Here's the log... ComboFix 08-10-16.08 - abigailong 2008-10-17 20:48:22.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.950.886.1033.18.78 [GMT 8:00]
執行位置: D:\Documents and Settings\abigailong\Desktop\ComboFix.exe
Command switches used :: D:\Documents and Settings\abigailong\Desktop\CFScript.txt
* 成功創造新還原點
注意 - 這台電腦沒有安裝恢復控制台 !!.
((((((((((((((((((((((((( 2008-09-17 至 2008-10-17 的新的檔案 )))))))))))))))))))))))))))))))
.
2008-10-16 08:01 . 2008-10-16 08:01 262,144 --a------ D:\ntuser.dat
2008-10-08 21:43 . 2008-10-08 21:43 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-08 21:43 . 2008-10-08 21:43 <DIR> d-------- D:\Documents and Settings\abigailong\Application Data\Malwarebytes
2008-10-08 21:42 . 2008-10-08 21:42 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-08 21:42 . 2008-09-10 00:04 38,528 --a------ D:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-08 21:42 . 2008-09-10 00:03 17,200 --a------ D:\WINDOWS\system32\drivers\mbam.sys
2008-10-08 21:41 . 2008-10-08 21:41 <DIR> d-------- D:\Documents and Settings\abigailong\Application Data\SUPERAntiSpyware.com
2008-10-08 21:29 . 2008-10-08 21:29 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-10-08 18:56 . 2008-10-08 18:56 <DIR> dr------- D:\My Pictures
2008-10-07 14:33 . 2003-12-12 16:06 1,693,696 --a------ D:\WINDOWS\system32\ltclr13n.dll
2008-10-07 14:33 . 2003-11-04 15:11 155,648 --a------ D:\WINDOWS\system32\lftif13n.dll
2008-10-07 14:33 . 2003-11-04 15:10 98,304 --a------ D:\WINDOWS\system32\lffax13n.dll
2008-09-23 15:00 . 2008-09-23 15:00 26,800 --ah----- D:\WINDOWS\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-17 13:03 --------- d-----w D:\Documents and Settings\abigailong\Application Data\Skype
2008-10-16 03:14 --------- d-----w D:\Documents and Settings\abigailong\Application Data\Yahoo!
2008-10-16 00:01 --------- d--h--r D:\Documents and Settings\All Users\Application Data\yahoo!
2008-10-08 03:40 --------- d-----w D:\Program Files\Common Files\Ahead
2008-09-15 22:08 --------- d-----w D:\Documents and Settings\abigailong\Application Data\Apple Computer
2008-09-15 21:55 --------- d-----w D:\Program Files\Apple Software Update
2008-09-15 11:57 1,846,016 ----a-w D:\WINDOWS\system32\win32k.sys
2008-09-09 03:30 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-03 23:17 --------- d-----w D:\Documents and Settings\All Users\Application Data\TEMP
2008-08-28 10:04 333,056 ----a-w D:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:38 659,456 ----a-w D:\WINDOWS\system32\wininet.dll
2008-08-14 10:00 2,180,352 ----a-w D:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:22 2,057,728 ----a-w D:\WINDOWS\system32\ntkrnlpa.exe
2008-07-18 14:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 14:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 14:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 14:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 14:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 14:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 14:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 14:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-06-20 03:18 25,976 ----a-w D:\Documents and Settings\abigailong\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-10-16_12.58.24.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-02-28 09:08:48 2,136,064 ------w D:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 09:58:27 2,136,064 ------w D:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 ------w D:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 ------w D:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 ------w D:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:22:14 2,015,744 ------w D:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 ------w D:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 ------w D:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
- 2008-06-23 15:38:28 1,023,488 ----a-w D:\WINDOWS\system32\browseui.dll
+ 2008-08-20 05:38:45 1,023,488 ----a-w D:\WINDOWS\system32\browseui.dll
- 2008-06-23 15:38:29 151,040 ----a-w D:\WINDOWS\system32\cdfview.dll
+ 2008-08-20 05:38:39 151,040 ----a-w D:\WINDOWS\system32\cdfview.dll
- 2008-06-23 15:38:30 1,054,208 ----a-w D:\WINDOWS\system32\danim.dll
+ 2008-08-20 05:38:40 1,054,208 ----a-w D:\WINDOWS\system32\danim.dll
- 2008-06-20 10:44:38 138,368 -c----w D:\WINDOWS\system32\dllcache\afd.sys
+ 2008-08-14 09:51:43 138,368 -c----w D:\WINDOWS\system32\dllcache\afd.sys
- 2008-06-23 15:38:28 1,023,488 -c----w D:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-08-20 05:38:45 1,023,488 -c----w D:\WINDOWS\system32\dllcache\browseui.dll
- 2008-06-23 15:38:29 151,040 -c----w D:\WINDOWS\system32\dllcache\cdfview.dll
+ 2008-08-20 05:38:39 151,040 -c----w D:\WINDOWS\system32\dllcache\cdfview.dll
- 2008-06-23 15:38:30 1,054,208 -c----w D:\WINDOWS\system32\dllcache\danim.dll
+ 2008-08-20 05:38:40 1,054,208 -c----w D:\WINDOWS\system32\dllcache\danim.dll
- 2008-06-23 15:38:30 357,888 -c----w D:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-08-20 05:38:40 357,888 -c----w D:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-06-23 15:38:30 205,312 -c----w D:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-08-20 05:38:40 205,312 -c----w D:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-06-23 15:38:30 55,808 -c----w D:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-08-20 05:38:40 55,808 -c----w D:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-06-23 09:49:29 18,432 -c----w D:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-08-19 09:30:39 18,432 -c----w D:\WINDOWS\system32\dllcache\iedw.exe
- 2008-06-23 15:38:31 251,392 -c----w D:\WINDOWS\system32\dllcache\iepeers.dll
+ 2008-08-20 05:38:41 251,392 -c----w D:\WINDOWS\system32\dllcache\iepeers.dll
- 2008-06-23 15:38:31 96,256 -c----w D:\WINDOWS\system32\dllcache\inseng.dll
+ 2008-08-20 05:38:41 96,256 -c----w D:\WINDOWS\system32\dllcache\inseng.dll
- 2008-06-23 15:38:31 16,384 -c----w D:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-08-20 05:38:44 16,384 -c----w D:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-06-23 15:38:33 3,059,712 -c----w D:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-08-20 05:38:47 3,060,224 -c----w D:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-06-23 15:38:33 449,024 -c----w D:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-08-20 05:38:43 449,024 -c----w D:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-06-23 15:38:33 146,432 -c----w D:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-08-20 05:38:41 146,432 -c----w D:\WINDOWS\system32\dllcache\msrating.dll
- 2008-06-23 15:38:33 532,480 -c----w D:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-08-20 05:38:41 532,480 -c----w D:\WINDOWS\system32\dllcache\mstime.dll
- 2007-02-28 09:08:48 2,136,064 -c----w D:\WINDOWS\system32\dllcache\ntkrnlmp.exe
+ 2008-08-14 09:58:27 2,136,064 -c----w D:\WINDOWS\system32\dllcache\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 -c----w D:\WINDOWS\system32\dllcache\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 -c----w D:\WINDOWS\system32\dllcache\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 -c----w D:\WINDOWS\system32\dllcache\ntkrpamp.exe
+ 2008-08-14 09:22:14 2,015,744 -c----w D:\WINDOWS\system32\dllcache\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 -c----w D:\WINDOWS\system32\dllcache\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 -c----w D:\WINDOWS\system32\dllcache\ntoskrnl.exe
- 2008-06-23 15:38:33 39,424 -c----w D:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-08-20 05:38:41 39,424 -c----w D:\WINDOWS\system32\dllcache\pngfilt.dll
- 2008-06-23 15:38:34 1,494,528 -c----w D:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-08-20 05:38:42 1,494,528 -c----w D:\WINDOWS\system32\dllcache\shdocvw.dll
- 2008-06-23 15:38:34 474,112 -c----w D:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2008-08-20 05:38:44 474,112 -c----w D:\WINDOWS\system32\dllcache\shlwapi.dll
- 2006-08-14 10:34:41 332,928 -c----w D:\WINDOWS\system32\dllcache\srv.sys
+ 2008-08-28 10:04:17 333,056 -c----w D:\WINDOWS\system32\dllcache\srv.sys
- 2008-06-23 15:38:34 615,936 -c----w D:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-08-20 05:38:45 615,936 -c----w D:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-03-19 09:47:00 1,845,248 -c----w D:\WINDOWS\system32\dllcache\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 -c----w D:\WINDOWS\system32\dllcache\win32k.sys
- 2008-06-23 15:38:34 659,456 -c----w D:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-08-20 05:38:43 659,456 -c----w D:\WINDOWS\system32\dllcache\wininet.dll
- 2008-06-20 10:44:38 138,368 ----a-w D:\WINDOWS\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 ----a-w D:\WINDOWS\system32\drivers\afd.sys
- 2008-06-23 15:38:30 357,888 ----a-w D:\WINDOWS\system32\dxtmsft.dll
+ 2008-08-20 05:38:40 357,888 ----a-w D:\WINDOWS\system32\dxtmsft.dll
- 2008-06-23 15:38:30 205,312 ----a-w D:\WINDOWS\system32\dxtrans.dll
+ 2008-08-20 05:38:40 205,312 ----a-w D:\WINDOWS\system32\dxtrans.dll
- 2008-06-23 15:38:30 55,808 ------w D:\WINDOWS\system32\extmgr.dll
+ 2008-08-20 05:38:40 55,808 ------w D:\WINDOWS\system32\extmgr.dll
- 2008-06-27 05:10:23 122,928 ----a-w D:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-17 12:22:58 122,928 ----a-w D:\WINDOWS\system32\FNTCACHE.DAT
- 2008-06-23 15:38:31 251,392 ----a-w D:\WINDOWS\system32\iepeers.dll
+ 2008-08-20 05:38:41 251,392 ----a-w D:\WINDOWS\system32\iepeers.dll
- 2008-06-23 15:38:31 96,256 ----a-w D:\WINDOWS\system32\inseng.dll
+ 2008-08-20 05:38:41 96,256 ----a-w D:\WINDOWS\system32\inseng.dll
- 2008-06-23 15:38:31 16,384 ----a-w D:\WINDOWS\system32\jsproxy.dll
+ 2008-08-20 05:38:44 16,384 ----a-w D:\WINDOWS\system32\jsproxy.dll
- 2008-06-23 15:38:33 3,059,712 ----a-w D:\WINDOWS\system32\mshtml.dll
+ 2008-08-20 05:38:47 3,060,224 ----a-w D:\WINDOWS\system32\mshtml.dll
- 2008-06-23 15:38:33 449,024 ----a-w D:\WINDOWS\system32\mshtmled.dll
+ 2008-08-20 05:38:43 449,024 ----a-w D:\WINDOWS\system32\mshtmled.dll
- 2008-06-23 15:38:33 146,432 ----a-w D:\WINDOWS\system32\msrating.dll
+ 2008-08-20 05:38:41 146,432 ----a-w D:\WINDOWS\system32\msrating.dll
- 2008-06-23 15:38:33 532,480 ----a-w D:\WINDOWS\system32\mstime.dll
+ 2008-08-20 05:38:41 532,480 ----a-w D:\WINDOWS\system32\mstime.dll
- 2008-06-23 15:38:33 39,424 ----a-w D:\WINDOWS\system32\pngfilt.dll
+ 2008-08-20 05:38:41 39,424 ----a-w D:\WINDOWS\system32\pngfilt.dll
- 2008-06-23 15:38:34 1,494,528 ----a-w D:\WINDOWS\system32\shdocvw.dll
+ 2008-08-20 05:38:42 1,494,528 ----a-w D:\WINDOWS\system32\shdocvw.dll
- 2008-06-23 15:38:34 474,112 ----a-w D:\WINDOWS\system32\shlwapi.dll
+ 2008-08-20 05:38:44 474,112 ----a-w D:\WINDOWS\system32\shlwapi.dll
- 2007-07-27 02:41:40 16,760 ------w D:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w D:\WINDOWS\system32\spmsg.dll
- 2008-06-23 15:38:34 615,936 ----a-w D:\WINDOWS\system32\urlmon.dll
+ 2008-08-20 05:38:45 615,936 ----a-w D:\WINDOWS\system32\urlmon.dll
- 2008-07-03 09:14:02 351,744 ----a-w D:\WINDOWS\system32\xpsp3res.dll
+ 2008-08-19 09:20:32 351,744 ----a-w D:\WINDOWS\system32\xpsp3res.dll
+ 2008-10-17 12:55:05 16,384 ----atw D:\WINDOWS\Temp\Perflib_Perfdata_690.dat
.
-- 快照技術重新設置 --
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-06-03 04:56 160496 --a------ D:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.Exe" [2006-06-17 5324584]
"Skype"="D:\Program Files\Skype\Phone\Skype.exe" [2006-07-07 20034600]
"Yahoo! Pager"="D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-07-05 4538368]
"EPSON Stylus CX5500 Series"="D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAP.EXE" [2007-03-01 180736]
"EPSON Stylus CX5500 Series (Copy 1)"="D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAP.EXE" [2007-03-01 180736]
"YSearchProtection"="D:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="D:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="D:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-06-04 126976]
"SynTPEnh"="D:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-06-04 540672]
"AdaptecDirectCD"="D:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-19 684032]
"LiveMonitor"="D:\Program Files\MSI\Live Update 3\LMonitor.exe" [2006-06-08 484352]
"YSearchProtection"="D:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"GWMDMMSG"="GWMDMMSG.exe" [2002-05-07 D:\WINDOWS\GWMDMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-05-25 D:\WINDOWS\system32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-05-25 D:\WINDOWS\system32\atiptaxx.exe]
"Multi-function Keyboard"="GWHotKey.exe" [2001-08-29 D:\WINDOWS\GWHotKey.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="D:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-06-19 54472]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Install Pending Files.LNK - D:\Program Files\SIFXINST\SIFXINST.EXE [2006-03-24 569344]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
SecureDoc.lnk - D:\Program Files\MSI\SecureDoc\Logon.exe [2006-07-27 82944]
Wireless LAN Utility.lnk - D:\WINDOWS\Installer\{BDC88E5A-F47B-4314-AB38-994592E32C95}\NewShortcut1.exe [2006-08-27 40960]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "F:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\msncall.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"D:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\WINDOWS\\system32\\dpvsetup.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 NwSapAgent;SAP Agent;D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 iscFlash;iscFlash;D:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys [ ]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;D:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-03-29 167424]
.
‘計劃任務’ 文件夾 裡的內容
2008-10-17 D:\WINDOWS\Tasks\avast! Antivirus.job
- D:\PROGRA~1\ALWILS~1\Avast4\ashAvast.exe [2008-07-19 22:28]
2008-10-17 D:\WINDOWS\Tasks\Symantec NetDetect.job
- D:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2003-06-19 08:17]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-17 20:57:21
Windows 5.1.2600 Service Pack 2 NTFS
掃描被隱藏的進程。。。 ...
掃描被隱藏的啟動組。。。
掃描被隱藏的文件。。。
掃描完成
被隱藏的檔案: 0
**************************************************************************
.
------------------------ 其他運行進程 ------------------------
.
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\system32\conime.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\WINDOWS\system32\ati2evxx.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
D:\Program Files\corega\WLUSB2GL\SiSWLSvc.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\corega\WLUSB2GL\WlanCU.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
完成時間: 2008-10-17 21:13:50 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2008-10-17 13:13:25
ComboFix2.txt 2008-10-16 05:00:05
Pre-Run: 2,619,138,048 bytes free
Post-Run: 2,630,262,784 bytes free
251 --- E O F --- 2008-10-16 14:38:35