Ga naar inhoud

sweetsss

Lid
  • Items

    29
  • Registratiedatum

  • Laatst bezocht

sweetsss's prestaties

  1. Oke. Alleen de internetbrowser is weer ietsjes langzamer, maar dat kan ook komen door de updates die de computer aan het doen is. Ik zal het nu afsluiten. Nogmaals bedankt!
  2. ik heb nog 1 laatste vraag. hij heeft alle programma's verwijderd die we bij dit probleem gebruikt hebben (adwcleaner, rsit, etc). maakt dit iets uit ? Hierna zal ik dit topic sluiten. Dank je wel voor al je hulp en tijd!
  3. heb net even snel gecheckt, maar tot nu toe geen pop-ups. van de games is een deel gedownload en een deel gekocht. bij de eset scan werd er aangegeven of ik de besmette bestanden wou verwijderen. kan ik dat gewoon doen ?
  4. ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ac3855ee5ffc5f4681d42bd395c64a4b # engine=16069 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2013-11-30 05:14:23 # local_time=2013-11-30 06:14:23 (+0100, West-Europa (standaardtijd)) # country="Netherlands" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=5122 16777214 66 93 1775338 135666821 0 0 # compatibility_mode=5892 16776573 100 100 119104 223364391 0 0 # scanned=406746 # found=17 # cleaned=17 # scan_time=32060 sh=2DF4344B63FDDA0F7D40187FB0AB7B4A9EB901B1 ft=0 fh=0000000000000000 vn="JS/Iframe.IX trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content(85).IE5\LUM1MG8S\look[1].htm" sh=1A9805F3DFE7328C4AD41F2BE76064F59B1952D9 ft=0 fh=0000000000000000 vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joyce\AppData\Local\temp(86)\jar_cache2823018898809015237.tmp" sh=3A89DAEE2C931D0AAA7B102D3DA9D2174DC5875E ft=1 fh=d16f3ccb0b0b7a97 vn="a variant of Win32/Bundled.Toolbar.Ask application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joyce\Documents\Downloads\Programma setup en updates\SetupImgBurn_2.5.5.0.exe" sh=419716F712489099B040AB846B565D808119B5E8 ft=1 fh=562d50baf79e8eca vn="a variant of Win32/Toolbar.Conduit.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joyce\Hijackthis\backups\backup-20120530-102631-506.dll" sh=EAC8C7D8D62710544E535010D891998E5CE6D58A ft=1 fh=9ed035c0b66684e8 vn="a variant of Win32/Toolbar.Visicom.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joyce\Hijackthis\backups\backup-20120530-102631-778.dll" sh=18746373BD6597C22122BED78C4C514140150934 ft=0 fh=0000000000000000 vn="a variant of MSIL/Toolbar.Linkury.C application (deleted - quarantined)" ac=C fn="C:\Windows\Installer\31dc23b.msi" sh=6535EF1963B5B6CEE0990224524F94C314EA960A ft=1 fh=c71c00117cfe6f75 vn="Win32/BHO.OEY trojan (cleaned by deleting (after the next restart) - quarantined)" ac=C fn="C:\Windows\System32\d33dx10.dll" sh=6535EF1963B5B6CEE0990224524F94C314EA960A ft=1 fh=c71c00117cfe6f75 vn="Win32/BHO.OEY trojan (cleaned by deleting - quarantined)" ac=C fn="C:\zoek_backup\C_Qoobox\Quarantine\C\Windows\System32\d33Dx10.dll.vir" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Toolbar.Conduit.B application (deleted - quarantined)" ac=C fn="H:\Games\Hidden Object Games\Big Fish Games Pack 2011.iso" sh=6E00A773636DF122D6E65357DB47A7160DE9D61D ft=1 fh=d4f6947a436bd278 vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\A - E\Aladin and the Wonderful Lamp The 1001 Nights_setup.exe" sh=67FD8E17A66785EF7725875D9A5D43D1780966B6 ft=1 fh=9c645f5d977aecbd vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\A - E\Epic Adventures Cursed Onboard.exe" sh=9B602753C187F84BEECF974D74CDA42405BBA18A ft=1 fh=c485c40776eb7798 vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\K - O\Mystery Agency Secrets of the Orient.exe" sh=3D74AC6D9571EF566DCAB50FCF3B548BC6AE450D ft=1 fh=ef89d1af48f58d7f vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\P - S\Pirate Mysteries.exe" sh=D2BAE5E2287910A06C9E7D90D721191CD427E19A ft=1 fh=51da2927f3020882 vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\T - Z\The Curse of the Thirty Denariii.exe" sh=909203426D9170CEE1FC2216EB8B8A835FC85A97 ft=1 fh=e91bc67bcc056370 vn="Win32/TrojanDropper.Small.NMC trojan (cleaned by deleting - quarantined)" ac=C fn="H:\Games\Hidden Object Games\T - Z\The Revenge.exe" sh=0772319B2C11A66C49AC28AB90A7DBCFD89C0E6A ft=0 fh=0000000000000000 vn="multiple threats (deleted - quarantined)" ac=C fn="H:\PC_VAN_JOYCE\Backup Set 2013-05-15 205743\Backup Files 2013-07-20 051031\Backup files 6.zip" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/BHO.OEY trojan (contained infected files)" ac=C fn="${Memory}"
  5. Klopt dat de scan heel lang duurt? hij staat al aan vanaf ongeveer 9.15 en is nu pas bij 28%
  6. Vuze is verwijderd van mijn computer. Ik dacht dat het door de Zoek scan kwam. De pop-ups blijven bij die sites nog steeds komen.
  7. Zoek.exe Version 4.0.0.5 Updated 24-November-2013Tool run by Joyce on wo 27-11-2013 at 15:28:38,97.Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86Running in: Normal Mode Internet Access DetectedLaunched: C:\Users\Joyce\Desktop\zoek\zoek.exe [script inserted] ==== Older Logs ======================C:\zoek-results2013-11-23-132719.log 25815 bytesC:\zoek-results2013-11-23-214420.log 31918 bytesC:\zoek-results2013-11-24-154044.log 5532 bytesC:\zoek-results2013-11-26-170617.log 46591 bytesC:\zoek-results2013-11-27-022040.log 5653 bytes==== Deleting Files \ Folders ======================C:\Program Files\Vuze deleted==== Chrome Look ======================HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensionsfheoggkfdfchfphceeifdbepaooicaho - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx[02-10-2013 13:05]SiteAdvisor - Joyce - Default\Extensions\fheoggkfdfchfphceeifdbepaooicahoStar Gazing - Joyce - Default\Extensions\mblmlcbknbnfebdfjnolmcapmdofhmme==== Chrome Fix ======================C:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfullyC:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Extensions\mblmlcbknbnfebdfjnolmcapmdofhmme deleted successfully==== Deleting Registry Keys ======================HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Fheoggkfdfchfphceeifdbepaooicaho deleted successfully==== After Reboot ========================== Deleting Files / Folders ======================"C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx" not deleted==== EOF on wo 27-11-2013 at 15:48:06,11 ======================
  8. Heb even snel gekeken.. Internetbrowser laad nu sneller. Wel heb ik bij die sites nog steeds last van pop-ups. Het gaat om website met torrents. Ook krijg ik bij de adwarecleaner scan steeds het bestand Vuze te zien.. Kan dit misschien ook problemen geven?
  9. Zoek.exe Version 4.0.0.5 Updated 24-November-2013 Tool run by Joyce on wo 27-11-2013 at 2:14:00,56. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Joyce\Desktop\zoek\zoek.exe [script inserted] ==== Older Logs ====================== C:\zoek-results2013-11-23-132719.log 25815 bytes C:\zoek-results2013-11-23-214420.log 31918 bytes C:\zoek-results2013-11-24-154044.log 5532 bytes C:\zoek-results2013-11-26-170617.log 46591 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ssqqnksys"=- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "ssqqnksys"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mobilegeni daemon"=- [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "crossriderapp498@crossrider.com"=- ==== Deleting Files \ Folders ====================== C:\Users\Joyce\AppData\Local\RewardsArcade not found "C:\Program Files\tanzuki\fheleffhdiajkhjhebfibagnfkoelbdk.crx" not found C:\Windows\system32\Tasks\{14C43A3D-211D-44CE-83EB-4B01C666FE55} deleted C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 deleted C:\Windows\system32\tasks\0 deleted C:\Windows\system32\tasks\4687 deleted "C:\Qoobox" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files\McAfee\SiteAdvisor" [04-10-2013 16:36] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx[02-10-2013 13:05] SiteAdvisor - Joyce - Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho Star Gazing - Joyce - Default\Extensions\mblmlcbknbnfebdfjnolmcapmdofhmme ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{273A0332-1B97-40E6-B3DF-8E3CEC101608}" {273A0332-1B97-40E6-B3DF-8E3CEC101608} AOL Zoeken Url="{searchTerms} - AOL Search resultaten" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}" {C113F95F-E0F1-4A2E-AF9D-4788A9D49151} Kelkoo Url="http://nl.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913935" ==== Empty IE Cache ====================== C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XSCYE1RA will be deleted at reboot C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Joyce\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XSCYE1RA" not found ==== EOF on wo 27-11-2013 at 3:20:40,42 ======================
  10. Ik had eerst nog een scan met Malwarebytes gedaan, waarmee ik weer geïnfecteerde bestanden vond. Hierbij de log: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Databaseversie: v2013.11.25.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Joyce :: PC_VAN_JOYCE [administrator] 26-11-2013 5:19:59 mbam-log-2013-11-26 (05-19-59).txt Scan type: Volledige scan (C:\|D:\|) Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scan opties: P2P Objecten gescand: 557690 Verstreken tijd: 5 uur/uren, 39 minuut/minuten, 44 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 1 C:\Users\Joyce\AppData\Local\temp\ct2504091 (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. Bestanden gedetecteerd: 3 C:\AdwCleaner\Quarantine\C\Program Files\Vuze\.install4j\user\mism.exe.vir (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\Vuze\.install4j\user\mism.exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Joyce\AppData\Local\temp\ct2504091\ism.exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. (einde) Hier de log van Zoek: Zoek.exe Version 4.0.0.5 Updated 24-November-2013 Tool run by Joyce on di 26-11-2013 at 15:48:12,55. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Joyce\Desktop\zoek\zoek.exe [script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2013-11-23-132719.log 25815 bytes C:\zoek-results2013-11-23-214420.log 31918 bytes C:\zoek-results2013-11-24-154044.log 5532 bytes ==== Reset Hosts File ====================== # Copyright © 1993-2006 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost ::1 localhost ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2101717001-3418350084-2231240781-1000\Software\Microsoft\Internet Explorer\SearchScopes\{35651EE7-5AB8-44B2-9C31-8DC52C5DEE4E} deleted successfully HKEY_USERS\S-1-5-21-2101717001-3418350084-2231240781-1000\Software\Microsoft\Internet Explorer\SearchScopes\{654BA83E-FA5A-4022-83BD-C7713448FF40} deleted successfully HKEY_USERS\S-1-5-21-2101717001-3418350084-2231240781-1000\Software\Microsoft\Internet Explorer\SearchScopes\{84B93BE4-7605-4C78-900E-C2D50C39F337} deleted successfully HKEY_USERS\S-1-5-21-2101717001-3418350084-2231240781-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BC69120F-1308-4496-BF16-6C22847C5AFC} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Joyce\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js: Added to C:\Users\Joyce\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js: user_pref("browser.startup.homepage", "Google"); user_pref("browser.search.defaulturl", "Google="); user_pref("browser.newtab.url", "Google"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "Google="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Joyce\AppData\Roaming\Mozilla\Firefox\Profiles\extensions user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_23-11-2013_2154_.backup prefs_26-11-2013_1709_.backup ==== Deleting Files \ Folders ====================== C:\Users\Joyce\daemonprocess.txt deleted C:\Program Files\Mobogenie deleted C:\Program Files\BearShare Applications\MediaBar deleted C:\Program Files\tanzuki deleted C:\extensions deleted C:\Users\Joyce\AppData\Roaming\Alawar Entertainment deleted C:\Users\Joyce\AppData\Roaming\AlawarEntertainment deleted C:\Users\Joyce\AppData\Roaming\LimeWirePlus deleted C:\Users\Joyce\AppData\Local\Mobogenie deleted C:\Users\Joyce\AppData\LocalLow\uTorrentBar_NL deleted C:\Windows\system32\tasks\YourFile DownloaderUpdate deleted C:\user.js deleted C:\prefs.js deleted C:\END deleted C:\Users\Joyce\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2013-11-16 13:43:17 47D2D836EDC4D62C47A05DAED90F1AB9 305736031 ----a-w- C:\Windows\MEMORY.DMP ====== C:\Users\Joyce\AppData\Local\Temp ==== 2013-11-25 22:22:44 7E89844169E755775F09AA4724680281 24489269 ----a-w- C:\Users\Joyce\AppData\Local\Temp\vlc-2.1.1-win32.exe 2013-11-25 21:51:58 FBBE666FFDA9DADF43EF083F9CA78F19 104137 ----a-w- C:\Users\Joyce\AppData\Local\Temp\Uninstall.exe 2013-11-25 09:28:16 EFA14B8099DD1CC2F93213745A5AB4E6 4220936 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\HPDiagnosticCoreUI.exe 2013-11-25 09:28:15 F83D8C0CD50B825DE2976E3C54B43309 2278920 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\DeviceManager\DeviceManager.exe 2013-11-25 09:28:15 F4D5352EF00CC2B97B150AF6B36F10ED 1695752 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\FileExtractor.exe 2013-11-25 09:28:15 B12842B441FD6E76EC814A6DA5455132 58176 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\OESISCore.dll 2013-11-25 09:28:15 98ABCBD70CDA02B76E1A1E46C16192FA 35176 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\hpodss01.dll 2013-11-25 09:28:15 67EC459E42D3081DD8FD34356F7CAFC1 770384 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\msvcr100.dll 2013-11-25 09:28:15 4D144541EE2E6FB2C26653C22BC419C7 77120 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\Impl_SoftwareProductLib.dll 2013-11-25 09:28:15 38F548B446636444C00CA64D4BB8B3D0 60224 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\Impl_FirewallLib.dll 2013-11-25 09:28:15 03E9314004F504A14A61C3D364B62F66 421200 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\msvcp100.dll 2013-11-25 09:28:14 960A1D195A77D873810A9CBD71DA1E93 3129864 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\HPDiagnosticCore.dll 2013-11-25 09:28:13 D671C7CC1308576B31EA69BE2D180D17 217408 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\FWManager.dll 2013-11-25 09:28:13 D199B1ADFFB14070E8C4DA9E879EDBEE 309760 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\DIFxAPI.dll 2013-11-25 09:28:13 585D2EB9FBED6B7B9D0107BFB5C94043 531512 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\DeviceManager\DIFxAPI.dll 2013-11-25 09:28:13 4046243A482465070E8336034D2BB2F6 495424 ----a-w- C:\Users\Joyce\AppData\Local\Temp\7zS6353\CoreUtils.dll 2013-11-22 17:33:17 0E771375445E13429E68CAE720A48B72 35224 ----a-w- C:\Users\Joyce\AppData\Local\Temp\e4j6B11.tmp_dir1385141596\i4jdel.exe 2013-11-16 15:36:32 0E771375445E13429E68CAE720A48B72 35224 ----a-w- C:\Users\Joyce\AppData\Local\Temp\e4j8601.tmp_dir1384616192\i4jdel.exe 2013-11-15 17:53:57 0E771375445E13429E68CAE720A48B72 35224 ----a-w- C:\Users\Joyce\AppData\Local\Temp\e4j2AC7.tmp_dir1384538037\i4jdel.exe ====== Java Cache ===== ====== C:\Windows\system32 ===== 2013-11-17 02:04:41 B798365F54AF889BFD7D04ED75C016B7 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2013-11-17 02:04:41 3CC9655434741363AF977498A2B5E425 73216 ----a-w- C:\Windows\System32\mshtmled.dll 2013-11-17 02:04:40 677857FAC307E46E44F710B6C6F84607 420864 ----a-w- C:\Windows\System32\vbscript.dll 2013-11-17 02:04:38 E26C86DE3AC36D09D201691B9D482D5B 176640 ----a-w- C:\Windows\System32\ieui.dll 2013-11-17 02:04:38 375652E4B01E421683437896DA8D76C4 65024 ----a-w- C:\Windows\System32\jsproxy.dll 2013-11-17 02:04:36 E2E9F49C84C49C2DB5ADAF85D8CD8F1C 142848 ----a-w- C:\Windows\System32\ieUnatt.exe 2013-11-17 02:04:35 E1092FB18A2D53DFC20D2EA8AC158E4B 607744 ----a-w- C:\Windows\System32\msfeeds.dll 2013-11-17 02:04:35 C36E38AD3C7FAFF0E30C4CBCB28CE7FB 1129472 ----a-w- C:\Windows\System32\wininet.dll 2013-11-17 02:04:34 FFA200640B887CBB737DA74C299BCE62 717824 ----a-w- C:\Windows\System32\jscript.dll 2013-11-17 02:04:32 D36137E26569D22B6C395EB68CBE0018 1806848 ----a-w- C:\Windows\System32\jscript9.dll 2013-11-17 02:04:32 26ED02FA7B11FBFD87D4FF304EFFFFBF 231936 ----a-w- C:\Windows\System32\url.dll 2013-11-17 02:04:31 58C300DB5ED80A46A778DECB9D02DA57 1796096 ----a-w- C:\Windows\System32\iertutil.dll 2013-11-17 02:04:29 B8D440F705D52D9167C572ECF6522E89 1104896 ----a-w- C:\Windows\System32\urlmon.dll 2013-11-17 02:04:29 AB3F4974C87DC6DE7E427CF713E88B28 1427968 ----a-w- C:\Windows\System32\inetcpl.cpl 2013-11-17 02:04:27 048FF8515CE100990423E96678112CDF 9739264 ----a-w- C:\Windows\System32\ieframe.dll 2013-11-17 02:04:25 AC986A1AD35CDBF07B0E5D1AC9D527B5 12344832 ----a-w- C:\Windows\System32\mshtml.dll 2013-11-16 13:54:43 872363237F24BCB03D73E2A3B4FBF38D 297984 ----a-w- C:\Windows\System32\gdi32.dll 2013-11-16 13:53:12 0317420D419E1885894B3ED9D375D245 993792 ----a-w- C:\Windows\System32\crypt32.dll 2013-11-16 13:48:51 4687EE0C0DD2CE5F7AAA9C2E33C1DC78 444928 ----a-w- C:\Windows\System32\IKEEXT.DLL 2013-11-16 13:48:50 EE16F3E01C4A6C77383F1BBBD10AD6C2 596480 ----a-w- C:\Windows\System32\FWPUCLNT.DLL 2013-11-16 13:48:50 14D9A057A082E00116A7A4415051D07C 218228 ----a-w- C:\Windows\System32\WFP.TMF ====== C:\Windows\system32\drivers ===== 2013-11-10 06:05:11 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\Windows\System32\drivers\mbam.sys 2013-11-06 21:57:58 156765F692192EA9039A6C4A809312FD 147912 ----a-w- C:\Windows\System32\drivers\HipShieldK.sys 2013-11-06 21:56:45 12F0F8D3F84FAB8F31D073286FE131CB 2641 ----a-w- C:\Windows\System32\drivers\mfencrk.inf 2013-11-06 21:56:43 4DC47CB74EBC1D92DD445FCC5DEAE76A 2951 ----a-w- C:\Windows\System32\drivers\mfencbdc.inf ====== C:\Windows\Tasks ====== 2013-11-25 04:27:58 4FE3DFEFAE1C934C9C491946051D55E9 3150 ----a-w- C:\Windows\system32\Tasks\{14C43A3D-211D-44CE-83EB-4B01C666FE55} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-11-25 20:19:22 -------- d-----w- C:\Program Files\Vuze 2013-11-06 22:06:25 -------- d-----w- C:\Program Files\iPod ======= C: ===== ====== C:\Users\Joyce\AppData\Roaming ====== 2013-11-25 22:17:19 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Questerium - Sinister Trinity CE 2013-11-25 22:11:22 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cursery. The Crooked Man 1.0 2013-11-24 20:31:14 -------- d-----w- C:\Users\Public\AppData\Local\temp 2013-11-24 20:31:14 -------- d-----w- C:\Users\Joyce\AppData\Local\temp(86) 2013-11-24 20:31:14 -------- d-----w- C:\Users\Default\AppData\Local\temp 2013-11-24 20:31:14 -------- d-----w- C:\Users\Default User\AppData\Local\temp 2013-11-24 06:52:07 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Digital Quarter 2013-11-11 12:26:02 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted House Mysteries 2013-11-10 04:31:52 AD20B43650D9760DA69255BB4B6939E2 5 ----a-w- C:\Users\Joyce\AppData\Roaming\mbam.context.scan 2013-11-07 00:18:41 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Witchs Green Amulet 2013-11-06 23:59:02 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Empress of the Deep III Legacy of the Phoenix CE 2013-11-06 23:03:12 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Hidden Objects TheHauntedHouse 2013-11-06 02:21:36 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Anvate Games 2013-11-06 02:19:05 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Silverback Games 2013-11-06 01:45:14 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Beast of Lycan Isle CE 2013-11-06 01:36:37 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Night Mysteries The Amphora Prisoner 1.0 2013-11-05 06:33:07 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Legacy Games 2013-11-05 06:16:07 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paranormal State - Poison Spring 2013-11-04 11:00:10 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Friendly Cactus 2013-11-03 21:35:32 -------- d-----w- C:\Users\Joyce\AppData\Roaming\TheMissingMonaLisa 2013-11-03 18:53:44 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Time Chronicles - The Missing Mona Lisa 2013-10-28 03:30:07 -------- d-----w- C:\Users\Joyce\AppData\Roaming\Mad Head Games ====== C:\Users\Joyce ====== 2013-11-25 04:39:11 AFAFA655CC59872129A32CDE4F60F2DE 1091882 ----a-w- C:\Users\Joyce\Desktop\adwcleaner.exe 2013-11-06 22:08:13 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2013-11-06 22:06:11 -------- d-----w- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 ====== C: exe-files == 2013-11-25 22:13:08 30DD6C9D0BF2E0E2FF06E07D07ADBF79 1345024 ----a-w- C:\Program Files\Foxy Games\Questerium - Sinister Trinity CE\uninstall.exe 2013-11-25 09:28:17 CFBF037E1A6BB739D708D69768A56180 6110144 ----a-w- C:\Program Files\HP\Diagnostics\PSDR\HPPSDr.exe 2013-11-19 22:29:28 FFD052D0F464ADC243C24E71D15C9990 12344 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe 2013-11-19 22:29:28 DD79A6B15C2F28DE98DF4852AAF6B13B 21720 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe 2013-11-19 22:29:28 7B3E10D0AC50271E46A2ED00FE6C4B54 48440 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil7.exe 2013-11-19 22:29:28 3A6EB91CFADA8C4978E7EA79E3A2394B 57048 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\WarrantyObjectChecker.exe 2013-11-19 22:29:28 1C2AD4C01B0CC57094B7EF6803A1A597 151864 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil.exe 2013-11-19 22:29:26 FEE46F832FE746EB600AC65CA6451D1F 27352 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_EMEA.exe 2013-11-19 22:29:26 F86275D16121F6591B69B801DE6ED394 21408 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_NetworkCheck.exe 2013-11-19 22:29:26 F3531CF1C8A643377641A6F9D516FED2 35544 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\OnlineBackupDetection.exe 2013-11-19 22:29:26 DF2AC1055C406AA66869C95C2FD84A21 17464 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSACIPDetection4.exe 2013-11-19 22:29:26 B26DFFF460A1F21A3DCD3529F3F61E14 33544 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\hpsacommander.exe 2013-11-19 22:29:26 A15FA916BD02FE910C2C3017C026FF80 49880 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_PostWarrantyAlert.exe 2013-11-19 22:29:26 99450E601834605668AE9E13BB26F09B 33264 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_CoolSense.exe 2013-11-19 22:29:26 87095CBDCC02AB8BB5ED4B124A70FC5B 27352 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_NSPOS.exe 2013-11-19 22:29:26 78BCA0FAD639A6877813F713FD2B2952 23256 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_RecoveryDisc.exe 2013-11-19 22:29:26 4E68E7D985D5F2EB68405CD246EBEDEB 18336 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_PremiumAlert.exe 2013-11-19 22:29:26 4E3643177241FE9097606FDE53E6298C 33496 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RevGenCountry.exe 2013-11-19 22:29:26 1D80ADF858D37526CDDAE21FA595319F 17312 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSACIPDetection.exe 2013-11-19 22:29:26 136D8804CB446BB88C19856B1DC75861 32472 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_Ex_US.exe 2013-11-19 22:29:26 0986D1E655F8C3014C514F322DD49250 33496 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_CountryCode.exe 2013-11-19 22:29:26 06D9888F172A8AC47959DA5DF68270DE 29400 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_US.exe 2013-11-19 22:29:24 E4F8F4F057E3164A52D9D206D1F99193 31544 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_SmartFriendAwareness.exe 2013-11-19 22:29:24 4C5282B9AF02E930E85761395610DCA1 27864 ----a-w- C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\SystemAgeOneYear.exe === C: other files == 2013-11-25 04:38:35 DBFD867A512C3F9FA2C241EE3B566D46 1304128 ----a-w- C:\Users\Joyce\AppData\Local\temp\azlocprov_0.1.6.3.zip 2013-11-24 20:25:28 DF2626F81C91EF456738E5D81706729D 375 ----a-w- C:\Qoobox\Quarantine\H\av2.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ssqqnksys"="rundll32.exe ssqrrs.dll,s" [HKEY_USERS\S-1-5-21-2101717001-3418350084-2231240781-1000\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden" "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" "HP Photosmart 5510 series (NET)"="C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe -deviceID CN196091LK05NR:NW -scfn HP Photosmart 5510 series (NET) -AutoStart 1" "Facebook Update"="C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe /preload" @="C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "ssqqnksys"="rundll32.exe ssqrrs.dll,s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" "UpdatePSTShortCut"="C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\DVD Suite UpdateWithCreateOnce Software\CyberLink\PowerStarter" "UpdatePDIRShortCut"="C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\PowerDirector UpdateWithCreateOnce SOFTWARE\CyberLink\PowerDirector\7.0" "UpdateP2GoShortCut"="C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0" "UpdateLBPShortCut"="C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5" "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" "UCam_Menu"="C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\YouCam UpdateWithCreateOnce Software\CyberLink\YouCam\2.0" "SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" "QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start" "Persistence"="C:\Windows\system32\igfxpers.exe" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE -startup" "KiesTrayAgent"="C:\Program Files\Samsung\Kies\KiesTrayAgent.exe" "mobilegeni daemon"="C:\Program Files\Mobogenie\DaemonProcess.exe" "mcpltui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden" "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" "HP Photosmart 5510 series (NET)"="C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe -deviceID CN196091LK05NR:NW -scfn HP Photosmart 5510 series (NET) -AutoStart 1" "Facebook Update"="C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe /preload" @="C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" ==== Startup Folders ====================== 2012-05-30 03:12:59 1658 ----a-w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk 2012-05-30 03:12:59 1115 ----a-w- C:\Users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [undetermined Task] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000Core.job --a------ C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe [17-03-2013 22:41] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000UA.job --a------ [undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [undetermined Task] C:\Windows\tasks\HP Photo Creations Messager.job --a------ [undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\0" [c:\program files\internet explorer\iexplore.exe] "C:\Windows\system32\tasks\4687" [wscript.exe C:\Users\Joyce\AppData\Local\Temp\launchie.vbs //B] "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000Core" [C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000UA" [C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\HP Photo Creations Messager" [C:\ProgramData\HP Photo Creations\MessageCheck.exe] "C:\Windows\system32\tasks\HPCustParticipation HP Photosmart 5510 series" ["C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe"] "C:\Windows\system32\tasks\SmartDefragUpdate" [C:\Program Files\IObit\Smart Defrag 2\AutoUpdate.exe] "C:\Windows\system32\tasks\SmartDefrag_Startup" [C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{CA4AB69E-3234-4131-BE49-AAEEAD1A9489}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\{4B682B6B-B23E-40CE-BC3A-FDDF583E17C0}" [C:\Program Files\Skype\Phone\Skype.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask" [C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe] "C:\Windows\system32\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\system32\tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup" [C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files\McAfee\SiteAdvisor" [04-10-2013 16:36] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "crossriderapp498@crossrider.com"="C:\Users\Joyce\AppData\Local\RewardsArcade\498\Firefox" [] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dcmagccbogebndpoodhhhafmofelpffh - C:\Users\Joyce\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx[] fheleffhdiajkhjhebfibagnfkoelbdk - C:\Program Files\tanzuki\fheleffhdiajkhjhebfibagnfkoelbdk.crx[] fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx[02-10-2013 13:05] icdlfehblmklkikfigmjhbmmpmkmpooj - C:\Program Files\Common Files\Spigot\GC\errorassistant_1.1.crx[] SiteAdvisor - Joyce - Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho Star Gazing - Joyce - Default\Extensions\mblmlcbknbnfebdfjnolmcapmdofhmme ==== Chrome Fix ====================== C:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj deleted successfully C:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhhndocbepopiengmnalddpofmgddkfp deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" "Search Page"="Google" "Search Bar"="Upgrade to Google Chrome" "Default_Search_URL"="Google" "Default_Page_URL"="Google" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" "Default_Page_URL"="Google" "Default_Search_URL"="Google" "Search Page"="Google" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="%s - Google Search" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="Google" "CustomizeSearch"="Google" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="Upgrade to Google Chrome" "Default_Search_URL"="Upgrade to Google Chrome" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="Bing" "Search Bar"="Bing" "Default_Search_URL"="Bing" "Default_Page_URL"="MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!" "Start Page"="https://www.google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="Bing" "Search Page"="Bing" "Start Page"="MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!" "Default_Page_URL"="MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="%s - Bing" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="Bing" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{273A0332-1B97-40E6-B3DF-8E3CEC101608}" {273A0332-1B97-40E6-B3DF-8E3CEC101608} AOL Zoeken Url="{searchTerms} - AOL Search resultaten" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}" {C113F95F-E0F1-4A2E-AF9D-4788A9D49151} Kelkoo Url="http://nl.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913935" ==== Reset Google Chrome ====================== Nothing found to reset ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\crossriderapp498@crossrider.com deleted successfully ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyOverride"="*.local" "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dcmagccbogebndpoodhhhafmofelpffh deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\fheleffhdiajkhjhebfibagnfkoelbdk deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj deleted successfully ==== HijackThis Entries ====================== R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.nl/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = Bing R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Groove GFS Browser Helper - {4DB74D06-491C-440D-305E-012400990F3E} - C:\Windows\system32\d33dx10.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [updatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunOnce: [NCPluginUpdater] "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe O4 - HKCU\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN196091LK05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload O4 - HKCU\..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe O4 - HKUS\S-1-5-18\..\Run: [ssqqnksys] rundll32.exe "ssqrrs.dll",s (User 'SYSTEEM') O4 - HKUS\.DEFAULT\..\Run: [ssqqnksys] rundll32.exe "ssqrrs.dll",s (User 'Default user') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: HP Slim selecteren - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\mcsniepl.dll O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - (no file) O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\aestsrv.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe O23 - Service: Google Updateservice (gupdate1cad429e4fae9f9) (gupdate1cad429e4fae9f9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: Online Games Manager (ogmservice) - RealNetworks, Inc. - C:\Program Files\Online Games Manager\ogmservice.exe O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe ==== Empty IE Cache ====================== C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Joyce\AppData\Local\temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U73RZH2Q will be deleted at reboot C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Joyce\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Joyce\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U73RZH2Q" not found ==== EOF on di 26-11-2013 at 18:06:17,88 ======================
  11. Alleen de internet browser laadt wel langzamer dan gisteren, maar voor de rest merk ik weinig verschil.
  12. # AdwCleaner v3.013 - Report created 25/11/2013 at 14:34:49 # Updated 24/11/2013 by Xplode # Operating System : Windows Vista Home Premium Service Pack 2 (32 bits) # Username : Joyce - PC_VAN_JOYCE # Running from : C:\Users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CQVX44VN\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files\Vuze File Deleted : C:\END ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\Conduit ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16520 -\\ Mozilla Firefox v [ File : C:\Users\Joyce\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ] ************************* AdwCleaner[R0].txt - [927 octets] - [25/11/2013 14:29:29] AdwCleaner[s0].txt - [857 octets] - [25/11/2013 14:34:49] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [916 octets] ########## Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Databaseversie: v2013.11.25.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Joyce :: PC_VAN_JOYCE [administrator] 25-11-2013 4:39:25 mbam-log-2013-11-25 (04-39-25).txt Scan type: Volledige scan (C:\|D:\|) Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scan opties: P2P Objecten gescand: 554282 Verstreken tijd: 8 uur/uren, 49 minuut/minuten, 33 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 1 C:\Users\Joyce\AppData\Local\temp\ct2504091 (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. Bestanden gedetecteerd: 1 C:\Users\Joyce\AppData\Local\temp\ct2504091\ism.exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd. (einde)
  13. Ik heb een klein probleempje denk ik. Ik heb vannacht mijn computer moeten herstellen naar een herstelpunt op 23-11 .. Ik weet niet wat de gevolgen daarvan zijn voor alle handelingen die we gedaan hebben. De computer is nu een scan van MalwareBytes aan het doen. Ook heb ik net de adwcleaner al een keer gedaan.. Moet alles weer opnieuw gescand worden??
  14. De internet browser laadde heel snel, maar nadat ik me computer opnieuw opgestart had, laadde die heel langzaam. Ook heb ik 2 websites gecheckt, waar ik normaal altijd een pop up venster krijg. Maar ik kreeg weer 2 pop up vensters. Kan dat misschien toch aan de websites zelf liggen?
  15. ComboFix 13-11-23.02 - Joyce 24-11-2013 20:57:58.3.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3002.1217 [GMT 1:00] Gestart vanuit: c:\users\Joyce\Desktop\ComboFix.exe AV: McAfee Antivirus en antispyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892} FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9} SP: McAfee Antivirus en antispyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Aanwezig AV is actief . . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Joyce\AppData\Local\Microsoft\Windows\Temporary Internet Files\tanzuki_iels c:\users\Joyce\AppData\Roaming\inst.exe c:\users\Joyce\AppData\Roaming\log.txt c:\windows\system32\d33Dx10.dll c:\windows\system32\FlashPlayerApp.exe H:\Autorun.inf . . (((((((((((((((((((( Bestanden Gemaakt van 2013-10-24 to 2013-11-24 )))))))))))))))))))))))))))))) . . 2013-11-24 20:25 . 2013-11-24 20:25 -------- d-----w- c:\users\Joyce\AppData\Local\temp 2013-11-24 20:25 . 2013-11-24 20:25 -------- d-----w- c:\users\Public\AppData\Local\temp 2013-11-24 20:25 . 2013-11-24 20:25 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-11-24 15:28 . 2013-11-24 14:06 24064 ----a-w- c:\windows\zoek-delete.exe 2013-11-24 10:39 . 2013-11-24 10:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-11-24 10:39 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-11-24 06:52 . 2013-11-24 06:52 -------- d-----w- c:\users\Joyce\AppData\Roaming\Digital Quarter 2013-11-23 12:26 . 2013-11-24 15:03 -------- d-----w- C:\zoek_backup 2013-11-22 18:01 . 2013-11-08 01:15 7772552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2E9CE69-A2F1-415E-894C-1D7BF3BB8DE3}\mpengine.dll 2013-11-16 13:57 . 2013-11-16 14:03 -------- d-----w- c:\windows\system32\MRT 2013-11-16 13:54 . 2013-10-03 12:45 297984 ----a-w- c:\windows\system32\gdi32.dll 2013-11-16 13:53 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll 2013-11-16 13:48 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-11-16 13:48 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-11-10 19:36 . 2013-11-10 19:37 -------- d-----w- C:\rsit 2013-11-10 09:33 . 2013-11-24 19:13 -------- d-----w- C:\AdwCleaner 2013-11-06 23:40 . 2013-11-06 23:40 -------- d-----w- c:\users\Joyce\AppData\Local\McAfee File Lock 2013-11-06 23:03 . 2013-11-06 23:04 -------- d-----w- c:\users\Joyce\AppData\Roaming\Hidden Objects TheHauntedHouse 2013-11-06 22:06 . 2013-11-06 22:06 -------- d-----w- c:\program files\iPod 2013-11-06 22:06 . 2013-11-06 22:08 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-11-06 21:57 . 2013-09-23 12:48 147912 ----a-w- c:\windows\system32\drivers\HipShieldK.sys 2013-11-06 02:21 . 2013-11-06 02:21 -------- d-----w- c:\users\Joyce\AppData\Roaming\Anvate Games 2013-11-06 02:19 . 2013-11-07 00:00 -------- d-----w- c:\users\Joyce\AppData\Roaming\Silverback Games 2013-11-06 00:58 . 2013-11-12 00:43 -------- d-----w- C:\Games 2013-11-05 06:33 . 2013-11-05 06:33 -------- d-----w- c:\users\Joyce\AppData\Roaming\Legacy Games 2013-11-04 22:41 . 2013-11-05 05:23 -------- d-----w- c:\users\Joyce\AppData\Local\Mobogenie 2013-11-04 22:36 . 2013-11-05 05:25 -------- d-----w- c:\program files\Mobogenie 2013-11-04 11:00 . 2013-11-04 11:00 -------- d-----w- c:\users\Joyce\AppData\Roaming\Friendly Cactus 2013-11-03 21:35 . 2013-11-03 21:35 -------- d-----w- c:\users\Joyce\AppData\Roaming\TheMissingMonaLisa 2013-11-03 18:42 . 2013-11-03 18:42 -------- d-----w- c:\windows\Hidden Mysteries - Notre Dame 2013-11-03 05:51 . 2013-11-03 05:51 -------- d-----w- c:\windows\Rite of Passage 2- Child of the Forest CE 2013-10-28 03:30 . 2013-11-03 22:00 -------- d-----w- c:\users\Joyce\AppData\Roaming\Mad Head Games . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-11-23 12:20 . 2011-05-18 10:17 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-11-11 04:50 . 2010-05-18 21:43 230048 ------w- c:\windows\system32\MpSigStub.exe 2013-09-24 19:53 . 2012-07-08 11:03 60920 ----a-w- c:\windows\system32\drivers\cfwids.sys 2013-09-24 19:49 . 2012-07-08 11:03 213200 ----a-w- c:\windows\system32\drivers\mfewfpk.sys 2013-09-24 19:49 . 2011-07-07 21:04 172416 ----a-w- c:\windows\system32\mfevtps.exe 2013-09-24 19:45 . 2011-03-13 09:20 571608 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2013-09-24 19:44 . 2012-07-08 11:03 365256 ----a-w- c:\windows\system32\drivers\mfefirek.sys 2013-09-24 19:44 . 2012-07-08 11:03 65928 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2013-09-24 19:43 . 2012-07-08 11:03 235488 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2013-09-24 19:42 . 2011-03-13 09:20 133928 ----a-w- c:\windows\system32\drivers\mfeapfk.sys 2013-09-20 08:37 . 2013-09-20 08:37 10152 ----a-w- c:\windows\system32\drivers\mfeclnrk.sys 2013-09-20 08:37 . 2013-09-20 08:37 80656 ----a-w- c:\windows\system32\drivers\mfencrk.sys 2013-09-20 08:37 . 2013-09-20 08:37 301248 ----a-w- c:\windows\system32\drivers\mfencbdc.sys 2013-09-10 21:18 . 2013-09-10 21:18 97008 ----a-w- c:\windows\system32\drivers\RapportKELL.sys 2013-09-09 10:11 . 2012-10-28 06:04 66296 ----a-w- c:\windows\system32\drivers\McPvDrv.sys 2013-08-29 07:36 . 2013-10-11 16:11 2050048 ----a-w- c:\windows\system32\win32k.sys 2013-08-27 02:47 . 2013-10-11 16:12 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-08-27 02:47 . 2013-10-11 16:12 189952 ----a-w- c:\windows\system32\d3d10core.dll 2013-08-27 02:47 . 2013-10-11 16:12 1029120 ----a-w- c:\windows\system32\d3d10.dll 2013-08-27 02:47 . 2013-10-11 16:12 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2013-08-27 01:52 . 2013-10-11 16:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2013-08-27 01:50 . 2013-10-11 16:12 486400 ----a-w- c:\windows\system32\d3d10level9.dll 2013-08-27 01:32 . 2013-10-11 16:12 683008 ----a-w- c:\windows\system32\d2d1.dll 2013-08-27 01:28 . 2013-10-11 16:12 1069056 ----a-w- c:\windows\system32\DWrite.dll 2013-08-27 01:28 . 2013-10-11 16:12 798208 ----a-w- c:\windows\system32\FntCache.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-06 39408] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392] "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-06-06 102400] "HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-05-25 1801064] "Facebook Update"="c:\users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-03-17 138096] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-03-01 18643560] "KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2013-09-04 1564528] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432] "UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-12-24 210216] "UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216] "UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216] "UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-06-03 450652] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-28 154136] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-28 150040] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-28 178712] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-05 59240] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 516912] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2013-04-15 337432] "KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2013-09-04 311152] "mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 516912] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-11-01 152392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="c:\program files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2013-11-19 21720] . c:\users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\aestsrv.exe [2009-03-02 81920] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-11-17 09:47 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe . Inhoud van de 'Gedeelde Taken' map . 2013-11-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 12:20] . 2013-11-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000Core.job - c:\users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-17 21:41] . 2013-11-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2101717001-3418350084-2231240781-1000UA.job - c:\users\Joyce\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-17 21:41] . 2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 19:05] . 2013-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 19:05] . 2013-11-24 c:\windows\Tasks\HP Photo Creations Messager.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11] . . ------- Bijkomende Scan ------- . uStart Page = https://www.google.nl/ IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.254 . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-10 - (no file) HKLM-Run-mobilegeni daemon - c:\program files\Mobogenie\DaemonProcess.exe HKU-Default-Run-ssqqnksys - ssqrrs.dll c:\users\Joyce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe -startup SafeBoot-Wdf01000.sys SafeBoot-WudfPf SafeBoot-WudfRd AddRemove-8461-7759-5462-8226 - c:\program files\Vuze\uninstall.exe AddRemove-Activation Assistant for the 2007 Microsoft Office suites - c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2013-11-24 21:25 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . HKLM\Software\Microsoft\Windows\CurrentVersion\Run mobilegeni daemon = c:\program files\Mobogenie\DaemonProcess.exe????????????????????????????????????????????????????????????????????????????????????? . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Voltooingstijd: 2013-11-24 21:31:08 ComboFix-quarantined-files.txt 2013-11-24 20:31 ComboFix2.txt 2012-05-30 14:30 ComboFix3.txt 2012-05-30 13:43 . Pre-Run: 47.010.701.312 bytes beschikbaar Post-Run: 46.971.252.736 bytes beschikbaar . - - End Of File - - A9183AD598640C59EBD6E6B6214E476C 588AE8F0C685C02BA11F30D9CD7E61A0
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.