Fix resultaat van Farbar Recovery Scan Tool (x64) Versie:07-06-2016 Gestart door Patrick (2016-06-07 19:44:55) Run:1 Gestart vanaf C:\Users\Patrick\Desktop Geladen Profielen: Patrick (Beschikbare Profielen: Patrick) Boot Modus: Normal ============================================== fixlist inhoud: ***************** start CreateRestorePoint: CloseProcesses: Task: {0D8A891D-890C-4808-84D8-2F436AB14653} - \Microsoft\Windows\Application Experience\AitAgent -> Geen bestand <==== AANDACHT Task: {1274336E-AB06-46B6-A48C-0671C5557CC6} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> Geen bestand <==== AANDACHT Task: {1687544D-7247-4F5A-965A-A6E920E55278} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> Geen bestand <==== AANDACHT Task: {6F02587F-8A2B-4552-97F6-DEEF229E335B} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> Geen bestand <==== AANDACHT Task: {A51A8121-082E-4396-83DA-2B3854B70007} - \CreateChoiceProcessTask -> Geen bestand <==== AANDACHT Task: {B7992938-01F1-4F40-A0EC-0D23D2F0F152} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> Geen bestand <==== AANDACHT Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - \Microsoft\Windows\SettingSync\BackupTask -> Geen bestand <==== AANDACHT AlternateDataStreams: C:\Windows:nlsPreferences [386] AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [125] IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0411dd.com -> 0411dd.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0511zfhl.com -> 0511zfhl.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0632qyw.com -> 0632qyw.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\...\1001movie.com -> 1001movie.com FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => niet gevonden FF HKLM-x32\...\Firefox\Extensions: [belgiumeid@eid.belgium.be] - C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be => niet gevonden FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => niet gevonden S3 AndnetBus; \SystemRoot\System32\drivers\lgandnetbus64.sys [X] S3 AndNetDiag; \SystemRoot\system32\DRIVERS\lgandnetdiag64.sys [X] S3 ANDNetModem; \SystemRoot\system32\DRIVERS\lgandnetmodem64.sys [X] S2 Par1284; \??\C:\Program Files (x86)\FlexiSIGN-PRO 7.6v2\Program\Par1284.sys [X] Hosts: EmptyTemp: end ***************** Herstelpunt is succesfol gemaakt. Proces succesvol afgesloten. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0D8A891D-890C-4808-84D8-2F436AB14653}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D8A891D-890C-4808-84D8-2F436AB14653}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1274336E-AB06-46B6-A48C-0671C5557CC6}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1274336E-AB06-46B6-A48C-0671C5557CC6}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Maintenance Configurator" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1687544D-7247-4F5A-965A-A6E920E55278}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1687544D-7247-4F5A-965A-A6E920E55278}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Manual Maintenance" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F02587F-8A2B-4552-97F6-DEEF229E335B}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F02587F-8A2B-4552-97F6-DEEF229E335B}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Idle Maintenance" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A51A8121-082E-4396-83DA-2B3854B70007}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A51A8121-082E-4396-83DA-2B3854B70007}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateChoiceProcessTask" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7992938-01F1-4F40-A0EC-0D23D2F0F152}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7992938-01F1-4F40-A0EC-0D23D2F0F152}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TaskScheduler\Regular Maintenance" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFD7C21A-808B-487B-A6EC-8A10E44E8360}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFD7C21A-808B-487B-A6EC-8A10E44E8360}" => sleutel is succesvol verwijderd. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SettingSync\BackupTask" => sleutel is succesvol verwijderd. C:\Windows => ":nlsPreferences" ADS is succesvol verwijderd.. C:\ProgramData\Temp => ":5C321E34" ADS is succesvol verwijderd.. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0411dd.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0511zfhl.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0632qyw.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com" => sleutel is succesvol verwijderd. "HKU\S-1-5-21-2096965510-2667581601-1132752284-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001movie.com" => sleutel is succesvol verwijderd. HKLM\Software\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => waarde is succesvol verwijderd. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\belgiumeid@eid.belgium.be => waarde is succesvol verwijderd. HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => waarde is succesvol verwijderd. AndnetBus => dienst is succesvol verwijderd. AndNetDiag => dienst is succesvol verwijderd. ANDNetModem => dienst is succesvol verwijderd. Par1284 => dienst is succesvol verwijderd. C:\Windows\System32\Drivers\etc\hosts => is succesvol verplaatst. Hosts met succes hersteld. EmptyTemp: => 793.9 MB tijdelijke gegevens verwijderd. Het systeem moest herstart worden. ==== Eind van Fixlog 19:48:26 ====