Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

dwm.exe(Trojan.BitcoinMiner) detected by Malwarebytes


  • This topic is locked This topic is locked
8 replies to this topic

#1 painpotato

painpotato

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:08 PM

Posted 03 October 2013 - 09:16 PM

hi

my computer has been infected by a malware called Trojan.BitcoinMiner.

a faked dwm.exe procedure is automatically created every time my pc is idle for about 1 minute.

and then self killed right after a key is pressed or mouse moved.

Malwarebytes cant seems to detected it permanently

 

so here i am.

i have followed the instruction and post this request.

below is my attach.txt:

 

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 企業版 
Boot Device: \Device\HarddiskVolume1
Install Date: 2012/7/12 下午 04:57:44
System Uptime: 2013/10/4 上午 08:25:55 (2 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. |  | EP45-UD3R
Processor: Intel® Core™2 Quad CPU    Q8200  @ 2.33GHz | Socket 775 | 2333/333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 270 GiB total, 122.887 GiB free.
D: is FIXED (NTFS) - 300 GiB total, 85.958 GiB free.
E: is FIXED (NTFS) - 932 GiB total, 176.721 GiB free.
F: is FIXED (NTFS) - 1397 GiB total, 825.313 GiB free.
S: is NetworkDisk (NTFS) - 932 GiB total, 90.435 GiB free.
W: is NetworkDisk (NTFS) - 400 GiB total, 256.091 GiB free.
X: is NetworkDisk (NTFS) - 400 GiB total, 292.108 GiB free.
Y: is FIXED (NTFS) - 26 GiB total, 15.323 GiB free.
Z: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Description: Wacom Virtual Hid Driver
Device ID: ROOT\HIDCLASS\0000
Manufacturer: Wacom
Name: Wacom Virtual Hid Driver
PNP Device ID: ROOT\HIDCLASS\0000
Service: wacomvhid
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: gogo6 Virtual Multi-Tunnel Adapter
Device ID: ROOT\NET\0000
Manufacturer: gogo6
Name: gogo6 Virtual Multi-Tunnel Adapter
PNP Device ID: ROOT\NET\0000
Service: gogoTunnelDevice
.
==== System Restore Points ===================
.
RP174: 2013/9/13 下午 02:17:44 - Installed PACE License Support Win64
RP175: 2013/9/13 下午 05:06:43 - Windows Update
RP176: 2013/9/16 下午 02:03:43 - Installed iTunes
RP177: 2013/9/16 下午 04:50:55 - Installed Jellycam
RP178: 2013/9/16 下午 04:55:04 - Removed Jellycam
RP179: 2013/9/17 上午 08:52:43 - 已安裝 Cerio UW-200NH 11n USB Wireless LAN Driver and Utility
RP180: 2013/10/1 下午 02:12:54 - Installed HiJackThis
RP181: 2013/10/3 下午 04:35:16 - 已安裝 Cerio UW Series 11n USB Wireless LAN Software
RP182: 2013/10/4 上午 09:00:22 - Installed SpyHunter
RP183: 2013/10/4 上午 09:36:46 - Removed SpyHunter
.
==== Installed Programs ======================
.
??QQ2013
2007 Microsoft Office 程式的 Microsoft 另存 PDF 或 XPS 檔增益集
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.8) MUI
AmpliTube 3 version 3.11.1
Apple Mobile Device Support
Apple Software Update
Apple 應用程式支援
Artillery2 CM Edition
Astralis CM v1.0 1.0
Avidemux 2.5
Avidemux 2.6 (32-bit)
Bonjour
CamStudio version 2.7
Cerio Wireless LAN Driver and Utility
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Custom Shop version 1.3.0
D3DX10
E-License Manager
EBPdfViewer6.0
eLicenser Control
Engine 2
Firebird v2.0
GeForce Experience NvStream Client Components
Gigabyte Raid Cinfigurer
gogo6 gogoCLIENT
Google Chrome
Google Chrome Canary
HiJackThis
IK Multimedia Authorization Manager version 1.0.9
IL Autogun
IL Download Manager
IL Shared Libraries
iTunes
IVGI version 1.0.0
iZotope Vinyl
K-Lite Mega Codec Pack 9.1.0
Kaspersky Anti-Virus 6.0 for Windows Workstations
Kaspersky Lab Network Agent
Kong Audio Chinee Orchestra Library
Kong Audio Qin Rack Version
M-Audio MIDISPORT Driver 6.1.2 (x64)
MAGIX Independence Libraries Common Files
MAGIX Independence Pro 3.1 VST-Plugins
MAGIX Independence Pro Software Suite 3.1
Malwarebytes Anti-Malware 版本 1.75.0.1300
Messenger 分享元件
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Chinese (Traditional)) 2007
Microsoft Office Excel 2007 Help 更新程式 (KB963678)
Microsoft Office Excel MUI (Chinese (Traditional)) 2007
Microsoft Office File Validation Add-In
Microsoft Office IME (Chinese (Traditional)) 2007
Microsoft Office InfoPath MUI (Chinese (Traditional)) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office Outlook MUI (Chinese (Traditional)) 2007
Microsoft Office Powerpoint 2007 Help 更新程式 (KB963669)
Microsoft Office PowerPoint MUI (Chinese (Traditional)) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (Chinese (Traditional)) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proofing (Chinese (Traditional)) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Chinese (Traditional)) 2007
Microsoft Office Shared 64-bit MUI (Chinese (Traditional)) 2007
Microsoft Office Shared MUI (Chinese (Traditional)) 2007
Microsoft Office Word 2007 Help 更新程式 (KB963665)
Microsoft Office Word MUI (Chinese (Traditional)) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mp3tag v2.57
MPC-BE x64 1.1.3.0
MSVCRT
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
Native Instruments Abbey Road 60s Drums
Native Instruments Abbey Road 70s Drums
Native Instruments Abbey Road 80s Drums
Native Instruments Abbey Road Modern Drums
Native Instruments Absynth 5
Native Instruments Alicias Keys
Native Instruments Balinese Gamelan
Native Instruments Battery 3
Native Instruments Battery Library Importer for Maschine
Native Instruments Berlin Concert Grand
Native Instruments Controller Editor
Native Instruments Driver
Native Instruments DrumMicA
Native Instruments Evolve Mutations
Native Instruments Evolve Mutations 2
Native Instruments FM8
Native Instruments George Duke Soul Treasures
Native Instruments Guitar Rig 5
Native Instruments Guitar Rig Pro Library for Maschine
Native Instruments Komplete 8 Ultimate
Native Instruments Kontakt 5
Native Instruments Kontakt Factory Library
Native Instruments Maschine Drum Selection
Native Instruments Massive
Native Instruments New York Concert Grand
Native Instruments Rammfire
Native Instruments Rammfire for Maschine
Native Instruments Razor
Native Instruments Reaktor 5
Native Instruments Reaktor Prism
Native Instruments Reaktor Spark R2
Native Instruments Reflektor
Native Instruments Reflektor for Maschine
Native Instruments Retro Machines Mk2
Native Instruments Scarbee Funk Guitarist
Native Instruments Scarbee Jay-Bass
Native Instruments Scarbee MM-Bass
Native Instruments Scarbee MM-Bass Amped
Native Instruments Scarbee Pre-Bass
Native Instruments Scarbee Pre-Bass Amped
Native Instruments Scarbee Vintage Keys
Native Instruments Service Center
Native Instruments Session Strings Pro
Native Instruments Solid Bus Comp
Native Instruments Solid Bus Comp for Maschine
Native Instruments Solid Dynamics
Native Instruments Solid Dynamics for Maschine
Native Instruments Solid EQ
Native Instruments Solid EQ for Maschine
Native Instruments Studio Drummer
Native Instruments The Finger R2
Native Instruments The Mouth
Native Instruments Traktors 12
Native Instruments Traktors 12 for Maschine
Native Instruments Transient Master
Native Instruments Transient Master for Maschine
Native Instruments Upright Piano
Native Instruments VC 160
Native Instruments VC 160 for Maschine
Native Instruments VC 2A
Native Instruments VC 2A for Maschine
Native Instruments VC 76
Native Instruments VC 76 for Maschine
Native Instruments Vienna Concert Grand
Native Instruments Vintage Organs
Native Instruments West Africa
NVIDIA 3D Vision 控制器驅動程式 326.01
NVIDIA 3D Vision 驅動程式 327.23
NVIDIA GeForce Experience 1.6.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX 系統軟體 9.13.0725
NVIDIA Stereoscopic 3D Driver
NVIDIA Update Components
NVIDIA Virtual Audio 1.2.5
NVIDIA 更新程式 8.3.14
NVIDIA 控制面板 327.23
NVIDIA 圖形驅動程式 327.23
PACE License Support Win64
Paint.NET v3.5.10
Play Update 4.0.12
PunkBuster Services
QuickTime
Realtek Ethernet Controller Driver For Windows Vista and Later
rgc:audio Triangle II
rgc:audio z3ta+ 1.5 (x64)
RME DIGICheck
RME Hammerfall DSP (WDM)
SampleTank FREE
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760588) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760823) 32-Bit Edition 
Security Update for Microsoft Office Excel 2007 (KB2760583) 32-Bit Edition 
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition 
Security Update for Microsoft Office Outlook 2007 (KB2825999) 32-Bit Edition 
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition 
Security Update for Microsoft Office Word 2007 (KB2767773) 32-Bit Edition 
SetFileDate 1.1
SHIELD Streaming
Skype™ 6.6
Sonnox Restoration Tools for Wavelab VST v1.0.0 (32-bit)
Steinberg Cubase 5 64bit
Steinberg Cubase 7 64bit
Steinberg Drum Loop Expansion 01
Steinberg Eucon Adapter 6.5 64bit
Steinberg Groove Agent ONE Allen Morgan Signature Drums
Steinberg Groove Agent ONE Content
Steinberg Groove Agent ONE Vintage Beatboxes
Steinberg HALion Sonic SE 64bit
Steinberg HALion Sonic SE Content
Steinberg HALionOne 64bit
Steinberg HALionOne Additional Content Set 01
Steinberg HALionOne Expression Set
Steinberg HALionOne GM Drum Set
Steinberg HALionOne GM Set
Steinberg HALionOne Pro Set
Steinberg HALionOne Studio Drum Set
Steinberg HALionOne Studio Set
Steinberg LoopMash Content
Steinberg LoopMash Content 2
Steinberg Midi Loop Library
Steinberg Padshop 64bit
Steinberg Retrologue 64bit
Steinberg REVerence Content 01
Steinberg Upload Manager
Steinberg VST Amp Rack Content 01
TortoiseSVN 1.7.5.22551 (64 bit)
Unity
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825641) 32-Bit Edition
UVI Workstation x64 2.1.5
Wacom 數位板
WaveLab 7
WaveLab 7 (64 bit)
WebTablet FB Plugin
WebTablet IE Plugin
WebTablet Netscape Plugin
Winamp
Windows Live Communications Platform
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live 程式集
Windows Live 影像中心
WinRAR 4.20 (64 位元)
.
==== End Of File ===========================
 
 
and then dds.txt:
 
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 9.0.8112.16506
Run by rizet at 10:00:14 on 2013-10-04
Microsoft Windows 7 企業版   6.1.7601.1.950.886.1028.18.8190.4688 [GMT 8:00]
.
AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
FW: Kaspersky Anti-Virus *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Tablet\Wacom\Wacom_TouchService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Program Files (x86)\Kaspersky Lab\NetworkAgent 8\klnagent.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtlService.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\alg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtWlan.exe
C:\Program Files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RTLDHCP.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\hdsp32.exe
C:\Windows\System32\hdspmix.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
C:\Users\rizet\AppData\Local\Google\Update\1.3.21.153\GoogleCrashHandler.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Users\rizet\AppData\Local\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Tencent\QQ\QQProtect\Bin\QQProtect.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQ\bin\QQ.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQ\bin\TXPlatform.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQ\bin\QQExternal.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msiexec.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\rizet\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://h1app.softstar.com.tw/Softstar/
uProxyOverride = local;*.local
mWinlogon: Userinit = userinit.exe,
BHO: Windows Live ID 登入協助程式: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
uRun: [Google Update] "C:\Users\rizet\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun_KL_notset = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: disablecad = dword:1
IE: 匯出至 Microsoft Excel(&X) - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: 新增至廣告橫幅防護 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\ie_banner_deny.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {42BCE7C0-5E2B-11D7-8D51-0006291EDF61} - hxxps://stock2.ubot.com.tw/Web/ebroker/axebroker.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 172.18.99.101 172.18.99.102
TCP: Interfaces\{A8D0DC6F-5882-4777-BC86-0BCA1882B38D} : DHCPNameServer = 172.18.99.101 172.18.99.102
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= C:\PROGRA~2\KASPER~1\KASPER~1.0FO\adialhk.dll, C:\PROGRA~2\KASPER~1\KASPER~1.0FO\kloehk.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [HDSPTray1] hdsp32.exe
x64-Run: [HDSPTray2] hdspmix.exe
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6}
x64-DPF: {CB927D12-4FF7-4A9E-A169-56E4B8A75598} - hxxp://qtinstall.apple.com/qtactivex/qtplugin.cab
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2009-9-14 27736]
R2 AVP;Kaspersky Anti-Virus 6.0;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [2010-3-12 311680]
R2 JMB36X;JMB36X;C:\Windows\SysWOW64\XSrvSetup.exe [2012-7-12 65536]
R2 klnagent;Kaspersky Lab Network Agent;C:\Program Files (x86)\Kaspersky Lab\NetworkAgent 8\klnagent.exe [2010-3-10 136352]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-2 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-2 701512]
R2 MIDISPORTAudioDevMon;MIDISPORT Audio Device Monitor;C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe [2010-10-6 1636872]
R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2013-1-18 6383920]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-7-31 14997280]
R2 PaceLicenseDServices;PACE License Services;C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2013-8-15 17142176]
R2 Realtek11nSU;Realtek11nSU;C:\Program Files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtlService.exe [2013-10-3 36864]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-9-12 414496]
R2 TabletServiceWacom;TabletServiceWacom;C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe [2013-3-27 7515000]
R2 TouchServiceWacom;Wacom Professional Touch Service;C:\Program Files\Tablet\Wacom\Wacom_TouchService.exe [2013-7-19 552312]
R3 hdsp;RME Hammerfall Audio Device;C:\Windows\System32\drivers\hdsp_64.sys [2013-1-22 102400]
R3 iLokDrvr;Usb Driver;C:\Windows\System32\drivers\iLokDrvr.sys [2013-9-13 25808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\System32\drivers\klfltdev.sys [2009-9-3 30736]
R3 MAUSBMIDISPORT;Service for M-Audio MIDISPORT;C:\Windows\System32\drivers\MAudioMIDISPORT.sys [2010-10-6 199176]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-10-2 25928]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2013-9-30 39200]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-7-12 239616]
R3 RTL8192su;Cerio UW Series Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8192su.sys [2013-10-3 694376]
R3 SynUSB64;eLicenser;C:\Windows\System32\drivers\synusb64.sys [2012-7-13 30352]
R3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2013-3-27 13312]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-22 71168]
S3 gogoc;gogo6 gogoCLIENT;C:\Program Files\gogo6\gogoCLIENT\gogoc.exe [2010-3-13 527688]
S3 gogoTunnelDevice;gogo6  Multi-Virtual Tunnel Adapter;C:\Windows\System32\drivers\gogotun.sys [2010-3-13 27648]
S3 MADFUMIDISPORT2010;Service for M-Audio MIDISPORT DFU;C:\Windows\System32\drivers\MAudioMIDISPORT_DFU.sys [2010-10-6 28680]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-20 19456]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-22 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2012-11-20 29696]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-20 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-20 30208]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-22 117248]
S3 WatAdminSvc;Windows 啟用技術服務;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-7-13 1255736]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\notepad.exe %1
.
=============== Created Last 30 ================
.
2013-10-04 01:42:23 -------- d-----w- C:\FRST
2013-10-04 01:04:33 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1A2F984-122F-45BB-B0C7-4EC1B02D32EC}\offreg.dll
2013-10-04 01:01:03 -------- d-----w- C:\Program Files\Enigma Software Group
2013-10-04 01:00:16 -------- d-----w- C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-04 01:00:15 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-10-03 08:36:07 694376 ----a-w- C:\Windows\System32\drivers\RTL8192su.sys
2013-10-03 08:36:01 -------- d-----w- C:\Program Files (x86)\Cerio UW Series
2013-10-02 21:47:35 9694160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E1A2F984-122F-45BB-B0C7-4EC1B02D32EC}\mpengine.dll
2013-10-02 05:24:32 -------- d-----w- C:\Users\rizet\AppData\Roaming\Malwarebytes
2013-10-02 05:24:19 -------- d-----w- C:\ProgramData\Malwarebytes
2013-10-02 05:24:18 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-10-02 05:24:18 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-01 06:13:25 388096 ----a-r- C:\Users\rizet\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-01 06:13:25 -------- d-----w- C:\Program Files (x86)\Trend Micro
2013-09-30 07:31:07 39200 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
2013-09-30 07:31:07 28448 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2013-09-30 07:08:38 -------- d-----w- C:\Downloads
2013-09-27 07:18:04 -------- d-----w- C:\Program Files\iPod
2013-09-27 07:18:03 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-27 07:18:03 -------- d-----w- C:\Program Files\iTunes
2013-09-27 07:18:03 -------- d-----w- C:\Program Files (x86)\iTunes
2013-09-27 01:43:42 -------- d-----w- C:\Users\rizet\AppData\Local\Best Service
2013-09-27 01:42:51 -------- dc-h--w- C:\ProgramData\{B104EEFB-5DC6-4374-BAEE-2B59875F3650}
2013-09-27 01:42:45 -------- d-----w- C:\Program Files\Best Service
2013-09-27 01:42:44 -------- d-----w- C:\ProgramData\Best Service
2013-09-27 01:42:27 -------- dc-h--w- C:\ProgramData\{019B143A-9DF7-4A4E-9071-1FB3892DDD09}
2013-09-27 01:42:27 -------- d-----w- C:\Program Files (x86)\Common Files\Yellow Tools
2013-09-25 06:32:44 -------- d-----w- C:\Users\rizet\AppData\Roaming\Voxengo
2013-09-23 02:04:45 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\外掛模組\npqtplugin5.dll
2013-09-23 02:04:45 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\外掛模組\npqtplugin4.dll
2013-09-23 02:04:45 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\外掛模組\npqtplugin3.dll
2013-09-23 02:04:45 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\外掛模組\npqtplugin2.dll
2013-09-23 02:04:45 159744 ----a-w- C:\Program Files (x86)\Internet Explorer\外掛模組\npqtplugin.dll
2013-09-18 07:10:48 -------- d-----w- C:\Users\rizet\AppData\Roaming\VST XMLs
2013-09-18 07:10:00 -------- d-----w- C:\Users\rizet\AppData\Roaming\VST3 Presets
2013-09-18 07:09:38 -------- d-----w- C:\Program Files\Common Files\Propellerhead Software
2013-09-18 07:09:14 -------- d-----w- C:\Program Files\eLicenser
2013-09-18 05:55:58 -------- d-----w- C:\Program Files\u-he
2013-09-17 00:53:55 -------- d-----w- C:\Program Files (x86)\Cisco
2013-09-17 00:53:01 614400 ----a-w- C:\Windows\SysWow64\Rtlihvs.dll
2013-09-17 00:53:01 380928 ----a-w- C:\Windows\RtlUI2.exe
2013-09-17 00:53:01 188416 ----a-w- C:\Windows\SysWow64\RTLExtUI.dll
2013-09-16 08:51:18 -------- d-----w- C:\Users\rizet\AppData\Roaming\uk.co.jellycam.V4
2013-09-16 06:05:02 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-09-16 06:02:54 -------- d-----w- C:\Program Files\Bonjour
2013-09-16 06:02:54 -------- d-----w- C:\Program Files (x86)\Bonjour
2013-09-13 07:00:37 -------- d-----w- C:\Users\rizet\AppData\Local\PaceAP
2013-09-13 06:56:39 -------- d-----w- C:\Users\rizet\AppData\Roaming\UVIWorkstation
2013-09-13 06:50:30 -------- d-----w- C:\Program Files\UVISoundBanks
2013-09-13 06:50:26 -------- d-----w- C:\Program Files\Common Files\Avid
2013-09-13 06:50:23 2311680 ----a-w- C:\Windows\System32\libsndfile-1.dll
2013-09-13 06:50:23 -------- d-----w- C:\Program Files\UVI Workstation x64
2013-09-13 06:50:23 -------- d-----w- C:\Program Files (x86)\Common Files\UVI
2013-09-13 06:46:42 -------- d-----w- C:\ProgramData\PACE
2013-09-13 06:19:12 25808 ----a-w- C:\Windows\System32\drivers\iLokDrvr.sys
2013-09-13 06:19:00 -------- d-----w- C:\Program Files (x86)\iLok License Manager
2013-09-13 06:19:00 -------- d-----w- C:\Program Files (x86)\Common Files\PACE
2013-09-11 17:17:50 571168 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-09-11 09:12:59 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-09-11 09:12:59 362496 ----a-w- C:\Windows\System32\wow64win.dll
2013-09-11 09:12:59 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-09-11 09:12:59 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-09-11 09:12:59 112640 ----a-w- C:\Windows\System32\smss.exe
2013-09-11 09:12:58 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-09-11 09:12:58 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-09-11 09:11:50 3155456 ----a-w- C:\Windows\System32\win32k.sys
2013-09-11 00:31:49 -------- d-----w- C:\Program Files (x86)\OB_DEHUMANISER_WIN
2013-09-11 00:13:20 -------- d-----w- C:\Users\rizet\AppData\Roaming\Cycling '74
2013-09-09 00:36:24 4249197 ----a-w- C:\Windows\SysWow64\WIN Installer Authorization Manager (Ver. 1.0.9 RC4).exe
.
==================== Find3M  ====================
.
2013-09-27 00:59:47 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-27 00:59:47 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-25 06:53:41 16 ----a-w- C:\Windows\System32\msvcsv60.dll
2013-09-25 06:53:41 16 ----a-w- C:\Users\rizet\AppData\Roaming\msregsvv.dll
2013-09-18 08:25:05 1249792 ----a-w- C:\Users\rizet\AppData\Roaming\msvcr90-ruby191.dll
2013-09-18 08:25:01 16 ----a-w- C:\Windows\SysWow64\msvcsv60.dll
2013-09-12 07:25:43 6599968 ----a-w- C:\Windows\System32\nvcpl.dll
2013-09-12 07:25:43 3452192 ----a-w- C:\Windows\System32\nvsvc64.dll
2013-09-12 07:25:40 920864 ----a-w- C:\Windows\System32\nvvsvc.exe
2013-09-12 07:25:40 63776 ----a-w- C:\Windows\System32\nvshext.dll
2013-09-12 07:25:40 2559776 ----a-w- C:\Windows\System32\nvsvcr.dll
2013-09-12 07:25:40 219424 ----a-w- C:\Windows\System32\nvmctray.dll
2013-08-20 13:32:58 29984 ----a-w- C:\Windows\System32\nvaudcap64v.dll
2013-08-02 02:15:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:51:23 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 ----a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:45:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-31 13:29:19 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-07-31 13:19:03 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-07-31 13:18:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-07-31 13:14:29 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-07-31 13:13:07 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-07-31 13:08:44 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-07-31 10:00:20 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-07-31 09:52:44 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-07-31 09:52:34 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-07-31 09:48:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-07-31 09:48:09 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-07-31 09:45:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 10:00:46.22 ===============
 
 
those two txt are also attached.
thanks!
 
 

Attached Files



BC AdBot (Login to Remove)

 


#2 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:08 AM

Posted 03 October 2013 - 09:36 PM

Hello painpotato,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Follow This Topic.I suggest you click it and select Immediate E-Mail notification and click on Follow This Topic. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

  • Finally, please reply using the Post button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.
  • Download RogueKiller on the desktop
  • Close all the running processes
  • Under Vista/Seven, right click -> Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • When prompted, Click Scan
  • A report should open, give its content to your helper. (RKreport could also be found next to the executable)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename in winlogon.exe (or winlogon.com) and try again

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#3 painpotato

painpotato
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:08 PM

Posted 03 October 2013 - 09:46 PM

hi

thanks for the quick response.

here is my RKreport:

 

RogueKiller V8.7.1 [Oct  3 2013] tigzy 設計製作
電子郵件 : tigzyRK<at>gmail<dot>com
 
作業系統 : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
開始在 : 標準模式
使用�?� : rizet [系統�?�理員權限]
模式 : 掃瞄 -- 日期 : 10/04/2013 10:43:37
| ARK || FAK || MBR |
 
¤¤¤ 損壞的處理程序 : 0 ¤¤¤
 
¤¤¤ 系統登錄項�? : 0 ¤¤¤
 
¤¤¤ 計劃任務 : 0 ¤¤¤
 
¤¤¤ 啟動的項�? : 0 ¤¤¤
 
¤¤¤ Web�?�覽器 : 0 ¤¤¤
 
¤¤¤ 特�?�檔案/資料夾: ¤¤¤
 
¤¤¤ 驅動程式 : [未載入 0x0] ¤¤¤
 
¤¤¤ 外部 Hives: ¤¤¤
 
¤¤¤ 感染 :  ¤¤¤
 
¤¤¤ HOSTS 檔: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
127.0.0.1 localhost
 
 
¤¤¤ MBR 檢查: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (標準磁碟機) - WDC WD6400AAKS-00A7B2 ATA Device +++++
--- User ---
[MBR] a3768d443af0d19bbfcafe20b7190919
[BSP] 32855c36c5e27a8160d613324e5724a7 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 276501 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 566275185 | Size: 333976 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) (標準磁碟機) - WDC WD10EALX-009BA0 ATA Device +++++
--- User ---
[MBR] 8072e80d6e3d0abcbbbc42f5c2d70a05
[BSP] 847649596dd38710bbab6a92411ab5d7 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 953867 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ IDE) (標準磁碟機) - WDC WD1502FAEX-007BA0 ATA Device +++++
--- User ---
[MBR] 2a7ca0abec85303403ec251070f43ef8
[BSP] ccd17d376bc8c4f809524c0e7c40bf85 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 1430797 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
�?�成 : << RKreport[0]_S_10042013_104337.txt >>


#4 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:08 AM

Posted 06 October 2013 - 03:39 PM

Install Recovery Console and Run ComboFix

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

Download Combofix from any of the links below, and save it to your desktop

Link 1
Link 2

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • RcAuto1.gif
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    whatnext.png
  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
 


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#5 painpotato

painpotato
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:08 PM

Posted 06 October 2013 - 09:04 PM

thank you

during the running of ComboFix i got some error messages like "pev.3XE has stop working (and "PEV.exe" as well),and i just ignored them.

below is the content of ComboFix.txt

 

ComboFix 13-10-04.02 - rizet 3/10/07 週一   9:08.1.4 - x64
Microsoft Windows 7 企業版   6.1.7601.1.950.886.1028.18.8190.6500 [GMT 8:00]
執行位置: c:\users\rizet\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
FW: Kaspersky Anti-Virus *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   被刪除的檔案   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\smartdl
c:\program files (x86)\smartdl\gunzip.exe
c:\program files (x86)\smartdl\status
c:\windows\SysWow64\msvcsv60.dll
c:\windows\TEMP\kladminkit\0592010f-a7b3-4456-bb31-9dc8d01e62df.dll
.
.
(((((((((((((((((((((((((  2013-09-07 至 2013-10-07 的新的檔案  )))))))))))))))))))))))))))))))
.
.
2013-10-07 01:17 . 2013-10-07 01:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-10-07 01:17 . 2013-10-07 01:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-07 01:17 . 2013-10-07 01:17 -------- d-----w- c:\users\user\AppData\Local\temp
2013-10-04 01:42 . 2013-10-04 01:42 -------- d-----w- C:\FRST
2013-10-04 01:01 . 2013-10-04 01:01 -------- d-----w- c:\program files\Enigma Software Group
2013-10-04 01:00 . 2013-10-04 01:52 -------- d-----w- c:\windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-04 01:00 . 2013-10-04 01:00 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-10-03 08:36 . 2011-08-11 05:46 694376 ----a-w- c:\windows\system32\drivers\RTL8192su.sys
2013-10-03 08:36 . 2013-10-03 08:36 -------- d-----w- c:\program files (x86)\Cerio UW Series
2013-10-02 21:47 . 2013-09-15 16:50 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E1A2F984-122F-45BB-B0C7-4EC1B02D32EC}\mpengine.dll
2013-10-02 05:24 . 2013-10-02 05:24 -------- d-----w- c:\users\rizet\AppData\Roaming\Malwarebytes
2013-10-02 05:24 . 2013-10-02 05:24 -------- d-----w- c:\programdata\Malwarebytes
2013-10-02 05:24 . 2013-10-02 05:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-10-02 05:24 . 2013-04-04 06:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-01 06:13 . 2013-10-01 06:13 388096 ----a-r- c:\users\rizet\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-01 06:13 . 2013-10-01 06:13 -------- d-----w- c:\program files (x86)\Trend Micro
2013-09-30 07:40 . 2013-09-30 07:40 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-09-30 07:31 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-30 07:31 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-30 07:08 . 2013-09-30 07:08 -------- d-----w- C:\Downloads
2013-09-27 07:18 . 2013-09-27 07:18 -------- d-----w- c:\program files\iPod
2013-09-27 07:18 . 2013-09-27 07:18 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-27 07:18 . 2013-09-27 07:18 -------- d-----w- c:\program files\iTunes
2013-09-27 07:18 . 2013-09-27 07:18 -------- d-----w- c:\program files (x86)\iTunes
2013-09-27 01:43 . 2013-09-27 01:43 -------- d-----w- c:\users\rizet\AppData\Local\Best Service
2013-09-27 01:42 . 2013-09-27 01:42 -------- dc-h--w- c:\programdata\{B104EEFB-5DC6-4374-BAEE-2B59875F3650}
2013-09-27 01:42 . 2013-09-27 01:42 -------- d-----w- c:\program files\Best Service
2013-09-27 01:42 . 2013-09-27 01:42 -------- d-----w- c:\programdata\Best Service
2013-09-27 01:42 . 2013-09-27 01:42 -------- dc-h--w- c:\programdata\{019B143A-9DF7-4A4E-9071-1FB3892DDD09}
2013-09-27 01:42 . 2013-09-27 01:42 -------- d-----w- c:\program files (x86)\Common Files\Yellow Tools
2013-09-25 06:32 . 2013-09-25 06:32 -------- d-----w- c:\users\rizet\AppData\Roaming\Voxengo
2013-09-23 02:04 . 2013-09-23 02:04 159744 ----a-w- c:\program files (x86)\Internet Explorer\外掛模組\npqtplugin5.dll
2013-09-23 02:04 . 2013-09-23 02:04 159744 ----a-w- c:\program files (x86)\Internet Explorer\外掛模組\npqtplugin4.dll
2013-09-23 02:04 . 2013-09-23 02:04 159744 ----a-w- c:\program files (x86)\Internet Explorer\外掛模組\npqtplugin3.dll
2013-09-23 02:04 . 2013-09-23 02:04 159744 ----a-w- c:\program files (x86)\Internet Explorer\外掛模組\npqtplugin2.dll
2013-09-23 02:04 . 2013-09-23 02:04 159744 ----a-w- c:\program files (x86)\Internet Explorer\外掛模組\npqtplugin.dll
2013-09-23 02:04 . 2013-09-23 02:04 -------- d-----w- c:\program files (x86)\QuickTime
2013-09-18 07:10 . 2013-09-18 07:10 -------- d-----w- c:\users\rizet\AppData\Roaming\VST XMLs
2013-09-18 07:10 . 2013-09-18 07:10 -------- d-----w- c:\users\rizet\AppData\Roaming\VST3 Presets
2013-09-18 07:09 . 2013-09-18 07:09 -------- d-----w- c:\program files\Common Files\Propellerhead Software
2013-09-18 07:09 . 2013-09-18 07:09 -------- d-----w- c:\program files\eLicenser
2013-09-18 05:55 . 2013-09-18 05:55 -------- d-----w- c:\program files\u-he
2013-09-17 00:53 . 2013-09-17 00:54 -------- d-----w- c:\program files (x86)\Cisco
2013-09-17 00:53 . 2009-04-02 02:27 188416 ----a-w- c:\windows\SysWow64\RTLExtUI.dll
2013-09-17 00:53 . 2009-03-31 06:31 380928 ----a-w- c:\windows\RtlUI2.exe
2013-09-17 00:53 . 2008-07-01 04:31 614400 ----a-w- c:\windows\SysWow64\Rtlihvs.dll
2013-09-16 08:51 . 2013-09-16 08:51 -------- d-----w- c:\users\rizet\AppData\Roaming\uk.co.jellycam.V4
2013-09-16 06:05 . 2012-08-21 05:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-09-16 06:03 . 2013-09-16 06:03 -------- d-----w- c:\program files (x86)\Apple Software Update
2013-09-16 06:03 . 2013-09-16 06:03 -------- d-----w- c:\program files\Common Files\Apple
2013-09-16 06:02 . 2013-09-16 06:02 -------- d-----w- c:\program files\Bonjour
2013-09-16 06:02 . 2013-09-16 06:02 -------- d-----w- c:\program files (x86)\Bonjour
2013-09-13 07:00 . 2013-09-13 07:00 -------- d-----w- c:\users\rizet\AppData\Local\PaceAP
2013-09-13 06:56 . 2013-09-13 07:00 -------- d-----w- c:\users\rizet\AppData\Roaming\UVIWorkstation
2013-09-13 06:50 . 2013-09-13 06:50 -------- d-----w- c:\program files\UVISoundBanks
2013-09-13 06:50 . 2013-09-13 06:50 -------- d-----w- c:\program files\Common Files\Avid
2013-09-13 06:50 . 2013-09-13 06:50 -------- d-----w- c:\program files\UVI Workstation x64
2013-09-13 06:50 . 2013-09-13 06:50 -------- d-----w- c:\program files (x86)\Common Files\UVI
2013-09-13 06:50 . 2013-04-17 10:37 2311680 ----a-w- c:\windows\system32\libsndfile-1.dll
2013-09-13 06:46 . 2013-09-13 06:46 -------- d-----w- c:\programdata\PACE
2013-09-13 06:19 . 2013-09-13 06:19 25808 ----a-w- c:\windows\system32\drivers\iLokDrvr.sys
2013-09-13 06:19 . 2013-09-13 06:19 -------- d-----w- c:\program files (x86)\iLok License Manager
2013-09-13 06:19 . 2013-09-13 06:19 -------- d-----w- c:\program files (x86)\Common Files\PACE
2013-09-11 17:17 . 2013-09-11 17:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-09-11 09:12 . 2013-08-02 02:15 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-09-11 09:12 . 2013-08-02 02:15 362496 ----a-w- c:\windows\system32\wow64win.dll
2013-09-11 09:12 . 2013-08-02 02:15 243712 ----a-w- c:\windows\system32\wow64.dll
2013-09-11 09:12 . 2013-08-02 02:13 1161216 ----a-w- c:\windows\system32\kernel32.dll
2013-09-11 09:12 . 2013-08-02 01:59 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-11 09:12 . 2013-08-02 00:59 112640 ----a-w- c:\windows\system32\smss.exe
2013-09-11 09:12 . 2013-08-02 02:23 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-09-11 09:12 . 2013-08-02 01:59 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-09-11 09:11 . 2013-08-08 01:20 3155456 ----a-w- c:\windows\system32\win32k.sys
2013-09-11 09:10 . 2013-07-26 02:24 14172672 ----a-w- c:\windows\system32\shell32.dll
2013-09-11 09:10 . 2013-07-26 02:24 197120 ----a-w- c:\windows\system32\shdocvw.dll
2013-09-11 00:31 . 2013-09-11 00:31 -------- d-----w- c:\program files (x86)\OB_DEHUMANISER_WIN
2013-09-11 00:13 . 2013-09-11 00:13 -------- d-----w- c:\users\rizet\AppData\Roaming\Cycling '74
2013-09-09 00:36 . 2012-12-04 09:26 4249197 ----a-w- c:\windows\SysWow64\WIN Installer Authorization Manager (Ver. 1.0.9 RC4).exe
.
.
.
((((((((((((((((((((((((((((((((((((((((   在三個月內被修改的檔案   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-27 00:59 . 2012-07-27 03:38 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-27 00:59 . 2012-07-27 03:38 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-25 06:53 . 2012-07-18 01:21 16 ----a-w- c:\windows\system32\msvcsv60.dll
2013-09-25 06:53 . 2012-07-18 01:21 16 ----a-w- c:\users\rizet\AppData\Roaming\msregsvv.dll
2013-09-18 08:25 . 2013-05-31 09:01 1249792 ----a-w- c:\users\rizet\AppData\Roaming\msvcr90-ruby191.dll
2013-09-12 08:58 . 2013-03-26 00:33 2986672 ----a-w- c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2013-03-26 00:33 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-09-12 08:58 . 2013-03-26 00:33 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-09-12 08:58 . 2013-03-26 00:33 12947360 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-09-12 07:25 . 2013-03-26 00:34 6599968 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2013-03-26 00:34 3452192 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2013-03-26 00:34 920864 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2013-03-26 00:34 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2013-03-26 00:34 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2013-03-26 00:34 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-08-20 13:32 . 2013-07-31 00:20 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-08-14 23:45 . 2012-07-12 09:32 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-02 01:48 . 2013-09-11 09:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 00:26 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 00:26 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 23:48 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 23:48 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 00:32 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 00:25 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 00:32 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 00:32 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-09 05:46 . 2013-08-14 00:32 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 04:52 . 2013-08-14 00:25 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 00:32 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 00:32 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 00:32 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-09 04:46 . 2013-08-14 00:32 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
.
.
(((((((((((((((((((((((((((((((((((((   重要登入點   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2013-09-03 40312]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-04-30 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-09-17 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"disablecad"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1.0FO\adialhk.dll c:\progra~2\KASPER~1\KASPER~1.0FO\kloehk.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ   \0
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 gogoc;gogo6 gogoCLIENT;c:\program files\gogo6\gogoCLIENT\gogoc.exe;c:\program files\gogo6\gogoCLIENT\gogoc.exe [x]
R3 gogoTunnelDevice;gogo6  Multi-Virtual Tunnel Adapter;c:\windows\system32\DRIVERS\gogotun.sys;c:\windows\SYSNATIVE\DRIVERS\gogotun.sys [x]
R3 MADFUMIDISPORT2010;Service for M-Audio MIDISPORT DFU;c:\windows\system32\DRIVERS\MAudioMIDISPORT_DFU.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioMIDISPORT_DFU.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows 啟用技術服務;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S2 klnagent;Kaspersky Lab Network Agent;c:\program files (x86)\Kaspersky Lab\NetworkAgent 8\klnagent.exe;c:\program files (x86)\Kaspersky Lab\NetworkAgent 8\klnagent.exe [x]
S2 MIDISPORTAudioDevMon;MIDISPORT Audio Device Monitor;c:\program files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe;c:\program files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe [x]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
S2 Realtek11nSU;Realtek11nSU;c:\program files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtlService.exe;c:\program files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtlService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [x]
S2 TouchServiceWacom;Wacom Professional Touch Service;c:\program files\Tablet\Wacom\Wacom_TouchService.exe;c:\program files\Tablet\Wacom\Wacom_TouchService.exe [x]
S3 hdsp;RME Hammerfall Audio Device;c:\windows\system32\drivers\hdsp_64.sys;c:\windows\SYSNATIVE\drivers\hdsp_64.sys [x]
S3 iLokDrvr;Usb Driver;c:\windows\system32\DRIVERS\iLokDrvr.sys;c:\windows\SYSNATIVE\DRIVERS\iLokDrvr.sys [x]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys;c:\windows\SYSNATIVE\DRIVERS\klfltdev.sys [x]
S3 MAUSBMIDISPORT;Service for M-Audio MIDISPORT;c:\windows\system32\DRIVERS\MAudioMIDISPORT.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioMIDISPORT.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192su;Cerio UW Series Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
S3 SynUSB64;eLicenser;c:\windows\system32\DRIVERS\SynUSB64.sys;c:\windows\SYSNATIVE\DRIVERS\SynUSB64.sys [x]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys;c:\windows\SYSNATIVE\DRIVERS\wacmoumonitor.sys [x]
.
.
 ‘計劃任務’ 文件夾 裡的內容
.
2013-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 00:59]
.
2013-10-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2931986577-4141694688-2209301252-1410Core.job
- c:\users\rizet\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-13 04:42]
.
2013-10-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2931986577-4141694688-2209301252-1410UA.job
- c:\users\rizet\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-13 04:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 02:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDSPTray1"="hdsp32.exe" [2012-11-16 648192]
"HDSPTray2"="hdspmix.exe" [2012-11-16 1159168]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1.0FO\x64\kloehk.dll c:\progra~2\KASPER~1\KASPER~1.0FO\x64\adialhk.dll
.
------- 而外的掃描 -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://h1app.softstar.com.tw/Softstar/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local;*.local
IE: 匯出至 Microsoft Excel(&X) - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 172.18.99.101 172.18.99.102
DPF: {42BCE7C0-5E2B-11D7-8D51-0006291EDF61} - hxxps://stock2.ubot.com.tw/Web/ebroker/axebroker.cab
.
.
------- 文件類型 -------
.
txtfile=c:\windows\notepad.exe %1
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-GoogleDriveSync - c:\program files (x86)\Google\Drive\googledrivesync.exe
Wow6432Node-HKLM-Run-AVP - c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe
AddRemove-{1457D7DC-9E2F-4559-955B-9E29E04C384C} - c:\programdata\{A6017E65-D6CA-4789-B9AD-CF6816B1815D}\E-License Manager.exe
AddRemove-{1D6D673D-C78F-4EC1-9D46-48068543784B} - c:\programdata\{1D2B2B7D-077F-415B-A61E-36CD2DAB34F3}\Engine Installer.exe
AddRemove-{2CC24A0D-82DA-4061-A91E-C4528767C700} - c:\programdata\{61B6FEE8-00B2-43F5-A30A-4AB4D9B5272A}\Engine Installer.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PaceLicenseDServices]
"ImagePath"="\"c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe\" -u https://activation.paceap.com/InitiateActivation"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2931986577-4141694688-2209301252-1410\Software\SOFTSTAR\'b?*?*o?*]
"UnityGraphicsQuality_h1669003810"=dword:00000003
"Screenmanager Resolution Width_h182942802"=dword:00000400
"Screenmanager Resolution Height_h2627697771"=dword:00000300
"Screenmanager Is Fullscreen mode_h3981298716"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ 其他運行進程 ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RtWlan.exe
c:\program files (x86)\Cerio UW Series\11n USB Wireless LAN Utility\RTLDHCP.exe
.
**************************************************************************
.
完成時間: 2013-10-07  09:42:42 - 電腦已重新啟動
ComboFix-quarantined-files.txt  2013-10-07 01:42
.
Pre-Run: 140,808,183,808 位元組可用
Post-Run: 146,885,124,096 位元組可用
.
- - End Of File - - 9904E162783669B52BEF382584BE0A4A
A36C5E4F47E84449FF07ED3517B43A31


#6 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:08 AM

Posted 07 October 2013 - 07:25 PM

How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#7 painpotato

painpotato
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:08 PM

Posted 07 October 2013 - 07:45 PM

thank you.

so far it's running like nothing ever happened.

is it safe now to say it is cured?



#8 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:08 AM

Posted 12 October 2013 - 10:29 AM

Hello, painpotato.
Congratulations! You now appear clean! :cool:


Uninstall Combofix
  • Make sure that Combofix.exe that you downloaded is on your Desktop but Do not run it!
    o *If it is not on your Desktop, the below will not work.
  • Click on StartBtn.gif then Run....
  • Now copy & paste the green bolded text in the run-box and click OK.

    ComboFix /Uninstall

    CF_Uninstall-1.jpg

    <Notice the space between the "x" and "/".> <--- It needs to be there
    Windows Vista users: Press the Windows Key + R to bring the Run... Command and then from there you can add in the Combofix /Uninstall
  • Please advise if this step is missed for any reason as it performs some important actions:
    "This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.
    It also makes a clean Restore Point and flashes all the old restore points in order to prevent possible reinfection from an old one through system restore".
Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

We Need to Clean Up Our Mess
  • Download OTC by OldTimer and save it to your desktop.
  • Double click OTC_Icon.jpg icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big CleanUp.jpg button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
One of the most common questions found when cleaning malware is "how did my machine get infected?"

There are a variety of reasons, but the most common ones are that you are not practicing Safe Internet, you are not running the proper security software or that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer to help reduce the chance of being infected again in the future.

Do not use P2P programs
Peer-to-peer or file-sharing programs (such as uTorrent, Limewire and Bitorrent) are probably the primary route of infection nowadays. These programs allow file sharing between users as the name(s) suggest. It is almost impossible to know whether the file you’re downloading through P2P programs is safe.

It is therefore possible to be infected by downloading infected files via peer-to-peer programs and so I recommend that you do not use these programs. Should you wish to use them, they must be used with extreme care. Some further reading on this subject, along with included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."

In addition, P2P programs facilitate cyber crime and help distribute pirated software, movies and other illegal material.

Practice Safe Internet
Another one of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on. Whether these things are files or sites it doesn't really matter. If something is out to get you, and you click on it, it most likely will.

Below are a list of simple precautions to take to keep your computer clean and running securely:
  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.
  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean. For the casual computer user, you will almost never receive a valid attachment of this type.
  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is. The email could be from someone you know who is themselves infected with malware which is trying to infect everyone in their address book. A key thing to look out for here is: does the email sound as though it’s from the person you know? Often, the email may simply have a web link or a “Run this file to make your PC run fast” message in it.
  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!. These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software. For an example of these types of pop-ups, or Foistware, you should read this article: Foistware, And how to avoid it.
    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. Removal instructions for a lot of these "rogues" can be found here.
  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you, or will download a file to your PC without your knowledge. You can check to see if it's a real alert by right-clicking on the window. If there is a menu that comes up saying Add to Favorites... you know it's a fake. DO NOT click on these windows, instead close them by finding the open window on your Taskbar, right click and chose close.
  • Do not visit pornographic websites. I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites. I am not saying all adult sites do this, but a lot do, as this can often form part of their funding.
  • When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection. Instead when you receive a message that contains a link you should message back to the person asking if it is legit.
  • Stay away from Warez and Crack sites! As with Peer-2-Peer programs, in addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.
  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download files from a site, and are not sure if they are legitimate, you can use tools such as BitDefender Traffic Light, Norton Safe Web, or McAfee SiteAdvisor to look up info on the site and stay protected against malicious sites. Please be sure to only choose and install one of those tool bars.
  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money. By reading the agreement there is a good chance you can spot this and not install the software.
    Sometimes even legitimate programs will try to bundle extra, unwanted, software with the program you want - this is done to raise money for the program. Be sure to untick any boxes which may indicate that other programs will be downloaded.
Keep Windows up-to-date
Microsoft continually releases security and stability updates for its supported operating systems and you should always apply these to help keep your PC secure.
  • Windows XP users
    You should visit Windows Update to check for the latest updates to your system. The latest service pack (SP3) can be obtained directly from Microsoft here.
  • Windows Vista users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP2) can be obtained directly from Microsoft here.
  • Windows 7 users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP1) can be obtained directly from Microsoft here
Keep your browser secure
Most modern browsers have come on in leaps and bounds with their inbuilt, default security. The best way to keep your browser secure nowadays is simply to keep it up-to-date.

The latest versions of the three common browsers can be found below:Use an AntiVirus Software
It is very important that your computer has an up-to-date anti-virus software on it which has a real-time agent running. This alone can save you a lot of trouble with malware in the future.
See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources, a couple of free Anti-Virus programs you may be interested in are Microsoft Security Essentials and Avast.

It is imperative that you update your Antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out. If you use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.

All versions of Windows starting from XP have an in-built firewall. With Windows XP this firewall will protect you from incoming traffic (i.e. hackers). Starting with Windows Vista, the firewall was beefed up to also protect you against outgoing traffic (i.e. malicious programs installed on your machine should be blocked from sending data, such as your bank details and passwords, out).

In addition, if you connect to the internet via a router, this will normally have a firewall in-built.

Some people will recommend installing a different firewall (instead of the Windows’ built one), this is personal choice, but the message is to definitely have one! For a tutorial on Firewalls and a listing of some available ones see this link: Understanding and Using Firewalls

Install an Anti-Malware program
Recommended, and free, Anti-Malware programs are Malwarebytes Anti-Malware and SuperAntiSpyware.

You should regularly (perhaps once a week) scan your computer with an Anti-Malware program just as you would with an antivirus software.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is very important to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities (such as Adobe Reader and Java). You can check these by visiting Secunia Software Inspector.

Follow this list and your potential for being infected again will reduce dramatically.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#9 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:08 AM

Posted 15 October 2013 - 09:55 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users