Ga naar inhoud

Pc vernieuwen


bernard

Aanbevolen berichten

Ik begrijp uit verschillende schermpjes , dat windows geen ondersteuning meer bied aan XP.

Dat klopt, maar dat wil niet zeggen dat je Windows XP niet meer zou kunnen gebruiken.

Je zal bijvoorbeeld geen Updates meer ontvangen en wat veiligheid betreft ga je er dus op achteruit.

Als Antivirusprogramma zou je Avast nog kunnen gebruiken.

Office 2003 kan je probleemloos op een XP installeren, maar hier ook is de ondersteuning sinds kort beëindigd.

Maar ik dacht dat je de pc enkel wat ging gebruiken om de kleinkinderen wat computerervaring zouden opdoen?

Je zal de computer kunnen gebruiken zoals voorheen hoor.

Een andere mogelijkheid is dat je laat controleren op eventuele aanwezige malware en wat opruiming doet waardoor de PC misschien ook weer wat sneller wordt.

De keuze is aan jouw.

Link naar reactie
Delen op andere sites

  • Reacties 85
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Ok , maar ik loop al tegen het probleem aan dat mijn schijf productherstel niet doet wat we verwacht hadden .

Ik had eerst met het afsluiten dat er updates waren , en dat duurde en duurde , maaruiteoidelijk was het zo dat ik met het schijfje er in kon afsluiten zonder aangekondigde updates .

Maar bij het opstarten komt niet het bericht , waarna ik F12 moet in drukken .

Ik heb een paar keer geprobeerd , maar het lukt niet .

Verder had ik bij de beveiliging naar geschiedenis gekeken , enjawel , een heel rijtje troyaanse virussen .Ik heb ze laten verwijderen , maar misschien had ik ze voor je moeten laten staan ?

Dus alles bij elkaar ben ik maar heel weinig verder gekomen .

Link naar reactie
Delen op andere sites

Download 51a5f5d096dae-icon_RSIT.pngRSIT van de onderstaande locaties en sla deze op het bureaublad op.

Hoe je controleert of je met een 32- of 64-bitversie van Windows werkt kan je hier bekijken.

Dubbelklik op RSIT.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Vervolgens wordt de "Disclaimer of warranty" getoond, klik vervolgens op "Continue"
  • Wanneer de tool gereed is worden er twee kladblok bestanden geopend genaamd "Log.txt" en "Info.txt" .

RSIT Logbestanden plaatsen

  • Voeg het logbestand met de naam "Log.txt" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden in de map ""C:\\rsit")
  • Het logbestand met de naam "Info.txt" wat geminimaliseerd is hoeft u niet te plaatsen. (Dit logbestand wordt enkel de eerst keer bij het uitvoeren aangemaakt).
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

De handleiding voor het gebruik van RSIT kan je HIER bekijken en we hebben ook nog een instructievideo.

Link naar reactie
Delen op andere sites

Logfile of random's system information tool 1.10 (written by random/random)

Run by Gerda at 2014-08-07 14:53:24

Microsoft Windows XP Home Edition Service Pack 3

System drive C: has 134 GB (88%) free of 153 GB

Total RAM: 510 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:53:54, on 7-8-2014

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

c:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ACS.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe

C:\Program Files\TOSHIBA\TouchPad\TPTray.exe

C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe

C:\WINDOWS\system32\ZoomingHook.exe

C:\WINDOWS\system32\TCtrlIOHook.exe

C:\WINDOWS\system32\TPSMain.exe

C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe

C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe

C:\Program Files\TOSHIBA\Tvs\TvsTray.exe

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\WINDOWS\system32\rundll32.exe

C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbrmon.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\TPSBattM.exe

C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Documents and Settings\Gerda\Application Data\VOPackage\VOsrv.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Zebar\updateZebar.exe

C:\Program Files\Zebar\updater.exe

C:\Program Files\Zebar\bin\utilZebar.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Java\Java Update\jucheck.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\1R8EON0Q\RSIT[1].exe

C:\Program Files\trend micro\Gerda.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Startpagina.nl | Jouw startpagina voor weer, verkeer en meer

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbar.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: cosstminn - {6236E2B5-1BC1-2CD3-76D9-631EAFABC24D} - C:\Program Files\cosstminn\cz7ynHGCR.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll

O2 - BHO: Zebar - {cf8c409e-f507-4f95-b6dd-bf1eecf85c9d} - C:\Program Files\Zebar\Zebarbho.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe

O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe

O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe

O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP

O4 - HKLM\..\Run: [sVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL

O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe

O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe

O4 - HKLM\..\Run: [TPSMain] TPSMain.exe

O4 - HKLM\..\Run: [smoothView] C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe

O4 - HKLM\..\Run: [TFncKy] TFncKy.exe

O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h

O4 - HKLM\..\Run: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbrmon.exe

O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Search - http://tbedits.videodownloadconverter.com/one-toolbaredits/menusearch.jhtml?s=205320000&p2=^HJ^xdm069^YY^nl&si=pconverter&a=E2693A0F-6DE3-4CD5-929D-B4A2AE06A7D7&n=2013021607&cv=2

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1296993521765

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: VO Service component (servervo) - Unknown owner - C:\Documents and Settings\Gerda\Application Data\VOPackage\VOsrv.exe

O23 - Service: Update Zebar - Unknown owner - C:\Program Files\Zebar\updateZebar.exe

O23 - Service: UpdaterSvcZebar - Unknown owner - C:\Program Files\Zebar\updater.exe

O23 - Service: Util Zebar - Unknown owner - C:\Program Files\Zebar\bin\utilZebar.exe

O23 - Service: VideoDownloadConverterService (VideoDownloadConverter_4zService) - COMPANYVERS_NAME - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbarsvc.exe

--

End of file - 9229 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

C:\WINDOWS\tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c

C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges

C:\WINDOWS\tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job - C:\WINDOWS\system32\xp_eos.exe -c

C:\WINDOWS\tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job - C:\WINDOWS\system32\xp_eos.exe

C:\WINDOWS\tasks\MpIdleTask.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe -IdleTask -TaskName MpIdleTask

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]

Toolbar BHO - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbar.dll [2013-02-16 707728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]

DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2005-01-14 118842]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6236E2B5-1BC1-2CD3-76D9-631EAFABC24D}]

cosstminn - C:\Program Files\cosstminn\cz7ynHGCR.dll [2014-08-04 452096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-08-28 329712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]

Search Assistant BHO - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll [2013-02-16 62864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf8c409e-f507-4f95-b6dd-bf1eecf85c9d}]

Zebar - C:\Program Files\Zebar\Zebarbho.dll [2014-08-04 249624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-08-28 59376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-08-28 79856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{48586425-6bb7-4f51-8dc6-38c88e3ebb58} - VideoDownloadConverter - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll [2013-02-16 707728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2003-10-30 192512]

"PadTouch"=C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe [2004-12-01 1077327]

"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2004-10-28 88363]

"CeEKEY"=C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe [2005-01-21 675840]

"TPNF"=C:\Program Files\TOSHIBA\TouchPad\TPTray.exe [2004-11-29 53248]

"TOSHIBA Accessibility"=C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe [2004-12-07 24576]

"HWSetup"=C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe [2004-12-23 28672]

"SVPWUTIL"=C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe [2005-02-25 65536]

"Zooming"=C:\WINDOWS\system32\ZoomingHook.exe [2004-07-14 24576]

"TCtryIOHook"=C:\WINDOWS\system32\TCtrlIOHook.exe [2005-02-16 28672]

"TPSMain"=C:\WINDOWS\system32\TPSMain.exe [2005-01-21 266240]

"SmoothView"=C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe [2004-11-15 118784]

"TFncKy"=TFncKy.exe []

"Tvs"=C:\Program Files\TOSHIBA\Tvs\TvsTray.exe [2004-11-12 73728]

"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2005-01-14 122939]

"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-02-22 339968]

"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]

"VideoDownloadConverter Search Scope Monitor"=C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe [2013-02-16 42536]

"VideoDownloadConverter_4z Browser Plugin Loader"=C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbrmon.exe [2013-02-16 30096]

"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 951576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

"TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe [2005-03-02 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

C:\WINDOWS\system32\Ati2evxx.dll [2005-02-22 61440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"HonorAutoRunSetting"=1

"NoDriveAutoRun"=67108863

"NoDriveTypeAutoRun"=323

"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe"="C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe:*:Enabled:Java Platform SE binary"

"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java Platform SE binary"

"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"midimapper"=midimap.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msadpcm"=msadp32.acm

"msacm.msg711"=msg711.acm

"msacm.msgsm610"=msgsm32.acm

"msacm.trspch"=tssoft32.acm

"vidc.cvid"=iccvid.dll

"vidc.I420"=msh263.drv

"vidc.iv31"=ir32_32.dll

"vidc.iv32"=ir32_32.dll

"vidc.iv41"=ir41_32.ax

"vidc.iyuv"=iyuv_32.dll

"vidc.mrle"=msrle32.dll

"vidc.msvc"=msvidc32.dll

"vidc.uyvy"=msyuv.dll

"vidc.yuy2"=msyuv.dll

"vidc.yvu9"=tsbyuv.dll

"vidc.yvyu"=msyuv.dll

"wavemapper"=msacm32.drv

"msacm.msg723"=msg723.acm

"vidc.M263"=msh263.drv

"vidc.M261"=msh261.drv

"msacm.msaudio1"=msaud32.acm

"msacm.sl_anet"=sl_anet.acm

"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax

"vidc.iv50"=ir50_32.dll

"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

======List of files/folders created in the last 1 month======

2014-08-07 14:53:24 ----D---- C:\rsit

2014-08-06 19:56:52 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$

2014-08-06 19:20:56 ----D---- C:\WINDOWS\system32\XPSViewer

2014-08-06 19:20:09 ----D---- C:\Program Files\Reference Assemblies

2014-08-06 19:18:28 ----N---- C:\WINDOWS\system32\prntvpt.dll

2014-08-06 19:18:27 ----N---- C:\WINDOWS\system32\xpssvcs.dll

2014-08-06 19:18:27 ----N---- C:\WINDOWS\system32\xpsshhdr.dll

2014-08-06 19:18:25 ----D---- C:\dec4a3b3339f90200e6f2657a9e372

2014-08-04 22:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$

2014-08-04 22:52:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$

2014-08-04 22:51:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$

2014-08-04 22:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$

2014-08-04 22:50:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$

2014-08-04 22:47:47 ----D---- C:\Program Files\Common Files\DESIGNER

2014-08-04 22:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$

2014-08-04 22:05:53 ----A---- C:\WINDOWS\imsins.BAK

2014-08-04 22:04:23 ----A---- C:\WINDOWS\system32\drivers\{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt.sys

2014-08-04 21:38:26 ----D---- C:\Program Files\CCleaner

2014-08-04 21:03:34 ----D---- C:\Documents and Settings\All Users\Application Data\Systweak

2014-08-04 20:58:36 ----D---- C:\4eabd783f092732bc14cafd83d34b4

2014-08-04 20:57:41 ----D---- C:\Documents and Settings\Gerda\Application Data\VOPackage

2014-08-04 20:57:12 ----D---- C:\Documents and Settings\Gerda\Application Data\Systweak

2014-08-04 20:56:41 ----D---- C:\Program Files\Zebar

2014-08-04 20:56:27 ----D---- C:\Program Files\Supporter

2014-08-04 20:56:17 ----A---- C:\WINDOWS\system32\roboot.exe

2014-08-04 20:55:17 ----D---- C:\Documents and Settings\All Users\Application Data\c328a512a6b40fee

2014-08-04 20:55:14 ----D---- C:\Documents and Settings\All Users\Application Data\cosstminn

2014-08-04 20:54:36 ----D---- C:\Program Files\cosstminn

2014-08-04 20:53:42 ----D---- C:\Program Files\FLVM Player

2014-08-04 19:43:00 ----N---- C:\WINDOWS\system32\xp_eos.exe

2014-08-03 15:16:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$

======List of files/folders modified in the last 1 month======

2014-08-07 14:53:53 ----D---- C:\Program Files\Trend Micro

2014-08-07 14:49:05 ----RD---- C:\Program Files

2014-08-07 14:27:19 ----SD---- C:\WINDOWS\Tasks

2014-08-07 14:25:51 ----A---- C:\WINDOWS\win.ini

2014-08-07 14:19:53 ----D---- C:\WINDOWS\Temp

2014-08-07 14:17:56 ----D---- C:\WINDOWS\system32\CatRoot2

2014-08-06 21:17:51 ----A---- C:\WINDOWS\SchedLgU.Txt

2014-08-06 21:04:31 ----RSD---- C:\WINDOWS\assembly

2014-08-06 21:03:05 ----D---- C:\WINDOWS\Microsoft.NET

2014-08-06 20:01:41 ----D---- C:\WINDOWS

2014-08-06 19:57:26 ----D---- C:\WINDOWS\inf

2014-08-06 19:57:14 ----D---- C:\WINDOWS\system32\CatRoot

2014-08-06 19:57:01 ----RSHDC---- C:\WINDOWS\system32\dllcache

2014-08-06 19:54:38 ----SHD---- C:\WINDOWS\Installer

2014-08-06 19:54:38 ----D---- C:\Config.Msi

2014-08-06 19:31:06 ----D---- C:\WINDOWS\system32

2014-08-06 19:31:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

2014-08-06 19:30:35 ----D---- C:\WINDOWS\WinSxS

2014-08-06 19:20:40 ----D---- C:\Program Files\MSBuild

2014-08-06 19:20:29 ----RSD---- C:\WINDOWS\Fonts

2014-08-06 19:19:08 ----D---- C:\WINDOWS\system32\spool

2014-08-05 19:04:40 ----D---- C:\Program Files\Microsoft Silverlight

2014-08-04 22:57:25 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help

2014-08-04 22:52:51 ----D---- C:\WINDOWS\ie8updates

2014-08-04 22:47:47 ----D---- C:\Program Files\Common Files

2014-08-04 22:26:13 ----D---- C:\WINDOWS\system32\drivers

2014-08-04 22:26:12 ----D---- C:\Program Files\Microsoft Security Client

2014-08-04 22:13:17 ----D---- C:\WINDOWS\Debug

2014-08-04 22:05:45 ----D---- C:\Program Files\Internet Explorer

2014-08-04 21:21:35 ----D---- C:\Program Files\Google

2014-08-04 21:13:00 ----D---- C:\Documents and Settings\All Users\Application Data\Google

2014-08-04 19:32:06 ----SHD---- C:\RECYCLER

2014-08-04 19:32:06 ----D---- C:\Documents and Settings

2014-08-03 15:20:51 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 drvmcdb;drvmcdb; C:\WINDOWS\system32\drivers\drvmcdb.sys [2004-08-17 87168]

R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2014-01-25 231960]

R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-02-23 43872]

R1 {9f93bd66-d3d2-427d-b37f-743603e2388d}Gt;{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt; C:\WINDOWS\system32\drivers\{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt.sys [2014-07-25 55224]

R1 intelppm;Intel GV3-processorstuurprogramma; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]

R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr; C:\WINDOWS\system32\drivers\EPIOMngr.sys [2004-07-30 6400]

R1 SrvcEKIOMngr;SrvcEKIOMngr; C:\WINDOWS\System32\Drivers\EKIoMngr.sys [2004-07-29 6400]

R1 SrvcSSIOMngr;SrvcSSIOMngr; C:\WINDOWS\System32\Drivers\SSIoMngr.sys [2004-07-29 6400]

R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-12-02 5627]

R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-12-02 23545]

R1 TPwSav;Common Driver; C:\WINDOWS\System32\Drivers\TPwSav.sys [2005-02-25 8704]

R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-12-23 40544]

R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]

R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.10; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2011-02-06 15890]

R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2005-01-14 25883]

R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2005-01-14 34843]

R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2005-01-14 4123]

R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2005-01-14 2271]

R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2005-01-14 87706]

R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2005-01-14 15227]

R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2005-01-14 6363]

R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2005-01-14 99098]

R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2005-01-14 100603]

R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-10-28 1270572]

R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-10-27 2284864]

R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2004-05-08 101833]

R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-12-22 393600]

R3 Arp1394;1394 ARP-clientprotocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]

R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-02-22 986624]

R3 HidUsb;Microsoft HID Class-stuurprogramma; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]

R3 mouhid;Stuurprogramma voor muis-HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-06 12288]

R3 NIC1394;1394-stuurprogramma; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]

R3 Rasirda;WAN-minipoort (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]

R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-06-28 69760]

R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]

R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-02-11 157056]

R3 Tvs;Toshiba Virtual Sound with SRS technologies; C:\WINDOWS\system32\DRIVERS\Tvs.sys [2005-01-08 29184]

R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]

S1 StickyMesger;StickyMesger; \??\C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys []

S3 catchme;catchme; \??\C:\DOCUME~1\BERNAR~1\LOCALS~1\Temp\catchme.sys []

S3 rtl8139;NT-stuurprogramma voor Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]

S3 sffdisk;SFF Storage Class-stuurprogramma; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-13 11904]

S3 sffp_sd;Stuurprogramma volgens SFF-opslagprotocol voor SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-13 11008]

S3 SMCIRDA;SMSC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2004-06-16 46080]

S3 usbccgp;Microsoft generiek hoofd-USB-stuurprogramma; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]

S3 usbscan;Stuurprogramma voor USB-scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]

S3 USBSTOR;Stuurprogramma voor USB-massaopslag; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-10 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 40030ae4;Supporter; c:\progra~1\suppor~1\SupporterSvc.dll [2014-08-04 174416]

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\ACS.exe [2004-07-07 36864]

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-02-22 352256]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 Irmon;Infraroodmonitor; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-08-28 153584]

R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]

R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 22216]

R2 servervo;VO Service component; C:\Documents and Settings\Gerda\Application Data\VOPackage\VOsrv.exe [2014-08-04 73728]

R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]

R2 Update Zebar;Update Zebar; C:\Program Files\Zebar\updateZebar.exe [2014-08-06 323352]

R2 UpdaterSvcZebar;UpdaterSvcZebar; C:\Program Files\Zebar\updater.exe [2014-08-04 135960]

R2 Util Zebar;Util Zebar; C:\Program Files\Zebar\bin\utilZebar.exe [2014-08-06 323352]

S2 gupdate;Google Updateservice (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-29 135664]

S2 VideoDownloadConverter_4zService;VideoDownloadConverterService; C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbarsvc.exe [2013-02-16 42504]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-03 262320]

S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]

S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]

S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-29 135664]

S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]

S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites

Je Java software is verouderd.

Oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem.

Ga naar Java en download daar de correcte Java versie.

  • Klik op "Gratis Java-download".
  • Ga akkoord met de licentiebepalingen en klik op de button voor de gratis download.
  • Het bestand JavaSetup wordt aangeboden - kies hier voor "bestand opslaan".
  • Sluit alle programma's die eventueel open zijn - zeker je web browser!
  • Ga dan naar Start > Configuratiescherm > Software en verwijder alle oudere versies van Java uit de Softwarelijst.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE of JAVA) in de naam.
  • Klik dan op Verwijderen of op de Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart je pc.
  • Klik vervolgens op JavaSetup om de nieuwste versie van Java te installeren.
  • Vink de installatie van de Ask toolbar uit en ga dan verder met de installatie.

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  {93a3111f-4f74-4ed8-895e-d9708497629e};c
 C:\Program Files\VideoDownloadConverter_4z;fs
 {312f84fb-8970-4fd3-bddb-7012eac4afc9};c
 {6236E2B5-1BC1-2CD3-76D9-631EAFABC24D};c
 C:\Program Files\cosstminn;fs
 {c547c6c2-561b-4169-a2a5-20ba771ca93b};c
 {cf8c409e-f507-4f95-b6dd-bf1eecf85c9d};c
 C:\Program Files\Zebar;fs
 {E7E6F031-17CE-4C07-BC86-EABFE594F69C};c
 {48586425-6bb7-4f51-8dc6-38c88e3ebb58};c
 VideoDownloadConverter Search Scope Monitor;s
 VideoDownloadConverter_4z Browser Plugin Loader;s
 Update Zebar;s
 UpdaterSvcZebar;s
 Util Zebar;s
 VideoDownloadConverter_4zService;s
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}];r
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6236E2B5-1BC1-2CD3-76D9-631EAFABC24D}];r
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}];r
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf8c409e-f507-4f95-b6dd-bf1eecf85c9d}];r
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}];r
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run];r
 "VideoDownloadConverter Search Scope Monitor"=-,r
"VideoDownloadConverter_4z Browser Plugin Loader"=-;r
 C:\Documents and Settings\All Users\Application Data\Systweak;fs
C:\4eabd783f092732bc14cafd83d34b4;fs
C:\Documents and Settings\Gerda\Application Data\Systweak;fs
C:\Program Files\Supporter;fs
C:\WINDOWS\system32\roboot.exe;f
C:\Documents and Settings\All Users\Application Data\c328a512a6b40fee;fs
C:\Documents and Settings\All Users\Application Data\cosstminn;fs

emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Quick Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Zoek.exe v5.0.0.0 Updated 07-August-2014

Tool run by Gerda on vr 08-08-2014 at 15:31:56,71.

Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86

Running in: Normal Mode Internet Access Detected

Launched: C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\0JRBYD4P\zoek[2].exe [scan all users] [script inserted]

==== System Restore Info ======================

8-8-2014 15:41:08 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\Program Files\focusbase deleted successfully

C:\Documents and Settings\Default User\Application Data\AdobeUM deleted successfully

C:\Documents and Settings\Default User\Application Data\Symantec deleted successfully

C:\Documents and Settings\Gerda\Application Data\AdobeUM deleted successfully

C:\Documents and Settings\Gerda\Application Data\BabylonToolbar deleted successfully

C:\Documents and Settings\Gerda\Application Data\Symantec deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1705022645-2691431146-1015858574-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} deleted successfully

HKEY_USERS\S-1-5-21-1705022645-2691431146-1015858574-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1705022645-2691431146-1015858574-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Update Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UpdaterSvcZebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UpdaterSvcZebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util Zebar deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VideoDownloadConverter_4zService deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VideoDownloadConverter_4zService deleted successfully

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6236E2B5-1BC1-2CD3-76D9-631EAFABC24D}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf8c409e-f507-4f95-b6dd-bf1eecf85c9d}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"VideoDownloadConverter_4z Browser Plugin Loader"=-

==== Deleting Files \ Folders ======================

C:\Documents and Settings\All Users\Application Data\Systweak deleted

C:\4eabd783f092732bc14cafd83d34b4 deleted

C:\Documents and Settings\Gerda\Application Data\Systweak deleted

C:\Program Files\Supporter deleted

C:\Documents and Settings\All Users\Application Data\c328a512a6b40fee deleted

C:\Documents and Settings\All Users\Application Data\cosstminn deleted

"C:\WINDOWS\system32\roboot.exe" deleted

==== Files Recently Created / Modified ======================

====== C:\WINDOWS ====

2014-08-04 20:05:53 6F78A5B98BCA1C83D9E44E3065BA54C4 1355 ----a-w- C:\WINDOWS\imsins.BAK

====== C:\DOCUME~1\Gerda\LOCALS~1\Temp ====

2014-08-07 15:03:01 5689D43C3B201DD3810FA3BBA4A6476A 4216840 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\vcredist_x86.exe

2014-08-07 15:02:48 23128747B91B2F635A46B252F84C2EE1 5553368 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\BackupSetup.exe

2014-08-07 15:01:54 5CC99B42315686C0046EA44A69862C55 10200072 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\91407423675\1_Offer_15.exe

2014-08-07 15:01:14 B950B7D00028A589F3A6B9889DE51782 809856 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\rdms.exe

2014-08-07 09:33:06 386C66D3274A86E54D8463744BF25ED8 172179 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\1954544_stp\Generic_vo.exe

2014-08-04 18:55:06 AB29E25D21305D5BC1E7D23DC0E57000 5693496 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\optprosetup.exe

2014-08-04 18:53:59 60C86C38C11E191AAB741213232929CF 5870656 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\OptimizerPro.exe

2014-08-04 18:53:51 15515D70A1DCCEDE65C3242A3CD96B1B 290705 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\VOPackage.exe

2014-08-04 18:53:42 62BAFE9A908B1717484D32DE5A54244B 4380069 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\RegClean_0307-7366cb4a.exe

2014-08-04 18:53:31 BA0FAAEDEDAB6E6365A92143B558BD8C 4242370 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\systemsspeedup_0307-cd6becd7.exe

2014-08-04 18:53:21 0D0485EE935ACE396096EAB7FDE9A8BF 473688 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\Zebar_0104-57366623.exe

2014-08-04 18:53:17 8E21CF282EDB9C01A422690769EAB7DA 413184 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\CostMinInstaller.exe

2014-08-04 18:53:15 2701B76FD4D3163E20B75A613198AC84 5077425 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\FLVMPlayerSetup-c45490cb.exe

2014-08-04 18:53:06 2A29384AFF2E8D557DCEAD05CADFED5D 216648 ----atw- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\s2059.exe

2014-08-04 18:51:50 2701B76FD4D3163E20B75A613198AC84 5077425 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n1765\FLVMPlayerSetup-c45490cb.exe

2014-08-04 18:51:36 2A29384AFF2E8D557DCEAD05CADFED5D 216648 ----atw- C:\Documents and Settings\Gerda\Local Settings\temp\n1765\s1765.exe

2014-08-04 16:39:04 AA923F5D569DF958FC443E428F78F4BE 172020 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\7271119_stp\Generic_vo.exe

2014-08-04 16:39:04 AA923F5D569DF958FC443E428F78F4BE 172020 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\275509_stp\Generic_vo.exe

2014-08-03 13:21:00 !HASH: COULD NOT OPEN FILE !!!!! 231584 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\temp\9401e5f9e96928afc6b6106573\MPSigStub.exe

2014-08-03 13:06:45 26932B588F2502854D808D80CFB5633D 100976376 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\temp\mpam-bd0594e4.exe

====== Java Cache =====

2014-08-08 13:28:27 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-409432aa

====== C:\WINDOWS\system32 =====

2014-08-08 13:18:46 6818CC5AEB477497480269CE627DDF17 145408 ----a-w- C:\WINDOWS\System32\javacpl.cpl

2014-08-08 13:18:46 07EF2978A5BC36720378F95566697FD8 272808 ----a-w- C:\WINDOWS\System32\javaws.exe

2014-08-08 13:18:34 49E203776C2ACB289385168A9058EE9E 96680 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge.dll

2014-08-08 13:18:34 3BDEB17FE6390BFF1BF3A2D964DE8E48 175528 ----a-w- C:\WINDOWS\System32\javaw.exe

2014-08-08 13:18:34 11FD45A41DF45298686ED39062AABE2A 175528 ----a-w- C:\WINDOWS\System32\java.exe

2014-08-06 17:18:28 180E1D44727EB72CB11EC5953C5E4C52 117760 ------w- C:\WINDOWS\System32\prntvpt.dll

2014-08-06 17:18:27 89B23B4BE691942072E0E3F7EDEB33B6 1676288 ------w- C:\WINDOWS\System32\xpssvcs.dll

2014-08-06 17:18:27 81C4B0077427391D582FBB1B6B9578CB 575488 ------w- C:\WINDOWS\System32\xpsshhdr.dll

2014-08-04 17:43:00 DDC2FD95F1B3A55CDDD0D91F0D7B3122 13312 ------w- C:\WINDOWS\System32\xp_eos.exe

====== C:\WINDOWS\system32\drivers =====

2014-08-04 20:04:23 708DB5076348BAE2FCA8A773EBEF76A6 55224 ----a-w- C:\WINDOWS\System32\drivers\{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt.sys

====== C:\WINDOWS\Tasks ======

2014-08-07 14:09:43 7EC88B8F8F8CEBF26404E22D2FDD2197 366 ---ha-w- C:\WINDOWS\Tasks\MpIdleTask.job

2014-08-05 17:05:52 80E28ECFE995078453B46DA678C0F9CE 222 ----a-w- C:\WINDOWS\Tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job

2014-08-05 17:05:48 3B7F9D918D68E7933EFD4D5B149575F0 216 ----a-w- C:\WINDOWS\Tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job

2014-08-04 20:38:04 F510302C830B49A6B33AB9E5D1DD7EE1 386 ---ha-w- C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job

====== C:\WINDOWS\Temp ======

======= C:\Program Files =====

2014-08-07 15:03:27 -------- d-----w- C:\Program Files\MyPC Backup

2014-08-06 17:20:09 -------- d-----w- C:\Program Files\Reference Assemblies

2014-08-04 20:47:47 -------- d-----w- C:\Program Files\Common Files\DESIGNER

2014-08-04 18:56:41 -------- d-----w- C:\Program Files\Zebar

2014-08-04 18:54:36 -------- d-----w- C:\Program Files\cosstminn

2014-08-04 18:53:42 -------- d-----w- C:\Program Files\FLVM Player

======= C: =====

====== C:\Documents and Settings\Gerda\Application Data ======

2014-08-08 13:28:14 -------- d-----w- C:\Documents and Settings\Gerda\Local Settings\Application Data\Sun

2014-08-07 17:34:54 5FFBB9F997E5955E76AAF90329C58344 69232 ----a-w- C:\Documents and Settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2014-08-07 15:09:41 -------- d-----w- C:\Documents and Settings\Gerda\Local Settings\Application Data\Local_Weather_LLC

2014-08-07 15:09:04 -------- d-----w- C:\Documents and Settings\Gerda\Menu Start\Programma's\Weather Alerts

2014-08-07 15:07:56 -------- d-----w- C:\Documents and Settings\Gerda\Local Settings\Application Data\WeatherAlerts

2014-08-07 15:06:43 -------- d-----w- C:\Documents and Settings\Gerda\Application Data\webssearches

2014-08-04 18:54:12 -------- d-----w- C:\Documents and Settings\Gerda\Menu Start\Programma's\FLVM Player

====== C:\Documents and Settings\Gerda ======

2014-08-04 19:45:24 -------- d--h--r- C:\Documents and Settings\Gerda\Onlangs geopend

2014-08-04 18:55:03 -------- d-----w- C:\Documents and Settings\Gerda\AppData

====== C: exe-files ==

2014-08-08 13:18:46 07EF2978A5BC36720378F95566697FD8 272808 ----a-w- C:\WINDOWS\system32\javaws.exe

2014-08-08 13:18:34 3BDEB17FE6390BFF1BF3A2D964DE8E48 175528 ----a-w- C:\WINDOWS\system32\javaw.exe

2014-08-08 13:18:34 11FD45A41DF45298686ED39062AABE2A 175528 ----a-w- C:\WINDOWS\system32\java.exe

2014-08-08 13:18:18 CEEFA72555A8FAD52C29BA17AE3E6DEF 16296 ----a-w- C:\Program Files\Java\jre7\bin\servertool.exe

2014-08-08 13:18:18 A6B7A388547C4CDF4D8F2AF55D79AC85 145832 ----a-w- C:\Program Files\Java\jre7\bin\unpack200.exe

2014-08-08 13:18:18 8B986C008892DB58928BC72483ADF7B9 16808 ----a-w- C:\Program Files\Java\jre7\bin\tnameserv.exe

2014-08-08 13:18:18 7BDCC29DDFBB355761A018A74D4A1E8C 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmiregistry.exe

2014-08-08 13:18:18 7A17013ABD895DFBD61A5AF9996D0E5E 50088 ----a-w- C:\Program Files\Java\jre7\bin\ssvagent.exe

2014-08-08 13:18:18 48442596BFEB26E56898A0E4D2596A95 16296 ----a-w- C:\Program Files\Java\jre7\bin\policytool.exe

2014-08-08 13:18:18 34CEC403ED594B55D55DED61A3A53DAF 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmid.exe

2014-08-08 13:18:17 F67D9621616CB31217A497FEDE4913F5 16296 ----a-w- C:\Program Files\Java\jre7\bin\pack200.exe

2014-08-08 13:18:17 EC4C47AADE6606AFCDEAB28E29654ECE 75688 ----a-w- C:\Program Files\Java\jre7\bin\jp2launcher.exe

2014-08-08 13:18:17 C3F55C9B02A22EC0B345E20AE9AE9B71 16296 ----a-w- C:\Program Files\Java\jre7\bin\klist.exe

2014-08-08 13:18:17 BF918C9473D64BBD53C22C47045883F5 182696 ----a-w- C:\Program Files\Java\jre7\bin\jqs.exe

2014-08-08 13:18:17 A788E5ED0454307CBCFB95CC33E5F717 16808 ----a-w- C:\Program Files\Java\jre7\bin\orbd.exe

2014-08-08 13:18:17 7ED5C21F9F29B5278FFF39718C667235 16296 ----a-w- C:\Program Files\Java\jre7\bin\ktab.exe

2014-08-08 13:18:17 7DC9A0127F850997B4CFD9923C680D7D 16296 ----a-w- C:\Program Files\Java\jre7\bin\keytool.exe

2014-08-08 13:18:17 0371CFD6228F89B5B9E20F67807987FE 16296 ----a-w- C:\Program Files\Java\jre7\bin\kinit.exe

2014-08-08 13:18:15 F69D8BDC202973592D710BC913D01919 48040 ----a-w- C:\Program Files\Java\jre7\bin\jabswitch.exe

2014-08-08 13:18:15 C8883F91C31CAC40890AC8B668E05F61 16296 ----a-w- C:\Program Files\Java\jre7\bin\java-rmi.exe

2014-08-08 13:18:15 8B657BA869AE7D3C6A29792C986E0DD5 68008 ----a-w- C:\Program Files\Java\jre7\bin\javacpl.exe

2014-08-08 13:18:15 3BDEB17FE6390BFF1BF3A2D964DE8E48 175528 ----a-w- C:\Program Files\Java\jre7\bin\javaw.exe

2014-08-08 13:18:15 11FD45A41DF45298686ED39062AABE2A 175528 ----a-w- C:\Program Files\Java\jre7\bin\java.exe

2014-08-08 13:18:15 07EF2978A5BC36720378F95566697FD8 272808 ----a-w- C:\Program Files\Java\jre7\bin\javaws.exe

2014-08-08 13:17:46 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\B95FLT1T\JavaSetup7u67[1].exe

2014-08-08 13:17:37 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Documents and Settings\Gerda\Application Data\Sun\Java\jre1.7.0_67\lzma.exe

2014-08-08 13:17:19 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\0JRBYD4P\JavaSetup7u67[2].exe

2014-08-07 19:02:49 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\0JRBYD4P\JavaSetup7u67[1].exe

2014-08-07 15:09:04 3CAB8C3D08FA5967BBC86D7C3334D6DC 52339 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Application Data\WeatherAlerts\uninstall.exe

2014-08-07 15:07:57 252AE4CDABAE46180699207C80147872 146097 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Application Data\WeatherAlerts\DesktopWeatherAlertsuninstall.exe

2014-08-07 15:07:54 7503BB28DCFAEE54DAED5B25C5798558 482152 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\1R8EON0Q\DesktopWeatherAlertsSetup[1].exe

2014-08-07 15:07:01 357A3A310BC75B9B57A7292847896015 528384 ----a-w- C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe

2014-08-07 15:06:43 1608D54DC69EA7E763CDAB78F71CAFD6 1856512 ----a-w- C:\Documents and Settings\Gerda\Application Data\webssearches\UninstallManager.exe

2014-08-07 15:03:01 5689D43C3B201DD3810FA3BBA4A6476A 4216840 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\vcredist_x86.exe

2014-08-07 15:02:48 23128747B91B2F635A46B252F84C2EE1 5553368 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\BackupSetup.exe

2014-08-07 15:01:54 5CC99B42315686C0046EA44A69862C55 10200072 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\91407423675\1_Offer_15.exe

2014-08-07 15:01:50 AAC45B337DAF3F301EAE9BFCC7C3F66E 392973 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\B95FLT1T\VuuPC-Installer[1].exe

2014-08-07 15:01:14 B950B7D00028A589F3A6B9889DE51782 809856 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\rdms.exe

2014-08-07 13:20:48 718476F73BC55A62BCAFDDA22395728A 239384 ----a-w- C:\Program Files\Zebar\bin\Zebar.PurBrowse.exe

2014-08-07 12:53:26 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Gerda.exe

2014-08-07 09:33:06 386C66D3274A86E54D8463744BF25ED8 172179 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\1954544_stp\Generic_vo.exe

2014-08-06 19:12:58 4AF4D1D156DF61FC7364D1193862A068 4862664 ----a-w- C:\RECYCLER\S-1-5-21-1705022645-2691431146-1015858574-1007\Dc6.exe

2014-08-06 17:18:27 9CAC2BEE7724FC829567400EE751856A 597504 -c----w- C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe

2014-08-06 17:18:27 9CAC2BEE7724FC829567400EE751856A 597504 ------w- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2014-08-06 17:17:59 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XDK05EBH\dotnetfx35setup[1].exe

2014-08-04 20:53:08 2BF1A08F7CB7752AF697EE228514497F 234872 -c----w- C:\WINDOWS\ie8updates\KB2964358-IE8\spuninst\spuninst.exe

2014-08-04 20:05:39 2BF1A08F7CB7752AF697EE228514497F 234872 -c----w- C:\WINDOWS\ie8updates\KB2936068-IE8\spuninst\spuninst.exe

2014-08-04 20:05:34 9690B079450A711BC1942D0E1FD7AC37 174592 -c----w- C:\WINDOWS\ie8updates\KB2936068-IE8\ie4uinit.exe

2014-08-04 20:04:23 763960F8A4C8F0F3C9859AF143BA0271 96536 ----a-w- C:\Program Files\Zebar\bin\Zebar.BrowserAdapter.exe

2014-08-04 20:02:23 AA188DF322701F202AF185611DC3BB60 323352 ----a-w- C:\Program Files\Zebar\bin\utilZebar.exe

2014-08-04 18:58:34 269F314B87E6222A20E5F745B6B89783 2869264 ----a-w- C:\Program Files\Zebar\dotNetFx35setup.exe

2014-08-04 18:57:30 D8E577E956B7C248B6A1733169A3D2E5 241151 ----a-w- C:\Program Files\Zebar\ZebarUninstall.exe

2014-08-04 18:57:29 91188398D2511562E4B55319984172CB 1123608 ----a-w- C:\Program Files\Zebar\Zebar.FirstRun.exe

2014-08-04 18:55:06 AB29E25D21305D5BC1E7D23DC0E57000 5693496 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\optprosetup.exe

2014-08-04 18:54:17 AEDF260AD28B751B8B748A2ADBD01300 44253 ----a-w- C:\Program Files\FLVM Player\Uninstaller.exe

2014-08-04 18:53:59 60C86C38C11E191AAB741213232929CF 5870656 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\OptimizerPro.exe

2014-08-04 18:53:51 A61A24E28CE5E961941D61C1D342AC39 4748896 ----a-w- C:\RECYCLER\S-1-5-21-1705022645-2691431146-1015858574-1007\Dc2.exe

2014-08-04 18:53:51 15515D70A1DCCEDE65C3242A3CD96B1B 290705 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\VOPackage.exe

2014-08-04 18:53:42 62BAFE9A908B1717484D32DE5A54244B 4380069 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\RegClean_0307-7366cb4a.exe

2014-08-04 18:53:31 BA0FAAEDEDAB6E6365A92143B558BD8C 4242370 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\systemsspeedup_0307-cd6becd7.exe

2014-08-04 18:53:21 0D0485EE935ACE396096EAB7FDE9A8BF 473688 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\Zebar_0104-57366623.exe

2014-08-04 18:53:17 8E21CF282EDB9C01A422690769EAB7DA 413184 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\CostMinInstaller.exe

2014-08-04 18:53:15 2701B76FD4D3163E20B75A613198AC84 5077425 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\FLVMPlayerSetup-c45490cb.exe

2014-08-04 18:53:06 2A29384AFF2E8D557DCEAD05CADFED5D 216648 ----atw- C:\Documents and Settings\Gerda\Local Settings\temp\n2059\s2059.exe

2014-08-04 18:51:50 2701B76FD4D3163E20B75A613198AC84 5077425 ----a-w- C:\Documents and Settings\Gerda\Local Settings\temp\n1765\FLVMPlayerSetup-c45490cb.exe

2014-08-04 18:51:36 2A29384AFF2E8D557DCEAD05CADFED5D 216648 ----atw- C:\Documents and Settings\Gerda\Local Settings\temp\n1765\s1765.exe

2014-08-04 18:31:30 AA188DF322701F202AF185611DC3BB60 323352 ----a-w- C:\Program Files\Zebar\updateZebar.exe

2014-08-04 18:31:30 734B0546EE0BCDBA1E0BEDCC505386B3 135960 ----a-w- C:\Program Files\Zebar\updater.exe

2014-08-04 17:43:00 DDC2FD95F1B3A55CDDD0D91F0D7B3122 13312 -c----w- C:\WINDOWS\system32\dllcache\xp_eos.exe

2014-08-04 17:43:00 DDC2FD95F1B3A55CDDD0D91F0D7B3122 13312 ------w- C:\WINDOWS\system32\xp_eos.exe

2014-08-04 16:39:04 AA923F5D569DF958FC443E428F78F4BE 172020 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\7271119_stp\Generic_vo.exe

2014-08-04 16:39:04 AA923F5D569DF958FC443E428F78F4BE 172020 ------w- C:\Documents and Settings\Gerda\Local Settings\temp\is45637729\275509_stp\Generic_vo.exe

2014-08-03 13:21:00 !HASH: COULD NOT OPEN FILE !!!!! 231584 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\temp\9401e5f9e96928afc6b6106573\MPSigStub.exe

2014-08-03 13:06:45 26932B588F2502854D808D80CFB5633D 100976376 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\temp\mpam-bd0594e4.exe

=== C: other files ==

2014-08-08 13:19:06 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\B95FLT1T\java[1].com

2014-08-08 13:18:19 F3EABF8A2AF5C0D8BAE022EE6C17FD91 18650 ----a-w- C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip

2014-08-08 13:16:53 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\QZ0KCZ4V\www.java[1].com

2014-08-08 13:05:15 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\QZ0KCZ4V\www.systweak[1].com

2014-08-08 12:47:21 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\0JRBYD4P\www.contenko[2].com

2014-08-08 12:46:45 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\1R8EON0Q\istart.webssearches[1].com

2014-08-08 05:27:00 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\QZ0KCZ4V\www.tuneuppro[1].com

2014-08-07 19:59:22 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\QZ0KCZ4V\w.prize44[1].com

2014-08-07 19:27:46 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\B95FLT1T\www.casino[1].com

2014-08-07 18:47:53 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\1R8EON0Q\www.thatrendsystem[1].com

2014-08-07 17:31:29 7215EE9C7D9DC229D2921A40E899EC5F 1 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\QZ0KCZ4V\powerbundle.systweak[1].com

2014-08-07 14:58:37 ED43F0DF4E0371F51B48AA8B56E874E1 22027 ----a-w- C:\Documents and Settings\Gerda\Local Settings\Temporary Internet Files\Content.IE5\B95FLT1T\www.avg[1].com

2014-08-04 20:04:23 708DB5076348BAE2FCA8A773EBEF76A6 55224 ----a-w- C:\WINDOWS\system32\drivers\{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt.sys

2014-08-04 20:04:20 3B5B087A4BE2B128FFA2014FBF4F9485 372356 ----a-w- C:\Program Files\Zebar\bin\Zebar.PurBrowseG.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t"

[HKEY_USERS\S-1-5-21-1705022645-2691431146-1015858574-1007\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe"

"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Apoint"="C:\Program Files\Apoint2K\Apoint.exe"

"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe"

"AGRSMMSG"="AGRSMMSG.exe"

"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"

"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"

"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe"

"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP"

"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL"

"Zooming"="ZoomingHook.exe"

"TCtryIOHook"="TCtrlIOHook.exe"

"TPSMain"="TPSMain.exe"

"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe"

"TFncKy"="TFncKy.exe"

"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe"

"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe"

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

"APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

"VideoDownloadConverter Search Scope Monitor"="C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe /m=2 /w /h"

"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"

"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe"

"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"

==== Startup Folders ======================

2014-08-07 15:07:59 1181 ----a-w- C:\Documents and Settings\Gerda\Menu Start\Programma's\Opstarten\DesktopWeatherAlerts.lnk

2014-08-07 15:09:10 1149 ----a-w- C:\Documents and Settings\Gerda\Menu Start\Programma's\Opstarten\Weather Alerts.lnk

==== Task Scheduler Jobs ======================

C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [03-08-2014 15:21]

C:\WINDOWS\tasks\AppleSoftwareUpdate.job --a------ C:\Program Files\AppleC:oftware Update\SoftwareUpdate.exe []

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [29-01-2012 11:17]

C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [29-01-2012 11:17]

C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job --ah----- C:\Program Files\Microsoft Security Client\MpCmdRun.exe []

C:\WINDOWS\tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job --a------ C:\WINDOWS\system32\xp_eos.exe [27-02-2014 01:28]

C:\WINDOWS\tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job --a------ C:\WINDOWS\system32\xp_eos.exe [27-02-2014 01:28]

C:\WINDOWS\tasks\MpIdleTask.job --ah----- C:\Program Files\Microsoft Security Client\MpCmdRun.exe []

==== C:\zoek_backup content ======================

C:\zoek_backup (files=143 folders=14 186280429 bytes)

==== EOF on vr 08-08-2014 at 15:48:42,34 ======================

- - - Updated - - -

Ik heb zojuist een logje gestuurd , alleen weet ik niet of dit de goeie is .

Volgens mij had ik te laat : do a quick scan en auto clean aangevinkt .

Kunnen jullie dat zoen ?

Link naar reactie
Delen op andere sites

Dubbelklik op Zoek.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  C:\Program Files\MyPC Backup;fs
 C:\Program Files\Zebar;fs
 C:\Program Files\cosstminn;fs
 C:\Documents and Settings\Gerda\Application Data\webssearches;fs
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
 "VideoDownloadConverter Search Scope Monitor"=-;r

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Quick Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Hoe en waarom weet ik niet , maar ik heb eerder wel een log kunnen verzenden , maar ik weet echt niet meer hoe ik dat voor elkaar heb gekregen .

Ik ga dus naar zoek exe , en dan ga ik de code selecteren , en dan kopieren

Dan ga ik naar word , en doe ctrl = v

Maar hoe verder , en dan gaat hij dus zoeken , en als dat logje klaar is hoe krijg ik deze in het grote scherm?

Link naar reactie
Delen op andere sites

@ Bernard,

Hoe en waarom weet ik niet , maar ik heb eerder wel een log kunnen verzenden , maar ik weet echt niet meer hoe ik dat voor elkaar heb gekregen.

Zie beschrijving in het bericht #18

Zoek.exe logbestand plaatsen

  1. Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\Zoek-results.log.)
  2. Hoe u een bijlage kunt toevoegen aan het bericht leest u hier

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.