ComboFix 10-05-26.01 - Tom Clinic 7/2010 Thu 9:16.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2039.1414 [GMT -10:00]
Execute location: c:\documents and settings\Tom Clinic\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Tom Clinic\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
FILE ::
"c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe"
"c:\windows\system32\drivers\KAVSafe.sys"
.
((((((((((((((((((((((((((((((((((((((( deleted files )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\kis\log\uplive\kislive_dll.log
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\kis\uplive\addin.dat
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\KXEngine\Data\kwsupd.dat
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\KXEngine\Data\kwsupd.log
c:\program files\Kingsoft
c:\program files\Kingsoft\PowerWord PE\cache\baikedata.dat
c:\program files\Kingsoft\PowerWord PE\cache\netdicdata.dat
c:\program files\Kingsoft\PowerWord PE\cache\spelldata.dat
c:\program files\Kingsoft\PowerWord PE\cache\WikiData.dat
c:\program files\Kingsoft\PowerWord PE\cb_sound.swf
c:\program files\Kingsoft\PowerWord PE\CBDBCoreplus.dll
c:\program files\Kingsoft\PowerWord PE\CBGrabConnect_x64.exe
c:\program files\Kingsoft\PowerWord PE\CBGrabModule_x64.dll
c:\program files\Kingsoft\PowerWord PE\CBGrabProxy.dll
c:\program files\Kingsoft\PowerWord PE\CBParser.dll
c:\program files\Kingsoft\PowerWord PE\CBSelectText.dll
c:\program files\Kingsoft\PowerWord PE\CBSelectText_x64.dll
c:\program files\Kingsoft\PowerWord PE\CBTray.exe
c:\program files\Kingsoft\PowerWord PE\CBUpdate.exe
c:\program files\Kingsoft\PowerWord PE\CBUpdateself.exe
c:\program files\Kingsoft\PowerWord PE\CBux.dll
c:\program files\Kingsoft\PowerWord PE\CibaPopo.dll
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\download\1508ceb890bc0a0c42a2aa8ee426017e.zip
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\unzip\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\download\54d89bfc50c889e58ade5ef6f17fb7ba.zip
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\unzip\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\cibaupdate\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\config\CBSDisList.txt
c:\program files\Kingsoft\PowerWord PE\config\CBSDisList_64.txt
c:\program files\Kingsoft\PowerWord PE\config\Defaultsort.ini
c:\program files\Kingsoft\PowerWord PE\config\GrabOption.ini
c:\program files\Kingsoft\PowerWord PE\CoolWord.exe
c:\program files\Kingsoft\PowerWord PE\coolword\GMAT词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\GRE词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\IELTS词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MBA词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA专业词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA公共词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA词组.txt
c:\program files\Kingsoft\PowerWord PE\coolword\TOFEL词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\大学英语六级词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\大学英语四级词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\成人高考词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\研究生入学考试词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业专科词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业基础词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业本科词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\高中英语词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_back.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_end.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_foremost.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_front.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_latch-down.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_latch-up.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_off.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_setting.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_sound.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_stop.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\lock_bk.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\lockwindow_skin.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\logo.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\resouce.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\skin_bg.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\toolbar_skin.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\word_bg.png
c:\program files\Kingsoft\PowerWord PE\data\ciba_segment.index
c:\program files\Kingsoft\PowerWord PE\data\default.html
c:\program files\Kingsoft\PowerWord PE\data\default_skin
c:\program files\Kingsoft\PowerWord PE\data\dj_sound.swf
c:\program files\Kingsoft\PowerWord PE\data\hanyu.html
c:\program files\Kingsoft\PowerWord PE\data\history_words.js
c:\program files\Kingsoft\PowerWord PE\data\img\17_03.gif
c:\program files\Kingsoft\PowerWord PE\data\img\17_04.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk001.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk002.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk003.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk004.gif
c:\program files\Kingsoft\PowerWord PE\data\img\cbdic_net.gif
c:\program files\Kingsoft\PowerWord PE\data\img\cbdic_new.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dict_name_bk.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dict_name_line.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dj.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dot.gif
c:\program files\Kingsoft\PowerWord PE\data\img\error_tip.gif
c:\program files\Kingsoft\PowerWord PE\data\img\googlelogo.png
c:\program files\Kingsoft\PowerWord PE\data\img\kingsoftlogo.png
c:\program files\Kingsoft\PowerWord PE\data\img\loading.gif
c:\program files\Kingsoft\PowerWord PE\data\img\logo-icon.png
c:\program files\Kingsoft\PowerWord PE\data\img\logo.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_05.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_09.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_18.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\button_alt.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\end_main.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\end_more.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\Grab.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\han_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\mini_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\mini_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\pro_inmages.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\pro_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\qinging_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_config.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_feature_5.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_loaddict.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_mini.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_setdict.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\xzmc_inmages.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\随机.gif
c:\program files\Kingsoft\PowerWord PE\data\img\tag.gif
c:\program files\Kingsoft\PowerWord PE\data\jd_offline_no_found.htm
c:\program files\Kingsoft\PowerWord PE\data\license.txt
c:\program files\Kingsoft\PowerWord PE\data\loading.htm
c:\program files\Kingsoft\PowerWord PE\data\notes.js
c:\program files\Kingsoft\PowerWord PE\data\result_preview.html
c:\program files\Kingsoft\PowerWord PE\data\support.htm
c:\program files\Kingsoft\PowerWord PE\data\wiki_03_special.js
c:\program files\Kingsoft\PowerWord PE\data\xml_replace.ini
c:\program files\Kingsoft\PowerWord PE\DownloadData.dll
c:\program files\Kingsoft\PowerWord PE\filecache.dll
c:\program files\Kingsoft\PowerWord PE\google_service.dll
c:\program files\Kingsoft\PowerWord PE\HotFix.exe
c:\program files\Kingsoft\PowerWord PE\HotKeyControl.dll
c:\program files\Kingsoft\PowerWord PE\index.dll
c:\program files\Kingsoft\PowerWord PE\ksdcallcenter.dll
c:\program files\Kingsoft\PowerWord PE\KSDConfig.dll
c:\program files\Kingsoft\PowerWord PE\KSDIPC.dll
c:\program files\Kingsoft\PowerWord PE\KSDNettools.dll
c:\program files\Kingsoft\PowerWord PE\KSDRepair.exe
c:\program files\Kingsoft\PowerWord PE\KSDStatistic.dll
c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe
c:\program files\Kingsoft\PowerWord PE\localdictmgr.dll
c:\program files\Kingsoft\PowerWord PE\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\NetUtil.dll
c:\program files\Kingsoft\PowerWord PE\newword.dll
c:\program files\Kingsoft\PowerWord PE\Newword.exe
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\1.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\2.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\3.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\4.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\5.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\add.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\bottom.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\browse.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\browse_top.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\card.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\cardright.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\cardsetup.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\changePad.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\checkall.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\combobox_3state.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\config.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\delete.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\delete_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\drop.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\edit.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\edit_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\exam.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\help.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\manage.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\next.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\pre.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\print.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\printsetup.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\radio_inner.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\radio_outter.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\recite.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\reset.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\saveasnew.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\saveasnew_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\scrollword.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\sep.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\shadow.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\shadow2.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\skin.xml
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\starttest.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_next.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_refer.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_repeat.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_report_ok.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_skin.xml
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_sound.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_spell_ok.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\testback.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\top.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\tpl\audio.tpl
c:\program files\Kingsoft\PowerWord PE\NewWordGuide.exe
c:\program files\Kingsoft\PowerWord PE\plugin\baikequery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\baikequery\baikequerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\google\google_service.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\googlequerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\google\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\MulTranslation.dll
c:\program files\Kingsoft\PowerWord PE\plugin\googlequery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\huihuaquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\huihuaquery\huihuaquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\image\default.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\eeaced.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\googlepic.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\hanyingt.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdecmc.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdecyf.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdsyhr.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdxrh.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\wordnet.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\localquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\localquery\localquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\NetDicQuery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netdicquery\netdicquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\netindex.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netindex\netindexdictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\netquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netquery\netquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\situationsentence.dll
c:\program files\Kingsoft\PowerWord PE\plugin\situationsentence\situationsentencedictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\spellsuggest.dll
c:\program files\Kingsoft\PowerWord PE\plugin\spellsuggest\spellsuggestdictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\WikiQuery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\WikiQuery\configure.ini
c:\program files\Kingsoft\PowerWord PE\PowerwordGrab.api
c:\program files\Kingsoft\PowerWord PE\queryprocesscenter.dll
c:\program files\Kingsoft\PowerWord PE\SelectForIE.dll
c:\program files\Kingsoft\PowerWord PE\SelectForOffice.dll
c:\program files\Kingsoft\PowerWord PE\SettingGuide.exe
c:\program files\Kingsoft\PowerWord PE\SettingUI.dll
c:\program files\Kingsoft\PowerWord PE\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\3state_tab.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottomleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottommiddle.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottomright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\button_close_3state.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\close_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\combobox_dropstate.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\conversation.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\dic_guid.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\dict_ico_setting.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\droplist_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\grab_sel_switch.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\GuidePreview.gif
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_fankui.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_language_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_search_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_switch.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_switch02.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_ico_green.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_ico_red.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_sound.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\logo.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\lookup_word.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\main_view.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_bg.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_dict_ico.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down_page-down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down_page-up.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_index_bk.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_index_button_jiantou.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_translate_b_t.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\minimize_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\next_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\previous_button.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\resouce.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\restore_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\restore2.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\Search_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\sentence.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\setting_button_download.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\setting_button_manage.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\sys_menu.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tableback.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\Thumbs.db
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topmiddle.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_bk.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_dropdown_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_guide_ico_sentence.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_sentence_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_sentence_guide_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tree_disable_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tree_enable_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\treeNodeImg.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\vmiddleleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\vmiddleright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_chinese_page_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_dic_guide_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_index_dlg_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_transpage_skin.xml
c:\program files\Kingsoft\PowerWord PE\sqlite3.dll
c:\program files\Kingsoft\PowerWord PE\styles\KSDBlack.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBlack_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBule.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBule_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDDefault.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDDefault_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDGreen.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDGreen_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDRed.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDRed_big.css
c:\program files\Kingsoft\PowerWord PE\TTsCheck.exe
c:\program files\Kingsoft\PowerWord PE\uninst.exe
c:\program files\Kingsoft\PowerWord PE\XDict.exe
c:\program files\Kingsoft\PowerWord PE\XGrab.dll
c:\program files\Kingsoft\PowerWord PE\XGrabDataService.dll
c:\program files\Kingsoft\PowerWord PE\zlib.dll
c:\windows\system32\drivers\KAVSafe.sys
.
((((((((((((((((((((((((((((((((((((((( drivers/services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_KAVSAFE
——-\Legacy_KSDSVC
——-\Service_KAVSafe
——-\Service_KSDSVC
((((((((((((((((((((((((( New files from 2010-04-27 to 2010-05-27 )))))))))))))))))))))))))))))))
.
2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\VS Revo Group
2010-05-26 17:14 . 2009-12-30 22:20 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\program files\VS Revo Group
2010-05-26 08:14 . 2010-05-26 08:19 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\WeatherWatcherLive
2010-05-26 08:13 . 2010-05-26 08:14 ——– d—–w- c:\program files\Weather Watcher Live
2010-05-26 08:13 . 2004-05-27 11:32 102400 —-a-w- c:\windows\system32\unzip32.dll
2010-05-26 07:32 . 2010-05-26 07:32 ——– d—–w- c:\program files\X桌面软件
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Office Genuine Advantage
2010-05-24 07:59 . 2010-05-24 07:59 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Identities
2010-05-24 00:44 . 2009-08-07 05:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-05-24 00:44 . 2009-08-07 05:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-05-23 11:14 . 2010-04-27 15:16 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-23 10:56 . 2001-08-18 08:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-05-23 10:56 . 2008-04-14 15:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-05-23 10:56 . 2008-04-14 10:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-23 10:56 . 2008-04-14 10:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-23 09:30 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-23 09:30 . 2010-05-23 09:30 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-23 09:23 . 2010-05-23 09:23 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Sunbelt Software
2010-05-23 09:22 . 2010-05-23 09:22 ——– dc-h–w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-23 09:22 . 2010-05-23 09:30 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2010-05-23 09:20 . 2010-05-23 09:20 ——– d—–w- c:\program files\Foxit Software
2010-05-23 06:17 . 2010-05-24 17:12 ——– d—–w- c:\documents and settings\Tom Clinic\Tracing
2010-05-23 06:15 . 2010-05-23 06:15 ——– d—–w- c:\program files\Microsoft
2010-05-23 02:40 . 2010-05-23 02:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WEBREG
2010-05-23 02:28 . 2010-05-23 02:28 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:22 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP Product Assistant
2010-05-23 02:19 . 2010-05-23 02:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Hewlett-Packard
2010-05-23 02:18 . 2007-11-08 15:06 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-05-23 02:18 . 2007-10-21 04:25 117760 —-a-w- c:\windows\system32\hpzll5mu.dll
2010-05-23 02:18 . 2007-10-21 04:21 278016 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-23 02:15 . 2008-04-14 10:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-05-23 02:10 . 2010-05-23 02:41 168980 —-a-w- c:\windows\hphins27.dat
2010-05-23 02:10 . 2007-12-13 00:04 787 ——w- c:\windows\hphmdl27.dat
2010-05-22 22:51 . 2010-05-22 22:51 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Tencent
2010-05-22 20:36 . 2010-05-22 20:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Tencent
2010-05-22 19:19 . 2007-04-09 05:23 28552 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-05-22 19:19 . 2007-04-09 05:23 28040 —-a-w- c:\windows\system32\mdimon.dll
2010-05-22 19:18 . 2010-05-22 19:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-05-22 18:21 . 2010-05-22 18:21 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-05-22 13:37 . 2010-05-22 19:04 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WinZip
2010-05-22 13:32 . 2010-05-22 13:32 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\DivX
2010-05-22 13:31 . 2010-05-26 02:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Storm
2010-05-22 13:27 . 2010-05-27 09:55 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-05-22 13:26 . 2010-05-22 13:27 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SolidDocuments
2010-05-22 13:25 . 2010-05-22 13:25 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-05-22 13:25 . 2010-05-27 08:40 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\skypePM
2010-05-22 13:24 . 2010-05-22 13:25 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2010-05-22 13:19 . 2010-05-27 08:41 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Skype
2010-05-22 13:14 . 2010-05-22 13:15 ——– d—–w- c:\program files\Raxco
2010-05-22 13:13 . 2010-05-22 13:13 20 —-a-w- c:\windows\system32\pub_store.dat
2010-05-22 13:07 . 2010-05-22 13:07 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Meitu
2010-05-22 12:33 . 2010-05-22 12:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SogouPY.users
2010-05-22 12:33 . 2010-05-27 19:07 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SogouPY
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-22 11:52 . 2010-05-22 11:52 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Registry Mechanic
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Raxco
2010-05-22 11:24 . 2010-05-22 11:24 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Trillian
2010-05-22 11:16 . 2010-05-23 23:23 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-05-22 11:13 . 2010-05-22 11:13 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Opera
2010-05-22 11:10 . 2010-05-22 11:10 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Avant Profiles
2010-05-22 11:08 . 2010-05-22 11:08 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Fetion
2010-05-22 11:07 . 2010-05-22 11:09 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Fetion
2010-05-22 11:07 . 2010-05-23 06:16 24320 —-a-w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-22 10:19 . 2010-05-22 11:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\RoboForm
2010-05-22 10:09 . 2010-05-22 10:09 0 —-a-w- c:\windows\nsreg.dat
2010-05-22 10:08 . 2010-05-22 10:08 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Mozilla
2010-05-22 09:54 . 2010-05-23 08:40 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\TeamViewer
2010-05-22 09:35 . 2010-05-22 09:35 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol
2010-05-22 09:34 . 2010-05-22 09:34 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Softarium.com
2010-05-22 09:33 . 2010-05-22 09:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\kingsoft
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinic\IECompatCache
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinic\PrivacIE
2010-05-22 09:22 . 2010-05-22 09:22 ——– d-sh–w- c:\documents and settings\Tom Clinic\IETldCache
2010-05-22 09:16 . 2010-05-22 09:27 ——– d—–w- c:\windows\system32\KB905474
2010-05-22 09:15 . 2010-02-25 21:54 11070976 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-05-22 09:15 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-05-22 09:15 . 2010-02-25 06:24 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-05-22 09:15 . 2010-02-25 06:24 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-05-22 09:15 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-22 09:15 . 2010-02-25 06:24 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-05-22 09:00 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2010-05-22 09:00 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2010-05-22 08:59 . 2010-02-24 13:11 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-22 08:55 . 2010-02-17 19:10 2189952 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-22 08:55 . 2010-02-16 14:08 2146304 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-22 08:55 . 2010-02-16 13:25 2024448 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-22 08:53 . 2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-05-22 08:44 . 2010-05-22 14:03 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-05-22 08:44 . 2008-10-10 00:25 69008 —-a-w- c:\windows\system32\zlcomm.dll
2010-05-22 08:44 . 2008-10-10 00:25 106384 —-a-w- c:\windows\system32\zlcommdb.dll
2010-05-22 08:44 . 2008-10-10 00:25 1221008 —-a-w- c:\windows\system32\zpeng25.dll
2010-05-22 08:42 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2010-05-22 08:38 . 2009-01-08 04:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2010-05-22 08:32 . 2010-05-22 08:53 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-22 08:32 . 2010-05-22 08:53 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-22 08:32 . 2010-05-22 09:26 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2010-05-22 08:31 . 2010-05-22 08:31 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-05-22 08:26 . 2008-04-14 10:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-05-22 08:23 . 2005-09-20 17:36 81920 —-a-w- c:\windows\system32\igfxres.dll
2010-05-22 08:20 . 2005-02-23 18:04 192512 ——w- c:\windows\system32\AegisI5.exe
2010-05-22 08:20 . 2005-05-31 18:46 87936 —-a-r- c:\windows\system32\drivers\gtipci21.sys
2010-05-22 08:20 . 2004-03-23 19:45 28672 —-a-r- c:\windows\cttib1.dll
2010-05-22 08:15 . 2005-12-19 19:08 667648 —-a-w- c:\windows\system32\BCMLogon.dll
2010-05-22 08:13 . 2005-07-08 23:19 666 —-a-w- c:\windows\speed.reg
2010-05-22 08:08 . 2010-05-22 08:08 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Novatel Wireless
2010-05-22 08:05 . 2008-04-14 10:15 6272 -c–a-w- c:\windows\system32\dllcache\splitter.sys
2010-05-22 08:05 . 2008-04-14 10:15 6272 —-a-w- c:\windows\system32\drivers\splitter.sys
2010-05-22 08:05 . 2008-04-14 10:47 83072 -c–a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-05-22 08:05 . 2008-04-14 10:47 83072 —-a-w- c:\windows\system32\drivers\wdmaud.sys
2010-05-22 08:05 . 2008-04-14 10:15 52864 -c–a-w- c:\windows\system32\dllcache\dmusic.sys
2010-05-22 08:05 . 2008-04-14 10:15 52864 —-a-w- c:\windows\system32\drivers\DMusic.sys
2010-05-22 08:05 . 2008-04-14 10:15 56576 -c–a-w- c:\windows\system32\dllcache\swmidi.sys
2010-05-22 08:05 . 2008-04-14 10:15 56576 —-a-w- c:\windows\system32\drivers\swmidi.sys
.
(((((((((((((((((((((((((((((((((((((((( Files edited within last three months ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 09:54 . 2010-04-24 20:13 ——– d—–w- c:\program files\CCleaner
2010-05-27 07:48 . 2010-04-24 22:49 ——– d—–w- c:\program files\SogouInput
2010-05-26 21:20 . 2010-05-22 07:53 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-26 16:49 . 2010-04-26 20:46 ——– d—–w- c:\program files\easyMule
2010-05-23 23:22 . 2010-04-26 13:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-23 11:07 . 2010-04-27 07:04 ——– d—–w- c:\program files\nEO iMAGING
2010-05-23 08:41 . 2010-05-23 08:41 537088 —-a-w- c:\documents and settings\Tom Clinic\Application Data\Meitu\KanKan\PlugIns\facedetect\facedetect.dll
2010-05-22 21:59 . 2010-04-24 20:41 ——– d—–w- c:\program files\Trillian
2010-05-22 21:59 . 2010-04-24 21:47 ——– d—–w- c:\program files\ePrompter
2010-05-22 19:19 . 2010-05-22 19:19 7358 —-a-r- c:\documents and settings\Tom Clinic\Application Data\Microsoft\Installer\{C2182670-EEF5-4B1C-822F-66972FFDEAC7}\_69525f90.exe
2010-05-22 18:17 . 2010-05-22 18:17 95744 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit\DAP\SDCondition.dll
2010-05-22 18:17 . 2010-04-25 19:35 ——– d—–w- c:\program files\Startup Faster 2004
2010-05-22 13:29 . 2010-04-24 20:14 ——– d—–w- c:\program files\SpywareBlaster
2010-05-22 11:52 . 2010-04-24 20:09 ——– d—–w- c:\program files\DAP
2010-05-22 08:24 . 2010-04-24 18:14 ——– d—–w- c:\program files\Dell
2010-05-22 08:08 . 2010-04-24 18:14 ——– d—–w- c:\program files\Common Files\Zeepe Framework 7
2010-05-22 07:51 . 2010-05-22 07:51 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-08 03:23 . 2010-04-24 20:37 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-05-05 06:15 . 2010-04-26 13:39 ——– d—–w- c:\program files\SogouExtension
2010-04-27 07:09 . 2010-04-27 07:08 ——– d—–w- c:\program files\Conew
2010-04-27 07:07 . 2010-04-27 07:07 ——– d—–w- c:\program files\Meitu
2010-04-26 19:10 . 2010-04-26 19:06 ——– d—–w- c:\program files\HP
2010-04-26 19:09 . 2010-04-26 19:09 ——– d—–w- c:\program files\Common Files\HP
2010-04-25 06:45 . 2010-04-25 06:45 ——– d—–w- c:\program files\Java
2010-04-25 06:05 . 2010-04-25 06:00 ——– d—–w- c:\program files\StartupFaster
2010-04-25 06:03 . 2010-04-25 06:03 ——– d—–w- c:\program files\Common Files\Java
2010-04-25 05:48 . 2010-04-25 05:47 ——– d—–w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2010-04-25 01:28 . 2010-04-25 01:28 ——– d—–w- c:\program files\YourWare Solutions
2010-04-25 01:12 . 2010-04-25 01:12 ——– d—–w- c:\program files\Microsoft.NET
2010-04-25 00:30 . 2010-04-25 00:30 ——– d—–w- c:\program files\Siber Systems
2010-04-24 23:05 . 2010-04-24 23:05 ——– d—–w- c:\program files\CursorXP
2010-04-24 21:38 . 2010-04-24 21:37 ——– d—–w- c:\program files\Windows Live
2010-04-24 21:38 . 2010-04-24 21:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-04-24 21:33 . 2010-04-24 18:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-24 21:25 . 2010-04-24 21:25 ——– d—–w- c:\program files\Common Files\Windows Live
2010-04-24 21:22 . 2010-04-24 21:22 ——– d—–w- c:\program files\China Mobile
2010-04-24 21:10 . 2010-04-24 21:10 ——– d—–w- c:\program files\Avant Browser
2010-04-24 20:56 . 2010-04-24 20:55 ——– d—–r- c:\program files\Skype
2010-04-24 20:55 . 2010-04-24 20:55 ——– d—–w- c:\program files\Common Files\Skype
2010-04-24 20:51 . 2010-04-24 20:51 ——– d—–w- c:\program files\TeamViewer
2010-04-24 20:23 . 2010-04-24 20:23 ——– d—–w- c:\program files\Lavasoft
2010-04-24 20:20 . 2010-04-24 20:17 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-24 19:57 . 2010-04-24 19:57 ——– d—–w- c:\program files\Idailydiary
2010-04-24 19:49 . 2010-04-24 19:49 ——– d—–w- c:\program files\reliz
2010-04-24 19:44 . 2010-04-24 19:44 ——– d—–w- c:\program files\Common Files\PC Tools
2010-04-24 19:35 . 2010-04-24 19:35 ——– d—–w- c:\program files\Ashampoo
2010-04-24 19:04 . 2010-04-24 19:04 ——– d—–w- c:\program files\Windows Media Connect 2
2010-04-24 18:26 . 2010-04-24 18:26 ——– d—–w- c:\program files\Broadcom
2010-04-24 18:26 . 2010-04-24 18:09 ——– d—–w- c:\program files\Common Files\InstallShield
2010-04-24 18:15 . 2010-04-24 18:15 ——– d—–w- c:\program files\Intel
2010-04-24 18:09 . 2010-04-24 18:09 ——– d—–w- c:\program files\SigmaTel
2010-04-24 18:05 . 2010-04-24 18:05 ——– d—–w- c:\program files\AVG
2010-04-24 17:42 . 2010-04-24 17:42 ——– d—–w- c:\program files\microsoft frontpage
2010-04-24 17:41 . 2010-05-22 09:35 0 —-a-w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol\Config.sys
2010-04-24 17:41 . 2010-05-22 09:35 0 —-a-w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol\Autoexec.bat
2010-04-17 08:12 . 2010-04-17 08:12 48464 —-a-w- c:\windows\system32\sirenacm.dll
2010-03-10 06:15 . 2008-04-14 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-05-26_17.53.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-22 07:58 . 2010-05-26 19:48 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-05-22 07:58 . 2010-05-26 19:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-05-23 09:44 . 2010-05-25 05:42 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-05-23 09:44 . 2010-05-26 19:48 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-05-26 19:48 . 2010-05-26 19:48 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-05-22 07:53 . 2010-05-26 21:20 2850 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
.
((((((((((((((((((((((((((((((((((((( important log in sites ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Attention* some are not shown:
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}]
2010-05-20 09:41 147928 —-a-w- c:\program files\easyMule\modules\IE2EM.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 20:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster 2004\StrpFstCfg.exe" [2005-02-21 2198016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\StartupFaster
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
StartupFaster.ini [2010-5-24 353]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Meitu\\KanKan\\KanKan\\KanKan.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\SogouInput\\5.0.0.3912\\PinyinUp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/21/2010 10:32 PM 52872]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/22/2010 11:30 PM 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/21/2010 10:32 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/21/2010 10:32 PM 242896]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [5/21/2010 10:53 PM 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/21/2010 10:53 PM 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 5:52 AM 1314704]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/26/2010 3:28 AM 304464]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [4/24/2010 9:44 AM 583640]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [5/21/2010 10:20 PM 87936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/22/2010 1:56 AM 20952]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [5/26/2010 7:14 AM 27064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents in ‘Task schedule’ foler
2010-05-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 09:30]
2010-05-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-04 01:07]
2010-05-27 c:\windows\Tasks\SogouImeMgr.job
- c:\progra~1\SOGOUI~1\500~1.391\SGTool.exe [2010-04-27 09:33]
.
.
——- other scan ——-
.
uStart Page = hxxp://www.baidu.com/index.php?tn=avantcn_dg
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Download by easyMule - c:\program files\easyMule\IE2EM.htm
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Logoff - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: 导出到 Microsoft Office Excel(&X) - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-27 09:39
Windows 5.1.2600 Service Pack 3 NTFS
process of scanning hidden files 。。。
scan hidden startup groups 。。。
scan hidden documents 。。。
scan complete
hidden files: 0
**************************************************************************
.
——————— links ———————
- - - - - - - > 'explorer.exe'(1792)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— other processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\conime.exe
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Startup Faster 2004\sfAgent.exe
c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
c:\progra~1\AVG\AVG9\avgtray.exe
c:\program files\reliz\akeys.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Raxco\PerfectDisk10\PDEngine.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Raxco\PerfectDisk10\PDAgentS1.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
complete time: 2010-05-27 09:49:23 - computer reboot
ComboFix-quarantined-files.txt 2010-05-27 19:49
ComboFix2.txt 2010-05-26 17:57
Pre-Run: 223,677,452,288 bytes free
Post-Run: 223,533,522,944 bytes free
- - End Of File - - 5015BC41D2283AF206290AB07CBF9894