SSL-certificaat van Xolphin Powered by Cloud VPS - High Availability Cloud Servers Steun Nucia, doneer!
Resultaten 1 tot 10 van de 10

Onderwerp: virusinfectie?

  1. #1

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326

  2. #2
    Schermafbeelding van Juisterr



    Technische vaardigheid
    5. Expert
    Besturingssysteem
    Windows 7 Home Premium 64 bits
    Antivirus
    AV Defender
    Firewall
    router
    Berichten
    14.573
    Blog Berichten
    10

  3. #3

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326
    Ik heb vermoedelijk een virusinfectie op een windows 7 pc en heb een thread gemaakt in de categorie pc problemen windows 7. Geen reactie dus heb ik het verplaatst naar categorie virusinfecties, ook geen reactie en dan een link naar de regels waarin staat dat onderwerpen verplaatsen niet toegestaan is, tja... Ik zou willen vragen om deze thread in behandeling te nemen http://www.nucia.eu/forum/threads/74602-virusinfectie

  4. #4
    Schermafbeelding van Juisterr



    Technische vaardigheid
    5. Expert
    Besturingssysteem
    Windows 7 Home Premium 64 bits
    Antivirus
    AV Defender
    Firewall
    router
    Berichten
    14.573
    Blog Berichten
    10
    Lezen is een kunst.

    Download de Farbar Recovery Scan Tool 32 of 64 bit van één van de onderstaande links

    Hier staat een beschrijving hoe u kunt kijken of u een 32 of 64 bit versie van Windows heeft.

    Farbar Recovery Scan Tool uitvoeren
    • Dubbelklik op FRST.exe om de tool te starten.
    • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
    • Als het programma is geopend klik Yes (Ja) bij de disclaimer.
    • Druk vervolgens op de Scan knop, er zal nu eerst een back-up van het register worden gemaakt.
    • Wanneer de scan gereed is worden er twee logbestanden aangemaakt met de naam (FRST.txt) & (Addition.txt) op dezelfde plaats vanwaar de 'tool' is gestart.
    • Voeg beide logbestanden als bijlage toe aan het volgende bericht.

  5. #5

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326
    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-10-2017
    Ran by KIDS (administrator) on KIDS-PC (13-10-2017 04:55:14)
    Running from C:\Users\KIDS\Downloads
    Loaded Profiles: KIDS (Available Profiles: KIDS)
    Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    ( ) C:\Windows\System32\dlbkcoms.exe
    (Popcorn Time) C:\Program Files\Popcorn Time\Updater.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
    HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [85600 2013-11-26] (Nullsoft, Inc.)
    HKU\S-1-5-21-541891432-2115559380-3082969310-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-07-14] (Apple Inc.)
    HKU\S-1-5-21-541891432-2115559380-3082969310-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7348440 2017-03-03] (Piriform Ltd)
    HKU\S-1-5-21-541891432-2115559380-3082969310-1000\...\MountPoints2: {29e5588e-9b53-11e7-aca5-7071bc1d425d} - E:\AutoRun.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{FBD7D39D-D3F6-4058-97E9-AEB4CD46494E}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-541891432-2115559380-3082969310-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.be/?gws_rd=ssl
    BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2017-01-03] (Eyeo GmbH)

    FireFox:
    ========
    FF DefaultProfile: vle3utq9.default
    FF ProfilePath: C:\Users\KIDS\AppData\Roaming\Mozilla\Firefox\Profiles\vle3utq9.default [2017-10-13]
    FF Homepage: Mozilla\Firefox\Profiles\vle3utq9.default -> www.google.be
    FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\KIDS\AppData\Roaming\Mozilla\Firefox\Profiles\vle3utq9.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-12]
    FF Extension: (Adblock Plus) - C:\Users\KIDS\AppData\Roaming\Mozilla\Firefox\Profiles\vle3utq9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-08-11]
    FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-29] (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-29] (Google Inc.)
    FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)

    Chrome:
    =======
    CHR Profile: C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default [2017-09-13]
    CHR Extension: (Google Presentaties) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-29]
    CHR Extension: (Google Documenten) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-29]
    CHR Extension: (Google Drive) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-29]
    CHR Extension: (YouTube) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-29]
    CHR Extension: (Google Spreadsheets) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-29]
    CHR Extension: (Offline Documenten) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-08]
    CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-08]
    CHR Extension: (Gmail) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-29]
    CHR Extension: (Chrome Media Router) - C:\Users\KIDS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-08]

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 dlbk_device; C:\Windows\system32\dlbkcoms.exe [537840 2007-06-25] ( )
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3398608 2017-05-09] (Malwarebytes)
    R2 Update service; C:\Program Files\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [221600 2017-10-12] (Malwarebytes)
    S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2016-12-21] (Apple, Inc.) [File not signed]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-10-13 04:55 - 2017-10-13 04:55 - 000007123 _____ C:\Users\KIDS\Downloads\FRST.txt
    2017-10-13 04:55 - 2017-10-13 04:55 - 000000000 ____D C:\FRST
    2017-10-13 04:53 - 2017-10-13 04:53 - 001797632 _____ (Farbar) C:\Users\KIDS\Downloads\FRST.exe
    2017-10-12 03:01 - 2017-10-12 03:01 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
    2017-10-11 19:37 - 2017-09-07 21:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2017-10-11 19:36 - 2017-09-13 17:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
    2017-10-11 19:36 - 2017-09-13 17:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2017-10-11 19:36 - 2017-09-13 17:13 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2017-10-11 19:36 - 2017-09-13 17:13 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2017-10-11 19:36 - 2017-09-13 17:10 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2017-10-11 19:36 - 2017-09-13 17:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2017-10-11 19:36 - 2017-09-13 17:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2017-10-11 19:36 - 2017-09-13 16:53 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
    2017-10-11 19:36 - 2017-09-13 16:50 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2017-10-11 19:36 - 2017-09-13 16:50 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2017-10-11 19:36 - 2017-09-13 16:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2017-10-11 19:36 - 2017-09-13 16:50 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2017-10-11 19:36 - 2017-09-13 16:50 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2017-10-11 19:36 - 2017-09-13 16:48 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2017-10-11 19:36 - 2017-09-13 16:46 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2017-10-11 19:36 - 2017-09-13 16:46 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2017-10-11 19:36 - 2017-09-13 16:46 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2017-10-11 19:36 - 2017-09-13 16:46 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2017-10-11 19:36 - 2017-09-13 16:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2017-10-11 19:36 - 2017-09-13 16:46 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2017-10-11 19:36 - 2017-09-13 16:46 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2017-10-11 19:36 - 2017-09-09 01:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2017-10-11 19:36 - 2017-09-08 17:14 - 001213672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2017-10-11 19:36 - 2017-09-08 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
    2017-10-11 19:36 - 2017-09-08 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
    2017-10-11 19:36 - 2017-09-08 17:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
    2017-10-11 19:36 - 2017-09-08 17:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
    2017-10-11 19:36 - 2017-09-08 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
    2017-10-11 19:36 - 2017-09-08 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
    2017-10-11 19:36 - 2017-09-08 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
    2017-10-11 19:36 - 2017-09-08 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
    2017-10-11 19:36 - 2017-09-08 16:50 - 002402304 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2017-10-11 19:36 - 2017-09-08 16:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll
    2017-10-11 19:36 - 2017-09-08 16:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
    2017-10-11 19:36 - 2017-09-08 16:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll
    2017-10-11 19:36 - 2017-09-07 21:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2017-10-11 19:36 - 2017-09-07 21:26 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2017-10-11 19:36 - 2017-09-07 21:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2017-10-11 19:36 - 2017-09-07 21:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2017-10-11 19:36 - 2017-09-07 21:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2017-10-11 19:36 - 2017-09-07 21:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2017-10-11 19:36 - 2017-09-07 21:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2017-10-11 19:36 - 2017-09-07 21:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2017-10-11 19:36 - 2017-09-07 21:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2017-10-11 19:36 - 2017-09-07 21:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2017-10-11 19:36 - 2017-09-07 20:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2017-10-11 19:36 - 2017-09-07 20:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2017-10-11 19:36 - 2017-09-07 20:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2017-10-11 19:36 - 2017-09-07 20:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2017-10-11 19:36 - 2017-09-07 20:58 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2017-10-11 19:36 - 2017-09-07 20:52 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2017-10-11 19:36 - 2017-09-07 20:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2017-10-11 19:36 - 2017-09-07 20:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
    2017-10-11 19:36 - 2017-09-07 20:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2017-10-11 19:36 - 2017-09-07 20:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
    2017-10-11 19:36 - 2017-09-07 20:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2017-10-11 19:36 - 2017-09-07 20:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2017-10-11 19:36 - 2017-09-07 20:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2017-10-11 19:36 - 2017-09-07 20:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2017-10-11 19:36 - 2017-09-07 20:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2017-10-11 19:36 - 2017-09-07 20:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2017-10-11 19:36 - 2017-09-07 20:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2017-10-11 19:36 - 2017-09-07 20:26 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2017-10-11 19:36 - 2017-09-07 20:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2017-10-11 19:36 - 2017-09-07 20:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2017-10-11 19:36 - 2017-09-07 20:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2017-10-11 19:36 - 2017-09-07 20:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2017-10-11 19:36 - 2017-09-07 19:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2017-10-11 19:36 - 2017-09-07 19:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2017-10-11 19:36 - 2017-09-07 17:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
    2017-10-11 19:36 - 2017-09-07 16:48 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
    2017-10-11 19:36 - 2017-09-07 16:48 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
    2017-10-11 19:36 - 2017-09-07 16:48 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
    2017-10-11 19:36 - 2017-08-19 17:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2017-10-11 19:36 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2017-10-11 19:36 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2017-10-11 19:36 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2017-10-11 19:36 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2017-10-11 19:36 - 2017-08-14 19:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
    2017-10-11 19:36 - 2017-08-14 19:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
    2017-10-11 19:36 - 2017-08-13 23:35 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
    2017-10-11 08:17 - 2017-10-11 08:17 - 000000000 ____D C:\Users\KIDS\Desktop\Amazon.com Sign up for Prime Video_bestanden
    2017-10-11 08:16 - 2017-10-11 08:17 - 000044012 _____ C:\Users\KIDS\Desktop\Amazon.com Sign up for Prime Video.htm
    2017-10-03 07:11 - 2017-10-03 07:11 - 000502392 _____ C:\Users\KIDS\Desktop\oothandel Veiligheidsbril Gallerij - Koop Goedkope Veiligheidsbril Loten op Aliexpress.com.htm
    2017-10-03 07:11 - 2017-10-03 07:11 - 000000000 ____D C:\Users\KIDS\Desktop\oothandel Veiligheidsbril Gallerij - Koop Goedkope Veiligheidsbril Loten op Aliexpress.com_bestanden
    2017-09-27 07:46 - 2017-09-27 07:46 - 000000384 _____ C:\Users\KIDS\Desktop\Delete from Lacie.txt
    2017-09-25 06:39 - 2017-09-25 06:39 - 000000925 _____ C:\Users\Public\Desktop\CDex.lnk
    2017-09-25 06:39 - 2017-09-25 06:39 - 000000000 ____D C:\ProgramData\Package Cache
    2017-09-25 06:39 - 2017-09-25 06:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
    2017-09-25 06:38 - 2017-09-25 06:39 - 000000000 ____D C:\Program Files\CDex
    2017-09-25 06:36 - 2017-09-25 06:37 - 020583777 _____ (CDex) C:\Users\KIDS\Downloads\CDex-1.83.exe
    2017-09-25 06:33 - 2017-10-03 13:34 - 000000819 _____ C:\Users\KIDS\Desktop\klusjes & Steven.txt
    2017-09-23 03:35 - 2017-09-23 03:35 - 000000000 ____D C:\Users\KIDS\.android
    2017-09-23 03:35 - 2017-09-23 03:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZTE Handset USB Driver
    2017-09-23 03:35 - 2017-09-23 03:35 - 000000000 ____D C:\Program Files\ZTE_Handset_USB_Driver
    2017-09-23 03:35 - 2015-09-06 14:22 - 000104088 _____ (Google, inc) C:\Windows\AdbWinApi.dll
    2017-09-23 03:35 - 2015-09-06 14:22 - 000068760 _____ (Google, inc) C:\Windows\AdbWinUsbApi.dll
    2017-09-23 03:35 - 2015-09-06 14:21 - 001017496 _____ C:\Windows\adb.exe
    2017-09-23 03:35 - 2014-03-17 09:59 - 000117960 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsser.sys
    2017-09-23 03:35 - 2013-09-11 14:28 - 000149696 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsnet.sys
    2017-09-23 03:35 - 2012-11-09 15:12 - 000053000 _____ (VIA Telecom) C:\Windows\system32\Drivers\viahsser.sys
    2017-09-23 03:35 - 2012-10-31 16:02 - 000027016 _____ (Via Telecom, Inc.) C:\Windows\system32\Drivers\viahsets.sys
    2017-09-23 03:35 - 2012-06-20 11:51 - 000017672 _____ (HandSet Incorporated) C:\Windows\system32\Drivers\massfilter_hs.sys
    2017-09-21 07:58 - 2017-09-30 03:43 - 000000206 _____ C:\Users\KIDS\Desktop\Cat plylst.txt
    2017-09-13 18:13 - 2017-09-13 18:13 - 000115263 _____ C:\Users\KIDS\Downloads\DPD_labels_11092017_71207131.pdf
    2017-09-13 05:36 - 2017-08-19 17:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
    2017-09-13 05:36 - 2017-08-16 17:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2017-09-13 05:36 - 2017-08-15 17:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2017-09-13 05:36 - 2017-08-15 17:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
    2017-09-13 05:36 - 2017-08-14 19:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
    2017-09-13 05:36 - 2017-08-14 19:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
    2017-09-13 05:36 - 2017-08-14 19:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
    2017-09-13 05:36 - 2017-08-14 19:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
    2017-09-13 05:36 - 2017-08-13 23:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
    2017-09-13 05:36 - 2017-08-11 08:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000781824 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000019968 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 08:10 - 000066048 _____ C:\Windows\system32\PrintBrmUi.exe
    2017-09-13 05:36 - 2017-08-11 08:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
    2017-09-13 05:36 - 2017-08-11 08:09 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
    2017-09-13 05:36 - 2017-08-11 08:09 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
    2017-09-13 05:36 - 2017-08-11 08:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
    2017-09-13 05:36 - 2017-08-11 08:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
    2017-09-13 05:36 - 2017-08-11 07:58 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2017-09-13 05:36 - 2017-08-11 07:55 - 000188928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
    2017-09-13 05:36 - 2017-08-11 07:55 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
    2017-09-13 05:36 - 2017-08-11 07:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 07:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 07:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2017-09-13 05:36 - 2017-08-11 07:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2017-09-13 05:36 - 2017-07-07 17:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-10-12 20:58 - 2009-07-14 06:34 - 000021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2017-10-12 20:58 - 2009-07-14 06:34 - 000021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2017-10-12 07:35 - 2017-08-10 03:05 - 000000000 ____D C:\Users\KIDS\AppData\LocalLow\Mozilla
    2017-10-12 04:00 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
    2017-10-12 03:28 - 2010-11-20 23:01 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
    2017-10-12 03:28 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
    2017-10-12 03:23 - 2017-08-21 20:56 - 000221600 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2017-10-12 03:23 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2017-10-12 03:23 - 2009-07-14 06:33 - 000267248 _____ C:\Windows\system32\FNTCACHE.DAT
    2017-10-12 03:03 - 2017-06-01 10:29 - 000000000 ____D C:\Windows\system32\MRT
    2017-10-12 03:01 - 2017-06-01 10:29 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2017-10-11 08:17 - 2017-06-05 20:28 - 000005959 _____ C:\Users\KIDS\Desktop\MrtnblnS fleshbloodandsoul.txt
    2017-10-11 04:25 - 2017-08-10 03:04 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
    2017-10-11 04:25 - 2017-08-10 03:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2017-10-10 20:26 - 2017-06-04 17:02 - 000000000 ___RD C:\Users\KIDS\Desktop\MUSIC 2017
    2017-10-10 09:30 - 2017-06-04 16:53 - 000000000 ____D C:\ProgramData\Soulseek
    2017-10-07 03:40 - 2017-07-26 03:30 - 000000617 _____ C:\Users\KIDS\Desktop\Kopen.txt
    2017-09-28 21:46 - 2017-06-29 18:42 - 000008015 _____ C:\Users\KIDS\Desktop\boodschappen.txt
    2017-09-27 07:46 - 2017-06-21 12:22 - 000001364 _____ C:\Users\KIDS\Desktop\iPhone.txt
    2017-09-25 07:04 - 2017-07-29 15:54 - 000000051 _____ C:\Users\KIDS\Desktop\Software installeren.txt
    2017-09-25 06:55 - 2017-07-15 12:30 - 000000480 _____ C:\Users\KIDS\Desktop\plylst.txt
    2017-09-23 21:53 - 2017-08-20 01:13 - 000000000 ____D C:\Users\KIDS\Desktop\MUSIC 2013 - 2014 DELETEN WHEN BACKED UP
    2017-09-23 03:35 - 2017-05-29 19:51 - 000000000 ____D C:\Users\KIDS
    2017-09-14 20:40 - 2016-08-21 12:51 - 000001225 _____ C:\Users\KIDS\Desktop\discogs formats.txt

    ==================== Files in the root of some directories =======

    2017-06-21 11:51 - 2017-06-21 11:51 - 000033193 _____ () C:\Users\KIDS\AppData\Roaming\UserTile.png

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-10-10 00:25

    ==================== End of FRST.txt ============================

  6. #6

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326
    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-10-2017
    Ran by KIDS (13-10-2017 04:55:54)
    Running from C:\Users\KIDS\Downloads
    Microsoft Windows 7 Professional Service Pack 1 (X86) (2017-05-29 17:51:37)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-541891432-2115559380-3082969310-500 - Administrator - Disabled)
    Guest (S-1-5-21-541891432-2115559380-3082969310-501 - Limited - Disabled)
    KIDS (S-1-5-21-541891432-2115559380-3082969310-1000 - Administrator - Enabled) => C:\Users\KIDS

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adblock Plus voor IE (32-bit) (HKLM\...\{6467504D-EF07-4BF2-A42A-96D47C50BAFC}) (Version: 1.6 - Eyeo GmbH)
    Apple Application Support (32-bit) (HKLM\...\{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}) (Version: 5.6 - Apple Inc.)
    Apple Software Update (HKLM\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
    Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.)
    CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform)
    CDex - Digital Audio CD Extractor and Converter (HKLM\...\CDex) (Version: 1.83.0.2017 - CDex.mu)
    Google Chrome (HKLM\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
    Google Earth Pro (HKLM\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
    Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
    iCloud (HKLM\...\{AFA154E8-2D57-4789-AB2D-9761E6AC5988}) (Version: 6.2.3.17 - Apple Inc.)
    Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
    Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
    Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation)
    Mozilla Firefox 56.0 (x86 nl) (HKLM\...\Mozilla Firefox 56.0 (x86 nl)) (Version: 56.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.0.6478 - Mozilla)
    msvcrt_installer (HKLM\...\{6068A42A-C1CF-45F2-9859-5DB16287FE5D}) (Version: 1.0.0 - SAH)
    Popcorn Time (HKLM\...\Popcorn Time_is1) (Version: 5.6.1.0 - Popcorn Time) <==== ATTENTION
    Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
    SoulSeek 157 NS 13e (HKLM\...\Soulseek2) (Version: - )
    VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
    Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
    ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version: - ZTE Corporation)
    ZTE Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2104.1.02B08 - ZTE Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll [2017-07-14] (Apple Inc.)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2010-10-16] (Intel Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {119DB1C4-B50A-4199-95A0-FF374ED51DD7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-29] (Google Inc.)
    Task: {2BF65B4D-2FA5-4116-885A-15369ED1D49D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
    Task: {4C225898-5E73-49B3-8A26-787A7947E661} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-29] (Google Inc.)
    Task: {772CC35B-637B-4B9D-9F17-62EA6FD667E5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ShortcutWithArgument: C:\Users\KIDS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5d696d521de238c3\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default

    ==================== Loaded Modules (Whitelisted) ==============

    2017-07-28 20:18 - 2007-02-28 08:49 - 000102400 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\dlbkpp5c.dll
    2017-07-13 20:51 - 2017-07-13 20:51 - 001041720 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2017-05-09 00:45 - 2017-05-09 00:45 - 000080184 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2017-07-13 20:50 - 2017-07-13 20:50 - 000189752 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 04:04 - 2009-06-10 23:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-541891432-2115559380-3082969310-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\KIDS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
    FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
    FirewallRules: [{459AE1AC-158E-4409-9F94-550622F28903}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
    FirewallRules: [{4F94DD98-0B48-4D4A-BFDE-A3984C4331DC}] => (Allow) D:\fscommand\CKSocketServer.exe
    FirewallRules: [{9A998611-5007-4122-837E-91A4E977A28F}] => (Allow) D:\fscommand\CKSocketServer.exe
    FirewallRules: [TCP Query User{6D5D2BEA-BD90-4CD3-8C47-750A86C64AB0}C:\program files\soulseekqt\soulseekqt.exe] => (Allow) C:\program files\soulseekqt\soulseekqt.exe
    FirewallRules: [UDP Query User{35CF728C-C3A0-4A65-A891-E96504E4A640}C:\program files\soulseekqt\soulseekqt.exe] => (Allow) C:\program files\soulseekqt\soulseekqt.exe
    FirewallRules: [TCP Query User{17D58C11-B4CA-40EB-8D5A-F52410658A1F}C:\program files\soulseekns\slsk.exe] => (Allow) C:\program files\soulseekns\slsk.exe
    FirewallRules: [UDP Query User{6EAF5B35-8EB0-43F8-9376-252B00E352B6}C:\program files\soulseekns\slsk.exe] => (Allow) C:\program files\soulseekns\slsk.exe
    FirewallRules: [{DA549BE8-67AC-459E-9D26-D4661F0BBA3A}] => (Block) C:\program files\soulseekns\slsk.exe
    FirewallRules: [{E814BA0D-B771-487B-985A-E7EDBAA53688}] => (Block) C:\program files\soulseekns\slsk.exe
    FirewallRules: [{EBC0C0DD-62AF-4416-B412-B2410442ED07}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{5CD8E2CA-3C9E-4596-9C21-C4560A3F3A4B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{6B15B975-263F-427D-B9BA-FD65E0BC9399}] => (Allow) C:\Windows\System32\dlbkcoms.exe
    FirewallRules: [{6380092D-801C-49F7-B9FC-F81762D8003F}] => (Allow) C:\Windows\System32\dlbkcoms.exe
    FirewallRules: [{12C39886-39CE-4635-AF71-6CB9B8D309B1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{B3BECB59-A52E-4ED8-88B4-E7424687821A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{3E94995A-CDD2-4D7D-BEE4-C4F57E50C4FF}] => (Allow) C:\Program Files\Popcorn Time\Updater.exe
    FirewallRules: [{BB545EDD-D00E-42A0-AC0E-0DD06D379BA5}] => (Allow) C:\Program Files\Popcorn Time\Updater.exe
    FirewallRules: [{B0CA75C4-4A9C-4E3E-AACE-BC9CCAE3DD5F}] => (Allow) C:\Program Files\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{F121907E-800F-4DD1-BE11-C133E7F0E9B1}] => (Allow) C:\Program Files\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{E04C5B82-B468-4965-99C3-F445AE315840}] => (Allow) C:\Program Files\Popcorn Time\chromecast\node.exe
    FirewallRules: [{B5571575-2B1F-43D0-94BD-14988886E766}] => (Allow) C:\Program Files\Popcorn Time\chromecast\node.exe
    FirewallRules: [{0E6B7B32-E234-4AE5-A328-6228DC79B45A}] => (Allow) C:\Program Files\Winamp\winamp.exe
    FirewallRules: [{1B54EEC9-9CC7-45FC-8E31-9F28C85B2B3A}] => (Allow) C:\Program Files\Winamp\winamp.exe
    FirewallRules: [{7A71184C-65C8-40DE-978A-3EA19E75BA65}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

    ==================== Restore Points =========================

    14-09-2017 03:00:16 Windows Update
    19-09-2017 08:35:56 Windows Update
    25-09-2017 06:39:01 Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008
    26-09-2017 06:25:50 Windows Update
    29-09-2017 18:05:25 Windows Update
    03-10-2017 05:56:44 Windows Update
    10-10-2017 05:41:50 Windows Update
    12-10-2017 03:00:30 Windows Update

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (10/12/2017 03:24:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/11/2017 07:29:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/11/2017 04:27:46 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/09/2017 11:18:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/06/2017 04:33:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 34499075

    Error: (10/06/2017 04:33:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 34499075

    Error: (10/06/2017 04:33:53 AM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (10/05/2017 06:20:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/04/2017 12:21:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/03/2017 03:05:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


    System errors:
    =============
    Error: (10/06/2017 07:30:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (09/27/2017 01:27:11 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (09/23/2017 02:52:34 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (09/21/2017 06:35:54 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (09/02/2017 02:25:56 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

    Error: (09/01/2017 11:51:31 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

    Error: (09/01/2017 04:00:33 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (08/30/2017 07:37:02 PM) (Source: Server) (EventID: 2505) (User: )
    Description: The server could not bind to the transport \Device\NetBT_Tcpip_{FBD7D39D-D3F6-4058-97E9-AEB4CD46494E} because another computer on the network has the same name. The server could not start.

    Error: (08/29/2017 01:52:39 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

    Error: (08/25/2017 06:27:27 PM) (Source: Server) (EventID: 2505) (User: )
    Description: The server could not bind to the transport \Device\NetBT_Tcpip_{FBD7D39D-D3F6-4058-97E9-AEB4CD46494E} because another computer on the network has the same name. The server could not start.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM)2 Duo CPU E7500 @ 2.93GHz
    Percentage of memory in use: 63%
    Total physical RAM: 2013.18 MB
    Available physical RAM: 728.88 MB
    Total Virtual: 4026.36 MB
    Available Virtual: 2214.19 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:297.99 GB) (Free:178.73 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: D5736FD6)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

  7. #7

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326
    M'n pc draait eigenlijk best wel goed, ik had wat probleempjes maar dat bleek door AdblockPlus te komen, die uitschakelen en het was opgelost. Even nakijken of er iets opgekuist moet worden kan zeker geen kwaad.

    Met m'n smartphone zijn er ook wat issues denk ik, die is nog vrij nieuw en malwarebytes zegt me dat er een schadelijke app op staat namelijk GO VR (Virtual Reality) die er door de fabrikant op is gezet of zo voorgeprogrammeerd is. Ik heb nog 7dagen mbam pro. Later meer over smartphone.

  8. #8
    Schermafbeelding van Juisterr



    Technische vaardigheid
    5. Expert
    Besturingssysteem
    Windows 7 Home Premium 64 bits
    Antivirus
    AV Defender
    Firewall
    router
    Berichten
    14.573
    Blog Berichten
    10
    Smartphones is heel andere koek hoor, die doe ik niet.

  9. #9

    Technische vaardigheid
    2.
    Besturingssysteem
    Windows 7 Professional 32
    Antivirus
    Avast
    Firewall
    Windows Firewall
    Berichten
    326
    Toch wel straf dat er op een nieuwe smartphone malware geinstalleerd is. Resetten zal nodig zijn. Resultaat van de Farbar scan?

  10. #10
    Schermafbeelding van Juisterr



    Technische vaardigheid
    5. Expert
    Besturingssysteem
    Windows 7 Home Premium 64 bits
    Antivirus
    AV Defender
    Firewall
    router
    Berichten
    14.573
    Blog Berichten
    10
    Resultaat is prima,


    * De gebruikte tools en logbestanden opruimen.
    Download "Delfix by Xplode" hier of hier.

    Start de tool middels dubbelklik.
    Zet nu vinkjes voor de volgende items:
    • Remove disinfection tools
    • Create registry backup

    Klik op Run en wacht geduldig tot de tool gereed is.
    De tool maakt een logbestand. Dit hoeft u niet te plaatsen.

    * Pas op bij het downloaden en installeren van programma's.
    Bestanden downloaden via de website 'softonic.com' en 'cnet.com' kan je beter vermijden aangezien deze vaak voorzien zijn van extra ongewenste software.
    Tijdens het installeren van programma's goed opletten of er extra, onnodige software meegeïnstalleerd wordt, zoals toolbars, extensies, plug-ins of browsers.
    Deze extra software staat standaard aangevinkt en kan je zonder problemen uitvinken.

Forum Rechten

  • Je mag geen nieuwe onderwerpen plaatsen
  • Je mag geen reacties plaatsen
  • Je mag geen bijlagen toevoegen
  • Je mag jouw berichten niet wijzigen
  •