Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: C:\Program Files\Finditnt
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 4481-C48B
Directory of C:\WINDOWS\System32
07/04/2005 12:48 PM <DIR> dllcache
02/05/2005 08:25 PM <DIR> Microsoft
0 File(s) 0 bytes
2 Dir(s) 6,112,157,696 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 4481-C48B
Directory of C:\WINDOWS\System32
07/07/2005 06:35 AM <DIR> vidctrl
07/04/2005 12:48 PM <DIR> dllcache
02/05/2005 08:20 PM 488 logonui.exe.manifest
02/05/2005 08:20 PM 488 WindowsLogon.manifest
02/05/2005 08:19 PM 749 sapi.cpl.manifest
02/05/2005 08:19 PM 749 nwc.cpl.manifest
02/05/2005 08:19 PM 749 ncpa.cpl.manifest
02/05/2005 08:19 PM 749 cdplayer.exe.manifest
02/05/2005 08:19 PM 749 wuaucpl.cpl.manifest
7 File(s) 4,721 bytes
2 Dir(s) 6,112,157,696 bytes free
------------ Files Named "Guard" ---------------
Volume in drive C has no label.
Volume Serial Number is 4481-C48B
Directory of C:\WINDOWS\System32
------ Temp Files in System32 Directory ------
Volume in drive C has no label.
Volume Serial Number is 4481-C48B
Directory of C:\WINDOWS\System32
------------------ User Agent ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
------------- Keys Under Notify -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
------------- Locate.com Results -------------
-------- Strings.exe Qoologic Results --------
--------- Strings.exe Aspack Results ---------
C:\WINDOWS\system32\MRT.exe: (ASPack)
C:\WINDOWS\system32\MRT.exe: ASPack 1.61
C:\WINDOWS\system32\MRT.exe: ASPack 1.084
C:\WINDOWS\system32\MRT.exe: ASPack 1.083
C:\WINDOWS\system32\MRT.exe: ASPack 1.08.02b
C:\WINDOWS\system32\MRT.exe: ASPack 1.07b
C:\WINDOWS\system32\MRT.exe: ASPack 1.05b
C:\WINDOWS\system32\MRT.exe: ASPack 1.02
C:\WINDOWS\system32\MRT.exe: ASPACK
C:\WINDOWS\system32\ntdll.dll: .aspack
-------------- HKLM Run Key ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"