Ga naar inhoud

Laptop is erg traag


Aanbevolen berichten

ComboFix 13-08-16.03 - Kim 18-08-2013 12:08:19.1.2 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.31.1043.18.4091.2525 [GMT 2:00]

Gestart vanuit: c:\users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93TZTI4O\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\Install.exe

c:\program files (x86)\SaveShare

c:\program files (x86)\SaveShare\sprotector.dll

c:\program files (x86)\SaveShare\uninstall.exe

c:\programdata\sAvenshare

c:\programdata\sAvenshare\A.dll

c:\programdata\sAvenshare\A.tlb

c:\programdata\sAvenshare\data\sAvenshare.dat

c:\programdata\sAvenshare\settings.ini

c:\programdata\sAvenshare\y.dll

c:\users\Kim\AppData\Local\.#

c:\users\Kim\zoek.exe

c:\windows\SysWow64\X86

.

Besmet exemplaar van c:\windows\SysWow64\user32.dll werd aangetroffen en gedesinfecteerd

Hersteld exemplaar van - c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-07-18 to 2013-08-18 ))))))))))))))))))))))))))))))

.

.

2013-08-16 06:55 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6EB92433-49B2-4118-85E5-F580F015727A}\mpengine.dll

2013-08-15 22:16 . 2013-08-15 22:18 -------- d-----w- c:\windows\system32\MRT

2013-08-15 20:00 . 2013-08-15 20:00 -------- d-----w- c:\programdata\Funny Bear Studio

2013-08-15 20:00 . 2011-08-16 11:48 -------- d-----w- c:\users\Kim\World Riddles 3 _Secrets of the Ages

2013-08-15 12:31 . 2013-08-15 12:31 -------- d-----w- c:\users\Kim\AppData\Roaming\Friday's games

2013-08-15 12:30 . 2012-01-28 05:35 -------- d-----w- c:\users\Kim\Gourma.._3_NL

2013-08-15 12:04 . 2013-08-15 12:30 -------- d-----w- c:\programdata\savensharei o

2013-08-15 06:42 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll

2013-08-15 06:42 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll

2013-08-15 06:42 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll

2013-08-15 06:42 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll

2013-08-15 06:42 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll

2013-08-15 06:42 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll

2013-08-15 06:42 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll

2013-08-15 06:42 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll

2013-08-11 19:54 . 2013-08-18 09:58 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service

2013-08-10 09:24 . 2013-08-10 09:25 -------- d-----w- c:\program files (x86)\Little Shop of Treasures Deluxe

2013-08-10 09:24 . 2010-01-27 21:29 25081658 ----a-w- c:\users\Kim\Little Shop of Treasures Deluxe.exe

2013-08-06 07:26 . 2013-08-06 07:26 -------- d-----w- c:\users\Kim\AppData\Roaming\Nordcurrent

2013-08-06 07:25 . 2013-08-05 22:04 -------- d-----w- c:\users\Kim\Happy Chef 2

2013-08-04 20:42 . 2013-08-04 20:42 -------- d-----w- c:\users\Kim\AppData\Roaming\Desperate Housewives

2013-08-04 20:17 . 2013-08-04 20:17 -------- d-----w- c:\program files (x86)\Buena Vista Games

2013-08-04 20:16 . 2013-08-04 20:16 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information

2013-08-04 20:16 . 2013-08-04 20:16 -------- d-----w- c:\users\Kim\AppData\Roaming\InstallShield

2013-07-27 22:47 . 2013-07-27 22:47 -------- d-----w- c:\users\Kim\AppData\Roaming\Tap It Games

2013-07-26 14:50 . 2013-07-26 14:50 -------- d-----w- c:\programdata\StarApp

2013-07-26 14:40 . 2013-08-15 20:00 -------- d-----w- c:\programdata\InstallMate

2013-07-24 13:17 . 2013-07-26 05:21 -------- d-----w- c:\users\Kim\AppData\Roaming\Ubisoft

2013-07-24 13:13 . 2013-07-24 13:13 -------- d-----w- c:\program files (x86)\Ubisoft

2013-07-24 13:11 . 2013-07-24 13:11 -------- d-----w- c:\users\Kim\AppData\Roaming\MysteryStudio

2013-07-24 10:45 . 2013-08-18 10:50 -------- d-----w- c:\users\Kim\AppData\Local\Temp

2013-07-24 10:45 . 2013-07-24 10:27 24064 ----a-w- c:\windows\zoek-delete.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-08-15 22:15 . 2012-11-13 07:11 78161360 ----a-w- c:\windows\system32\MRT.exe

2013-07-16 21:53 . 2013-07-16 21:53 388096 ----a-r- c:\users\Kim\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2013-07-16 21:52 . 2013-07-16 21:52 1402880 ----a-w- c:\users\Kim\HiJackThis.msi

2013-07-09 04:45 . 2013-08-15 06:41 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2013-07-07 08:54 . 2013-07-07 08:54 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-07-07 08:54 . 2012-11-08 11:44 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-07-07 08:54 . 2012-11-08 11:44 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2013-06-27 22:40 . 2013-03-14 16:18 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-06-27 22:40 . 2012-11-08 14:46 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys

2013-06-27 22:40 . 2012-11-08 14:46 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-06-12 08:35 . 2012-11-09 20:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-06-12 08:35 . 2012-11-09 20:30 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-06-05 03:34 . 2013-07-11 21:53 3153920 ----a-w- c:\windows\system32\win32k.sys

2013-06-04 06:00 . 2013-07-11 21:53 624128 ----a-w- c:\windows\system32\qedit.dll

2013-06-04 04:53 . 2013-07-11 21:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll

2012-11-28 07:15 . 2013-01-28 18:15 85504 ---h--w- c:\program files (x86)\IeAdsBlocker.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2}]

2013-08-15 12:04 184320 ----a-w- c:\programdata\savensharei o\QaJcHO.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2009-03-25 1840424]

"Spotify Web Helper"="c:\users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-06 1104384]

"Spotify"="c:\users\Kim\AppData\Roaming\Spotify\Spotify.exe" [2013-07-06 4640768]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"NBKeyScan"="c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-12-02 2221352]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]

R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]

R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

S0 aswRvrt;aswRvrt; [x]

S0 aswVmm;aswVmm; [x]

S1 aswSnx;aswSnx; [x]

S1 aswSP;aswSP; [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 aswFsBlk;aswFsBlk; [x]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]

S2 ogmservice;Online Games Manager;c:\program files (x86)\Online Games Manager\ogmservice.exe;c:\program files (x86)\Online Games Manager\ogmservice.exe [x]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2013-08-18 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-09 08:35]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.nl/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.254

FF - ProfilePath - c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine -

FF - prefs.js: keyword.URL -

FF - prefs.js: browser.startup.homepage -

FF - ExtSQL: 2013-08-15 14:04; qy2gk4uio@eizuuii.org; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qy2gk4uio@eizuuii.org

FF - ExtSQL: 2013-08-16 18:04; ppc.bv1awgq@b-ayavcc.edu; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ppc.bv1awgq@b-ayavcc.edu

FF - ExtSQL: !HIDDEN! 2012-11-14 21:26; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

.

- - - - ORPHANS VERWIJDERD - - - -

.

BHO-{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1} - c:\programdata\sAvenshare\A.dll

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

AddRemove-1ClickDownload - c:\program files (x86)\FTDownloader.com\uninst.exe

AddRemove-Dll-Files.com Fixer_is1 - c:\program files (x86)\Dll-Files.com Fixer\unins000.exe

AddRemove-SP_4e24eecb - c:\program files (x86)\WebSearch\uninstall.exe

AddRemove-SP_703c874a - c:\program files (x86)\SaveShare\uninstall.exe

AddRemove-{0611430E-8ACB-63BC-59D5-094BA74F6D45} - c:\progra~3\INSTAL~1\{A22D9~1\Setup.exe

AddRemove-{0BCC2557-0893-C7C7-159F-741222C6B313} - c:\progra~3\INSTAL~1\{E17FE~1\Setup.exe

AddRemove-{0F44DC3F-6E62-4961-A14B-95323C512F9B}_is1 - c:\program files (x86)\Solibo Ltd\NCdownloader\unins000.exe

AddRemove-{12993942-DD3A-93E2-C271-CE9EDA334D26} - c:\progra~3\INSTAL~1\{2B359~1\Setup.exe

AddRemove-{16ED46D0-EF3C-C3AD-D468-77F505C98203} - c:\progra~3\INSTAL~1\{EF9E6~1\Setup.exe

AddRemove-{18267028-7522-C8A2-DCE0-01127F53EDB4} - c:\progra~3\INSTAL~1\{B1B9F~1\Setup.exe

AddRemove-{4B163043-CC8A-147E-3197-DA508F4FA2DE} - c:\progra~3\INSTAL~1\{28D9E~1\Setup.exe

AddRemove-{4C3EDE29-88E7-E1EB-2289-E36E9732453E} - c:\progra~3\INSTAL~1\{02299~1\Setup.exe

AddRemove-{51B8D190-8C9D-67B9-BBBA-B3A54CC45322} - c:\progra~3\INSTAL~1\{C5662~1\Setup.exe

AddRemove-{57695C90-8DB1-45C5-ECEC-44165360478A} - c:\progra~3\INSTAL~1\{9C79A~1\Setup.exe

AddRemove-{5FAEB08B-7EAB-0781-7EEB-31D3AC0B1ADA} - c:\progra~3\INSTAL~1\{67BF8~1\Setup.exe

AddRemove-{6890042F-2A66-3684-6E27-D5F86BBDB77F} - c:\progra~3\INSTAL~1\{92CAC~1\Setup.exe

AddRemove-{7FC77E0A-BE31-FADA-A999-03CD68157009} - c:\progra~3\INSTAL~1\{94616~1\Setup.exe

AddRemove-{9BEA2784-CBC6-AC80-E740-0175DFEE0BA9} - c:\progra~3\INSTAL~1\{85517~1\Setup.exe

AddRemove-{A2BAE8B9-9018-94AA-33A5-C3F6BA37BCC0} - c:\progra~3\INSTAL~1\{B3A54~1\Setup.exe

AddRemove-{A35747C3-1C97-9368-A69D-A384AB0CF8A5} - c:\progra~3\INSTAL~1\{4919C~1\Setup.exe

AddRemove-{ABD30C90-91D2-CE97-9006-AB90E1B4B02D} - c:\progra~3\INSTAL~1\{AF88D~1\Setup.exe

AddRemove-{AED7E0DA-B57E-C384-E268-0E38B5720DB1} - c:\progra~3\INSTAL~1\{617F5~1\Setup.exe

AddRemove-{B0AA2343-F71D-041B-F547-07F2B85DC689} - c:\progra~3\INSTAL~1\{32E4E~1\Setup.exe

AddRemove-{B313B61D-B5BF-C87D-C723-BAA7CABE2820} - c:\progra~3\INSTAL~1\{10FB9~1\Setup.exe

AddRemove-{BF2DB609-8FCA-D798-3A36-4C2F26474C5A} - c:\progra~3\INSTAL~1\{74111~1\Setup.exe

AddRemove-{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} - c:\programdata\SearchNewTab\uninstall.exe

AddRemove-{D5DF7465-5DE1-8672-BB6A-E95E9C0447E7} - c:\progra~3\INSTAL~1\{9517F~1\Setup.exe

AddRemove-{D880A1A1-747F-0AFC-36DF-6AB80B28EC54} - c:\progra~3\INSTAL~1\{B3B4C~1\Setup.exe

AddRemove-{E0272288-5372-FDA8-5A93-8A1306F65621} - c:\progra~3\INSTAL~1\{15922~1\Setup.exe

AddRemove-{EB9B3528-EA62-6D75-6716-BC4953A9DAF8} - c:\progra~3\INSTAL~1\{6231D~1\Setup.exe

AddRemove-{ED5F85F7-9926-D783-94AB-1CF7F05657F4} - c:\progra~3\INSTAL~1\{A2ECF~1\Setup.exe

AddRemove-{F1AF3311-0293-825A-3C1A-B7FD0106FFC4} - c:\progra~3\INSTAL~1\{50366~1\Setup.exe

AddRemove-GoforFiles - c:\program files (x86)\GoforFiles\uninstall.exe

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]

@="?????????????????? v1"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]

@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]

@="?????????????????? v2"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]

@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\program files\AVAST Software\Avast\AvastSvc.exe

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe

c:\windows\SysWOW64\IoctlSvc.exe

.

**************************************************************************

.

Voltooingstijd: 2013-08-18 12:55:39 - machine werd herstart

ComboFix-quarantined-files.txt 2013-08-18 10:55

.

Pre-Run: 384.410.374.144 bytes beschikbaar

Post-Run: 384.212.975.616 bytes beschikbaar

.

- - End Of File - - 0C19A7C11B3EE11871BFD020F3230315

A36C5E4F47E84449FF07ED3517B43A31

Link naar reactie
Delen op andere sites

  • Reacties 32
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

Schakel alle antivirus- en antispywareprogramma's uit, want deze kunnen namelijk conflicteren met ComboFix.

(hier of hier) kan je lezen hoe je de gebruikte beveiligingssoftware kunt uitschakelen.

Open een nieuw leeg Kladblok scherm, kopieer en plak hierin de volgende code.

 
 Registry::
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2}]

 Firefox::
 FF - ProfilePath - c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\
 FF - prefs.js: browser.search.defaulturl -
 FF - prefs.js: browser.search.selectedEngine -
 FF - prefs.js: keyword.URL -
 FF - prefs.js: browser.startup.homepage -
 FF - ExtSQL: 2013-08-15 14:04; qy2gk4uio@eizuuii.org; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qy2gk4uio@eizuuii. org
 FF - ExtSQL: 2013-08-16 18:04; ppc.bv1awgq@b-ayavcc.edu; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ppc.bv1awgq@b-ayavcc.edu

Sla dit op op je Bureaublad als CFScript.txt

Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld:

CFScript.gif

Nu zal ComboFix vanzelf worden gestart.

Start opnieuw op als daarom gevraagd wordt, en post de inhoud van de Combofix.txt in je volgende antwoord.

Link naar reactie
Delen op andere sites

ComboFix 13-08-18.01 - Kim 18-08-2013 17:14:27.2.2 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.31.1043.18.4091.2445 [GMT 2:00]

Gestart vanuit: c:\users\Kim\Desktop\ComboFix.exe

gebruikte Opdracht switches :: c:\users\Kim\Desktop\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-07-18 to 2013-08-18 ))))))))))))))))))))))))))))))

.

.

2013-08-18 15:21 . 2013-08-18 15:21 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-08-16 06:55 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6EB92433-49B2-4118-85E5-F580F015727A}\mpengine.dll

2013-08-15 22:16 . 2013-08-15 22:18 -------- d-----w- c:\windows\system32\MRT

2013-08-15 20:00 . 2013-08-15 20:00 -------- d-----w- c:\programdata\Funny Bear Studio

2013-08-15 20:00 . 2011-08-16 11:48 -------- d-----w- c:\users\Kim\World Riddles 3 _Secrets of the Ages

2013-08-15 12:31 . 2013-08-15 12:31 -------- d-----w- c:\users\Kim\AppData\Roaming\Friday's games

2013-08-15 12:30 . 2012-01-28 05:35 -------- d-----w- c:\users\Kim\Gourma.._3_NL

2013-08-15 12:04 . 2013-08-15 12:30 -------- d-----w- c:\programdata\savensharei o

2013-08-15 06:42 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll

2013-08-15 06:42 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll

2013-08-15 06:42 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll

2013-08-15 06:42 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll

2013-08-15 06:42 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll

2013-08-15 06:42 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll

2013-08-15 06:42 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll

2013-08-15 06:42 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll

2013-08-11 19:54 . 2013-08-18 09:58 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service

2013-08-10 09:24 . 2013-08-10 09:25 -------- d-----w- c:\program files (x86)\Little Shop of Treasures Deluxe

2013-08-10 09:24 . 2010-01-27 21:29 25081658 ----a-w- c:\users\Kim\Little Shop of Treasures Deluxe.exe

2013-08-06 07:26 . 2013-08-06 07:26 -------- d-----w- c:\users\Kim\AppData\Roaming\Nordcurrent

2013-08-06 07:25 . 2013-08-05 22:04 -------- d-----w- c:\users\Kim\Happy Chef 2

2013-08-04 20:42 . 2013-08-04 20:42 -------- d-----w- c:\users\Kim\AppData\Roaming\Desperate Housewives

2013-08-04 20:17 . 2013-08-04 20:17 -------- d-----w- c:\program files (x86)\Buena Vista Games

2013-08-04 20:16 . 2013-08-04 20:16 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information

2013-08-04 20:16 . 2013-08-04 20:16 -------- d-----w- c:\users\Kim\AppData\Roaming\InstallShield

2013-07-27 22:47 . 2013-07-27 22:47 -------- d-----w- c:\users\Kim\AppData\Roaming\Tap It Games

2013-07-26 14:50 . 2013-07-26 14:50 -------- d-----w- c:\programdata\StarApp

2013-07-26 14:40 . 2013-08-15 20:00 -------- d-----w- c:\programdata\InstallMate

2013-07-24 13:17 . 2013-07-26 05:21 -------- d-----w- c:\users\Kim\AppData\Roaming\Ubisoft

2013-07-24 13:13 . 2013-07-24 13:13 -------- d-----w- c:\program files (x86)\Ubisoft

2013-07-24 13:11 . 2013-07-24 13:11 -------- d-----w- c:\users\Kim\AppData\Roaming\MysteryStudio

2013-07-24 10:45 . 2013-08-18 15:21 -------- d-----w- c:\users\Kim\AppData\Local\Temp

2013-07-24 10:45 . 2013-07-24 10:27 24064 ----a-w- c:\windows\zoek-delete.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-08-15 22:15 . 2012-11-13 07:11 78161360 ----a-w- c:\windows\system32\MRT.exe

2013-07-16 21:53 . 2013-07-16 21:53 388096 ----a-r- c:\users\Kim\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2013-07-16 21:52 . 2013-07-16 21:52 1402880 ----a-w- c:\users\Kim\HiJackThis.msi

2013-07-09 04:45 . 2013-08-15 06:41 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2013-07-07 08:54 . 2013-07-07 08:54 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-07-07 08:54 . 2012-11-08 11:44 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-07-07 08:54 . 2012-11-08 11:44 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2013-06-27 22:40 . 2013-03-14 16:18 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-06-27 22:40 . 2012-11-08 14:46 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys

2013-06-27 22:40 . 2012-11-08 14:46 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-06-12 08:35 . 2012-11-09 20:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-06-12 08:35 . 2012-11-09 20:30 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-06-05 03:34 . 2013-07-11 21:53 3153920 ----a-w- c:\windows\system32\win32k.sys

2013-06-04 06:00 . 2013-07-11 21:53 624128 ----a-w- c:\windows\system32\qedit.dll

2013-06-04 04:53 . 2013-07-11 21:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll

2012-11-28 07:15 . 2013-01-28 18:15 85504 ---h--w- c:\program files (x86)\IeAdsBlocker.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1}]

c:\programdata\sAvenshare\A.dll [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2}]

2013-08-15 12:04 184320 ----a-w- c:\programdata\savensharei o\QaJcHO.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2009-03-25 1840424]

"Spotify Web Helper"="c:\users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-06 1104384]

"Spotify"="c:\users\Kim\AppData\Roaming\Spotify\Spotify.exe" [2013-07-06 4640768]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"NBKeyScan"="c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-12-02 2221352]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]

R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]

R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

S0 aswRvrt;aswRvrt; [x]

S0 aswVmm;aswVmm; [x]

S1 aswSnx;aswSnx; [x]

S1 aswSP;aswSP; [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 aswFsBlk;aswFsBlk; [x]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]

S2 ogmservice;Online Games Manager;c:\program files (x86)\Online Games Manager\ogmservice.exe;c:\program files (x86)\Online Games Manager\ogmservice.exe [x]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2013-08-18 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-09 08:35]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.nl/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.254

FF - ProfilePath - c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\

FF - ExtSQL: 2013-08-15 14:04; qy2gk4uio@eizuuii.org; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qy2gk4uio@eizuuii.org

FF - ExtSQL: 2013-08-16 18:04; ppc.bv1awgq@b-ayavcc.edu; c:\users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\ppc.bv1awgq@b-ayavcc.edu

FF - ExtSQL: !HIDDEN! 2012-11-14 21:26; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

.

- - - - ORPHANS VERWIJDERD - - - -

.

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

AddRemove-1ClickDownload - c:\program files (x86)\FTDownloader.com\uninst.exe

AddRemove-Dll-Files.com Fixer_is1 - c:\program files (x86)\Dll-Files.com Fixer\unins000.exe

AddRemove-SP_4e24eecb - c:\program files (x86)\WebSearch\uninstall.exe

AddRemove-SP_703c874a - c:\program files (x86)\SaveShare\uninstall.exe

AddRemove-{0611430E-8ACB-63BC-59D5-094BA74F6D45} - c:\progra~3\INSTAL~1\{A22D9~1\Setup.exe

AddRemove-{0BCC2557-0893-C7C7-159F-741222C6B313} - c:\progra~3\INSTAL~1\{E17FE~1\Setup.exe

AddRemove-{0F44DC3F-6E62-4961-A14B-95323C512F9B}_is1 - c:\program files (x86)\Solibo Ltd\NCdownloader\unins000.exe

AddRemove-{12993942-DD3A-93E2-C271-CE9EDA334D26} - c:\progra~3\INSTAL~1\{2B359~1\Setup.exe

AddRemove-{16ED46D0-EF3C-C3AD-D468-77F505C98203} - c:\progra~3\INSTAL~1\{EF9E6~1\Setup.exe

AddRemove-{18267028-7522-C8A2-DCE0-01127F53EDB4} - c:\progra~3\INSTAL~1\{B1B9F~1\Setup.exe

AddRemove-{4B163043-CC8A-147E-3197-DA508F4FA2DE} - c:\progra~3\INSTAL~1\{28D9E~1\Setup.exe

AddRemove-{4C3EDE29-88E7-E1EB-2289-E36E9732453E} - c:\progra~3\INSTAL~1\{02299~1\Setup.exe

AddRemove-{51B8D190-8C9D-67B9-BBBA-B3A54CC45322} - c:\progra~3\INSTAL~1\{C5662~1\Setup.exe

AddRemove-{57695C90-8DB1-45C5-ECEC-44165360478A} - c:\progra~3\INSTAL~1\{9C79A~1\Setup.exe

AddRemove-{5FAEB08B-7EAB-0781-7EEB-31D3AC0B1ADA} - c:\progra~3\INSTAL~1\{67BF8~1\Setup.exe

AddRemove-{6890042F-2A66-3684-6E27-D5F86BBDB77F} - c:\progra~3\INSTAL~1\{92CAC~1\Setup.exe

AddRemove-{7FC77E0A-BE31-FADA-A999-03CD68157009} - c:\progra~3\INSTAL~1\{94616~1\Setup.exe

AddRemove-{9BEA2784-CBC6-AC80-E740-0175DFEE0BA9} - c:\progra~3\INSTAL~1\{85517~1\Setup.exe

AddRemove-{A2BAE8B9-9018-94AA-33A5-C3F6BA37BCC0} - c:\progra~3\INSTAL~1\{B3A54~1\Setup.exe

AddRemove-{A35747C3-1C97-9368-A69D-A384AB0CF8A5} - c:\progra~3\INSTAL~1\{4919C~1\Setup.exe

AddRemove-{ABD30C90-91D2-CE97-9006-AB90E1B4B02D} - c:\progra~3\INSTAL~1\{AF88D~1\Setup.exe

AddRemove-{AED7E0DA-B57E-C384-E268-0E38B5720DB1} - c:\progra~3\INSTAL~1\{617F5~1\Setup.exe

AddRemove-{B0AA2343-F71D-041B-F547-07F2B85DC689} - c:\progra~3\INSTAL~1\{32E4E~1\Setup.exe

AddRemove-{B313B61D-B5BF-C87D-C723-BAA7CABE2820} - c:\progra~3\INSTAL~1\{10FB9~1\Setup.exe

AddRemove-{BF2DB609-8FCA-D798-3A36-4C2F26474C5A} - c:\progra~3\INSTAL~1\{74111~1\Setup.exe

AddRemove-{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} - c:\programdata\SearchNewTab\uninstall.exe

AddRemove-{D5DF7465-5DE1-8672-BB6A-E95E9C0447E7} - c:\progra~3\INSTAL~1\{9517F~1\Setup.exe

AddRemove-{D880A1A1-747F-0AFC-36DF-6AB80B28EC54} - c:\progra~3\INSTAL~1\{B3B4C~1\Setup.exe

AddRemove-{E0272288-5372-FDA8-5A93-8A1306F65621} - c:\progra~3\INSTAL~1\{15922~1\Setup.exe

AddRemove-{EB9B3528-EA62-6D75-6716-BC4953A9DAF8} - c:\progra~3\INSTAL~1\{6231D~1\Setup.exe

AddRemove-{ED5F85F7-9926-D783-94AB-1CF7F05657F4} - c:\progra~3\INSTAL~1\{A2ECF~1\Setup.exe

AddRemove-{F1AF3311-0293-825A-3C1A-B7FD0106FFC4} - c:\progra~3\INSTAL~1\{50366~1\Setup.exe

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]

@="?????????????????? v1"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]

@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]

@="?????????????????? v2"

.

[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]

@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2013-08-18 17:24:09

ComboFix-quarantined-files.txt 2013-08-18 15:24

ComboFix2.txt 2013-08-18 10:55

.

Pre-Run: 384.281.964.544 bytes beschikbaar

Post-Run: 384.032.841.728 bytes beschikbaar

.

- - End Of File - - 698D9D97AD25176A4F7F5628DD36DD0E

A36C5E4F47E84449FF07ED3517B43A31

Link naar reactie
Delen op andere sites

Download 51a612a8b27e2-Zoek.pngzoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Klik op de knop "Options" en vink nu de onderstaande opties aan.
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

 
startupall; 
filesrcm; 
c:\programdata\savensharei o;fs
c:\programdata\StarApp;fs
c:\programdata\InstallMate;fs
c:\windows\zoek-delete.exe;f
c:\programdata\sAvenshare:fs
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1}];r64
{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1};c
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2}];r64
{F55A9352-6C81-1A82-F024-7CBF7C0919D2}];c

Vink nu de onderstaande opties aan.

  • Firefox Look
  • Chrome Look
  • Firefox Defaults
  • Reset Chrome
  • IE Defaults
  • Auto Clean

  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.
  • Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Zoek.exe Version 4.0.0.4 Updated 10-August-2013

Tool run by Kim on zo 18-08-2013 at 23:21:47,42.

Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\Kim\Desktop\zoek.exe [script inserted] [Checkboxes used]

==== Older Logs ======================

C:\zoek-results17-07-2013-2208.log 11842 bytes

C:\zoek-results24-07-2013-1251.log 123211 bytes

==== Creating Sample_18-08-2013_2326.zip ======================

Copied file C:\Users\Kim\Little Shop of Treasures Deluxe.exe to sample\Little Shop of Treasures Deluxe.exe

sample\Little Shop of Treasures Deluxe.exe renamed to C620B75C4FC4EB2DF96B4DE7B33B5BDC

C:\Users\Public\Desktop\sample_18-08-2013_2326.zip created successfully

==== Deleting CLSID Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

==== FireFox Fix ======================

Deleted from C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\prefs.js:

user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");

user_pref("browser.search.defaultenginename", "");

user_pref("browser.search.defaultenginename,S", "");

user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");

user_pref("browser.search.selectedEngine,S", "");

user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");

user_pref("browser.search.order.1", "");

user_pref("browser.search.order.1,S", "");

user_pref("sweetim.toolbar.previous.keyword.URL", "");

Added to C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\prefs.js:

user_pref("browser.startup.homepage", "Google");

user_pref("browser.search.defaulturl", "Google=");

user_pref("browser.newtab.url", "Google");

user_pref("browser.search.defaultengine", "Google");

user_pref("browser.search.defaultenginename", "Google");

user_pref("browser.search.selectedEngine", "Google");

user_pref("browser.search.order.1", "Google");

user_pref("keyword.URL", "Google=");

user_pref("browser.search.suggest.enabled", true);

user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default

user.js not found

---- Lines qy2gk4uio@eizuuii.org removed from prefs.js ----

user_pref("extensions.bootstrappedAddons", "{\"qy2gk4uio@eizuuii.org\":{\"version\":\"5.10\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qy2gk4uio@eizuuii.org\"},\"ppc.bv1awgq@b-ayavcc.edu\":{\"version\":\"5.10\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\ppc.bv1awgq@b-ayavcc.edu\"}}");

---- Lines qy2gk4uio@eizuuii.org modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926,\"rdfTime\":1242939258000},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1369898841599,\"rdfTime\":1368089726000}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1376776761081,\"rdfTime\":1376776760931}}},{\"name\":\"winreg-app-user\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\MozillaAddOn3\",\"mtime\":1352924793926,\"rdfTime\":1242939258000}}},{\"name\":\"app-profile\",\"addons\":{\"leethax@leethax.net\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\leethax@leethax.net.xpi\",\"mtime\":1376251179982},\"ppc.bv1awgq@b-ayavcc.edu\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\ppc.bv1awgq@b-ayavcc.edu\",\"mtime\":1376775722349,\"rdfTime\":1345060300214},\"qy2gk4uio@eizuuii.org\":{\"descriptor\":\"C:\\\\Users\\\\Kim\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\o3rq6e92.default\\\\extensions\\\\qy2gk4uio@eizuuii.org\",\"mtime\":1376776894945,\"rdfTime\":1345032248153}}}]");

---- Lines babylon removed from prefs.js ----

user_pref("extensions.BabylonToolbar.prtkDS", 0);

user_pref("extensions.BabylonToolbar.prtkHmpg", 0);

---- Lines babylon modified from prefs.js ----

---- Lines SweetIM removed from prefs.js ----

user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");

user_pref("sweetim.toolbar.searchguard.enable", "");

user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");

user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");

---- Lines SweetIM modified from prefs.js ----

---- FireFox user.js and prefs.js backups ----

user_24-07-2013_1233_.backup

prefs_18-08-2013_2326_.backup

prefs_24-07-2013_1233_.backup

==== Registry Fix Code x64 ======================

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{69FCDB30-084A-8DEF-27D0-F3913D4B2CD1}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2}]

==== Deleting Files \ Folders ======================

"c:\windows\zoek-delete.exe" not found

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\Invalidprefs.js" deleted

"C:\Users\Kim\Little Shop of Treasures Deluxe.exe" deleted

"c:\programdata\savensharei o" deleted

"c:\programdata\StarApp" deleted

"c:\programdata\InstallMate" deleted

"C:\ProgramData\savensharei o" deleted

"C:\ProgramData\StarApp" deleted

"C:\ProgramData\InstallMate" deleted

"C:\Users\Kim\AppData\LocalLow\IAC" deleted

"C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default\extensions\qy2gk4uio@eizuuii.org" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

2013-08-18 10:05:18 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe

2013-08-18 10:05:18 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe

2013-08-18 10:05:18 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe

2013-08-18 10:05:18 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe

2013-08-18 10:05:18 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe

2013-08-04 20:16:20 D9BF7B25AA656E5B09E66D027A6943B5 1140 ----a-w- C:\Windows\disney.ini

====== C:\Users\Kim\AppData\Local\Temp ====

====== C:\Windows\SysWOW64 =====

2013-08-15 06:42:13 AE8EB083B050E17A7D6EB5E28AECDDD6 1166848 ----a-w- C:\Windows\SysWOW64\crypt32.dll

2013-08-15 06:42:08 68EAAEDF0365168B804E8728368FA946 175104 ----a-w- C:\Windows\SysWOW64\wintrust.dll

2013-08-15 06:42:07 7CA1BECEA5DE2643ADDAD32670E7A4C9 140288 ----a-w- C:\Windows\SysWOW64\cryptsvc.dll

2013-08-15 06:42:06 7B851A8018B1EA00A69707A390004884 103936 ----a-w- C:\Windows\SysWOW64\cryptnet.dll

2013-08-15 06:41:55 D5E18BA95F9E7D787D25EF07AC68603E 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll

2013-08-15 06:41:47 0805487A6036A9F9C4E7AF7FEF835529 1620992 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL

2013-08-15 06:41:45 4DC999CED9429939D75682EBD7D48901 663552 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll

2013-08-15 06:41:41 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

2013-08-15 06:41:39 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

2013-08-15 06:41:37 528D298F9914C558EA7A9809BE598E65 1292192 ----a-w- C:\Windows\SysWOW64\ntdll.dll

2013-08-15 06:41:36 77F5D2CB80697EB96C45E79A869A6FAC 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll

2013-08-15 06:41:34 4E77948A7BD16BA5724EC79C60176B03 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll

2013-08-15 06:41:34 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

2013-08-15 06:41:33 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

2013-08-15 06:41:33 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

2013-08-15 06:41:24 3173F614E291666863678A6C66568063 6036480 ----a-w- C:\Windows\SysWOW64\mshtml.dll

2013-08-15 06:41:20 0C23641D79723940D2AD151664A0825C 11020800 ----a-w- C:\Windows\SysWOW64\ieframe.dll

2013-08-15 06:41:18 E0EE8761EDC829EB0BC44B6EAA3E9677 1231872 ----a-w- C:\Windows\SysWOW64\urlmon.dll

2013-08-15 06:41:18 00A6F17B36BF1D19B8EDF5DDAA615F31 627712 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

2013-08-15 06:41:16 8B2F4C327F07BE7AC7BDB120A6B630AA 981504 ----a-w- C:\Windows\SysWOW64\wininet.dll

2013-08-15 06:41:14 B204E8A9530ADF9D179BC55695B12BD6 176640 ----a-w- C:\Windows\SysWOW64\ieui.dll

2013-08-15 06:41:14 3CC89D7E8E267C78022E2A0511BC1CF9 2078208 ----a-w- C:\Windows\SysWOW64\iertutil.dll

2013-08-15 06:41:13 889F87BF86CF6A03D597253DBFDF71EE 67584 ----a-w- C:\Windows\SysWOW64\mshtmled.dll

2013-08-15 06:41:13 3956B2475E844DD9BFDD0571688C4D9F 48640 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

2013-08-15 06:41:12 EA5B7A2226C2B2E008AB126F871639D3 132096 ----a-w- C:\Windows\SysWOW64\url.dll

2013-08-15 06:41:12 5434C1F5612184724EAC890A5C3E537D 1638912 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2013-08-15 06:42:14 287998A9BA0140ABB59792CDEB2F8483 1472512 ----a-w- C:\Windows\Sysnative\crypt32.dll

2013-08-15 06:42:10 959041D7014C97133D859B45BCA0FC58 224256 ----a-w- C:\Windows\Sysnative\wintrust.dll

2013-08-15 06:42:07 6B400F211BEE880A37A1ED0368776BF4 184320 ----a-w- C:\Windows\Sysnative\cryptsvc.dll

2013-08-15 06:42:06 A6B726DCA228F7878E38368A1BDC68BE 139776 ----a-w- C:\Windows\Sysnative\cryptnet.dll

2013-08-15 06:41:55 B3CA3253009D26666F5BCB16E77D2618 2048 ----a-w- C:\Windows\Sysnative\tzres.dll

2013-08-15 06:41:47 D29200AB0B37B7293C6942EAF755295E 1888768 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL

2013-08-15 06:41:46 26036E228D2467DE6975AD819C22C043 1217024 ----a-w- C:\Windows\Sysnative\rpcrt4.dll

2013-08-15 06:41:38 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe

2013-08-15 06:41:38 8E45DD84F8F786B2DB94AD95225B9246 1732032 ----a-w- C:\Windows\Sysnative\ntdll.dll

2013-08-15 06:41:37 D6180FBBADA79BC28E5FD8187EBE7F64 243712 ----a-w- C:\Windows\Sysnative\wow64.dll

2013-08-15 06:41:26 83EDF2B580F1483CC6ED226DEAEEF886 9065472 ----a-w- C:\Windows\Sysnative\mshtml.dll

2013-08-15 06:41:23 F1DBE3869C1573AB5E6300F927603936 12295680 ----a-w- C:\Windows\Sysnative\ieframe.dll

2013-08-15 06:41:18 B6843A2C9FEDD7FC4F71AB05B2E04037 735232 ----a-w- C:\Windows\Sysnative\msfeeds.dll

2013-08-15 06:41:18 15607E09506CF9F3BAD8FEB139A6D630 1493504 ----a-w- C:\Windows\Sysnative\urlmon.dll

2013-08-15 06:41:15 63DE09F0F87772A49C6A4DF69AC13774 1188864 ----a-w- C:\Windows\Sysnative\wininet.dll

2013-08-15 06:41:14 F5D2F19D42E602572A4462474D3D1013 247808 ----a-w- C:\Windows\Sysnative\ieui.dll

2013-08-15 06:41:14 AAD3413B7903DE9A9CFAAB9D2DE1E859 2458112 ----a-w- C:\Windows\Sysnative\iertutil.dll

2013-08-15 06:41:13 F97AB70AF6926EC1854724ECC06E69A8 65024 ----a-w- C:\Windows\Sysnative\jsproxy.dll

2013-08-15 06:41:13 C546E6733B16A048438AC7F8E006E1F2 134144 ----a-w- C:\Windows\Sysnative\url.dll

2013-08-15 06:41:13 54971809075D905822E88AB09A25FDB4 97792 ----a-w- C:\Windows\Sysnative\mshtmled.dll

2013-08-15 06:41:12 E6E84B4476280D3ACF339344C3B4CD65 1638912 ----a-w- C:\Windows\Sysnative\mshtml.tlb

====== C:\Windows\Sysnative\drivers =====

2013-08-15 06:41:32 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\Sysnative\drivers\tssecsrv.sys

2013-08-15 06:41:31 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys

====== C:\Windows\Tasks ======

2013-07-24 10:26:00 CA67EA86DEC39648A65E8A200D1309E7 3294 ----a-w- C:\Windows\Sysnative\Tasks\4470

2013-07-24 10:25:58 0395EDD724B994404FB7791E10C63A11 3214 ----a-w- C:\Windows\Sysnative\Tasks\0

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\Program Files (x86) =====

2013-08-11 19:54:51 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service

2013-08-10 09:24:54 -------- d-----w- C:\Program Files (x86)\Little Shop of Treasures Deluxe

2013-08-04 20:17:13 -------- d-----w- C:\Program Files (x86)\Buena Vista Games

2013-08-04 20:16:44 -------- d--h--w- C:\Program Files (x86)\InstallShield Installation Information

2013-07-24 13:13:00 -------- d-----w- C:\Program Files (x86)\Ubisoft

======= C: =====

====== C:\Users\Kim\AppData\Roaming ======

2013-08-18 15:24:11 -------- d-----w- C:\users\Public\AppData\Local\temp

2013-08-18 15:24:11 -------- d-----w- C:\users\Default\AppData\Local\temp

2013-08-18 15:24:11 -------- d-----w- C:\users\Default User\AppData\Local\temp

2013-08-15 12:31:24 -------- d-----w- C:\users\Kim\AppData\Roaming\Friday's games

2013-08-10 09:25:01 -------- d-----w- C:\users\Kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Little Shop of Treasures Deluxe

2013-08-06 07:26:16 -------- d-----w- C:\users\Kim\AppData\Roaming\Nordcurrent

2013-08-04 20:42:05 -------- d-----w- C:\users\Kim\AppData\Roaming\Desperate Housewives

2013-08-04 20:16:12 -------- d-----w- C:\users\Kim\AppData\Roaming\InstallShield

2013-07-27 22:47:40 -------- d-----w- C:\users\Kim\AppData\Roaming\Tap It Games

2013-07-24 13:17:42 -------- d-----w- C:\users\Kim\AppData\Roaming\Ubisoft

2013-07-24 13:11:36 -------- d-----w- C:\users\Kim\AppData\Roaming\MysteryStudio

2013-07-24 10:45:05 -------- d-----w- C:\users\Kim\AppData\Local\Temp

====== C:\Users\Kim ======

2013-08-18 10:55:42 -------- d-----w- C:\Users\Public\AppData

2013-08-15 20:00:59 -------- d-----w- C:\ProgramData\Funny Bear Studio

2013-08-15 20:00:40 7C6258397861C4AB19E65F2E406CBD95 1625600 ----a-w- C:\Users\Kim\World Riddles 3 _Secrets of the Ages\world-3.exe

2013-08-15 20:00:39 9241E5966D57683B1AA97F0E5EA323AD 522752 ----a-w- C:\Users\Kim\World Riddles 3 _Secrets of the Ages\GDF.dll

2013-08-15 20:00:38 0BE4A226874ECCB9F8BFE3D8DCED0C09 92728 ----a-w- C:\Users\Kim\World Riddles 3 _Secrets of the Ages\bass.dll

2013-08-15 20:00:38 -------- d-----w- C:\Users\Kim\World Riddles 3 _Secrets of the Ages

2013-08-15 12:30:56 D494267BC169604FAC5E3679B9A97FED 444952 ----a-w- C:\Users\Kim\Gourma.._3_NL\wrap_oal.dll

2013-08-15 12:30:56 235355A8DD26903E75D5E812ECF50E53 109080 ----a-w- C:\Users\Kim\Gourma.._3_NL\OpenAL32.dll

2013-08-15 12:30:56 01456B909081A70DFA799A00424F7814 551936 ----a-w- C:\Users\Kim\Gourma.._3_NL\magic.dll

2013-08-15 12:30:55 E801D9316D258838AE1E11EDFA99C033 18317312 ----a-w- C:\Users\Kim\Gourma.._3_NL\gourmania3.exe

2013-08-15 12:30:53 -------- d-----w- C:\Users\Kim\Gourma.._3_NL

2013-08-10 09:25:01 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Little Shop of Treasures Deluxe

2013-08-06 07:25:27 A7B377B8C0162FB49EDC8AA50C170E14 3690 ----a-w- C:\Users\Kim\Happy Chef 2\d3dx9.dll

2013-08-06 07:25:27 14440987F112E5CEA232A1883A115F23 8930816 ----a-w- C:\Users\Kim\Happy Chef 2\Happy Chef 2.exe

2013-08-06 07:25:27 -------- d-----w- C:\Users\Kim\Happy Chef 2

2013-08-04 20:34:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Buena Vista Games

2013-07-24 13:13:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft

====== C: exe-files ==

2013-08-18 10:05:18 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe

2013-08-18 10:05:18 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe

2013-08-18 10:05:18 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe

2013-08-18 10:05:18 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe

2013-08-18 10:05:18 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe

2013-08-15 20:00:40 7C6258397861C4AB19E65F2E406CBD95 1625600 ----a-w- C:\Users\Kim\World Riddles 3 _Secrets of the Ages\world-3.exe

2013-08-15 19:51:16 1F4DAC4B0214DF1989E7202867949AF3 320656 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CXAXKU4H\World_Riddles_3__Secrets_of_the_Ages.rar[1].exe

2013-08-15 12:30:55 E801D9316D258838AE1E11EDFA99C033 18317312 ----a-w- C:\Users\Kim\Gourma.._3_NL\gourmania3.exe

2013-08-15 12:03:39 38EE543BC7D47A94D4AA5E0C1479D5AC 320528 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AOJGNNS7\Gourma.._3_NL.rar[1].exe

2013-08-15 11:33:51 2977FEAB6216956A68667A3C60383297 320536 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GO7MWOO6\Gourma.._3_NL.rar[1].exe

2013-08-15 06:41:41 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

2013-08-15 06:41:39 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

2013-08-15 06:41:38 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-08-15 06:41:34 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

2013-08-15 06:41:33 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

2013-08-15 06:41:33 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

=== C: other files ==

2013-08-18 21:26:17 03D4BD054544195638AF8701AA8A48E9 24981201 ----a-w- C:\Users\Public\Desktop\sample_18-08-2013_2326.zip

2013-08-17 21:26:52 95125CDB81059005550903555D37CFE6 79979 ----a-w- C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UO3DTHW4\nos[1].zip

2013-08-15 06:41:32 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys

2013-08-15 06:41:31 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-1635193343-2580408697-3417977720-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020"

"Spotify Web Helper"="C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

"Spotify"="C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

"NBKeyScan"="C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui"

"HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe"

"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020"

"Spotify Web Helper"="C:\Users\Kim\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

"Spotify"="C:\Users\Kim\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart"

==== Startup Folders ======================

2012-11-14 20:24:51 2111 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-06-2013 10:35]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default

- sAvenshare - %ProfilePath%\extensions\ppc.bv1awgq@b-ayavcc.edu

- leethax.net extension - %ProfilePath%\extensions\leethax@leethax.net.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Kim\AppData\Roaming\Mozilla\Firefox\Profiles\o3rq6e92.default

D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17

3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash

15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

kiplfnciaokpcennlkldkdaeaaomamof - C:\Users\Kim\AppData\Local\Torch\Plugins\TorchPlugin.crx[09-04-2013 18:30]

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting CLSID Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F55A9352-6C81-1A82-F024-7CBF7C0919D2} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{F55A9352-6C81-1A82-F024-7CBF7C0919D2} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F55A9352-6C81-1A82-F024-7CBF7C0919D2} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\10O75MAP will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93TZTI4O will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RXQH5MXY will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UTXRQEG8 will be deleted at reboot

C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\users\Kim\AppData\Local\Mozilla\Firefox\Profiles\o3rq6e92.default\Cache will be emptied at reboot

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\Kim\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\10O75MAP" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93TZTI4O" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RXQH5MXY" not found

"C:\Users\Kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UTXRQEG8" not found

==== EOF on zo 18-08-2013 at 23:36:54,50 ======================

Link naar reactie
Delen op andere sites


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.