SystemLook 04.09.10 by jpshortstuff Log created at 22:36 on 19/10/2010 by user Administrator - Elevation successful ========== filefind ========== Searching for "aegisp.sys" C:\WINDOWS\system32\drivers\AegisP.sys --a---- 21035 bytes [07:47 12/09/2008] [07:47 12/09/2008] 30BB1BDE595CA65FD5549462080D94E5 Searching for "afd.sys" C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys --a---- 138496 bytes [08:43 15/10/2008] [10:34 14/08/2008] 4D43E74F2A1239D53929B82600F1971C C:\WINDOWS\$NtUninstallKB956803$\afd.sys -----c- 138496 bytes [11:35 15/10/2008] [11:40 20/06/2008] E3049B90FE06F3F740B7CFDA44995E2C C:\WINDOWS\system32\dllcache\afd.sys --a--c- 138496 bytes [12:00 15/04/2008] [10:04 14/08/2008] 7E775010EF291DA96AD17CA4B17137D7 C:\WINDOWS\system32\drivers\afd.sys --a---- 138496 bytes [12:00 15/04/2008] [10:04 14/08/2008] 7E775010EF291DA96AD17CA4B17137D7 Searching for "ipsec.sys" C:\WINDOWS\system32\dllcache\ipsec.sys --a--c- 75264 bytes [12:00 15/04/2008] [12:00 15/04/2008] 23C74D75E36E7158768DD63D92789A91 C:\WINDOWS\system32\drivers\ipsec.sys --a---- 75264 bytes [12:00 15/04/2008] [12:00 15/04/2008] 23C74D75E36E7158768DD63D92789A91 Searching for "win32k.sys" C:\WINDOWS\$hf_mig$\KB2160329\SP3QFE\win32k.sys --a---- 1861376 bytes [21:30 24/06/2010] [21:30 24/06/2010] 76CECF074846E3EEA7756F2D5FA450C0 C:\WINDOWS\$hf_mig$\KB954211\SP3QFE\win32k.sys --a---- 1847168 bytes [08:43 15/10/2008] [15:21 15/09/2008] 42DE5D60AFA64F9D438C625D5941CE42 C:\WINDOWS\$hf_mig$\KB958690\SP3QFE\win32k.sys --a---- 1847808 bytes [14:01 09/02/2009] [14:01 09/02/2009] A485966EB21C85CA63EBF20D9E3550E8 C:\WINDOWS\$hf_mig$\KB968537\SP3QFE\win32k.sys --a---- 1848064 bytes [19:44 19/04/2009] [19:44 19/04/2009] 07B95CDAD12D796515F44DC7425B000F C:\WINDOWS\$hf_mig$\KB969947\SP3QFE\win32k.sys --a---- 1859968 bytes [16:00 14/08/2009] [16:00 14/08/2009] EEFA58C10EB24258F164054DE9C9CAD6 C:\WINDOWS\$hf_mig$\KB979559\SP3QFE\win32k.sys --a---- 1860608 bytes [08:04 02/05/2010] [08:04 02/05/2010] F3258FE8B8DB4523FBC92B8C530E02C1 C:\WINDOWS\$hf_mig$\KB981957\SP3QFE\win32k.sys --a---- 1862144 bytes [07:57 01/09/2010] [07:57 01/09/2010] BB6347F0DED07CF8AFE050297B195096 C:\WINDOWS\$NtUninstallKB2160329$\win32k.sys -----c- 1851520 bytes [19:07 12/08/2010] [08:09 02/05/2010] DD2B4E85907F4394EB9C1B3631EA4D73 C:\WINDOWS\$NtUninstallKB954211$\win32k.sys -----c- 1845888 bytes [11:35 15/10/2008] [12:00 15/04/2008] 55007D27BF2ADDDB0D18A573E27CBE74 C:\WINDOWS\$NtUninstallKB958690$\win32k.sys -----c- 1846656 bytes [18:24 13/03/2009] [15:27 15/09/2008] 2689F9961D732204D70CDDB17778036A C:\WINDOWS\$NtUninstallKB968537$\win32k.sys -----c- 1847040 bytes [11:00 12/06/2009] [14:07 09/02/2009] 970DB9E819C8A57F7C68E0FC9480E6E7 C:\WINDOWS\$NtUninstallKB969947$\win32k.sys -----c- 1847424 bytes [00:50 12/11/2009] [19:51 19/04/2009] DB80AF3303E1FC633716AE6188884F10 C:\WINDOWS\$NtUninstallKB979559$\win32k.sys -----c- 1850880 bytes [22:31 10/06/2010] [15:15 14/08/2009] 12A361C86617082FFBAA17E094064F4D C:\WINDOWS\$NtUninstallKB981957$\win32k.sys -----c- 1852160 bytes [20:32 16/10/2010] [09:02 24/06/2010] 1B754A277A8B99D036D92F09213B3A02 C:\WINDOWS\SoftwareDistribution\Download\ae44d0bab1ea9e6b55017222024076c4\sp3gdr\win32k.sys --a---- 1853056 bytes [07:57 01/09/2010] [07:57 01/09/2010] 6CEC839ACBBC9D512F7EAAB14F04E720 C:\WINDOWS\SoftwareDistribution\Download\ae44d0bab1ea9e6b55017222024076c4\sp3qfe\win32k.sys --a---- 1862144 bytes [07:57 01/09/2010] [07:57 01/09/2010] BB6347F0DED07CF8AFE050297B195096 C:\WINDOWS\system32\win32k.sys --a---- 1853056 bytes [12:00 15/04/2008] [07:57 01/09/2010] 6CEC839ACBBC9D512F7EAAB14F04E720 C:\WINDOWS\system32\dllcache\win32k.sys --a--c- 1853056 bytes [12:00 15/04/2008] [07:57 01/09/2010] 6CEC839ACBBC9D512F7EAAB14F04E720 Searching for "vga.dll" C:\WINDOWS\system32\vga.dll --a---- 9344 bytes [12:00 15/04/2008] [12:00 15/04/2008] FF5D39FF73DDDAE56FE177A88894E3B4 C:\WINDOWS\system32\dllcache\vga.dll --a--c- 9344 bytes [12:00 15/04/2008] [12:00 15/04/2008] FF5D39FF73DDDAE56FE177A88894E3B4 Searching for "ipnathlp.dll" C:\WINDOWS\system32\ipnathlp.dll --a---- 330752 bytes [12:00 15/04/2008] [12:00 15/04/2008] DA5C015911F68F22ED821E9EE49AB233 C:\WINDOWS\system32\dllcache\ipnathlp.dll --a--c- 330752 bytes [12:00 15/04/2008] [12:00 15/04/2008] DA5C015911F68F22ED821E9EE49AB233 -= EOF =-