Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Databaseversie: v2013.07.04.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Ronald :: ACER [administrator]
4-7-2013 21:29:27
mbam-log-2013-07-04 (21-29-27).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 197731
Verstreken tijd: 7 minuut/minuten, 48 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16490
Run by dorado at 21:42:23 on 2013-07-04
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3070.1624 [GMT 2:00]
.
AV: Immunet 3.0 *Enabled/Updated* {065276D9-6EBF-968C-B5ED-7B8B1DCF4059}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\Explorer.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Immunet\3.0.8\agent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
C:\Program Files\Immunet\3.0.8\iptray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\System Explorer\SystemExplorer.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\System Explorer\service\SystemExplorerService.exe
C:\Program Files\KeyScrambler\KeyScrambler.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Ronald\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\WmiPrvSE.exe
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Windows\system32\wermgr.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\WmiPrvSE.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=2&o=vp32&d=0513&m=aspire_6530g
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=2&o=vp32&d=0513&m=aspire_6530g
mDefault_Page_URL = hxxp://nl.intl.acer.yahoo.com
uProxyServer = hxxp=cache.zeelandnet.nl:800
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4A368E80-174F-4872-96B5-0B27DDD11DB2} - c:\program files\spywareguard\dlprotect.dll
uRun: [CCleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Immunet Protect] "c:\program files\immunet\3.0.8\iptray.exe"
mRun: [Firefox] c:\program files\mozilla firefox\firefox.exe
mRun: [Opera] c:\program files\opera\opera.exe
mRun: [SystemExplorerAutoStart] "c:\program files\system explorer\SystemExplorer.exe" /TRAY
mRun: [Launchy] c:\program files\launchy\Launchy.exe
mRun: [IObit Malware Fighter] "c:\program files\iobit\iobit malware fighter\IMF.exe" /autostart
mRun: [MRU Blaster silent clean] "c:\program files\mru-blaster\mrublaster.exe" -silent
mRun: [Dragon] c:\program files\comodo\dragon\dragon.exe
mRun: [KeyScrambler] c:\program files\keyscrambler\keyscrambler.exe /a
StartupFolder: c:\users\ronald\appdata\roaming\micros~1\windows\startm~1\programs\startup\mru-bl~1.lnk - c:\program files\mru-blaster\mrublaster.exe
StartupFolder: c:\users\ronald\appdata\roaming\micros~1\windows\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\launchy.lnk - c:\program files\launchy\Launchy.exe
uPolicies-Explorer: NoResolveTrack = dword:1
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: MemCheckBoxInRunDlg = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: DisableCAD = dword:1
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 208.67.222.123 208.67.220.123
TCP: Interfaces\{1C08D2A2-B88E-4DAB-9C2C-E7705346BFE7} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{1C08D2A2-B88E-4DAB-9C2C-E7705346BFE7} : DHCPNameServer = 208.67.222.123 208.67.220.123
TCP: Interfaces\{F12140D6-DBEC-4056-9DB5-71F3458AA545} : NameServer = 208.67.222.222,208.67.220.220
Notify: AWinNotifyVitaKey MC3000 - <no file>
Notify: spba - c:\program files\common files\spba\homefus2.dll
SEH: SpywareGuard.Handler - {81559C35-8464-49F7-BB0E-07A383BEF910} - c:\program files\spywareguard\spywareguard.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\
FF - prefs.js: browser.startup.homepage - people.zeelandnet.nl/bliekron|chrome://speeddial/content/speeddial.xul
FF - plugin: c:\users\ronald\appdata\roaming\mozilla\plugins\np-mswmp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
FF - ExtSQL: 2013-05-17 17:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: 2013-05-29 15:10; [email protected]; c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\extensions\[email protected] o.xpi
FF - ExtSQL: 2013-06-26 15:28; {9AA46F4F-4DC7-4c06-97AF-6665170634FE}; c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\extensions\{9AA46F4F-4DC7-4c06-97AF-6665170634FE}.xpi
.
============= SERVICES / DRIVERS ===============
.
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\program files\malwarebytes anti-exploit\mbae.sys [2013-6-24 44632]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2013-5-20 22560]
R1 ImmunetProtectDriver;ImmunetProtectDriver;c:\windows\system32\drivers\ImmunetProtect.sys [2013-5-17 51528]
R1 ImmunetSelfProtectDriver;ImmunetSelfProtectDriver;c:\windows\system32\drivers\ImmunetSelfProtect.sys [2013-5-17 35016]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2012-11-16 291840]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\comodo\dragon\dragon_updater.exe [2013-6-20 2095752]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2013-5-20 335168]
R2 ImmunetNetworkMonitorDriver;ImmunetNetworkMonitorDriver;c:\windows\system32\drivers\ImmunetNetworkMo nitor.sys [2013-5-17 103880]
R2 ImmunetProtect;Immunet 3.0;c:\program files\immunet\3.0.8\agent.exe [2013-5-17 872824]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2013-6-9 37944]
R3 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\FileMonitor.sys [2013-6-6 21480]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2013-5-23 209304]
R3 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\RegFilter.sys [2013-6-6 31752]
R3 SystemExplorerHelpService;System Explorer Service;c:\program files\system explorer\service\SystemExplorerService.exe [2013-5-17 567256]
R3 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\UrlFilter.sys [2013-6-6 20944]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2013-5-16 22072]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-3-28 43008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2013-5-17 23456]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\drivers\netr28.sys [2008-11-3 419328]
S3 rspUndeluxe;rspUndeluxe;c:\windows\system32\drivers\rspUnd32.sys [2013-5-19 23096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
ShellExec: Opera.exe: open="c:\program files\opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2013-07-04 18:54:08 -------- d-----w- c:\program files\ZHPDiag
2013-07-04 12:23:46 36864 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - disable or enable dep\Disable_Enable_DEP.exe
2013-07-02 19:53:17 -------- d-----w- c:\users\ronald\appdata\local\gpick
2013-07-02 19:51:51 -------- d-----w- c:\program files\Gpick
2013-07-02 17:57:58 -------- d-----w- c:\users\ronald\appdata\roaming\Opera Software
2013-07-02 17:57:58 -------- d-----w- c:\users\ronald\appdata\local\Opera Software
2013-07-02 17:08:54 7068072 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{02ec6267-2f16-4c08-9002-9956d214a21e}\mpengine.dll
2013-07-01 15:03:53 47368 ----a-w- c:\windows\system32\certsentry.dll
2013-06-30 18:39:23 585728 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - change dns servers\Change_DNS_Servers.exe
2013-06-30 17:45:19 7612 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - repair winsock & dns cache\files\regfiles\file_associations\vista\dir.reg
2013-06-29 09:55:25 953 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - repair windows updates\files\regfiles\file_associations\8\scr.reg
2013-06-29 09:23:05 -------- d-----w- c:\users\ronald\appdata\roaming\Comodo
2013-06-29 09:23:05 -------- d-----w- c:\users\ronald\appdata\local\Comodo
2013-06-29 07:00:50 39424 ----a-w- c:\windows\zipinst.exe
2013-06-29 07:00:50 -------- d-----w- c:\program files\avenger
2013-06-29 06:38:59 953 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - remove temp files\files\regfiles\file_associations\7\scr.reg
2013-06-29 06:32:20 -------- d-----w- c:\program files\CleanUp!
2013-06-25 20:31:18 -------- d-----w- c:\users\ronald\appdata\roaming\CrystalIdea Software
2013-06-25 09:05:42 -------- d-----w- c:\program files\GIMP 2
2013-06-24 16:20:04 743248 ----a-w- c:\windows\system32\msvcp100d.dll
2013-06-24 16:20:04 1498960 ----a-w- c:\windows\system32\msvcr100d.dll
2013-06-24 16:20:04 -------- d-----w- c:\program files\Malwarebytes Anti-Exploit
2013-06-23 06:42:30 -------- d-----w- c:\program files\Sysinspector
2013-06-23 06:40:25 -------- d-----w- c:\program files\DDS
2013-06-23 06:33:32 -------- d-----w- c:\program files\RSIT
2013-06-23 06:31:32 -------- d-----w- c:\users\ronald\appdata\roaming\calibre
2013-06-17 09:31:00 773632 ----a-w- c:\users\ronald\appdata\roaming\System.Data.SQLite.dll
2013-06-17 08:54:33 -------- d-----w- c:\program files\LogAnalyzer
2013-06-13 17:46:24 -------- d-----w- c:\program files\VideoLAN
2013-06-12 06:18:18 -------- d-----w- c:\users\ronald\appdata\local\Deployment
2013-06-12 04:55:41 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-12 04:55:36 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-06-12 04:55:36 37376 ----a-w- c:\windows\system32\printcom.dll
2013-06-12 04:55:07 812544 ----a-w- c:\windows\system32\certutil.exe
2013-06-12 04:55:06 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-06-12 04:55:06 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-12 04:55:06 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-12 04:55:05 41984 ----a-w- c:\windows\system32\certenc.dll
2013-06-12 04:54:31 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-12 04:54:29 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-09 17:39:26 -------- d-----w- c:\users\ronald\appdata\local\AMD
2013-06-09 17:38:51 -------- d-----w- c:\program files\AMD APP
2013-06-09 17:36:18 -------- d-----w- c:\programdata\AMD
2013-06-09 17:35:23 37944 ----a-w- c:\windows\system32\drivers\amdiox86.sys
2013-06-09 17:35:07 -------- d-----w- c:\program files\ATI Technologies
2013-06-09 17:25:57 -------- d-----w- C:\AMD
2013-06-09 14:22:32 -------- d-----w- c:\program files\File Shredder
2013-06-08 19:19:36 -------- d-----w- c:\windows\PCHEALTH
2013-06-08 19:15:55 -------- d-----w- c:\users\ronald\appdata\local\Microsoft Help
2013-06-06 20:08:58 -------- d-----w- c:\program files\Perfect Uninstaller
2013-06-06 05:36:41 -------- d-----w- c:\users\ronald\appdata\roaming\FreeFixer
2013-06-06 05:36:41 -------- d-----w- c:\users\ronald\appdata\local\FreeFixer
2013-06-06 05:36:36 -------- d-----w- c:\program files\FreeFixer
.
==================== Find3M ====================
.
2013-06-29 11:45:56 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2013-06-12 05:10:20 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 05:10:19 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-27 14:32:36 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2013-05-27 14:26:54 4096 ----a-w- c:\windows\system32\drivers\nl-nl\dxgkrnl.sys.mui
2013-05-27 14:26:53 519680 ----a-w- c:\windows\system32\d3d11.dll
2013-05-27 14:26:53 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2013-05-27 14:26:53 252928 ----a-w- c:\windows\system32\dxdiag.exe
2013-05-27 14:26:53 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2013-05-27 14:26:52 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-05-27 14:26:52 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-05-27 14:26:52 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-05-20 21:04:25 22560 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-05-17 19:16:52 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-05-17 16:04:21 51528 ----a-w- c:\windows\system32\drivers\ImmunetProtect.sys
2013-05-17 16:04:21 35016 ----a-w- c:\windows\system32\drivers\ImmunetSelfProtect.sys
2013-05-17 16:04:21 304712 ----a-w- c:\windows\system32\drivers\Trufos.sys
2013-05-17 16:04:21 103880 ----a-w- c:\windows\system32\drivers\ImmunetNetworkMonitor.sys
2013-05-16 22:39:39 1800704 ----a-w- c:\windows\system32\jscript9.dll
2013-05-16 22:28:26 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-05-16 22:27:30 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2013-05-16 22:21:37 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2013-05-16 22:20:30 420864 ----a-w- c:\windows\system32\vbscript.dll
2013-05-16 22:16:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-05-16 12:14:34 319456 ----a-w- c:\windows\DIFxAPI.dll
2013-05-16 12:09:16 0 ----a-w- c:\windows\ativpsrm.bin
2013-05-02 00:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-15 14:20:04 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-13 10:56:44 37376 ----a-w- c:\windows\system32\cdd.dll
2013-04-09 01:36:18 2049024 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 21:42:55,90 ===============
www.malwarebytes.org
Databaseversie: v2013.07.04.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Ronald :: ACER [administrator]
4-7-2013 21:29:27
mbam-log-2013-07-04 (21-29-27).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 197731
Verstreken tijd: 7 minuut/minuten, 48 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16490
Run by dorado at 21:42:23 on 2013-07-04
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3070.1624 [GMT 2:00]
.
AV: Immunet 3.0 *Enabled/Updated* {065276D9-6EBF-968C-B5ED-7B8B1DCF4059}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\Explorer.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Immunet\3.0.8\agent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
C:\Program Files\Immunet\3.0.8\iptray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\System Explorer\SystemExplorer.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\System Explorer\service\SystemExplorerService.exe
C:\Program Files\KeyScrambler\KeyScrambler.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Ronald\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\WmiPrvSE.exe
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Windows\system32\wermgr.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\WmiPrvSE.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=2&o=vp32&d=0513&m=aspire_6530g
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=2&o=vp32&d=0513&m=aspire_6530g
mDefault_Page_URL = hxxp://nl.intl.acer.yahoo.com
uProxyServer = hxxp=cache.zeelandnet.nl:800
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4A368E80-174F-4872-96B5-0B27DDD11DB2} - c:\program files\spywareguard\dlprotect.dll
uRun: [CCleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Immunet Protect] "c:\program files\immunet\3.0.8\iptray.exe"
mRun: [Firefox] c:\program files\mozilla firefox\firefox.exe
mRun: [Opera] c:\program files\opera\opera.exe
mRun: [SystemExplorerAutoStart] "c:\program files\system explorer\SystemExplorer.exe" /TRAY
mRun: [Launchy] c:\program files\launchy\Launchy.exe
mRun: [IObit Malware Fighter] "c:\program files\iobit\iobit malware fighter\IMF.exe" /autostart
mRun: [MRU Blaster silent clean] "c:\program files\mru-blaster\mrublaster.exe" -silent
mRun: [Dragon] c:\program files\comodo\dragon\dragon.exe
mRun: [KeyScrambler] c:\program files\keyscrambler\keyscrambler.exe /a
StartupFolder: c:\users\ronald\appdata\roaming\micros~1\windows\startm~1\programs\startup\mru-bl~1.lnk - c:\program files\mru-blaster\mrublaster.exe
StartupFolder: c:\users\ronald\appdata\roaming\micros~1\windows\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\launchy.lnk - c:\program files\launchy\Launchy.exe
uPolicies-Explorer: NoResolveTrack = dword:1
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: MemCheckBoxInRunDlg = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: DisableCAD = dword:1
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 208.67.222.123 208.67.220.123
TCP: Interfaces\{1C08D2A2-B88E-4DAB-9C2C-E7705346BFE7} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{1C08D2A2-B88E-4DAB-9C2C-E7705346BFE7} : DHCPNameServer = 208.67.222.123 208.67.220.123
TCP: Interfaces\{F12140D6-DBEC-4056-9DB5-71F3458AA545} : NameServer = 208.67.222.222,208.67.220.220
Notify: AWinNotifyVitaKey MC3000 - <no file>
Notify: spba - c:\program files\common files\spba\homefus2.dll
SEH: SpywareGuard.Handler - {81559C35-8464-49F7-BB0E-07A383BEF910} - c:\program files\spywareguard\spywareguard.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\
FF - prefs.js: browser.startup.homepage - people.zeelandnet.nl/bliekron|chrome://speeddial/content/speeddial.xul
FF - plugin: c:\users\ronald\appdata\roaming\mozilla\plugins\np-mswmp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
FF - ExtSQL: 2013-05-17 17:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - ExtSQL: 2013-05-29 15:10; [email protected]; c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\extensions\[email protected] o.xpi
FF - ExtSQL: 2013-06-26 15:28; {9AA46F4F-4DC7-4c06-97AF-6665170634FE}; c:\users\ronald\appdata\roaming\mozilla\firefox\profiles\yat7uozw.default\extensions\{9AA46F4F-4DC7-4c06-97AF-6665170634FE}.xpi
.
============= SERVICES / DRIVERS ===============
.
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\program files\malwarebytes anti-exploit\mbae.sys [2013-6-24 44632]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2013-5-20 22560]
R1 ImmunetProtectDriver;ImmunetProtectDriver;c:\windows\system32\drivers\ImmunetProtect.sys [2013-5-17 51528]
R1 ImmunetSelfProtectDriver;ImmunetSelfProtectDriver;c:\windows\system32\drivers\ImmunetSelfProtect.sys [2013-5-17 35016]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2012-11-16 291840]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\comodo\dragon\dragon_updater.exe [2013-6-20 2095752]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2013-5-20 335168]
R2 ImmunetNetworkMonitorDriver;ImmunetNetworkMonitorDriver;c:\windows\system32\drivers\ImmunetNetworkMo nitor.sys [2013-5-17 103880]
R2 ImmunetProtect;Immunet 3.0;c:\program files\immunet\3.0.8\agent.exe [2013-5-17 872824]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2013-6-9 37944]
R3 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\FileMonitor.sys [2013-6-6 21480]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2013-5-23 209304]
R3 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\RegFilter.sys [2013-6-6 31752]
R3 SystemExplorerHelpService;System Explorer Service;c:\program files\system explorer\service\SystemExplorerService.exe [2013-5-17 567256]
R3 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\wlh_x86\UrlFilter.sys [2013-6-6 20944]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2013-5-16 22072]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-3-28 43008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2013-5-17 23456]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\drivers\netr28.sys [2008-11-3 419328]
S3 rspUndeluxe;rspUndeluxe;c:\windows\system32\drivers\rspUnd32.sys [2013-5-19 23096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
ShellExec: Opera.exe: open="c:\program files\opera\Launcher.exe" "%1"
.
=============== Created Last 30 ================
.
2013-07-04 18:54:08 -------- d-----w- c:\program files\ZHPDiag
2013-07-04 12:23:46 36864 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - disable or enable dep\Disable_Enable_DEP.exe
2013-07-02 19:53:17 -------- d-----w- c:\users\ronald\appdata\local\gpick
2013-07-02 19:51:51 -------- d-----w- c:\program files\Gpick
2013-07-02 17:57:58 -------- d-----w- c:\users\ronald\appdata\roaming\Opera Software
2013-07-02 17:57:58 -------- d-----w- c:\users\ronald\appdata\local\Opera Software
2013-07-02 17:08:54 7068072 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{02ec6267-2f16-4c08-9002-9956d214a21e}\mpengine.dll
2013-07-01 15:03:53 47368 ----a-w- c:\windows\system32\certsentry.dll
2013-06-30 18:39:23 585728 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - change dns servers\Change_DNS_Servers.exe
2013-06-30 17:45:19 7612 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - repair winsock & dns cache\files\regfiles\file_associations\vista\dir.reg
2013-06-29 09:55:25 953 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - repair windows updates\files\regfiles\file_associations\8\scr.reg
2013-06-29 09:23:05 -------- d-----w- c:\users\ronald\appdata\roaming\Comodo
2013-06-29 09:23:05 -------- d-----w- c:\users\ronald\appdata\local\Comodo
2013-06-29 07:00:50 39424 ----a-w- c:\windows\zipinst.exe
2013-06-29 07:00:50 -------- d-----w- c:\program files\avenger
2013-06-29 06:38:59 953 ----a-w- c:\users\ronald\appdata\roaming\microsoft\windows\start menu\programs\tweaking.com\tweaking.com - remove temp files\files\regfiles\file_associations\7\scr.reg
2013-06-29 06:32:20 -------- d-----w- c:\program files\CleanUp!
2013-06-25 20:31:18 -------- d-----w- c:\users\ronald\appdata\roaming\CrystalIdea Software
2013-06-25 09:05:42 -------- d-----w- c:\program files\GIMP 2
2013-06-24 16:20:04 743248 ----a-w- c:\windows\system32\msvcp100d.dll
2013-06-24 16:20:04 1498960 ----a-w- c:\windows\system32\msvcr100d.dll
2013-06-24 16:20:04 -------- d-----w- c:\program files\Malwarebytes Anti-Exploit
2013-06-23 06:42:30 -------- d-----w- c:\program files\Sysinspector
2013-06-23 06:40:25 -------- d-----w- c:\program files\DDS
2013-06-23 06:33:32 -------- d-----w- c:\program files\RSIT
2013-06-23 06:31:32 -------- d-----w- c:\users\ronald\appdata\roaming\calibre
2013-06-17 09:31:00 773632 ----a-w- c:\users\ronald\appdata\roaming\System.Data.SQLite.dll
2013-06-17 08:54:33 -------- d-----w- c:\program files\LogAnalyzer
2013-06-13 17:46:24 -------- d-----w- c:\program files\VideoLAN
2013-06-12 06:18:18 -------- d-----w- c:\users\ronald\appdata\local\Deployment
2013-06-12 04:55:41 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-12 04:55:36 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-06-12 04:55:36 37376 ----a-w- c:\windows\system32\printcom.dll
2013-06-12 04:55:07 812544 ----a-w- c:\windows\system32\certutil.exe
2013-06-12 04:55:06 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-06-12 04:55:06 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-12 04:55:06 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-12 04:55:05 41984 ----a-w- c:\windows\system32\certenc.dll
2013-06-12 04:54:31 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-12 04:54:29 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-09 17:39:26 -------- d-----w- c:\users\ronald\appdata\local\AMD
2013-06-09 17:38:51 -------- d-----w- c:\program files\AMD APP
2013-06-09 17:36:18 -------- d-----w- c:\programdata\AMD
2013-06-09 17:35:23 37944 ----a-w- c:\windows\system32\drivers\amdiox86.sys
2013-06-09 17:35:07 -------- d-----w- c:\program files\ATI Technologies
2013-06-09 17:25:57 -------- d-----w- C:\AMD
2013-06-09 14:22:32 -------- d-----w- c:\program files\File Shredder
2013-06-08 19:19:36 -------- d-----w- c:\windows\PCHEALTH
2013-06-08 19:15:55 -------- d-----w- c:\users\ronald\appdata\local\Microsoft Help
2013-06-06 20:08:58 -------- d-----w- c:\program files\Perfect Uninstaller
2013-06-06 05:36:41 -------- d-----w- c:\users\ronald\appdata\roaming\FreeFixer
2013-06-06 05:36:41 -------- d-----w- c:\users\ronald\appdata\local\FreeFixer
2013-06-06 05:36:36 -------- d-----w- c:\program files\FreeFixer
.
==================== Find3M ====================
.
2013-06-29 11:45:56 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2013-06-12 05:10:20 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 05:10:19 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-27 14:32:36 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2013-05-27 14:26:54 4096 ----a-w- c:\windows\system32\drivers\nl-nl\dxgkrnl.sys.mui
2013-05-27 14:26:53 519680 ----a-w- c:\windows\system32\d3d11.dll
2013-05-27 14:26:53 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2013-05-27 14:26:53 252928 ----a-w- c:\windows\system32\dxdiag.exe
2013-05-27 14:26:53 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2013-05-27 14:26:52 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-05-27 14:26:52 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-05-27 14:26:52 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-05-20 21:04:25 22560 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-05-17 19:16:52 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-05-17 16:04:21 51528 ----a-w- c:\windows\system32\drivers\ImmunetProtect.sys
2013-05-17 16:04:21 35016 ----a-w- c:\windows\system32\drivers\ImmunetSelfProtect.sys
2013-05-17 16:04:21 304712 ----a-w- c:\windows\system32\drivers\Trufos.sys
2013-05-17 16:04:21 103880 ----a-w- c:\windows\system32\drivers\ImmunetNetworkMonitor.sys
2013-05-16 22:39:39 1800704 ----a-w- c:\windows\system32\jscript9.dll
2013-05-16 22:28:26 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-05-16 22:27:30 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2013-05-16 22:21:37 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2013-05-16 22:20:30 420864 ----a-w- c:\windows\system32\vbscript.dll
2013-05-16 22:16:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-05-16 12:14:34 319456 ----a-w- c:\windows\DIFxAPI.dll
2013-05-16 12:09:16 0 ----a-w- c:\windows\ativpsrm.bin
2013-05-02 00:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-15 14:20:04 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-13 10:56:44 37376 ----a-w- c:\windows\system32\cdd.dll
2013-04-09 01:36:18 2049024 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 21:42:55,90 ===============
Comment