SystemLook 04.09.10 by jpshortstuff
Log created at 16:52 on 20/11/2010 by Natty
Administrator - Elevation successful
No Context: Code:
========== filefind ==========
Searching for "*desktoplayer*"
C:\Qoobox\Quarantine\C\Program Files\Microsoft\_DesktopLayer_.exe.zip --a---- 49424 bytes [00:43 19/10/2010] [13:00 09/11/2010] 4047C00887AB8F3278B57990CB54C219
Searching for "scecli.dll"
C:\WINDOWS\ERDNT\cache\scecli.dll --a---- 180224 bytes [14:00 18/10/2010] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\scecli.dll --a---- 180224 bytes [01:07 04/08/2004] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\dllcache\scecli.dll --a--c- 180224 bytes [01:07 04/08/2004] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
Searching for "netlogon.dll"
C:\WINDOWS\ERDNT\cache\netlogon.dll --a---- 407040 bytes [14:00 18/10/2010] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\netlogon.dll --a---- 407040 bytes [01:07 04/08/2004] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c- 407040 bytes [01:07 04/08/2004] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
Searching for "eventlog.dll"
C:\WINDOWS\ERDNT\cache\eventlog.dll --a---- 55808 bytes [14:00 18/10/2010] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\eventlog.dll --a---- 55808 bytes [01:07 04/08/2004] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c- 55808 bytes [01:07 04/08/2004] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
Searching for "winlogon.exe"
C:\WINDOWS\ERDNT\cache\winlogon.exe --a---- 502272 bytes [14:00 18/10/2010] [01:07 04/08/2004] 01C3346C241652F43AED8E2149881BFE
C:\WINDOWS\system32\winlogon.exe --a---- 502272 bytes [01:07 04/08/2004] [01:07 04/08/2004] 93469F95485FA06E5D8BEB8D18AE309C
C:\WINDOWS\system32\dllcache\winlogon.exe --a---- 502272 bytes [01:07 04/08/2004] [01:07 04/08/2004] 93469F95485FA06E5D8BEB8D18AE309C
Searching for "comres.dll"
C:\WINDOWS\system32\comres.dll --a---- 792064 bytes [01:07 04/08/2004] [01:07 04/08/2004] 6728270CB7DBB776ED086F5AC4C82310
C:\WINDOWS\system32\dllcache\comres.dll --a--c- 792064 bytes [01:07 04/08/2004] [01:07 04/08/2004] 6728270CB7DBB776ED086F5AC4C82310
Searching for "crypt32.dll"
C:\WINDOWS\system32\crypt32.dll --a---- 597504 bytes [01:07 04/08/2004] [01:07 04/08/2004] EFC958396A7A7EF7E6D4A52B97512E18
C:\WINDOWS\system32\dllcache\crypt32.dll --a--c- 597504 bytes [01:07 04/08/2004] [01:07 04/08/2004] EFC958396A7A7EF7E6D4A52B97512E18
Searching for "gpedit.dll"
C:\WINDOWS\system32\gpedit.dll --a--c- 566784 bytes [01:07 04/08/2004] [01:07 04/08/2004] C4EE648B2474D84CF081C3FE0DC578DA
C:\WINDOWS\system32\dllcache\gpedit.dll --a--c- 566784 bytes [01:07 04/08/2004] [01:07 04/08/2004] C4EE648B2474D84CF081C3FE0DC578DA
Searching for "rundll32.exe"
C:\WINDOWS\system32\rundll32.exe --a---- 33280 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\dllcache\rundll32.exe --a--c- 33280 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA285490BBD8A1D0CE6623577D5BA1FF
Searching for "sfc.dll"
C:\WINDOWS\ERDNT\cache\sfc.dll --a---- 5120 bytes [14:00 18/10/2010] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\sfc.dll --a---- 5120 bytes [01:07 04/08/2004] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\dllcache\sfc.dll --a--c- 5120 bytes [01:07 04/08/2004] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
Searching for "svchost.exe"
C:\WINDOWS\ERDNT\cache\svchost.exe --a---- 14336 bytes [14:00 18/10/2010] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\svchost.exe --a---- 14336 bytes [01:07 04/08/2004] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\dllcache\svchost.exe --a--c- 14336 bytes [01:07 04/08/2004] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
Searching for "cngaudit.dll"
No files found.
Searching for "beep.sys"
C:\WINDOWS\ERDNT\cache\beep.sys --a---- 4224 bytes [14:00 18/10/2010] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\dllcache\beep.sys --a--c- 4224 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\drivers\beep.sys --a---- 4224 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
Searching for "wscntfy.exe"
C:\WINDOWS\ERDNT\cache\wscntfy.exe --a---- 13824 bytes [14:00 18/10/2010] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\wscntfy.exe --a--c- 13824 bytes [01:07 04/08/2004] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\dllcache\wscntfy.exe --a--c- 13824 bytes [01:07 04/08/2004] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
Searching for "atapi.sys"
C:\WINDOWS\ERDNT\cache\atapi.sys --a---- 95360 bytes [14:00 18/10/2010] [22:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\drivers\atapi.sys --a---- 95360 bytes [01:07 04/08/2004] [22:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
-= EOF =-
Log created at 16:52 on 20/11/2010 by Natty
Administrator - Elevation successful
No Context: Code:
========== filefind ==========
Searching for "*desktoplayer*"
C:\Qoobox\Quarantine\C\Program Files\Microsoft\_DesktopLayer_.exe.zip --a---- 49424 bytes [00:43 19/10/2010] [13:00 09/11/2010] 4047C00887AB8F3278B57990CB54C219
Searching for "scecli.dll"
C:\WINDOWS\ERDNT\cache\scecli.dll --a---- 180224 bytes [14:00 18/10/2010] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\scecli.dll --a---- 180224 bytes [01:07 04/08/2004] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\dllcache\scecli.dll --a--c- 180224 bytes [01:07 04/08/2004] [01:07 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
Searching for "netlogon.dll"
C:\WINDOWS\ERDNT\cache\netlogon.dll --a---- 407040 bytes [14:00 18/10/2010] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\netlogon.dll --a---- 407040 bytes [01:07 04/08/2004] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c- 407040 bytes [01:07 04/08/2004] [01:07 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
Searching for "eventlog.dll"
C:\WINDOWS\ERDNT\cache\eventlog.dll --a---- 55808 bytes [14:00 18/10/2010] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\eventlog.dll --a---- 55808 bytes [01:07 04/08/2004] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c- 55808 bytes [01:07 04/08/2004] [01:07 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
Searching for "winlogon.exe"
C:\WINDOWS\ERDNT\cache\winlogon.exe --a---- 502272 bytes [14:00 18/10/2010] [01:07 04/08/2004] 01C3346C241652F43AED8E2149881BFE
C:\WINDOWS\system32\winlogon.exe --a---- 502272 bytes [01:07 04/08/2004] [01:07 04/08/2004] 93469F95485FA06E5D8BEB8D18AE309C
C:\WINDOWS\system32\dllcache\winlogon.exe --a---- 502272 bytes [01:07 04/08/2004] [01:07 04/08/2004] 93469F95485FA06E5D8BEB8D18AE309C
Searching for "comres.dll"
C:\WINDOWS\system32\comres.dll --a---- 792064 bytes [01:07 04/08/2004] [01:07 04/08/2004] 6728270CB7DBB776ED086F5AC4C82310
C:\WINDOWS\system32\dllcache\comres.dll --a--c- 792064 bytes [01:07 04/08/2004] [01:07 04/08/2004] 6728270CB7DBB776ED086F5AC4C82310
Searching for "crypt32.dll"
C:\WINDOWS\system32\crypt32.dll --a---- 597504 bytes [01:07 04/08/2004] [01:07 04/08/2004] EFC958396A7A7EF7E6D4A52B97512E18
C:\WINDOWS\system32\dllcache\crypt32.dll --a--c- 597504 bytes [01:07 04/08/2004] [01:07 04/08/2004] EFC958396A7A7EF7E6D4A52B97512E18
Searching for "gpedit.dll"
C:\WINDOWS\system32\gpedit.dll --a--c- 566784 bytes [01:07 04/08/2004] [01:07 04/08/2004] C4EE648B2474D84CF081C3FE0DC578DA
C:\WINDOWS\system32\dllcache\gpedit.dll --a--c- 566784 bytes [01:07 04/08/2004] [01:07 04/08/2004] C4EE648B2474D84CF081C3FE0DC578DA
Searching for "rundll32.exe"
C:\WINDOWS\system32\rundll32.exe --a---- 33280 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\dllcache\rundll32.exe --a--c- 33280 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA285490BBD8A1D0CE6623577D5BA1FF
Searching for "sfc.dll"
C:\WINDOWS\ERDNT\cache\sfc.dll --a---- 5120 bytes [14:00 18/10/2010] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\sfc.dll --a---- 5120 bytes [01:07 04/08/2004] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\dllcache\sfc.dll --a--c- 5120 bytes [01:07 04/08/2004] [01:07 04/08/2004] E8A12A12EA9088B4327D49EDCA3ADD3E
Searching for "svchost.exe"
C:\WINDOWS\ERDNT\cache\svchost.exe --a---- 14336 bytes [14:00 18/10/2010] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\svchost.exe --a---- 14336 bytes [01:07 04/08/2004] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\dllcache\svchost.exe --a--c- 14336 bytes [01:07 04/08/2004] [01:07 04/08/2004] 8F078AE4ED187AAABC0A305146DE6716
Searching for "cngaudit.dll"
No files found.
Searching for "beep.sys"
C:\WINDOWS\ERDNT\cache\beep.sys --a---- 4224 bytes [14:00 18/10/2010] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\dllcache\beep.sys --a--c- 4224 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\drivers\beep.sys --a---- 4224 bytes [01:07 04/08/2004] [01:07 04/08/2004] DA1F27D85E0D1525F6621372E7B685E9
Searching for "wscntfy.exe"
C:\WINDOWS\ERDNT\cache\wscntfy.exe --a---- 13824 bytes [14:00 18/10/2010] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\wscntfy.exe --a--c- 13824 bytes [01:07 04/08/2004] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\dllcache\wscntfy.exe --a--c- 13824 bytes [01:07 04/08/2004] [01:07 04/08/2004] 49911DD39E023BB6C45E4E436CFBD297
Searching for "atapi.sys"
C:\WINDOWS\ERDNT\cache\atapi.sys --a---- 95360 bytes [14:00 18/10/2010] [22:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\drivers\atapi.sys --a---- 95360 bytes [01:07 04/08/2004] [22:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
-= EOF =-