SystemLook 30.07.11 by jpshortstuff Log created at 23:29 on 26/06/2012 by z00269rd (Limited User) ========== reg ========== [HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}] (No values found) [HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32] "ThreadingModel"="Both" @="C:\Documents and Settings\z00269rd\Local Settings\Application Data\{54f6e7f6-26ad-329d-3d66-862fba7c2c62}\n." [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}] @="Microsoft WBEM New Event Subsystem" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32] @="\\.\globalroot\systemroot\Installer\{54f6e7f6-26ad-329d-3d66-862fba7c2c62}\n." "ThreadingModel"="Both" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}] @="MruPidlList" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] @="%SystemRoot%\system32\shdocvw.dll" "ThreadingModel"="Apartment" ========== filefind ========== Searching for "services.exe" C:\Stary laptop\SYSTEM_WXP\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe --a---- 110592 bytes [15:25 26/03/2011] [11:11 06/02/2009] 65DF52F5B8B6E9BBD183505225C37315 C:\Stary laptop\SYSTEM_WXP\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe --a---- 110592 bytes [15:25 26/03/2011] [11:06 06/02/2009] 020CEAAEDC8EB655B6506B8C70D53BB6 C:\Stary laptop\SYSTEM_WXP\WINDOWS\system32\services.exe --a---- 110592 bytes [14:59 26/03/2011] [11:06 06/02/2009] 020CEAAEDC8EB655B6506B8C70D53BB6 C:\Stary laptop\SYSTEM_WXP\WINDOWS\system32\dllcache\services.exe --a---- 110592 bytes [15:04 26/03/2011] [11:06 06/02/2009] 020CEAAEDC8EB655B6506B8C70D53BB6 C:\WINNT\system32\services.exe --a---- 110592 bytes [17:47 26/01/2011] [11:06 06/02/2009] 020CEAAEDC8EB655B6506B8C70D53BB6 C:\WINNT\system32\dllcache\services.exe --a--c- 110592 bytes [17:47 26/01/2011] [11:06 06/02/2009] 020CEAAEDC8EB655B6506B8C70D53BB6 -= EOF =-