Za te stvari imas mnogo bolji i jednostavniji alat SystemLook
http://jpshortstuff.247fixes.com/SystemLook.exe
Korisna alatka za pretragu fajlova, foldera i registry baze i prikazivanje potrebnih podataka u vezi istih.
Ima dosta direktiva, nabrojacu samo neke.
Recimo
Kod:
:file
c:\documents and settings\administrator\local settings\application data\7255871.exe
Dobijes ovako
Kod:
SystemLook 30.07.11 by jpshortstuff
Log created at 10:17 on 28/04/2012 by Administrator
Administrator - Elevation successful
========== File ==========
c:\documents and settings\administrator\local settings\application data\7255871.exe - File found and opened.
MD5: 3BF625E12066A8F03DC5F2FAA0F6942E
Created at 15:16 on 24/04/2012
Modified at 15:16 on 24/04/2012
Size: 992256 bytes
Attributes: --a----
No version information available.
-= EOF =-
Pa dobijes da je ovo malware
https://www.virustotal.com/file/582f...e642/analysis/
Ili za folder
Kod:
:dir
c:\documents and settings\administrator\local settings\application data
Kod:
SystemLook 30.07.11 by jpshortstuff
Log created at 10:38 on 28/04/2012 by Administrator
Administrator - Elevation successful
========== dir ==========
c:\documents and settings\administrator\local settings\application data - Parameters: "(none)"
---Files---
0047527631.exe --a---- 992256 bytes [17:30 23/04/2012] [17:30 23/04/2012]
7255871.exe --a---- 992256 bytes [15:16 24/04/2012] [15:16 24/04/2012]
IconCache.db --ah--- 3745230 bytes [12:07 20/04/2012] [15:20 24/04/2012]
---Folders---
Microsoft d------ [11:57 20/04/2012]
Mozilla d------ [12:20 20/04/2012]
VMware d------ [12:07 20/04/2012]
-= EOF =-
Isto to samo md5
Kod:
:dir
c:\documents and settings\administrator\local settings\application data /md5
Kod:
SystemLook 30.07.11 by jpshortstuff
Log created at 10:41 on 28/04/2012 by Administrator
Administrator - Elevation successful
========== dir ==========
c:\documents and settings\administrator\local settings\application data - Parameters: "/md5"
---Files---
0047527631.exe --a---- 992256 bytes [17:30 23/04/2012] [17:30 23/04/2012] 3BF625E12066A8F03DC5F2FAA0F6942E
7255871.exe --a---- 992256 bytes [15:16 24/04/2012] [15:16 24/04/2012] 3BF625E12066A8F03DC5F2FAA0F6942E
IconCache.db --ah--- 3745230 bytes [12:07 20/04/2012] [15:20 24/04/2012] 402E556685CEC973F0A34C83EE47E8A1
---Folders---
Microsoft d------ [11:57 20/04/2012]
Mozilla d------ [12:20 20/04/2012]
VMware d------ [12:07 20/04/2012]
-= EOF =-
Ima tih direktiva jos puno, ali nije ni vreme ni mesto za skolu
