . 2014-11-01 13:17 -------- d-----w- c:\users\Dean\AppData\Roaming\AVAST Software
2014-11-01 13:16 . 2014-11-01 13:16 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-11-01 13:16 . 2014-11-01 13:16 116728 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-11-01 13:16 . 2014-11-01 13:16 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-11-01 13:16 . 2014-11-01 13:16 436624 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-11-01 13:16 . 2014-11-01 13:16 83280 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
2014-11-01 13:16 . 2014-11-01 13:16 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-11-01 13:16 . 2014-11-01 13:16 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-11-01 13:16 . 2014-11-01 13:16 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-11-01 13:16 . 2014-11-01 13:16 364512 ----a-w- c:\windows\system32\aswBoot.exe
2014-11-01 13:16 . 2014-11-01 13:16 43152 ----a-w- c:\windows\avastSS.scr
2014-11-01 13:15 . 2014-11-01 13:15 -------- d-----w- c:\program files\AVAST Software
2014-11-01 13:13 . 2014-11-01 13:15 -------- d-----w- c:\programdata\AVAST Software
2014-11-01 12:08 . 2014-11-03 04:49 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-11-01 12:08 . 2014-11-03 01:30 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-11-01 12:08 . 2014-11-01 12:08 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-11-01 12:08 . 2014-11-01 12:08 -------- d-----w- c:\programdata\Malwarebytes
2014-11-01 12:08 . 2014-10-01 03:11 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-01 12:08 . 2014-10-01 03:11 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-10-29 20:42 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4B886DBD-E901-42AC-AC4C-EDEB1497EC15}\mpengine.dll
2014-10-29 04:35 . 2014-10-29 04:35 -------- d-----w- c:\programdata\KuaiKuai
2014-10-24 07:09 . 2014-10-26 05:32 -------- d-----w- c:\users\Dean\AppData\Local\My Games
2014-10-22 13:52 . 2014-10-22 13:52 -------- d-----w- c:\windows\Migration
2014-10-21 05:34 . 2014-10-21 05:50 -------- d-----w- c:\program files (x86)\ASIO4ALL v2
2014-10-21 04:14 . 2012-07-26 05:18 2560 ----a-w- c:\windows\system32\drivers\zh-TW\wdf01000.sys.mui
2014-10-21 04:14 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-10-21 04:14 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-10-21 04:14 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-10-21 04:12 . 2014-10-21 04:12 -------- d-----w- c:\program files\MUSILAND
2014-10-21 04:12 . 2014-10-21 04:12 -------- d-----w- c:\program files (x86)\MUSILAND
2014-10-20 00:34 . 2014-10-20 01:44 -------- d-----w- c:\users\Dean\AppData\Roaming\AIMP3
2014-10-20 00:33 . 2014-10-20 00:48 -------- d-----w- c:\program files (x86)\AIMP3
2014-10-18 12:08 . 2014-10-18 12:08 -------- d-----w- c:\programdata\ATI
2014-10-18 12:06 . 2014-10-18 12:06 -------- d-----w- c:\program files (x86)\AMD AVT
2014-10-16 23:41 . 2014-11-01 00:45 220784 ----a-w- c:\program files (x86)\Mozilla Firefox\sandboxbroker.dll
2014-10-05 18:24 . 2014-10-05 18:25 -------- d-----w- c:\program files (x86)\ProjectLibre
2014-10-04 19:08 . 2014-10-04 19:08 78432 ----a-w- c:\windows\system32\atimpc64.dll
2014-10-04 19:08 . 2014-10-04 19:08 78432 ----a-w- c:\windows\system32\amdpcom64.dll
2014-10-04 19:08 . 2014-10-04 19:08 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
2014-10-04 19:08 . 2014-10-04 19:08 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2014-10-04 19:08 . 2014-10-04 19:08 126848 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2014-10-04 19:07 . 2014-10-04 19:07 9254184 ----a-w- c:\windows\SysWow64\atidxx32.dll
2014-10-04 19:05 . 2014-10-04 19:05 293064 ----a-w- c:\windows\system32\drivers\amdacpksd.sys
2014-10-04 19:04 . 2014-10-04 19:04 16750080 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2014-10-04 18:50 . 2014-10-04 18:50 235008 ----a-w- c:\windows\system32\clinfo.exe
2014-10-04 18:50 . 2014-10-04 18:50 98816 ----a-w- c:\windows\system32\OpenVideo64.dll
2014-10-04 18:50 . 2014-10-04 18:50 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2014-10-04 18:50 . 2014-10-04 18:50 86528 ----a-w- c:\windows\system32\OVDecode64.dll
2014-10-04 18:50 . 2014-10-04 18:50 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll
2014-10-04 18:50 . 2014-10-04 18:50 33867264 ----a-w- c:\windows\system32\amdocl64.dll
2014-10-04 18:49 . 2014-10-04 18:49 27918336 ----a-w- c:\windows\system32\atio6axx.dll
2014-10-04 18:49 . 2014-10-04 18:49 28770304 ----a-w- c:\windows\SysWow64\amdocl.dll
2014-10-04 18:48 . 2014-10-04 18:48 65024 ----a-w- c:\windows\system32\OpenCL.dll
2014-10-04 18:48 . 2014-10-04 18:48 58880 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-10-04 18:44 . 2014-10-04 18:44 23375360 ----a-w- c:\windows\SysWow64\atioglxx.dll
2014-10-04 18:43 . 2014-10-04 18:43 127488 ----a-w- c:\windows\system32\mantle64.dll
2014-10-04 18:42 . 2014-10-04 18:42 113664 ----a-w- c:\windows\SysWow64\mantle32.dll
2014-10-04 18:42 . 2014-10-04 18:42 5639168 ----a-w- c:\windows\system32\amdmantle64.dll
2014-10-04 18:42 . 2014-10-04 18:42 48128 ----a-w- c:\windows\system32\amdmmcl6.dll
2014-10-04 18:42 . 2014-10-04 18:42 37888 ----a-w- c:\windows\SysWow64\amdmmcl.dll
2014-10-04 18:40 . 2014-10-04 18:40 367104 ----a-w- c:\windows\system32\atiapfxx.exe
2014-10-04 18:40 . 2014-10-04 18:40 62464 ----a-w- c:\windows\system32\aticalrt64.dll
2014-10-04 18:40 . 2014-10-04 18:40 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll
2014-10-04 18:40 . 2014-10-04 18:40 55808 ----a-w- c:\windows\system32\aticalcl64.dll
2014-10-04 18:40 . 2014-10-04 18:40 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll
2014-10-04 18:39 . 2014-10-04 18:39 15716352 ----a-w- c:\windows\system32\aticaldd64.dll
2014-10-04 18:39 . 2014-10-04 18:39 4480000 ----a-w- c:\windows\SysWow64\amdmantle32.dll
2014-10-04 18:39 . 2014-10-04 18:39 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll
2014-10-04 18:37 . 2014-10-04 18:37 91648 ----a-w- c:\windows\system32\mantleaxl64.dll
2014-10-04 18:37 . 2014-10-04 18:37 85504 ----a-w- c:\windows\SysWow64\mantleaxl32.dll
2014-10-04 18:35 . 2014-10-04 18:35 442368 ----a-w- c:\windows\system32\atidemgy.dll
2014-10-04 18:35 . 2014-10-04 18:35 31232 ----a-w- c:\windows\system32\atimuixx.dll
2014-10-04 18:35 . 2014-10-04 18:35 619008 ----a-w- c:\windows\system32\atieclxx.exe
2014-10-04 18:35 . 2014-10-04 18:35 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2014-10-04 18:35 . 2014-10-04 18:35 190976 ----a-w- c:\windows\system32\atitmm64.dll
2014-10-04 18:31 . 2014-10-04 18:31 1210880 ----a-w- c:\windows\system32\atiadlxx.dll
2014-10-04 18:31 . 2014-10-04 18:31 900608 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2014-10-04 18:31 . 2014-10-04 18:31 75264 ----a-w- c:\windows\system32\atig6pxx.dll
2014-10-04 18:31 . 2014-10-04 18:31 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2014-10-04 18:31 . 2014-10-04 18:31 69632 ----a-w- c:\windows\system32\atiglpxx.dll
2014-10-04 18:31 . 2014-10-04 18:31 146944 ----a-w- c:\windows\system32\atig6txx.dll
2014-10-04 18:31 . 2014-10-04 18:31 133632 ----a-w- c:\windows\SysWow64\atigktxx.dll
2014-10-04 18:31 . 2014-10-04 18:31 576000 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2014-10-04 18:31 . 2014-10-04 18:31 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2014-10-04 06:54 . 2014-10-04 06:54 51200 ----a-w- c:\windows\system32\kdbsdk64.dll
2014-10-04 06:52 . 2014-10-04 06:52 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-01 00:54 . 2013-09-20 18:59 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-01 00:54 . 2013-09-20 18:59 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-10-04 19:08 . 2014-06-21 05:26 144328 ----a-w- c:\windows\system32\atiuxp64.dll
2014-10-04 19:08 . 2014-04-18 02:42 118096 ----a-w- c:\windows\system32\atiu9p64.dll
2014-10-04 19:08 . 2014-09-15 22:31 100032 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2014-10-04 19:08 . 2011-07-28 09:39 1335544 ----a-w- c:\windows\system32\aticfx64.dll
2014-10-04 19:07 . 2014-09-15 22:31 1113576 ----a-w- c:\windows\SysWow64\aticfx32.dll
2014-10-04 19:07 . 2014-06-21 05:25 10826488 ----a-w- c:\windows\system32\atidxx64.dll
2014-10-04 19:07 . 2014-09-15 22:31 7207592 ----a-w- c:\windows\SysWow64\atiumdva.dll
2014-10-04 19:07 . 2014-09-15 22:31 7028336 ----a-w- c:\windows\SysWow64\atiumdag.dll
2014-10-04 19:07 . 2014-04-18 02:42 8044976 ----a-w- c:\windows\system32\atiumd6a.dll
2014-10-04 19:07 . 2014-04-18 02:42 8296296 ----a-w- c:\windows\system32\atiumd64.dll
2014-10-04 18:33 . 2014-09-15 21:59 827392 ----a-w- c:\windows\system32\coinst_14.30.dll
2014-10-02 07:53 . 2011-11-16 13:56 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-09-18 09:26 . 2014-06-01 14:13 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-09-18 09:26 . 2011-11-19 12:17 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-09-18 09:24 . 2011-11-16 18:19 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-09-03 14:48 . 2013-05-30 02:02 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-29 14:46 . 2014-08-27 11:43 52 ----a-w- c:\users\Dean\AppData\Local\Temp.vbs
.
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4BF2CB0E-658A-442B-AC83-A64EC2150BFC}]
2013-01-06 10:20 442248 ----a-w- c:\programdata\PPBrowserHelper\BHO\TipsBHO.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D297}]
2013-09-16 03:23 327808 ----a-w- c:\program files (x86)\QvodPlayer\QvodExtend\5.0.95.0\QvodExtend.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 12:38 1720976 ----a-w- c:\progra~2\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 12:38 1720976 ----a-w- c:\progra~2\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 12:38 1720976 ----a-w- c:\progra~2\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AAADesktopTips]
@="{4562B511-62E9-4533-B7B2-56A8BB10B482}"
[HKEY_CLASSES_ROOT\CLSID\{4562B511-62E9-4533-B7B2-56A8BB10B482}]
2013-06-05 14:55 373704 ----a-w- c:\users\Public\Thunder Network\KanKan\reghelper\xappex.1.1.1.70.(84).dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DownloadIcon]
@="{A8502600-B272-4F68-A67B-A0305D46D297}"
[HKEY_CLASSES_ROOT\CLSID\{A8502600-B272-4F68-A67B-A0305D46D297}]
2013-09-16 03:23 327808 ----a-w- c:\program files (x86)\QvodPlayer\QvodExtend\5.0.95.0\QvodExtend.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"HP Deskjet 3070 B611 series (NET)"="c:\program files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe" [2011-06-08 2676584]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Rapoo 8300"="c:\program files (x86)\Rapoo\8300\8300_Mouse.exe" [2010-12-14 2571776]
"Rapoo LedStatus"="c:\program files (x86)\Rapoo\8300\LedStatus\LedStatus.exe" [2010-10-14 1701888]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-10-04 767176]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-11-01 5223016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"PPS Accelerator"="c:\pps.tv\PPStream\PPSKernel.exe" [2013-01-23 3682168]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AOD"="c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" [2014-10-04 344064]
.
c:\users\Dean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
AutoHotkey.lnk - c:\program files\AutoHotkey\AutoHotkey.exe [2013-5-6 1306112]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-6-23 38072]
TaskbarController.lnk - c:\program files (x86)\RocketDock\TrayController\TaskbarController.exe [2013-6-24 679303]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 AODDriver4.3;AODDriver4.3;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 MlCyMonFW;Firmware Driver for MUSILAND Monitor Series(USB);c:\windows\system32\Drivers\MlCyMonFW.sys;c:\windows\SYSNATIVE\Drivers\MlCyMonFW.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 MySQL56;MySQL56;C:/Program Files/MySQL/MySQL Server 5.6/bin\mysqld --defaults-file=c:\programdata\MySQL\MySQL Server 5.6\my.ini MySQL56;C:/Program Files/MySQL/MySQL Server 5.6/bin\mysqld --defaults-file=c:\programdata\MySQL\MySQL Server 5.6\my.ini MySQL56 [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys;c:\windows\SYSNATIVE\drivers\SndTAudio.sys [x]
R3 SRS_AE_Service;SRS Audio Essentials;c:\windows\system32\drivers\SRS_AE_amd64.sys;c:\windows\SYSNATIVE\drivers\SRS_AE_amd64.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv90;Performance Tools Driver 9.0;e:\microsoft visual studio 9.0\Team Tools\Performance Tools\x64\VSPerfDrv90.sys;e:\microsoft visual studio 9.0\Team Tools\Performance Tools\x64\VSPerfDrv90.sys [x]
R3 WsAudio_Device(1);WsAudio_Device(1);c:\windows\system32\drivers\VirtualAudio1.sys;c:\windows\SYSNATIVE\drivers\VirtualAudio1.sys [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
R4 AlipaySecSvc;Alipay security service;c:\program files (x86)\alipay\alieditplus\AlipaySecSvc.exe;c:\program files (x86)\alipay\alieditplus\AlipaySecSvc.exe [x]
R4 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
R4 PingzapperSvc;Pingzapper Service;c:\program files (x86)\Pingzapper\PZService.exe;c:\program files (x86)\Pingzapper\PZService.exe [x]
R4 SplashtopRemoteService;SplashtopR Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [x]
R4 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 MlCyMonSvc;MUSILAND Monitor Series(USB) CPL Daemon;c:\windows\SysWOW64\MlCyMonSvc.exe;c:\windows\SysWOW64\MlCyMonSvc.exe [x]
S2 PPTVService;PPTVService;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 RzKLService;RzKLService;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe [x]
S2 SADP_NPF;Sadp Driver (SADP_NPF);c:\windows\SysWOW64\drivers\sadp_npf64.sys;c:\windows\SysWOW64\drivers\sadp_npf64.sys [x]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
S2 XLServicePlatform;XLServicePlatform;c:\windows\system32\svchost;c:\windows\SYSNATIVE\svchost [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S3 IPvE;IPvE Adapter Driver;c:\windows\system32\DRIVERS\IPvEx64.sys;c:\windows\SYSNATIVE\DRIVERS\IPvEx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 MlCyMon;Device Driver for MUSILAND Monitor Series(USB);c:\windows\system32\Drivers\MlCyMon.sys;c:\windows\SYSNATIVE\Drivers\MlCyMon.sys [x]
S3 MlCyMonBus;Bus Driver for MUSILAND Monitor Series(USB);c:\windows\system32\Drivers\MlCyMonBus.sys;c:\windows\SYSNATIVE\Drivers\MlCyMonBus.sys [x]
S3 rp24msdrv;2.4g Device;c:\windows\system32\drivers\rp24msdrv.sys;c:\windows\SYSNATIVE\drivers\rp24msdrv.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
XLServicePlatform REG_MULTI_SZ XLServicePlatform
PPTVServiceGroup REG_MULTI_SZ PPTVService
FunshionServiceTools REG_MULTI_SZ FunshionSvr
.
‘計劃任務’ 文件夾 裡的內容
.
2014-11-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2371761838-3269241468-585396966-1000Core.job
- c:\users\Dean\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-11 11:50]
.
2014-11-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2371761838-3269241468-585396966-1000UA.job
- c:\users\Dean\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-11 11:50]
.
2014-10-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2371761838-3269241468-585396966-1000Core.job
- c:\users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-16 21:11]
.
2014-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2371761838-3269241468-585396966-1000UA.job
- c:\users\Dean\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-16 21:11]
.
2014-11-03 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E}]
2013-06-08 12:57 628680 ----a-w- c:\program files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.4.4462.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D298}]
2013-09-16 03:23 482944 ----a-w- c:\program files (x86)\QvodPlayer\QvodExtend\5.0.95.0\QvodExtend_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 12:37 2322576 ----a-w- c:\progra~1\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 12:37 2322576 ----a-w- c:\progra~1\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 12:37 2322576 ----a-w- c:\progra~1\MIF5BA~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-11-01 13:16 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DownloadIcon]
@="{A8502600-B272-4F68-A67B-A0305D46D298}"
[HKEY_CLASSES_ROOT\CLSID\{A8502600-B272-4F68-A67B-A0305D46D298}]
2013-09-16 03:23 482944 ----a-w- c:\program files (x86)\QvodPlayer\QvodExtend\5.0.95.0\QvodExtend_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Dean\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568]
.
------- 而外的掃描 -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Bar =
https://hk.yahoo.com/?fr=hp-avast&type=avastbcl
uInternet Settings,ProxyOverride = *.local
IE: &妏蚚&捃濘燭盄狟婥 - c:\program files (x86)\Thunder Network\Thunder\BHO\OfflineDownload.htm
IE: &妏蚚&捃濘狟婥 - c:\program files (x86)\Thunder Network\Thunder\BHO\geturl.htm
IE: &妏蚚&捃濘狟婥窒蟈諉 - c:\program files (x86)\Thunder Network\Thunder\BHO\GetAllUrl.htm
IE: Download all by FlashGet3 - c:\users\Dean\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - c:\users\Dean\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: Foxy 下載 - c:\program files (x86)\Foxy\Foxy.exe/download.htm
IE: Foxy 搜尋 - c:\program files (x86)\Foxy\Foxy.exe/search.htm
IE: 使用快播按?找片 - c:\program files (x86)\QvodPlayer\AddIn\ImgSeed.htm
IE: 使用迅雷下? - e:\tddownload\高速通道破解版迅雷\BHO\geturl.htm
IE: 使用迅雷下?全部?接 - e:\tddownload\高速通道破解版迅雷\BHO\GetAllUrl.htm
IE: 使用迅雷看看播放器播放 - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
IE: 傳送至 OneNote(&N) - c:\progra~1\MIF5BA~1\Office15\ONBttnIE.dll/105
IE: 匯出至 Microsoft Excel(&X) - c:\progra~1\MIF5BA~1\Office15\EXCEL.EXE/3000
IE: 添加?前?到迅雷看看播放器?? - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenuAddStoreTab.htm
IE: { - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
IE: {{08155d3c-68e2-4215-a47a-e800a446447a} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
IE: {{09155d3c-68e2-4215-a47a-e800a446447a} - c:\users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm
IE: {{0A155D3C-68E2-4215-A47A-E800A446447A}
IE: {{5D578929-E74E-46A2-A810-4F33D011DC52} - c:\program files (x86)\Common Files\Thunder Network\Kankan\XLStartKankan.exe
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1DD68048-DCEF-4BEB-8E10-B30147D3F4EE}: NameServer = 8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\vb4o6mpk.default\
FF - user.js: extensions.claro.tlbrSrchUrl -
FF - user.js: extensions.claro.id - c8ded3ec00000000000000ff88c88eb2
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15711
FF - user.js: extensions.claro.vrsn - 1.8.8.5
FF - user.js: extensions.claro.vrsni - 1.8.8.5
FF - user.js: extensions.claro_i.vrsnTs - 1.8.8.518:19
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - base
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro_i.excTlbr - false
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
FF - user.js: extensions.claro.autoRvrt - false
FF - user.js: extensions.claro.rvrt - false
FF - user.js: extensions.claro_i.newTab - false
FF - user.js: network.protocol-handler.external.foxy - true
FF - user.js: network.protocol-handler.warn-external.foxy - false
FF - user.js: network.protocol-handler.expose.foxy - true
FF - user.js: general.useragent.extra.foxy1 - Foxy/1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{FE69C007-C452-4d3e-86D2-1730DF8BC871} - (no file)
BHO-{1D0ED993-9A54-E354-AB89-0C6766D2C082} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-AlipaySecControl - c:\windows\system32\aliedit\3.6.0.0\uninst.exe
AddRemove-Defense Grid 2_is1 - e:\games @ e\Defense Grid 2\unins000.exe
AddRemove-Glyph - e:\games @ e\Glyph\glyphuninstall.exe
AddRemove-Glyph Archeage - e:\games @ e\Glyph\GlyphClient.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-Rise of Nations: Extended Edition_is1 - e:\games @ e\Rise of Nations\unins000.exe
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-WildStar - e:\games @ e\WildStar\Wildstar.exe
AddRemove-ApplicationUpdater - c:\users\Dean\AppData\Local\Sony Online Entertainment\ApplicationUpdater\Uninstaller.exe
AddRemove-PlanetSide 2 - d:\games @ d\PlanetSide 2\Uninstaller.exe
AddRemove-soe-PlanetSide 2 - d:\games @ d\PlanetSide 2\Uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL56]
"ImagePath"="\"C:/Program Files/MySQL/MySQL Server 5.6/bin\mysqld\" --defaults-file=\"c:\programdata\MySQL\MySQL Server 5.6\my.ini\" MySQL56"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL56]
"ImagePath"="\"C:/Program Files/MySQL/MySQL Server 5.6/bin\mysqld\" --defaults-file=\"c:\programdata\MySQL\MySQL Server 5.6\my.ini\" MySQL56"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2371761838-3269241468-585396966-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏甒競腤eZ]
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\OfflineDownload.htm"
"Name"="xl_offlinedownload"
"Contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2371761838-3269241468-585396966-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏腤eZ]
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\geturl.htm"
"Name"="xl_geturl"
"Contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2371761838-3269241468-585396966-1000\Software\Microsoft\Internet Explorer\MenuExt\&*?&*Cc喏腤eZ蘙??]
@="c:\\Program Files (x86)\\Thunder Network\\Thunder\\BHO\\GetAllUrl.htm"
"Name"="xl_getallurl"
"Contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-2371761838-3269241468-585396966-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"?慴"=hex:b3,a4,ac,47,d7,fb,95,15,04,e3,e8,03,81,c7,37,aa,f0,f3,ff,f5,5d,8f,df,
35,31,ce,e1,f4,e4,3d,3c,8e,30,c0,32,d6,7c,a0,35,ea,02,85,85,fa,71,d7,e6,fe,\
"歲祥"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-2371761838-3269241468-585396966-1000\Software\SecuROM\License information*]
"datasecu"=hex:54,e1,de,d7,78,d7,1c,5d,f2,80,52,2a,78,da,21,c5,ba,ef,8e,14,c1,
48,52,97,af,76,c3,46,c2,80,7b,b9,d5,f4,1c,1b,a7,6b,75,f0,62,94,94,cf,90,ab,\
"rkeysecu"=hex:89,a7,7f,d1,f9,17,2e,02,ed,eb,e0,a2,24,36,69,0a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*3*\DsDriver]
"printBinNames"=multi:"\00\00"
"printCollate"=hex:00
"printColor"=hex:01
"printDuplexSupported"=hex:00
"printStaplingSupported"=hex:00
"printMaxXExtent"=dword:00000b9a
"printMaxYExtent"=dword:000010de
"printMinXExtent"=dword:000003d8
"printMinYExtent"=dword:00000771
"printMediaSupported"=multi:"Letter\00Tabloid\00Legal\00Executive\00A3\00A4\00B4 (JIS)\00B5 (JIS)\00Envelope #10\00Envelope Monarch\00\00"
"printMediaReady"=multi:"A4\00\00"
"printNumberUp"=dword:00000000
"printMemory"=dword:00008000
"printOrientationsSupported"=multi:"PORTRAIT\00LANDSCAPE\00\00"
"printMaxResolutionSupported"=dword:000004b0
"printLanguage"=multi:"\00\00"
"printRateUnit"=""
"driverVersion"=dword:00000401
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*3*\DsSpooler]
"driverName"="Send to Microsoft OneNote 15 Driver"
"portName"=multi:"nul:\00\00"
"printStartTime"=dword:00000000
"printEndTime"=dword:00000000
"printerName"="傳送至 OneNote 2013"
"printKeepPrintedJobs"=hex:00
"printSpooling"="PrintAfterSpooled"
"priority"=dword:00000001
"uNCName"="\\\\Dean-PC\\傳送至 OneNote 2013"
"serverName"="Dean-PC"
"shortServerName"="DEAN-PC"
"versionNumber"=dword:00000004
"flags"=dword:00000000
"description"=""
"location"=""
"printSeparatorFile"=""
"printShareName"=""
"url"="
http://Dean-PC/"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*3*\PrinterDriverData]
"InitDriverVersion"=dword:00000600
"Model"="Send To OneNote Driver"
"FreeMem"=hex:00,80,00,00
"PrinterDataSize"=dword:00000230
"PrinterData"=hex:00,06,30,02,81,08,00,00,00,f8,ba,01,00,00,00,00,00,00,00,00,
64,00,58,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ac,13,d8,c0,01,\
"FeatureKeywordSize"=dword:00000012
"FeatureKeyword"=hex:4d,65,6d,6f,72,79,00,33,32,37,36,38,4b,42,00,0a,00,00
"Forms?"=dword:c0d813ac
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\E* *:\鱍]
"FormKeyword"=hex:45,5f,53,49,5a,45,3a,48,50,00
"ResourceNameID"="@hpzstw71.dll,3398"
.
------------------------ 其他運行進程 ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files (x86)\MUSILAND\Monitor Series(USB)\MlCyMonApp.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
完成時間: 2014-11-03 12:58:26 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2014-11-03 04:58
.
Pre-Run: 27,861,934,080 位元組可用
Post-Run: 27,722,301,440 位元組可用
.
- - End Of File - - 850EE54C5593C471CB090B7369A760B8
A36C5E4F47E84449FF07ED3517B43A31