Ga naar inhoud

ldv

Lid
  • Items

    78
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door ldv

  1. helaas niets aan te doen maar toch hartelijk bedankt voor jullie goede hulp en zorgen Luc
  2. hier het speccy logje heb de indruk dat snelheid verschilt bij iedere opstart(soms tergend traag en soms iets sneller(vloter)) LDV.txt
  3. helaas niets merkbaar veranderd
  4. het is Malwarebytes Anti-Malware(premium) 2.0.1.1004 maar vind reatime bescherming niet direct
  5. pc nieuw met windows 7 computer komt eigenlijk van mijn dochter die hem teveel had(nieuwe van werkgever) heb regelmatig een waarschuwing intensief CPU gebruik door vb firefox of iets anders
  6. het is bij alle programma's (1 a 2min) ook afsluiten is traag ook (melding reageert niet)
  7. http://speccy.piriform.com/results/pzaTEQUOLYzBfhBKMoE3Me8
  8. hier zoek-results zoek-results.txt
  9. hier het zoekbestand groeten ldv zoek-results.txt
  10. hier ComboFix bestand ComboFix.txt
  11. Hallo Mijn laptop is traag, Ram geheugen va; 2 naar 8GB opstarttijd schommeld van 65 naar 85 seconden na opstarten vb fierfox opstarten duur er lang 3min of meer Kan daar wat aan gedaan worden ? hierbij het logje alvast bedankt Luc log.txt
  12. Alvast bedankt aan iedereen voor alles en zal uitkijken maar nieuwe harde schijf Groeten Luc
  13. hier het resultaat [TABLE] [TR] [TD=width: 15]+[/TD] [TD=width: 130]System[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15]-[/TD] [TD=width: 130]Provider[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Name] [/TD] [TD]Microsoft-Windows-Wininit[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Guid] [/TD] [TD]{206f6dea-d3c5-4d10-bc72-989f03c8b84b}[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ EventSourceName] [/TD] [TD]Wininit[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15]-[/TD] [TD=width: 130]EventID[/TD] [TD]1001[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Qualifiers] [/TD] [TD]16384[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Version[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Level[/TD] [TD]4[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Task[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Opcode[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Keywords[/TD] [TD]0x80000000000000[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15]-[/TD] [TD=width: 130]TimeCreated[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ SystemTime] [/TD] [TD]2014-03-24T17:03:02.000Z[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]EventRecordID[/TD] [TD]46354[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD]Correlation[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15]-[/TD] [TD=width: 130]Execution[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ ProcessID] [/TD] [TD]0[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ ThreadID] [/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Channel[/TD] [TD]Application[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 130]Computer[/TD] [TD]PC_van_ldv[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD=width: 15][/TD] [TD]Security[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15]-[/TD] [TD=width: 130]EventData[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD=width: 15][/TD] [TD=width: 15][/TD] [TD=width: 130][/TD] [TD]Het bestandssysteem op C: wordt gecontroleerd... Het type bestandssysteem is NTFS. Volumenaam is ACER. Er is in een eerder stadium een schijfcontrole gepland. Windows zal de schijf nu controleren. 223936 bestandsrecords verwerkt. 1329 records met grote bestanden verwerkt. 0 records met beschadigde bestanden verwerkt. 2 EA-records verwerkt. 64 reparserecords verwerkt. 281488 indexvermeldingen verwerkt. 0 niet-geïndexeerde bestanden verwerkt. 223936 security descriptors verwerkt. 41 ongebruikte indexingangen in de index $SII van het bestand 0x9 verwijderen. 41 ongebruikte indexingangen in de index $SDH van het bestand 0x9 verwijderen. 41 ongebruikte security descriptors verwijderen. 28777 gegevensbestanden verwerkt. Het USN-logboek controleren... 36798976 USN-bytes verwerkt. Controle van USN-logboek is voltooid. CHKDSK controleert de bestandsgegevens (stap 4 van 5)... Leesfout met status 0xc0000185 op offset 0x147425e000 voor 0x10000 bytes. Leesfout met status 0xc0000185 op offset 0x1474260000 voor 0x1000 bytes. Windows heeft beschadigde clusters in bestand 76534 met naam \Windows\SOFTWA~1\DATAST~1\DATAST~1.EDB vervangen. 223920 bestanden verwerkt. De controle van bestandsgegevens is voltooid. Vrije ruimte controleren (stap 5 van 5)... 14112349 vrije clusters verwerkt. De controle op vrije schijfruimte is voltooid. 1 beschadigde clusters toevoegen aan het bestand met beschadigde clusters. Fouten in de volumebitmap herstellen. Het bestandssysteem is hersteld. 118902783 kB totale schijfruimte. 62033980 kB in 150638 bestanden. 82380 kB in 28778 indexen. 4 kB in beschadigde sectoren. 337023 kB in gebruik door het systeem. Het logboekbestand neemt 65536 kB in beslag. 56449396 kB beschikbaar op schijf. 4096 bytes per cluster 29725695 clusters in totaal op schijf 14112349 clusters beschikbaar op schijf Interne info: c0 6a 03 00 e3 bc 02 00 0b bf 04 00 00 00 00 00 .j.............. c1 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 ....@........... 42 00 00 00 e2 73 fb 76 50 8b 29 00 50 83 29 00 B....s.vP.).P.). Windows heeft de schijfcontrole voltooid. Een ogenblik geduld. De computer wordt opnieuw opgestart. [/TD] [/TR] [/TABLE] - - - Updated - - - hier het resultaat De computer loopt niet meer vast [TABLE] [TR] [TD]+[/TD] [TD=width: 130]System[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD]-[/TD] [TD=width: 130]Provider[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Name][/TD] [TD]Microsoft-Windows-Wininit[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Guid][/TD] [TD]{206f6dea-d3c5-4d10-bc72-989f03c8b84b}[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ EventSourceName][/TD] [TD]Wininit[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD]-[/TD] [TD=width: 130]EventID[/TD] [TD]1001[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ Qualifiers][/TD] [TD]16384[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Version[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Level[/TD] [TD]4[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Task[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Opcode[/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Keywords[/TD] [TD]0x80000000000000[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD]-[/TD] [TD=width: 130]TimeCreated[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ SystemTime][/TD] [TD]2014-03-24T17:03:02.000Z[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]EventRecordID[/TD] [TD]46354[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD]Correlation[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD]-[/TD] [TD=width: 130]Execution[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ ProcessID][/TD] [TD]0[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 12][/TD] [TD=width: 105][ ThreadID][/TD] [TD]0[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Channel[/TD] [TD]Application[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD=width: 130]Computer[/TD] [TD]PC_van_ldv[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD] [TABLE] [TR] [TD][/TD] [TD]Security[/TD] [/TR] [/TABLE] [/TD] [/TR] [/TABLE] [TABLE] [TR] [TD]-[/TD] [TD=width: 130]EventData[/TD] [/TR] [/TABLE] [TABLE] [TR] [TD][/TD] [TD=width: 15][/TD] [TD=width: 130][/TD] [TD]Het bestandssysteem op C: wordt gecontroleerd... Het type bestandssysteem is NTFS. Volumenaam is ACER. Er is in een eerder stadium een schijfcontrole gepland. Windows zal de schijf nu controleren. 223936 bestandsrecords verwerkt. 1329 records met grote bestanden verwerkt. 0 records met beschadigde bestanden verwerkt. 2 EA-records verwerkt. 64 reparserecords verwerkt. 281488 indexvermeldingen verwerkt. 0 niet-geïndexeerde bestanden verwerkt. 223936 security descriptors verwerkt. 41 ongebruikte indexingangen in de index $SII van het bestand 0x9 verwijderen. 41 ongebruikte indexingangen in de index $SDH van het bestand 0x9 verwijderen. 41 ongebruikte security descriptors verwijderen. 28777 gegevensbestanden verwerkt. Het USN-logboek controleren... 36798976 USN-bytes verwerkt. Controle van USN-logboek is voltooid. CHKDSK controleert de bestandsgegevens (stap 4 van 5)... Leesfout met status 0xc0000185 op offset 0x147425e000 voor 0x10000 bytes. Leesfout met status 0xc0000185 op offset 0x1474260000 voor 0x1000 bytes. Windows heeft beschadigde clusters in bestand 76534 met naam \Windows\SOFTWA~1\DATAST~1\DATAST~1.EDB vervangen. 223920 bestanden verwerkt. De controle van bestandsgegevens is voltooid. Vrije ruimte controleren (stap 5 van 5)... 14112349 vrije clusters verwerkt. De controle op vrije schijfruimte is voltooid. 1 beschadigde clusters toevoegen aan het bestand met beschadigde clusters. Fouten in de volumebitmap herstellen. Het bestandssysteem is hersteld. 118902783 kB totale schijfruimte. 62033980 kB in 150638 bestanden. 82380 kB in 28778 indexen. 4 kB in beschadigde sectoren. 337023 kB in gebruik door het systeem. Het logboekbestand neemt 65536 kB in beslag. 56449396 kB beschikbaar op schijf. 4096 bytes per cluster 29725695 clusters in totaal op schijf 14112349 clusters beschikbaar op schijf Interne info: c0 6a 03 00 e3 bc 02 00 0b bf 04 00 00 00 00 00 .j.............. c1 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 ....@........... 42 00 00 00 e2 73 fb 76 50 8b 29 00 50 83 29 00 B....s.vP.).P.). Windows heeft de schijfcontrole voltooid. Een ogenblik geduld. De computer wordt opnieuw opgestart.[/TD] [/TR] [/TABLE]
  14. ziehier de link http://speccy.piriform.com/results/KjGAj15cwnoaG4Y3BsMcfyS
  15. Computer start goed op. Dan naar firefox(ook ok) Pchelpforum opgestart maar de discussie gegaan en dan loopt hij terug vast. Melding firefox (reageert niet) Moet dan computer afsluiten (gefirceerd) en dan terug in veilige modus opstarten groeten
  16. hallo goede morgen hier het logbestand van adwcleaner bedankt LDV AdwCleaner[S0].txt AdwCleaner[R0].txt
  17. Hallo ziehier het zoeklogje (moet wel in veilige modus werken) zoek-results.log
  18. Hallo Na het opstarten van de computer loopt hij na enkele minuten vast. heb norton,anti malware, adwcleaner,jrt laten lopen maar niets helpt. De pc draait met Windouws Vista Hopelijk kunnen jullie helpen waarvoor alvast mijn dank. Hierbij het logje. Luc[ATTACH]30861[/ATTACH] log.txt
  19. Heb geen vervelende reclame meer waarvoor al mijn dank ldv AdwCleaner[S1].txt
  20. Zoek.exe v5.0.0.0 Updated 13-February-2014 Tool run by elkedevreese on vr 14/02/2014 at 7:57:33,89. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\elkedevreese\Downloads\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== System Restore Info ====================== 14/02/2014 8:03:13 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\Users\elkedevreese\AppData\Roaming\Nico Mak Computing deleted successfully C:\Users\elkedevreese\AppData\Roaming\TP deleted successfully ==== Creating Sample_20141402_0912.zip ====================== Process firefox.exe killed Copied file C:\ProgramData\pclunst.exe to sample\pclunst.exe sample\pclunst.exe renamed to 59CEA6A230264D080D53455F760F24FB C:\Users\Public\Desktop\sample_20141402_0912.zip created successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\video-saver deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\video-saver deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Video-Saver deleted C:\Program Files (x86)\Enigma Software Group deleted C:\Program Files\Enigma Software Group deleted C:\Program Files (x86)\SecurityXploded deleted C:\PROGRA~2\GUMBA97.tmp deleted C:\PROGRA~2\Mobogenie deleted C:\Users\elkedevreese\AppData\Local\Mobogenie deleted C:\Users\elkedevreese\AppData\Local\cache deleted C:\Users\wangzhisong\AppData\Local\Mobogenie deleted C:\Users\wangzhisong deleted C:\Users\elkedevreese\Documents\Mobogenie deleted C:\ProgramData\pclunst.exe deleted "C:\Windows\tasks\Video-Saver_wd.job" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCall.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla17.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla18.exe" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla19.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla2.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla20.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla21.dll" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla21.exe" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseData.ini" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCall.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla2.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla21.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.exe" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla32.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla33.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla34.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.exe" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseData.ini" deleted "C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\ELKEDE~1\AppData\Local\Temp ==== 2014-02-13 12:42:16 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ====== C:\Windows\SysWOW64 ===== 2014-02-13 15:03:52 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-02-13 15:02:21 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-02-13 15:02:21 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 15:02:19 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-02-13 15:02:16 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 15:02:15 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 15:02:15 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 15:02:14 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-02-13 15:02:14 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 15:02:14 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-02-13 15:02:12 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 15:02:12 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 15:02:11 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-02-13 15:02:10 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-02-13 15:02:09 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-02-13 15:02:08 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 15:02:06 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-02-13 15:02:04 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-02-13 15:02:03 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-02-13 13:48:53 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-02-13 13:48:53 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll 2014-02-13 13:48:52 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls 2014-02-13 13:48:35 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-13 13:48:35 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe 2014-02-13 13:48:35 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-13 13:48:34 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll 2014-02-13 13:48:34 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll 2014-02-13 13:48:34 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-13 13:48:33 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-13 13:48:33 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll 2014-02-13 13:48:33 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-13 13:48:24 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 13:48:22 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll 2014-02-01 13:00:26 ED1543644C11CD56F374F3CDCD5A685F 692616 ----a-w- C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-01 13:00:26 675BCED636193DA8BCCDF2D9594EF4E8 71048 ----a-w- C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-02-13 15:03:52 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-02-13 15:02:21 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-02-13 15:02:20 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-02-13 15:02:19 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-02-13 15:02:17 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-02-13 15:02:17 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-02-13 15:02:17 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-02-13 15:02:16 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-02-13 15:02:15 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-02-13 15:02:14 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-02-13 15:02:14 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-02-13 15:02:14 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-02-13 15:02:14 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-02-13 15:02:13 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-02-13 15:02:12 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-02-13 15:02:12 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-02-13 15:02:10 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-02-13 15:02:09 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-02-13 15:02:09 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-02-13 15:02:08 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-02-13 15:02:07 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-02-13 15:02:02 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-02-13 13:48:54 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-02-13 13:48:53 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll 2014-02-13 13:48:52 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls 2014-02-13 13:48:36 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe 2014-02-13 13:48:35 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe 2014-02-13 13:48:35 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe 2014-02-13 13:48:35 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe 2014-02-13 13:48:34 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll 2014-02-13 13:48:34 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll 2014-02-13 13:48:34 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll 2014-02-13 13:48:33 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll 2014-02-13 13:48:33 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll 2014-02-13 13:48:24 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll 2014-02-13 13:48:23 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll ====== C:\Windows\Sysnative\drivers ===== 2014-02-08 12:43:35 E16E2431516D904CED3946AD3FF8C86B 854 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.INF 2014-02-08 12:43:35 97E11C50CE52277B377396EA8838E539 177752 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.SYS 2014-02-08 12:43:35 7846ED59291A134CC5DD017C6EC7B433 8222 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.CAT 2014-02-07 21:59:42 B9657A0AFF28C1CB114ACC0CB93EE4BB 51496 ----a-w- C:\Windows\Sysnative\drivers\stflt.sys 2014-02-05 13:40:38 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2014-01-15 11:44:01 18A85013A3E0F7E1755365D287443965 53248 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-01-15 11:44:00 FFA06EF43987ED0DD42AD59B260C0C78 7808 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-01-15 11:44:00 DD253AFC3BC6CBA412342DE60C3647F3 30720 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-01-15 11:44:00 DCA68B0943D6FA415F0C56C92158A83A 99840 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-01-15 11:44:00 8D1196CFBB223621F2C67D45710F25BA 343040 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-01-15 11:44:00 765A92D428A8DB88B960DA5A8D6089DC 25600 ----a-w- C:\Windows\Sysnative\drivers\usbohci.sys 2014-01-15 11:44:00 12FEB33791920678F8433701C822BCFD 325120 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-01-15 11:43:56 3555BA97171CD153118F73FDCCC8BFDE 376768 ----a-w- C:\Windows\Sysnative\drivers\netio.sys ====== C:\Windows\Tasks ====== 2014-02-11 20:43:21 9B7DD89F133CA1BD9830886D99F9EC12 3230 ----a-w- C:\Windows\Sysnative\Tasks\SidebarExecute 2014-02-01 13:00:28 28092A51E732FBBF444CF4FE76899F4E 3878 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater 2014-02-01 13:00:27 C75436F568D25696625B749869678C57 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-02-11 15:25:46 -------- d-----w- C:\Program Files\trend micro 2014-02-04 17:53:20 -------- d-----w- C:\Program Files\Common Files\Macrovision Shared 2014-02-04 17:47:50 -------- d-----w- C:\Program Files\Common Files\Autodesk Shared 2014-02-04 17:47:50 -------- d-----w- C:\Program Files\AutoCAD LT 2010 ======= C:\PROGRA~2 ===== 2014-02-07 20:31:14 -------- d-----w- C:\PROGRA~2\Loaris 2014-02-07 19:31:26 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service 2014-02-04 17:48:24 -------- d-----w- C:\PROGRA~2\COMMON~1\Autodesk Shared ======= C: ===== 2014-02-11 13:36:42 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-02-07 11:45:36 02B255C37A377C93F10558FB19E614B3 1365 ----a-w- C:\AdwCleaner[R1].txt 2014-02-07 11:14:23 749FD378813017158CDC49AB51A6BB2A 1305 ----a-w- C:\AdwCleaner[s6].txt 2014-02-06 19:18:11 EB2DDA9CA58C8919933697616E5770BC 1366 ----a-w- C:\AdwCleaner[s5].txt 2014-02-05 21:57:51 D7EFC95EBF67C51FFFE28B6E4DE803C9 1306 ----a-w- C:\AdwCleaner[s4].txt 2014-02-05 16:27:36 7263FB9F12D1C0CD2A440DDB7089D014 1124 ----a-w- C:\AdwCleaner[s3].txt 2014-02-05 13:35:38 0C8E63C48F6B271BC72FB58CEF0AEA8E 1219 ----a-w- C:\AdwCleaner[s2].txt 2014-02-05 13:35:11 67AAC58FE022983B245E271084CE1D80 275 ----a-w- C:\AdwCleaner[s1].txt ====== C:\Users\elkedevreese\AppData\Roaming ====== 2014-02-11 20:42:28 -------- d-----w- C:\Users\elkedevreese\AppData\Roaming\TuneUp Software 2014-02-07 22:34:32 BC519C193A1B6C89FD20D17CA69279F9 141312 ----a-w- C:\Windows\SysNative\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-07 20:29:40 -------- d-----w- C:\Users\elkedevreese\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-02-05 22:00:23 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\CrashDumps 2014-02-04 17:47:50 -------- d-----w- C:\Users\elkedevreese\AppData\Roaming\Autodesk 2014-02-04 17:47:50 -------- d-----w- C:\Users\elkedevreese\AppData\Local\Autodesk 2014-01-21 14:56:51 -------- d-----w- C:\Users\elkedevreese\AppData\Local\Mozilla 2014-01-21 14:56:44 -------- d-----w- C:\Users\elkedevreese\AppData\Roaming\Mozilla ====== C:\Users\elkedevreese ====== 2014-02-13 14:11:57 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\elkedevreese\Downloads\RSITx64.exe 2014-02-13 12:43:09 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Users\elkedevreese\Desktop\JRT_NEW.exe 2014-02-11 20:32:28 -------- d--h--w- C:\ProgramData\Common Files 2014-02-11 12:35:22 -------- d-----w- C:\ProgramData\Doctor Web 2014-02-11 11:49:09 -------- d-----w- C:\ProgramData\NCOTEMP 2014-02-07 20:29:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-02-04 17:59:16 -------- d-----w- C:\ProgramData\FLEXnet 2014-02-04 17:50:13 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk 2014-02-04 17:47:50 -------- d-----w- C:\ProgramData\Autodesk 2014-01-21 14:56:26 -------- d-----w- C:\ProgramData\Mozilla ====== C: exe-files == 2014-02-13 15:02:17 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-02-13 15:02:15 AFAB9B381886ABE3490689B7633A858F 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-02-13 15:02:15 9E8F9FDD407DDE997965EEFD9E635CCF 469504 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-02-13 15:02:15 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 15:02:14 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-02-13 15:02:14 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-02-13 15:02:09 C6E1178294BDEAB1CACF50427688DF05 806104 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-02-13 15:02:09 4263F6C131E513CEA1AE82B5B81A4E1A 808152 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-02-13 14:11:57 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\elkedevreese\Downloads\RSITx64.exe 2014-02-13 13:48:36 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe 2014-02-13 13:48:35 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-13 13:48:35 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe 2014-02-13 13:48:35 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\System32\RMActivate_ssp_isv.exe 2014-02-13 13:48:35 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\System32\RMActivate.exe 2014-02-13 13:48:35 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-13 13:48:35 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\System32\RMActivate_ssp.exe 2014-02-13 13:48:34 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-13 12:43:09 56DBC01BF6DFBA60A863DE308FB58334 1037530 ----a-w- C:\Users\elkedevreese\Desktop\JRT_NEW.exe 2014-02-13 12:42:16 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\erunt\ERUNT.EXE 2014-02-11 15:25:47 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\elkedevreese.exe 2014-02-07 19:31:29 87AA03C017EED7D9F257FB149D0B214C 106212 ----a-w- C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe 2014-02-07 19:31:27 A7A117CB1104D0829466F48E17BE0A71 118896 ----a-w- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe === C: other files == 2014-02-14 08:12:55 7BE932B5FCB35CD5F18F2BCE8FE52973 5265590 ----a-w- C:\Users\Public\Desktop\sample_20141402_0912.zip 2014-02-13 12:42:16 DFB8D08F2FD68D58239045B366D68CE2 10261 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\JRT.bat 2014-02-13 12:42:16 CC6C23C02BE66014AD87F2678BBB3A1D 8117 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\modules.bat 2014-02-13 12:42:16 C4A5476A9D54B400F1623A2EE7DDA5C5 13955 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\chrome.bat 2014-02-13 12:42:16 B964B792D3692699CD7D4FDB63EE470E 1239 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\FWPolicy.bat 2014-02-13 12:42:16 B45931E5313CB14CAA0F2BC3DA30E6FC 29648 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\ask.bat 2014-02-13 12:42:16 AE697BC275F5B52FB9E1164F14FB18F8 151936 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\firefox.bat 2014-02-13 12:42:16 8C7709AE609C5235976C4567E810D4B8 154424 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\misc.bat 2014-02-13 12:42:16 868D0E22DC055BA214D7EC71600F2CFA 16063 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\get.bat 2014-02-13 12:42:16 80D02380F1AC33E459324B088392A1EC 732 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\ev_clear.bat 2014-02-13 12:42:16 75C9C20DD9839BF287B43B0E179822DC 31414 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\iexplore.bat 2014-02-13 12:42:16 7178963AEE641F3E47E1CE22416F8A3A 9295 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\runvalues.bat 2014-02-13 12:42:16 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\delorphans.bat 2014-02-13 12:42:16 58605DA3492FB918D3D40B1FB88046AE 39471 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\prelim.bat 2014-02-13 12:42:16 372EA6F783198102CF5779072EE78C79 24751 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\searchlnk.bat 2014-02-13 12:42:16 1FBF882AA934A741530741FC134872A3 1243 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\TDL4.bat 2014-02-13 12:42:16 14D6EE8B672684E2232FB430D8C4A928 18668 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\medfos.bat 2014-02-13 12:42:16 0768E560CCD86C18F35FAD29DCEA7B80 1820 ----a-w- C:\Users\elkedevreese\AppData\Local\Temp\jrt\delfolders.bat 2014-02-11 13:36:42 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-02-10 18:44:24 0510396A957E9FD7205BA62D3CAE4528 162392 ----a-w- C:\Windows\System32\drivers\NSTx64\7DE06000.01B\ccsetx64.sys 2014-02-10 18:34:58 B18CE01B9C09C59422BA7C7064248B35 36952 ----a-r- C:\Windows\System32\drivers\NAVx64\1501000.012\srtspx64.sys 2014-02-10 18:34:58 8BFD1752AAA15BF47D668E9AC5AF96FB 858200 ----a-w- C:\Windows\System32\drivers\NAVx64\1501000.012\srtsp64.sys 2014-02-10 18:34:58 78A2F073AD9EA5EBC04A70931EA36C9A 590936 ----a-w- C:\Windows\System32\drivers\NAVx64\1501000.012\symnets.sys 2014-02-10 18:34:58 5C9EE2303CA7F267665D75237862B39C 493656 ----a-r- C:\Windows\System32\drivers\NAVx64\1501000.012\symds64.sys 2014-02-10 18:34:58 20F758E6339A16F97DD83389D582E09A 23568 ----a-r- C:\Windows\System32\drivers\NAVx64\1501000.012\symelam.sys 2014-02-10 18:34:58 08AF51153E441687130B759A8F6892ED 1147480 ----a-w- C:\Windows\System32\drivers\NAVx64\1501000.012\symefa64.sys 2014-02-10 18:34:57 48C2934683CBD06F662B088EEF49EF6A 264280 ----a-r- C:\Windows\System32\drivers\NAVx64\1501000.012\ironx64.sys 2014-02-10 18:34:57 0510396A957E9FD7205BA62D3CAE4528 162392 ----a-w- C:\Windows\System32\drivers\NAVx64\1501000.012\ccsetx64.sys 2014-02-08 12:43:35 97E11C50CE52277B377396EA8838E539 177752 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS 2014-02-07 21:59:42 B9657A0AFF28C1CB114ACC0CB93EE4BB 51496 ----a-w- C:\Windows\System32\drivers\stflt.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mobilegeni daemon" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Mobogenie\\DaemonProcess.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NBAgent" "hkey"="HKLM" "command"="\"c:\\Program Files (x86)\\Nero\\Nero 10\\Nero BackItUp\\NBAgent.exe\" /WinStart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpywareTerminatorShield] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SpywareTerminatorShield" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Spyware Terminator\\SpywareTerminatorShield.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpywareTerminatorUpdater] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SpywareTerminatorUpdater" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Spyware Terminator\\SpywareTerminatorUpdate.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\StartCCC] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="StartCCC" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\" MSRun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SynTPEnh] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SynTPEnh" "hkey"="HKLM" "command"="%ProgramFiles%\\Synaptics\\SynTP\\SynTPEnh.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TCrdMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TCrdMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\FlashCards\\TCrdMain.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TOPI.EXE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TOPI.EXE" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\TOSHIBA\\TOSHIBA Online Product Information\\TOPI.exe /STARTUP" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba Registration] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba Registration" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\Registration\\ToshibaReminder.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPRO] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba TEMPRO" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Toshiba TEMPRO\\TemproTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosNC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosNC" "hkey"="HKLM" "command"="%ProgramFiles%\\Toshiba\\BulletinBoard\\TosNcCore.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosReelTimeMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosReelTimeMonitor" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\ReelTime\\TosReelTimeMonitor.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosSENotify] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosSENotify" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\TOSHIBA HDD SSD Alert\\TosWaitSrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosVolRegulator] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosVolRegulator" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\TosVolRegulator\\TosVolRegulator.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TPwrMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TPwrMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\Power Saver\\TPwrMain.EXE" ==== Startup Folders ====================== 2011-03-04 12:56:00 1258 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2011-03-04 12:56:00 1258 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [05/02/2014 21:03] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17/05/2013 10:17] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17/05/2013 10:17] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\ConfigFree Startup Programs" [C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\WSCStub.exe"] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\{1BC5D72A-EF7C-415D-A665-D456499D6089}" ["C:\Program Files (x86)\Internet Explorer\iexplore.exe" ]Download Skype op uw computer ? Mac, Windows, Linux*?*Skype "C:\Windows\SysNative\tasks\Norton 360\Norton Error Analyzer" [C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\SymErr.exe] "C:\Windows\SysNative\tasks\Norton 360\Norton Error Processor" [C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\SymErr.exe] "C:\Windows\SysNative\tasks\Norton AntiVirus\Norton Error Analyzer" [C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\SymErr.exe] "C:\Windows\SysNative\tasks\Norton AntiVirus\Norton Error Processor" [C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Identity Safe\Norton Error Analyzer" [C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Identity Safe\Norton Error Processor" [C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\SymErr.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.0.1.3\IPSFF" [10/02/2014 19:38] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\elkedevreese\AppData\Roaming\Mozilla\Firefox\Profiles\0xy6pavw.default FD6ACD9D85177259D442A0C4AC15F7B8 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll - Shockwave Flash ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions nppllibpnmahfaklnpggkibhkapjkeob - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\Exts\Chrome.crx[28/11/2013 11:25] Google Wallet - elkedevreese\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Norton Identity Protection - elkedevreese\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {194F51C1-694E-4198-9064-D43B03B87ECB} eBay Url="http://rover.ebay.com/rover/1/1346-71494-26233-7/4?satitle={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {AA2FE37C-C320-4F86-A368-76F535DD5767} Unknown Url="Not_Found" {C0662D9A-823D-47C4-8C85-4A290992CB20} Amazon Url="http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2" {DB340D26-7DAF-4CED-90FE-8E3332B237CB} Bing Url="http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1590102809-793007682-2146393987-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AA2FE37C-C320-4F86-A368-76F535DD5767} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\elkedevreese\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\elkedevreese\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\elkedevreese\AppData\Local\Mozilla\Firefox\Profiles\0xy6pavw.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\elkedevreese\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=353 folders=56 100256509 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\elkedevreese\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\ELKEDE~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on vr 14/02/2014 at 9:43:59,50 ======================
  21. Hallo, Bij het opstarten van firefox worden andere pagina's geopend en verschijnt er vervelende reclame. De computer is ook trager geworden ondanks het RAM geheugen uitgebreid is naar 8GB. Verschillende antievirus progr. laten lopen, Norton antivirus,Anti-malware,JRT blijkt er niets te helpen. Hierbij voeg ik het RSIT bestand. Hopelijk kunnen julie er eits aan veranderen en hierbij alvast hartelijk bedankt Luc log.txt
  22. Op dit moment zie ik geen moeilijkheden meer Bedankt voor de fantastische hulp en hopelijk blijft alles nu ok (als je tips hebt om mijn pc beter te beschermen laat het gerust weten) bedankt voor alles
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.