************************************************** **********************************
Checking File System for suspicious Files
--------------------------------------------------------------------------
Items in the Root Directory:
--------------------------------------------------------------------------
Locating all files created in H:\
H:\
!KILLBOX Sat 24 Nov 2007 22:57:18 .D... <Dir>
587FBB~1 Sat 18 Nov 2006 19:35:56 .D... <Dir>
A4D986~1 Sat 18 Nov 2006 19:35:48 .D... <Dir>
BJPRIN~1 Mon 18 Sep 2006 10:25:30 .D.H. <Dir>
boot.ini Sun 23 Jul 2006 3:43:46 ..SH. 210 0.20 K
CLONED~1 Mon 31 Jul 2006 14:32:58 .D... <Dir>
DECKARD Tue 20 Nov 2007 6:53:54 .D... <Dir>
DOCUME~1 Sun 23 Jul 2006 3:44:42 .D... <Dir>
ETAX2006 Tue 8 Aug 2006 17:19:34 .D... <Dir>
ETAX2007 Thu 23 Aug 2007 18:12:54 .D... <Dir>
hiberfil.sys Tue 27 Nov 2007 18:15:54 A.SH. 1,609,945,088 1535.36 M
ISEEYO~1 Tue 27 Nov 2007 10:32:24 .D... <Dir>
MSOCACHE Sun 23 Jul 2006 8:44:12 .D.HR <Dir>
ntdetect.com Wed 4 Aug 2004 7:08:34 A.SHR 47,564 46.45 K
ntldr Wed 4 Aug 2004 7:29:34 A.SHR 250,032 244.17 K
pagefile.sys Tue 27 Nov 2007 18:15:54 A.SH. 792,723,456 756.00 M
PROGRA~1 Sun 23 Jul 2006 3:46:26 .D..R <Dir>
RECYCLER Mon 26 Nov 2007 10:14:16 .DSH. <Dir>
S400 Mon 18 Sep 2006 10:20:12 .D... <Dir>
sq13b0~1.sqm Sat 2 Jun 2007 11:48:24 A..H. 244 0.24 K
sq13b4~1.sqm Sat 2 Jun 2007 12:11:08 A..H. 244 0.24 K
sq13b8~1.sqm Mon 20 Aug 2007 8:41:44 A..H. 244 0.24 K
sq13bc~1.sqm Mon 20 Aug 2007 8:42:16 A..H. 244 0.24 K
sq23b0~1.sqm Sat 2 Jun 2007 12:11:30 A..H. 244 0.24 K
sq23b4~1.sqm Sat 16 Jun 2007 17:01:10 A..H. 244 0.24 K
sq23b8~1.sqm Sat 2 Jun 2007 12:11:12 A..H. 244 0.24 K
sq23bc~1.sqm Sat 2 Jun 2007 12:11:28 A..H. 244 0.24 K
sq2fa0~1.sqm Thu 19 Jul 2007 21:32:14 A..H. 244 0.24 K
sq2fa4~1.sqm Thu 19 Jul 2007 21:32:38 A..H. 244 0.24 K
sq2fa8~1.sqm Mon 16 Jul 2007 21:42:16 A..H. 244 0.24 K
sq2fac~1.sqm Tue 17 Jul 2007 20:56:24 A..H. 244 0.24 K
sq33b8~1.sqm Sat 16 Jun 2007 17:01:12 A..H. 244 0.24 K
sq33bc~1.sqm Sat 16 Jun 2007 17:01:20 A..H. 244 0.24 K
sq3fa8~1.sqm Fri 20 Jul 2007 18:00:00 A..H. 244 0.24 K
sq3fac~1.sqm Fri 20 Jul 2007 19:34:40 A..H. 244 0.24 K
sqa368~1.sqm Mon 20 Aug 2007 8:41:46 A..H. 232 0.23 K
sqa378~1.sqm Sat 2 Jun 2007 12:11:12 A..H. 232 0.23 K
sqa37a~1.sqm Mon 16 Jul 2007 21:42:16 A..H. 232 0.23 K
sqa388~1.sqm Sat 16 Jun 2007 17:01:12 A..H. 232 0.23 K
sqa38a~1.sqm Fri 20 Jul 2007 18:00:00 A..H. 232 0.23 K
sqa768~1.sqm Mon 20 Aug 2007 8:42:16 A..H. 232 0.23 K
sqa778~1.sqm Sat 2 Jun 2007 12:11:28 A..H. 232 0.23 K
sqa77a~1.sqm Tue 17 Jul 2007 20:56:24 A..H. 232 0.23 K
sqa788~1.sqm Sat 16 Jun 2007 17:01:20 A..H. 232 0.23 K
sqa78a~1.sqm Fri 20 Jul 2007 19:34:40 A..H. 232 0.23 K
sqab68~1.sqm Sat 2 Jun 2007 11:48:24 A..H. 232 0.23 K
sqab78~1.sqm Sat 2 Jun 2007 12:11:30 A..H. 232 0.23 K
sqab7a~1.sqm Thu 19 Jul 2007 21:32:14 A..H. 232 0.23 K
sqaf68~1.sqm Sat 2 Jun 2007 12:11:08 A..H. 232 0.23 K
sqaf78~1.sqm Sat 16 Jun 2007 17:01:10 A..H. 232 0.23 K
sqaf7a~1.sqm Thu 19 Jul 2007 21:32:38 A..H. 232 0.23 K
sqmdat~1.sqm Sun 1 Jul 2007 22:50:22 A..H. 232 0.23 K
sqmdat~2.sqm Mon 2 Jul 2007 21:00:22 A..H. 268 0.26 K
sqmdat~3.sqm Mon 2 Jul 2007 21:00:22 A..H. 136 0.13 K
sqmdat~4.sqm Mon 2 Jul 2007 21:00:22 A..H. 160 0.16 K
sqmnoo~1.sqm Sun 1 Jul 2007 22:50:22 A..H. 244 0.24 K
sqmnoo~2.sqm Mon 2 Jul 2007 21:00:22 A..H. 244 0.24 K
sqmnoo~3.sqm Mon 2 Jul 2007 21:00:22 A..H. 244 0.24 K
sqmnoo~4.sqm Mon 2 Jul 2007 21:00:22 A..H. 172 0.17 K
STUDIO~1 Sun 7 Oct 2007 21:35:30 .D... <Dir>
SYSTEM~1 Sun 23 Jul 2006 3:44:42 .DSH. <Dir>
VIDEO Sun 23 Jul 2006 8:21:18 .D... <Dir>
WINDOWS Sun 23 Jul 2006 3:39:52 .D... <Dir>
63 items found: 45 files (45 H/S), 18 directories (4 H/S).
Total of file sizes: 2,402,975,666 bytes 2.23 G
--------------------------------------------------------------------------
Locating all Backup files on H:
--------------------------------------------------------------------------
Locating all *.BAK* files
H:\ETAX2006\
damian~1.bak Tue 29 Aug 2006 19:21:12 A.... 3,168 3.09 K
H:\ETAX2007\
damian.bak Thu 23 Aug 2007 18:53:14 A.... 2,880 2.81 K
damian07.bak Fri 24 Aug 2007 14:14:20 A.... 3,008 2.94 K
H:\STUDIO~1\
slddin~1.bak Sun 28 Oct 2007 0:18:16 A.... 5,016 4.90 K
H:\PROGRA~1\STUDIO~1\
relaxi~1.bak Sun 28 Oct 2007 0:18:16 A.... 931 0.91 K
H:\PROGRA~1\COMMON~1\SYMANT~1\
firewall.bak Sat 5 May 2007 19:23:32 A.... 46,516 45.43 K
persist.bak Thu 22 Nov 2007 12:14:46 A.... 2,212 2.16 K
H:\PROGRA~1\ELABOR~1\CLONED~1\
cloned~1.bak Wed 13 Jul 2005 5:28:38 A.... 4,636,672 4.42 M
rgdrvl~1.bak Wed 13 Jul 2005 5:28:38 A.... 128,000 125.00 K
H:\PROGRA~1\SLYSOFT\ANYDVD\
anydvd~1.bak Mon 27 Nov 2006 4:29:38 A.... 498,176 486.50 K
H:\PROGRA~1\COMMON~1\SYMANT~1\IDS\
idssettg.bak Sat 24 Nov 2007 7:41:44 A.... 3,788 3.70 K
H:\DOCUME~1\ADMINI~1\APPLIC~1\MICROS~1\INTERN~1\
brndlog.bak Sat 22 Jul 2006 18:28:14 A.... 113 0.11 K
H:\DOCUME~1\ALLUSE~1\APPLIC~1\SYMANTEC\COMMON~1\
settings.bak Tue 27 Nov 2007 10:43:24 A.... 5,318,164 5.07 M
H:\DOCUME~1\DAMIAN\APPLIC~1\MICROS~1\INTERN~1\
brndlog.bak Sat 22 Jul 2006 18:28:34 A.... 141 0.14 K
H:\DOCUME~1\DEFAUL~1\APPLIC~1\MICROS~1\INTERN~1\
brndlog.bak Sat 22 Jul 2006 18:28:14 A.... 113 0.11 K
H:\WINDOWS\PCHEALTH\HELPCTR\CONFIG\CACHE\
profes~1.bak Tue 27 Nov 2007 9:56:36 A.... 268,934 262.63 K
H:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA \
opa11.bak Thu 17 Oct 2002 22:23:16 A.... 8,200 8.01 K
H:\DOCUME~1\DAMIAN\APPLIC~1\MOZILLA\FIREFOX\PROFIL ES\B1GKMR~1.DEF\
bookma~1.bak Tue 27 Nov 2007 18:19:58 A.... 41,475 40.50 K
bookma~2.bak Sat 24 Nov 2007 20:59:40 A.... 32,924 32.15 K
H:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\MICRO S~1\INTERN~1\
brndlog.bak Sat 22 Jul 2006 18:28:14 A.... 113 0.11 K
20 items found: 20 files, 0 directories.
Total of file sizes: 11,000,544 bytes 10.49 M
--------------------------------------------------------------------------
Locating all copies of Internet Explorer on H:
--------------------------------------------------------------------------
Locating all copies of Internet Explorer
H:\PROGRA~1\INTERN~1\
iexplore.exe Wed 4 Aug 2004 9:26:52 A.... 93,184 91.00 K
H:\WINDOWS\SYSTEM32\DLLCACHE\
iexplore.exe Wed 4 Aug 2004 9:26:52 A.... 93,184 91.00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 186,368 bytes 182.00 K
--------------------------------------------------------------------------
Locating all copies of Windows Explorer on H:
--------------------------------------------------------------------------
Locating all copies of Windows Explorer
H:\WINDOWS\
explorer.exe Wed 13 Jun 2007 21:56:04 A.... 1,033,216 1009.00 K
H:\WINDOWS\$N7CCA~1\
explorer.exe Thu 20 Jul 2006 6:45:58 ..... 1,032,192 1008.00 K
H:\WINDOWS\SYSTEM32\DLLCACHE\
explorer.exe Wed 13 Jun 2007 21:56:04 A.... 1,033,216 1009.00 K
3 items found: 3 files, 0 directories.
Total of file sizes: 3,098,624 bytes 2.95 M
--------------------------------------------------------------------------
Items in Document and Settings:
--------------------------------------------------------------------------
Listing contents of H:\Documents and Settings
No matches found.
--------------------------------------------------------------------------
Desktop Items:
--------------------------------------------------------------------------
Locating all files created in H:\Documents and Settings\Damian\Desktop within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\All Users\Desktop\ within the last 90 days.
No matches found.
--------------------------------------------------------------------------
Start Menu Items:
--------------------------------------------------------------------------
Locating all files created inH:\Documents and Settings\Damian\Start Menu within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\Damian\Start Menu\Programs\Startup within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\All Users\Start Menu within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\All Users\Start Menu\Programs\Startup\ within the last 90 days.
No matches found.
--------------------------------------------------------------------------
Application Data Items:
--------------------------------------------------------------------------
Locating all files created in H:\Documents and Settings\Damian\Application Data\ within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\Damian\Local Settings\Application Data\ within the last 90 days.
No matches found.
Locating all files created in H:\Documents and Settings\All Users\Application Data\ within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\Documents and Settings\Damian\Local Settings\TEMP:
--------------------------------------------------------------------------
Locating all files created in H:\Documents and Settings\Damian\Local Settings\TEMP within the last 90 days.
--------------------------------------------------------------------------
Items in Templates Folder:
--------------------------------------------------------------------------
Locating all files created in H:\Documents and Settings\Damian\Templates
No matches found.
--------------------------------------------------------------------------
Items in Program Files:
--------------------------------------------------------------------------
Locating all files created in H:\Program Files\ within the last 90 days.
No matches found.
Locating all files created in H:\Program Files\Common Files\ within the last 90 days.
No matches found.
Locating all files created in H:\Program Files\Common Files\Microsoft Shared\Web Folders within the last 90 days.
--------------------------------------------------------------------------
Items in the Windows Directory:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\ within the last 90 days.
H:\WINDOWS\
$N28DE~1 Fri 31 Aug 2007 16:46:18 .D.H. <Dir>
$N30AC~1 Thu 11 Oct 2007 9:45:40 .D.H. <Dir>
$N38D4~1 Wed 14 Nov 2007 6:25:54 .D.H. <Dir>
$N48EA~1 Thu 11 Oct 2007 9:46:38 .D.H. <Dir>
$N88B6~1 Thu 11 Oct 2007 9:46:50 .D.H. <Dir>
0.log Tue 27 Nov 2007 18:16:56 A.... 0 0.00 K
alcfdrtm.ver Sat 24 Nov 2007 18:11:26 A.... 81,920 80.00 K
bootstat.dat Tue 27 Nov 2007 18:16:00 A.S.. 2,048 2.00 K
ERDNT Tue 20 Nov 2007 6:54:36 .D... <Dir>
FTPCACHE Sun 21 Oct 2007 0:54:50 .DSH. <Dir>
MINIDUMP Tue 16 Oct 2007 9:17:00 .D... <Dir>
nerodi~1.ini Fri 23 Nov 2007 8:58:02 A.... 116 0.11 K
nsreg.dat Fri 16 Nov 2007 12:23:48 A.... 0 0.00 K
relax.ini Sun 7 Oct 2007 21:35:44 A.... 52 0.05 K
s1650e~1.tmp Sun 14 Oct 2007 22:54:04 ..SH. 24 0.02 K
schedlgu.txt Tue 27 Nov 2007 10:43:24 A.... 14,712 14.37 K
sti_tr~1.log Sun 25 Nov 2007 8:11:58 A.... 0 0.00 K
SUN Thu 8 Nov 2007 19:56:26 .D... <Dir>
thumbs.db Fri 14 Sep 2007 17:49:04 A.SH. 7,680 7.50 K
wiadebug.log Tue 27 Nov 2007 18:16:52 A.... 159 0.15 K
wiaservc.log Tue 27 Nov 2007 18:16:38 A.... 50 0.05 K
window~1.log Tue 27 Nov 2007 18:21:40 A.... 203,781 199.00 K
wininit.ini Mon 19 Nov 2007 13:53:34 A.... 449 0.44 K
23 items found: 14 files (3 H/S), 9 directories (6 H/S).
Total of file sizes: 310,991 bytes 303.70 K
--------------------------------------------------------------------------
H:\WINDOWS\Downloaded Program Files:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\Downloaded Program Files\ within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\WINDOWS\PCHealth\HelpCtr\Binaries:
--------------------------------------------------------------------------
Locating all files in H:\WINDOWS\PCHealth\HelpCtr\Binaries
H:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\
brpinfo.dll Thu 23 Aug 2001 22:30:00 A.... 21,504 21.00 K
hcappres.dll Thu 23 Aug 2001 22:30:00 A.... 6,656 6.50 K
helpctr.exe Wed 4 Aug 2004 9:26:50 A.... 768,512 750.50 K
helphost.exe Thu 23 Aug 2001 22:30:00 A.... 99,840 97.50 K
helpsvc.exe Wed 4 Aug 2004 9:26:52 A.... 743,936 726.50 K
hscmui.cab Sat 17 Jul 2004 20:09:14 A.... 68,327 66.72 K
hscsp_w3.cab Sat 17 Jul 2004 20:09:16 A.... 305,145 297.99 K
hscupd.exe Wed 4 Aug 2004 9:26:52 A.... 18,944 18.50 K
msconfig.exe Thu 20 Jul 2006 6:46:18 A.... 169,984 166.00 K
msinfo.dll Wed 4 Aug 2004 9:26:44 A.... 376,320 367.50 K
notiflag.exe Thu 23 Aug 2001 22:30:00 A.... 35,328 34.50 K
pchdt_w3.cab Wed 4 Aug 2004 7:19:10 A.... 2,737,914 2.61 M
pchshell.dll Wed 4 Aug 2004 9:26:46 A.... 102,400 100.00 K
pchsvc.dll Wed 4 Aug 2004 9:26:46 A.... 38,912 38.00 K
14 items found: 14 files, 0 directories.
Total of file sizes: 5,493,722 bytes 5.24 M
--------------------------------------------------------------------------
H:\WINDOWS\system:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\WINDOWS\system32:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system32 within the last 90 days.
H:\WINDOWS\SYSTEM32\
ADOBE Mon 26 Nov 2007 21:44:16 .D... <Dir>
aiqegays.ini Sun 25 Nov 2007 23:01:54 ..SH. 776,132 757.94 K
bassmod.dll Sun 21 Oct 2007 13:45:34 A.... 34,308 33.50 K
bbatbpwm.dll Tue 27 Nov 2007 10:30:50 A.... 86,080 84.06 K
java.exe Mon 24 Sep 2007 22:30:28 A.... 135,168 132.00 K
javacpl.cpl Mon 24 Sep 2007 23:31:42 A.... 69,632 68.00 K
javaw.exe Mon 24 Sep 2007 22:30:30 A.... 135,168 132.00 K
javaws.exe Mon 24 Sep 2007 23:31:42 A.... 139,264 136.00 K
jupdat~1.log Thu 8 Nov 2007 19:56:08 A.... 5,387 5.26 K
KASPER~1 Wed 21 Nov 2007 8:02:24 .D... <Dir>
mcrh.tmp Mon 26 Nov 2007 14:03:08 A.... 143 0.14 K
mrt.exe Fri 2 Nov 2007 0:12:58 A.... 18,238,072 17.39 M
mwpbtabb.ini Tue 27 Nov 2007 18:16:52 ..SH. 781,415 763.10 K
nvapps.xml Tue 27 Nov 2007 18:16:26 A.... 61,465 60.02 K
paaivpcd.ini Tue 27 Nov 2007 10:30:16 ..SH. 778,838 760.58 K
perfc009.dat Sun 28 Oct 2007 9:01:58 A.... 40,952 39.99 K
perfh009.dat Sun 28 Oct 2007 9:01:58 A.... 314,816 307.44 K
perfst~1.ini Sun 28 Oct 2007 9:01:58 A.... 360,124 351.68 K
profile.dat Tue 27 Nov 2007 10:43:24 A.... 40 0.04 K
shell32.dll Fri 26 Oct 2007 14:04:02 A.... 8,460,288 8.07 M
sstts.dll Wed 14 Nov 2007 17:43:56 ..... 320,608 313.09 K
stream~1.dll Tue 20 Nov 2007 15:09:42 ....R 59,392 58.00 K
sttss.ini Tue 27 Nov 2007 18:21:50 A.SH. 91,384 89.24 K
sttss~1.ini Tue 27 Nov 2007 18:19:24 A.SH. 93,754 91.55 K
sybsaoxe.ini Mon 26 Nov 2007 17:12:04 ..SH. 776,492 758.29 K
sytmwgpx.ini Sat 24 Nov 2007 7:42:02 ..SH. 775,832 757.65 K
tzlog.log Fri 31 Aug 2007 16:46:18 A.... 253,934 247.98 K
wpa.dbl Sun 18 Nov 2007 14:49:04 A.... 2,206 2.15 K
xpgwmtys.dll Sat 24 Nov 2007 7:41:40 A.... 86,080 84.06 K
xpsp3res.dll Mon 29 Oct 2007 20:34:04 A.... 350,720 342.50 K
30 items found: 28 files (7 H/S), 2 directories.
Total of file sizes: 33,227,694 bytes 31.69 M
--------------------------------------------------------------------------
H:\WINDOWS\system32\com:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system32\com within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\WINDOWS\system32\components:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system32\components within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\WINDOWS\system32\drivers:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system32\drivers within the last 90 days.
H:\WINDOWS\SYSTEM32\DRIVERS\
anydvd.sys Wed 21 Nov 2007 10:29:48 A.... 97,216 94.94 K
tmcomm.sys Thu 15 Nov 2007 15:25:36 A.... 102,664 100.26 K
2 items found: 2 files, 0 directories.
Total of file sizes: 199,880 bytes 195.20 K
--------------------------------------------------------------------------
H:\WINDOWS\system32\drivers\etc:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\system32\drivers\etc within the last 90 days.
No matches found.
--------------------------------------------------------------------------
H:\WINDOWS\TEMP:
--------------------------------------------------------------------------
Locating all files created in H:\WINDOWS\TEMP within the last 90 days.
H:\WINDOWS\TEMP\
wgaerr~1.txt Tue 27 Nov 2007 18:16:14 A.... 255 0.25 K
wganot~1.set Tue 27 Nov 2007 18:17:18 A.... 409 0.40 K
2 items found: 2 files, 0 directories.
Total of file sizes: 664 bytes 0.65 K
************************************************** **********************************


Reply With Quote