Jump to content

wow.dll error every time I right click on a file in windows explorer


Recommended Posts

I am getting this message every time I right click on any desktop icon or any file in windows explorer.

 

There was a problem starting

C:\users\liyunq~1\appdata\local\temp\sqfuood\sivoxcr\wow.dll

the specified module could not be found

 

I have gone over the forum and it seems others are getting similar problems, but each solution might be slightly different. I downloaded roguekiller software for my 64 bit windows 7 OS and ran the scan. I have included the scan report below. Any help on how to proceed from here is greatly appreciated.

 

 

RogueKiller V8.7.13 _x64_ [Dec 18 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Liyun Qiu Ringue [Admin rights]
Mode : Scan -- Date : 12/23/2013 20:01:18
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 0 ¤¤¤
 
¤¤¤ Registry Entries : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ INPROC][sUSP PATH] HKCR\[...]\InprocServer32 :  (C:\Users\LIYUNQ~1\AppData\Local\Temp\sqfuood\sivoxcr\wow64.dll [-]) -> FOUND
 
¤¤¤ Scheduled tasks : 1 ¤¤¤
[V2][sUSP PATH] {C44DF985-73EB-436F-B043-3ACD2F4C9609} : C:\Users\Liyun Qiu Ringue\Desktop\Junwen\LeagueOfLegends\League of Legends\lol.launcher.exe [x] -> FOUND
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) ST31000528AS +++++
--- User ---
[MBR] acbe81f50ad6abe86c7a18954da3fb1b
[bSP] 7f061f6e2cbab784ed6c4741448d5688 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 941361 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1928114176 | Size: 12406 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Link to post
Share on other sites

Here are my dds and attach scans

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.16428  BrowserJavaVersion: 10.25.2
Run by Liyun Qiu Ringue at 20:24:53 on 2013-12-23
Microsoft Windows 7 Home Premium   6.1.7601.1.936.86.1033.18.8055.6511 [GMT -8:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Windows\SysWOW64\svchost.exe -k PPTVServiceGroup
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\PPLiveNetwork\PPAP.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: IE2EMBHO Class: {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files (x86)\easyMule\modules\IE2EM.dll
BHO: BrowserHelper: {4BF2CB0E-658A-442B-AC83-A64EC2150BFC} - C:\ProgramData\PPBrowserHelper\BHO\TipsBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: 7DCCDF95-9CCC-4312-0D4E-6BE551BA6789 Class: {7DCCDF95-9CCC-4312-0D4E-6BE551BA6789} - C:\Program Files (x86)\ppsaddr\{7DCCDF95-9CCC-4312-0D4E-6BE551BA6789}\AddressBar.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
dRun: [PPS Accelerator] D:\PPS.tv\PPStream\PPSKernel.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download by easyMule - C:\Program Files (x86)\easyMule\IE2EM.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to iPod Converter - C:\Users\Liyun Qiu Ringue\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files (x86)\PPLive\PPTV\PPLive.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\0596E6B664963786D27657563747 : DHCPNameServer = 76.14.0.8 76.14.0.9 76.14.96.14
TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\C496E6B6379737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\C496E6B63797370393233333 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\E45445745414259343 : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Liyun Qiu Ringue\AppData\Roaming\Mozilla\Firefox\Profiles\lkxhbd8p.default\
FF - prefs.js: network.proxy.type - 0
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\coFFPlgn\components\coFFPlgn.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll
FF - plugin: C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll
FF - plugin: C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.1.94\Bin\npSSOAxCtrlForPTLogin.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Internet Explorer\PPLite\plugin\1.0.1.3117\npplugin2.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Tencent\Qzone\npQQPhotoDrawEx.dll
FF - plugin: C:\Program Files (x86)\Tencent\QZoneMusic\2013.10.5.19.52.40\npQzoneMusic.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll
FF - plugin: C:\Users\Liyun Qiu Ringue\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extentions.y2layers.installId - 509759a6-aa96-40c0-8df2-e4baa795dcea
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 134944]
R2 PPTVService;PPTVService;C:\Windows\System32\svchost.exe -k PPTVServiceGroup [2009-7-13 27136]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-24 56344]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2010-11-24 852256]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-24 346144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FlyUsb;FLY Fusion;C:\Windows\System32\drivers\FlyUsb.sys [2011-11-12 24576]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-12 111616]
S3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2010-5-7 30304]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-17 351136]
S3 LVUVC64;Logitech HD Webcam C310(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-17 4865568]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-7 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-12 1255736]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-24 203264]
S4 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-6-12 400368]
S4 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-4-27 48488]
S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-24 13336]
S4 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2010-5-7 197976]
S4 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-11-24 635416]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S4 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
S4 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-24 2320920]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-12-24 00:29:59 82944 ----a-w- C:\Windows\System32\drivers\ipfltdrv.sys.bak
2013-12-23 23:39:09 -------- d-----w- C:\Users\Liyun Qiu Ringue\AppData\Local\SlimWare Utilities Inc
2013-12-23 23:39:05 -------- d-----w- C:\ProgramData\SlimWare Utilities Inc
2013-12-23 20:52:05 10315576 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8BF6C951-1462-41D9-9A8B-99E34ADA7554}\mpengine.dll
2013-12-22 20:51:47 10315576 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-12 11:03:08 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-12 11:03:08 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 11:03:07 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2013-12-12 11:03:07 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2013-12-12 11:02:00 353280 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll
2013-12-12 11:02:00 293072 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2013-12-12 11:02:00 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-12-12 11:02:00 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2013-12-12 11:02:00 270848 ----a-w- C:\Program Files (x86)\Internet Explorer\ieproxy.dll
2013-12-12 11:02:00 251392 ----a-w- C:\Program Files (x86)\Internet Explorer\IEShims.dll
2013-12-12 11:02:00 235216 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2013-12-12 06:29:43 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-12-11 06:21:21 9293192 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2013-12-06 18:28:14 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E20ACCD8-A3C5-4FEB-ABB3-4B88565D01E4}\gapaengine.dll
2013-11-26 06:30:12 -------- d-----w- C:\Program Files\CCleaner
.
==================== Find3M  ====================
.
2013-12-11 06:21:32 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 06:21:32 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-26 10:18:23 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2013-11-26 09:48:07 66048 ----a-w- C:\Windows\System32\iesetup.dll
2013-11-26 09:46:25 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2013-11-26 09:18:39 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-11-26 09:18:09 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2013-11-26 09:16:57 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2013-11-26 08:35:02 5769216 ----a-w- C:\Windows\System32\jscript9.dll
2013-11-26 08:28:16 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2013-11-26 08:16:12 4243968 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-11-26 08:02:16 1995264 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-11-26 07:32:06 1928192 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-11-26 07:07:57 2334208 ----a-w- C:\Windows\System32\wininet.dll
2013-11-26 06:33:33 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-11-23 18:26:20 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-11-23 17:47:34 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-11-19 10:21:41 267936 ------w- C:\Windows\System32\MpSigStub.exe
2013-11-12 02:23:09 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-11-12 02:07:29 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-10-30 01:24:31 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-10-19 02:18:57 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-10-19 01:36:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-10-12 02:32:04 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-10-12 02:31:04 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:36 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-10-12 02:03:31 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:33:39 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-10-12 01:33:26 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-10-12 01:15:48 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-10-12 01:15:48 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2013-10-05 20:25:35 1474048 ----a-w- C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25 1168384 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31 190464 ----a-w- C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17 197120 ----a-w- C:\Windows\System32\credui.dll
2013-10-04 02:24:49 1930752 ----a-w- C:\Windows\System32\authui.dll
2013-10-04 02:16:30 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2013-10-04 01:58:50 152576 ----a-w- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25 168960 ----a-w- C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00 1796096 ----a-w- C:\Windows\SysWow64\authui.dll
2013-10-04 01:36:04 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2013-10-03 02:23:48 404480 ----a-w- C:\Windows\System32\gdi32.dll
2013-10-03 02:00:44 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2013-09-28 01:09:10 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-09-27 17:53:06 248240 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2013-09-27 17:53:06 134944 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2011-06-27 23:43:18 977784 ----a-w- C:\Program Files (x86)\LockDown.exe
2011-04-20 23:28:46 106496 ----a-w- C:\Program Files (x86)\TaskKeyHook.dll
2007-08-17 00:47:06 51656 ----a-w- C:\Program Files (x86)\RPUPDATE.exe
2007-03-14 10:57:26 348160 ----a-w- C:\Program Files (x86)\msvcr71.dll
2006-05-24 22:13:02 47560 ----a-w- C:\Program Files (x86)\LDBD.exe
.
============= FINISH: 20:25:09.32 ===============
 
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium 
Boot Device: \Device\HarddiskVolume1
Install Date: 3/10/2011 4:32:36 PM
System Uptime: 12/23/2013 5:34:09 PM (3 hours ago)
.
Motherboard: MSI |  | 2A9C
Processor: Intel® Core i5 CPU         650  @ 3.20GHz | CPU 1 | 3201/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 919 GiB total, 758.644 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 1.22 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP513: 12/9/2013 9:49:05 PM - Windows Update
RP514: 12/12/2013 3:00:36 AM - Windows Update
RP515: 12/15/2013 3:00:12 AM - Windows Update
RP516: 12/18/2013 11:13:32 PM - Windows Update
RP517: 12/22/2013 12:57:08 AM - Windows Update
RP518: 12/23/2013 4:13:08 PM - Removed SlimCleaner Plus
.
==== Installed Programs ======================
.
 Update for Microsoft Office 2007 (KB2508958)
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.7)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bejeweled 2 Deluxe
Blackhawk Striker 2
Bonjour
Build-a-lot 2
CameraHelperMsi
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Chuzzle Deluxe
CinemaNow Media Manager
Command & Conquer? Red Alert? 3
CyberLink DVD Suite Deluxe
D3DX10
Diner Dash 2 Restaurant Rescue
Dora's Carnival Adventure
DVD Menu Pack for HP MediaSmart Video
easyMule
erLT
Escape Rosecliff Island
FATE
Final Drive Nitro
Free YouTube to iPod Converter version 3.9.33.426
Full Tilt Poker
Google Chrome
Google Earth Plug-in
Google Update Helper
Heroes of Hellas 2 - Olympia
Hewlett-Packard ACLM.NET v1.2.1.1
HP Customer Experience Enhancements
HP Games
HP MediaSmart CinemaNow 2.0
HP MediaSmart DVD
HP MediaSmart Music
HP MediaSmart Photo
HP MediaSmart SmartMenu
HP MediaSmart Video
HP MediaSmart/TouchSmart Netflix
HP Odometer
HP Setup
HP Support Assistant
HP Support Information
HP Update
HP Vision Hardware Diagnostics
Hulu Desktop
HydraVision
iCloud
Intel® Management Engine Components
Intel® Rapid Storage Technology
iTunes
Java 7 Update 25
Java Auto Updater
Java 7 Update 4 (64-bit)
Jewel Quest 3
Jewel Quest Solitaire 2
Junk Mail filter update
Kobo
LabelPrint
LeapFrog Connect
LeapFrog Tag Plugin
LightScribe System Software
Logitech Vid HD
Logitech Webcam Software
LWS Facebook
LWS Gallery
LWS Help_main
LWS Launcher
LWS Motion Detection
LWS Pictures And Video
LWS Twitter
LWS Video Mask Maker
LWS VideoEffects
LWS Webcam Software
LWS WLM Plugin
LWS YouTube Plugin
MapleStory
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2010
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft OpenType Font File Properties Extension
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Movie Theme Pack for HP MediaSmart Video
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nexon Game Manager
Origin
Pando Media Booster
PDF Complete Special Edition
PDF Vista 7.02
Penguins!
PhotoNow!
PictureMover
Plants vs. Zombies
PlayReady PC Runtime amd64
Poker Superstars III
Polar Bowler
Polar Golfer
Power2Go
PowerDirector
ppsAddr
PPS影音 V2.7.0.1516 正式版
PPTV V3.3.1.0038
PressReader
QQ游戏
QQ音乐2013
QuickTime
Ralink RT2860 Wireless LAN Card
Realtek High Definition Audio Driver
Recovery Manager
Respondus LockDown Browser
Roxio CinemaNow 2.0
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition 
Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition 
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition 
Security Update for Microsoft Office Outlook 2007 (KB2825644) 32-Bit Edition 
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition 
Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition 
Security Update for Microsoft Visual Basic for Applications 6.5 (KB974945)
Skype Click to Call
Skype? 5.10
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
Virtual Families
Virtual Villagers - The Secret City
Vuze
Wheel of Fortune 2
Windows Driver Package - LeapFrog (FlyUsb) USB  (11/05/2008 1.1.1.0)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.20 (64 位)
Yontoo 1.10.02
Zinio Reader 4
Zuma Deluxe
华宇拼音输入法V6.9
微博桌面
腾讯QQ2013
.
==== End Of File ===========================
 

 

Link to post
Share on other sites

Hello lilosilver! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
P2P/Piracy Warning:

If you're using Peer 2 Peer software such as easyMule, Vuze or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Link to post
Share on other sites

DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 11.0.9600.16428  BrowserJavaVersion: 10.25.2

Run by Liyun Qiu Ringue at 15:35:54 on 2013-12-26

Microsoft Windows 7 Home Premium   6.1.7601.1.936.86.1033.18.8055.6665 [GMT -8:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

c:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\WUDFHost.exe

C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

C:\Windows\SysWOW64\svchost.exe -k PPTVServiceGroup

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

c:\Program Files\Microsoft Security Client\NisSrv.exe

C:\Users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Windows\explorer.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

c:\Program Files\Microsoft Security Client\MpCmdRun.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.


BHO: BrowserHelper: {4BF2CB0E-658A-442B-AC83-A64EC2150BFC} - C:\ProgramData\PPBrowserHelper\BHO\TipsBHO.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: 7DCCDF95-9CCC-4312-0D4E-6BE551BA6789 Class: {7DCCDF95-9CCC-4312-0D4E-6BE551BA6789} - C:\Program Files (x86)\ppsaddr\{7DCCDF95-9CCC-4312-0D4E-6BE551BA6789}\AddressBar.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll

BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll

dRun: [PPS Accelerator] D:\PPS.tv\PPStream\PPSKernel.exe

StartupFolder: C:\Users\LIYUNQ~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\Dropbox.exe

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

uPolicies-Explorer: NoDriveAutoRun = dword:0

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: Free YouTube to iPod Converter - C:\Users\Liyun Qiu Ringue\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

IE: {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files (x86)\PPLive\PPTV\PPLive.exe



TCP: NameServer = 192.168.1.1

TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6} : DHCPNameServer = 192.168.1.1

TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\0596E6B664963786D27657563747 : DHCPNameServer = 76.14.0.8 76.14.0.9 76.14.96.14

TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\C496E6B6379737 : DHCPNameServer = 192.168.1.1

TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\C496E6B63797370393233333 : DHCPNameServer = 192.168.1.1

TCP: Interfaces\{25295ED5-4607-4A7F-B19F-5900739CCBA6}\E45445745414259343 : DHCPNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll

x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update

x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe

x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-SSODL: WebCheck - <orphaned>

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Liyun Qiu Ringue\AppData\Roaming\Mozilla\Firefox\Profiles\lkxhbd8p.default\

FF - prefs.js: network.proxy.type - 0

FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\coFFPlgn\components\coFFPlgn.dll

FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\IPSFFPlgn\components\IPSFFPl.dll

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll

FF - plugin: C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll

FF - plugin: C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.1.94\Bin\npSSOAxCtrlForPTLogin.dll

FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Internet Explorer\PPLite\plugin\1.0.1.3117\npplugin2.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

FF - plugin: C:\Program Files (x86)\Tencent\Qzone\npQQPhotoDrawEx.dll

FF - plugin: C:\Program Files (x86)\Tencent\QZoneMusic\2013.10.5.19.52.40\npQzoneMusic.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll

FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll

FF - plugin: C:\Users\Liyun Qiu Ringue\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll

FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

.

---- FIREFOX POLICIES ----

FF - user.js: extentions.y2layers.installId - 509759a6-aa96-40c0-8df2-e4baa795dcea

FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,

FF - user.js: extensions.autoDisableScopes - 14

FF - user.js: security.csp.enable - false

.

============= SERVICES / DRIVERS ===============

.

R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]

R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]

R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 134944]

R2 PPTVService;PPTVService;C:\Windows\System32\svchost.exe -k PPTVServiceGroup [2009-7-13 27136]

R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-24 56344]

R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2010-11-24 852256]

R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-24 346144]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S3 FlyUsb;FLY Fusion;C:\Windows\System32\drivers\FlyUsb.sys [2011-11-12 24576]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-22 1493352]

S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-12 111616]

S3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2010-5-7 30304]

S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-17 351136]

S3 LVUVC64;Logitech HD Webcam C310(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-17 4865568]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-7 59392]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-12 1255736]

S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-24 203264]

S4 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-6-12 400368]

S4 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-4-27 48488]

S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-24 13336]

S4 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2010-5-7 197976]

S4 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-11-24 635416]

S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]

S4 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]

S4 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-24 2320920]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2013-12-26 07:09:26 10315576 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AD5CB8E9-B0BC-41F2-8EFE-989EA70E2979}\mpengine.dll

2013-12-25 00:05:23 -------- d-----r- C:\Users\Liyun Qiu Ringue\Dropbox

2013-12-25 00:03:12 -------- d-----w- C:\Users\Liyun Qiu Ringue\AppData\Roaming\Dropbox

2013-12-24 23:02:15 10315576 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-12-24 00:29:59 82944 ----a-w- C:\Windows\System32\drivers\ipfltdrv.sys.bak

2013-12-23 23:39:09 -------- d-----w- C:\Users\Liyun Qiu Ringue\AppData\Local\SlimWare Utilities Inc

2013-12-23 23:39:05 -------- d-----w- C:\ProgramData\SlimWare Utilities Inc

2013-12-12 11:03:08 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe

2013-12-12 11:03:08 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe

2013-12-12 11:03:07 12625920 ----a-w- C:\Windows\System32\wmploc.DLL

2013-12-12 11:03:07 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL

2013-12-12 11:02:00 353280 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll

2013-12-12 11:02:00 293072 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll

2013-12-12 11:02:00 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-12-12 11:02:00 2724864 ----a-w- C:\Windows\System32\mshtml.tlb

2013-12-12 11:02:00 270848 ----a-w- C:\Program Files (x86)\Internet Explorer\ieproxy.dll

2013-12-12 11:02:00 251392 ----a-w- C:\Program Files (x86)\Internet Explorer\IEShims.dll

2013-12-12 11:02:00 235216 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll

2013-12-12 06:29:43 335360 ----a-w- C:\Windows\System32\msieftp.dll

2013-12-11 06:21:21 9293192 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2013-12-06 18:28:14 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E20ACCD8-A3C5-4FEB-ABB3-4B88565D01E4}\gapaengine.dll

.

==================== Find3M  ====================

.

2013-12-11 06:21:32 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-12-11 06:21:32 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-11-26 10:18:23 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll

2013-11-26 09:48:07 66048 ----a-w- C:\Windows\System32\iesetup.dll

2013-11-26 09:46:25 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll

2013-11-26 09:18:39 139264 ----a-w- C:\Windows\System32\ieUnatt.exe

2013-11-26 09:18:09 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe

2013-11-26 09:16:57 708608 ----a-w- C:\Windows\System32\jscript9diag.dll

2013-11-26 08:35:02 5769216 ----a-w- C:\Windows\System32\jscript9.dll

2013-11-26 08:28:16 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll

2013-11-26 08:16:12 4243968 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-11-26 08:02:16 1995264 ----a-w- C:\Windows\System32\inetcpl.cpl

2013-11-26 07:32:06 1928192 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2013-11-26 07:07:57 2334208 ----a-w- C:\Windows\System32\wininet.dll

2013-11-26 06:33:33 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-11-23 18:26:20 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll

2013-11-23 17:47:34 465920 ----a-w- C:\Windows\System32\WMPhoto.dll

2013-11-19 10:21:41 267936 ------w- C:\Windows\System32\MpSigStub.exe

2013-11-12 02:23:09 2048 ----a-w- C:\Windows\System32\tzres.dll

2013-11-12 02:07:29 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll

2013-10-30 01:24:31 3155968 ----a-w- C:\Windows\System32\win32k.sys

2013-10-19 02:18:57 81408 ----a-w- C:\Windows\System32\imagehlp.dll

2013-10-19 01:36:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2013-10-12 02:32:04 150016 ----a-w- C:\Windows\System32\wshom.ocx

2013-10-12 02:31:04 202752 ----a-w- C:\Windows\System32\scrrun.dll

2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll

2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL

2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL

2013-10-12 02:04:36 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx

2013-10-12 02:03:31 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll

2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll

2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL

2013-10-12 01:33:39 156160 ----a-w- C:\Windows\System32\cscript.exe

2013-10-12 01:33:26 168960 ----a-w- C:\Windows\System32\wscript.exe

2013-10-12 01:15:48 141824 ----a-w- C:\Windows\SysWow64\wscript.exe

2013-10-12 01:15:48 126976 ----a-w- C:\Windows\SysWow64\cscript.exe

2013-10-05 20:25:35 1474048 ----a-w- C:\Windows\System32\crypt32.dll

2013-10-05 19:57:25 1168384 ----a-w- C:\Windows\SysWow64\crypt32.dll

2013-10-04 02:28:31 190464 ----a-w- C:\Windows\System32\SmartcardCredentialProvider.dll

2013-10-04 02:25:17 197120 ----a-w- C:\Windows\System32\credui.dll

2013-10-04 02:24:49 1930752 ----a-w- C:\Windows\System32\authui.dll

2013-10-04 02:16:30 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys

2013-10-04 01:58:50 152576 ----a-w- C:\Windows\SysWow64\SmartcardCredentialProvider.dll

2013-10-04 01:56:25 168960 ----a-w- C:\Windows\SysWow64\credui.dll

2013-10-04 01:56:00 1796096 ----a-w- C:\Windows\SysWow64\authui.dll

2013-10-04 01:36:04 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys

2013-10-03 02:23:48 404480 ----a-w- C:\Windows\System32\gdi32.dll

2013-10-03 02:00:44 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll

2013-09-28 01:09:10 497152 ----a-w- C:\Windows\System32\drivers\afd.sys

2011-06-27 23:43:18 977784 ----a-w- C:\Program Files (x86)\LockDown.exe

2011-04-20 23:28:46 106496 ----a-w- C:\Program Files (x86)\TaskKeyHook.dll

2007-08-17 00:47:06 51656 ----a-w- C:\Program Files (x86)\RPUPDATE.exe

2007-03-14 10:57:26 348160 ----a-w- C:\Program Files (x86)\msvcr71.dll

2006-05-24 22:13:02 47560 ----a-w- C:\Program Files (x86)\LDBD.exe

.

============= FINISH: 15:36:14.37 ===============

 


.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Home Premium 

Boot Device: \Device\HarddiskVolume1

Install Date: 3/10/2011 4:32:36 PM

System Uptime: 12/25/2013 9:19:32 PM (18 hours ago)

.

Motherboard: MSI |  | 2A9C

Processor: Intel® Core i5 CPU         650  @ 3.20GHz | CPU 1 | 3201/133mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 919 GiB total, 759.181 GiB free.

D: is FIXED (NTFS) - 12 GiB total, 1.218 GiB free.

E: is CDROM ()

F: is Removable

G: is Removable

H: is Removable

I: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP515: 12/15/2013 3:00:12 AM - Windows Update

RP516: 12/18/2013 11:13:32 PM - Windows Update

RP517: 12/22/2013 12:57:08 AM - Windows Update

RP518: 12/23/2013 4:13:08 PM - Removed SlimCleaner Plus

RP519: 12/25/2013 11:08:55 PM - Windows Update

.

==== Installed Programs ======================

.

 Update for Microsoft Office 2007 (KB2508958)

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader X (10.1.7)

Apple Application Support

Apple Mobile Device Support

Apple Software Update

ATI Catalyst Install Manager

Bejeweled 2 Deluxe

Blackhawk Striker 2

Bonjour

Build-a-lot 2

CameraHelperMsi

Catalyst Control Center - Branding

Catalyst Control Center Graphics Previews Common

Catalyst Control Center Graphics Previews Vista

Catalyst Control Center InstallProxy

Catalyst Control Center Localization All

ccc-core-static

ccc-utility64

CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Czech

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Greek

CCC Help Hungarian

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Polish

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCC Help Thai

CCC Help Turkish

CCleaner

Chuzzle Deluxe

CinemaNow Media Manager

Command & Conquer? Red Alert? 3

CyberLink DVD Suite Deluxe

D3DX10

Diner Dash 2 Restaurant Rescue

Dora's Carnival Adventure

Dropbox

DVD Menu Pack for HP MediaSmart Video

erLT

Escape Rosecliff Island

FATE

Final Drive Nitro

Free YouTube to iPod Converter version 3.9.33.426

Full Tilt Poker

Google Chrome

Google Earth Plug-in

Google Update Helper

Heroes of Hellas 2 - Olympia

Hewlett-Packard ACLM.NET v1.2.1.1

HP Customer Experience Enhancements

HP Games

HP MediaSmart CinemaNow 2.0

HP MediaSmart DVD

HP MediaSmart Music

HP MediaSmart Photo

HP MediaSmart SmartMenu

HP MediaSmart Video

HP MediaSmart/TouchSmart Netflix

HP Odometer

HP Setup

HP Support Assistant

HP Support Information

HP Update

HP Vision Hardware Diagnostics

Hulu Desktop

HydraVision

iCloud

Intel® Management Engine Components

Intel® Rapid Storage Technology

iTunes

Java 7 Update 25

Java Auto Updater

Java 7 Update 4 (64-bit)

Jewel Quest 3

Jewel Quest Solitaire 2

Junk Mail filter update

Kobo

LabelPrint

LeapFrog Connect

LeapFrog Tag Plugin

LightScribe System Software

Logitech Vid HD

Logitech Webcam Software

LWS Facebook

LWS Gallery

LWS Help_main

LWS Launcher

LWS Motion Detection

LWS Pictures And Video

LWS Twitter

LWS Video Mask Maker

LWS VideoEffects

LWS Webcam Software

LWS WLM Plugin

LWS YouTube Plugin

MapleStory

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 4 Client Profile

Microsoft Application Error Reporting

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office 2010

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office Office 64-bit Components 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook Connector

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared 64-bit MUI (English) 2007

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft OpenType Font File Properties Extension

Microsoft Security Client

Microsoft Security Essentials

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319

Microsoft WSE 3.0 Runtime

Movie Theme Pack for HP MediaSmart Video

Mozilla Firefox 24.0 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

MSVCRT_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Nexon Game Manager

Origin

Pando Media Booster

PDF Complete Special Edition

PDF Vista 7.02

Penguins!

PhotoNow!

PictureMover

Plants vs. Zombies

PlayReady PC Runtime amd64

Poker Superstars III

Polar Bowler

Polar Golfer

Power2Go

PowerDirector

ppsAddr

PPS影音 V2.7.0.1516 正式版

PPTV V3.3.1.0038

PressReader

QQ游戏

QQ音乐2013

QuickTime

Ralink RT2860 Wireless LAN Card

Realtek High Definition Audio Driver

Recovery Manager

Respondus LockDown Browser

Roxio CinemaNow 2.0

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition 

Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition 

Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition 

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition 

Security Update for Microsoft Office Outlook 2007 (KB2825644) 32-Bit Edition 

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition 

Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition 

Security Update for Microsoft Visual Basic for Applications 6.5 (KB974945)

Skype Click to Call

Skype? 5.10

Unity Web Player

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2473228)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Client Profile (KB2836939)

Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office Infopath 2007 Help (KB963662)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)

Virtual Families

Virtual Villagers - The Secret City

Wheel of Fortune 2

Windows Driver Package - LeapFrog (FlyUsb) USB  (11/05/2008 1.1.1.0)

Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012)

Windows Live Communications Platform

Windows Live Essentials

Windows Live Family Safety

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

WinRAR 4.20 (64 位)

Yontoo 1.10.02

Zinio Reader 4

Zuma Deluxe

华宇拼音输入法V6.9

微博桌面

腾讯QQ2013

.

==== End Of File ===========================

 

Link to post
Share on other sites

Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Please visit this webpage and read the ComboFix User's Guide:

  • Once you've read the article and are ready to use the program you can download it directly from the link below.
  • Important! - Please make sure you save combofix to your desktop and do not run it from your browser
  • Direct download link for: ComboFix.exe
  • Please make sure you disable your security applications before running ComboFix.
  • Once Combofix has completed it will produce and open a log file. Please be patient as it can take some time to load.
  • Please copy/paste the contents or attach that log file to your next reply.
  • If needed the file can be located here: C:\combofix.txt
  • NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.
Link to post
Share on other sites

You will notice that there are some chinese characters (for the section titles only it seems). Sorry about that. My wife has her chinese characters installed so she can type, but I had no idea it was a part of my computer settings somehow. Please let me know if you have any problems reading this log and thanks again for your help. 

 

 

ComboFix 13-12-26.01 - Liyun Qiu Ringue 7/2013 Fri  10:27:02.1.4 - x64

Microsoft Windows 7 Home Premium   6.1.7601.1.936.86.1033.18.8055.5742 [GMT -8:00]

执行位置: c:\users\Liyun Qiu Ringue\Downloads\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((((((((   被删除的档案   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\favoritevideo\InvisibleFolder

c:\favoritevideo\InvisibleFolder\20130506123707_LANCOME%2b15s%2bENG.mp4

c:\favoritevideo\InvisibleFolder\20130506125602_LANCOME%2b15s%2bMAND.mp4

c:\favoritevideo\InvisibleFolder\20130515203308_totalcomfort_480x360.mp4

c:\favoritevideo\InvisibleFolder\20130517164144_37wan130520zhu15sa.mp4

c:\favoritevideo\InvisibleFolder\20130521100235_37wan130521zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130521170400_37wan130521zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130522164811_37wan130522zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130523175906_37wan130523zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130523180043_longjiang2130525qipao2.swf

c:\favoritevideo\InvisibleFolder\20130527182443_37wan130527zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130528165528_37wan130528zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130528204703_e37wan130528zhuhc15s.mp4

c:\favoritevideo\InvisibleFolder\20130529145405_abbottmama_zhuhc480_360.mp4

c:\favoritevideo\InvisibleFolder\20130529175742_37wan130529zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130530181957_37wan130530zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130531175021_Attack_zhuhc_480_360.mp4

c:\favoritevideo\InvisibleFolder\20130531181838_37wan130531zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130531181913_37wan130531zhuhc15sD.mp4

c:\favoritevideo\InvisibleFolder\20130531183325_Blackman_video1_zhuhc_480_360.mp4

c:\favoritevideo\InvisibleFolder\20130603180020_37wan130603zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130603180133_37wan130603zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130604162456_37wan130604zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130606175435_37wan130606zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130607115914_RADIORoll_III130607zhuhc.mp4

c:\favoritevideo\InvisibleFolder\20130607144833_DBS_TAIWAN_zhuhc480_360.mp4

c:\favoritevideo\InvisibleFolder\20130607171336_37wan130607zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130608154958_tj130611qipao2.swf

c:\favoritevideo\InvisibleFolder\20130608172835_37wan130608zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130613104624_zhu_zt.swf

c:\favoritevideo\InvisibleFolder\20130613144535_Narutoexpo_zhuzt400_300.swf

c:\favoritevideo\InvisibleFolder\20130613145346_Narutoexpo_15s_zhuhc480_360.mp4

c:\favoritevideo\InvisibleFolder\20130613181335_37wan130613zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130613181349_37wan130613zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130614155446_jhfy130615_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130614155646_jhfy130615_qipao2.swf

c:\favoritevideo\InvisibleFolder\20130614163356_lieyan130617qipao1.swf

c:\favoritevideo\InvisibleFolder\20130614170433_37wan130614zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130614185533_kanebo_allie_zhuhc480_360.mp4

c:\favoritevideo\InvisibleFolder\20130617164119_37wan130617zhuhuanchong15sa.mp4

c:\favoritevideo\InvisibleFolder\20130617164141_37wan130617zhuhuanchong15sb.mp4

c:\favoritevideo\InvisibleFolder\20130618102734_tj130619qipao1.swf

c:\favoritevideo\InvisibleFolder\20130618172533_37wan130618zhuhc15sA.mp4

c:\favoritevideo\InvisibleFolder\20130618172543_37wan130618zhuhc15sB.mp4

c:\favoritevideo\InvisibleFolder\20130620093132_gjqixia130624_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130620093511_gjqixia130624_qipao2.swf

c:\favoritevideo\InvisibleFolder\20130621164425_tulong130622qipao1.swf

c:\favoritevideo\InvisibleFolder\20130625114507_pptvlogo.jpg

c:\favoritevideo\InvisibleFolder\20130625163108_longjiang2130626qipao_1.swf

c:\favoritevideo\InvisibleFolder\20130626181155_mxqy130627qipao1.swf

c:\favoritevideo\InvisibleFolder\20130627175909_tj130629qipao3.swf

c:\favoritevideo\InvisibleFolder\20130628151657_dpqk130630qipao2.swf

c:\favoritevideo\InvisibleFolder\20130628151721_dpqk130630qipao3.swf

c:\favoritevideo\InvisibleFolder\20130701201955_dacaijue130702_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130703111340_sjsanguo130704qipao1.swf

c:\favoritevideo\InvisibleFolder\20130704171243_dpqk130707qipao1.swf

c:\favoritevideo\InvisibleFolder\20130705134519_zhuhc130704C.swf

c:\favoritevideo\InvisibleFolder\20130710173416_jjsguo130711qipao1.swf

c:\favoritevideo\InvisibleFolder\20130710173536_jjsguo130711qipao2.swf

c:\favoritevideo\InvisibleFolder\20130710173614_jjsguo130711qipao3.swf

c:\favoritevideo\InvisibleFolder\20130711154950_dpqk130712qipao1.swf

c:\favoritevideo\InvisibleFolder\20130711155121_dpqk130712qipao2.swf

c:\favoritevideo\InvisibleFolder\20130711155222_dpqk130712qipao3.swf

c:\favoritevideo\InvisibleFolder\20130711173053_tj130713qipao1.swf

c:\favoritevideo\InvisibleFolder\20130711173208_tj130713qipao2.swf

c:\favoritevideo\InvisibleFolder\20130711173302_tj130713qipao3.swf

c:\favoritevideo\InvisibleFolder\20130711180607_jiangshen1307131qipao1.swf

c:\favoritevideo\InvisibleFolder\20130711181614_jiangshen1307131qipao2.swf

c:\favoritevideo\InvisibleFolder\20130712175906_dacj130714qipao2.swf

c:\favoritevideo\InvisibleFolder\20130712180026_dacj130714ikanhc3.swf

c:\favoritevideo\InvisibleFolder\20130712185848_rxsg130712qipao1.swf

c:\favoritevideo\InvisibleFolder\20130712190044_rxsg130712qipao2.swf

c:\favoritevideo\InvisibleFolder\20130715150127_ds130716qipao1.swf

c:\favoritevideo\InvisibleFolder\20130715150220_ds130716qipao2.swf

c:\favoritevideo\InvisibleFolder\20130719184609_tmst130722_qipao2.swf

c:\favoritevideo\InvisibleFolder\20130724151926_Oguma_480_360zhuhc.flv

c:\favoritevideo\InvisibleFolder\20130731142550_dpqk130731qipao1.swf

c:\favoritevideo\InvisibleFolder\20130801143413_gjqixia130802qipao1.swf

c:\favoritevideo\InvisibleFolder\20130802162320_jjsguo130805qipao3.swf

c:\favoritevideo\InvisibleFolder\20130805165904_kasadi130805zhuhc.flv

c:\favoritevideo\InvisibleFolder\20130806144225_jhfy130807_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130807142959_txj0808qipao1.swf

c:\favoritevideo\InvisibleFolder\20130809151929_xsas130809_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130809181035_nslm130810qipao1.swf

c:\favoritevideo\InvisibleFolder\20130809202239_jiulongcao130812zqiapo1.swf

c:\favoritevideo\InvisibleFolder\20130809204240_shenwujiutian130812qipao1.swf

c:\favoritevideo\InvisibleFolder\20130812150404_tmst130813_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130812155530_lhzs130813qipao1.swf

c:\favoritevideo\InvisibleFolder\20130812161741_by130813_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130813132058_tmst130813_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130813163221_gjqx130814_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130814170616_jdsj130815_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130814180421_gongchengld0815qipao1.swf

c:\favoritevideo\InvisibleFolder\20130815142306_lieyan0816qipao1.swf

c:\favoritevideo\InvisibleFolder\20130815145729_ys0816qipao1.swf

c:\favoritevideo\InvisibleFolder\20130815153600_xxas0817_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130815160131_mjcs0817_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130821163959_lwzy0823_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130822181449_jdsj0825_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130822185314_gcld0825_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130826142018_hstx0826qipao1.swf

c:\favoritevideo\InvisibleFolder\20130828183417_20130828182553_fc.jpg

c:\favoritevideo\InvisibleFolder\20130829162907_swjt0830_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130830091027_lhzs130831qipao1.swf

c:\favoritevideo\InvisibleFolder\20130830102557_txj0901_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130903155940_dousheng0904_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130905091023_xxas0909qipao1.swf

c:\favoritevideo\InvisibleFolder\20130905102410_lj0909_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130910160709_lieyan0911qipao1.swf

c:\favoritevideo\InvisibleFolder\20130911131323_yinyueyazhou130911zhuhc15s.flv

c:\favoritevideo\InvisibleFolder\20130912104639_swjt0913qipao_hw.swf

c:\favoritevideo\InvisibleFolder\20130913152537_ndbg20915_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130913162439_lieyan0915_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130917134347_hw_hstx0918qipaohc1.swf

c:\favoritevideo\InvisibleFolder\20130918170132_sbcs0921qipao1.swf

c:\favoritevideo\InvisibleFolder\20130918170928_qianghun0920_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130918180401_lj20920_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130918190321_swjt0922_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130922153716_ndbg20923_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130922160630_lieyan0923_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130924173139_sjsg0925_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130926182647_wuyi0927_haiwaiqipao1.swf

c:\favoritevideo\InvisibleFolder\20130927144527_genghuanwuyi0927_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130927161349_yzgl0929_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130927190111_dpqk1003_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130929102410_lhzs1003_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130929141525_gjqixia1005qipao1.swf

c:\favoritevideo\InvisibleFolder\20130929145034_0930longjiang2_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130929153111_xxas1006qipao1.swf

c:\favoritevideo\InvisibleFolder\20130930130905_swjt1002qipao1.swf

c:\favoritevideo\InvisibleFolder\20130930133002_sbcs1007qipao1.swf

c:\favoritevideo\InvisibleFolder\20130930134809_longjiang1007_qipao1.swf

c:\favoritevideo\InvisibleFolder\20130930155558_gcld1008qipao1.swf

c:\favoritevideo\InvisibleFolder\20131005101234_ATT_505_60_HSIConcept1_Static.jpg

c:\favoritevideo\InvisibleFolder\20131008151102_sjsg1009_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131010163108_haiwaiwycq1011_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131012142622_sbcs1014qipao1.swf

c:\favoritevideo\InvisibleFolder\20131012144437_lj2_1014qipao1.swf

c:\favoritevideo\InvisibleFolder\20131012153106_gcld1013qipao1.swf

c:\favoritevideo\InvisibleFolder\20131015144834_nslm1016_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131016154356_tgzt1017_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131016163736_ly1017_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131017154310_dntg1018_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131018180419_sbcs1021qipao1.swf

c:\favoritevideo\InvisibleFolder\20131018184850_lj2_1021qipao1.swf

c:\favoritevideo\InvisibleFolder\20131022183617_hstx1023_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131024154029_ly1025_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131024173546_swjt1026_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131024180156_jdsj1026_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131104165051_dntg1105-qipao1.swf

c:\favoritevideo\InvisibleFolder\20131114153710_swjt1115_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131114162310_wy1115_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131115170830_lztx1118-qipao1.swf

c:\favoritevideo\InvisibleFolder\20131118170520_ahxy1119_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131118172858_wycq1109_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131120142229_lhtx1121_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131129150644_dntg1130_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131129183012_zwj1201_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131203113002_lztx1204_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131205173600_wy1206_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131205180503_haiwaiwy1206_qipao1.swf

c:\favoritevideo\InvisibleFolder\20131206185625_tssg1209-qipao1.swf

c:\favoritevideo\InvisibleFolder\20131206191726_gj1209-qipao1.swf

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7116.dll

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7278.dll

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7344.dll

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7354.dll

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7553.dll

c:\favoritevideo\InvisibleFolder\peer_2.4.0.7599.dll

c:\favoritevideo\InvisibleFolder\pptvsetup_3.3.6.0027_s.exe

c:\favoritevideo\InvisibleFolder\pptvsetup_3.3.8.0023_s.exe

c:\favoritevideo\InvisibleFolder\pptvsetup_3.4.0.0071_s.exe

c:\favoritevideo\InvisibleFolder\pptvsetup_3.4.0.0111_s.exe

c:\favoritevideo\InvisibleFolder\tipsbubble_1.1.1.4.dll

c:\favoritevideo\InvisibleFolder\tipsbubble_1.1.1.6.dll

c:\favoritevideo\InvisibleFolder\tipsbubble_1.1.1.7.dll

c:\favoritevideo\InvisibleFolder\tipsbubble_1.1.1.8.dll

c:\favoritevideo\InvisibleFolder\tipsbubble_3.4.0.78.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.4.7.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.4.9.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.5.0.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.5.1.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.5.2.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.5.3.dll

c:\favoritevideo\InvisibleFolder\tipsclient_1.0.5.6.dll

c:\favoritevideo\InvisibleFolder\tipsdone(1.0.0.8).dll

c:\favoritevideo\InvisibleFolder\tipsflash_1.0.0.1.dll

c:\program files (x86)\Common Files\Tencent\Paycenter

c:\program files (x86)\Common Files\Tencent\Paycenter\qqcert.dll

c:\program files (x86)\Common Files\Tencent\Paycenter\qqedit.dll

c:\users\Liyun Qiu Ringue\Favorites\Hao123.url

c:\windows\PFRO.log

c:\windows\SysWow64\kindling.dll

c:\windows\SysWow64\PPTVLauncher.exe

.

.

(((((((((((((((((((((((((  2013-11-27 至 2013-12-27 的新的档案  )))))))))))))))))))))))))))))))

.

.

2013-12-27 18:38 . 2013-12-27 18:38 -------- d-----w- c:\users\User\AppData\Local\temp

2013-12-27 18:38 . 2013-12-27 18:38 -------- d-----w- c:\users\user.Liyun-PC\AppData\Local\temp

2013-12-27 18:38 . 2013-12-27 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-12-27 15:37 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4B498975-8301-4CBA-BC48-C51F180CCD58}\mpengine.dll

2013-12-26 07:09 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-12-25 00:05 . 2013-12-27 18:21 -------- d-----r- c:\users\Liyun Qiu Ringue\Dropbox

2013-12-25 00:03 . 2013-12-27 18:20 -------- d-----w- c:\users\Liyun Qiu Ringue\AppData\Roaming\Dropbox

2013-12-24 00:29 . 2013-12-24 04:00 82944 ----a-w- c:\windows\system32\drivers\ipfltdrv.sys.bak

2013-12-23 23:39 . 2013-12-23 23:39 -------- d-----w- c:\users\Liyun Qiu Ringue\AppData\Local\SlimWare Utilities Inc

2013-12-23 23:39 . 2013-12-23 23:39 -------- d-----w- c:\programdata\SlimWare Utilities Inc

2013-12-12 11:03 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe

2013-12-12 11:03 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe

2013-12-12 11:03 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL

2013-12-12 11:03 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL

2013-12-12 11:03 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll

2013-12-12 11:02 . 2013-11-27 00:52 293072 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2013-12-12 11:02 . 2013-11-27 00:20 235216 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll

2013-12-12 11:02 . 2013-11-26 10:19 2724864 ----a-w- c:\windows\system32\mshtml.tlb

2013-12-12 11:02 . 2013-11-26 09:23 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb

2013-12-12 11:02 . 2013-11-26 06:48 353280 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2013-12-12 11:02 . 2013-11-26 06:41 251392 ----a-w- c:\program files (x86)\Internet Explorer\IEShims.dll

2013-12-12 11:02 . 2013-11-26 06:22 270848 ----a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll

2013-12-12 06:29 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll

2013-12-11 06:21 . 2013-12-11 06:21 9293192 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2013-12-06 18:28 . 2013-10-17 22:37 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E20ACCD8-A3C5-4FEB-ABB3-4B88565D01E4}\gapaengine.dll

2013-12-03 11:03 . 2013-10-15 02:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE

.

.

.

((((((((((((((((((((((((((((((((((((((((   在三个月内被修改的档案   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-12-15 11:00 . 2011-08-19 02:36 90708896 ----a-w- c:\windows\system32\MRT.exe

2013-12-11 06:21 . 2012-04-19 01:53 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-12-11 06:21 . 2011-06-02 07:26 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-11-19 10:21 . 2011-09-07 23:44 267936 ------w- c:\windows\system32\MpSigStub.exe

2013-10-22 01:20 . 2013-10-22 01:20 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin

2013-10-17 22:37 . 2013-06-14 02:14 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2013-10-12 02:30 . 2013-11-12 21:53 830464 ----a-w- c:\windows\system32\nshwfp.dll

2013-10-12 02:29 . 2013-11-12 21:53 859648 ----a-w- c:\windows\system32\IKEEXT.DLL

2013-10-12 02:29 . 2013-11-12 21:53 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL

2013-10-12 02:03 . 2013-11-12 21:53 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll

2013-10-12 02:01 . 2013-11-12 21:53 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL

2013-10-05 20:25 . 2013-11-12 21:53 1474048 ----a-w- c:\windows\system32\crypt32.dll

2013-10-05 19:57 . 2013-11-12 21:53 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll

2013-10-04 02:28 . 2013-11-12 21:53 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll

2013-10-04 02:25 . 2013-11-12 21:53 197120 ----a-w- c:\windows\system32\credui.dll

2013-10-04 02:24 . 2013-11-12 21:53 1930752 ----a-w- c:\windows\system32\authui.dll

2013-10-04 01:58 . 2013-11-12 21:53 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll

2013-10-04 01:56 . 2013-11-12 21:53 168960 ----a-w- c:\windows\SysWow64\credui.dll

2013-10-04 01:56 . 2013-11-12 21:53 1796096 ----a-w- c:\windows\SysWow64\authui.dll

2013-10-03 02:23 . 2013-11-12 21:53 404480 ----a-w- c:\windows\system32\gdi32.dll

2013-10-03 02:00 . 2013-11-12 21:53 311808 ----a-w- c:\windows\SysWow64\gdi32.dll

2011-06-27 23:43 . 2011-08-25 02:15 977784 ----a-w- c:\program files (x86)\LockDown.exe

2011-04-20 23:28 . 2011-08-25 02:15 106496 ----a-w- c:\program files (x86)\TaskKeyHook.dll

2007-08-17 00:47 . 2011-08-25 02:15 51656 ----a-w- c:\program files (x86)\RPUPDATE.exe

2007-03-14 10:57 . 2011-08-25 02:15 348160 ----a-w- c:\program files (x86)\msvcr71.dll

2006-05-24 22:13 . 2011-08-25 02:15 47560 ----a-w- c:\program files (x86)\LDBD.exe

.

.

(((((((((((((((((((((((((((((((((((((   重要登入点   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*注意* 空白与合法缺省登录将不会被显示 

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4BF2CB0E-658A-442B-AC83-A64EC2150BFC}]

2013-03-02 18:34 442248 ----a-w- c:\programdata\PPBrowserHelper\BHO\TipsBHO.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7DCCDF95-9CCC-4312-0D4E-6BE551BA6789}]

2012-12-14 03:09 1189848 ----a-w- c:\program files (x86)\ppsaddr\{7DCCDF95-9CCC-4312-0D4E-6BE551BA6789}\AddressBar.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]

2011-12-09 01:11 194848 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2013-09-11 02:09 131248 ----a-w- c:\users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2013-09-11 02:09 131248 ----a-w- c:\users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2013-09-11 02:09 131248 ----a-w- c:\users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"PPS Accelerator"="d:\pps.tv\PPStream\PPSKernel.exe" [2013-01-23 3682168]

.

c:\users\Liyun Qiu Ringue\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Liyun Qiu Ringue\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-12-17 30714312]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804]

   Ime File REG_SZ         UNISPIM6.IME

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R1 rdfbeecr;rdfbeecr;c:\windows\system32\drivers\rdfbeecr.sys;c:\windows\SYSNATIVE\drivers\rdfbeecr.sys [x]

R1 wzkbqfjl;wzkbqfjl;c:\windows\system32\drivers\wzkbqfjl.sys;c:\windows\SYSNATIVE\drivers\wzkbqfjl.sys [x]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 PPTVService;PPTVService;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]

R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]

R3 FlyUsb;FLY Fusion;c:\windows\system32\DRIVERS\FlyUsb.sys;c:\windows\SYSNATIVE\DRIVERS\FlyUsb.sys [x]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]

R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]

R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]

R3 LVUVC64;Logitech HD Webcam C310(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

R4 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [x]

R4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]

R4 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [x]

R4 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]

R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R4 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]

R4 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]

S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]

S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

PPTVServiceGroup REG_MULTI_SZ   PPTVService

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-12-05 17:27 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe

.

 ‘计划任务’ 文件夹 里的内容

.

2013-12-27 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 06:21]

.

2013-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 05:01]

.

2013-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 05:01]

.

2013-12-27 c:\windows\Tasks\HPCeeScheduleForLiyun Qiu Ringue.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"NCPluginUpdater"="c:\program files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2013-12-13 21720]

.

------- 而外的扫描 -------

.


uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: Free YouTube to iPod Converter - c:\users\Liyun Qiu Ringue\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\users\Liyun Qiu Ringue\AppData\Roaming\Mozilla\Firefox\Profiles\lkxhbd8p.default\

FF - prefs.js: network.proxy.type - 0

FF - user.js: extentions.y2layers.installId - 509759a6-aa96-40c0-8df2-e4baa795dcea

FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,

FF - user.js: extensions.autoDisableScopes - 14

FF - user.js: security.csp.enable - false

.

- - - - ORPHANS REMOVED - - - -

.

SafeBoot-QQPCRTP

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)

ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)

ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)

ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)

AddRemove-{037524F1-D279-4FD5-A5DE-19B241F4ED4E} - c:\programdata\{065E61A5-8EBF-4FD0-B4F4-9E3DC8089AD0}\UMPSetup.exe

AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]

"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-3391680156-2608931035-1395739760-1001\Software\SecuROM\License information*]

"datasecu"=hex:ac,1f,93,02,1b,55,88,32,43,a9,58,a6,a7,87,16,69,ab,9b,22,24,13,

   ff,00,56,85,c2,ea,78,e7,d6,7d,c4,08,32,55,42,bd,88,56,dd,b9,e9,59,99,d9,09,\

"rkeysecu"=hex:f4,11,74,ca,36,d9,ab,b2,1b,97,6d,bc,49,67,31,17

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Q*Q*8nb]

"DisplayName"="QQ游戏"

"UninstallString"="c:\\Program Files (x86)\\Tencent\\QQGame\\Uninstall.EXE"

"Publisher"="腾讯公司"

"DisplayIcon"="c:\\Program Files (x86)\\Tencent\\QQGame\\QQGame.EXE"

"DisplayVersion"="3.1.101.31"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

完成时间: 2013-12-27  10:44:17

ComboFix-quarantined-files.txt  2013-12-27 18:44

.

Pre-Run: 815,284,613,120 bytes free

Post-Run: 819,615,592,448 bytes free

.

- - End Of File - - E113641AF8DD34DFB61399A191C09A27
Link to post
Share on other sites

Don't worry about them. :)

Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.

    ESET OnlineScan

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.

      Save it to your Desktop.

    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under Scan Settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
Link to post
Share on other sites

Good news, but we still have some work to do.

Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 2

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner\AdwCleaner[s0].txt as well.
Step 3

javaicon.gif Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older versions of Java components and upgrade the application.

Upgrading Java :

Please download JavaRa to your desktop and unzip it to its own folder

  • Run JavaRa.exe, then click Remove JRE.
  • Run the built-in uninstallers for all copies of java listed
  • Click the Next button
  • Click the Next button again
  • Click the Java Manual Download link
  • A browser window will open with the Java download page
  • Click the Windows Offline (32-bit) or Windows Offline (64-bit) link to download Java (based on your browser type)
  • Run the installer
  • Close JavaRa
  • Step 4

    Please download the Kaspersky Virus Removal Tool from here to your Desktop.

    Double-click the Removal Tool.

    Click the cog in the upper right corner:

    AVPfront.gif

    Select down to and including your main drive.

    Once done please select the Automatic Scan tab and press Start Scan.

    avpsettings.gif

    Allow AVP to delete all infections found.

    Once it has finished select the Report tab.

    Select the Detected threats report from the left and press the Save button.

    Save it to your Desktop and post the contents in your next reply.

    In your next reply, post the following log files:

    • Junkware Removal Tool log
    • AdwCleaner log
    • Kaspersky AVP log
Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.