Ga naar inhoud

Conduit search aartemis


Aanbevolen berichten

Ik heb gisteren per ongeluk de adware variant conduit search aartemis binnen gehaald op mijn pc. Op internet explorer en chrome merk ik er niks meer van. Alles is oké daar en in de invoegtoepassingen beheren bij de zoekmachines als bij de extensies op google chrome kom ik geen schadelijke software tegen. Heb ADW Cleaner erop losgelaten en de Junkware Removal Tool en Malwarebytes. Alleen kom ik in het hijack this logje nog steeds aartemis tegen bij R1. Ik heb op fix geklikt maar hij blijft er steeds in staan iemand een idee? Misschien hijack this verkeerd gedownload? Heb het via deze site Download HiJackThis from SourceForge.net

Logfile of HijackThis v1.99.1

Scan saved at 20:02:18, on 15-2-2014

Platform: Unknown Windows (WinNT 6.01.3505 SP1)

MSIE: Internet Explorer v11.0 (11.00.9600.16518)

Running processes:

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Gebruike\Downloads\hijackthis (3).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: ThreeShips IEHelper - {17FDB9F8-DCC4-4F6A-AE07-B16018A48469} - C:\Program Files (x86)\Common Files\Threeships Shared\DLL\ThreeShipsIEHelper.dll

O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - (no file)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [ChicaPasswordManager] "C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe" /autorunned

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O11 - Options group: [iNTERNATIONAL] International

O13 - Gopher Prefix:

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc (file missing)

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe (file missing)

Link naar reactie
Delen op andere sites

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: ThreeShips IEHelper - {17FDB9F8-DCC4-4F6A-AE07-B16018A48469} - C:\Program Files (x86)\Common Files\Threeships Shared\DLL\ThreeShipsIEHelper.dll

O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - (no file)

Klik op 'Fix checked' om de items te verwijderen.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.

Download 51a5f5d096dae-icon_RSIT.pngRSIT van de onderstaande locaties en sla deze op het bureaublad op.

Hier staat een beschrijving hoe je kan kijken of je een 32- of 64-bitversie van Windows heeft.

Dubbelklik op RSIT.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Vervolgens wordt de "Disclaimer of warranty" getoond, klik vervolgens op "Continue"
  • Wanneer de tool gereed is wordt er een kladblok bestand genaamd "Log" geopend.
  • Plaats de inhoud hiervan in het volgende bericht.

Bekijk ook de instructievideo.

Link naar reactie
Delen op andere sites

Hierbij de uitslag

gfile of random's system information tool 1.09 (written by random/random)

Run by Gebruike at 2014-02-15 21:40:50

Microsoft Windows 7 Home Premium Service Pack 1

System drive C: has 276 GB (59%) free of 467 GB

Total RAM: 7914 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 21:40:53, on 15-2-2014

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.16518)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files\trend micro\Gebruike.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [ChicaPasswordManager] "C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe" /autorunned

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 7383 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

wininit.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

winlogon.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k NetworkService

atieclxx

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService

"taskhost.exe"

"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"

"C:\Windows\system32\Dwm.exe"

C:\Windows\Explorer.EXE

C:\Windows\system32\svchost.exe -k imgsvc

"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"

WLIDSvcM.exe 2044

taskeng.exe {2DBC38D4-F2EE-402B-933B-4306D60C9B37}

"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe"

"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe"

"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6d3ef1d9-4d27-4ca1-938d-edb6bc70d5b2 -SystemEventPortName:HostProcess-01ae59c4-7ece-4e70-946c-a69347cc41ce -IoCancelEventPortName:HostProcess-0326e5dd-561a-4825-96ec-8ef3d04ca1df -NonStateChangingEventPortName:HostProcess-c0a7838a-f41e-4c87-8763-dd3b0627db49 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9d61d06f-d0fb-40cc-895a-b1a0869426e9 -DeviceGroupId:WpdFsGroup

C:\Windows\system32\SearchIndexer.exe /Embedding

"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3796.0.702182520\869225046" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,13,23 --gpu-vendor-id=0x1002 --gpu-device-id=0x6759 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/DeferBackgroundExtensionCreation/RateLimited/EmbeddedSearch/Group2 pct:10b stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ManagedModeLaunch/Active/OmniboxBundledExperimentV1/StandardR2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="3796.3.1214660972\830765951" /prefetch:673131151

C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\system32\sppsvc.exe

C:\Windows\System32\svchost.exe -k secsvcs

"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524

"C:\Users\Gebruike\Downloads\RSITx64.exe"

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000Core.job

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000UA.job

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]

SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"ChicaPasswordManager"=C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe /autorunned []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]

C:\Users\Gebruike\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-03 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload]

C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-04-23 1561968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]

C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-04-23 311152]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]

"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoActiveDesktop"=1

"NoActiveDesktopChanges"=1

"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"vidc.mrle"=msrle32.dll

"vidc.msvc"=msvidc32.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msg711"=msg711.acm

"msacm.msgsm610"=msgsm32.acm

"msacm.msadpcm"=msadp32.acm

"midimapper"=midimap.dll

"wavemapper"=msacm32.drv

"vidc.uyvy"=msyuv.dll

"vidc.yuy2"=msyuv.dll

"vidc.yvyu"=msyuv.dll

"vidc.iyuv"=iyuv_32.dll

"vidc.i420"=iyuv_32.dll

"vidc.yvu9"=tsbyuv.dll

"msacm.l3acm"=C:\Windows\System32\l3codeca.acm

"wave1"=wdmaud.drv

"midi1"=wdmaud.drv

"mixer1"=wdmaud.drv

"aux1"=wdmaud.drv

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

"aux"=wdmaud.drv

"wave2"=wdmaud.drv

"midi2"=wdmaud.drv

"mixer2"=wdmaud.drv

"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2014-02-15 21:40:51 ----D---- C:\Program Files\trend micro

2014-02-15 21:40:50 ----D---- C:\rsit

2014-02-15 19:50:13 ----D---- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs

2014-02-15 16:36:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll

2014-02-15 16:36:48 ----A---- C:\Windows\system32\vbscript.dll

2014-02-15 16:36:07 ----A---- C:\Windows\SYSWOW64\msrating.dll

2014-02-15 16:36:07 ----A---- C:\Windows\SYSWOW64\ieui.dll

2014-02-15 16:36:07 ----A---- C:\Windows\system32\msrating.dll

2014-02-15 16:36:07 ----A---- C:\Windows\system32\ieui.dll

2014-02-15 16:36:06 ----A---- C:\Windows\system32\iernonce.dll

2014-02-15 16:36:06 ----A---- C:\Windows\system32\ieetwcollectorres.dll

2014-02-15 16:36:06 ----A---- C:\Windows\system32\ie4uinit.exe

2014-02-15 16:36:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

2014-02-15 16:36:05 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

2014-02-15 16:36:05 ----A---- C:\Windows\system32\msfeeds.dll

2014-02-15 16:36:05 ----A---- C:\Windows\system32\jsproxy.dll

2014-02-15 16:36:04 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe

2014-02-15 16:36:04 ----A---- C:\Windows\SYSWOW64\iesetup.dll

2014-02-15 16:36:04 ----A---- C:\Windows\SYSWOW64\iernonce.dll

2014-02-15 16:36:04 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll

2014-02-15 16:36:04 ----A---- C:\Windows\system32\mshtml.dll

2014-02-15 16:36:04 ----A---- C:\Windows\system32\ieUnatt.exe

2014-02-15 16:36:04 ----A---- C:\Windows\system32\iesetup.dll

2014-02-15 16:36:04 ----A---- C:\Windows\system32\ieetwproxystub.dll

2014-02-15 16:36:04 ----A---- C:\Windows\system32\ieetwcollector.exe

2014-02-15 16:36:03 ----A---- C:\Windows\SYSWOW64\wininet.dll

2014-02-15 16:36:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll

2014-02-15 16:36:03 ----A---- C:\Windows\SYSWOW64\iertutil.dll

2014-02-15 16:36:03 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll

2014-02-15 16:36:03 ----A---- C:\Windows\system32\jscript9diag.dll

2014-02-15 16:36:03 ----A---- C:\Windows\system32\iertutil.dll

2014-02-15 16:36:03 ----A---- C:\Windows\system32\ieapfltr.dll

2014-02-15 16:36:02 ----A---- C:\Windows\SYSWOW64\urlmon.dll

2014-02-15 16:36:02 ----A---- C:\Windows\system32\wininet.dll

2014-02-15 16:36:02 ----A---- C:\Windows\system32\urlmon.dll

2014-02-15 16:36:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll

2014-02-15 16:36:01 ----A---- C:\Windows\system32\ieframe.dll

2014-02-15 16:36:00 ----A---- C:\Windows\SYSWOW64\mshtml.dll

2014-02-15 16:36:00 ----A---- C:\Windows\SYSWOW64\jscript9.dll

2014-02-15 16:35:59 ----A---- C:\Windows\system32\jscript9.dll

2014-02-14 21:37:15 ----D---- C:\Windows\ERUNT

2014-02-14 21:10:37 ----A---- C:\Windows\system32\FNTCACHE.DAT

2014-02-14 21:07:12 ----D---- C:\AdwCleaner

2014-02-14 20:41:47 ----D---- C:\Users\Gebruike\AppData\Roaming\Anvisoft

2014-02-14 20:41:39 ----D---- C:\ProgramData\Anvisoft

2014-02-14 20:41:37 ----D---- C:\Program Files (x86)\Anvisoft

2014-02-14 20:16:32 ----A---- C:\autoexec.bat

2014-02-14 20:16:10 ----D---- C:\Program Files\Enigma Software Group

2014-02-14 20:15:40 ----D---- C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\secproc.dll

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe

2014-02-12 19:20:12 ----A---- C:\Windows\SYSWOW64\msdrm.dll

2014-02-12 19:20:12 ----A---- C:\Windows\system32\secproc_isv.dll

2014-02-12 19:20:12 ----A---- C:\Windows\system32\secproc.dll

2014-02-12 19:20:12 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe

2014-02-12 19:20:12 ----A---- C:\Windows\system32\RMActivate_ssp.exe

2014-02-12 19:20:12 ----A---- C:\Windows\system32\RMActivate_isv.exe

2014-02-12 19:20:12 ----A---- C:\Windows\system32\RMActivate.exe

2014-02-12 19:20:12 ----A---- C:\Windows\system32\msdrm.dll

2014-02-12 19:20:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll

2014-02-12 19:20:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll

2014-02-12 19:20:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll

2014-02-12 19:20:11 ----A---- C:\Windows\system32\secproc_ssp.dll

2014-02-12 19:20:02 ----A---- C:\Windows\SYSWOW64\mstscax.dll

2014-02-12 19:20:02 ----A---- C:\Windows\system32\mstscax.dll

2014-02-12 19:19:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll

2014-02-12 19:19:47 ----A---- C:\Windows\SYSWOW64\d2d1.dll

2014-02-12 19:19:47 ----A---- C:\Windows\system32\d3d10warp.dll

2014-02-12 19:19:47 ----A---- C:\Windows\system32\d2d1.dll

2014-02-12 19:19:32 ----A---- C:\Windows\system32\msxml3.dll

2014-02-12 19:19:31 ----A---- C:\Windows\SYSWOW64\msxml3r.dll

2014-02-12 19:19:31 ----A---- C:\Windows\SYSWOW64\msxml3.dll

2014-02-12 19:19:31 ----A---- C:\Windows\system32\msxml3r.dll

2014-01-29 20:06:01 ----D---- C:\soulseek-downloads

2014-01-29 20:04:27 ----D---- C:\Program Files (x86)\SoulseekQt

2014-01-16 20:40:17 ----A---- C:\Windows\SYSWOW64\javaws.exe

2014-01-16 20:40:13 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll

2014-01-16 20:40:13 ----A---- C:\Windows\SYSWOW64\javaw.exe

2014-01-16 20:40:13 ----A---- C:\Windows\SYSWOW64\java.exe

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbuhci.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbport.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbohci.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbhub.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbehci.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbd.sys

2014-01-15 16:25:16 ----A---- C:\Windows\system32\drivers\usbccgp.sys

2014-01-15 16:25:15 ----A---- C:\Windows\system32\win32k.sys

2014-01-15 16:25:14 ----A---- C:\Windows\system32\drivers\netio.sys

2014-01-01 12:41:00 ----A---- C:\Windows\eReg.dat

2014-01-01 12:33:04 ----D---- C:\Program Files (x86)\EA Games

2013-12-30 18:58:41 ----D---- C:\Users\Gebruike\AppData\Roaming\vlc

2013-12-30 18:58:10 ----D---- C:\Program Files (x86)\VideoLAN

2013-12-30 18:54:12 ----D---- C:\ProgramData\WPM

2013-12-30 18:53:55 ----D---- C:\Program Files (x86)\Mobogenie

2013-12-29 19:00:57 ----D---- C:\ProgramData\ATI

2013-12-29 19:00:25 ----D---- C:\Program Files (x86)\AMD AVT

2013-12-29 18:56:08 ----D---- C:\ProgramData\Package Cache

2013-12-25 17:50:59 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI

2013-12-25 17:49:30 ----D---- C:\Windows\Migration

2013-12-24 12:12:37 ----D---- C:\Windows\ehome

2013-12-24 12:12:37 ----D---- C:\Program Files (x86)\Windows Media Player

2013-12-24 12:10:22 ----D---- C:\Users\Gebruike\AppData\Roaming\MPC-HC

2013-12-24 12:09:43 ----A---- C:\Windows\SYSWOW64\unrar.dll

2013-12-24 12:09:43 ----A---- C:\Windows\system32\unrar64.dll

2013-12-24 12:09:40 ----D---- C:\Program Files (x86)\K-Lite Codec Pack

2013-12-24 11:35:55 ----D---- C:\Program Files (x86)\VS Revo Group

2013-12-24 11:18:45 ----D---- C:\ProgramData\Windows Genuine Advantage

2013-12-11 18:35:38 ----A---- C:\Windows\SYSWOW64\wmploc.DLL

2013-12-11 18:35:38 ----A---- C:\Windows\system32\wmploc.DLL

2013-12-11 18:35:37 ----A---- C:\Windows\SYSWOW64\wmp.dll

2013-12-11 18:35:36 ----A---- C:\Windows\system32\wmp.dll

2013-12-11 18:21:48 ----A---- C:\Windows\SYSWOW64\msieftp.dll

2013-12-11 18:21:48 ----A---- C:\Windows\system32\msieftp.dll

2013-12-11 18:21:46 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll

2013-12-11 18:21:46 ----A---- C:\Windows\system32\WMPhoto.dll

2013-12-11 18:21:44 ----A---- C:\Windows\SYSWOW64\imagehlp.dll

2013-12-11 18:21:44 ----A---- C:\Windows\system32\imagehlp.dll

2013-12-11 18:21:41 ----A---- C:\Windows\SYSWOW64\tzres.dll

2013-12-11 18:21:41 ----A---- C:\Windows\system32\tzres.dll

2013-12-11 18:21:39 ----A---- C:\Windows\system32\drivers\portcls.sys

2013-12-11 18:21:39 ----A---- C:\Windows\system32\drivers\drmk.sys

2013-12-11 18:21:35 ----A---- C:\Windows\SYSWOW64\wscript.exe

2013-12-11 18:21:35 ----A---- C:\Windows\SYSWOW64\scrrun.dll

2013-12-11 18:21:35 ----A---- C:\Windows\SYSWOW64\cscript.exe

2013-12-11 18:21:35 ----A---- C:\Windows\system32\wscript.exe

2013-12-11 18:21:35 ----A---- C:\Windows\system32\scrrun.dll

2013-12-11 18:21:35 ----A---- C:\Windows\system32\cscript.exe

2013-12-06 23:07:36 ----A---- C:\Windows\system32\atimpc64.dll

2013-12-06 23:07:36 ----A---- C:\Windows\system32\amdpcom64.dll

2013-12-06 23:07:14 ----A---- C:\Windows\SYSWOW64\atimpc32.dll

2013-12-06 23:07:14 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll

2013-12-06 23:03:46 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll

2013-12-06 23:02:38 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll

2013-12-06 23:01:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll

2013-12-06 22:59:50 ----A---- C:\Windows\SYSWOW64\atidxx32.dll

2013-12-06 22:57:20 ----A---- C:\Windows\system32\atiumd6a.dll

2013-12-06 22:56:54 ----A---- C:\Windows\system32\atiumd64.dll

2013-12-06 22:52:14 ----A---- C:\Windows\system32\drivers\atikmdag.sys

2013-12-06 22:38:52 ----A---- C:\Windows\system32\clinfo.exe

2013-12-06 22:38:40 ----A---- C:\Windows\system32\amdocl_ld64.exe

2013-12-06 22:38:40 ----A---- C:\Windows\system32\amdocl_as64.exe

2013-12-06 22:38:38 ----A---- C:\Windows\SYSWOW64\amdocl_ld32.exe

2013-12-06 22:38:38 ----A---- C:\Windows\SYSWOW64\amdocl_as32.exe

2013-12-06 22:38:34 ----A---- C:\Windows\system32\OpenVideo64.dll

2013-12-06 22:38:28 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll

2013-12-06 22:38:22 ----A---- C:\Windows\system32\OVDecode64.dll

2013-12-06 22:38:18 ----A---- C:\Windows\SYSWOW64\OVDecode.dll

2013-12-06 22:37:58 ----A---- C:\Windows\system32\amdocl64.dll

2013-12-06 22:35:36 ----A---- C:\Windows\SYSWOW64\amdocl.dll

2013-12-06 22:33:28 ----A---- C:\Windows\system32\OpenCL.dll

2013-12-06 22:33:24 ----A---- C:\Windows\SYSWOW64\OpenCL.dll

2013-12-06 22:26:44 ----A---- C:\Windows\system32\coinst_13.251.dll

2013-12-06 22:16:40 ----A---- C:\Windows\system32\atio6axx.dll

2013-12-06 22:13:02 ----A---- C:\Windows\system32\atiapfxx.exe

2013-12-06 22:12:52 ----A---- C:\Windows\system32\aticalrt64.dll

2013-12-06 22:12:50 ----A---- C:\Windows\SYSWOW64\aticalrt.dll

2013-12-06 22:12:42 ----A---- C:\Windows\system32\aticalcl64.dll

2013-12-06 22:12:40 ----A---- C:\Windows\SYSWOW64\aticalcl.dll

2013-12-06 22:12:26 ----A---- C:\Windows\system32\aticaldd64.dll

2013-12-06 22:09:18 ----A---- C:\Windows\SYSWOW64\aticaldd.dll

2013-12-06 21:58:50 ----A---- C:\Windows\SYSWOW64\atioglxx.dll

2013-12-06 21:53:18 ----A---- C:\Windows\system32\atidemgy.dll

2013-12-06 21:53:10 ----A---- C:\Windows\system32\atimuixx.dll

2013-12-06 21:53:04 ----A---- C:\Windows\system32\atieclxx.exe

2013-12-06 21:52:10 ----A---- C:\Windows\system32\atiesrxx.exe

2013-12-06 21:50:36 ----A---- C:\Windows\system32\atitmm64.dll

2013-12-06 21:22:42 ----A---- C:\Windows\system32\atiadlxx.dll

2013-12-06 21:22:28 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll

2013-12-06 21:22:12 ----A---- C:\Windows\system32\atig6pxx.dll

2013-12-06 21:22:08 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll

2013-12-06 21:22:08 ----A---- C:\Windows\system32\atiglpxx.dll

2013-12-06 21:22:04 ----A---- C:\Windows\system32\atig6txx.dll

2013-12-06 21:21:54 ----A---- C:\Windows\SYSWOW64\atigktxx.dll

2013-12-06 21:21:44 ----A---- C:\Windows\system32\drivers\atikmpag.sys

2013-12-06 21:18:12 ----A---- C:\Windows\system32\drivers\ati2erec.dll

2013-12-06 16:49:18 ----A---- C:\Windows\system32\kdbsdk64.dll

2013-12-06 16:44:26 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll

2013-12-01 21:46:30 ----D---- C:\ProgramData\TmForever

2013-12-01 21:38:49 ----D---- C:\Program Files (x86)\TmNationsForever

2013-11-16 22:15:54 ----D---- C:\Users\Gebruike\AppData\Roaming\ICAClient

2013-11-16 22:15:26 ----D---- C:\Program Files (x86)\Citrix

======List of files/folders modified in the last 3 months======

2014-02-15 21:40:52 ----D---- C:\Windows\Temp

2014-02-15 21:40:51 ----RD---- C:\Program Files

2014-02-15 21:40:37 ----D---- C:\Windows\System32

2014-02-15 21:40:37 ----A---- C:\Windows\system32\PerfStringBackup.INI

2014-02-15 21:40:36 ----D---- C:\Windows\inf

2014-02-15 21:37:39 ----D---- C:\Windows\system32\config

2014-02-15 20:51:09 ----D---- C:\Windows\rescache

2014-02-15 19:50:19 ----D---- C:\Windows\system32\drivers\etc

2014-02-15 19:50:13 ----RD---- C:\Program Files (x86)

2014-02-15 16:38:36 ----D---- C:\Windows\winsxs

2014-02-15 16:37:20 ----D---- C:\Windows\SysWOW64

2014-02-15 16:37:20 ----D---- C:\Program Files\Internet Explorer

2014-02-15 16:37:20 ----D---- C:\Program Files (x86)\Internet Explorer

2014-02-15 16:36:53 ----D---- C:\Windows\system32\catroot

2014-02-15 16:36:21 ----D---- C:\Windows\system32\catroot2

2014-02-15 16:35:53 ----SHD---- C:\System Volume Information

2014-02-15 13:38:24 ----D---- C:\Users\Gebruike\AppData\Roaming\uTorrent

2014-02-15 13:27:31 ----D---- C:\Windows\Logs

2014-02-15 13:16:21 ----D---- C:\Windows\servicing

2014-02-15 13:14:22 ----D---- C:\Windows\SYSWOW64\nl-NL

2014-02-15 13:14:22 ----D---- C:\Windows\system32\nl-NL

2014-02-15 13:12:50 ----D---- C:\Windows\SYSWOW64\wbem

2014-02-15 13:12:50 ----D---- C:\Windows\SYSWOW64\migration

2014-02-15 13:12:50 ----D---- C:\Windows\SYSWOW64\en-US

2014-02-15 13:12:50 ----D---- C:\Windows\system32\wbem

2014-02-15 13:12:50 ----D---- C:\Windows\system32\migration

2014-02-15 13:12:50 ----D---- C:\Windows\system32\en-US

2014-02-15 13:12:50 ----D---- C:\Windows\PolicyDefinitions

2014-02-15 13:06:49 ----D---- C:\Windows

2014-02-15 13:01:16 ----D---- C:\Windows\Prefetch

2014-02-15 13:00:25 ----D---- C:\Windows\Panther

2014-02-15 10:21:18 ----D---- C:\Program Files (x86)\Google

2014-02-15 08:42:18 ----D---- C:\Windows\system32\LogFiles

2014-02-14 21:25:13 ----D---- C:\Windows\system32\drivers

2014-02-14 21:10:32 ----SHD---- C:\Config.Msi

2014-02-14 21:09:08 ----D---- C:\Windows\Tasks

2014-02-14 21:09:08 ----D---- C:\Windows\system32\Tasks

2014-02-14 21:08:57 ----SHD---- C:\Windows\Installer

2014-02-14 21:05:06 ----D---- C:\Windows\SoftwareDistribution

2014-02-14 21:04:02 ----D---- C:\Windows\Minidump

2014-02-14 20:41:39 ----HD---- C:\ProgramData

2014-02-14 20:15:40 ----D---- C:\Program Files (x86)\Common Files

2014-02-14 19:21:02 ----D---- C:\Films

2014-02-14 17:21:02 ----D---- C:\Windows\Microsoft.NET

2014-02-14 16:57:42 ----RSD---- C:\Windows\assembly

2014-02-13 08:36:48 ----D---- C:\Program Files (x86)\Steam

2014-02-13 08:36:39 ----D---- C:\Windows\debug

2014-02-12 22:08:33 ----D---- C:\Users\Gebruike\AppData\Roaming\Skype

2014-02-12 19:29:45 ----D---- C:\Windows\system32\MRT

2014-02-12 19:28:39 ----A---- C:\Windows\system32\MRT.exe

2014-02-11 20:29:54 ----D---- C:\ProgramData\Origin

2014-02-11 20:26:21 ----D---- C:\Program Files (x86)\Origin

2014-02-10 15:51:30 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

2014-01-16 20:40:40 ----D---- C:\ProgramData\Oracle

2014-01-16 20:40:13 ----D---- C:\Program Files (x86)\Java

2014-01-16 09:31:56 ----D---- C:\Windows\system32\DriverStore

2014-01-15 22:37:27 ----D---- C:\ProgramData\Microsoft Help

2014-01-15 12:51:07 ----D---- C:\Program Files (x86)\Euro Truck Simulator 2

2014-01-04 21:30:41 ----D---- C:\Windows\system32\wfp

2014-01-04 21:29:54 ----D---- C:\Windows\system32\CodeIntegrity

2014-01-04 21:29:54 ----D---- C:\Windows\AppCompat

2014-01-04 21:29:49 ----D---- C:\Windows\registration

2013-12-30 19:32:27 ----D---- C:\Program Files\Microsoft Games

2013-12-30 15:37:06 ----RSD---- C:\Windows\Fonts

2013-12-30 15:27:23 ----D---- C:\Program Files (x86)\Microsoft Games

2013-12-29 19:00:26 ----D---- C:\ProgramData\AMD

2013-12-29 18:59:52 ----D---- C:\Program Files\ATI Technologies

2013-12-29 18:57:39 ----D---- C:\Program Files\AMD

2013-12-29 10:00:24 ----D---- C:\ProgramData\Skype

2013-12-29 10:00:22 ----RD---- C:\Program Files (x86)\Skype

2013-12-25 17:49:30 ----SD---- C:\ProgramData\Microsoft

2013-12-24 21:18:29 ----D---- C:\Program Files\Windows Media Player

2013-12-24 11:46:39 ----D---- C:\Windows\Downloaded Program Files

2013-12-24 11:16:41 ----SD---- C:\Users\Gebruike\AppData\Roaming\Microsoft

2013-12-18 06:13:56 ----N---- C:\Windows\system32\MpSigStub.exe

2013-12-06 23:04:10 ----A---- C:\Windows\system32\atiuxp64.dll

2013-12-06 23:03:00 ----A---- C:\Windows\system32\atiu9p64.dll

2013-12-06 23:01:52 ----A---- C:\Windows\system32\aticfx64.dll

2013-12-06 23:00:16 ----A---- C:\Windows\system32\atidxx64.dll

2013-12-06 22:59:00 ----A---- C:\Windows\SYSWOW64\atiumdva.dll

2013-12-06 22:58:10 ----A---- C:\Windows\SYSWOW64\atiumdag.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]

R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]

R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]

R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]

R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]

R3 amdhub30;AMD USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\amdhub30.sys [2011-03-18 87168]

R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]

R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552]

R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 626176]

R3 amdxhc;AMD USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\amdxhc.sys [2011-03-18 188544]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]

R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-04-21 471144]

R3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]

S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-04-03 103064]

S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]

S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2013-04-03 169288]

S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2013-04-03 21320]

S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2013-04-03 188232]

S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2013-04-03 158024]

S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-04-03 203672]

S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]

S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]

S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 239616]

R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]

R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]

S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22 116648]

S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]

S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22 116648]

S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-12 1255736]

S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]

S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-05-04 543656]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP;f
 C:\ProgramData\WPM;fs
 C:\Program Files (x86)\Mobogenie;fs
  emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "Options" en vink nu de onderstaande opties aan.
  • Do a Quick Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Hierbij het logje. Ik wil nog even de volgende dingen melden.

De RO's search assistant en customize search blijven staan bij hijack this.

Ik had eerst ook chicalogic password manager bij msconfig staan bij de services en die vervolgens uitgevinkt.

Ik zie nu dat deze helemaal niet meer bij staat.

Waarschijnlijk heeft zoek.exe dit opgelost.

Zoek.exe v5.0.0.0 Updated 15-February-2014

Tool run by Gebruike on zo 16-02-2014 at 21:04:06,64.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\Gebruike\Desktop\zoek.exe [scan all users] [script inserted] [Checkboxes used]

==== System Restore Info ======================

16-2-2014 21:05:32 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\PROGRA~2\DSP-worx deleted successfully

C:\PROGRA~2\MSXML 4.0 deleted successfully

C:\PROGRA~2\VS Revo Group deleted successfully

C:\Program Files\SAMSUNG deleted successfully

C:\ProgramData\Oracle deleted successfully

C:\Users\Gebruike\AppData\Roaming\Anvisoft deleted successfully

C:\Users\Gebruike\AppData\Local\genienext deleted successfully

==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

==== Deleting Files \ Folders ======================

C:\ProgramData\WPM deleted

C:\Program Files (x86)\Mobogenie deleted

C:\Users\Gebruike\daemonprocess.txt deleted

C:\Users\Gebruike\.android deleted

C:\PROGRA~2\GUT8F64.tmp deleted

C:\PROGRA~2\GUM8F63.tmp deleted

C:\PROGRA~2\VirtuoCity Browser Plugin 3.1 deleted

C:\ProgramData\Package Cache deleted

C:\Users\Gebruike\AppData\Local\Mobogenie deleted

C:\Users\Gebruike\AppData\Local\cache deleted

C:\Users\Gebruike\Documents\Mobogenie deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCall.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla2.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla21.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.exe" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla32.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla33.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla34.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.dll" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.exe" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseData.ini" deleted

"C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

====== C:\Users\Gebruike\AppData\Local\Temp ====

2014-02-15 18:50:12 FBC207AD85D053D4FD9DD93C595D1A1D 285455 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe

2014-02-15 09:19:25 A9C86900D2A61728C8326FE7147617C5 578440 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\npGoogleUpdate3.dll

2014-02-15 09:19:25 3A49D76D0AA3DC5FC0B4EEF3B7E84EF1 166792 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\psmachine.dll

2014-02-15 09:19:25 3703787CB966F9F6C69EF9164D882EE3 166792 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\psuser.dll

2014-02-15 09:19:23 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateOnDemand.exe

2014-02-15 09:19:23 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleCrashHandler64.exe

2014-02-15 09:19:23 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleCrashHandler.exe

2014-02-15 09:19:23 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateSetup.exe

2014-02-15 09:19:23 A43B937C580F5DFC43EF63EF72992FE9 847752 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\goopdate.dll

2014-02-15 09:19:23 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateBroker.exe

2014-02-15 09:19:23 6996AB4F70B3718CC465DE43A75A10C8 26112 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateHelper.msi

2014-02-15 09:19:23 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdate.exe

2014-02-14 20:37:08 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\erunt\ERUNT.EXE

2014-02-14 19:16:13 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\ESGScanner.sys

2014-02-14 19:13:22 5C28E508C83A3B0DDBB224B04B1418B9 47329360 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\SHSetup.exe

====== Java Cache =====

2014-02-04 13:46:45 C90C0270DE9C5C124A7F0F811EDB69FA 9780 ----a-w- C:\Users\Gebruike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\1611b40b-27f5bfd1

2014-02-04 13:46:42 B923FAD88018A8D5FD87AEEBA2A0938E 37 ----a-w- C:\Users\Gebruike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\46478770-6.0.lap

====== C:\Windows\SysWOW64 =====

2014-02-15 15:36:48 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll

2014-02-15 15:36:07 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll

2014-02-15 15:36:07 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

2014-02-15 15:36:07 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll

2014-02-15 15:36:05 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

2014-02-15 15:36:05 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

2014-02-15 15:36:04 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe

2014-02-15 15:36:04 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll

2014-02-15 15:36:04 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll

2014-02-15 15:36:04 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll

2014-02-15 15:36:03 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll

2014-02-15 15:36:03 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll

2014-02-15 15:36:03 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll

2014-02-15 15:36:03 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll

2014-02-15 15:36:02 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll

2014-02-15 15:36:02 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl

2014-02-15 15:36:01 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll

2014-02-15 15:36:00 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll

2014-02-15 15:36:00 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll

2014-02-12 18:20:12 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

2014-02-12 18:20:12 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll

2014-02-12 18:20:12 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll

2014-02-12 18:20:12 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe

2014-02-12 18:20:12 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll

2014-02-12 18:20:12 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

2014-02-12 18:20:12 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

2014-02-12 18:20:11 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll

2014-02-12 18:20:11 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll

2014-02-12 18:20:02 5CFA81C05054018FC91F75C6AABB7EE8 5693440 ----a-w- C:\Windows\SysWOW64\mstscax.dll

2014-02-12 18:19:47 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll

2014-02-12 18:19:47 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll

2014-02-12 18:19:33 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls

2014-02-12 18:19:31 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll

2014-02-12 18:19:31 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2014-02-15 15:36:48 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll

2014-02-15 15:36:08 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb

2014-02-15 15:36:07 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll

2014-02-15 15:36:07 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll

2014-02-15 15:36:06 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll

2014-02-15 15:36:06 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll

2014-02-15 15:36:06 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe

2014-02-15 15:36:05 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll

2014-02-15 15:36:05 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll

2014-02-15 15:36:04 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll

2014-02-15 15:36:04 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe

2014-02-15 15:36:04 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll

2014-02-15 15:36:04 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll

2014-02-15 15:36:04 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe

2014-02-15 15:36:03 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll

2014-02-15 15:36:03 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll

2014-02-15 15:36:03 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll

2014-02-15 15:36:02 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl

2014-02-15 15:36:02 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll

2014-02-15 15:36:02 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll

2014-02-15 15:36:01 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll

2014-02-15 15:35:59 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll

2014-02-14 20:10:37 F60CD87653FCA1650AAB9BC169CC283C 352472 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT

2014-02-12 18:20:12 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll

2014-02-12 18:20:12 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll

2014-02-12 18:20:12 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll

2014-02-12 18:20:12 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe

2014-02-12 18:20:12 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe

2014-02-12 18:20:12 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe

2014-02-12 18:20:12 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe

2014-02-12 18:20:11 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll

2014-02-12 18:20:11 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll

2014-02-12 18:20:02 8F273C46BF2261BB872B3766521C9C2A 6573056 ----a-w- C:\Windows\Sysnative\mstscax.dll

2014-02-12 18:19:47 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll

2014-02-12 18:19:47 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll

2014-02-12 18:19:33 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls

2014-02-12 18:19:32 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll

2014-02-12 18:19:31 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll

====== C:\Windows\Sysnative\drivers =====

====== C:\Windows\Tasks ======

====== C:\Windows\Temp ======

======= C:\Program Files =====

2014-02-15 20:40:51 -------- d-----w- C:\Program Files\trend micro

2014-02-14 19:16:10 -------- d-----w- C:\Program Files\Enigma Software Group

======= C:\PROGRA~2 =====

2014-02-14 19:15:40 -------- d-----w- C:\PROGRA~2\COMMON~1\Wise Installation Wizard

2014-01-29 19:04:27 -------- d-----w- C:\PROGRA~2\SoulseekQt

======= C: =====

2014-02-14 19:16:32 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat

====== C:\Users\Gebruike\AppData\Roaming ======

2014-02-14 20:11:32 B0FF39189C17DCB99409C344DF01F1A0 84600 ----a-w- C:\Users\Gebruike\AppData\Local\GDIPFONTCACHEV1.DAT

2014-01-29 19:12:19 -------- d-----w- C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoulseekQt

2014-01-29 19:03:33 -------- d-----w- C:\Users\Gebruike\AppData\Local\SoulseekQt

====== C:\Users\Gebruike ======

2014-02-15 19:09:35 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Users\Gebruike\Desktop\JRT.exe

2014-02-15 12:23:23 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\Downloads\adwcleaner (1).exe

2014-02-15 12:20:51 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\Desktop\AdwCleaner.exe

2014-02-15 12:03:40 11DB1879DE4EB5DEDCCAE5399E349C4A 59087056 ----a-w- C:\Users\Gebruike\Downloads\IE11-Windows6.1-x64-nl-nl.exe

2014-02-15 09:21:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

2014-02-14 19:41:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft

2014-02-14 19:41:39 -------- d-----w- C:\ProgramData\Anvisoft

2014-02-14 19:38:22 C772D7BAD5ED1B8766527B67140EF76F 26548024 ----a-w- C:\Users\Gebruike\Downloads\asdsetup.exe

2014-02-14 19:13:14 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Gebruike\Downloads\SpyHunter-Installer.exe

====== C: exe-files ==

2014-02-15 20:40:51 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruike.exe

2014-02-15 19:09:35 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Users\Gebruike\Desktop\JRT.exe

2014-02-15 18:50:14 C1DB9BDF885C2F1ADC15264FBEA2788F 302961 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BW8B3URE\HOSTS_Anti-Adware_main[1].exe

2014-02-15 18:50:13 59538D76EA7D0FE8283D72265833E0E4 285795 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZRQSEC09\HOSTS_Anti-Adware[1].exe

2014-02-15 18:50:12 FBC207AD85D053D4FD9DD93C595D1A1D 285455 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe

2014-02-15 18:50:12 FBC207AD85D053D4FD9DD93C595D1A1D 285455 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GS6C02PQ\Install_HOSTS_Anti-Adware[1].exe

2014-02-15 15:36:06 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\System32\ie4uinit.exe

2014-02-15 15:36:05 AFAB9B381886ABE3490689B7633A858F 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe

2014-02-15 15:36:05 9E8F9FDD407DDE997965EEFD9E635CCF 469504 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe

2014-02-15 15:36:04 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe

2014-02-15 15:36:04 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe

2014-02-15 15:36:04 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\System32\ieUnatt.exe

2014-02-15 15:36:02 C6E1178294BDEAB1CACF50427688DF05 806104 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe

2014-02-15 15:36:02 4263F6C131E513CEA1AE82B5B81A4E1A 808152 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe

2014-02-15 12:23:23 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\Downloads\adwcleaner (1).exe

2014-02-15 12:20:51 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\Desktop\AdwCleaner.exe

2014-02-15 12:03:40 11DB1879DE4EB5DEDCCAE5399E349C4A 59087056 ----a-w- C:\Users\Gebruike\Downloads\IE11-Windows6.1-x64-nl-nl.exe

2014-02-15 09:21:17 4336FBC3A8A75922456D194391A5999C 36528344 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\32.0.1700.107\32.0.1700.107_chrome_installer.exe

2014-02-15 09:19:23 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateOnDemand.exe

2014-02-15 09:19:23 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleCrashHandler64.exe

2014-02-15 09:19:23 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleCrashHandler.exe

2014-02-15 09:19:23 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateSetup.exe

2014-02-15 09:19:23 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdateBroker.exe

2014-02-15 09:19:23 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Users\Gebruike\AppData\Local\Temp\{D195A8D7-A6AC-434F-872C-CEFBC12F5872}\GoogleUpdate.exe

2014-02-14 20:37:08 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\erunt\ERUNT.EXE

2014-02-14 20:37:01 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UCXDCGPB\JRT.exe

2014-02-14 20:25:52 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BW8B3URE\adwcleaner.exe

2014-02-14 20:06:51 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7IDJIOMN\adwcleaner.exe

2014-02-14 20:06:13 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SQFEAXCN\AdwCleaner[1].exe

2014-02-14 20:05:38 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N4C52NCQ\adwcleaner.exe

2014-02-14 19:38:22 C772D7BAD5ED1B8766527B67140EF76F 26548024 ----a-w- C:\Users\Gebruike\Downloads\asdsetup.exe

2014-02-14 19:13:22 5C28E508C83A3B0DDBB224B04B1418B9 47329360 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\SHSetup.exe

2014-02-14 19:13:14 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Gebruike\Downloads\SpyHunter-Installer.exe

2014-02-14 17:34:28 8D04AD7926541115D672462CB35E2256 1520208 ----a-w- C:\Users\Gebruike\AppData\Roaming\uTorrent\updates\3.3.2_30586.exe

2014-02-12 18:20:12 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

2014-02-12 18:20:12 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe

2014-02-12 18:20:12 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\System32\RMActivate_ssp_isv.exe

2014-02-12 18:20:12 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\System32\RMActivate.exe

2014-02-12 18:20:12 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe

2014-02-12 18:20:12 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

2014-02-12 18:20:12 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

2014-02-12 18:20:12 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\System32\RMActivate_ssp.exe

2014-02-11 19:26:06 2BB5195D2A05C18BAEF5CB9F31643389 8803160 ----a-w- C:\Program Files (x86)\Origin\OriginER.exe

2014-02-11 12:50:42 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe

2014-02-11 12:50:42 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateBroker.exe

2014-02-11 12:50:41 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateSetup.exe

2014-02-11 12:50:36 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe

2014-02-11 12:50:36 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe

2014-02-11 12:50:36 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdate.exe

2014-02-11 12:50:28 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe

=== C: other files ==

2014-02-15 20:15:46 7C73EDDA7B34BDA6876467D979ECFAAE 279966 ----a-w- C:\Users\Gebruike\Downloads\src_204 (1).zip

2014-02-15 20:15:32 7C73EDDA7B34BDA6876467D979ECFAAE 279966 ----a-w- C:\Users\Gebruike\Downloads\src_204.zip

2014-02-14 20:37:08 DFB8D08F2FD68D58239045B366D68CE2 10261 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\JRT.bat

2014-02-14 20:37:08 CC6C23C02BE66014AD87F2678BBB3A1D 8117 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\modules.bat

2014-02-14 20:37:08 C4A5476A9D54B400F1623A2EE7DDA5C5 13955 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\chrome.bat

2014-02-14 20:37:08 B964B792D3692699CD7D4FDB63EE470E 1239 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\FWPolicy.bat

2014-02-14 20:37:08 B45931E5313CB14CAA0F2BC3DA30E6FC 29648 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\ask.bat

2014-02-14 20:37:08 AE697BC275F5B52FB9E1164F14FB18F8 151936 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\firefox.bat

2014-02-14 20:37:08 8C7709AE609C5235976C4567E810D4B8 154424 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\misc.bat

2014-02-14 20:37:08 868D0E22DC055BA214D7EC71600F2CFA 16063 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\get.bat

2014-02-14 20:37:08 80D02380F1AC33E459324B088392A1EC 732 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\ev_clear.bat

2014-02-14 20:37:08 75C9C20DD9839BF287B43B0E179822DC 31414 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\iexplore.bat

2014-02-14 20:37:08 7178963AEE641F3E47E1CE22416F8A3A 9295 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\runvalues.bat

2014-02-14 20:37:08 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\delorphans.bat

2014-02-14 20:37:08 58605DA3492FB918D3D40B1FB88046AE 39471 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\prelim.bat

2014-02-14 20:37:08 372EA6F783198102CF5779072EE78C79 24751 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\searchlnk.bat

2014-02-14 20:37:08 1FBF882AA934A741530741FC134872A3 1243 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\TDL4.bat

2014-02-14 20:37:08 14D6EE8B672684E2232FB430D8C4A928 18668 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\medfos.bat

2014-02-14 20:37:08 0768E560CCD86C18F35FAD29DCEA7B80 1820 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\jrt\delfolders.bat

2014-02-14 19:16:32 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat

2014-02-14 19:16:13 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Users\Gebruike\AppData\Local\Temp\ESGScanner.sys

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"amd_dc_opt"="C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe"

"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun"

"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice"

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"=""

"hkey"="HKCU"

"command"="C:\\Program Files (x86)\\Samsung\\Kies\\External\\FirmwareUpdate\\KiesPDLR.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe ARM"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChicaPasswordManager]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ChicaPasswordManager"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\ChicaLogic\\Chica Password Manager\\stpass.exe\" /autorunned"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Facebook Update]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Facebook Update"

"hkey"="HKCU"

"command"="\"C:\\Users\\Gebruike\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe\" /c /nocrashserver"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="KiesPreload"

"hkey"="HKCU"

"command"="C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe /preload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="KiesTrayAgent"

"hkey"="HKLM"

"command"="C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeFlashPlayerUpdateSvc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SkypeUpdate]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Steam Client Service]

==== Task Scheduler Jobs ======================

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000Core.job --a------ C:\Users\Gebruike\AppData\Local\Facebook\Update\FacebookUpdate.exe [03-03-2013 20:24]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000UA.job --a------ C:\Users\Gebruike\AppData\Local\Facebook\Update\FacebookUpdate.exe [03-03-2013 20:24]

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [22-12-2012 12:12]

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [22-12-2012 12:12]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]

"C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000Core" [C:\Users\Gebruike\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-920102977-993485452-1621598587-1000UA" [C:\Users\Gebruike\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

==== Chrome Look ======================

Google Docs - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

Google Drive - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

YouTube - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

Google Search - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

Google Wallet - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

Gmail - Gebruike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.google.nl"

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.google.nl"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

"DefaultScope"="{7A442F8E-8742-4729-A7CE-F6B90774265D}"

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

{7A442F8E-8742-4729-A7CE-F6B90774265D} Google Url="http://www.google.nl/search?hl=nl&q={searchTerms}"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ChicaPasswordManager deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Gebruike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Gebruike\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=234 folders=53 130727855 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully

C:\Users\Default User\AppData\Local\Temp emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

C:\Users\Gebruike\AppData\Local\Temp will be emptied at reboot

C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\Gebruike\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on zo 16-02-2014 at 21:17:39,57 ======================

Link naar reactie
Delen op andere sites

Dubbelklik op Zoek.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  C:\autoexec.bat;f
 C:\Users\Gebruike\AppData\Local\GDIPFONTCACHEV1.DAT;f
shortcutfix;

  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Zoek.exe v5.0.0.0 Updated 15-February-2014

Tool run by Gebruike on ma 17-02-2014 at 7:28:57,43.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\Gebruike\Desktop\zoek.exe [scan all users] [script inserted]

==== Older Logs ======================

C:\zoek-results2014-02-16-201739.log 33257 bytes

==== Deleting Files \ Folders ======================

"C:\autoexec.bat" deleted

"C:\Users\Gebruike\AppData\Local\GDIPFONTCACHEV1.DAT" deleted

==== shortcuts on Users Desktops ======================

C:\Users\Gebruike\Desktop\Driver San Francisco - Snelkoppeling.lnk -

C:\Users\Gebruike\Desktop\Games for Windows Marketplace.lnk - C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLive.exe

C:\Users\Gebruike\Desktop\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Users\Gebruike\Desktop\James Bond 007 Nightfire.lnk - C:\Program Files (x86)\EA Games\Nightfire\Bond.exe

C:\Users\Gebruike\Desktop\Microsoft Office Excel 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

C:\Users\Gebruike\Desktop\Microsoft Office PowerPoint 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

C:\Users\Gebruike\Desktop\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

C:\Users\Gebruike\Desktop\oude-pc backup.lnk - D:\backup\Eigenaar

C:\Users\Gebruike\Desktop\Play GTA Vice City.lnk - C:\Program Files (x86)\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe

C:\Users\Gebruike\Desktop\Play GTAIII.lnk - C:\Program Files (x86)\Rockstar Games\GTAIII\gta3.exe

C:\Users\Gebruike\Desktop\Play Hitman Contracts.lnk - C:\Program Files (x86)\Eidos\Hitman Contracts\HitmanContracts.exe

C:\Users\Gebruike\Desktop\Scannerbeheer - Snelkoppeling.lnk -

C:\Users\Gebruike\Desktop\SoulseekQt.lnk - C:\Program Files (x86)\SoulseekQt\SoulseekQt.exe

C:\Users\Gebruike\Desktop\Windows Live Mail.lnk - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe

C:\Users\Public\Desktop\Crysis 3.lnk - C:\Program Files (x86)\Origin Games\Crysis 3\bin32\Crysis3.exe

C:\Users\Public\Desktop\Euro Truck Simulator 2.lnk - C:\Program Files (x86)\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe

C:\Users\Public\Desktop\FIFA 12.lnk - C:\Program Files (x86)\Origin Games\FIFA 12\Game\fifa.exe

C:\Users\Public\Desktop\FIFA 13.lnk - C:\Program Files (x86)\Origin Games\FIFA 13\Game\fifa13.exe

C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Public\Desktop\Google Earth.lnk - C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe

C:\Users\Public\Desktop\Halo.lnk - C:\Program Files (x86)\Microsoft Games\Halo\halo.exe

C:\Users\Public\Desktop\James Bond 007 - Blood Stone.lnk - C:\Program Files (x86)\Activision\James Bond 007 - Blood Stone\BizLaunch.exe

C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Users\Public\Desktop\Mass Effect 3.lnk - C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe

C:\Users\Public\Desktop\Need for Speed World.lnk - C:\Program Files (x86)\Origin Games\Need for Speed World\GameLauncher.exe

C:\Users\Public\Desktop\Origin.lnk - C:\Program Files (x86)\Origin\Origin.exe

C:\Users\Public\Desktop\Samsung Kies (Lite).lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe /lite

C:\Users\Public\Desktop\Samsung Kies.lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe

C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe

C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe

C:\Users\Public\Desktop\TmNationsForever.lnk - C:\Program Files (x86)\TmNationsForever\TmForeverLauncher.exe

C:\Users\Public\Desktop\Train Simulator.lnk - C:\Program Files (x86)\Microsoft Games\Train Simulator\launcher.exe -rungame

C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff

C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\James Bond 007 Nightfire™.lnk -

C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoulseekQt\SoulseekQt.lnk - C:\Program Files (x86)\SoulseekQt\SoulseekQt.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoulseekQt\Uninstall.lnk - C:\Program Files (x86)\SoulseekQt\uninstall.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AB0000000001}\SC_Reader.ico

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -

C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe /lite

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Calculator.lnk - C:\Windows\system32\calc.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Live Mail.lnk - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe

C:\Users\Gebruike\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1

==== C:\zoek_backup content ======================

C:\zoek_backup (files=236 folders=53 130812617 bytes)

==== EOF on ma 17-02-2014 at 7:30:36,13 ======================

Link naar reactie
Delen op andere sites

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1388426037&from=cor&uid=HitachiXHDS721010CLA330_JP2911N03MW26V3MW26VX&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

Klik op 'Fix checked' om de items te verwijderen.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.

aangepast door kape
Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.