Ga naar inhoud

Aanbevolen berichten


Ik had nog een poging gedaan maar na 4 uur bleef hij steken. Zie hieronder.

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Have0 on do 25-08-2016 at 14:11:00,02.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Have0\Desktop\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 13:00:14,94 =====

--- Create Environment Variables 13:00:19,98
--- Checking Input 13:00:45,52
--- Torpig Check 13:02:03,49
--- AU AppData Check 13:02:15,25
--- Remove From Windows Installer 13:02:25,70
--- Registry HKLM Software Check 13:09:39,79
--- Quick Launch Shortcut Check 13:11:44,35
--- IE Startpage Check 13:12:20,87
--- Program Files DB Check 13:15:02,83
--- C:\Users\Default\AppData\Roaming DB Check 13:17:56,62
--- C:\Users\Default User\AppData\Roaming DB Check 13:17:56,62
--- C:\Users\Have0\AppData\Roaming DB Check 13:17:56,62
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 13:17:56,62
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 13:17:56,62
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 13:17:56,62
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 13:17:56,62
--- C:\Users\Have0 DB Check 13:25:53,62
--- C:\PROGRA~3 DB Check 13:27:12,01
--- C:\Users\Default\AppData\Local DB Check 13:28:07,47
--- C:\Users\Default User\AppData\Local DB Check 13:28:07,47
--- C:\Users\Have0\AppData\Local DB Check 13:28:07,47
--- C:\Users\Public\AppData\Local DB Check 13:28:07,47
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 13:28:07,47
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 13:28:07,47
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 13:28:07,47
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 13:28:07,47
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 13:34:22,12
--- C:\Users\Have0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 13:34:58,05
--- Tasks DB Check 13:35:20,53
--- Downloads DB Check 13:35:36,19
--- C:\Users\Have0\AppData\LocalLow DB Check 13:35:55,92
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 13:35:55,92
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 13:35:55,92
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 13:35:55,92
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 13:35:55,92
--- Tasks2 DB Check 13:38:38,35
--- Documents DB Check 13:40:31,82
--- C:\Users\Have0\AppData\Roaming\Mozilla\Firefox\Profiles\93wcg9ro.default-1470143960058 DB Check 13:40:58,36
--- C:\Users\Have0\AppData\Roaming\TomTom\HOME\Profiles\7gfw6mr0.default DB Check 13:40:58,36
--- C:\Users\Public\Desktop DB Check 13:41:15,49
--- C:\Users\Have0\Desktop DB Check 13:41:37,06
--- Services DB Check 13:42:10,28
--- FF prefs.js DB Check 13:44:37,10
--- Del by CLSID 13:49:28,62
--- Delete Services 13:51:54,72
--- Delete files\folders 13:52:03,64
--- Create Backups 13:52:04,09
--- Folders in C:\PROGRA~3 0-6 Months 13:52:23,84
--- Firefox Extensions 13:52:26,84



Beste lezer, ik weet niet zeker of de scan/verwijdering gelukt is ? Ik las pas later goed dat ik de zoek result logs ook handmatig kon opzoeken. Sorry. Zie hieronder.

Ziet iets bijzonders ? Het wisselt nog qua snelheid de p.c. bedoel ik.


Ter info


Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Have0 on do 25-08-2016 at 14:11:00,02.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Have0\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-08-22-125826.log    7080 bytes

==== Torpig Check ======================

HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll

==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

==== Services(whitelist) ======================
Powered by E Dev

R2 - [ABBYY.Licensing.FineReader.Sprint.9.0] - ABBYY FineReader 9.0 Sprint Licensing Service - c:\program files (x86)\common files\abbyy\finereadersprint\9.00\licensing\networklicenseserver.exe
R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe
R2 - [ASLDRService] - ASLDR Service - c:\program files (x86)\asus\atk hotkey\asldrsrv.exe
R2 - [ATKGFNEXSrv] - ATKGFNEX Service - c:\program files\atkgfnex\gfnexsrv.exe
R2 - [avgsvc] - AVG Service - c:\program files (x86)\avg\framework\common\avgsvca.exe
R2 - [avgwd] - AVG WatchDog - c:\program files (x86)\avg\av\avgwdsvca.exe
R2 - [EPSON_PM_RPCV4_04] - EPSON V3 Service4(04) - c:\program files\common files\epson\epw!3 ssrp\e_s50rpb.exe
R2 - [ftnlsv3hv] - VMware Netlink Supervisor Service - c:\program files\common files\vmware\deviceredirectioncommon\ftnlsv.exe
R2 - [ftscanmgr] - VMware Scanner Redirection Client Service - c:\program files (x86)\vmware\scannerredirection\ftscanmgr.exe
R2 - [VMUSBArbService] - VMware USB Arbitration Service - c:\program files (x86)\common files\vmware\usb\vmware-usbarbitrator64.exe
R2 - [vmware-view-usbd] - VMware View USB - c:\program files (x86)\vmware\vmware horizon view client\bin\vmware-view-usbd.exe
R2 - [vmwsprrdpwks] - VMware Serial Com Redirection Client service - c:\program files (x86)\common files\vmware\serialportredirection\client\vmwsprrdpwks.exe
R2 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
R3 - [osppsvc] - Office Software Protection Platform - c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
S2 - [AVGIDSAgent] - AVGIDSAgent - c:\program files (x86)\avg\av\avgidsagenta.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - c:\windows\\framework\v4.0.30319\mscorsvw.exe
S2 - [clr_optimization_v4.0.30319_64] - Microsoft .NET Framework NGEN v4.0.30319_X64 - c:\windows\\framework64\v4.0.30319\mscorsvw.exe
S2 - [SkypeUpdate] - Skype Updater - c:\program files (x86)\skype\updater\updater.exe
S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
S3 - [AvgAMPS] - AvgAMPS - c:\program files (x86)\avg\av\avgamps.exe
S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
S3 - [ehRecvr] - Windows Media Center Receiver Service - c:\windows\ehome\ehrecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - c:\windows\ehome\ehsched.exe
S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache - c:\windows\\framework64\v3.0\wpf\presentationfontcache.exe
S3 - [fsssvc] - Windows Live Family Safety - c:\program files (x86)\windows live\family safety\fsssvc.exe
S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
S3 - [Microsoft SharePoint Workspace Audit Service] - Microsoft SharePoint Workspace Audit Service - c:\program files (x86)\microsoft office\office14\groove.exe
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
S3 - [ose] - Office  Source Engine - c:\program files (x86)\common files\microsoft shared\source engine\ose.exe
S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
S3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
S3 - [WatAdminSvc] - Windows Activation Technologies-service - c:\windows\system32\wat\watadminsvc.exe
S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
S4 - [aspnet_state] - ASP.NET-statusservice - c:\windows\\framework64\v4.0.30319\aspnet_state.exe
S4 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - c:\windows\\framework\v2.0.50727\mscorsvw.exe
S4 - [clr_optimization_v2.0.50727_64] - Microsoft .NET Framework NGEN v2.0.50727_X64 - c:\windows\\framework64\v2.0.50727\mscorsvw.exe
S4 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe

==== Deleting Services ======================

==== Deleting Files \ Folders ======================

==== Folders in C:\PROGRA~3 0-6 Months Old ======================

2016-04-04 17:43:43    --------    dc----w-    C:\PROGRA~3\TomTom
2016-04-25 15:50:51    --------    dc----w-    C:\PROGRA~3\UniqueId
2016-06-17 14:28:49    --------    dc----w-    C:\PROGRA~3\Logishrd
2016-06-17 14:28:52    --------    dc----w-    C:\PROGRA~3\Logitech

==== Firefox Extensions Registry ======================

"{5D3F3872-91E9-4d59-AD9F-AA174A3145DD}"="C:\Program Files\Logitech\FlowScroll\LogiSmoothFirefoxExt" [17-06-2016 16:28]



Goede middag,


Sorry voor het late antwoord, volgens mij gebruik je de aangeboden code niet en start je zoek.exe zonder de code.

Gebruik deze code aub.




Hoi Juisterr, ik weet niet zeker of het nu zo weg gelukt is ? Zie onderstaande logfile.


Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Have0 on di 30-08-2016 at 17:16:36,83.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Have0\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-08-22-125826.log    7080 bytes
C:\zoek-results2016-08-26-115227.log    6696 bytes
C:\zoek-results2016-08-30-125422.log    432 bytes
C:\zoek-results2016-08-30-143630.log    12205 bytes

==== Torpig Check ======================

HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll

==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

==== Services(whitelist) ======================
Powered by E Dev

R2 - [ABBYY.Licensing.FineReader.Sprint.9.0] - ABBYY FineReader 9.0 Sprint Licensing Service - c:\program files (x86)\common files\abbyy\finereadersprint\9.00\licensing\networklicenseserver.exe
R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe
R2 - [ASLDRService] - ASLDR Service - c:\program files (x86)\asus\atk hotkey\asldrsrv.exe
R2 - [ATKGFNEXSrv] - ATKGFNEX Service - c:\program files\atkgfnex\gfnexsrv.exe
R2 - [avgsvc] - AVG Service - c:\program files (x86)\avg\framework\common\avgsvca.exe
R2 - [avgwd] - AVG WatchDog - c:\program files (x86)\avg\av\avgwdsvca.exe
R2 - [EPSON_PM_RPCV4_04] - EPSON V3 Service4(04) - c:\program files\common files\epson\epw!3 ssrp\e_s50rpb.exe
R2 - [ftnlsv3hv] - VMware Netlink Supervisor Service - c:\program files\common files\vmware\deviceredirectioncommon\ftnlsv.exe
R2 - [ftscanmgr] - VMware Scanner Redirection Client Service - c:\program files (x86)\vmware\scannerredirection\ftscanmgr.exe
R2 - [VMUSBArbService] - VMware USB Arbitration Service - c:\program files (x86)\common files\vmware\usb\vmware-usbarbitrator64.exe
R2 - [vmware-view-usbd] - VMware View USB - c:\program files (x86)\vmware\vmware horizon view client\bin\vmware-view-usbd.exe
R2 - [vmwsprrdpwks] - VMware Serial Com Redirection Client service - c:\program files (x86)\common files\vmware\serialportredirection\client\vmwsprrdpwks.exe
R2 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
R3 - [osppsvc] - Office Software Protection Platform - c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
S2 - [AVGIDSAgent] - AVGIDSAgent - c:\program files (x86)\avg\av\avgidsagenta.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - c:\windows\\framework\v4.0.30319\mscorsvw.exe
S2 - [clr_optimization_v4.0.30319_64] - Microsoft .NET Framework NGEN v4.0.30319_X64 - c:\windows\\framework64\v4.0.30319\mscorsvw.exe
S2 - [SkypeUpdate] - Skype Updater - c:\program files (x86)\skype\updater\updater.exe
S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
S3 - [AvgAMPS] - AvgAMPS - c:\program files (x86)\avg\av\avgamps.exe
S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
S3 - [ehRecvr] - Windows Media Center Receiver Service - c:\windows\ehome\ehrecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - c:\windows\ehome\ehsched.exe
S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache - c:\windows\\framework64\v3.0\wpf\presentationfontcache.exe
S3 - [fsssvc] - Windows Live Family Safety - c:\program files (x86)\windows live\family safety\fsssvc.exe
S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
S3 - [Microsoft SharePoint Workspace Audit Service] - Microsoft SharePoint Workspace Audit Service - c:\program files (x86)\microsoft office\office14\groove.exe
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
S3 - [ose] - Office  Source Engine - c:\program files (x86)\common files\microsoft shared\source engine\ose.exe
S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
S3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
S3 - [WatAdminSvc] - Windows Activation Technologies-service - c:\windows\system32\wat\watadminsvc.exe
S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
S4 - [aspnet_state] - ASP.NET-statusservice - c:\windows\\framework64\v4.0.30319\aspnet_state.exe
S4 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - c:\windows\\framework\v2.0.50727\mscorsvw.exe
S4 - [clr_optimization_v2.0.50727_64] - Microsoft .NET Framework NGEN v2.0.50727_X64 - c:\windows\\framework64\v2.0.50727\mscorsvw.exe
S4 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe

==== Deleting Services ======================

==== Deleting Files \ Folders ======================

==== Folders in C:\PROGRA~3 0-6 Months Old ======================

2016-04-04 17:43:43    --------    dc----w-    C:\PROGRA~3\TomTom
2016-04-25 15:50:51    --------    dc----w-    C:\PROGRA~3\UniqueId
2016-06-17 14:28:49    --------    dc----w-    C:\PROGRA~3\Logishrd
2016-06-17 14:28:52    --------    dc----w-    C:\PROGRA~3\Logitech

==== Firefox Extensions Registry ======================

"{5D3F3872-91E9-4d59-AD9F-AA174A3145DD}"="C:\Program Files\Logitech\FlowScroll\LogiSmoothFirefoxExt" [17-06-2016 16:28]



Beste Juisterr, er is zeker een positief verschil merkbaar. Wat kan ik doen om heel log te laten zien ? Ziet u of er veel verwijderd is ? Kan/moet ik nog iets meer doen ?




Met het onderstaande tooltje ruim je o.a. alle gebruikte tools op:

Download 51a5ce45263de-delfix.pngDelfix - Alternatieve downloadlink by Xplode naar het bureaublad.

Dubbelklik op Delfix.exe om de tool te starten.
Zet nu vinkjes voor de volgende items:

  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore

Klik nu op "Run" en wacht geduldig tot de tool gereed is.
Wanneer de tool gereed is wordt er een logbestand aangemaakt. Dit hoeft je echter niet te plaatsen.
Start je pc hierna opnieuw op, mochten er nog programma's of log bestanden aanwezig zijn mag je die handmatig verwijderen.

  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.