Ga naar inhoud

Aanbevolen berichten

Geplaatst:

Download 52147fb3b2536-AdwCleaner_99_3_16x16x32.pngAdwCleaner by Xplode naar het bureaublad.

AdwCleaner uitvoeren

  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik vervolgens op de knop Scan.
  • Wanneer de scan gereed is Klikt u vervolgens op de knop Clean.
  • Als dit gereed is wordt er gevraagd om de computer opnieuw op te starten, klik hier op OK.
  • Nadat de computer opnieuw is opgestart wordt het logbestand automatisch geopend.
  • Plaats dit logbestand in het volgende bericht.

Geplaatst:

Download 51a5bf3d99e8a-ComboFixlogo16.pngComboFix van één van de onderstaande locaties naar het bureaublad.

Bleeping Computer

Info Spyware

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met ComboFix.exe

(hier of hier) kan je lezen hoe je de gebruikte beveiligingssoftware kunt uitschakelen.

  • Dubbelklik op "ComboFix" om de tool te starten, Windows Vista, 7 & 8 gebruikers zullen een melding krijgen van UAC (Gebruikersaccountbeheer), klik hier op Ja / yes.
  • Op een Windows XP computer zal ComboFix de "Recovery Console" installeren als deze nog niet aanwezig is. (Een actieve internet verbinding is dan een vereiste).
  • Klik in het venster bij het 'Installeren van de Recovery Console' op "Ok".
  • Klik in het info scherm op "Ja" als de Recovery Console met succes is geïnstalleerd.
  • Klik in het scherm van de disclaimer op "I Agree", de benodigde onderdelen worden nu uitgepakt en middels ERUNT wordt er een register back-up gemaakt.
  • Wanneer dit gereed is zal ComboFix vanzelf starten, in het blauwe scherm ziet u de voortgang van de systeemscan die wordt uitgevoerd.
  • Belangrijk! gebruik de computer tijdens de scan niet voor andere zaken.
  • Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden zoals bijvoorbeeld bij de aanwezigheid van een rootkit, dit is normaal.
  • Wanneer ComboFix gereed is, zal het een logbestand aanmaken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

* Noot !!! Indien u één van de onderstaande meldingen krijgt na het gebruik van ComboFix herstart dan de computer.

  • Er is geprobeerd een ongeldige bewerking uit te voeren op een registersleutel die is gemarkeerd voor verwijdering.
  • Illegal operation attempted on a registry key that has been marked for deletion.

Geplaatst:

ComboFix 14-01-16.03 - Arvid Beekman 21-01-2014 10:23:50.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4095.2565 [GMT 1:00]

Gestart vanuit: c:\users\Arvid Beekman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MQNGC0Q1\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Arvid Beekman\AppData\Roaming\Microsoft\engine_ag.dll

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-12-21 to 2014-01-21 ))))))))))))))))))))))))))))))

.

.

2014-01-21 09:31 . 2014-01-21 09:31 -------- d-----w- c:\users\Public\AppData\Local\temp

2014-01-21 09:31 . 2014-01-21 09:31 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-01-21 09:17 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29F7ACDE-00F0-47EF-94A6-8014049F8714}\mpengine.dll

2014-01-20 15:29 . 2014-01-20 15:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2014-01-20 15:29 . 2014-01-20 15:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2014-01-19 17:58 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2014-01-17 11:04 . 2012-06-01 05:36 192000 ----a-w- c:\windows\system32\iisRtl.dll

2014-01-17 11:04 . 2012-06-01 04:37 154624 ----a-w- c:\windows\SysWow64\iisRtl.dll

2014-01-17 11:04 . 2012-06-01 05:34 55296 ----a-w- c:\windows\system32\admwprox.dll

2014-01-17 11:04 . 2012-06-01 04:35 50688 ----a-w- c:\windows\SysWow64\admwprox.dll

2014-01-17 11:04 . 2012-06-01 05:39 14848 ----a-w- c:\windows\system32\wamregps.dll

2014-01-17 11:04 . 2012-06-01 05:35 60928 ----a-w- c:\windows\system32\ahadmin.dll

2014-01-17 11:04 . 2012-06-01 05:33 16896 ----a-w- c:\windows\system32\iisreset.exe

2014-01-17 11:04 . 2012-06-01 04:35 26624 ----a-w- c:\windows\SysWow64\ahadmin.dll

2014-01-17 11:04 . 2012-06-01 04:34 15360 ----a-w- c:\windows\SysWow64\iisreset.exe

2014-01-17 11:04 . 2012-06-01 05:36 11264 ----a-w- c:\windows\system32\iisrstap.dll

2014-01-17 11:04 . 2012-06-01 04:40 10752 ----a-w- c:\windows\SysWow64\wamregps.dll

2014-01-17 11:04 . 2012-06-01 04:37 8192 ----a-w- c:\windows\SysWow64\iisrstap.dll

2014-01-17 10:55 . 2013-12-01 13:10 257624 ----a-w- c:\windows\system32\unrar64.dll

2014-01-17 10:55 . 2013-12-01 13:10 218200 ----a-w- c:\windows\SysWow64\unrar.dll

2014-01-17 10:55 . 2014-01-17 10:55 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack

2014-01-16 14:30 . 2014-01-16 14:30 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\AnvSoft

2014-01-16 14:30 . 2014-01-16 14:30 -------- d-----w- c:\program files (x86)\AnvSoft

2014-01-16 10:03 . 2014-01-16 09:45 24064 ----a-w- c:\windows\zoek-delete.exe

2014-01-16 10:03 . 2014-01-21 09:31 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\Temp

2014-01-16 09:45 . 2014-01-16 09:57 -------- d-----w- C:\zoek_backup

2014-01-16 08:03 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys

2014-01-16 08:03 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys

2014-01-16 08:03 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys

2014-01-16 08:03 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys

2014-01-16 08:03 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys

2014-01-16 08:03 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys

2014-01-16 08:03 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys

2014-01-16 08:03 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys

2014-01-16 08:03 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys

2014-01-16 08:02 . 2014-01-16 08:02 -------- d-----w- C:\inetpub

2014-01-15 13:11 . 2014-01-15 13:11 -------- d-----w- C:\AMD

2014-01-15 12:43 . 2014-01-15 12:43 -------- d-----w- C:\rsit

2014-01-15 12:43 . 2014-01-15 12:43 -------- d-----w- c:\program files\trend micro

2014-01-15 09:24 . 2014-01-15 09:24 -------- d--h--w- c:\windows\AxInstSV

2014-01-15 09:09 . 2014-01-15 09:09 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\ElevatedDiagnostics

2014-01-11 10:45 . 2014-01-11 10:45 -------- d-----w- c:\windows\SysWow64\Adobe

2014-01-10 11:23 . 2014-01-10 11:23 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\Apowersoft

2014-01-09 12:32 . 2014-01-09 14:18 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\Spotydl

2014-01-09 12:31 . 2014-01-09 12:32 -------- d-----w- c:\program files (x86)\Spotydl

2014-01-04 13:01 . 2014-01-04 13:01 -------- d-----w- c:\programdata\ASUS

2014-01-04 13:01 . 2014-01-04 13:01 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\ASUS

2013-12-28 13:41 . 2013-12-28 13:41 -------- d-----w- c:\program files\iPod

2013-12-28 13:41 . 2013-12-28 13:43 -------- d-----w- c:\program files\iTunes

2013-12-28 13:41 . 2013-12-28 13:43 -------- d-----w- c:\program files (x86)\iTunes

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-01-19 07:33 . 2013-10-14 17:10 270496 ------w- c:\windows\system32\MpSigStub.exe

2014-01-16 08:13 . 2013-10-14 19:03 86054176 ----a-w- c:\windows\system32\MRT.exe

2013-11-23 18:26 . 2013-12-11 09:10 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll

2013-11-23 17:47 . 2013-12-11 09:10 465920 ----a-w- c:\windows\system32\WMPhoto.dll

2013-11-12 02:23 . 2013-12-11 09:10 2048 ----a-w- c:\windows\system32\tzres.dll

2013-11-12 02:07 . 2013-12-11 09:10 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2013-10-30 11:13 . 2013-11-21 19:29 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll

2013-10-30 11:07 . 2013-10-30 11:07 90112 ----a-w- c:\windows\MAMCityDownload.ocx

2013-10-30 11:07 . 2013-10-30 11:07 330240 ----a-w- c:\windows\MASetupCaller.dll

2013-10-30 11:07 . 2013-10-30 11:07 30568 ----a-w- c:\windows\MusiccityDownload.exe

2013-10-30 11:06 . 2013-10-30 11:06 974848 ----a-w- c:\windows\SysWow64\cis-2.4.dll

2013-10-30 11:06 . 2013-10-30 11:06 81920 ----a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll

2013-10-30 11:06 . 2013-10-30 11:06 65536 ----a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll

2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\MTXSYNCICON.dll

2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\MK_Lyric.dll

2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\issacapi_se-2.3.dll

2013-10-30 11:06 . 2013-10-30 11:06 569344 ----a-w- c:\windows\SysWow64\muzdecode.ax

2013-10-30 11:06 . 2013-10-30 11:06 491520 ----a-w- c:\windows\SysWow64\muzapp.dll

2013-10-30 11:06 . 2013-10-30 11:06 49152 ----a-w- c:\windows\SysWow64\MaJGUILib.dll

2013-10-30 11:06 . 2013-10-30 11:06 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll

2013-10-30 11:06 . 2013-10-30 11:06 45056 ----a-w- c:\windows\SysWow64\MaXMLProto.dll

2013-10-30 11:06 . 2013-10-30 11:06 45056 ----a-w- c:\windows\SysWow64\MACXMLProto.dll

2013-10-30 11:06 . 2013-10-30 11:06 40960 ----a-w- c:\windows\SysWow64\MTTELECHIP.dll

2013-10-30 11:06 . 2013-10-30 11:06 352256 ----a-w- c:\windows\SysWow64\MSLUR71.dll

2013-10-30 11:06 . 2013-10-30 11:06 258048 ----a-w- c:\windows\SysWow64\muzoggsp.ax

2013-10-30 11:06 . 2013-10-30 11:06 245760 ----a-w- c:\windows\SysWow64\MSCLib.dll

2013-10-30 11:06 . 2013-10-30 11:06 24576 ----a-w- c:\windows\SysWow64\MASetupCleaner.exe

2013-10-30 11:06 . 2013-10-30 11:06 200704 ----a-w- c:\windows\SysWow64\muzwmts.dll

2013-10-30 11:06 . 2013-10-30 11:06 172032 ----a-w- c:\windows\SysWow64\muzapp.exe

2013-10-30 11:06 . 2013-10-30 11:06 155648 ----a-w- c:\windows\SysWow64\MSFLib.dll

2013-10-30 11:06 . 2013-10-30 11:06 143360 ----a-w- c:\windows\SysWow64\3DAudio.ax

2013-10-30 11:06 . 2013-10-30 11:06 135168 ----a-w- c:\windows\SysWow64\muzaf1.dll

2013-10-30 11:06 . 2013-10-30 11:06 131072 ----a-w- c:\windows\SysWow64\muzmpgsp.ax

2013-10-30 11:06 . 2013-10-30 11:06 122880 ----a-w- c:\windows\SysWow64\muzeffect.ax

2013-10-30 11:06 . 2013-10-30 11:06 118784 ----a-w- c:\windows\SysWow64\MaDRM.dll

2013-10-30 11:06 . 2013-10-30 11:06 110592 ----a-w- c:\windows\SysWow64\muzmp4sp.ax

2013-10-30 11:06 . 2013-11-21 19:29 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll

2013-10-30 08:59 . 2013-10-30 08:59 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2013-10-30 08:59 . 2013-10-30 08:59 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2013-10-30 08:59 . 2013-10-30 08:59 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll

2013-10-30 08:59 . 2013-10-30 08:59 1682432 ----a-w- c:\windows\system32\XpsPrint.dll

2013-10-30 08:59 . 2013-10-30 08:59 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll

2013-10-30 08:59 . 2013-10-30 08:59 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-10-30 08:59 . 2013-10-30 08:59 648192 ----a-w- c:\windows\system32\d3d10level9.dll

2013-10-30 08:59 . 2013-10-30 08:59 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll

2013-10-30 08:59 . 2013-10-30 08:59 3928064 ----a-w- c:\windows\system32\d2d1.dll

2013-10-30 08:59 . 2013-10-30 08:59 363008 ----a-w- c:\windows\system32\dxgi.dll

2013-10-30 08:59 . 2013-10-30 08:59 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll

2013-10-30 08:59 . 2013-10-30 08:59 333312 ----a-w- c:\windows\system32\d3d10_1core.dll

2013-10-30 08:59 . 2013-10-30 08:59 296960 ----a-w- c:\windows\system32\d3d10core.dll

2013-10-30 08:59 . 2013-10-30 08:59 293376 ----a-w- c:\windows\SysWow64\dxgi.dll

2013-10-30 08:59 . 2013-10-30 08:59 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll

2013-10-30 08:59 . 2013-10-30 08:59 2565120 ----a-w- c:\windows\system32\d3d10warp.dll

2013-10-30 08:59 . 2013-10-30 08:59 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll

2013-10-30 08:59 . 2013-10-30 08:59 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll

2013-10-30 08:59 . 2013-10-30 08:59 221184 ----a-w- c:\windows\system32\UIAnimation.dll

2013-10-30 08:59 . 2013-10-30 08:59 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll

2013-10-30 08:59 . 2013-10-30 08:59 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll

2013-10-30 08:59 . 2013-10-30 08:59 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll

2013-10-30 08:59 . 2013-10-30 08:59 194560 ----a-w- c:\windows\system32\d3d10_1.dll

2013-10-30 08:59 . 2013-10-30 08:59 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll

2013-10-30 08:59 . 2013-10-30 08:59 1643520 ----a-w- c:\windows\system32\DWrite.dll

2013-10-30 08:59 . 2013-10-30 08:59 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll

2013-10-30 08:59 . 2013-10-30 08:59 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll

2013-10-30 08:59 . 2013-10-30 08:59 1238528 ----a-w- c:\windows\system32\d3d10.dll

2013-10-30 08:59 . 2013-10-30 08:59 1175552 ----a-w- c:\windows\system32\FntCache.dll

2013-10-30 08:59 . 2013-10-30 08:59 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll

2013-10-30 02:32 . 2013-12-11 09:10 335360 ----a-w- c:\windows\system32\msieftp.dll

2013-10-30 02:19 . 2013-12-11 09:10 301568 ----a-w- c:\windows\SysWow64\msieftp.dll

2013-10-28 16:44 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll

2013-10-28 16:44 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll

2013-10-26 08:26 . 2013-12-06 14:12 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{465ED3EC-3071-4C89-923D-033AF590D9C1}\gapaengine.dll

2013-10-26 08:26 . 2013-10-26 08:26 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]

@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"

[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]

2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]

@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"

[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]

2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]

@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"

[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]

2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"KiesPreload"="c:\users\Arvid Beekman\Kies\Kies.exe" [2013-11-06 1564528]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"KiesTrayAgent"="c:\users\Arvid Beekman\Kies\KiesTrayAgent.exe" [2013-11-06 311152]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-17 2245120]

"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]

"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2010-01-13 7109248]

"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2010-01-05 170624]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]

"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-11 98304]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]

R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]

R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]

R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]

R4 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]

S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]

S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2014-01-21 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-20 15:29]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]

@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"

[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]

2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]

@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"

[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]

2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]

@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"

[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]

2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]

"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]

"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = https://www.google.nl/

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 192.168.2.254 195.121.1.34 195.121.1.66

Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr

AddRemove-PC Cleaners - c:\programdata\pclunst.exe

AddRemove-UpdaterEX - c:\users\Arvid Beekman\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2014-01-21 10:35:14

ComboFix-quarantined-files.txt 2014-01-21 09:35

ComboFix2.txt 2013-12-15 18:49

.

Pre-Run: 2.100.330.496 bytes beschikbaar

Post-Run: 2.284.457.984 bytes beschikbaar

.

- - End Of File - - CE46A40B831386729A9798F8CFF00963

5C616939100B85E558DA92B899A0FC36

Geplaatst:

Dubbelklik op Zoek.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

firefoxlook; 

  • Klik op de knop "Options" en vink nu de onderstaande opties aan.
  • IE Defaults
  • Reset Chrome
  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.