system
25
[Files/Folders - Modified Within 30 days]
Documents and Settings → %SystemDrive%\Documents and Settings → [Folder | Modified Date = 1/2/2008 1:39:20 PM | Attr = ]
hiberfil.sys → %SystemDrive%\hiberfil.sys → [Ver = | Size = 528011264 bytes | Modified Date = 1/4/2008 8:29:16 AM | Attr = HS]
Program Files → %ProgramFiles% → [Folder | Modified Date = 1/3/2008 2:30:52 PM | Attr = ]
QooBox → %SystemDrive%\QooBox → [Folder | Modified Date = 1/3/2008 2:21:42 PM | Attr = ]
System Volume Information → %SystemDrive%\System Volume Information → [Folder | Modified Date = 1/2/2008 2:09:40 PM | Attr = HS]
WINDOWS → %SystemRoot% → [Folder | Modified Date = 1/4/2008 8:29:30 AM | Attr = ]
$hf_mig$ → %SystemRoot%$hf_mig$ → [Folder | Modified Date = 12/20/2007 8:20:44 PM | Attr = H ]
$NtUninstallKB941568$ → %SystemRoot%$NtUninstallKB941568$ → [Folder | Modified Date = 12/11/2007 7:18:42 PM | Attr = H ]
$NtUninstallKB941569$ → %SystemRoot%$NtUninstallKB941569$ → [Folder | Modified Date = 12/11/2007 7:19:08 PM | Attr = H ]
$NtUninstallKB942615$ → %SystemRoot%$NtUninstallKB942615$ → [Folder | Modified Date = 12/11/2007 7:18:34 PM | Attr = H ]
$NtUninstallKB942763$ → %SystemRoot%$NtUninstallKB942763$ → [Folder | Modified Date = 12/11/2007 7:19:14 PM | Attr = H ]
$NtUninstallKB942840$ → %SystemRoot%$NtUninstallKB942840$ → [Folder | Modified Date = 12/11/2007 7:20:24 PM | Attr = H ]
$NtUninstallKB944653$ → %SystemRoot%$NtUninstallKB944653$ → [Folder | Modified Date = 12/11/2007 7:18:18 PM | Attr = H ]
$NtUninstallKB946627$ → %SystemRoot%$NtUninstallKB946627$ → [Folder | Modified Date = 12/20/2007 8:21:18 PM | Attr = H ]
bootstat.dat → %SystemRoot%\bootstat.dat → [Ver = | Size = 2048 bytes | Modified Date = 1/4/2008 8:29:18 AM | Attr = S]
Downloaded Program Files → %SystemRoot%\Downloaded Program Files → [Folder | Modified Date = 1/2/2008 9:43:26 AM | Attr = S]
erdnt → %SystemRoot%\erdnt → [Folder | Modified Date = 1/3/2008 2:15:04 PM | Attr = ]
Help → %SystemRoot%\Help → [Folder | Modified Date = 12/11/2007 2:34:22 PM | Attr = ]
imsins.BAK → %SystemRoot%\imsins.BAK → [Ver = | Size = 1393 bytes | Modified Date = 12/11/2007 7:20:26 PM | Attr = ]
inf → %SystemRoot%\inf → [Folder | Modified Date = 12/20/2007 8:21:26 PM | Attr = H ]
Prefetch → %SystemRoot%\Prefetch → [Folder | Modified Date = 1/4/2008 10:08:36 AM | Attr = ]
system.ini → %SystemRoot%\system.ini → [Ver = | Size = 227 bytes | Modified Date = 1/3/2008 2:17:14 PM | Attr = ]
system32 → %System32% → [Folder | Modified Date = 1/3/2008 2:16:42 PM | Attr = ]
Tasks → %SystemRoot%\Tasks → [Folder | Modified Date = 1/3/2008 2:14:44 PM | Attr = S]
Temp → %SystemRoot%\Temp → [Folder | Modified Date = 1/4/2008 8:30:06 AM | Attr = ]
win.ini → %SystemRoot%\win.ini → [Ver = | Size = 800 bytes | Modified Date = 1/2/2008 12:51:04 PM | Attr = ]
SA.DAT → %SystemRoot%\tasks\SA.DAT → [Ver = | Size = 6 bytes | Modified Date = 1/4/2008 8:29:22 AM | Attr = H ]
CatRoot2 → %System32%\CatRoot2 → [Folder | Modified Date = 1/2/2008 9:43:26 AM | Attr = ]
config → %System32%\config → [Folder | Modified Date = 1/3/2008 2:15:16 PM | Attr = ]
CONFIG.NT → %System32%\CONFIG.NT → [Ver = | Size = 2626 bytes | Modified Date = 12/14/2007 9:30:04 AM | Attr = ]
dllcache → %System32%\dllcache → [Folder | Modified Date = 12/11/2007 7:20:26 PM | Attr = RHS]
drivers → %System32%\drivers → [Folder | Modified Date = 1/3/2008 2:17:00 PM | Attr = ]
Restore → %System32%\Restore → [Folder | Modified Date = 1/2/2008 2:09:40 PM | Attr = ]
wpa.dbl → %System32%\wpa.dbl → [Ver = | Size = 1158 bytes | Modified Date = 1/4/2008 8:29:40 AM | Attr = ]
etc → %System32%\drivers\etc → [Folder | Modified Date = 1/3/2008 2:16:58 PM | Attr = ]
[File String Scan - Non-Microsoft Only]
PEC2 , → %SystemDrive%\crash.txt → [Ver = | Size = 866536 bytes | Modified Date = 1/17/2005 11:09:28 PM | Attr = ]
PECompact2 , qoologic , SAHAgent , → %SystemRoot%\LPT$VPN.363 → [Ver = | Size = 12104615 bytes | Modified Date = 1/20/2005 12:35:56 PM | Attr = ]
UPX! , UPX0 , → %SystemRoot%\tsc.exe → Trend Micro Inc. [Ver = 3.9.0.1020 | Size = 170053 bytes | Modified Date = 1/20/2005 12:35:56 PM | Attr = ]
PECompact2 , qoologic , SAHAgent , → %SystemRoot%\VPTNFILE.363 → [Ver = | Size = 12104615 bytes | Modified Date = 1/20/2005 12:35:56 PM | Attr = ]
UPX! , aspack , → %SystemRoot%\vsapi32.dll → Trend Micro Inc. [Ver = 7.000-1004 | Size = 1036800 bytes | Modified Date = 1/20/2005 12:35:56 PM | Attr = ]
WSUD , → %System32%\ALSNDMGR.CPL → Realtek Semiconductor Corp. [Ver = 2.2.0.34 | Size = 16121856 bytes | Modified Date = 9/20/2004 6:20:44 PM | Attr = ]
UPX! , UPX0 , → %System32%\aswBoot.exe → ALWIL Software [Ver = 4, 7, 1098, 0 | Size = 837496 bytes | Modified Date = 12/4/2007 6:04:28 AM | Attr = ]
PEC2 , → %System32%\dfrg.msc → [Ver = | Size = 41397 bytes | Modified Date = 8/29/2002 5:00:00 AM | Attr = ]
PTech , → %System32%\igfxhcsy.lhp → [Ver = | Size = 59914 bytes | Modified Date = 8/20/2004 6:56:24 PM | Attr = ]
Thawte Consulting , → %System32%\rmoc3260.dll → RealNetworks, Inc. [Ver = 6.0.9.2884 | Size = 185688 bytes | Modified Date = 8/2/2007 5:49:12 AM | Attr = ]
UPX! , UPX0 , → %System32%\swreg.exe → SteelWerX [Ver = 2.0.1.11 | Size = 156160 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
UPX! , UPX0 , → %System32%\swsc.exe → SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
winsync , → %System32%\wbdbase.deu → [Ver = | Size = 1309184 bytes | Modified Date = 8/29/2002 5:00:00 AM | Attr = ]
WSUD , UPX0 , → %System32%\dllcache\hwxjpn.dll → [Ver = | Size = 13463552 bytes | Modified Date = 8/29/2002 5:00:00 AM | Attr = ]
PTech , → %System32%\drivers\mtlstrm.sys → Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 10:41:38 PM | Attr = ]
< End of report >