Ga naar inhoud

ukash virus


Aanbevolen berichten

ik had het ukash virus op mijn laptop, door systeemherstel krijg k het politiescherm niet meer, maar enk dat het niet volledig weg is.

hieronder het hijackthislogje en malwarebyteslog

Logfile of Trend Micro HijackThis v2.0.5

Scan saved at 14:04:01, on 5/06/2013

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v10.0 (10.00.9200.16576)

FIREFOX: 21.0 (nl)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Users\deben\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe

C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe

C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrchMn.exe

C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brmon.exe

C:\Windows\SysWOW64\jmdp\stij.exe

C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe

C:\Users\deben\AppData\Roaming\Spotify\Spotify.exe

C:\Program Files\Sony\VAIO Care\listener.exe

C:\Program Files\Sony\VAIO Personalization Manager\VpmIfPav.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe

C:\Users\deben\Downloads\HijackThis.exe

C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to the VAIO portal

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^UX^xdm170^YY^be&ptb=36C28743-013B-4A3F-8A80-7A9AC8FF3F01&si=KI_MAPS_FIG_BEL_116

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll

R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: Toolbar BHO - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:\PROGRA~2\MAPSGA~2\bar\1.bin\39bar.dll

O2 - BHO: IB Updater Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll

O2 - BHO: Search Assistant BHO - {71c1d63a-c944-428a-a5bd-ba513190e5d2} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: DVDVideoSoftTB - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll

O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: (no name) - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)

O3 - Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O3 - Toolbar: (no name) - !{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O3 - Toolbar: (no name) - !{F9639E4A-801B-4843-AEE3-03D9DA199E77} - (no file)

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: MapsGalaxy - {364ea597-e728-4ce4-bb4a-ed846ef47970} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39bar.dll

O4 - HKLM\..\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart

O4 - HKLM\..\Run: [iSBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [sweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

O4 - HKLM\..\Run: [MapsGalaxy Search Scope Monitor] "C:\PROGRA~2\MAPSGA~2\bar\1.bin\39srchmn.exe" /m=2 /w /h

O4 - HKLM\..\Run: [MapsGalaxy_39 Browser Plugin Loader] C:\PROGRA~2\MAPSGA~2\bar\1.bin\39brmon.exe

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\deben\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKCU\..\Run: [Elbserver] C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay

O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\deben\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

O4 - Startup: Facebook Messenger.lnk = deben\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\deben\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - AppInit_DLLs: C:\PROGRA~3\Wincert\WIN32C~1.DLL

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

O23 - Service: IB Updater - Unknown owner - C:\Program Files\IB Updater\ExtensionUpdaterService.exe

O23 - Service: IBUpdaterService - Unknown owner - C:\Windows\system32\dmwu.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

O23 - Service: MapsGalaxyService (MapsGalaxy_39Service) - COMPANYVERS_NAME - C:\PROGRA~2\MAPSGA~2\bar\1.bin\39barsvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe

O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe

O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe

O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - c:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe

O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe

O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe

O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe

O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe

O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 16334 bytes

Malwarebytes Anti-Malware 1.75.0.1300

Malwarebytes : Free anti-malware download

Databaseversie: v2013.06.05.03

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 10.0.9200.16576

deben :: DEBEN-VAIO [administrator]

5/06/2013 14:07:32

MBAM-log-2013-06-05 (14-11-15).txt

Scan type: Snelle scan

Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scan opties: P2P

Objecten gescand: 219126

Verstreken tijd: 3 minuut/minuten, 30 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 2

HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) -> Geen actie ondernomen.

HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Geen actie ondernomen.

Registerwaarden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

(einde)

alvast bedankt,

Glenn

Link naar reactie
Delen op andere sites


Hallo Glenn,

Ik zal je log bekijken.

Ik moet echter mijn advies eerst laten keuren door een gekwalificeerd helper, hierdoor kan het iets langer duren voordat ik je verder kan helpen.

Alvast bedankt voor je begrip.

Met vriendelijke groet,

Mako

Link naar reactie
Delen op andere sites

Hallo Glenn,

Download 51a612a8b27e2-Zoek.pngzoek.exe naar het bureaublad.

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe

(hier of hier) kan je lezen hoe je dat doet.


  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.
     
    startupall;
    filesrcm;
    C:\Program Files (x86)\SweetIM;fs
    C:\Program Files (x86)\MapsGalaxy_39;fs
    C:\Program Files (x86)\DVDVideoSoftTB;fs
    C:\Program Files\IB Updater;fs
    C:\PROGRA~3\Wincert;fs
    IB Updater;s
    IBUpdaterService;s
    MapsGalaxyService;s
    {872b5b88-9db5-4310-bdd0-ac189557e5f5};c
    {ba14329e-9550-4989-b3f2-9732e92d17cc};c
    {26842a09-ffa8-4e2c-ae12-0c80f01c3295};c
    {1e91a655-bb4b-4693-a05e-2edebc4c9d89};c
    {336D0C35-8A85-403a-B9D2-65C292C39087};c
    {71c1d63a-c944-428a-a5bd-ba513190e5d2};c
    {9D717F81-9148-4f12-8568-69135F087DB0};c
    {D4027C7F-154A-4066-A1AD-4243D8127440};c
    {F9639E4A-801B-4843-AEE3-03D9DA199E77};c
    {364ea597-e728-4ce4-bb4a-ed846ef47970};c
    !{872b5b88-9db5-4310-bdd0-ac189557e5f5};c
    !{ba14329e-9550-4989-b3f2-9732e92d17cc};c
    !{D4027C7F-154A-4066-A1AD-4243D8127440};c
    !{F9639E4A-801B-4843-AEE3-03D9DA199E77};c
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r64
    "SweetIM"=-;r64
    "MapsGalaxy Search Scope Monitor"=-;r64
    "MapsGalaxy_39 Browser Plugin Loader"=-;r64
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows];r
    "AppInit_DLLs"=-;r
    autoclean; 
    


  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites


Zoek.exe Version 4.0.0.2 Updated 03-June-2013

Tool run by deben on ma 10/06/2013 at 20:14:19,34.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4f12-8568-69135F087DB0} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4f12-8568-69135F087DB0} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{26842a09-ffa8-4e2c-ae12-0c80f01c3295} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1e91a655-bb4b-4693-a05e-2edebc4c9d89} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{26842a09-ffa8-4e2c-ae12-0c80f01c3295} deleted successfully

HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\internet explorer\urlsearchhooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully

HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{364ea597-e728-4ce4-bb4a-ed846ef47970} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IB Updater deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IB Updater deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IBUpdaterService deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IBUpdaterService deleted successfully

==== FireFox Fix ======================

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0

user.js not found

---- Lines EEE6C361-6118-11DC-9C72-001320C79847 removed from prefs.js ----

---- Lines EEE6C361-6118-11DC-9C72-001320C79847 modified from prefs.js ----

---- Lines SweetIM removed from prefs.js ----

---- Lines SweetIM modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

prefs_20131006_2017_.backup

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

user.js not found

---- Lines EEE6C361-6118-11DC-9C72-001320C79847 removed from prefs.js ----

---- Lines EEE6C361-6118-11DC-9C72-001320C79847 modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}\":{\"descriptor\":\"C:\\\\Program Files\\\\IB Updater\\\\Firefox\",\"mtime\":1362514294925,\"rdfTime\":1359466114000},\"39ffxtbr@MapsGalaxy_39.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\MapsGalaxy_39\\\\bar\\\\1.bin\",\"mtime\":1370419397924,\"rdfTime\":1370419394102}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1370419451162,\"rdfTime\":1368303951000}}},{\"name\":\"app-profile\",\"addons\":{\"39ffxtbr@MapsGalaxy_39.com\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\39ffxtbr@MapsGalaxy_39.com\",\"mtime\":1370419397970,\"rdfTime\":1370419394102},\"cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com\",\"mtime\":1370878057845,\"rdfTime\":1370779442000},\"fhdp@fhdp.tv\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\fhdp@fhdp.tv.xpi\",\"mtime\":1368358750099},\"{EEE6C361-6118-11DC-9C72-001320C79847}\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi\",\"mtime\":1368358860660}}}]");

---- Lines SweetIM removed from prefs.js ----

user_pref("browser.search.defaultenginename", "SweetIM Search");

user_pref("browser.search.selectedEngine", "SweetIM Search");

user_pref("keyword.URL", "http://search.sweetim.com/search.asp?src=6&barid={9E6A31D0-BAF8-11E2-8282-64273797DE10}&crg=3.1010000.10011&st=23&q=");

---- Lines SweetIM modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

prefs_20131006_2017_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=-

==== Registry Fix Code x64 ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SweetIM"=-

"MapsGalaxy Search Scope Monitor"=-

"MapsGalaxy_39 Browser Plugin Loader"=-

==== Deleting Files \ Folders ======================

"C:\user.js" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\searchplugins\SweetIM Search.xml" deleted

"C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml" deleted

"C:\Users\deben\AppData\Roaming\skype.dat" deleted

"C:\windows\SysNative\dmwu.exe" deleted

"C:\ProgramData\7ofiwin.pad" deleted

"C:\ProgramData\kjhy64.txt" deleted

"C:\user.js" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\searchplugins\MyStart Search.xml" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\searchplugins\SweetIM Search.xml" deleted

"C:\PROGRA~3\Wincert\win32cert.dll" deleted

"C:\PROGRA~3\Wincert\win32prop.dll" deleted

"C:\ProgramData\Wincert\win32cert.dll" deleted

"C:\ProgramData\Wincert\win32prop.dll" deleted

"C:\Windows\Syswow64\jmdp\lmrn.dll" deleted

"C:\Windows\Syswow64\jmdp\msvcp100.dll" deleted

"C:\Windows\Syswow64\jmdp\msvcr100.dll" deleted

"C:\Windows\Syswow64\jmdp\sqlite3.dll" deleted

"C:\Windows\Syswow64\jmdp\stij.exe" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgcommon.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgcommunication.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgconfig.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mghooking.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgsimcommon.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgUpdateSupport.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgxml_wrapper.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\msvcp71.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\msvcr71.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brmon.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brstub.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39hkstub.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrchMn.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\AppIntegrator64.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\AppIntegratorStub64.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\Hpg64.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\T8RES.DLL" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brmon.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brstub.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39hkstub.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrchMn.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\AppIntegrator64.exe" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\AppIntegratorStub64.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\Hpg64.dll" deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\T8RES.DLL" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgcommon.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgcommunication.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgconfig.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mghooking.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgsimcommon.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgUpdateSupport.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\mgxml_wrapper.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\msvcp71.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\msvcr71.dll" deleted

"C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe" deleted

"C:\Users\deben\AppData\Roaming\iolo" deleted

"C:\Program Files (x86)\SweetIM" not deleted

"C:\Program Files (x86)\MapsGalaxy_39" not deleted

"C:\Program Files (x86)\DVDVideoSoftTB" deleted

"C:\Program Files\IB Updater" deleted

"C:\PROGRA~3\Wincert" deleted

"C:\Program Files (x86)\TornTV.com" deleted

"C:\Program Files (x86)\FirstRowSportApp.com" deleted

"C:\Program Files (x86)\Search Results Toolbar" deleted

"C:\Program Files (x86)\DVDVideoSoftTB" deleted

"C:\Program Files (x86)\Common Files\DVDVideoSoft\TB" deleted

"C:\Program Files (x86)\Common Files\DVDVideoSoft\bin" deleted

"C:\Program Files (x86)\Yontoo" deleted

"C:\Program Files (x86)\MapsGalaxy_39" not deleted

"C:\Program Files (x86)\sweetpacks bundle uninstaller" deleted

"C:\Program Files\IB Updater" deleted

"C:\Program Files (x86)\SweetIM" not deleted

"C:\Program Files (x86)\Conduit" deleted

"C:\Program Files (x86)\Searchqu Toolbar" deleted

"C:\Users\deben\AppData\Roaming\OpenCandy" deleted

"C:\ProgramData\Browser Manager" deleted

"C:\ProgramData\Ask" deleted

"C:\ProgramData\boost_interprocess" deleted

"C:\ProgramData\Wincert" deleted

"C:\ProgramData\SweetIM" deleted

"C:\ProgramData\Tarma Installer" deleted

"C:\Users\deben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FirstRowSportApp.com" deleted

"C:\Users\deben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com" deleted

"C:\Users\deben\AppData\Local\Ilivid Player" deleted

"C:\Users\deben\AppData\Local\Conduit" deleted

"C:\Users\deben\AppData\LocalLow\DVDVideoSoftTB" deleted

"C:\Users\deben\AppData\LocalLow\DataMngr" deleted

"C:\Users\deben\AppData\LocalLow\searchquband" deleted

"C:\Users\deben\AppData\LocalLow\Conduit" deleted

"C:\Users\deben\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd" deleted

"C:\Windows\Syswow64\jmdp" not deleted

"C:\Windows\Syswow64\ARFC" deleted

"C:\Windows\Syswow64\WNLT" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\jetpack" deleted

"C:\Windows\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}" deleted

"C:\Program Files (x86)\SweetIM\Messenger" not deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar" not deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin" not deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar" not deleted

"C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin" not deleted

"C:\Program Files (x86)\SweetIM\Messenger" not deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

====== C:\Users\deben\AppData\Local\Temp ====

2013-06-08 09:43:53 F7C120110847B47C7D2DC9F3643AF90F 76640 ----a-w- C:\Users\deben\AppData\Local\Temp\TUUUninstallHelper.exe

====== C:\Windows\SysWOW64 =====

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

====== C:\Windows\Sysnative\drivers =====

2013-06-05 11:37:16 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys

2013-05-15 08:33:54 AF2E16242AA723F68F461B6EAE2EAD3D 983400 ----a-w- C:\Windows\Sysnative\drivers\dxgkrnl.sys

2013-05-15 08:33:53 1F04CFB79DD5FB7694468CE3FB3DCC31 265064 ----a-w- C:\Windows\Sysnative\drivers\dxgmms1.sys

====== C:\Windows\Tasks ======

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\Program Files (x86) =====

2013-06-05 08:03:14 -------- d-----w- C:\Program Files (x86)\MapsGalaxy_39

2013-05-12 11:40:11 -------- d-----w- C:\Program Files (x86)\SweetIM

======= C: =====

2013-06-10 14:33:57 1954EFB7F8F139DA6C5D2FE5CDD9DABB 3416 ------w- C:\bootsqm.dat

====== C:\Users\deben\AppData\Roaming ======

2013-06-10 15:29:18 -------- d-----r- C:\users\deben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices

====== C:\Users\deben ======

2013-06-05 11:36:38 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Users\deben\Downloads\mbam-setup-1.75.0.1300.exe

2013-06-05 11:33:47 B36B2E3CA24D80973C59BFBDA1C4800B 4378864 ----a-w- C:\Users\deben\Downloads\ccsetup402.exe

====== C: exe-files ==

2013-06-08 09:43:53 F7C120110847B47C7D2DC9F3643AF90F 76640 ----a-w- C:\Users\deben\AppData\Local\Temp\TUUUninstallHelper.exe

2013-06-05 11:36:38 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Users\deben\Downloads\mbam-setup-1.75.0.1300.exe

2013-06-05 11:33:47 B36B2E3CA24D80973C59BFBDA1C4800B 4378864 ----a-w- C:\Users\deben\Downloads\ccsetup402.exe

2013-06-04 19:31:06 17EFB4C5F996F783E90BE1EB0077BA40 477560 ----a-w- C:\Users\deben\AppData\Local\Temp\MSS\3.0.318.3\McUICnt.exe

=== C: other files ==

2013-06-05 11:37:16 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"Facebook Update"="C:\Users\deben\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"Elbserver"="C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay"

"Spotify Web Helper"="C:\Users\deben\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe"

"Dolby Home Theater v4"="C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe -autostart"

"ISBMgr.exe"="C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"

"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

"SweetIM"="C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe"

"MapsGalaxy Search Scope Monitor"="C:\PROGRA~2\MAPSGA~2\bar\1.bin\39srchmn.exe /m=2 /w /h"

"MapsGalaxy_39 Browser Plugin Loader"="C:\PROGRA~2\MAPSGA~2\bar\1.bin\39brmon.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"Facebook Update"="C:\Users\deben\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"Elbserver"="C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay"

"Spotify Web Helper"="C:\Users\deben\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"

"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 "

"AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

"AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

"MapsGalaxy Home Page Guard 64 bit"="C:\PROGRA~2\MAPSGA~2\bar\1.bin\AppIntegrator64.exe"

"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe "

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe ARM"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe Reader Speed Launcher"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="msnmsgr"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\Windows Live\\Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Spotify"

"hkey"="HKCU"

"command"="\"C:\\Users\\deben\\AppData\\Roaming\\Spotify\\Spotify.exe\" /uri spotify:autostart"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Spotify Web Helper"

"hkey"="HKCU"

"command"="\"C:\\Users\\deben\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\""

==== Startup Folders ======================

2012-07-11 19:07:44 1322 ----a-w- C:\users\deben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [undertermined Task]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1488088736-1313127206-2769114686-1001Core.job --a------ C:\Users\deben\AppData\Local\Facebook\Update\FacebookUpdate.exe [24/07/2012 16:55]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1488088736-1313127206-2769114686-1001UA.job --a------ C:\Users\deben\AppData\Local\Facebook\Update\FacebookUpdate.exe [24/07/2012 16:55]

==== Firefox Extensions ======================

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0

- MapsGalaxy - %ProfilePath%\extensions\39ffxtbr@MapsGalaxy_39.com

- Torntv - %ProfilePath%\extensions\torntv@torntv.com.xpi

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

- MapsGalaxy - %ProfilePath%\extensions\39ffxtbr@MapsGalaxy_39.com

- Mediavid - %ProfilePath%\extensions\cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com

- FreeHDSport TV - %ProfilePath%\extensions\fhdp@fhdp.tv.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

7ABE33792F2787D599B6963E71B9E8CD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll - Shockwave Flash

2BF85B6162528E0635DD8D632EB975C8 - C:\Users\deben\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll - Facebook Desktop

0B31B0F8FA99CFD009C8FBEA9E20C9DE - C:\Users\deben\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin

==== Deleting Files \ Folders ======================

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\torntv@torntv.com.xpi" deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

dlnembnfbcpjnepmfjmngjenhhajpdfd - C:\Program Files\IB Updater\source.crx[]

jbpkiefagocgkmemidfngdkamloieekf - C:\Program Files (x86)\TornTV.com\torn10.crx[]

kkfggacklibaabdomphfdpcodjgihgon - C:\Program Files (x86)\FirstRowSportApp.com\stv10.crx[]

niapdbllcanepiiimjjndipklodoedlc - No path found[]

Norton Identity Protection - deben - Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk

==== Chrome Fix ======================

C:\Users\deben\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage deleted successfully

C:\Users\deben\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^UX^xdm170^YY^be&ptb=36C28743-013B-4A3F-8A80-7A9AC8FF3F01&si=KI_MAPS_FIG_BEL_116"

"Default_Page_URL"="http://vaioportal.sony.eu"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] not found

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Start Page"="http://www.google.com"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

{25F70F62-98D0-43A9-9510-989E28A1C9F5} eBay Url="http://rover.ebay.com/rover/1/1553-42507-16445-59/4?mpre=http://shop.benl.ebay.be/?oemInLn=ieSrch-Q112&_nkw={searchTerms}"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_USERS\S-1-5-21-1488088736-1313127206-2769114686-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kkfggacklibaabdomphfdpcodjgihgon deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\deben\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\deben\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\users\deben\AppData\Local\Mozilla\Firefox\Profiles\ahegsr6j.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\users\deben\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\deben\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\windows\SysNative\dmwu.exesearch" deleted

"C:\Program Files (x86)\SweetIM" not found

"C:\Program Files (x86)\MapsGalaxy_39" not found

"C:\Program Files (x86)\MapsGalaxy_39" not found

"C:\Program Files (x86)\SweetIM" not found

"C:\Windows\Syswow64\jmdp" not found

==== EOF on ma 10/06/2013 at 20:22:30,57 ======================

Link naar reactie
Delen op andere sites

Hallo,

Daar is al heel wat verwijderd zeg :top:


    • Dubbelklik op 51a612a8b27e2-Zoek.pngZoek.exe om de tool te starten.
    • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
    • Kopieer nu onderstaande code en plak die in het grote invulvenster:
    • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.
       
      C:\Program Files (x86)\SweetIM;fs
      C:\Program Files (x86)\MapsGalaxy_39;fs
      C:\Windows\Syswow64\jmdp;fs
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
      "SweetIM"=-;r
      "MapsGalaxy Search Scope Monitor"=-;r
      "MapsGalaxy_39 Browser Plugin Loader"=-;r
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r64
      "MapsGalaxy Home Page Guard 64 bit"=-;r64
      MapsGalaxy;ff
      Mediavid;ff
      


    • Klik nu op de knop "Run script".
    • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
    • Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.
    • Post het geopende logje in het volgende bericht.

[*]Download adwcleaner.pngAdwCleaner by Xplode naar het bureaublad.


  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner om hem te starten.
  • Klik vervolgens op Verwijderen.
  • Klik bij AdwCleaner – Informatie op OK
  • Klik bij AdwCleaner – Herstarten Noodzakelijk op OK

Dat tijdens de actie de snelkoppelingen verdwijnen, is normaal.

Nadat de PC opnieuw is opgestart, opent een logfile.

Post aansluitend de inhoud van dit log in je volgende bericht.

Groet,

Mako

Link naar reactie
Delen op andere sites

Zoek.exe Version 4.0.0.2 Updated 03-June-2013

Tool run by deben on di 11/06/2013 at 9:54:24,47.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

==== FireFox Fix ======================

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0

user.js not found

---- Lines MapsGalaxy removed from prefs.js ----

---- Lines MapsGalaxy modified from prefs.js ----

---- Lines Mediavid removed from prefs.js ----

---- Lines Mediavid modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

prefs_20131006_2017_.backup

prefs_20131106_0954_.backup

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

user.js not found

---- Lines MapsGalaxy removed from prefs.js ----

---- Lines MapsGalaxy modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1370419451162,\"rdfTime\":1368303951000}}},{\"name\":\"app-profile\",\"addons\":{\"39ffxtbr@MapsGalaxy_39.com\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\39ffxtbr@MapsGalaxy_39.com\",\"mtime\":1370419397970,\"rdfTime\":1370419394102},\"cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com\",\"mtime\":1370878057845,\"rdfTime\":1370779442000},\"fhdp@fhdp.tv\":{\"descriptor\":\"C:\\\\Users\\\\deben\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\ahegsr6j.default\\\\extensions\\\\fhdp@fhdp.tv.xpi\",\"mtime\":1368358750099}}}]");

---- Lines Mediavid removed from prefs.js ----

---- Lines Mediavid modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

prefs_20131006_2017_.backup

prefs_20131106_0954_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SweetIM"=-

"MapsGalaxy Search Scope Monitor"=-

"MapsGalaxy_39 Browser Plugin Loader"=-

==== Registry Fix Code x64 ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MapsGalaxy Home Page Guard 64 bit"=-

==== Deleting Files \ Folders ======================

"C:\Program Files (x86)\SweetIM" not found

"C:\Program Files (x86)\MapsGalaxy_39" not found

"C:\Windows\Syswow64\jmdp" not found

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\39ffxtbr@MapsGalaxy_39.com" deleted

"C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\extensions\39ffxtbr@MapsGalaxy_39.com" deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

- Mediavid - %ProfilePath%\extensions\cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com

- FreeHDSport TV - %ProfilePath%\extensions\fhdp@fhdp.tv.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default

7ABE33792F2787D599B6963E71B9E8CD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll - Shockwave Flash

2BF85B6162528E0635DD8D632EB975C8 - C:\Users\deben\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll - Facebook Desktop

0B31B0F8FA99CFD009C8FBEA9E20C9DE - C:\Users\deben\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin

==== EOF on di 11/06/2013 at 9:55:06,12 ======================

# AdwCleaner v2.303 - Verslag gemaakt op 11/06/2013 om 10:07:47

# Geactualiseerd op 08/06/2013 door Xplode

# Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

# Gebruiker : deben - DEBEN-VAIO

# Opstarten Modus : Normale modus

# Gelanceerd vanaf : C:\Users\deben\Downloads\adwcleaner.exe

# Optie [Verwijderen]

***** [Diensten] *****

***** [Files / Mappen] *****

File Verwijderd : C:\Users\deben\Desktop\TornTV.lnk

Map Verwijderd : C:\Users\deben\AppData\Roaming\dvdvideosoftiehelpers

Map Verwijderd : C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\jetpack

***** [Register] *****

Sleutel Verwijderd : HKCU\Software\1ClickDownload

Sleutel Verwijderd : HKCU\Software\APN PIP

Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\Conduit

Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB

Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\MapsGalaxy_39

Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\searchqutoolbar

Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\SmartBar

Sleutel Verwijderd : HKCU\Software\AppDataLow\Toolbar

Sleutel Verwijderd : HKCU\Software\Conduit

Sleutel Verwijderd : HKCU\Software\DataMngr

Sleutel Verwijderd : HKCU\Software\ilivid

Sleutel Verwijderd : HKCU\Software\IM

Sleutel Verwijderd : HKCU\Software\ImInstaller

Sleutel Verwijderd : HKCU\Software\MapsGalaxy_39

Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}

Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

Sleutel Verwijderd : HKCU\Software\WNLT

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\Extension.DLL

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1

Sleutel Verwijderd : HKLM\Software\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B

Sleutel Verwijderd : HKLM\Software\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\sim-packages

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Toolbar.CT2269050

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}

Sleutel Verwijderd : HKLM\Software\Conduit

Sleutel Verwijderd : HKLM\Software\DeviceVM

Sleutel Verwijderd : HKLM\Software\DVDVideoSoftTB

Sleutel Verwijderd : HKLM\Software\IB Updater

Sleutel Verwijderd : HKLM\Software\iLividSRTB

Sleutel Verwijderd : HKLM\Software\MapsGalaxy_39

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

Sleutel Verwijderd : HKLM\SOFTWARE\MozillaPlugins\@MapsGalaxy_39.com/Plugin

Sleutel Verwijderd : HKLM\Software\PIP

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23119123-0854-469D-807A-171568457991}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5A17090E-A5E2-4E0A-8176-330A54611CFD}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74F6D582-5B40-4433-A71B-505374625775}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SweetIM Bundle by SweetPacks

Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WNLT

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}

Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}

Sleutel Verwijderd : HKLM\SOFTWARE\DataMngr

Sleutel Verwijderd : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}

Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar

Sleutel Verwijderd : HKLM\SOFTWARE\Tarma Installer

Waarde Verwijderd : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

Waarde Verwijderd : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}]

Waarde Verwijderd : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [39ffxtbr@MapsGalaxy_39.com]

Waarde Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]

Waarde Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

***** [browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Het register bevat geen enkele ongeoorloofde invoer.

-\\ Mozilla Firefox v21.0 (nl)

File : C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js

[OK] De file bevat geen enkele ongeoorloofde invoer.

File : C:\Users\deben\AppData\Roaming\Mozilla\Firefox\Profiles\ahegsr6j.default\prefs.js

Verwijderd : user_pref("browser.search.defaultenginename", "SweetIM Search");

Verwijderd : user_pref("browser.search.selectedEngine", "SweetIM Search");

Verwijderd : user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=6&barid={9E6A31D0-BAF8-11E2-8282-[...]

-\\ Google Chrome v [Onmogelijk de versie te verkrijgen]

File : C:\Users\deben\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] De file bevat geen enkele ongeoorloofde invoer.

*************************

AdwCleaner[s1].txt - [11708 octets] - [11/06/2013 10:07:47]

########## EOF - C:\AdwCleaner[s1].txt - [11769 octets] ##########

alvast bedankt Mako!

Link naar reactie
Delen op andere sites


Hoi,


  • Dubbelklik op 51a612a8b27e2-Zoek.pngZoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.
     
    Mediavid;ff
    FreeHDSport TV;ff
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\cb9ad6f4-a6db-493e-8aab-6a2b525d06f5@6cb56be9-0226-40cd-be18-54220b0b7b03.com];r
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\fhdp@fhdp.tv.xpi];r
    chromelook; 
    


  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Laat na het plaatsen van het logje maar even weten hoe het nu met de computer gaat :-)

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
 Delen

×
×
  • Nieuwe aanmaken...