[Files/Folders - Modified Within 30 days]
CanoScan -> %SystemDrive%\CanoScan -> [Folder | Modified Date = 22/10/2007 9:46:56 PM | Attr = H ]
Clips -> %SystemDrive%\Clips -> [Folder | Modified Date = 27/10/2007 7:21:40 PM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 21/10/2007 7:33:14 PM | Attr = HS]
Fraps -> %SystemDrive%\Fraps -> [Folder | Modified Date = 13/10/2007 9:16:38 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 21/10/2007 4:03:48 PM | Attr = R ]
ProgramData -> %AllUsersAppData% -> [Folder | Modified Date = 21/10/2007 4:03:50 PM | Attr = H ]
Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 25/10/2007 11:01:46 PM | Attr = ]
Windows -> %SystemRoot% -> [Folder | Modified Date = 24/10/2007 2:17:28 PM | Attr = ]
AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 16/10/2007 7:10:12 AM | Attr = ]
assembly -> %SystemRoot%\assembly -> [Folder | Modified Date = 20/10/2007 8:08:54 PM | Attr = R S]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 67584 bytes | Modified Date = 28/10/2007 1:52:42 AM | Attr = S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 20/10/2007 11:42:00 PM | Attr = S]
ERUNT -> %SystemRoot%\ERUNT -> [Folder | Modified Date = 16/10/2007 1:19:36 PM | Attr = ]
Filzip.ini -> %SystemRoot%\Filzip.ini -> [Ver = | Size = 41 bytes | Modified Date = 7/10/2007 6:31:00 PM | Attr = ]
gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 13, 12551 | Size = 585791 bytes | Modified Date = 21/10/2007 12:45:44 PM | Attr = ]
gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 250 bytes | Modified Date = 21/10/2007 12:45:44 PM | Attr = ]
gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Modified Date = 21/10/2007 12:45:44 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 28/10/2007 2:00:10 AM | Attr = ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 21/10/2007 5:20:22 PM | Attr = HS]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 28/10/2007 1:58:12 AM | Attr = ]
MEMORY.DMP -> %SystemRoot%\MEMORY.DMP -> [Ver = | Size = 273322982 bytes | Modified Date = 20/10/2007 4:40:20 PM | Attr = ]
Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 20/10/2007 4:40:26 PM | Attr = ]
NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 69 bytes | Modified Date = 27/10/2007 7:34:28 PM | Attr = ]
pdf995.ini -> %SystemRoot%\pdf995.ini -> [Ver = | Size = 28 bytes | Modified Date = 24/10/2007 2:17:28 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 28/10/2007 2:01:22 AM | Attr = ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 20/10/2007 8:06:34 PM | Attr = ]
rescache -> %SystemRoot%\rescache -> [Folder | Modified Date = 16/10/2007 7:56:32 AM | Attr = ]
System32 -> %System32% -> [Folder | Modified Date = 28/10/2007 2:00:10 AM | Attr = ]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 28/10/2007 1:53:18 AM | Attr = ]
twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 22/10/2007 9:47:34 PM | Attr = ]
winsxs -> %SystemRoot%\winsxs -> [Folder | Modified Date = 21/10/2007 10:06:46 AM | Attr = ]
wpd99.drv -> %SystemRoot%\wpd99.drv -> [Ver = | Size = 117 bytes | Modified Date = 4/10/2007 11:27:18 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 28/10/2007 1:52:46 AM | Attr = H ]
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> %System32%\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [Ver = | Size = 2368 bytes | Modified Date = 28/10/2007 1:52:46 AM | Attr = H ]
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> %System32%\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [Ver = | Size = 2368 bytes | Modified Date = 28/10/2007 1:52:46 AM | Attr = H ]
BMXState-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> %System32%\BMXState-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> [Ver = | Size = 53964 bytes | Modified Date = 26/10/2007 9:04:56 PM | Attr = ]
BMXStateBkp-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> %System32%\BMXStateBkp-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> [Ver = | Size = 53964 bytes | Modified Date = 26/10/2007 9:04:56 PM | Attr = ]
catroot -> %System32%\catroot -> [Folder | Modified Date = 22/10/2007 9:47:02 PM | Attr = ]
catroot2 -> %System32%\catroot2 -> [Folder | Modified Date = 21/10/2007 9:37:22 AM | Attr = ]
conf.dat -> %System32%\conf.dat -> [Ver = | Size = 94 bytes | Modified Date = 6/10/2007 5:50:22 PM | Attr = ]
cookie1.dat -> %System32%\cookie1.dat -> [Ver = | Size = 1 bytes | Modified Date = 6/10/2007 5:51:26 PM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 22/10/2007 9:47:36 PM | Attr = ]
DVCState-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> %System32%\DVCState-{00000007-00000000-00000006-00001102-00000005-002C1102}.rfx -> [Ver = | Size = 64756 bytes | Modified Date = 26/10/2007 9:04:56 PM | Attr = ]
en-US -> %System32%\en-US -> [Folder | Modified Date = 16/10/2007 7:10:12 AM | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Modified Date = 20/10/2007 1:24:30 PM | Attr = ]
Macromed -> %System32%\Macromed -> [Folder | Modified Date = 21/10/2007 9:32:24 AM | Attr = ]
migration -> %System32%\migration -> [Folder | Modified Date = 21/10/2007 10:08:52 AM | Attr = ]
pdf995mon.dll -> %System32%\pdf995mon.dll -> [Ver = | Size = 51716 bytes | Modified Date = 4/10/2007 11:25:44 PM | Attr = ]
pdfmona.dll -> %System32%\pdfmona.dll -> TODO: <Company name> [Ver = 1.0.0.1 | Size = 249856 bytes | Modified Date = 4/10/2007 11:25:44 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 118776 bytes | Modified Date = 28/10/2007 2:00:10 AM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 652050 bytes | Modified Date = 28/10/2007 2:00:10 AM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 767184 bytes | Modified Date = 28/10/2007 2:00:10 AM | Attr = ]
ps1.dat -> %System32%\ps1.dat -> [Ver = | Size = 1 bytes | Modified Date = 6/10/2007 5:51:26 PM | Attr = ]
rc.dat -> %System32%\rc.dat -> [Ver = | Size = 1 bytes | Modified Date = 6/10/2007 5:51:26 PM | Attr = ]
SLUI -> %System32%\SLUI -> [Folder | Modified Date = 16/10/2007 7:10:12 AM | Attr = ]
WinFast -> %System32%\WinFast -> [Folder | Modified Date = 10/10/2007 2:40:42 AM | Attr = ]
ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 21/10/2007 10:06:54 AM | Attr = ]
avipbb.sys -> %System32%\drivers\avipbb.sys -> AVIRA GmbH [Ver = 1.00.02.13 | Size = 61632 bytes | Modified Date = 16/10/2007 2:11:30 PM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 20/10/2007 11:52:00 PM | Attr = ]
gmer.sys -> %System32%\drivers\gmer.sys -> GMER [Ver = 1, 0, 12, 3911 | Size = 70001 bytes | Modified Date = 21/10/2007 12:45:44 PM | Attr = ]
sptd.sys -> %System32%\drivers\sptd.sys -> [Ver = | Size = 685816 bytes | Modified Date = 20/10/2007 4:44:26 PM | Attr = ]
tmcomm.sys -> %System32%\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 20/10/2007 11:44:00 PM | Attr = ]
vsconfig.xml -> %System32%\drivers\vsconfig.xml -> [Ver = | Size = 350468 bytes | Modified Date = 28/10/2007 1:52:48 AM | Attr = H ]
[File String Scan - Non-Microsoft Only]
File scan skipped for file %SystemRoot%\MEMORY.DMP -> File size too big (273322982 bytes) ->
FSG! , -> %System32%\28MBGM.sf2 -> [Ver = | Size = 29705938 bytes | Modified Date = 4/05/2006 10:37:00 AM | Attr = ]
Thawte Consulting , -> %System32%\AddCat.exe -> Creative Technology Ltd. [Ver = 0.0.0.1 | Size = 48400 bytes | Modified Date = 10/05/2007 3:36:50 PM | Attr = ]
UPX! , UPX0 , -> %System32%\avisynth.dll -> The Public [Ver = 2, 5, 7, 0 | Size = 306688 bytes | Modified Date = 12/11/2006 1:44:10 PM | Attr = ]
UPX! , UPX0 , -> %System32%\CoreAAC.ax -> [Ver = 1, 2, 0, 575 | Size = 175104 bytes | Modified Date = 17/08/2006 12:23:32 AM | Attr = RHS]
Thawte Consulting , -> %System32%\ctpxinst.exe -> Creative Technology Ltd [Ver = 1, 1, 0, 58 | Size = 58104 bytes | Modified Date = 14/11/2006 5:01:30 PM | Attr = ]
Thawte Consulting , -> %System32%\ctpxst32.exe -> Creative Technology Ltd [Ver = 1, 1, 0, 59 | Size = 89336 bytes | Modified Date = 13/03/2007 10:32:14 AM | Attr = ]
UPX! , UPX0 , -> %System32%\DiracSplitter.ax -> Gabest [Ver = 1, 0, 0, 0 | Size = 179200 bytes | Modified Date = 18/01/2005 8:56:36 AM | Attr = RHS]
PEC2 , PECompact2 , -> %System32%\DivX.dll -> DivX, Inc. [Ver = 6.6.1.4 | Size = 740442 bytes | Modified Date = 3/07/2007 5:07:36 AM | Attr = ]
UPX! , UPX0 , -> %System32%\i420vfw.dll ->
www.helixcommunity.org [Ver = R1.02 | Size = 70656 bytes | Modified Date = 3/01/2004 12:08:00 AM | Attr = ]
Thawte Consulting , -> %System32%\pxcpya64.exe -> Sonic Solutions [Ver = 1.00.35a | Size = 63144 bytes | Modified Date = 25/08/2006 1:17:00 PM | Attr = ]
Thawte Consulting , -> %System32%\pxhpinst.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 67240 bytes | Modified Date = 25/08/2006 1:17:00 PM | Attr = ]
Thawte Consulting , -> %System32%\pxinsa64.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 62632 bytes | Modified Date = 25/08/2006 1:17:00 PM | Attr = ]
Thawte Consulting , -> %System32%\pxinsi64.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 115880 bytes | Modified Date = 25/08/2006 1:17:00 PM | Attr = ]
UPX! , UPX0 , -> %System32%\RLOgg.ax -> RadLight [Ver = 1.0.0.2 | Size = 186880 bytes | Modified Date = 13/02/2005 8:30:00 AM | Attr = RHS]
UPX! , UPX0 , -> %System32%\RLSpeexDec.ax -> [Ver = 1, 0, 0, 0 | Size = 51712 bytes | Modified Date = 13/02/2005 8:30:00 AM | Attr = RHS]
UPX! , UPX0 , -> %System32%\RLTheoraDec.ax -> RadLight, LLC [Ver = 1, 0, 0, 3 | Size = 67584 bytes | Modified Date = 13/02/2005 8:30:00 AM | Attr = RHS]
UPX! , UPX0 , -> %System32%\RLVorbisDec.ax -> RadLight [Ver = 1, 0, 1, 1 | Size = 92672 bytes | Modified Date = 6/02/2005 8:30:00 AM | Attr = RHS]
Thawte Consulting , -> %System32%\rmoc3260.dll -> RealNetworks, Inc. [Ver = 6.0.9.2568 | Size = 185952 bytes | Modified Date = 7/10/2006 5:18:32 AM | Attr = ]
PECompact2 , -> %System32%\Smab.dll -> [Ver = | Size = 471552 bytes | Modified Date = 12/12/2006 2:15:08 PM | Attr = ]
UPX! , UPX0 , -> %System32%\x.264.exe -> [Ver = | Size = 240128 bytes | Modified Date = 10/11/2005 1:16:02 PM | Attr = ]
UPX! , UPX0 , -> %System32%\yv12vfw.dll ->
www.helixcommunity.org [Ver = R1.02 | Size = 70656 bytes | Modified Date = 3/01/2004 12:08:00 AM | Attr = ]
< End of report >