Ga naar inhoud

FindRight invoegtoepassing op Internet Explorer


Hensyr

Aanbevolen berichten

Beste collega's,

Bij het installeren van software heb ik domweg op accept geklikt voor het mee installeren van een ongewilde invoegtoepassing: FindRicht

Deze invoegtoepassing zou ik graag verwijderd willen zien van mijn computer.

kan iemand mij hierin helpen a.u.b.

Link naar reactie
Delen op andere sites

Download 51a5f5d096dae-icon_RSIT.pngRSIT van de onderstaande locaties en sla deze op het bureaublad op.

Hier staat een beschrijving hoe je kan kijken of je een 32- of 64-bitversie van Windows heeft.

Dubbelklik op RSIT.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Vervolgens wordt de "Disclaimer of warranty" getoond, klik vervolgens op "Continue"
  • Wanneer de tool gereed is wordt er een kladblok bestand genaamd "Log" geopend.
  • Plaats de inhoud hiervan in het volgende bericht.

Bekijk ook de instructievideo.

Link naar reactie
Delen op andere sites

Dag Kape,

hier het RSIT log:

Logfile of random's system information tool 1.09 (written by random/random)

Run by Hendrik at 2014-02-16 10:12:04

Microsoft Windows 7 Enterprise N Service Pack 1

System drive C: has 79 GB (35%) free of 227 GB

Total RAM: 4094 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 10:12:23, on 16/02/2014

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.16518)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

C:\Program Files (x86)\Internet Explorer\IELowutil.exe

C:\Users\Hendrik\AppData\Roaming\uTorrent\uTorrent.exe

C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Program Files (x86)\Windows Live\Mail\wlmail.exe

C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

C:\Program Files\trend micro\Hendrik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

O2 - BHO: (no name) - AutorunsDisabled - (no file)

O2 - BHO: FindRight - {2c774641-5504-46a8-b63f-6715ae3fe376} - C:\Program Files (x86)\FindRight\FindRightbho.dll

O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui

O4 - HKLM\..\Run: [D-Link D-Link Wireless N Dual Band DWA-160 ] C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - Startup: CurseClientStartup.ccip

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Secunia PSI Tray.lnk = ?

O9 - Extra button: (no name) - AutorunsDisabled - (no file)

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\LaunchEspresso.exe

O9 - Extra 'Tools' menuitem: HP Smart Print 2.0 - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\LaunchEspresso.exe

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: *.dexia.be

O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - Automatically Find HP Updates | HP Support

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: @%systemroot%\system32\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\Windows\system32\CISVC.EXE (file missing)

O23 - Service: D-Link Wireless N Dual Band DWA-160 _WPS Service (D-Link Wireless N Dual Band DWA-160 _WPS) - Unknown owner - C:\Program Files (x86)\D-Link\DWA-160\ANIWConnService.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe

O23 - Service: Media Jukebox 14 Service - J. River, Inc. - C:\Program Files (x86)\J River\Media Jukebox 14\JRService.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe

O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe

O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

O23 - Service: Interactive Services Detection (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Unsigned Themes (UnsignedThemes) - The Within Network, LLC - C:\Windows\UnsignedThemesSvc.exe

O23 - Service: Update FindRight - Unknown owner - C:\Program Files (x86)\FindRight\updateFindRight.exe

O23 - Service: Util FindRight - Unknown owner - C:\Program Files (x86)\FindRight\bin\utilFindRight.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 14330 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

wininit.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

winlogon.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

"C:\Windows\system32\nvvsvc.exe"

"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\UnsignedThemesSvc.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"

C:\Windows\system32\nvvsvc.exe -session -first

C:\Windows\system32\svchost.exe -k NetworkService

"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"

"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"

"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service

"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service

C:\Windows\system32\CISVC.EXE

"C:\Program Files (x86)\D-Link\DWA-160\ANIWConnService.exe"

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Windows\system32\IProsetMonitor.exe

"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"

"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS

C:\Windows\System32\svchost.exe -k HPZ12

"C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe"

"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"

"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"

"C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service

"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"

C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"

C:\Windows\system32\SearchIndexer.exe /Embedding

WLIDSvcM.exe 3236

"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0315ae4f-54dd-41dc-90d8-09ae6605b6aa -SystemEventPortName:HostProcess-083b5435-d414-407e-b18d-b74b7e6a6634 -IoCancelEventPortName:HostProcess-ecdad5d0-ea41-4484-b516-1aed5b8c9f56 -NonStateChangingEventPortName:HostProcess-cebd82d4-49c6-40fd-96d9-7f39c9ec10a6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:62752dba-87b4-49b4-80c9-08ddc9ffe729 -DeviceGroupId:WpdFsGroup

"C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe" /DisableUI

"C:\Program Files (x86)\Nero\Update\NASvc.exe"

"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c

C:\Windows\System32\svchost.exe -k secsvcs

"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe"

"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe"

"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp

\??\C:\Windows\system32\conhost.exe "158809619-6647990-130114326715506386391587201891244754937-8416343521113413682

"taskhost.exe"

"C:\Windows\system32\Dwm.exe"

C:\Windows\Explorer.EXE

"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s

"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe"

"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming

"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

"C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background

"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun

"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"

"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"

"C:\Program Files (x86)\Secunia\PSI\psi_tray.exe"

"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui

C:\Windows\system32\svchost.exe -k imgsvc

"C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe"

"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1

"C:\Users\Hendrik\AppData\Local\Apps\2.0\MN359O47.HTL\TDVPT8E9.53B\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe"

KHALMNPR.EXE /API

"C:\Program Files\Windows Media Player\wmpnetwk.exe"

"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Officejet J4500 Series#1352682878" -Startup

"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding

"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding

"C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe"

C:\Windows\system32\svchost.exe -k SDRSVC

"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding

"C:\Program Files (x86)\FindRight\updateFindRight.exe"

"C:\Users\Hendrik\AppData\Roaming\uTorrent\uTorrent.exe" "magnet:?xt=urn:btih:542b76c0ea114ec8484a3b3947251341b8f7d4e5&dn=Carrie+%282013%29+BRRip+NL+Subs+DutchReleaseTeam&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F%2Ftracker.publicbt.com%3A80&tr=udp%3A%2F%2Ftracker.istole.it%3A6969&tr=udp%3A%2F%2Ftracker.ccc.de%3A80&tr=udp%3A%2F%2Fopen.demonii.com%3A1337"

"C:\Program Files (x86)\FindRight\bin\utilFindRight.exe"

C:\Windows\system32\wbem\wmiprvse.exe

"C:\Program Files\Internet Explorer\iexplore.exe"

"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5716 CREDAT:275457 /prefetch:2

"C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe" /medium

"C:\Program Files (x86)\Windows Live\Mail\wlmail.exe"

"C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding

"C:\Program Files\Internet Explorer\iexplore.exe" Windows 7 FindRight invoegtoepassing op Internet Explorer

"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:7996 CREDAT:267521 /prefetch:2

"C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe"

C:\Windows\system32\Macromed\Flash\FlashUtil64_12_0_0_44_ActiveX.exe -Embedding

"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536

"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:7996 CREDAT:4134164 /prefetch:2

"D:\My Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

C:\Windows\tasks\AmiUpdXp.job

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

C:\Windows\tasks\Malwarebytes Anti-Exploit.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]

avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-24 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]

avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-24 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-14 256080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-11-20 6270336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2c774641-5504-46a8-b63f-6715ae3fe376}]

FindRight - C:\Program Files (x86)\FindRight\FindRightbho.dll [2014-02-14 249632]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]

RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14 542376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-02-04 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]

avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-24 1143168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-14 194128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-02-04 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-24 1390368]

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-14 256080]

{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-24 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-14 194128]

{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-24 1143168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-06-09 11860072]

"Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [2013-11-08 1028384]

"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]

"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2013-10-18 1063200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-08-19 39408]

"FileHippo.com"=C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [2012-11-23 307712]

"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]

C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-07-17 64000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]

C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2013-11-15 1861968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyDriveConnect.exe]

C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [2013-11-29 473496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-08-19 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk]

C:\PROGRA~2\Secunia\PSI\psi_tray.exe [2013-07-03 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^simplicheck.lnk]

C:\PROGRA~2\SIMPLI~1\SIMPLI~1\SIMPLI~1.EXE -timer []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Hendrik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Curse Client.lnk]

C:\Users\Hendrik\AppData\Local\Apps\2.0\QNGTC4Y9.75E\YWZ2QVZG.EQN\curs..tion_eee711038731a406_0004.0000_2bd39706d04e72c8\CurseClient.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Hendrik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]

C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Hendrik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3 .lnk]

C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]

"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-10-28 49208]

""= []

"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-01-24 3767096]

"D-Link D-Link Wireless N Dual Band DWA-160 "=C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe [2011-11-02 1078592]

"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\TkBellExe]

[]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

Secunia PSI Tray.lnk - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

CurseClientStartup.ccip

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]

c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=Windows 7 Enterprise Ultimate 64-bit ServicePack1

"legalnoticetext"=Dit is de homecomputer van Hendrik Van Marcke

Windows 7 Enterprise 64-bit SP1

Processor: Intel Core 2 Duo E7400 @ 2,80GHz

Wolfdale 45nm Technologie

Ram: 4,00 GB Dual-Kanaal DDR2 @ 332MHz (5-5-5-15)

Moederbord: Micro-Star International co., LTD MS-7502 (Socket 775)

Graphics: MD 20122 (1680x1050@59Hz)

32W_LCD_TV (1920x1080@60Hz)

512MBGeforce GT 230 (MSI)

Harde schijven: 625GB Western Digital WDC WD6400AACS-00G8B1 ATA Device (SATA)

1954GB Seagate ST32000542AS ATA Device (SATA)

Optische schijven: HL-DT-ST DVDRAM GH22NS40 ATA Device

Audio: Realtek High Definition Audio

U dient een wachtwoord in te voeren na op OK te klikken!

Welkom en succes!

Hendrik Van Marcke

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=177

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"vidc.mrle"=msrle32.dll

"vidc.msvc"=msvidc32.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msg711"=msg711.acm

"msacm.msgsm610"=msgsm32.acm

"msacm.msadpcm"=msadp32.acm

"midimapper"=midimap.dll

"wavemapper"=msacm32.drv

"VIDC.UYVY"=msyuv.dll

"VIDC.YUY2"=msyuv.dll

"VIDC.YVYU"=msyuv.dll

"VIDC.IYUV"=iyuv_32.dll

"VIDC.YVU9"=tsbyuv.dll

"msacm.l3acm"=C:\Windows\System32\l3codeca.acm

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

"aux"=wdmaud.drv

"MSVideo8"=VfWWDM32.dll

"wave1"=wdmaud.drv

"midi1"=wdmaud.drv

"mixer1"=wdmaud.drv

"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-02-16 10:12:04 ----D---- C:\rsit

2014-02-16 01:33:46 ----D---- C:\Program Files (x86)\FindRight

2014-02-13 19:05:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll

2014-02-13 19:05:21 ----A---- C:\Windows\system32\vbscript.dll

2014-02-13 19:02:58 ----A---- C:\Windows\SYSWOW64\msrating.dll

2014-02-13 19:02:58 ----A---- C:\Windows\system32\msrating.dll

2014-02-13 19:02:56 ----A---- C:\Windows\SYSWOW64\ieui.dll

2014-02-13 19:02:55 ----A---- C:\Windows\system32\ieui.dll

2014-02-13 19:02:53 ----A---- C:\Windows\system32\iernonce.dll

2014-02-13 19:02:53 ----A---- C:\Windows\system32\ieetwcollectorres.dll

2014-02-13 19:02:53 ----A---- C:\Windows\system32\ie4uinit.exe

2014-02-13 19:02:52 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

2014-02-13 19:02:52 ----A---- C:\Windows\system32\msfeeds.dll

2014-02-13 19:02:52 ----A---- C:\Windows\system32\jsproxy.dll

2014-02-13 19:02:51 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

2014-02-13 19:02:51 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe

2014-02-13 19:02:51 ----A---- C:\Windows\SYSWOW64\iesetup.dll

2014-02-13 19:02:51 ----A---- C:\Windows\system32\ieUnatt.exe

2014-02-13 19:02:50 ----A---- C:\Windows\SYSWOW64\iernonce.dll

2014-02-13 19:02:50 ----A---- C:\Windows\system32\iesetup.dll

2014-02-13 19:02:49 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll

2014-02-13 19:02:49 ----A---- C:\Windows\system32\ieetwproxystub.dll

2014-02-13 19:02:49 ----A---- C:\Windows\system32\ieetwcollector.exe

2014-02-13 19:02:48 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll

2014-02-13 19:02:48 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll

2014-02-13 19:02:48 ----A---- C:\Windows\system32\mshtml.dll

2014-02-13 19:02:48 ----A---- C:\Windows\system32\jscript9diag.dll

2014-02-13 19:02:48 ----A---- C:\Windows\system32\ieapfltr.dll

2014-02-13 19:02:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll

2014-02-13 19:02:47 ----A---- C:\Windows\system32\iertutil.dll

2014-02-13 19:02:46 ----A---- C:\Windows\SYSWOW64\wininet.dll

2014-02-13 19:02:46 ----A---- C:\Windows\SYSWOW64\urlmon.dll

2014-02-13 19:02:46 ----A---- C:\Windows\system32\wininet.dll

2014-02-13 19:02:46 ----A---- C:\Windows\system32\urlmon.dll

2014-02-13 19:02:43 ----A---- C:\Windows\system32\ieframe.dll

2014-02-13 19:02:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll

2014-02-13 19:02:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll

2014-02-13 19:02:40 ----A---- C:\Windows\SYSWOW64\jscript9.dll

2014-02-13 19:02:40 ----A---- C:\Windows\system32\jscript9.dll

2014-02-13 01:26:39 ----A---- C:\Windows\SYSWOW64\msxml3r.dll

2014-02-13 01:26:39 ----A---- C:\Windows\SYSWOW64\msxml3.dll

2014-02-13 01:26:39 ----A---- C:\Windows\system32\msxml3r.dll

2014-02-13 01:26:39 ----A---- C:\Windows\system32\msxml3.dll

2014-02-13 01:26:29 ----A---- C:\Windows\system32\RMActivate_isv.exe

2014-02-13 01:26:29 ----A---- C:\Windows\system32\RMActivate.exe

2014-02-13 01:26:28 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe

2014-02-13 01:26:28 ----A---- C:\Windows\SYSWOW64\RMActivate.exe

2014-02-13 01:26:26 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe

2014-02-13 01:26:22 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe

2014-02-13 01:26:22 ----A---- C:\Windows\system32\RMActivate_ssp.exe

2014-02-13 01:26:21 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe

2014-02-13 01:26:21 ----A---- C:\Windows\system32\secproc_isv.dll

2014-02-13 01:26:20 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll

2014-02-13 01:26:20 ----A---- C:\Windows\SYSWOW64\secproc.dll

2014-02-13 01:26:20 ----A---- C:\Windows\SYSWOW64\msdrm.dll

2014-02-13 01:26:20 ----A---- C:\Windows\system32\secproc_ssp_isv.dll

2014-02-13 01:26:20 ----A---- C:\Windows\system32\secproc_ssp.dll

2014-02-13 01:26:20 ----A---- C:\Windows\system32\secproc.dll

2014-02-13 01:26:20 ----A---- C:\Windows\system32\msdrm.dll

2014-02-13 01:26:19 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll

2014-02-13 01:26:19 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll

2014-02-13 01:25:52 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll

2014-02-13 01:25:52 ----A---- C:\Windows\system32\d3d10warp.dll

2014-02-13 01:25:51 ----A---- C:\Windows\SYSWOW64\d2d1.dll

2014-02-13 01:25:51 ----A---- C:\Windows\system32\d2d1.dll

2014-02-11 06:33:23 ----D---- C:\Program Files\VideoLAN

2014-02-07 13:17:49 ----D---- C:\Program Files (x86)\Toolbar Cleaner

2014-02-05 14:59:07 ----A---- C:\Users\Hendrik\AppData\Roaming\burnaware.ini

2014-02-04 14:24:29 ----A---- C:\Windows\SYSWOW64\javaws.exe

2014-02-04 14:24:21 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll

2014-02-04 14:24:21 ----A---- C:\Windows\SYSWOW64\javaw.exe

2014-02-04 14:24:21 ----A---- C:\Windows\SYSWOW64\java.exe

2014-02-04 14:24:00 ----D---- C:\Program Files (x86)\Java

2014-01-31 21:55:15 ----D---- C:\ProgramData\WarThunder

2014-01-31 21:55:02 ----D---- C:\Program Files (x86)\WarThunder

2014-01-26 03:02:27 ----D---- C:\ProgramData\regid.1991-06.com.microsoft

2014-01-26 02:48:21 ----D---- C:\Program Files (x86)\MSECache

2014-01-26 02:15:59 ----D---- C:\Users\Hendrik\AppData\Roaming\AutoCAD DWG to Image Converter

2014-01-23 02:13:22 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

2014-01-20 22:01:18 ----D---- C:\Program Files (x86)\Edraw Max 6

2014-01-20 16:45:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

2014-01-19 20:26:48 ----D---- C:\Program Files\Recuva

======List of files/folders modified in the last 1 month======

2014-02-16 10:12:12 ----D---- C:\Windows\Temp

2014-02-16 10:12:10 ----D---- C:\Program Files\trend micro

2014-02-16 10:11:07 ----D---- C:\Users\Hendrik\AppData\Roaming\uTorrent

2014-02-16 06:17:30 ----D---- C:\Windows\system32\config

2014-02-16 01:48:15 ----D---- C:\Program Files (x86)\SciLor's grooveshark.com Downloader

2014-02-16 01:47:42 ----D---- C:\Windows\Tasks

2014-02-16 01:47:42 ----D---- C:\Windows\system32\Tasks

2014-02-16 01:33:46 ----RD---- C:\Program Files (x86)

2014-02-14 16:29:07 ----D---- C:\Windows\Prefetch

2014-02-13 21:04:10 ----D---- C:\ProgramData\NVIDIA

2014-02-13 20:59:14 ----D---- C:\Windows\system32\MRT

2014-02-13 20:54:59 ----A---- C:\Windows\system32\MRT.exe

2014-02-13 20:54:41 ----SHD---- C:\System Volume Information

2014-02-13 20:07:51 ----D---- C:\Windows\Microsoft.NET

2014-02-13 19:59:08 ----RSD---- C:\Windows\assembly

2014-02-13 19:33:21 ----D---- C:\Windows\winsxs

2014-02-13 19:21:09 ----D---- C:\Windows\SysWOW64

2014-02-13 19:21:09 ----D---- C:\Windows\System32

2014-02-13 19:20:57 ----D---- C:\Windows\SYSWOW64\pt-BR

2014-02-13 19:20:57 ----D---- C:\Windows\SYSWOW64\bg-BG

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\uk-UA

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\pt-PT

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\pl-PL

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\ko-KR

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\it-IT

2014-02-13 19:20:56 ----D---- C:\Windows\SYSWOW64\he-IL

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\sl-SI

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\nl-NL

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\hu-HU

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\hr-HR

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\fr-FR

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\fi-FI

2014-02-13 19:20:55 ----D---- C:\Windows\SYSWOW64\el-GR

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\tr-TR

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\th-TH

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\sv-SE

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\lv-LV

2014-02-13 19:20:54 ----D---- C:\Windows\SYSWOW64\es-ES

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\zh-TW

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\zh-CN

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\sk-SK

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\lt-LT

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\ja-JP

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\et-EE

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\de-DE

2014-02-13 19:20:53 ----D---- C:\Windows\SYSWOW64\cs-CZ

2014-02-13 19:20:52 ----D---- C:\Windows\SYSWOW64\ru-RU

2014-02-13 19:20:52 ----D---- C:\Windows\SYSWOW64\ro-RO

2014-02-13 19:20:52 ----D---- C:\Windows\SYSWOW64\ar-SA

2014-02-13 19:20:51 ----D---- C:\Windows\SYSWOW64\nb-NO

2014-02-13 19:20:51 ----D---- C:\Windows\SYSWOW64\da-DK

2014-02-13 19:20:50 ----D---- C:\Windows\SYSWOW64\en-US

2014-02-13 19:20:46 ----D---- C:\Windows\system32\pt-BR

2014-02-13 19:20:46 ----D---- C:\Windows\system32\it-IT

2014-02-13 19:20:46 ----D---- C:\Windows\system32\bg-BG

2014-02-13 19:20:45 ----D---- C:\Windows\system32\uk-UA

2014-02-13 19:20:45 ----D---- C:\Windows\system32\pt-PT

2014-02-13 19:20:45 ----D---- C:\Windows\system32\pl-PL

2014-02-13 19:20:45 ----D---- C:\Windows\system32\he-IL

2014-02-13 19:20:44 ----D---- C:\Windows\system32\ko-KR

2014-02-13 19:20:43 ----D---- C:\Windows\system32\sl-SI

2014-02-13 19:20:43 ----D---- C:\Windows\system32\nl-NL

2014-02-13 19:20:43 ----D---- C:\Windows\system32\hu-HU

2014-02-13 19:20:43 ----D---- C:\Windows\system32\hr-HR

2014-02-13 19:20:43 ----D---- C:\Windows\system32\fr-FR

2014-02-13 19:20:43 ----D---- C:\Windows\system32\el-GR

2014-02-13 19:20:42 ----D---- C:\Windows\system32\tr-TR

2014-02-13 19:20:42 ----D---- C:\Windows\system32\th-TH

2014-02-13 19:20:42 ----D---- C:\Windows\system32\sv-SE

2014-02-13 19:20:42 ----D---- C:\Windows\system32\sr-Latn-CS

2014-02-13 19:20:42 ----D---- C:\Windows\system32\fi-FI

2014-02-13 19:20:41 ----D---- C:\Windows\system32\zh-TW

2014-02-13 19:20:41 ----D---- C:\Windows\system32\sk-SK

2014-02-13 19:20:41 ----D---- C:\Windows\system32\lv-LV

2014-02-13 19:20:41 ----D---- C:\Windows\system32\lt-LT

2014-02-13 19:20:41 ----D---- C:\Windows\system32\es-ES

2014-02-13 19:20:40 ----D---- C:\Windows\system32\et-EE

2014-02-13 19:20:40 ----D---- C:\Windows\system32\de-DE

2014-02-13 19:20:40 ----D---- C:\Windows\system32\cs-CZ

2014-02-13 19:20:39 ----D---- C:\Windows\system32\zh-CN

2014-02-13 19:20:39 ----D---- C:\Windows\system32\ja-JP

2014-02-13 19:20:39 ----D---- C:\Windows\system32\ar-SA

2014-02-13 19:20:38 ----D---- C:\Windows\system32\ru-RU

2014-02-13 19:20:38 ----D---- C:\Windows\system32\ro-RO

2014-02-13 19:20:37 ----D---- C:\Windows\system32\nb-NO

2014-02-13 19:20:37 ----D---- C:\Windows\system32\da-DK

2014-02-13 19:20:36 ----D---- C:\Windows\system32\en-US

2014-02-13 19:20:09 ----D---- C:\Program Files (x86)\Internet Explorer

2014-02-13 19:20:08 ----D---- C:\Program Files\Internet Explorer

2014-02-13 19:17:22 ----SHD---- C:\Windows\Installer

2014-02-13 19:17:21 ----D---- C:\Config.Msi

2014-02-13 19:09:06 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI

2014-02-13 19:09:00 ----D---- C:\Windows\inf

2014-02-13 19:08:48 ----A---- C:\Windows\system32\PerfStringBackup.INI

2014-02-13 19:06:59 ----D---- C:\Windows\system32\catroot

2014-02-13 19:04:31 ----D---- C:\Windows\system32\catroot2

2014-02-13 15:40:35 ----RD---- C:\Program Files (x86)\Skype

2014-02-13 15:40:21 ----D---- C:\ProgramData\Skype

2014-02-13 15:40:21 ----D---- C:\Program Files (x86)\Mozilla Firefox

2014-02-12 15:54:46 ----D---- C:\Program Files\WinRAR

2014-02-11 15:08:35 ----D---- C:\Program Files (x86)\Edraw Max 5

2014-02-11 07:15:25 ----D---- C:\Program Files (x86)\VideoLAN

2014-02-11 06:38:16 ----RD---- C:\Program Files

2014-02-11 06:38:07 ----D---- C:\Windows\system32\drivers

2014-02-11 06:23:29 ----D---- C:\Windows\system32\wbem

2014-02-09 23:08:50 ----D---- C:\Windows\SYSWOW64\directx

2014-02-07 17:22:55 ----D---- C:\Program Files\Defraggler

2014-02-07 17:20:32 ----D---- C:\Program Files (x86)\OpenOffice 4

2014-02-07 17:18:18 ----RSD---- C:\Windows\Fonts

2014-02-05 14:59:09 ----D---- C:\Program Files (x86)\BurnAware Free

2014-02-04 14:26:35 ----D---- C:\ProgramData\Oracle

2014-02-04 14:25:46 ----D---- C:\Program Files (x86)\Common Files

2014-02-04 13:52:17 ----D---- C:\Program Files\Java

2014-02-03 17:35:51 ----D---- C:\Users\Hendrik\AppData\Roaming\Nitro PDF

2014-02-03 17:35:12 ----D---- C:\Program Files\Speccy

2014-01-31 21:55:15 ----D---- C:\ProgramData

2014-01-31 20:39:52 ----D---- C:\Program Files (x86)\Steam

2014-01-26 14:42:40 ----D---- C:\Program Files\Common Files\Microsoft Shared

2014-01-26 03:02:27 ----D---- C:\Program Files (x86)\Microsoft Office

2014-01-26 03:02:26 ----D---- C:\Program Files\Microsoft Office

2014-01-26 02:57:05 ----D---- C:\Windows\Minidump

2014-01-26 02:57:05 ----D---- C:\Windows

2014-01-24 19:10:46 ----A---- C:\Windows\system32\aswBoot.exe

2014-01-24 19:04:54 ----D---- C:\Program Files\CCleaner

2014-01-24 19:04:01 ----D---- C:\Users\Hendrik\AppData\Roaming\Skype

2014-01-24 18:57:29 ----D---- C:\Windows\rescache

2014-01-23 15:32:43 ----D---- C:\Windows\debug

2014-01-23 02:15:26 ----D---- C:\Users\Hendrik\AppData\Roaming\Mozilla

2014-01-20 10:59:19 ----D---- C:\Program Files (x86)\EASEUS

2014-01-18 14:44:56 ----D---- C:\Windows\SYSWOW64\Macromed

2014-01-18 12:11:02 ----D---- C:\Program Files (x86)\Battle.net

2014-01-18 12:10:26 ----D---- C:\Program Files\Malwarebytes Anti-Exploit

2014-01-17 00:57:09 ----A---- C:\Users\Hendrik\AppData\Roaming\CamShapes.ini

2014-01-17 00:57:09 ----A---- C:\Users\Hendrik\AppData\Roaming\CamLayout.ini

2014-01-17 00:57:09 ----A---- C:\Users\Hendrik\AppData\Roaming\Camdata.ini

2014-01-17 00:00:21 ----D---- C:\Users\Hendrik\AppData\Roaming\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-21 65776]

R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-12-25 207904]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]

R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]

R1 anodlwf;ANOD Network Security Filter driver; C:\Windows\system32\DRIVERS\anodlwfx.sys [2010-05-29 15872]

R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-21 92544]

R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2014-01-24 1038072]

R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2014-01-24 421704]

R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]

R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2013-03-04 40344]

R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files\Malwarebytes Anti-Exploit\MBAE.sys [2013-12-17 62168]

R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]

R1 SAS***IL;SAS***IL; \??\C:\Program Files\SUPERAntiSpyware\SAS***IL64.SYS [2011-07-12 12368]

R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2013-06-21 238352]

R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2013-06-21 120080]

R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2014-01-24 78648]

R2 cpuz135;cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]

R2 uxpatch;uxpatch; \??\C:\Windows\system32\drivers\uxpatch.sys [2009-07-13 30568]

R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2014-01-24 80184]

R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]

R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]

R3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]

R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032e.sys [2009-06-10 278016]

R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-06-14 2899176]

R3 L8042Kbd;SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2011-09-02 32536]

R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]

R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]

R3 netr28ux;D-Link dnetr28u USB Extensible Wireless LAN Card Driver; C:\Windows\system32\DRIVERS\Dnetr28ux.sys [2011-09-09 1660480]

R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-09-28 39200]

R3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf_amd64.sys [2013-07-03 18456]

R3 usbscan;USB Scanner Driver; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]

R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2013-06-21 146704]

R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2013-03-11 36352]

S2 supersafer64;supersafer64; \??\C:\Windows\SysWOW64\drivers\supersafer64.sys []

S3 Afc;PPdus ASPI Shell; C:\Windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]

S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]

S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]

S3 hitmanpro37;HitmanPro 3.7 Support Driver; \??\C:\Windows\system32\drivers\hitmanpro37.sys [2013-08-15 32000]

S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 255552]

S3 OV550I;OVT Scanner; C:\Windows\System32\Drivers\ov550ivx.sys [2008-02-21 196992]

S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]

S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]

S3 RTL8192cu;Belkin Wireless Adapter; C:\Windows\system32\DRIVERS\rtwlanu.sys [2012-02-01 1041000]

S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2010-09-29 695400]

S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]

S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]

S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]

S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-05-10 51712]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2013-06-21 131856]

S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []

S4 A2DDA;A2 Direct Disk Access Support Driver; \??\D:\My Desktop\Bleeping computer\EmisoftEmergencyKit\Run\a2ddax64.sys []

S4 catchme;catchme; \??\C:\ComboFix\catchme.sys []

S4 cpuz134;cpuz134; \??\C:\Program Files (x86)\CPUID\PC Wizard 2010\pcwiz_x64.sys []

S4 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []

S4 RsFx0105;RsFx0105 Driver; C:\Windows\system32\DRIVERS\RsFx0105.sys [2011-09-22 311144]

S4 rt61x64;Linksys Wireless-G PCI Adapter Driver; C:\Windows\system32\DRIVERS\WMP54Gv41x64.sys []

S4 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []

S4 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []

S4 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-05-23 143120]

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-01-24 50344]

R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-01-03 1363616]

R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-01-03 1748640]

R2 CISVC;@%systemroot%\system32\CISVC.EXE,-1; C:\Windows\system32\CISVC.EXE [2009-07-14 19456]

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]

R2 D-Link Wireless N Dual Band DWA-160 _WPS;D-Link Wireless N Dual Band DWA-160 _WPS Service; C:\Program Files (x86)\D-Link\DWA-160\ANIWConnService.exe [2010-07-12 53248]

R2 Fabs;FABS - Helping agent for MAGIX media database; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-05-24 1840128]

R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2009-07-14 27136]

R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2013-02-23 183048]

R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]

R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-09-22 58345832]

R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432]

R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]

R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [2013-06-18 230416]

R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-11-08 15125280]

R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-23 922912]

R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]

R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-08-14 39056]

R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]

R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [2013-07-03 1228504]

R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2011-09-22 154984]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-10-23 414496]

R2 UnsignedThemes;Unsigned Themes; C:\Windows\UnsignedThemesSvc.exe [2009-07-13 24168]

R2 Update FindRight;Update FindRight; C:\Program Files (x86)\FindRight\updateFindRight.exe [2014-02-14 80672]

R2 Util FindRight;Util FindRight; C:\Program Files (x86)\FindRight\bin\utilFindRight.exe [2014-02-16 80672]

R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]

S2 gupdate;Google Updateservice (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-19 136176]

S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-11-08 1914656]

S2 Secunia Update Agent;Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [2013-07-03 660184]

S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05 257928]

S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]

S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]

S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]

S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848]

S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-19 136176]

S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-11 194032]

S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]

S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]

S3 Media Jukebox 14 Service;Media Jukebox 14 Service; C:\Program Files (x86)\J River\Media Jukebox 14\JRService.exe [2010-07-15 379400]

S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-01-28 118896]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-10-30 566696]

S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]

S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

S4 cbVSCService11;Cobian Backup 11 Volume Shadow Copy Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-06-29 67584]

S4 CTDevice_Srv;CT Device Query service; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [2007-04-02 61440]

S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]

S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-22 431464]

S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie).

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  {2c774641-5504-46a8-b63f-6715ae3fe376};c
 C:\Program Files (x86)\FindRight;fs
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501};c
 Update FindRight;s
 Util FindRight;s
 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled];r64
 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2c774641-5504-46a8-b63f-6715ae3fe376}];r64
 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run];r64
 ""=-;r64
 autoclean;

  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Dag Kape,

Hierbij het zoek-result.log:

Zoek.exe v5.0.0.0 Updated 15-February-2014

Tool run by Hendrik on zo 16/02/2014 at 14:59:32,09.

Microsoft Windows 7 Enterprise N 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: D:\My Desktop\zoek.exe [scan all users] [script inserted]

==== System Restore Info ======================

16/02/2014 15:03:53 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1364749199-3237543244-4035560231-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2c774641-5504-46a8-b63f-6715ae3fe376} deleted successfully

HKEY_USERS\S-1-5-21-1364749199-3237543244-4035560231-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2c774641-5504-46a8-b63f-6715ae3fe376} deleted successfully

HKEY_USERS\S-1-5-21-1364749199-3237543244-4035560231-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2c774641-5504-46a8-b63f-6715ae3fe376} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2c774641-5504-46a8-b63f-6715ae3fe376} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update FindRight deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update FindRight deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util FindRight deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util FindRight deleted successfully

==== Registry Fix Code x64 ======================

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2c774641-5504-46a8-b63f-6715ae3fe376}]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

""=-

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Toolbar Cleaner deleted

C:\Users\Hendrik\AppData\Roaming\burnaware.ini deleted

C:\Users\Hendrik\AppData\Local\SwvUpdater deleted

C:\Windows\tasks\AmiUpdXp.job deleted

C:\windows\SysNative\tasks\AmiUpdXp deleted

C:\END deleted

"C:\Program Files (x86)\FindRight\updateFindRight.exe" deleted

"C:\PROGRA~2\FindRight\updateFindRight.exe" deleted

"C:\Program Files (x86)\FindRight\bin\utilFindRight.exe" deleted

"C:\PROGRA~2\FindRight\bin\utilFindRight.exe" deleted

"C:\Program Files (x86)\FindRight" not deleted

"C:\PROGRA~2\FindRight" not deleted

"C:\Program Files (x86)\FindRight\bin" not deleted

"C:\PROGRA~2\FindRight\bin" not deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]

"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [29/08/2013 14:58]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Hendrik\AppData\Roaming\Mozilla\Profiles\2nh8u0b4.Hendrik

- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

- Quick Translator - %ProfilePath%\extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox

- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[14/08/2013 14:24]

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Test account 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\Local Settings\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\Local Settings\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Temporary Internet Files\Content.IE5\75EVWQM4 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Temporary Internet Files\Content.IE5\Q1YC0EF2 will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\container.dat will be deleted at reboot

C:\Users\Hendrik\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=311 folders=42 12473830 bytes)

==== Empty Temp Folders ======================

C:\Users\AppData\AppData\Local\Temp emptied successfully

C:\Users\Default\AppData\Local\Temp emptied successfully

C:\Users\Default User\AppData\Local\Temp emptied successfully

C:\Users\Public\AppData\Local\Temp emptied successfully

C:\Users\Test account 1\AppData\Local\Temp emptied successfully

C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

C:\Users\Hendrik\AppData\Local\Temp will be emptied at reboot

C:\Windows\Temp will be emptied at reboot

- - - Updated - - -

De invoegtoepassing FindRight is verwijderd van het systeem.

Waarvoor mijn hartelijke dank.

Link naar reactie
Delen op andere sites

Download 52147fb3b2536-AdwCleaner_99_3_16x16x32.pngAdwCleaner by Xplode naar het bureaublad.

AdwCleaner uitvoeren

  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik vervolgens op de knop Scan.
  • Wanneer de scan gereed is Klikt u vervolgens op de knop Clean.
  • Als dit gereed is wordt er gevraagd om de computer opnieuw op te starten, klik hier op OK.
  • Nadat de computer opnieuw is opgestart wordt het logbestand automatisch geopend.
  • Plaats dit logbestand in het volgende bericht.

Link naar reactie
Delen op andere sites

Dag Kape,

Hier is het AdwCleaner log:

# AdwCleaner v3.018 - Report created 16/02/2014 at 18:45:17

# Updated 28/01/2014 by Xplode

# Operating System : Windows 7 Enterprise N Service Pack 1 (64 bits)

# Username : Hendrik - HENDRIK-W7-ENTE

# Running from : D:\My Desktop\adwcleaner.exe

# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Toolbar Cleaner

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd

Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

Key Deleted : HKCU\Software\Conduit

Key Deleted : HKCU\Software\InstallCore

Key Deleted : HKLM\Software\Toolbar Cleaner

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518

*************************

AdwCleaner[R0].txt - [2859 octets] - [16/02/2014 18:44:08]

AdwCleaner[s0].txt - [2726 octets] - [16/02/2014 18:45:17]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [2786 octets] ##########

Link naar reactie
Delen op andere sites

Prima ... dan mag je aan de opruiming van de gebruikte tools en restjes beginnen:

Download 51a5ce45263de-delfix.pngDelfix by Xplode naar het bureaublad.

Dubbelklik op Delfix.exe om de tool te starten.

Zet nu vinkjes voor de volgende items:

  • Remove disinfection tools
  • Purge System Restore
  • Reset system settings

Klik nu op "Run" en wacht geduldig tot de tool gereed is.

Wanneer de tool gereed is wordt er een logbestand aangemaakt. Dit hoeft u echter niet te plaatsen.

Download CCleaner. (Als je het nog niet hebt)

Installeer het (als je niet wilt dat Google Chrome op je PC als standaard-webbrowser wordt geïnstalleerd, moet je de 2 vinkjes wegdoen !!!) en start CCleaner op.

Klik in de linkse kolom op “Cleaner”.

Klik achtereenvolgens op ‘Analyseren’ en na de analyse op 'Schoonmaken'.

Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”.

Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”.

Dan krijg je de vraag om een back-up te maken. Klik op “JA”.

Kies dan “Herstel alle geselecteerde fouten”.

Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft.

Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Indien dit allemaal probleemloos verlopen is en je binnen dit topic verder geen vragen of problemen meer hebt, mag je dit onderwerp afsluiten door een klik op de knop "Markeer als opgelost", die je links onderaan kan terugvinden … zo blijft het voor iedereen overzichtelijk.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.