Hallo Nuciamedewerkers,
Even geleden, maar ja.. hier zijn we toch weer es...
Internet en zeker chrome, traag...
Mijne norton antivirus update niet meer.. ( en is niet vervallen)
Ik heb chrome ook al es verwijderd en opnieuw geïnstalleerd. Helpt niet.
De stappen uitgevoerd: Defogger/Mbam: alles oké/DDS: zie logs/Gmer: zie logs
Verder installeerde PREVX zich tijdens het scannen op rootkits?
Nu is het me toch al gelukt om housecall te draaien maar erg traag ook. Voorlopig niets..
Greetz !!
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2
Run by ilse at 22:08:25 on 2013-08-23
Microsoft Windows XP Professional 5.1.2600.3.1252.32.1043.18.3582.2165 [GMT 2:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
AV: Symantec AntiVirus Corporate Edition *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ================
.
F:\Program Files\Sandbox\SbieSvc.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\KMService.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\WINDOWS\RTHDCPL.EXE
F:\Program Files\Adobe\Acrobat\Acrotray.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Office 2010\Office14\ONENOTEM.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\ilse\Bureaublad\Defogger.exe
F:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Documents and Settings\ilse\Bureaublad\h688q3ky.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\WRSA.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.be/
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - f:\program files\office 2010\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - f:\program files\office 2010\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [AdobeBridge] <no file>
mRun: [EasyTuneVPro] c:\program files\gigabyte\et5pro\ETcall.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BCSSync] "f:\program files\office 2010\office14\BCSSync.exe" /DelayServices
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Acrobat Assistant 8.0] "f:\program files\adobe\acrobat\Acrotray.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "c:\program files\common files\adobe\cs6servicemanager\CS6ServiceManager.exe" -launchedbylogin
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Nvtmru] "c:\program files\nvidia corporation\nvidia update core\nvtmru.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [QuickTime Task] "f:\program files\quicktime\qttask.exe" -atboottime
mRun: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui
mRun: [muBlinder] c:\documents and settings\ilse\mijn documenten\downloads\mublinder\muBlinder.exe -startup
mRunOnce: [Malwarebytes Anti-Malware] f:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\ilse\menust~1\progra~1\opstar~1\onenot~2.lnk - f:\program files\office 2010\office14\ONENOTEM.EXE
StartupFolder: c:\docume~1\ilse\menust~1\progra~1\opstar~1\onenot~1.lnk - f:\program files\office 2010\office14\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\adobea~1.lnk - c:\windows\installer\{ac76ba86-1040-7d00-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\adober~1.lnk - f:\program files\adobe\acrobat\AdobeCollabSync.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
IE: Converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - f:\progra~1\office~1\office14\EXCEL.EXE/3000
IE: Geselecteerde koppelingen converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Koppelingdoel converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Koppelingdoel converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Se&nd to OneNote - f:\progra~1\office~1\office14\ONBttnIE.dll/105
IE: Selectie converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Selectie converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Toevoegen aan bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\program files\office 2010\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - f:\program files\office 2010\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350773546906
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1350774295109
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{84F1B249-EB44-4570-A3A8-C28543DFB43D} : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - f:\program files\office 2010\office14\GROOVEEX.DLL
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\ilse\application data\mozilla\firefox\profiles\l1lfrgl6.default\
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npo1d.dll
FF - plugin: c:\documents and settings\ilse\local settings\application data\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\nokia\nokia suite\npNokiaSuiteEnabler.dll
FF - plugin: c:\program files\tabletplugins\npWacomTabletPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll
FF - plugin: f:\progra~1\office~1\office14\NPAUTHZ.DLL
FF - plugin: f:\progra~1\office~1\office14\NPSPWRAP.DLL
FF - plugin: f:\program files\quicktime\plugins\npqtplugin.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin2.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin3.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin4.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin5.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin6.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin7.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2013-8-23 116224]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2013-1-10 8192]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2012-10-22 22016]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2009-11-16 9216]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2013-8-23 744448]
R2 WTabletServiceCon;Wacom Consumer Service;c:\program files\tablet\pen\WTabletServiceCon.exe [2013-1-17 526208]
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [2013-5-26 28256]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-3-22 106656]
R3 hidkmdf;KMDF Driver;c:\windows\system32\drivers\hidkmdf.sys [2013-1-17 11680]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-8-23 40776]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20130705.002\naveng.sys [2013-7-5 93272]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20130705.002\navex15.sys [2013-7-5 1611992]
R3 SbieDrv;SbieDrv;f:\program files\sandbox\SbieDrv.sys [2013-7-8 159208]
R3 WacHidRouter;Wacom Hid Router;c:\windows\system32\drivers\wachidrouter.sys [2013-1-17 69024]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\drivers\wacomrouterfilter.sys [2013-1-17 13728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-10-22 1691480]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [2013-5-26 28256]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-5-15 83864]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\f:\program files\live update 5\ntiolib.sys --> f:\program files\live update 5\NTIOLib.sys [?]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2012-10-22 36384]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2012-10-22 17664]
S3 RTLVLANMP;Realtek Virtual Adapter;c:\windows\system32\drivers\RTLVLAN.SYS [2012-10-22 17664]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;f:\program files\sisoftware sandra lite 2013.sp4\RpcAgentSrv.exe [2013-7-4 71832]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-5-15 181912]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-16 755880]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2013-3-23 114688]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2013-3-23 105088]
SUnknown GVTDrv;GVTDrv; [x]
.
=============== Created Last 30 ================
.
2013-08-23 19:59:27 150160 ----a-w- c:\windows\system32\WRusr.dll
2013-08-23 19:59:26 116224 ----a-w- c:\windows\system32\drivers\WRkrn.sys
2013-08-23 19:59:21 -------- d-----w- c:\program files\Webroot
2013-08-23 19:58:50 -------- d-----w- c:\documents and settings\all users\application data\WRData
2013-08-23 19:31:07 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-08-23 19:31:00 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-23 11:22:50 -------- d--h--r- c:\documents and settings\ilse\Onlangs geopend
2013-08-20 23:12:26 -------- d-----w- c:\documents and settings\ilse\local settings\application data\Logitech
2013-08-20 22:30:47 -------- d-----w- c:\program files\common files\Logitech
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-08-15 20:35:14 -------- d-----w- c:\windows\system32\MRT
.
==================== Find3M ====================
.
2013-08-23 11:31:32 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2013-07-26 02:49:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-07-26 02:48:59 43520 ------w- c:\windows\system32\licmgr10.dll
2013-07-26 02:48:59 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-07-25 20:53:17 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-25 20:53:17 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-25 15:58:11 385024 ------w- c:\windows\system32\html.iec
2013-07-10 10:37:49 406016 ----a-w- c:\windows\system32\usp10.dll
2013-07-04 07:33:59 2154496 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 07:33:59 2033152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-27 20:59:46 1091636 ----a-w- c:\windows\system32\nvdrsdb1.bin
2013-06-27 20:59:46 1 ----a-w- c:\windows\system32\nvdrssel.bin
2013-06-27 20:59:40 1091636 ----a-w- c:\windows\system32\nvdrsdb0.bin
2013-06-12 19:48:23 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-12 19:48:17 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-12 19:48:00 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-12 19:35:55 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-06-11 23:55:25 9089416 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-06-05 09:08:29 1876864 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 07:22:58 563200 ----a-w- c:\windows\system32\qedit.dll
2013-05-28 01:59:30 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2013-05-28 01:05:24 6656 ----a-w- c:\windows\system32\xpsp4res.dll
.
============= FINISH: 22:08:44,21 ===============
Even geleden, maar ja.. hier zijn we toch weer es...
Internet en zeker chrome, traag...
Mijne norton antivirus update niet meer.. ( en is niet vervallen)
Ik heb chrome ook al es verwijderd en opnieuw geïnstalleerd. Helpt niet.
De stappen uitgevoerd: Defogger/Mbam: alles oké/DDS: zie logs/Gmer: zie logs
Verder installeerde PREVX zich tijdens het scannen op rootkits?
Nu is het me toch al gelukt om housecall te draaien maar erg traag ook. Voorlopig niets..
Greetz !!
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2
Run by ilse at 22:08:25 on 2013-08-23
Microsoft Windows XP Professional 5.1.2600.3.1252.32.1043.18.3582.2165 [GMT 2:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
AV: Symantec AntiVirus Corporate Edition *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ================
.
F:\Program Files\Sandbox\SbieSvc.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\KMService.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\WINDOWS\RTHDCPL.EXE
F:\Program Files\Adobe\Acrobat\Acrotray.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Office 2010\Office14\ONENOTEM.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\ilse\Bureaublad\Defogger.exe
F:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Documents and Settings\ilse\Bureaublad\h688q3ky.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\WRSA.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.be/
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - f:\program files\office 2010\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - f:\program files\office 2010\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - f:\program files\adobe\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [AdobeBridge] <no file>
mRun: [EasyTuneVPro] c:\program files\gigabyte\et5pro\ETcall.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BCSSync] "f:\program files\office 2010\office14\BCSSync.exe" /DelayServices
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Acrobat Assistant 8.0] "f:\program files\adobe\acrobat\Acrotray.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "c:\program files\common files\adobe\cs6servicemanager\CS6ServiceManager.exe" -launchedbylogin
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Nvtmru] "c:\program files\nvidia corporation\nvidia update core\nvtmru.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [QuickTime Task] "f:\program files\quicktime\qttask.exe" -atboottime
mRun: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui
mRun: [muBlinder] c:\documents and settings\ilse\mijn documenten\downloads\mublinder\muBlinder.exe -startup
mRunOnce: [Malwarebytes Anti-Malware] f:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\ilse\menust~1\progra~1\opstar~1\onenot~2.lnk - f:\program files\office 2010\office14\ONENOTEM.EXE
StartupFolder: c:\docume~1\ilse\menust~1\progra~1\opstar~1\onenot~1.lnk - f:\program files\office 2010\office14\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\adobea~1.lnk - c:\windows\installer\{ac76ba86-1040-7d00-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\adober~1.lnk - f:\program files\adobe\acrobat\AdobeCollabSync.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
IE: Converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - f:\progra~1\office~1\office14\EXCEL.EXE/3000
IE: Geselecteerde koppelingen converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Koppelingdoel converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Koppelingdoel converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Se&nd to OneNote - f:\progra~1\office~1\office14\ONBttnIE.dll/105
IE: Selectie converteren naar Adobe PDF - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Selectie converteren naar bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Toevoegen aan bestaand PDF-bestand - f:\program files\adobe\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\program files\office 2010\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - f:\program files\office 2010\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350773546906
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1350774295109
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{84F1B249-EB44-4570-A3A8-C28543DFB43D} : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - f:\program files\office 2010\office14\GROOVEEX.DLL
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\ilse\application data\mozilla\firefox\profiles\l1lfrgl6.default\
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\ilse\application data\mozilla\plugins\npo1d.dll
FF - plugin: c:\documents and settings\ilse\local settings\application data\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\nokia\nokia suite\npNokiaSuiteEnabler.dll
FF - plugin: c:\program files\tabletplugins\npWacomTabletPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll
FF - plugin: f:\progra~1\office~1\office14\NPAUTHZ.DLL
FF - plugin: f:\progra~1\office~1\office14\NPSPWRAP.DLL
FF - plugin: f:\program files\quicktime\plugins\npqtplugin.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin2.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin3.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin4.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin5.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin6.dll
FF - plugin: f:\program files\quicktime\plugins\npqtplugin7.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2013-8-23 116224]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2013-1-10 8192]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2012-10-22 22016]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2009-11-16 9216]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2013-8-23 744448]
R2 WTabletServiceCon;Wacom Consumer Service;c:\program files\tablet\pen\WTabletServiceCon.exe [2013-1-17 526208]
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [2013-5-26 28256]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-3-22 106656]
R3 hidkmdf;KMDF Driver;c:\windows\system32\drivers\hidkmdf.sys [2013-1-17 11680]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-8-23 40776]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20130705.002\naveng.sys [2013-7-5 93272]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20130705.002\navex15.sys [2013-7-5 1611992]
R3 SbieDrv;SbieDrv;f:\program files\sandbox\SbieDrv.sys [2013-7-8 159208]
R3 WacHidRouter;Wacom Hid Router;c:\windows\system32\drivers\wachidrouter.sys [2013-1-17 69024]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\drivers\wacomrouterfilter.sys [2013-1-17 13728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-10-22 1691480]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [2013-5-26 28256]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-5-15 83864]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\f:\program files\live update 5\ntiolib.sys --> f:\program files\live update 5\NTIOLib.sys [?]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2012-10-22 36384]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2012-10-22 17664]
S3 RTLVLANMP;Realtek Virtual Adapter;c:\windows\system32\drivers\RTLVLAN.SYS [2012-10-22 17664]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;f:\program files\sisoftware sandra lite 2013.sp4\RpcAgentSrv.exe [2013-7-4 71832]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-5-15 181912]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-16 755880]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2013-3-23 114688]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2013-3-23 105088]
SUnknown GVTDrv;GVTDrv; [x]
.
=============== Created Last 30 ================
.
2013-08-23 19:59:27 150160 ----a-w- c:\windows\system32\WRusr.dll
2013-08-23 19:59:26 116224 ----a-w- c:\windows\system32\drivers\WRkrn.sys
2013-08-23 19:59:21 -------- d-----w- c:\program files\Webroot
2013-08-23 19:58:50 -------- d-----w- c:\documents and settings\all users\application data\WRData
2013-08-23 19:31:07 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-08-23 19:31:00 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-23 11:22:50 -------- d--h--r- c:\documents and settings\ilse\Onlangs geopend
2013-08-20 23:12:26 -------- d-----w- c:\documents and settings\ilse\local settings\application data\Logitech
2013-08-20 22:30:47 -------- d-----w- c:\program files\common files\Logitech
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-08-17 01:32:06 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-08-15 20:35:14 -------- d-----w- c:\windows\system32\MRT
.
==================== Find3M ====================
.
2013-08-23 11:31:32 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2013-07-26 02:49:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-07-26 02:48:59 43520 ------w- c:\windows\system32\licmgr10.dll
2013-07-26 02:48:59 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-07-25 20:53:17 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-25 20:53:17 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-25 15:58:11 385024 ------w- c:\windows\system32\html.iec
2013-07-10 10:37:49 406016 ----a-w- c:\windows\system32\usp10.dll
2013-07-04 07:33:59 2154496 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 07:33:59 2033152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-27 20:59:46 1091636 ----a-w- c:\windows\system32\nvdrsdb1.bin
2013-06-27 20:59:46 1 ----a-w- c:\windows\system32\nvdrssel.bin
2013-06-27 20:59:40 1091636 ----a-w- c:\windows\system32\nvdrsdb0.bin
2013-06-12 19:48:23 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-12 19:48:17 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-12 19:48:00 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-12 19:35:55 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-06-11 23:55:25 9089416 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-06-05 09:08:29 1876864 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 07:22:58 563200 ----a-w- c:\windows\system32\qedit.dll
2013-05-28 01:59:30 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2013-05-28 01:05:24 6656 ----a-w- c:\windows\system32\xpsp4res.dll
.
============= FINISH: 22:08:44,21 ===============
Comment