Академический Документы
Профессиональный Документы
Культура Документы
213830 rash-----
c:\bootf
<DIR>
r--h-d---
c:\MSOCa
<DIR>
---h-d---
d:\Ghost
52
-a-------
32128
-a-----c-
32128
-a-------
<DIR>
-----d---
C:\Progr
-a-------
C:\law.s
09:12:25
<DIR>
-----d---
C:\Docum
09:12:25
<DIR>
--s--d---
C:\Docum
18:41:50
1889988
-a-------
02:31:30
211
--sh-----
C:\boot.ini
2011-07-01 15:22:20 . 2008-04-15 19:00:00
C:\WINDOWS\win.ini
2011-07-01 15:22:20 . 2008-04-15 19:00:00
C:\WINDOWS\system.ini
2011-07-01 15:20:52 . 2009-11-04 16:01:44
ents and Settings\XP\.rainlendar2
2011-07-01 15:20:13 . 2008-04-15 19:00:00
C:\WINDOWS\SYSTEM32\wpa.dbl
2011-07-01 15:20:03 . 2009-07-22 09:12:26
WS\0.log
2011-07-01 15:20:01 . 2009-07-21 18:32:09
C:\WINDOWS\SYSTEM32\FNTCACHE.DAT
2011-07-01 15:19:47 . 2009-07-21 18:37:50
C:\WINDOWS\wiadebug.log
2011-07-01 15:19:45 . 2009-07-21 18:37:50
C:\WINDOWS\wiaservc.log
2011-07-01 15:19:22 . 2009-07-21 18:44:17
C:\WINDOWS\bootstat.dat
2011-07-01 15:17:51 . 2009-07-22 09:11:10
C:\WINDOWS\SchedLgU.Txt
2011-07-01 15:17:48 . 2009-07-22 09:12:25
C:\Documents and Settings\XP\ntuser.ini
2011-07-01 15:17:08 . 2009-07-22 09:12:25
ents and Settings\XP\My Documents
2011-07-01 15:17:08 . 2009-07-22 02:26:04
WS\inf
2011-07-01 15:17:00 . 2009-07-21 18:32:27
C:\WINDOWS\setupapi.log
2011-07-01 15:13:03 . 2010-01-14 15:55:05
s3
2011-07-01 15:12:38 . 2011-07-01 15:12:38
C:\WINDOWS\Wininit.ini
2011-07-01 15:06:19 . 2009-07-21 18:32:33
WS\SYSTEM32\CatRoot2
2011-06-22 15:28:27 . 2009-07-22 02:26:04
WS\SYSTEM32\dllcache
2011-06-22 15:28:22 . 2009-07-22 02:26:04
WS\SYSTEM32\drivers
2011-06-22 15:28:13 . 2009-07-21 18:32:15
C:\WINDOWS\setupact.log
2011-06-21 17:46:10 . 2009-02-24 08:28:02
C:\WINDOWS\SYSTEM32\DRIVERS\wpshelper.sys
2011-06-21 11:13:10 . 2009-07-21 18:35:18
am Files\Common Files\Microsoft Shared
2011-06-21 11:11:36 . 2009-09-09 10:51:27
C:\WINDOWS\SYSTEM32\ssprs.tgz
2011-06-21 11:11:36 . 2009-09-09 10:49:47
C:\WINDOWS\SYSTEM32\lsprst7.tgz
2011-06-21 11:11:36 . 2009-09-09 10:49:47
C:\WINDOWS\SYSTEM32\lsprst7.dll
2011-06-21 11:11:36 . 2009-09-09 10:49:47
C:\WINDOWS\SYSTEM32\servdat.slm
2011-06-21 11:10:51 . 2011-06-21 11:10:51
p
573
-a-------
227
-a-------
<DIR>
2206
0
-----d---
C:\Docum
-a-------a-------
C:\WINDO
415656
-a-------
159
-a-------
48
-a-------
2048
-as------
32528
-a-------
178
--sh-----
<DIR>
r----d---
C:\Docum
<DIR>
---h-d---
C:\WINDO
706657
<DIR>
52
-a-----------d---
C:\EView
-a-------
<DIR>
-----d---
C:\WINDO
<DIR>
r-sh-d-c-
C:\WINDO
<DIR>
-----d---
C:\WINDO
177703
-a-------
167936
-a-------
<DIR>
-----d---
C:\Progr
87
-a-------
355
-a-------
341
-a-------
17
-a-h-----a-------
C:\law.s
================================================================================
{:
[V] [PID: 1040 ] C:\WINDOWS\system32\services.exe [ Microsoft Corporation ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
"command"="SkyTel.EXE" [ Realtek Semiconductor Corp. ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
"command"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.e
xe" [ Google Inc. ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Au
toDetector v2]
"command"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe"
[ Ulead Systems, Inc. ]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"="145"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"HonorAutoRunSetting"="1"
[hku\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"="149"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
PendingFileRenameOperations C:\DOCUME~1\XP\LOCALS~1\Temp\~nsu.tmp\Au_.exe ;DELETE;
C:\DOCUME~1\XP\LOCALS~1\Temp\~nsu.tmp ;DELETE;
================================================================================
A \ X C:
: A AW;W;W
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C41D93B8-0B87-478A-B793-1908EDB2144D
}\Shell\Open\Command]
@=C:\Program Files\Symantec\LiveUpdate\LUCONFIG.EXE
************************* HKCU\SOFTWARE\Classes\CLSID\...\COMMAND ****
.
[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{C41D93B8-0B87-478A-B793-1908EDB2144D}
\Shell\Open\Command]
@=C:\Program Files\Symantec\LiveUpdate\LUCONFIG.EXE
FIREFOX DEFAULT PREFS.JS
"C:\Documents and Settings\XP\Application Data\MOZILLA\FIREFOX\PROFILES\kplf5dje
.default\prefs.js"
user_pref("browser.startup.homepage", "hxxp://tw.yahoo.com/");
user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.18");
************************* FILES SCAN *********************************
[ Mic
Removable
Fixed
Fixed
CDROM
0MB
35625MB
78419MB
0MB
0MB
70009MB
87055MB
4018MB
NTFS
NTFS
UDF
NOTREADY
READY
READY
READY
================================================================================
y: 2011-07-01 15:27:29.73
[/CODE]