[code]
efix 5.3 20100105.31 - 2010-01-08 16:01:10.76 - ntfs
Windows Vista (TM) Home Basic Service Pack 2 - user
執行位置: C:\Users\user\Desktop\EF2010010531.exe
系統在 2010-01-08 15:58:31.236 重新啟動
* 已建立系統還原點.
提示:
未安裝安全性更新 KB971029
================================================================================
使用者帳戶列表:
Administrator
Guest
user -- Current
自定義刪除腳本報告
MOVE FILE::
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\ゐ雄 Internet Explorer 銡擬ん.lnk
c:\Program Files\JlingK\DeskMate.exe
c:\program files\jlingk\deskmate.exe
RESET REG::
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MAIN
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MAIN]
MOD REG::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://tw.yahoo.com/"
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo!Mini"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"QvodPlayer"=-
"袤醱藝趙凅"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"袤醱藝趙凅"=-
REBOOT::
================================================================================
EF刪除的檔案列表:
沒有刪除任何檔案.
================================================================================
EF修改的登錄值列表:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://tw.yahoo.com/"
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo!Mini"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"QvodPlayer"=-
"袤醱藝趙凅"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"袤醱藝趙凅"=-
================================================================================
各磁碟根目錄含有隱藏屬性的資料夾和檔案 :
2008-08-09 07:41:32 . 2009-04-11 01:36:36 arhs--- 333257 C:\bootmgr
2008-08-09 07:41:32 . 2009-09-20 18:54:57 --hs---
C:\Boot
2006-11-02 07:59:44 . 2006-11-02 07:59:44 --hs--- C:\Documents and Settings
2009-03-01 10:22:07 . 2009-03-01 10:22:07 -rh---- C:\MSOCache
2006-11-02 06:18:33 . 2010-01-06 01:53:27 --h---- C:\ProgramData
2009-06-28 00:49:20 . 2009-06-28 00:50:32 --hs--- D:\GVODCache
********** Created 2009-12 -- 2010-01 Files: **********
2010-01-08 15:58:29 . 2010-01-08 15:58:30 ------- C:\Windows\System32\ef_backup
2010-01-08 15:32:40 . 2010-01-08 15:32:41 ------- C:\ComboFix
2010-01-08 12:47:05 . 2010-01-08 12:47:05 ------- C:\Qoobox
2010-01-06 01:52:28 . 2010-01-06 01:52:28 ------- C:\Program Files\Common Files\Apple
2010-01-06 01:52:07 . 2010-01-06 01:52:10 ------- C:\Program Files\Apple Software Update
2009-12-21 02:01:29 . 2010-01-06 00:49:14 a------ 56816 C:\Windows\System32\drivers\avgntflt.sys
2009-12-21 02:01:29 . 2009-03-30 09:33:07 a------ 96104 C:\Windows\System32\drivers\avipbb.sys
2009-12-21 02:01:28 . 2009-05-11 09:12:24 a------ 28520 C:\Windows\System32\drivers\ssmdrv.sys
2009-12-21 02:01:22 . 2009-12-21 02:01:22 ------- C:\Program Files\Avira
2009-12-20 17:48:27 . 2009-12-20 17:48:27 ------- C:\Users\user\AppData\Roaming\Super Rabbit
2009-12-20 17:23:31 . 2009-12-20 17:23:31 ------- C:\Windows\Minidump
2009-12-20 17:19:16 . 2009-12-20 17:19:16 ------- C:\Windows\System32\driver
2009-12-20 17:12:03 . 2009-12-20 17:20:07 ------- C:\Users\user\AppData\Roaming\Kingsoft
2009-12-20 17:10:35 . 2009-12-20 17:10:35 ------- C:\Program Files\kingsoft
2009-12-20 14:11:26 . 2009-11-02 20:42:06 ------- 195456 C:\Windows\System32\MpSigStub.exe
2009-12-20 05:20:16 . 2009-12-20 05:20:16 -rhs--- C:\Windows\System32\Autorun.inf
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo0.0ll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\sysutils.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\p3rlud.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo0.0ll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jwedsfdo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jwedsfdo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\bitkv1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\bitkv0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\amvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\amvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\843wee1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\843wee0.dll
2009-12-20 05:20:15 . 2008-01-20 21:34:42 a------ 134656 C:\Windows\regedit2.com
2009-12-20 05:20:14 . 2008-01-20 21:33:22 a------ 318976 C:\Windows\System32\cmd.com
2009-12-19 03:55:56 . 2009-12-20 03:50:35 a------ 495652 C:\Windows\System32\syskbds.drv
2009-12-16 03:07:07 . 2008-12-11 08:38:22 a------ 159600 C:\Windows\System32\drivers\pctgntdi.sys
2009-12-16 03:06:59 . 2009-04-03 11:18:26 a------ 130936 C:\Windows\System32\drivers\PCTCore.sys
2009-12-16 03:06:59 . 2008-12-18 12:16:56 a------ 73840 C:\Windows\System32\drivers\PCTAppEvent.sys
2009-12-16 03:06:53 . 2008-12-10 11:36:04 a------ 64392 C:\Windows\System32\drivers\pctplsg.sys
2009-12-16 03:06:49 . 2009-12-16 03:06:49 ------- C:\Users\user\AppData\Roaming\PC Tools
2009-12-10 03:08:09 . 2009-12-10 03:08:09 --hs--- C:\Windows\System32\%APPDATA%
2009-12-09 21:22:02 . 2009-08-24 06:36:45 a------ 377344 C:\Windows\System32\winhttp.dll
2009-12-09 21:21:32 . 2009-11-21 01:35:43 a------ 5940736 C:\Windows\System32\mshtml.dll
2009-12-09 21:21:31 . 2009-11-21 01:34:39 a------ 1985536 C:\Windows\System32\iertutil.dll
2009-12-09 21:21:31 . 2009-11-21 01:34:38 a------ 11069952 C:\Windows\System32\ieframe.dll
2009-12-09 21:21:30 . 2009-11-21 01:40:20 a------ 916480 C:\Windows\System32\wininet.dll
2009-12-09 21:21:30 . 2009-11-21 01:40:03 a------ 1208832 C:\Windows\System32\urlmon.dll
2009-12-09 21:21:30 . 2009-11-21 01:38:17 a------ 206848 C:\Windows\System32\occache.dll
2009-12-09 21:21:30 . 2009-11-21 01:35:38 a------ 594432 C:\Windows\System32\msfeeds.dll
2009-12-09 21:21:30 . 2009-11-21 01:35:38 a------ 55296 C:\Windows\System32\msfeedsbs.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:58 a------ 25600 C:\Windows\System32\jsproxy.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 71680 C:\Windows\System32\iesetup.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 164352 C:\Windows\System32\ieui.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 109056 C:\Windows\System32\iesysprep.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:38 a------ 55808 C:\Windows\System32\iernonce.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:38 a------ 184320 C:\Windows\System32\iepeers.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:33 a------ 387584 C:\Windows\System32\iedkcs32.dll
2009-12-09 21:21:30 . 2009-11-20 23:59:58 a------ 133632 C:\Windows\System32\ieUnatt.exe
2009-12-09 21:21:30 . 2009-11-20 23:59:52 a------ 173056 C:\Windows\System32\ie4uinit.exe
2009-12-09 21:21:30 . 2009-11-20 23:59:14 a------ 13312 C:\Windows\System32\msfeedssync.exe
2009-12-09 21:21:04 . 2009-11-03 16:42:10 a------ 30720 C:\Windows\System32\httpapi.dll
2009-12-09 21:21:04 . 2009-11-03 14:41:44 a------ 411648 C:\Windows\System32\drivers\http.sys
2009-12-09 21:21:03 . 2009-11-03 16:43:29 a------ 24064 C:\Windows\System32\nshhttp.dll
2009-12-09 21:20:15 . 2009-10-07 06:36:36 a------ 243712 C:\Windows\System32\rastls.dll
2009-12-09 03:22:50 . 2009-12-09 03:22:50 ------- C:\Users\user\AppData\Roaming\YoudaGames
2009-12-09 03:21:45 . 2009-12-15 23:10:28 ------- C:\Program Files\Oberon Media
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\tavo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\kxvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\kavo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\jvvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\j3ewro.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\amvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\xvassdf.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\weidfsg.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\urretnd.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\uret463.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ubs.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\rttrwq.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\olhrwef.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\kacsde.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ierdfgh.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\huwesa.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\helpme.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ff.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\cvsdfw.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\abs.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\a.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\tt.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\System32\revo.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\System32\ebs.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\rrd.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\rd.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\mg.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\ddr.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\2.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\1.exe
2009-12-08 12:15:30 . 2009-12-16 03:07:18 ------- C:\Program Files\Common Files\PC Tools
.
********** Modified 2009-11 -- 2010-01 files: **********
2010-01-08 15:58:29 . 2010-01-08 15:58:30 ------- C:\Windows\System32\ef_backup
2010-01-08 15:32:40 . 2010-01-08 15:32:41 ------- C:\ComboFix
2010-01-08 12:47:05 . 2010-01-08 12:47:05 ------- C:\Qoobox
2010-01-06 01:52:28 . 2010-01-06 01:52:28 ------- C:\Program Files\Common Files\Apple
2010-01-06 01:52:07 . 2010-01-06 01:52:10 ------- C:\Program Files\Apple Software Update
2009-12-21 02:01:29 . 2010-01-06 00:49:14 a------ 56816 C:\Windows\System32\drivers\avgntflt.sys
2009-12-21 02:01:22 . 2009-12-21 02:01:22 ------- C:\Program Files\Avira
2009-12-20 17:48:27 . 2009-12-20 17:48:27 ------- C:\Users\user\AppData\Roaming\Super Rabbit
2009-12-20 17:23:31 . 2009-12-20 17:23:31 ------- C:\Windows\Minidump
2009-12-20 17:19:16 . 2009-12-20 17:19:16 ------- C:\Windows\System32\driver
2009-12-20 17:12:03 . 2009-12-20 17:20:07 ------- C:\Users\user\AppData\Roaming\Kingsoft
2009-12-20 17:10:35 . 2009-12-20 17:10:35 ------- C:\Program Files\kingsoft
2009-12-20 05:20:16 . 2009-12-20 05:20:16 -rhs--- C:\Windows\System32\Autorun.inf
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo0.0ll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\tavo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\taso.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\sysutils.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\p3rlud.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kxvo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo0.0ll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\kavo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jwedsfdo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jwedsfdo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\jvvo.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\bitkv1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\bitkv0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\amvo1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\amvo0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain0.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\afmain.exe
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\843wee1.dll
2009-12-20 05:20:15 . 2009-12-20 05:20:15 -rhs--- C:\Windows\System32\843wee0.dll
2009-12-19 03:55:56 . 2009-12-20 03:50:35 a------ 495652 C:\Windows\System32\syskbds.drv
2009-12-16 03:06:49 . 2009-12-16 03:06:49 ------- C:\Users\user\AppData\Roaming\PC Tools
2009-12-10 03:08:09 . 2009-12-10 03:08:09 --hs--- C:\Windows\System32\%APPDATA%
2009-12-09 21:21:32 . 2009-11-21 01:35:43 a------ 5940736 C:\Windows\System32\mshtml.dll
2009-12-09 21:21:31 . 2009-11-21 01:34:39 a------ 1985536 C:\Windows\System32\iertutil.dll
2009-12-09 21:21:31 . 2009-11-21 01:34:38 a------ 11069952 C:\Windows\System32\ieframe.dll
2009-12-09 21:21:30 . 2009-11-21 01:40:20 a------ 916480 C:\Windows\System32\wininet.dll
2009-12-09 21:21:30 . 2009-11-21 01:40:03 a------ 1208832 C:\Windows\System32\urlmon.dll
2009-12-09 21:21:30 . 2009-11-21 01:38:17 a------ 206848 C:\Windows\System32\occache.dll
2009-12-09 21:21:30 . 2009-11-21 01:35:38 a------ 594432 C:\Windows\System32\msfeeds.dll
2009-12-09 21:21:30 . 2009-11-21 01:35:38 a------ 55296 C:\Windows\System32\msfeedsbs.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:58 a------ 25600 C:\Windows\System32\jsproxy.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 71680 C:\Windows\System32\iesetup.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 164352 C:\Windows\System32\ieui.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:39 a------ 109056 C:\Windows\System32\iesysprep.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:38 a------ 55808 C:\Windows\System32\iernonce.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:38 a------ 184320 C:\Windows\System32\iepeers.dll
2009-12-09 21:21:30 . 2009-11-21 01:34:33 a------ 387584 C:\Windows\System32\iedkcs32.dll
2009-12-09 21:21:30 . 2009-11-20 23:59:58 a------ 133632 C:\Windows\System32\ieUnatt.exe
2009-12-09 21:21:30 . 2009-11-20 23:59:52 a------ 173056 C:\Windows\System32\ie4uinit.exe
2009-12-09 21:21:30 . 2009-11-20 23:59:14 a------ 13312 C:\Windows\System32\msfeedssync.exe
2009-12-09 03:22:50 . 2009-12-09 03:22:50 ------- C:\Users\user\AppData\Roaming\YoudaGames
2009-12-09 03:21:45 . 2009-12-15 23:10:28 ------- C:\Program Files\Oberon Media
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\tavo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\kxvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\kavo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\jvvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\j3ewro.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 -rhs--- C:\Windows\System32\amvo.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\xvassdf.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\weidfsg.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\urretnd.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\uret463.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ubs.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\rttrwq.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\olhrwef.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\kacsde.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ierdfgh.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\huwesa.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\helpme.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\ff.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\cvsdfw.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\abs.exe
2009-12-08 21:08:43 . 2009-12-20 05:31:54 ------- C:\Windows\System32\a.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\tt.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\System32\revo.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\System32\ebs.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\rrd.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\rd.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\mg.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\ddr.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\2.exe
2009-12-08 21:08:43 . 2009-12-08 21:08:43 ------- C:\Windows\1.exe
2009-12-08 12:15:30 . 2009-12-16 03:07:18 ------- C:\Program Files\Common Files\PC Tools
2009-11-17 02:11:32 . 2009-11-17 02:11:32 ------- C:\Program Files\Windows Portable Devices
2009-10-07 22:57:45 . 2010-01-07 22:13:02 ------- C:\Program Files\Mozilla Firefox
2009-09-14 02:12:52 . 2009-12-15 19:49:28 a------ 10 C:\Windows\popcinfo.dat
2009-07-20 07:23:28 . 2010-01-08 13:02:35 a------ 12 C:\Windows\bthservsdp.dat
2009-05-23 12:24:51 . 2009-12-09 04:05:24 ------- C:\cycgame
2009-05-17 09:23:12 . 2010-01-08 16:01:59 ------- C:\Users\user\AppData\Roaming\Skype
2009-04-23 03:50:37 . 2010-01-07 21:53:56 ------- C:\Users\user\AppData\Roaming\PPStream
2009-03-01 10:25:37 . 2009-12-20 05:20:16 ------- C:\Windows\SHELLNEW
2009-02-27 12:04:06 . 2010-01-06 01:54:48 ------- C:\Program Files\QuickTime
2009-02-19 09:58:38 . 2009-12-20 04:08:51 --hs--- C:\Users\user\AppData\Roaming\.#
2009-02-16 10:10:52 . 2010-01-08 16:01:13 ------- C:\Users\user\Tracing
2009-02-12 06:36:34 . 2010-01-08 15:54:02 -r----- C:\Users\user\Downloads
2009-02-12 06:36:34 . 2010-01-08 15:54:02 -r----- C:\Users\user\Desktop
2009-02-12 06:36:34 . 2009-12-20 18:49:20 ---s--- C:\Users\user\AppData\Roaming\Microsoft
2009-02-12 06:36:34 . 2009-12-13 22:20:46 -r----- C:\Users\user\Documents
2009-02-12 06:36:33 . 2010-01-08 16:01:54 a-hs--- 6291456 C:\Users\user\ntuser.dat
2009-02-12 06:36:33 . 2010-01-07 02:18:02 -r----- C:\Users\user\Favorites
2009-02-12 06:36:33 . 2009-12-14 01:05:39 -r----- C:\Users\user\Music
2009-02-12 06:36:33 . 2009-12-13 03:08:05 -r----- C:\Users\user\Saved Games
2009-02-12 06:36:33 . 2009-12-02 18:50:37 -r----- C:\Users\user\Pictures
2008-08-08 16:37:14 . 2009-12-15 19:51:09 ------- C:\Program Files\Common Files\Oberon Media
2008-08-08 16:37:13 . 2009-12-15 23:10:28 ------- C:\Program Files\Acer GameZone
2008-08-08 16:25:31 . 2010-01-06 09:57:49 ------- C:\Program Files\McAfee
2008-08-08 16:17:57 . 2009-12-09 00:08:22 --h---- C:\Program Files\InstallShield Installation Information
2008-08-08 15:47:45 . 2010-01-06 01:55:10 --hs--- C:\Windows\Installer
2008-08-08 15:42:21 . 2010-01-08 12:43:58 ------- C:\Windows\Prefetch
2008-01-21 00:41:40 . 2009-12-21 00:30:57 a------ 331226 C:\Windows\System32\prfh0404.dat
2008-01-21 00:41:40 . 2009-12-21 00:30:57 a------ 101932 C:\Windows\System32\prfc0404.dat
2008-01-21 00:41:01 . 2009-12-10 03:47:41 ------- C:\Windows\System32\drivers\zh-TW
2007-07-11 20:51:11 . 2010-01-08 15:59:35 ------- C:\Windows\System32
2007-07-11 20:48:01 . 2010-01-08 15:55:41 ------- C:\Windows
2006-11-02 07:53:49 . 2010-01-08 15:59:26 a--s--- 67584 C:\Windows\bootstat.dat
2006-11-02 07:44:53 . 2009-11-11 13:31:11 a------ 381632 C:\Windows\System32\FNTCACHE.DAT
2006-11-02 06:18:44 . 2010-01-08 16:01:04 ------- C:\Windows\Temp
2006-11-02 06:18:44 . 2010-01-06 01:52:56 ------- C:\Windows\winsxs
2006-11-02 06:18:44 . 2009-12-21 01:54:13 ------- C:\Windows\Tasks
2006-11-02 06:18:44 . 2009-12-20 03:50:26 ------- C:\Windows\Web
2006-11-02 06:18:43 . 2010-01-06 01:52:14 ------- C:\Windows\System32\Tasks
2006-11-02 06:18:43 . 2009-12-16 02:47:48 ------- C:\Windows\System32\WDI
2006-11-02 06:18:43 . 2009-12-10 03:47:45 ------- C:\Windows\System32\migration
2006-11-02 06:18:43 . 2009-12-10 03:47:41 ------- C:\Windows\System32\zh-TW
2006-11-02 06:18:43 . 2009-11-17 02:11:31 ------- C:\Windows\System32\wbem
2006-11-02 06:18:43 . 2009-11-17 02:11:29 ------- C:\Windows\System32\uk-UA
2006-11-02 06:18:43 . 2009-11-17 02:11:29 ------- C:\Windows\System32\pt-PT
2006-11-02 06:18:43 . 2009-11-17 02:11:29 ------- C:\Windows\System32\pt-BR
2006-11-02 06:18:43 . 2009-11-17 02:11:29 ------- C:\Windows\System32\pl-PL
2006-11-02 06:18:43 . 2009-11-17 02:11:29 ------- C:\Windows\System32\ko-KR
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\zh-HK
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\tr-TR
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\th-TH
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\sv-SE
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\sr-Latn-CS
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\sl-SI
2006-11-02 06:18:43 . 2009-11-17 02:11:28 ------- C:\Windows\System32\nl-NL
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\zh-CN
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\sk-SK
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\ru-RU
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\ro-RO
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\nb-NO
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\lv-LV
2006-11-02 06:18:43 . 2009-11-17 02:11:27 ------- C:\Windows\System32\lt-LT
2006-11-02 06:18:42 . 2009-12-10 03:47:41 ------- C:\Windows\System32\en-US
2006-11-02 06:18:42 . 2009-11-17 02:11:29 ------- C:\Windows\System32\it-IT
2006-11-02 06:18:42 . 2009-11-17 02:11:29 ------- C:\Windows\System32\he-IL
2006-11-02 06:18:42 . 2009-11-17 02:11:28 ------- C:\Windows\System32\hu-HU
2006-11-02 06:18:42 . 2009-11-17 02:11:28 ------- C:\Windows\System32\hr-HR
2006-11-02 06:18:42 . 2009-11-17 02:11:28 ------- C:\Windows\System32\fr-FR
2006-11-02 06:18:42 . 2009-11-17 02:11:28 ------- C:\Windows\System32\fi-FI
2006-11-02 06:18:42 . 2009-11-17 02:11:28 ------- C:\Windows\System32\el-GR
2006-11-02 06:18:42 . 2009-11-17 02:11:27 ------- C:\Windows\System32\ja-JP
2006-11-02 06:18:42 . 2009-11-17 02:11:27 ------- C:\Windows\System32\et-EE
2006-11-02 06:18:42 . 2009-11-17 02:11:27 ------- C:\Windows\System32\es-ES
2006-11-02 06:18:36 . 2010-01-08 12:16:02 ------- C:\Windows\System32\drivers
2006-11-02 06:18:36 . 2009-12-20 05:37:51 ------- C:\Windows\System32\catroot2
2006-11-02 06:18:36 . 2009-12-10 19:29:09 ------- C:\Windows\rescache
2006-11-02 06:18:36 . 2009-12-10 12:25:16 ------- C:\Windows\System32\catroot
2006-11-02 06:18:36 . 2009-12-09 01:05:11 ------- C:\Windows\System32\drivers\etc
2006-11-02 06:18:36 . 2009-11-17 02:12:33 ------- C:\Windows\System32\drivers\UMDF
2006-11-02 06:18:36 . 2009-11-17 02:11:29 ------- C:\Windows\System32\bg-BG
2006-11-02 06:18:36 . 2009-11-17 02:11:27 ------- C:\Windows\System32\de-DE
2006-11-02 06:18:36 . 2009-11-17 02:11:27 ------- C:\Windows\System32\da-DK
2006-11-02 06:18:36 . 2009-11-17 02:11:27 ------- C:\Windows\System32\cs-CZ
2006-11-02 06:18:36 . 2009-11-17 02:11:27 ------- C:\Windows\System32\ar-SA
2006-11-02 06:18:35 . 2009-12-20 04:16:50 ------- C:\Windows\Logs
2006-11-02 06:18:34 . 2010-01-07 02:22:07 ---s--- C:\Windows\Downloaded Program Files
2006-11-02 06:18:34 . 2009-12-21 03:47:18 ------- C:\Windows\inf
2006-11-02 06:18:34 . 2009-12-21 01:53:18 -r-s--- C:\Windows\assembly
2006-11-02 06:18:34 . 2009-12-20 18:49:19 ------- C:\Windows\AppPatch
2006-11-02 06:18:33 . 2010-01-07 21:32:51 -r----- C:\Program Files
2006-11-02 06:18:33 . 2010-01-06 01:54:50 ------- C:\Program Files\Internet Explorer
2006-11-02 06:18:33 . 2010-01-06 01:53:27 --h---- C:\ProgramData
2006-11-02 06:18:33 . 2010-01-06 01:52:28 ------- C:\Program Files\Common Files
2006-11-02 06:18:33 . 2009-12-20 05:35:09 -r----- C:\Users
2006-11-02 06:18:33 . 2009-12-10 03:47:41 ------- C:\Program Files\Windows Mail
2006-11-02 05:33:01 . 2009-12-21 00:30:57 a------ 590082 C:\Windows\System32\perfh009.dat
2006-11-02 05:33:01 . 2009-12-21 00:30:57 a------ 102094 C:\Windows\System32\perfc009.dat
2006-11-02 05:24:01 . 2009-12-01 15:06:19 a------ 25966024 C:\Windows\System32\mrt.exe
.
================================================================================
執行中的程序:
[PID: 596] C:\Windows\system32\wininit.exe [ Microsoft Corporation]
[PID: 652] C:\Windows\system32\lsm.exe [ Microsoft Corporation]
[PID: 1048] C:\Windows\system32\Ati2evxx.exe [ ATI Technologies Inc.]
[PID: 1268] C:\Windows\system32\SLsvc.exe [ Microsoft Corporation]
[PID: 1600] C:\Windows\system32\Ati2evxx.exe [ ATI Technologies Inc.]
[PID: 1768] C:\Windows\System32\spoolsv.exe [