***continue***
2008-01-02 16:53 . 2006-12-26 21:08 200,704 -----c--- C:\WINDOWS\system32\dllcache\msadox.dll
2008-01-02 16:53 . 2006-12-26 21:08 180,224 -----c--- C:\WINDOWS\system32\dllcache\msadomd.dll
2008-01-02 16:53 . 2006-12-26 21:08 102,400 -----c--- C:\WINDOWS\system32\dllcache\msjro.dll
2008-01-02 16:52 . 2006-12-14 21:45 981,760 -----c--- C:\WINDOWS\system32\dllcache\mfc42u.dll
2008-01-02 16:50 . 2006-12-20 02:17 331,776 -----c--- C:\WINDOWS\system32\dllcache\wiaservc.dll
2008-01-02 16:48 . 2007-01-24 03:30 546,304 -----c--- C:\WINDOWS\system32\dllcache\hhctrl.ocx
2008-01-02 16:46 . 2007-10-26 00:42 8,320,512 --a--c--- C:\WINDOWS\system32\dllcache\shell32.dll
2008-01-02 16:46 . 2006-12-20 05:49 133,632 -----c--- C:\WINDOWS\system32\dllcache\shsvcs.dll
2008-01-02 16:39 . 2006-10-20 09:38 704,512 -----c--- C:\WINDOWS\system32\dllcache\sxs.dll
2008-01-02 16:37 . 2006-10-13 18:23 163,584 -----c--- C:\WINDOWS\system32\dllcache\nwrdr.sys
2008-01-02 16:37 . 2006-10-13 20:36 134,656 -----c--- C:\WINDOWS\system32\dllcache\nwprovau.dll
2008-01-02 16:37 . 2006-10-13 20:36 65,536 -----c--- C:\WINDOWS\system32\dllcache\nwwks.dll
2008-01-02 16:35 . 2007-11-07 17:26 699,904 -----c--- C:\WINDOWS\system32\dllcache\lsasrv.dll
2008-01-02 16:35 . 2006-08-17 20:29 332,288 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-01-02 16:35 . 2006-08-17 20:29 132,096 -----c--- C:\WINDOWS\system32\dllcache\wkssvc.dll
2008-01-02 16:33 . 2006-08-16 17:37 225,664 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-01-02 16:33 . 2006-08-16 19:59 100,352 -----c--- C:\WINDOWS\system32\dllcache\6to4svc.dll
2008-01-02 16:32 . 2006-08-25 23:49 617,472 -----c--- C:\WINDOWS\system32\dllcache\comctl32.dll
2008-01-02 16:27 . 2007-10-11 14:10 1,497,600 -----c--- C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-01-02 16:25 . 2006-08-14 18:34 332,928 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-01-02 16:23 . 2006-06-22 13:06 1,422,336 -----c--- C:\WINDOWS\system32\dllcache\query.dll
2008-01-02 16:23 . 2006-06-22 13:06 69,120 -----c--- C:\WINDOWS\system32\dllcache\ciodm.dll
2008-01-02 16:15 . 2006-06-27 01:41 8,192 -----c--- C:\WINDOWS\system32\dllcache\rasadhlp.dll
2008-01-02 16:11 . 2006-06-27 01:41 148,480 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-01-02 16:11 . 2006-05-19 21:21 109,056 -----c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
.
(((((((((((((((((((((((((((((((((((( 近三個月內更動的檔案 )))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 04:09 --------- d-----w C:\Program Files\UltimateZip 2007
2008-01-07 05:33 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-21 04:10 19,456 ----a-w C:\WINDOWS\system32\drivers\xyiinixj.dat
2007-12-07 03:02 --------- d-----w C:\Documents and Settings\ahwa\Application Data\AdobeUM
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-07 09:26 699,904 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:42 1,269,248 ----a-w C:\WINDOWS\system32\quartz.dll
.
(((((((((((((((((((((((((((((((((((((((((( 重要登錄檔 )))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*注意* 空白或合法的登錄值將不會顯示
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89BA6A94-E207-40A5-B017-272A25CAADBD}]
2001-09-17 20:00 87552 --a------ C:\WINDOWS\system32\dpnwsoc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-11 18:16 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 21:00 79224]
"CJIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.exe" [2007-03-22 19:17 66400]
"PHIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.exe" [2007-03-22 19:17 98656]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 17:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-11 18:16 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2006-02-14 12:00 8704 C:\WINDOWS\system32\PCANotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^「開始」功能表^程式集^啟動^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"RSVP"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
R0 amhebrzp;amhebrzp;C:\WINDOWS\system32\drivers\xyiinixj.dat []
R1 ppmoucls;ppmoucls;C:\WINDOWS\system32\DRIVERS\ppmoucls.sys [2001-07-18 15:07]
R1 pptchpad;PenPower Touchpad;C:\WINDOWS\system32\DRIVERS\pptchpd5.sys [2002-01-02 20:28]
R3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-10-17 19:50]
S3 Arfumftr;Trust RF-Mouse filter driver;C:\WINDOWS\system32\DRIVERS\Arfumftr.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7aaaf358-6b40-11dc-8bfd-001676c54bfe}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac1974d0-ae9e-11dc-8c48-001a70ab63b5}]
\Shell\AutoRun\command - ntdelect.com
\Shell\explore\Command - ntdeIect.com
\Shell\open\Command - ntdeIect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0b80673-f2d0-11db-8b82-001676c54bfe}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f082993c-b9d8-11dc-8c52-001676c54bfe}]
\Shell\AutoRun\command - G:\copetttt.com
\Shell\explore\Command - G:\copetttt.com
\Shell\open\Command - G:\copetttt.com
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-28 17:48:47
Windows 5.1.2600 Service Pack 2 NTFS
掃描隱藏的程序...
掃描隱藏的進程...
掃描隱藏的檔案...
掃描完成
隱藏檔案?: 0
**************************************************************************
.
完成時間?: 2008-01-28 17:49:03