Emsisoft Emergency Kit - Versie 9.0 Laatste Update: 19-1-2015 5:22:03 Gebruikersaccount: wintjens\dannywintjens Scaninstellingen: Scanmodus: Diepe scan Objecten: Rootkits, Geheugen, Sporen, C:\ Detecteer PUPs: Aan Scan archieven: Aan ADS Scan: Aan Bestandsextensiefilter: Uit Geavanceerde cache: Aan Directe schijftoegang: Uit Scan gestart: 19-1-2015 5:22:51 Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Ontdekt: Application.Win32.WebApp (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MOBOGENIEADD Ontdekt: Application.AdGenie (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} Ontdekt: Application.AdGenie (A) Key: HKEY_USERS\S-1-5-20\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} Ontdekt: Application.AdGenie (A) Key: HKEY_USERS\S-1-5-19\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} Ontdekt: Application.AdGenie (A) Key: HKEY_USERS\S-1-5-20\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} Ontdekt: Application.AdGenie (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} Ontdekt: Application.AdGenie (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\SYSTWEAK Ontdekt: Application.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SYSTWEAK Ontdekt: Application.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTAINER.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTROLLER Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTROLLER.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATASTATISTICS Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATASTATISTICS.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLE Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLE.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEFIELDS Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEFIELDS.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEHOLDER Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEHOLDER.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.LSPLOGIC Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.LSPLOGIC.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.PROXYCHECKS Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.PROXYCHECKS.1 Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.READONLYMANAGER Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.READONLYMANAGER.1 Ontdekt: Application.AdSend (A) Key: HKEY_USERS\.DEFAULT\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} Ontdekt: Application.Win32.InstallAd (A) Key: HKEY_USERS\S-1-5-20\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} Ontdekt: Application.Win32.InstallAd (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} Ontdekt: Application.Win32.InstallAd (A) Key: HKEY_USERS\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} Ontdekt: Application.Win32.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Ontdekt: Application.AdGenie (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Ontdekt: Application.Win32.WSearch (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Ontdekt: Application.AdReg (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8} Ontdekt: Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SEARCHPROTECT Ontdekt: Application.InstallAd (A) C:\Users\dannywintjens\AppData\Roaming\PowerISO\Upgrade\PowerISO6-x64.exe Ontdekt: Application.Toolbar (A) C:\Users\dannywintjens\AppData\Roaming\uTorrent\updates\3.4.2_32343.exe Ontdekt: Gen:Variant.Kazy.522616 (B) C:\Users\dannywintjens\Downloads\CPUID HWMonitor Pro v1.20 Incl Keymaker-CORE [TorDigger]\Keymaker-CORE\keygen.exe Ontdekt: Riskware.Win32.Keygen (A) C:\Users\dannywintjens\Downloads\dlsecureTb_1.0.1.5.exe Ontdekt: Application.Toolbar (A) C:\Users\dannywintjens\Downloads\uTorrent® Plus 3.4.2 Build 32343\utorrent.exe Ontdekt: Gen:Variant.Kazy.522616 (B) C:\zoek_backup\C_Program Files (x86)_AmiExt\ZipEnhancer\ie\ZipEnhancer.dll Ontdekt: Application.InstallAd (A) C:\zoek_backup\C_PROGRA~2_AmiExt\ZipEnhancer\ie\ZipEnhancer.dll Ontdekt: Application.InstallAd (A) Gescand: 908946 Gevonden: 50 Scan geëindigd: 19-1-2015 8:54:21 Scantijd: 3:31:30 C:\zoek_backup\C_PROGRA~2_AmiExt\ZipEnhancer\ie\ZipEnhancer.dll In quarantaine geplaatst Application.InstallAd (A) C:\zoek_backup\C_Program Files (x86)_AmiExt\ZipEnhancer\ie\ZipEnhancer.dll In quarantaine geplaatst Application.InstallAd (A) C:\Users\dannywintjens\Downloads\uTorrent® Plus 3.4.2 Build 32343\utorrent.exe In quarantaine geplaatst Gen:Variant.Kazy.522616 (B) C:\Users\dannywintjens\Downloads\dlsecureTb_1.0.1.5.exe In quarantaine geplaatst Application.Toolbar (A) C:\Users\dannywintjens\Downloads\CPUID HWMonitor Pro v1.20 Incl Keymaker-CORE [TorDigger]\Keymaker-CORE\keygen.exe In quarantaine geplaatst Riskware.Win32.Keygen (A) C:\Users\dannywintjens\AppData\Roaming\uTorrent\updates\3.4.2_32343.exe In quarantaine geplaatst Gen:Variant.Kazy.522616 (B) C:\Users\dannywintjens\AppData\Roaming\PowerISO\Upgrade\PowerISO6-x64.exe In quarantaine geplaatst Application.Toolbar (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SEARCHPROTECT In quarantaine geplaatst Application.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33} In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} In quarantaine geplaatst Application.AdReg (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C} In quarantaine geplaatst Application.Win32.WSearch (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} In quarantaine geplaatst Application.AdGenie (A) Key: HKEY_USERS\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} In quarantaine geplaatst Application.Win32.InstallAd (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} In quarantaine geplaatst Application.Win32.InstallAd (A) Key: HKEY_USERS\S-1-5-20\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} In quarantaine geplaatst Application.Win32.InstallAd (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.READONLYMANAGER.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.READONLYMANAGER In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.PROXYCHECKS.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.PROXYCHECKS In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.LSPLOGIC.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.LSPLOGIC In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEHOLDER.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEHOLDER In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEFIELDS.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLEFIELDS In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLE.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATATABLE In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATASTATISTICS.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATASTATISTICS In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTROLLER.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTROLLER In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PCPROXY.DATACONTAINER.1 In quarantaine geplaatst Application.AdSend (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SYSTWEAK In quarantaine geplaatst Application.InstallAd (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\SYSTWEAK In quarantaine geplaatst Application.InstallAd (A) Key: HKEY_USERS\S-1-5-21-2480803176-3389462879-1122066420-1000\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} In quarantaine geplaatst Application.AdGenie (A) Key: HKEY_USERS\S-1-5-20\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} In quarantaine geplaatst Application.AdGenie (A) Key: HKEY_USERS\S-1-5-19\SOFTWARE\APPDATALOW\{5F189DF5-2D05-472B-9091-84D9848AE48B} In quarantaine geplaatst Application.AdGenie (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} In quarantaine geplaatst Application.AdGenie (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MOBOGENIEADD In quarantaine geplaatst Application.AdGenie (A) In quarantaine geplaatst 47