trage pc +rare marktplaats

  • DennisAA

    Goedenavond

    heb sinds een paar dagen een trage pc en dat ie de pagina,s ook errug lang moet laden

    ook sinds vanmiddag dat ik een scherm van marktplaats krijg dat ik als admin moet inloggen! ( nog nooit gezien)

    als ik op annuleren druk is t okee

    logjes

    # AdwCleaner v2.300 - Verslag gemaakt op 02/05/2013 om 17:49:37

    # Geactualiseerd op 28/04/2013 door Xplode

    # Besturingssysteem : Microsoft Windows XP Service Pack 3 (32 bits)

    # Gebruiker : Dennis - DENNIS-B7152B1D

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : C:\Documents and Settings\Dennis\Bureaublad\adwcleaner.exe

    # Optie

    ***** *****

    ***** *****

    Map Verwijdert : C:\Documents and Settings\All Users\Application Data\Babylon

    Map Verwijdert : C:\Documents and Settings\Dennis\Application Data\Babylon

    Map Verwijdert : C:\Documents and Settings\Dennis\Application Data\dvdvideosoftiehelpers

    Map Verwijdert : C:\Documents and Settings\Dennis\Local Settings\Application Data\APN

    Map Verwijdert : C:\Documents and Settings\Dennis\Local Settings\Application Data\Conduit

    Map Verwijdert : C:\Program Files\Common Files\DVDVideoSoft\TB

    ***** *****

    Sleutel Verwijdert : HKCU\Software\AppDataLow\Software\Conduit

    Sleutel Verwijdert : HKCU\Software\ConduitSearchScopes

    Sleutel Verwijdert : HKCU\Software\CT2269050

    Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}

    Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}

    Sleutel Verwijdert : HKCU\Software\SmartBar

    Sleutel Verwijdert : HKCU\Software\Softonic

    Sleutel Verwijdert : HKLM\Software\Babylon

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\secman.DLL

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Prod.cap

    Sleutel Verwijdert : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}

    Sleutel Verwijdert : HKLM\Software\Conduit

    Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater

    Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

    Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}

    Sleutel Verwijdert : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966

    Sleutel Verwijdert : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094

    Waarde Verwijdert : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

    Waarde Verwijdert : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

    ***** *****

    -\\ Internet Explorer v8.0.6001.18702

    Het register bevat geen enkele ongeoorloofde invoer.

    -\\ Google Chrome v23.0.1271.64

    File : C:\Documents and Settings\Dennis\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

    Verwijdert : homepage = "hxxp://www.delta-search.com/?affID=119556&babsrc=HP_ss&mntrId=d42078cd00000000000

    Verwijdert : urls_to_restore_on_startup =

    Verwijdert : icon_url = “hxxp://www.delta-search.com/favicon.ico”,

    Verwijdert : keyword = “delta-search.com”,

    Verwijdert : search_url = "hxxp://www.delta-search.com/?q={searchTerms}&affID=119556&babsrc=SP_ss&mntrId=d

    Verwijdert : homepage = "hxxp://www.delta-search.com/?affID=119556&babsrc=HP_ss&mntrId=d42078cd00000000000000

    Verwijdert : urls_to_restore_on_startup =

    *************************

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner.txt - ##########

    Malwarebytes Anti-Malware 1.75.0.1300

    www.malwarebytes.org

    Databaseversie: v2013.05.02.04

    Windows XP Service Pack 3 x86 NTFS

    Internet Explorer 8.0.6001.18702

    Dennis :: DENNIS-B7152B1D

    2-5-2013 17:53:59

    mbam-log-2013-05-02 (17-53-59).txt

    Scan type: Snelle scan

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 233956

    Verstreken tijd: 8 minuut/minuten, 57 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    Logfile of random's system information tool 1.09 (written by random/random)

    Run by Dennis at 2013-05-02 18:12:52

    Microsoft Windows XP Professional Service Pack 3

    System drive C: has 47 GB (61%) free of 76 GB

    Total RAM: 2048 MB (77% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:12:57, on 2-5-2013

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    c:\Program Files\Microsoft Security Client\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Java\jre7\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Documents and Settings\Dennis\Bureaublad\RSIT.exe

    C:\Program Files\trend micro\Dennis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Dennis\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com//activex/ractrl.cab?lmi=972

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe

    End of file - 5002 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

    C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job

    ======Registry dump======

    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    Java™ Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll

    Windows Live Aanmelden - Help - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    “MSC”=c:\Program Files\Microsoft Security Client\msseces.exe

    “ctfmon.exe”=C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe /Manual

    C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe

    C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe

    C:\Program Files\Epson Software\Event Manager\EEventManager.exe

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.EXE

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe

    C:\WINDOWS\system32\dumprep 0 -k

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

    C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

    C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe

    C:\Program Files\Driver-Soft\DriverGenius\StarterW3i.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    “NMIndexingService”=3

    “StarWindServiceAE”=2

    “ose”=3

    “odserv”=3

    “MBAMService”=3

    “JavaQuickStarterService”=2

    “Crypkey License”=2

    “Bonjour Service”=3

    “Apple Mobile Device”=3

    “WMDM PMSP Service”=2

    “AdvancedSystemCareService5”=3

    “PLFlash DeviceIoControl Service”=2

    “Nero BackItUp Scheduler 3”=2

    “WMPNetworkSvc”=3

    “gupdatem”=3

    “gupdate”=3

    “Sony SCSI Helper Service”=3

    “ABBYY.Licensing.FineReader.Sprint.9.0”=2

    “gusvc”=3

    C:\WINDOWS\system32\WgaLogon.dll

    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    “dontdisplaylastusername”=0

    “legalnoticecaption”=

    “legalnoticetext”=

    “shutdownwithoutlogon”=1

    “undockwithoutlogon”=1

    “NoDriveTypeAutoRun”=323

    “”=

    “NoDriveAutoRun”=67108863

    “NoDriveAutoRun”=67108863

    “NoDriveTypeAutoRun”=323

    “%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000”

    “%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019”

    “C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook”

    “C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote”

    “C:\Program Files\Windows Live\Messenger\wlcsdk.exe”=“C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call”

    “C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger”

    “C:\WINDOWS\system32\mmc.exe”=“C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console”

    “C:\Program Files\Epson Software\Event Manager\EEventManager.exe”=“C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application”

    “C:\WINDOWS\system32\muzapp.exe”=“C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player”

    “F:\NewsBin\nbpro.exe”=“F:\NewsBin\nbpro.exe:*:Enabled:NewsBin Pro”

    “C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe”=“C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit”

    “C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour-service”

    “C:\Program Files\Internet Explorer\iexplore.exe”=“C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer”

    “C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe”=“C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software”

    “%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000”

    “%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019”

    “C:\Program Files\Windows Live\Messenger\wlcsdk.exe”=“C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call”

    “C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger”

    “midimapper”=midimap.dll

    “msacm.imaadpcm”=imaadp32.acm

    “msacm.msadpcm”=msadp32.acm

    “msacm.msg711”=msg711.acm

    “msacm.msgsm610”=msgsm32.acm

    “msacm.trspch”=tssoft32.acm

    “vidc.cvid”=iccvid.dll

    “vidc.I420”=msh263.drv

    “vidc.iv31”=ir32_32.dll

    “vidc.iv32”=ir32_32.dll

    “vidc.iv41”=ir41_32.ax

    “vidc.iyuv”=iyuv_32.dll

    “vidc.mrle”=msrle32.dll

    “vidc.msvc”=msvidc32.dll

    “vidc.uyvy”=msyuv.dll

    “vidc.yuy2”=msyuv.dll

    “vidc.yvu9”=tsbyuv.dll

    “vidc.yvyu”=msyuv.dll

    “wavemapper”=msacm32.drv

    “msacm.msg723”=msg723.acm

    “vidc.M263”=msh263.drv

    “vidc.M261”=msh261.drv

    “msacm.msaudio1”=msaud32.acm

    “msacm.sl_anet”=sl_anet.acm

    “msacm.iac2”=C:\WINDOWS\system32\iac25_32.ax

    “vidc.iv50”=ir50_32.dll

    “msacm.l3acm”=C:\WINDOWS\system32\l3codeca.acm

    “msacm.siren”=sirenacm.dll

    “wave”=wdmaud.drv

    “midi”=wdmaud.drv

    “mixer”=wdmaud.drv

    “wave1”=wdmaud.drv

    “midi1”=wdmaud.drv

    “mixer1”=wdmaud.drv

    “vidc.ffds”=ff_vfw.dll

    “vidc.xvid”=xvidvfw.dll

    “vidc.lags”=lagarith.dll

    “msacm.ac3filter”=ac3filter.acm

    “msacm.divxa32”=DivXa32.acm

    “msacm.lameacm”=LameACM.acm

    ======List of files/folders created in the last 1 month======

    2013-05-02 18:12:52 —-D—- C:\Program Files\trend micro

    2013-05-02 18:12:51 —-D—- C:\rsit

    2013-05-02 17:49:37 —-A—- C:\AdwCleaner.txt

    2013-04-10 08:20:04 —-HDC—- C:\WINDOWS\$NtUninstallKB2808735$

    2013-04-10 08:19:54 —-HDC—- C:\WINDOWS\$NtUninstallKB2820917$

    2013-04-10 08:14:16 —-HDC—- C:\WINDOWS\$NtUninstallKB2813345$

    2013-04-10 08:13:43 —-HDC—- C:\WINDOWS\$NtUninstallKB2813170$

    ======List of files/folders modified in the last 1 month======

    2013-05-02 18:12:52 —-RD—- C:\Program Files

    2013-05-02 18:11:45 —-D—- C:\WINDOWS\Prefetch

    2013-05-02 18:09:08 —-D—- C:\WINDOWS\system32\drivers

    2013-05-02 18:01:38 —-SD—- C:\WINDOWS\Tasks

    2013-05-02 17:53:45 —-D—- C:\WINDOWS\Temp

    2013-05-02 17:52:45 —-D—- C:\WINDOWS\system32\CatRoot2

    2013-05-02 17:50:35 —-A—- C:\WINDOWS\SchedLgU.Txt

    2013-05-02 12:46:41 —-SD—- C:\WINDOWS\Downloaded Program Files

    2013-05-02 12:46:40 —-D—- C:\WINDOWS

    2013-05-01 12:11:53 —-SHD—- C:\WINDOWS\Installer

    2013-05-01 12:11:22 —-D—- C:\Config.Msi

    2013-05-01 12:11:21 —-D—- C:\Documents and Settings\All Users\Application Data\Microsoft Help

    2013-04-26 20:52:09 —-D—- C:\Documents and Settings\All Users\Application Data\Skype

    2013-04-26 20:52:05 —-D—- C:\Program Files\Common Files

    2013-04-26 20:52:00 —-D—- C:\Documents and Settings\Dennis\Application Data\Skype

    2013-04-25 20:58:23 —-A—- C:\WINDOWS\NeroDigital.ini

    2013-04-17 20:20:52 —-D—- C:\WINDOWS\Debug

    2013-04-17 20:13:34 —-D—- C:\Program Files\Malwarebytes' Anti-Malware

    2013-04-17 06:53:52 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe

    2013-04-17 06:53:47 —-A—- C:\WINDOWS\system32\FlashPlayerApp.exe

    2013-04-16 17:19:52 —-HD—- C:\WINDOWS\inf

    2013-04-11 18:51:12 —-SD—- C:\Documents and Settings\Dennis\Application Data\Microsoft

    2013-04-10 08:31:37 —-D—- C:\WINDOWS\system32

    2013-04-10 08:31:37 —-D—- C:\Program Files\Internet Explorer

    2013-04-10 08:22:17 —-RSHDC—- C:\WINDOWS\system32\dllcache

    2013-04-10 08:21:21 —-HD—- C:\WINDOWS\$hf_mig$

    2013-04-10 08:14:37 —-A—- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys

    R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys

    R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys

    R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys

    R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys

    R1 AmdK7;Stuurprogramma voor AMD K7-processor; C:\WINDOWS\system32\DRIVERS\amdk7.sys

    R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys

    R1 kbdhid;Stuurprogramma voor toetsenbord-HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys

    R1 NetworkX;NetworkX; C:\WINDOWS\system32\ckldrv.sys

    R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys

    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys

    R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys

    R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys

    R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys

    R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys

    R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys

    R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys

    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

    R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys

    R3 hidusb;Microsoft HID Class-stuurprogramma; C:\WINDOWS\system32\DRIVERS\hidusb.sys

    R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys

    R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys

    R3 mouhid;Stuurprogramma voor muis-HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys

    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

    R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys

    R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys

    R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys

    R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys

    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys

    R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys

    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys

    S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS

    S3 am5klbz1;am5klbz1; C:\WINDOWS\system32\drivers\am5klbz1.sys

    S3 catchme;catchme; C:\WINDOWS\system32\drivers\catchme.sys

    S3 ctljystk;Creative SB Live!-spelpoort; C:\WINDOWS\system32\DRIVERS\ctljystk.sys

    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys

    S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys

    S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys

    S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet-adapter - NT-stuurprogramma; C:\WINDOWS\system32\DRIVERS\fetnd5.sys

    S3 kxwdmdrv;kX WDM Driver Service; C:\WINDOWS\system32\drivers\kx.sys

    S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys

    S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys

    S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys

    S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys

    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys

    S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys

    S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys

    S3 usbccgp;Microsoft generiek hoofd-USB-stuurprogramma; C:\WINDOWS\system32\DRIVERS\usbccgp.sys

    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys

    S3 usbscan;Stuurprogramma voor USB-scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys

    S3 USBSTOR;Stuurprogramma voor USB-massaopslag; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys

    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe

    R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe

    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    S3 aspnet_state;ASP.NET-statusservice; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE

    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

    S4 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

    S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    S4 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe

    S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

    S4 Crypkey License;Crypkey License; C:\WINDOWS\system32\crypserv.exe

    S4 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe

    S4 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe

    S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    S4 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe

    S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

    S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE

    S4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe

    S4 Sony SCSI Helper Service;Sony SCSI Helper Service; C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

    S4 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

    S4 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe

    S4 WMPNetworkSvc;Windows Media Player Network Sharing-service; C:\Program Files\Windows Media Player\WMPNetwk.exe

    —————–EOF—————–

  • Ben

    Hallo,

    Download zoek.exe naar het bureaublad.

    Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe

    (hier of hier) kan je lezen hoe je dat doet.

    * Dubbelklik op Zoek.exe om de tool te starten.

    * Kopieer nu het onderstaande vet gedrukte code en plak die in het grote invulvenster:

    * Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.

    firefoxlook;

    chromelook;

    standardsearch;

    filesrcm;

    autoclean;

    startupall;

    *Klik nu op de knop "Run script".

    * Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    * Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    * Post nu de inhoud van het geopende logje in het volgende bericht.

    Gr.Ben

  • DennisAA

    Hoi Ben

    logje

    Zoek.exe Version 4.0.0.2 Updated 23-04-2013

    Tool run by Dennis on do 02-05-2013 at 19:18:16,25.

    Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86

    Running in: Normal Mode Internet Access Detected

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Running Processes ======================

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    c:\Program Files\Microsoft Security Client\MsMpEng.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Java\jre7\bin\jqs.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\System32\alg.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    C:\WINDOWS\system32\wscntfy.exe

    C:\Documents and Settings\Dennis\Bureaublad\zoek.exe

    C:\WINDOWS\system32\svchost.exe -k DcomLaunch

    C:\WINDOWS\system32\svchost.exe -k rpcss

    C:\WINDOWS\System32\svchost.exe -k netsvcs

    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

    C:\WINDOWS\system32\svchost.exe -k NetworkService

    C:\WINDOWS\system32\svchost.exe -k LocalService

    C:\WINDOWS\system32\svchost.exe -k imgsvc

    ==== System Specs ======================

    Windows: Windows XP Professional Service Pack 3 (Build 2600)

    Internet Explorer: 8.0.6001.18702

    Memory (RAM): 2048 MB

    CPU Info: AMD Athlon(TM) XP 3000+

    CPU Speed: 2161,7 MHz

    Sound Card: SB Live Audio |

    Display Adapters: NVIDIA GeForce4 MX 440 with AGP8X (Microsoft Corporation) | NetMeeting driver | RDPDD Chained DD

    Monitors: 1x; Plug en Play-monitor |

    Screen Resolution: 1280 X 1024 - 32 bit

    Network: Network Present

    Network Adapters: VIA Compatable Fast Ethernet Adapter - Pakketplanner-minipoort

    CD / DVD Drives: 2x (D: | E: | ) D: TSSTcorpCDDVDW SH-S222L | E: HL-DT-STDVD-ROM GDR8162B

    Ports: COM3 | COM4 | COM5 | COM1 LPT1

    Mouse: 5 Button Wheel Mouse Present

    Hard Disks: C: 74,5GB | F: 74,5GB

    Hard Disks - Free: C: 45,7GB | F: 31,1GB

    Manufacturer *: Award Software, Inc.

    BIOS Info: AT/AT COMPATIBLE | 08/06/03 | ASUS - 42302e31

    Time Zone: West-Europa (standaardtijd)

    Motherboard *: ASUSTeK Computer INC. A7V8X-X

    Sun Java version: 1.7.0_17

    Country: Nederland

    Language: NLD

    ==== Files Recently Created / Modified ======================

    ====== C:\WINDOWS ====

    ====== C:\DOCUME~1\Dennis\LOCALS~1\Temp ====

    ====== C:\WINDOWS\system32 =====

    ====== C:\WINDOWS\system32\drivers =====

    ====== C:\WINDOWS\Tasks ======

    ====== C:\WINDOWS\Temp ======

    ======= C:\Program Files =====

    2013-05-02 16:12:52 ——– d—–w- C:\Program Files\trend micro

    ======= C: =====

    2013-05-02 15:49:37 28987078F6EC6AC2230E6406418367F5 5166 —-a-w- C:\AdwCleaner.txt

    ====== C:\Documents and Settings\Dennis\Application Data ======

    2013-04-25 17:12:38 ——– d—–w- C:\Documents and Settings\Dennis\Local Settings\Application Data\WMTools Downloaded Files

    ====== C:\Documents and Settings\Dennis ======

    2013-04-26 18:55:33 ——– d–h–r- C:\Documents and Settings\Dennis\Onlangs geopend

    ====== C: exe-files ==

    2013-05-02 16:12:52 9A2347903D6EDB84C10F288BC0578C1C 388608 —-a-w- C:\Program Files\trend micro\Dennis.exe

    2013-05-02 16:10:53 69CA82A7482A00D8EE063D2B97FC4338 781383 —-a-w- C:\Documents and Settings\Dennis\Bureaublad\RSIT.exe

    2013-05-02 15:47:27 A95866BA166A09E360BB88DA72D4531D 628743 —-a-w- C:\Documents and Settings\Dennis\Bureaublad\adwcleaner.exe

    === C: other files ==

    ==== Startup Registry Enabled ======================

    “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE”

    “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe”

    “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE”

    “MSC”=“c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey”

    “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe”

    ==== Startup Registry Disabled ======================

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“”

    “hkey”=“HKLM”

    “command”=“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“Adobe ARM”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“Advanced SystemCare 5”

    “hkey”=“HKCU”

    “command”=“\”C:\\Program Files\\IObit\\Advanced SystemCare 5\\ASCTray.exe\“ /Manual”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“axcmd”

    “hkey”=“HKCU”

    “command”=“\”C:\\Program Files\\Alcohol Soft\\Alcohol 120\\axcmd.exe\“ /automount”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“APSDaemon”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“EEventManager”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“EPSON SX130 Series”

    “hkey”=“HKCU”

    “command”=“C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIHJE.EXE /FU \”C:\\WINDOWS\\TEMP\\E_S9E.tmp\“ /EF \”HKCU\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”

    “hkey”=“HKCU”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“iTunesHelper”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\iTunes\\iTunesHelper.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“Jet Detection”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“KernelFaultCheck”

    “hkey”=“HKLM”

    “command”=“%systemroot%\\system32\\dumprep 0 -k”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“Malwarebytes' Anti-Malware”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe\“ /starttray”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“NBKeyScan”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\“”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“NeroFilterCheck”

    “hkey”=“HKLM”

    “command”=“C:\\Program Files\\Common Files\\Nero\\Lib\\NeroCheck.exe”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“RIMBBLaunchAgent”

    “hkey”=“HKLM”

    “command”=“C:\\Program Files\\Common Files\\Research In Motion\\USB Drivers\\RIMBBLaunchAgent.exe”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“StarterW3i”

    “hkey”=“HKLM”

    “command”=“C:\\Program Files\\Driver-Soft\\DriverGenius\\StarterW3i.exe”

    “key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“SunJavaUpdateSched”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\“”

    ==== Task Scheduler Jobs ======================

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job –a—— C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job –a—— C:\Program Files\AppleC:oftware Update\SoftwareUpdate.exe

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job –a——

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job –a—— C:\Program Files\Google\Update\GoogleUpdate.exe

    C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job –ah—– C:\Program Files\Microsoft Security Client\MpCmdRun.exe

    ==== Chrome Look ======================

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions

    nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Documents and Settings\Dennis\Application Data\DVDVideoSoft\dvsYoutubeDownload.crx

    YouTube - Dennis - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Dennis - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Gmail - Dennis - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    ==== Set IE to Default ======================

    Old Values:

    “Start Page”=“http://www.google.nl/”

    New Values:

    “Start Page”=“http://www.google.nl/”

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    “DefaultScope”=“{0633EE93-D776-472f-A0FF-E1416B8B2E3A}”

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ieframe.dll,-12512 Url=“http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC”

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url=“http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}”

    ==== HijackThis Entries ======================

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Dennis\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com//activex/ractrl.cab?lmi=972

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe

    ==== Empty IE Cache ======================

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Documents and Settings\Dennis\Local Settings\temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Documents and Settings\Dennis\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    No FireFox Profiles found

    ==== Empty Chrome Cache ======================

    C:\Documents and Settings\Dennis\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    After Reboot

    ==== Empty Temp Folders ======================

    C:\WINDOWS\Temp successfully emptied

    C:\DOCUME~1\Dennis\LOCALS~1\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\RECYCLER successfully emptied

    ==== Deleting Files / Folders ======================

    “C:\Documents and Settings\Dennis\Local Settings\Temporary Internet Files\Content.IE5\index.dat” not deleted

  • Ben

    Hallo,

    Dit ziet er netjes uit, hoe draait de pc nu?

    Gr.Ben

  • DennisAA

    Hoi Ben

    ja draaid beter

    zat er veel rptzooi tussen?

    gr Dennis en thanks

  • Ben

    Hallo,

    Hoofdzakelijk troep wat je vooral via Softonic binnen krijgt.

    Malwarebytes kan je laten staan en één maal in de week (na te hebben geupdate) je pc mee scannen.

    1. De volgende programma's en bijbehorende log bestanden (waaronder ook je mappen en logjes te vinden op C:/ ) mag je verwijderen

    RSIT

    zoek.exe

    AdwCleaner via Deinstallatie functie als je het programma opstart.

    2. Download Ccleaner

    Bij het installeren van de nieuwste Ccleaner wordt nu ook Google Chrome (helaas) mee geinstalleerd.

    Je moet tijdens het installeren een vinkje weg halen, zodat Google Chrome niet geinstalleerd word.

    Installeer CCleaner en start CCleaner op.

    • Klik in de linkse kolom op Cleaner.

    • Klik achtereenvolgens op Analyseren en Opschonen.

    • Klik vervolgens in de linkse kolom op Register en klik op Scan naar problemen.

    • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen en OK.

    • Dan krijg je de vraag om een back-up te maken, klik op JA en kies dan Herstel alle geselecteerde fouten.

    • Sluit hierna CCleaner af.

    En dan is alles weer goed.

    Gr.Ben

  • DennisAA

    Gedaan

    bedankt Ben

    hij mag closed

    gr Dennis,

  • fazantje

    Omdat dit topic is opgelost word het gesloten.

    Wilt U Uw topic als nog weer openen, stuur dan een privé bericht naar Ben of Huib (fazantje).

    Zij zullen dan het “slotje” er van af halen en het topic is weer geopend.

    Het AV team.

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.