SystemLook 30.07.11 by jpshortstuff Log created at 09:25 on 08/01/2013 by mój-komputer Administrator - Elevation successful ========== reg ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\mrxsmb] "DisplayName"="@%systemroot%\system32\wkssvc.dll,-1002" "Group"="Network" "ImagePath"="system32\DRIVERS\mrxsmb.sys" "Description"="@%systemroot%\system32\wkssvc.dll,-1003" "ErrorControl"= 0x0000000001 (1) "Start"= 0x0000000003 (3) "Tag"= 0x0000000005 (5) "Type"= 0x0000000002 (2) "DependOnService"="rdbss" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\mrxsmb\Enum] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\srvnet] "Group"="Network" "ImagePath"="System32\DRIVERS\srvnet.sys" "ErrorControl"= 0x0000000001 (1) "Start"= 0x0000000003 (3) "Type"= 0x0000000002 (2) "DisplayName"="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\srvnet\Enum] ========== filefind ========== Searching for "mrxsmb.sys" C:\Windows\System32\drivers\mrxsmb.sys --a---- 158208 bytes [17:21 06/09/2011] [02:40 27/04/2011] A5D9106A73DC88564C825D317CAC68AC C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16385_none_db865edc6ace75ca\mrxsmb.sys --a---- 157184 bytes [23:24 13/07/2009] [23:24 13/07/2009] CFDCD8CA87C2A657DEBC150AC35B5E08 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16499_none_db7f91fe6ad2f43e\mrxsmb.sys --a---- 157696 bytes [23:04 08/12/2010] [23:04 08/12/2010] AB5892797C4114640BA333949568DE8C C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16539_none_dbc0736c6aa249bf\mrxsmb.sys --a---- 157696 bytes [23:16 08/12/2010] [23:16 08/12/2010] 767A4C3BCF9410C286CED15A2DB17108 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16765_none_db9c064c6abe3284\mrxsmb.sys --a---- 157696 bytes [17:23 06/09/2011] [05:15 23/02/2011] B7F3D2C40BDF8FFB73EBFB19C77734E2 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16808_none_dbdfe8986a8ad40a\mrxsmb.sys --a---- 157696 bytes [17:21 06/09/2011] [02:51 04/05/2011] 040D62A9D8AD28922632137ACDD984F2 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20612_none_dc58ae0983b60046\mrxsmb.sys --a---- 157696 bytes [23:04 08/12/2010] [23:04 08/12/2010] D16736A578236E7E4A796FA9A40DB9AF C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20655_none_dc306f3783d3bc0f\mrxsmb.sys --a---- 157696 bytes [23:16 08/12/2010] [23:16 08/12/2010] 968613CC6C0F7427FAC62ACED6F7B8C5 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20907_none_dc68851983a95a7d\mrxsmb.sys --a---- 158208 bytes [17:23 06/09/2011] [03:47 23/02/2011] BE3A495095CD3307DE152EFDAC946C2A C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20959_none_dc34761183d018e0\mrxsmb.sys --a---- 158208 bytes [17:21 06/09/2011] [02:41 04/05/2011] 629086CABFDFBE0AF7253CB6A494E35A C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17514_none_ddb772a467bcf964\mrxsmb.sys --a---- 158208 bytes [21:00 07/09/2011] [09:27 20/11/2010] FAF015B07E3A2874A790A39B7D2C579F C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17565_none_dd82635267e49e70\mrxsmb.sys --a---- 158208 bytes [17:23 06/09/2011] [04:56 23/02/2011] C2B4651001A867FF3F8865863B592991 C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17605_none_ddc344c067b3f3f1\mrxsmb.sys --a---- 158208 bytes [17:21 06/09/2011] [02:40 27/04/2011] A5D9106A73DC88564C825D317CAC68AC C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.21666_none_de0d006781015791\mrxsmb.sys --a---- 158208 bytes [17:23 06/09/2011] [03:32 23/02/2011] CD291E3C21C61E17972DFAF8E2E2E5DA C:\Windows\winsxs\amd64_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.21714_none_de41115580da9655\mrxsmb.sys --a---- 158208 bytes [17:21 06/09/2011] [02:31 27/04/2011] 8D841161A355809EF86819FD3C6361D3 Searching for "srvnet.sys" C:\Windows\System32\drivers\srvnet.sys --a---- 168448 bytes [17:17 06/09/2011] [03:05 29/04/2011] 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.16385_none_5fcb1fdb29d81d5e\srvnet.sys --a---- 162816 bytes [23:24 13/07/2009] [23:24 13/07/2009] 26E84D3649019C3244622E654DFCD75B C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.16481_none_5fc7209929dbb529\srvnet.sys --a---- 162304 bytes [23:05 08/12/2010] [23:05 08/12/2010] CCE32BB223E9FF55D241099A858FA889 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.16619_none_601ad629299bb698\srvnet.sys --a---- 162304 bytes [23:30 08/12/2010] [23:30 08/12/2010] FBD09635227A8026C0F7790F604343C6 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.16664_none_5fdfc51b29c8c39a\srvnet.sys --a---- 161792 bytes [17:07 06/09/2011] [03:37 27/08/2010] 5A663FD67049267BC5C3F3279E631FFB C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.16806_none_6022a903299648f0\srvnet.sys --a---- 161792 bytes [17:17 06/09/2011] [03:12 29/04/2011] 0AF6E19D39C70844C5CAA8FB0183C36E C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.20591_none_6045ed78430170e4\srvnet.sys --a---- 162304 bytes [23:05 08/12/2010] [23:05 08/12/2010] 47A7DCDDEA3FC3099A126EB603FEC7A3 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.20740_none_607b009642d9c626\srvnet.sys --a---- 162304 bytes [23:30 08/12/2010] [23:30 08/12/2010] A2FF8C218D5B62D693658F91B7FBB514 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.20789_none_6058c38042f219f9\srvnet.sys --a---- 161792 bytes [17:07 06/09/2011] [03:39 27/08/2010] 3EBBD18201CF162E537217D7C51047F6 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7600.20956_none_6076363242dc746f\srvnet.sys --a---- 161792 bytes [17:17 06/09/2011] [03:06 29/04/2011] 19E0B9883EE4DB831CD5DD781CBD6498 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7601.17514_none_61fc33a326c6a0f8\srvnet.sys --a---- 167936 bytes [21:01 07/09/2011] [09:27 20/11/2010] 2BA8F3250828CCDB4204ECF2C6F40B6A C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7601.17608_none_620b069d26bae78a\srvnet.sys --a---- 168448 bytes [17:17 06/09/2011] [03:05 29/04/2011] 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\winsxs\amd64_microsoft-windows-smbserver-common_31bf3856ad364e35_6.1.7601.21717_none_6288d3323fe189ee\srvnet.sys --a---- 168448 bytes [17:17 06/09/2011] [02:53 29/04/2011] 497BC12BDA57CACB29A6B63C3069A0F5 -= EOF =-