[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*U}
\!q餱cTR]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*U}
\!q餱cTR\OpenWithList]
@Class="Shell"
"a"="AVConverterUI.exe"
"MRUList"="a"
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Koei\ NW莤1*1*]
"Order"=hex:08,00,00,00,02,00,00,00,36,03,00,00,01,00,00,00,06,00,00,00,8c,00,
00,00,00,00,00,00,7e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,6c,00,36,\
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Koei\ NW莤g! *Z7_Hr]
"Order"=hex:08,00,00,00,02,00,00,00,16,01,00,00,01,00,00,00,02,00,00,00,82,00,
00,00,00,00,00,00,74,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,62,00,32,\
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Koei\ NW莤i! *Z7_Hr]
"Order"=hex:08,00,00,00,02,00,00,00,2e,03,00,00,01,00,00,00,06,00,00,00,8c,00,
00,00,00,00,00,00,7e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,6c,00,36,\
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\qg?b; NWKNfwm??I*I*]
"Order"=hex:08,00,00,00,02,00,00,00,2e,02,00,00,01,00,00,00,04,00,00,00,74,00,
00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,32,\
[HKEY_USERS\S-1-5-21-2000478354-1897051121-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\鋊*鷘a煃l?浨]
"Order"=hex:08,00,00,00,02,00,00,00,12,02,00,00,01,00,00,00,04,00,00,00,82,00,
00,00,00,00,00,00,74,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,62,00,36,\
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"
.
--------------------- 運行進程下的動態鏈接庫 ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ 其他運行進程 ------------------------
.
c:\program files\Netropa\Multimedia Keyboard\nhksrv.exe
c:\program files\AVPersonal\AVGUARD.EXE
c:\program files\AVPersonal\AVWUPSRV.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\conime.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
完成時間: 2009-02-27 9:57:01 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2009-02-27 01:56:54
Pre-Run: 16,265,117,696 位元組可用
Post-Run: 16,213,782,528 位元組可用
WindowsXP-KB310994-SP2-Home-BootDisk-CHT.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
626 --- E O F --- 2009-02-25 04:03:47