Ga naar inhoud

Heropend


Aanbevolen berichten

Heb reboot gedaan na F11 toets (zie bericht 3 augustus). Nadien hitman pro x64 kickstarter geplaatst en opnieuw opgestart.

Heb met dit programma virussen verwijderd en een log afgehaald via USB stick (zie bijlage).

Bij de vraag om computer opnieuw op te starten blijft deze wel 'hangen ' op 'update 19 van 20'

Hopelijk hebben we hier voldoende info mee om verder aan de slag te kunnen.

Logfile:

HitmanPro 3.7.9.221
www.hitmanpro.com


  Computer name . . . . : WILLY-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : NT AUTHORITY\SYSTEM
  UAC . . . . . . . . . : Disabled
  License . . . . . . . : Trial (22 days left)


  Scan date . . . . . . : 2014-08-11 20:58:51
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 17m 39s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : Yes


  Threats . . . . . . . : 134
  Traces  . . . . . . . : 135


  Objects scanned . . . : 2.340.866
  Files scanned . . . . : 116.746
  Remnants scanned  . . : 578.455 files / 1.645.665 keys


Malware remnants ____________________________________________________________


  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\ (Trojan.FakeAV) -> Deleted
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\ (Trojan.FakeAV) -> PendingDelete
  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\ (Trojan.FakeAV) -> PendingDelete


Potential Unwanted Programs _________________________________________________


  HKLM\SOFTWARE\Classes\s\ (Softonic) -> Deleted




Link naar reactie
Delen op andere sites

  • Reacties 27
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Download de 51a5c8edc4692-icon1337952077.pngFarbar Recovery Scan Tool 32 of 64 bit van één van de onderstaande links

Farbar Recovery Scan Tool 32 bit (x86)

Farbar Recovery Scan Tool 64 bit (x64)

  • Dubbelklik op FRST.exe om de tool te starten.
  • Als het programma is geopend klik Yes (Ja) bij de disclaimer.
  • Druk op de Scan knop
  • Er zal u een logbestand aangemaakt worden (FRST.txt) op dezelfde plaats vanwaar de 'tool' is gestart.

Logbestanden plaatsen

  • Voeg het logbestand met de naam "FRST.txt" als bijlage toe aan het volgende bericht.
  • Het logbestand met de naam "Addition.txt" wat geminimaliseerd is hoeft u niet te plaatsen, alleen als hierom wordt gevraagd.

Link naar reactie
Delen op andere sites

  • 2 weken later...

Hallo,

Is me niet duidelijk hoe ik dit programma aan de praat krijg. Als ik het goed begrijp is dit geen kickstartprogramma, maar moet ik de exe starten op de geïnfecteerde computer door te dubbelklikken.

Dit terwijl ik geen inhoud van mijn computer kan bekijken of bereiken?

Herstarten en F8 geeft blauw scherm met BOOT info (zie 5 augustus)

Herstarten en F11 geeft Power Recovery scherm.

Wat doe ik fout, waar zit de kink in de kabel?

Link naar reactie
Delen op andere sites

Klik op Start - Alle programma's - Bureau-accessoires.

Rechtsklik op Opdrachtprompt en klik op Als administrator uitvoeren.

Typ in het zwarte venster CHKDSK C: /R en druk op de enter-toets. (let op de spaties!)

Op de vraag "Wilt u dat dit volume wordt gecontroleerd zodra de computer de volgende keer wordt opgestart?" druk op J.

Herstart nu je computer.

Druk tijdens de herstart niet op een toets zodat Schijfcontrole wordt gestart.

Wacht dit geduldig af.

Na de herstart:

Klik op Start - Alle programma's - Bureau-accessoires.

Rechtsklik op Opdrachtprompt en klik op Als administrator uitvoeren.

Typ in het zwarte venster SFC /SCANNOW en druk op de enter-toets. (let op de spatie!)

Als dit klaar is maak je een screenshot en update het naar http://imgdumper.nl.

Post de link die je krijgt in je volgend bericht.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.