ComboFix 16-11-06.01 - Jason 6/11/10 週四 0:28.1.4 - x64 Microsoft Windows 7 家用進階版 6.1.7601.1.950.886.1028.18.8103.6024 [GMT 8:00] 執行位置: c:\users\Jason\Desktop\ComboFix.exe AV: Avast Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} SP: Avast Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Jason\AppData\Roaming\inst.exe c:\users\Jason\AppData\Roaming\vso_ts_preview.xml c:\windows\iun6002.exe c:\windows\SysWow64\DEBUG.log c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( 驅動/服務 ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . ((((((((((((((((((((((((( 2016-10-09 至 2016-11-09 的新的檔案 ))))))))))))))))))))))))))))))) . . 2016-11-09 16:34 . 2016-11-09 16:34 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-11-09 15:02 . 2016-11-09 15:02 -------- d-----w- c:\users\Jason\AppData\Local\Adobe 2016-10-12 19:26 . 2016-10-12 19:26 -------- d-s---w- c:\windows\SysWow64\Microsoft 2016-10-12 16:55 . 2016-09-12 21:17 77032 ----a-w- c:\windows\system32\CompatTelRunner.exe . . . (((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-11-09 15:46 . 2014-04-04 13:08 141011376 -c--a-w- c:\windows\system32\MRT.exe 2016-11-09 08:55 . 2014-04-04 12:58 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2016-11-09 08:55 . 2014-04-04 12:58 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2016-10-13 19:08 . 2014-04-04 15:08 293352 ----a-w- c:\windows\system32\drivers\aswvmm.sys 2016-10-07 15:12 . 2016-11-09 05:31 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2016-09-22 14:51 . 2014-04-04 13:37 513632 ----a-w- c:\windows\system32\drivers\aswsp.sys 2016-09-13 19:08 . 2014-04-04 13:37 969184 ----a-w- c:\windows\system32\drivers\aswsnx.sys 2016-09-08 19:08 . 2014-04-04 15:16 163416 ----a-w- c:\windows\system32\drivers\aswStm.sys 2016-09-08 19:08 . 2016-09-08 19:08 391496 ----a-w- c:\windows\system32\aswBoot.exe 2016-09-08 19:08 . 2014-04-25 16:24 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2016-09-08 19:08 . 2014-04-04 15:08 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2016-09-08 19:08 . 2014-04-04 13:37 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2016-09-08 19:08 . 2014-04-04 13:37 108816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2016-09-08 19:08 . 2016-09-08 19:08 53208 ----a-w- c:\windows\avastSS.scr 2016-09-08 19:08 . 2016-07-11 19:39 37144 ----a-w- c:\windows\system32\drivers\aswKbd.sys 2016-08-16 17:36 . 2016-09-14 07:23 1009152 ----a-w- c:\windows\system32\user32.dll 2016-08-16 02:48 . 2016-09-14 07:23 833024 ----a-w- c:\windows\SysWow64\user32.dll 2016-08-12 16:46 . 2016-10-12 16:57 2560 ----a-w- c:\windows\apppatch\AcRes.dll 2016-08-12 16:26 . 2016-09-14 07:29 464896 ----a-w- c:\windows\system32\drivers\srv.sys 2016-08-12 16:26 . 2016-09-14 07:29 405504 ----a-w- c:\windows\system32\drivers\srv2.sys 2016-08-12 16:26 . 2016-09-14 07:29 168960 ----a-w- c:\windows\system32\drivers\srvnet.sys . . ((((((((((((((((((((((((((((((((((((( 重要登入點 )))))))))))))))))))))))))))))))))))))))))))))))))) . . *注意* 空白與合法缺省登錄將不會被顯示 REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2016-09-09 67384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2016-11-09 9044392] "WinampAgent"="c:\program files (x86)\Winamp\Winampa.exe" [2002-05-03 12288] "ProductUpdater"="c:\program files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe" [2015-06-17 62464] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00d0404] IME File REG_SZ IMTCC14.IME . R2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service;c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe;c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows 啟用技術服務;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [x] S2 IQ Technology Going Service;IQ Technology Going Service;c:\program files\IQ Technology\Going10\GoingService.exe;c:\program files\IQ Technology\Going10\GoingService.exe [x] S2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 IntcDAud;Intel(R) 顯示器音效;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x] S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . ‘計劃任務’ 文件夾 裡的內容 . 2016-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-04 08:55] . 2016-11-09 c:\windows\Tasks\iToolsDaemon.job - c:\program files (x86)\ThinkSky\iTools 3\iToolsDaemon.exe [2015-08-21 02:23] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2016-09-08 19:08 1031520 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-01-29 171992] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-01-29 399832] "Persistence"="c:\windows\system32\igfxpers.exe" [2014-01-29 442328] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2015-08-26 3113592] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-05-25 500936] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2016-09-09 176440] . ------- 而外的掃描 ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://tw.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: 使用BitSpirit下載(&B) - c:\program files (x86)\BitSpirit\bsurl.htm TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 FF - ProfilePath - c:\users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\benf7c79.default\ FF - prefs.js: browser.search.defaulturl - hxxps://search.avast.com/AV772/search/web?q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Avast Search FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxps://search.avast.com/AV772/search/web?q={searchTerms} . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-AlcoholAutomount - :c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe Wow6432Node-HKLM-Run-ACSW14ZH - :c:\program files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe Wow6432Node-HKLM-Run-IME14 CHT Setup - :c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE Wow6432Node-HKLM-Run-NBAgent - :c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe HKLM-Run-RtHDVCpl - :c:\program files\Realtek\Audio\HDA\RAVCpl64.exe HKLM-Run-IME14 CHT Setup - :c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE HKLM-Run-BCSSync - :c:\program files\Microsoft Office\Office14\BCSSync.exe AddRemove-KKMAN - c:\windows\iun6002.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.032" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.abr" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ani" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.apd" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.bay" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.bw" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cs1" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dcx" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dib" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.djv" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.djvu" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.eps" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.erf" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.fff" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.fpx" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.hdr" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.icl" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.icn" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.iff" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ilbm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.int" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.inta" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.iw4" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jbr" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jfif" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jif" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jpk" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jpx" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.lbm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mef" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mos" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pbm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pbr" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pcd" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pct" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pic" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pict" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pix" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.psp" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pspbrush" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pspimage" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rgb" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rgba" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rle" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rsb" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rwl" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sgi" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.srw" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.thm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ttc" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ttf" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14o\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14o" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14p\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14p" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14pf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14pf" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.wbmp" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xbm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xif" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xmp" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xpm" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0] @Class="Shell" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0\OpenWithList] @Class="Shell" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\*RTX袈GY] @DACL="Unknown ACL Revision 0x04" @SACL=(02 0001) "Order"=hex:08,00,00,00,02,00,00,00,a0,01,00,00,01,00,00,00,02,00,00,00,dc,00, 00,00,00,00,00,00,ce,00,36,00,00,00,00,00,51,45,0c,94,20,00,00,52,54,58,20,\ . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\b*gaR] @DACL="Unknown ACL Revision 0x04" @SACL=(02 0001) "Order"=hex:08,00,00,00,02,00,00,00,f0,00,00,00,01,00,00,00,02,00,00,00,70,00, 00,00,00,00,00,00,62,00,36,00,00,00,00,00,85,44,a1,64,20,00,fa,5e,70,8b,84,\ . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000_Classes\Wow6432Node\CLSID\{130F8154-E804-4BD5-A07B-35BE69039715}\{A730F6F3-255C-417C-8986-2C578500547E}*Hidden] "{2338F5D5-2437-4FC3-9005-A01804321264}"="AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAe67hZYEiZEmHtAqDLjKPhAAAAAACAAAAAAAQZgAAAAEAACAAAAAAM4wJG7KrAQGwcI6H2WK0TvR+8/o/1F0/Kru0R9J3KgAAAAAOgAAAAAIAACAAAAABtLR4dOf4m14Jvdk2qvtMrMxXu5SLKjwL9mPrRbSmuiAAAACjJa46hw69Fo3sVOONAr8yCIm9EabE5zNQM+gJeUbUzEAAAACYG08ZanG1NSgJ+zrMMXLkFuN1MnxWkGEWLefqRZd/xQTwA1Kqb+KxB2iMLHYo59RXvZjK8tZQaasbASPedRQl" . [HKEY_USERS\S-1-5-21-2500281615-2632790571-2034117376-1000_Classes\Wow6432Node\CLSID\{130F8154-E804-4BD5-A07B-35BE69039715}\{A730F6F3-255C-417C-8986-2C578500547E}*Hidden\DeltaClock] "LastSynchronizationClock"=hex(b):90,a8,80,40,bc,08,d4,08 "DeltaClock"=hex(b):49,99,50,02,00,00,00,00 "LastNtpServer"="time.windows.com" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.23" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*0*\DsDriver] "printBinNames"=multi:"\00\00" "printCollate"=hex:00 "printColor"=hex:01 "printDuplexSupported"=hex:00 "printStaplingSupported"=hex:00 "printMaxXExtent"=dword:00000b9a "printMaxYExtent"=dword:000010de "printMinXExtent"=dword:000003d8 "printMinYExtent"=dword:00000771 "printMediaSupported"=multi:"Letter\00Tabloid\00Legal\00Executive\00A3\00A4\00B4 (JIS)\00B5 (JIS)\00Envelope #10\00Envelope Monarch\00\00" "printMediaReady"=multi:"A4\00\00" "printNumberUp"=dword:00000000 "printMemory"=dword:00008000 "printOrientationsSupported"=multi:"PORTRAIT\00LANDSCAPE\00\00" "printMaxResolutionSupported"=dword:000004b0 "printLanguage"=multi:"\00\00" "printRateUnit"="" "driverVersion"=dword:00000401 . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*0*\DsSpooler] "driverName"="Send To Microsoft OneNote 2010 Driver" "portName"=multi:"nul:\00\00" "printStartTime"=dword:00000000 "printEndTime"=dword:00000000 "printerName"="傳送至 OneNote 2010" "printKeepPrintedJobs"=hex:00 "printSpooling"="PrintAfterSpooled" "priority"=dword:00000001 "uNCName"="\\\\Jason-PC\\傳送至 OneNote 2010" "serverName"="Jason-PC" "shortServerName"="JASON-PC" "versionNumber"=dword:00000004 "flags"=dword:00000000 . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\袈?*O*n*e*N*o*t*e* *2*0*1*0*\PrinterDriverData] "InitDriverVersion"=dword:00000600 "Model"="Send To OneNote Driver" "FreeMem"=hex:00,80,00,00 "PrinterDataSize"=dword:00000230 "PrinterData"=hex:00,06,30,02,81,08,00,00,00,f8,ba,01,00,00,00,00,00,00,00,00, 64,00,58,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,c2,ac,90,51,01,\ "FeatureKeywordSize"=dword:00000012 "FeatureKeyword"=hex:4d,65,6d,6f,72,79,00,33,32,37,36,38,4b,42,00,0a,00,00 "Forms?"=dword:5190acc2 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ 其他運行進程 ------------------------ . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\SysWOW64\srvany.exe c:\windows\KMService.exe c:\program files\IQ Technology\Going10\GoImeServer10.exe c:\program files\IQ Technology\Going10\Addon\GoingCommercial.exe c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . 完成時間: 2016-11-10 00:42:32 - 電腦已重新啟動 ComboFix-quarantined-files.txt 2016-11-09 16:42 . Pre-Run: 10,508,460,032 位元組可用 Post-Run: 10,730,369,024 位元組可用 . - - End Of File - - CBBFAAAE978E536643CC73BCF1A4B78C A36C5E4F47E84449FF07ED3517B43A31