Archief - Trage computer

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

Ignorance:)

Legacy Member
De laatste tijd merk ik dat men computer aanzienlijk trager is geworden.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:23:17, on 18/04/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Combined Community Codec Pack\MPC\mpc-hc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Santiago\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Ask.com - International
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN | Hotmail | Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel meer, dat is MSN !
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN | Hotmail | Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel meer, dat is MSN !
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87775fdb-6972-41f9-ae51-8326e38cb206} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/nl.special-uninstallation-feedback-lsf?lic=TlVIRDQtWUg5UEUtTzNQNEUtUVJERUstR0RKWjctVk9YVUw"&"inst=NzYtMTA3ODExNzMzMy1TVDEyT0krMS1ERFQrMA"&"prod=55"&"ver=2012.0.1913"&"mid=3a82279e5db647d18fb1d168c3bc7db8-48f44cf7e8c23fe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8890 bytes

Juisterr

Legacy Member
Download ComboFix van één van deze locaties:

Link 1
Link 2


* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op.

>>Hier<< kunt u lezen hoe u Combofix dient te gebruiken.




4de6eab6867f3-Combofix.JPG


1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix.

* (hier of hier 2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.
3. Dubbelklik op "Combofix.exe" om de tool te starten.
4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

* Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion." herstart dan de computer.

5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Ignorance:)

Legacy Member
Nieuw logje want is nog steeds traag.Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:41:58, on 7/06/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Users\Santiago\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Users\Santiago\AppData\Roaming\Spotify\spotify.exe
E:\Games\Steam\Steam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Ask.com - International
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN | Hotmail | Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel meer, dat is MSN !
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN | Hotmail | Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel meer, dat is MSN !
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Santiago\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Santiago\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8626 bytes

Juisterr

Legacy Member
Mag ik het combofix logje zien aub. Aan een nieuwe HijackThis log heb ik helemaal niks :puke:

Ignorance:)

Legacy Member
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-10-16 3077528]
"Akamai NetSession Interface"="c:\users\Santiago\AppData\Local\Akamai\netsession_win.exe" [2012-05-07 3331872]
"Spotify Web Helper"="c:\users\Santiago\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-06 932528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-30 257696]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-03-01 130976]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-07 113120]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub; [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Inhoud van de 'Gedeelde Taken' map
.
2012-06-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-18 10:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
"TNOD UP"="c:\program files (x86)\TNod User & Password Finder\TNODUP.exe" [BU]
.
------- Bijkomende Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://eu.ask.com/?l=dis&o=102866&gct=hp
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 195.130.131.131 195.130.130.3
FF - ProfilePath - c:\users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\
FF - prefs.js: browser.startup.homepage - google.be
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B74243e4f-f03b-47b7-ae62-b1b596d7d148%7D&mid=3a82279e5db647d18fb1d168c3bc7db8-48f44cf7e8c23fe274d3afd5621895ea54045adc&ds=AVG&v=10.2.0.3&lang=nl&pr=fr&d=2012-04-10%2012%3A29%3A47&sap=ku&q=
FF - prefs.js: network.proxy.type - 4
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6Oyvu4X7t6&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 0c1b6784000000000000000cf643be6f
FF - user.js: extensions.incredibar_i.hardId - 0c1b6784000000000000000cf643be6f
FF - user.js: extensions.incredibar_i.instlDay - 15410
FF - user.js: extensions.incredibar_i.vrsn - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsni - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.3.2722:01
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6Oyvu4X7t6
FF - user.js: extensions.incredibar_i.upn2n - 92261047817920656
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10595
FF - user.js: extensions.incredibar_i.ppd -
.
- - - - ORPHANS VERWIJDERD - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
AddRemove-Crysis 2.Limited Edition.v 1.9.0.0_is1 - c:\program files (x86)\Crysis 2.Limited Edition.v 1.9.0.0\Uninstall\unins000.exe
AddRemove-Trine 2_is1 - e:\trine 2\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll"
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
.
**************************************************************************
.
Voltooingstijd: 2012-06-10 12:02:17 - machine werd herstart
ComboFix-quarantined-files.txt 2012-06-10 10:02
ComboFix2.txt 2012-04-22 09:45
ComboFix3.txt 2011-05-14 11:29
.
Pre-Run: 29.090.152.448 bytes free
Post-Run: 29.460.320.256 bytes beschikbaar
.
- - End Of File - - 6A360C141EF265E2455EFEC70CDE44FC

Ignorance:)

Legacy Member
Crash dumps are enabled on your computer.


On Tue 12/06/2012 14:47:01 GMT your computer crashed
crash dump file: C:\Windows\Minidump\061212-36332-01.dmp
This was probably caused by the following module: atikmpag.sys (atikmpag+0x8768)
Bugcheck code: 0x116 (0xFFFFFA8003FE14E0, 0xFFFFF88003B63768, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\atikmpag.sys
product: AMD driver
company: Advanced Micro Devices, Inc.
description: AMD multi-vendor Miniport Driver
Bug check description: This indicates that an attempt to reset the display driver and recover from a timeout failed.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: atikmpag.sys (AMD multi-vendor Miniport Driver, Advanced Micro Devices, Inc.).
Google query: atikmpag.sys Advanced Micro Devices, Inc. VIDEO_TDR_ERROR




On Tue 12/06/2012 14:47:01 GMT your computer crashed
crash dump file: C:\Windows\memory.dmp
This was probably caused by the following module: dxgkrnl.sys (dxgkrnl!TdrResetFromTimeout+0x214)
Bugcheck code: 0x116 (0xFFFFFA8003FE14E0, 0xFFFFF88003B63768, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\dxgkrnl.sys
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: DirectX Graphics Kernel
Bug check description: This indicates that an attempt to reset the display driver and recover from a timeout failed.
The crash took place in a standard Microsoft module. Your system configuration may be incorrect. Possibly this problem is caused by another driver on your system which cannot be identified at this time.


On Tue 12/06/2012 13:56:13 GMT your computer crashed
crash dump file: C:\Windows\Minidump\061212-30529-01.dmp
This was probably caused by the following module: watchdog.sys (watchdog+0x122F)
Bugcheck code: 0x119 (0x1, 0x4048, 0x404A, 0x4049)
Error: VIDEO_SCHEDULER_INTERNAL_ERROR
file path: C:\Windows\system32\drivers\watchdog.sys
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: Watchdog Driver
Bug check description: This indicates that the video scheduler has detected a fatal violation.
The crash took place in a standard Microsoft module. Your system configuration may be incorrect. Possibly this problem is caused by another driver on your system which cannot be identified at this time.


On Fri 8/06/2012 18:17:03 GMT your computer crashed
crash dump file: C:\Windows\Minidump\060812-41574-01.dmp
This was probably caused by the following module: watchdog.sys (watchdog+0x122F)
Bugcheck code: 0x119 (0x1, 0x4E, 0x52, 0x51)
Error: VIDEO_SCHEDULER_INTERNAL_ERROR
file path: C:\Windows\system32\drivers\watchdog.sys
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: Watchdog Driver
Bug check description: This indicates that the video scheduler has detected a fatal violation.
The crash took place in a standard Microsoft module. Your system configuration may be incorrect. Possibly this problem is caused by another driver on your system which cannot be identified at this time.


On Sun 6/05/2012 14:25:19 GMT your computer crashed
crash dump file: C:\Windows\Minidump\050612-29281-01.dmp
This was probably caused by the following module: atikmpag.sys (atikmpag+0x7AE4)
Bugcheck code: 0x116 (0xFFFFFA80062AD010, 0xFFFFF88003E07AE4, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\atikmpag.sys
product: AMD driver
company: Advanced Micro Devices, Inc.
description: AMD multi-vendor Miniport Driver
Bug check description: This indicates that an attempt to reset the display driver and recover from a timeout failed.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: atikmpag.sys (AMD multi-vendor Miniport Driver, Advanced Micro Devices, Inc.).
Google query: atikmpag.sys Advanced Micro Devices, Inc. VIDEO_TDR_ERROR




On Tue 1/05/2012 16:00:43 GMT your computer crashed
crash dump file: C:\Windows\Minidump\050112-31356-01.dmp
This was probably caused by the following module: atikmpag.sys (atikmpag+0x7AE4)
Bugcheck code: 0x116 (0xFFFFFA8006281420, 0xFFFFF88003E72AE4, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\atikmpag.sys
product: AMD driver
company: Advanced Micro Devices, Inc.
description: AMD multi-vendor Miniport Driver
Bug check description: This indicates that an attempt to reset the display driver and recover from a timeout failed.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: atikmpag.sys (AMD multi-vendor Miniport Driver, Advanced Micro Devices, Inc.).
Google query: atikmpag.sys Advanced Micro Devices, Inc. VIDEO_TDR_ERROR

Logje van whocrashed omdat de computer veel crasht, er komt altijd "deze beeldscherm werkte niet en is hersteld".
Blue screens net hetzelfde zoals je ziet.
Het is een 3dkaart die ook een goede maand geleden op deze forum heb gekocht.
Drivers heb ik al opnieuw geinstalleerd.

Ignorance:)

Legacy Member
Een deeltje er van.
ComboFix 12-06-09.02 - Santiago 10/06/2012 11:50:11.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.32.1033.18.4095.2863 [GMT 2:00]
Gestart vanuit: c:\users\Santiago\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-05-10 to 2012-06-10 ))))))))))))))))))))))))))))))
.
.
2012-06-10 09:54 . 2012-06-10 09:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-06-10 09:54 . 2012-06-10 09:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-08 18:23 . 2012-06-08 18:23 -------- d-----w- c:\programdata\ATI
2012-06-08 18:22 . 2012-06-08 18:22 -------- d-----w- c:\program files (x86)\AMD AVT
2012-06-08 18:22 . 2012-06-08 18:22 -------- d-----w- c:\program files (x86)\AMD APP
2012-06-08 18:22 . 2012-06-08 18:22 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-06-08 18:22 . 2012-06-08 18:22 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-06-08 18:20 . 2012-06-08 18:20 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-06-08 18:20 . 2012-06-08 18:22 -------- d-----w- c:\program files\ATI Technologies
2012-06-08 18:20 . 2012-06-08 18:20 -------- d-----w- c:\program files\ATI
2012-06-08 11:14 . 2012-05-14 23:41 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F6963BFF-20BC-416F-90A8-9A83108E5B3E}\mpengine.dll
2012-06-07 14:40 . 2012-06-07 14:40 388096 ----a-r- c:\users\Santiago\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-07 14:40 . 2012-06-07 14:40 -------- d-----w- c:\program files (x86)\Trend Micro
2012-06-07 12:05 . 2012-06-07 12:05 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-07 12:05 . 2012-06-07 12:05 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-04 19:05 . 2012-06-04 19:05 -------- d-----w- c:\programdata\Rockstar Games
2012-06-04 18:51 . 2012-06-04 18:51 -------- d-----w- c:\users\Santiago\AppData\Local\Chromium
2012-06-04 18:50 . 2012-06-04 18:50 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-06-04 18:49 . 2008-10-15 04:22 5631312 ----a-w- c:\windows\system32\D3DX9_40.dll
2012-06-04 18:49 . 2008-10-15 04:22 519000 ----a-w- c:\windows\system32\d3dx10_40.dll
2012-06-04 18:49 . 2008-10-15 04:22 452440 ----a-w- c:\windows\SysWow64\d3dx10_40.dll
2012-06-04 18:49 . 2008-10-15 04:22 2605920 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2012-06-04 18:49 . 2008-10-15 04:22 2036576 ----a-w- c:\windows\SysWow64\D3DCompiler_40.dll
2012-06-04 18:20 . 2012-06-04 18:20 -------- d-----w- c:\program files (x86)\Elaborate Bytes
2012-06-02 18:27 . 2012-06-07 15:39 -------- d-----w- c:\program files (x86)\Diablo III
2012-06-02 18:26 . 2012-06-02 18:26 -------- d-----w- c:\programdata\Battle.net
2012-05-13 12:27 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll
2012-05-13 12:27 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-05-13 12:26 . 2012-03-31 06:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-13 12:26 . 2012-03-31 03:10 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-05-13 12:26 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-13 12:26 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-13 12:26 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-13 12:26 . 2012-03-30 11:35 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-13 12:26 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-05-13 12:26 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-13 12:26 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-05-13 12:26 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-05-13 12:26 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-30 10:31 . 2012-04-18 18:09 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-30 10:31 . 2011-06-10 16:29 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 10:05 . 2012-05-05 10:05 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-06 05:22 . 2012-04-06 05:22 11174400 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-04-06 02:22 . 2012-04-06 02:22 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2012-04-06 02:21 . 2012-03-09 05:16 909312 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-04-06 02:20 . 2012-04-06 02:20 1067520 ----a-w- c:\windows\system32\aticfx64.dll
2012-04-06 02:16 . 2012-04-06 02:16 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-04-06 02:16 . 2012-04-06 02:16 503808 ----a-w- c:\windows\system32\atieclxx.exe
2012-04-06 02:16 . 2012-04-06 02:16 236544 ----a-w- c:\windows\system32\atiesrxx.exe
2012-04-06 02:14 . 2012-04-06 02:14 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-04-06 02:14 . 2012-04-06 02:14 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-04-06 02:14 . 2012-04-06 02:14 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-04-06 02:14 . 2012-04-06 02:14 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-04-06 02:13 . 2012-03-09 05:04 6800896 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-04-06 02:10 . 2012-04-06 02:10 26181632 ----a-w- c:\windows\system32\atio6axx.dll
2012-04-06 02:00 . 2011-07-08 02:54 64000 ----a-w- c:\windows\system32\coinst.dll
2012-04-06 01:54 . 2012-04-06 01:54 7479296 ----a-w- c:\windows\system32\atidxx64.dll
2012-04-06 01:50 . 2012-04-06 01:50 19753984 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-04-06 01:35 . 2012-04-06 01:35 1120768 ----a-w- c:\windows\system32\atiumd6v.dll
2012-04-06 01:34 . 2012-04-06 01:34 1831424 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2012-04-06 01:34 . 2012-04-06 01:34 4731904 ----a-w- c:\windows\system32\atiumd6a.dll
2012-04-06 01:34 . 2012-04-06 01:34 6203392 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-04-06 01:30 . 2012-04-06 01:30 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-04-06 01:30 . 2012-04-06 01:30 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-04-06 01:30 . 2012-04-06 01:30 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-04-06 01:30 . 2012-04-06 01:30 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-04-06 01:29 . 2012-04-06 01:29 16090624 ----a-w- c:\windows\system32\aticaldd64.dll
2012-04-06 01:25 . 2012-04-06 01:25 13764096 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-04-06 01:23 . 2012-04-06 01:23 7431680 ----a-w- c:\windows\system32\atiumd64.dll
2012-04-06 01:22 . 2012-04-06 01:22 4795904 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-04-06 01:11 . 2012-04-06 01:11 514560 ----a-w- c:\windows\system32\atiadlxx.dll
2012-04-06 01:11 . 2012-04-06 01:11 360448 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-04-06 01:11 . 2012-04-06 01:11 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2012-04-06 01:11 . 2012-04-06 01:11 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-04-06 01:11 . 2012-04-06 01:11 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-04-06 01:11 . 2012-04-06 01:11 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-04-06 01:10 . 2012-04-06 01:10 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-04-06 01:10 . 2012-04-06 01:10 343040 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-04-06 01:09 . 2012-04-06 01:09 54784 ----a-w- c:\windows\system32\atiuxp64.dll
2012-04-06 01:09 . 2012-03-09 03:56 41984 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-04-06 01:09 . 2012-04-06 01:09 44544 ----a-w- c:\windows\system32\atiu9p64.dll
2012-04-06 01:09 . 2012-04-06 01:09 32256 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-04-06 01:09 . 2012-04-06 01:09 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-04-06 01:06 . 2012-04-06 01:06 54784 ----a-w- c:\windows\system32\atimpc64.dll
2012-04-06 01:06 . 2012-04-06 01:06 54784 ----a-w- c:\windows\system32\amdpcom64.dll
2012-04-06 01:06 . 2012-04-06 01:06 53760 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-04-06 01:06 . 2012-04-06 01:06 53760 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-04-05 20:34 . 2012-04-05 20:34 187392 ----a-w- c:\windows\system32\clinfo.exe
2012-04-05 20:34 . 2012-04-05 20:34 74752 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-04-05 20:34 . 2012-04-05 20:34 64512 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-04-05 20:33 . 2012-04-05 20:33 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-04-05 20:33 . 2012-04-05 20:33 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-04-05 20:33 . 2012-04-05 20:33 16457216 ----a-w- c:\windows\system32\amdocl64.dll
2012-04-05 20:32 . 2012-04-05 20:32 13007872 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-04-04 13:56 . 2012-03-11 19:43 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2012-01-02 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2012-01-02 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-04-22_09.42.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-05-28 18:03 . 2010-06-02 02:55 74072 c:\windows\SysWOW64\XAPOFX1_5.dll
+ 2012-05-28 18:03 . 2009-09-04 15:44 69464 c:\windows\SysWOW64\XAPOFX1_3.dll
+ 2012-05-28 18:03 . 2008-10-27 08:04 70992 c:\windows\SysWOW64\XAPOFX1_2.dll
+ 2012-05-28 18:03 . 2008-07-31 08:41 68616 c:\windows\SysWOW64\XAPOFX1_1.dll
+ 2012-05-28 18:03 . 2009-03-16 12:18 22360 c:\windows\SysWOW64\X3DAudio1_6.dll
+ 2012-05-28 18:03 . 2008-10-27 08:04 23376 c:\windows\SysWOW64\X3DAudio1_5.dll
+ 2012-03-09 12:06 . 2012-03-09 12:06 24576 c:\windows\SysWOW64\kdbsdk32.dll
+ 2011-03-07 02:08 . 2011-03-07 02:08 93552 c:\windows\SysWOW64\ElbyCDIO.dll
+ 2009-07-14 04:54 . 2012-05-05 10:05 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-04-18 17:21 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-04-18 17:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-05 10:05 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-05 10:05 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-18 17:21 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-05-28 18:03 . 2010-06-02 02:55 77656 c:\windows\system32\XAPOFX1_5.dll
+ 2012-05-28 18:03 . 2010-02-04 08:01 78680 c:\windows\system32\XAPOFX1_4.dll
+ 2012-05-28 18:03 . 2009-09-04 15:44 73544 c:\windows\system32\XAPOFX1_3.dll
+ 2012-05-28 18:03 . 2008-10-27 08:04 74576 c:\windows\system32\XAPOFX1_2.dll
+ 2012-05-28 18:03 . 2008-07-31 08:41 72200 c:\windows\system32\XAPOFX1_1.dll
+ 2012-05-28 18:03 . 2010-02-04 08:01 24920 c:\windows\system32\X3DAudio1_7.dll
+ 2012-05-28 18:03 . 2009-03-16 12:18 24920 c:\windows\system32\X3DAudio1_6.dll
+ 2012-05-28 18:03 . 2008-10-27 08:04 25936 c:\windows\system32\X3DAudio1_5.dll
+ 2011-06-10 18:17 . 2012-06-10 10:00 55628 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-10 10:00 41906 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-06-10 16:19 . 2012-06-10 10:00 18236 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1876595635-2455843533-2650864247-1001_UserData.bin
+ 2012-03-09 12:07 . 2012-03-09 12:07 29184 c:\windows\system32\kdbsdk64.dll
- 2009-07-14 05:30 . 2012-04-10 12:09 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2012-06-08 18:21 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2011-01-15 16:21 . 2011-01-15 16:21 36352 c:\windows\system32\DriverStore\FileRepository\vclone.inf_amd64_neutral_90052917d000700d\Vista64\VClone.sys
+ 2012-04-06 02:00 . 2012-04-06 02:00 64000 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\coinst.dll
+ 2012-04-06 01:09 . 2012-04-06 01:09 41984 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiuxpag.dll
+ 2012-04-06 01:09 . 2012-04-06 01:09 54784 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiuxp64.dll
+ 2012-04-06 01:09 . 2012-04-06 01:09 32256 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiu9pag.dll
+ 2012-04-06 01:09 . 2012-04-06 01:09 44544 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiu9p64.dll
+ 2012-04-06 01:16 . 2012-04-06 01:16 72704 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atisamu64.dll
+ 2012-04-06 01:16 . 2012-04-06 01:16 67584 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atisamu32.dll
+ 2009-06-22 15:34 . 2009-06-22 15:34 51200 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\ATIODCLI.exe
+ 2012-04-06 02:14 . 2012-04-06 02:14 21504 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atimuixx.dll
+ 2012-04-06 01:06 . 2012-04-06 01:06 54784 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atimpc64.dll
+ 2012-04-06 01:06 . 2012-04-06 01:06 53760 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atimpc32.dll
+ 2012-04-06 01:11 . 2012-04-06 01:11 14848 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiglpxx.dll
+ 2012-04-06 01:10 . 2012-04-06 01:10 33280 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atigktxx.dll
+ 2012-04-06 01:11 . 2012-04-06 01:11 41984 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atig6txx.dll
+ 2012-04-06 01:11 . 2012-04-06 01:11 17408 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atig6pxx.dll
+ 2012-04-06 02:14 . 2012-04-06 02:14 59392 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\atiedu64.dll
+ 2012-04-06 01:30 . 2012-04-06 01:30 51200 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\aticalrt64.dll
+ 2012-04-06 01:30 . 2012-04-06 01:30 46080 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\aticalrt.dll
+ 2012-04-06 01:30 . 2012-04-06 01:30 44544 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\aticalcl64.dll
+ 2012-04-06 01:30 . 2012-04-06 01:30 44032 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\aticalcl.dll
+ 2012-04-06 01:09 . 2012-04-06 01:09 53248 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\ati2erec.dll
+ 2012-04-06 02:14 . 2012-04-06 02:14 43520 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\ati2edxx.dll
+ 2012-04-06 01:17 . 2012-04-06 01:17 71680 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\amdave64.dll
+ 2012-04-06 01:16 . 2012-04-06 01:16 72704 c:\windows\system32\DriverStore\FileRepository\c7137813.inf_amd64_neutral_320292ee1f7728c6\B136646\amdave32.dll
+ 2012-02-23 12:32 . 2012-02-23 12:32 95760 c:\windows\system32\DriverStore\FileRepository\atihdw76.inf_amd64_neutral_d30a2bac5901760e\AtihdW76.sys
+ 2011-01-15 16:21 . 2011-01-15 16:21 36352 c:\windows\system32\drivers\VClone.sys
+ 2010-12-16 22:58 . 2010-12-16 22:58 40816 c:\windows\system32\drivers\ElbyCDIO.sys
+ 2012-02-23 12:32 . 2012-02-23 12:32 95760 c:\windows\system32\drivers\AtihdW76.sys
- 2011-06-10 15:32 . 2012-04-21 11:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-10 15:32 . 2012-06-05 18:40 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-10 15:32 . 2012-06-05 18:40 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-06-10 15:32 . 2012-04-21 11:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-21 11:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-05 18:40 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-06-10 15:41 . 2012-04-22 09:30 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-10 15:41 . 2012-06-10 09:57 16384

Juisterr

Legacy Member
Opmerking:Vista of Windows 7 ? >> Alle tools steeds uitvoeren als admin.
Download AdwCleaner by Xplode naar je Bureaublad
Start AdwCleaner en klik Search
Na enige tijd opent een logfile (C:\ AdwCleaner[xx].txt) post de inhoud hier in het Forum

Ignorance:)

Legacy Member
# AdwCleaner v1.609 - Logfile created 06/14/2012 at 20:16:08
# Updated 10/06/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Santiago - SANTIAGO-PC
# Running from : C:\Users\Santiago\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Santiago\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Santiago\AppData\LocalLow\Conduit
Folder Found : C:\Users\Santiago\AppData\LocalLow\PriceGong
Folder Found : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\Conduit
Folder Found : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\ConduitCommon
Folder Found : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\extensions\[email protected]
Folder Found : C:\Program Files (x86)\Common Files\spigot
File Found : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\searchplugins\Askcom.xml
File Found : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\searchplugins\MyStart Search.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml

***** [Registry] *****

[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2865317
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[x64] Key Found : HKCU\Software\IM
[x64] Key Found : HKCU\Software\ImInstaller
[x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong
[x64] Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=102866&gct=hp

-\\ Mozilla Firefox v13.0 (nl)

Profile name : default
File : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\prefs.js

Found : user_pref("CT2865317..clientLogIsEnabled", true);
Found : user_pref("CT2865317..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2865317..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2865317.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2865317.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2865317.AppTrackingLastCheckTime", "Fri Sep 23 2011 19:48:52 GMT+0200 (Romance (zomerti[...]
Found : user_pref("CT2865317.CTID", "CT2865317");
Found : user_pref("CT2865317.CurrentServerDate", "25-11-2011");
Found : user_pref("CT2865317.DialogsAlignMode", "LTR");
Found : user_pref("CT2865317.DialogsGetterLastCheckTime", "Thu Nov 24 2011 18:33:03 GMT+0100 (Romance (stand[...]
Found : user_pref("CT2865317.DownloadReferralCookieData", "");
Found : user_pref("CT2865317.EMailNotifierPollDate", "Thu Nov 24 2011 23:28:02 GMT+0100 (Romance (standaardt[...]
Found : user_pref("CT2865317.FeedLastCount5397019970362056034", 501);
Found : user_pref("CT2865317.FeedPollDate2429156812186649977", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813040823546", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813130095866", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813224203613", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813230837251", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813454291735", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813729834876", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156813860870021", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156814264681793", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156814863075366", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedPollDate2429156815257761081", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.FeedTTL2429156813040823546", 15);
Found : user_pref("CT2865317.FeedTTL2429156813130095866", 10);
Found : user_pref("CT2865317.FeedTTL2429156813454291735", 5);
Found : user_pref("CT2865317.FeedTTL2429156814264681793", 5);
Found : user_pref("CT2865317.FirstServerDate", "10-6-2011");
Found : user_pref("CT2865317.FirstTime", true);
Found : user_pref("CT2865317.FirstTimeFF3", true);
Found : user_pref("CT2865317.FixPageNotFoundErrors", false);
Found : user_pref("CT2865317.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2865317.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2865317.HasUserGlobalKeys", true);
Found : user_pref("CT2865317.HomePageProtectorEnabled", false);
Found : user_pref("CT2865317.Initialize", true);
Found : user_pref("CT2865317.InitializeCommonPrefs", true);
Found : user_pref("CT2865317.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2865317.InstallationType", "UnknownIntegration");
Found : user_pref("CT2865317.InstalledDate", "Fri Jun 10 2011 21:23:23 GMT+0200 (Romance (zomertijd))");
Found : user_pref("CT2865317.IsAlertDBUpdated", true);
Found : user_pref("CT2865317.IsGrouping", false);
Found : user_pref("CT2865317.IsMulticommunity", false);
Found : user_pref("CT2865317.IsOpenThankYouPage", true);
Found : user_pref("CT2865317.IsOpenUninstallPage", false);
Found : user_pref("CT2865317.LanguagePackLastCheckTime", "Thu Nov 24 2011 18:32:58 GMT+0100 (Romance (standa[...]
Found : user_pref("CT2865317.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2865317.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2865317.LastLogin_3.3.3.2", "Thu Jul 07 2011 11:17:30 GMT+0200 (Romance (zomertijd))");
Found : user_pref("CT2865317.LastLogin_3.5.0.12", "Mon Aug 15 2011 22:48:36 GMT+0200 (Romance (zomertijd))")[...]
Found : user_pref("CT2865317.LastLogin_3.6.0.10", "Thu Sep 22 2011 20:00:16 GMT+0200 (Romance (zomertijd))")[...]
Found : user_pref("CT2865317.LastLogin_3.7.0.6", "Thu Nov 10 2011 00:08:11 GMT+0100 (Romance (standaardtijd)[...]
Found : user_pref("CT2865317.LastLogin_3.8.0.8", "Thu Nov 24 2011 22:33:01 GMT+0100 (Romance (standaardtijd)[...]
Found : user_pref("CT2865317.LatestVersion", "3.8.0.8");
Found : user_pref("CT2865317.Locale", "nl");
Found : user_pref("CT2865317.MCDetectTooltipHeight", "83");
Found : user_pref("CT2865317.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2865317.MCDetectTooltipWidth", "295");
Found : user_pref("CT2865317.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2865317.SearchBoxWidth", 148);
Found : user_pref("CT2865317.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Found : user_pref("CT2865317.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2865317.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT286[...]
Found : user_pref("CT2865317.SearchInNewTabEnabled", true);
Found : user_pref("CT2865317.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2865317.SearchInNewTabLastCheckTime", "Thu Nov 24 2011 18:32:56 GMT+0100 (Romance (stan[...]
Found : user_pref("CT2865317.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2865317.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Found : user_pref("CT2865317.SearchProtectorEnabled", false);
Found : user_pref("CT2865317.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT2865317.ServiceMapLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (Romance (standaar[...]
Found : user_pref("CT2865317.SettingsLastCheckTime", "Thu Nov 24 2011 18:32:56 GMT+0100 (Romance (standaardt[...]
Found : user_pref("CT2865317.SettingsLastUpdate", "1321973127");
Found : user_pref("CT2865317.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2865317.ThirdPartyComponentsLastCheck", "Sat Nov 12 2011 10:52:16 GMT+0100 (Romance (st[...]
Found : user_pref("CT2865317.ThirdPartyComponentsLastUpdate", "1256026239");
Found : user_pref("CT2865317.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2865317.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2865317");
Found : user_pref("CT2865317.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2865317.UserID", "UN54127799129869083");
Found : user_pref("CT2865317.ValidationData_Search", 2);
Found : user_pref("CT2865317.ValidationData_Toolbar", 2);
Found : user_pref("CT2865317.WeatherNetwork", "");
Found : user_pref("CT2865317.WeatherPollDate", "Thu Nov 24 2011 23:03:06 GMT+0100 (Romance (standaardtijd))"[...]
Found : user_pref("CT2865317.WeatherUnit", "C");
Found : user_pref("CT2865317.alertChannelId", "1257316");
Found : user_pref("CT2865317.backendstorage.cbfirsttime", "546875204E6F7620323420323031312031383A33333A30322[...]
Found : user_pref("CT2865317.backendstorage.enableinj", "");
Found : user_pref("CT2865317.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Found : user_pref("CT2865317.backendstorage.url_history", "687474703A2F2F7868616D737465722E636F6D2F757365722[...]
Found : user_pref("CT2865317.backendstorage.url_history_time", "31333232313537353339353736");
Found : user_pref("CT2865317.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2865317.globalFirstTimeInfoLastCheckTime", "Thu Nov 24 2011 22:32:59 GMT+0100 (Romance [...]
Found : user_pref("CT2865317.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2865317.initDone", true);
Found : user_pref("CT2865317.isAppTrackingManagerOn", true);
Found : user_pref("CT2865317.myStuffEnabled", true);
Found : user_pref("CT2865317.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2865317.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2865317.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2865317.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2865317.oldAppsList", "129363015615025603,129363015615338104,1000234,129363015615494356[...]
Found : user_pref("CT2865317.revertSettingsEnabled", true);
Found : user_pref("CT2865317.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2865317.searchProtectorEnableByLogin", true);
Found : user_pref("CT2865317.testingCtid", "");
Found : user_pref("CT2865317.toolbarAppMetaDataLastCheckTime", "Thu Nov 24 2011 18:32:58 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.toolbarContextMenuLastCheckTime", "Sat Nov 12 2011 18:59:27 GMT+0100 (Romance ([...]
Found : user_pref("CT2865317.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1257316/1252989/BE", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/BE", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2865317", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2865317",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2865317&octid=[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2865317/CT2865317[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=nl", "\"1ec[...]
Found : user_pref("CommunityToolbar.EngineOwner", "");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{87775fdb-6972-41f9-ae51-8326e38cb206}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar_nl");
Found : user_pref("CommunityToolbar.IsEngineShown", true);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Santiago\\AppData\\Roaming\\Mozilla[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Found : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://cdn.triplegames.com/shared/apps/gamearcad[...]
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2865317");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{87775fdb-6972-41f9-ae51-8326e38cb206}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar_nl");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2865317");
Found : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2865317");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Jun 10 2011 21:23:25 GMT+02[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Jul 07 2011 11:17:38 GMT+0200 (Roman[...]
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Jul 07 2011 11:17:30 GMT+0200 (Romance ([...]
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "972f69a3-3590-4e31-9647-c77e470e4bba");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (Rom[...]
Found : user_pref("CommunityToolbar.globalUserId", "766cd580-33de-471b-b459-5f590c63e658");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.killedEngine", true);
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Nov 20 2011 19:30:4[...]
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 24 2011 18:33:05 GMT+010[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (R[...]
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "02498136-fb07-4fca-b871-c07bcbbd09e5");
Found : user_pref("CommunityToolbar.undefined", "");
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("extensions.enabledAddons", "[email protected]:1.5.0,{73a6fe31-595d-460b-a920-fcc0f88[...]
Found : user_pref("extensions.incredibar.actvtyRptTime", "1339682226974");
Found : user_pref("extensions.incredibar.admin", false);
Found : user_pref("extensions.incredibar.aflt", "orgnl");
Found : user_pref("extensions.incredibar.cntry", "BE");
Found : user_pref("extensions.incredibar.dfltLng", "");
Found : user_pref("extensions.incredibar.dfltSrch", false);
Found : user_pref("extensions.incredibar.did", "10595");
Found : user_pref("extensions.incredibar.hdrMd5", "FE908C0A993F4340C26B59622D133746");
Found : user_pref("extensions.incredibar.hmpg", false);
Found : user_pref("extensions.incredibar.id", "0c1b6784000000000000000cf643be6f");
Found : user_pref("extensions.incredibar.installerproductid", "26");
Found : user_pref("extensions.incredibar.instlDay", "15410");
Found : user_pref("extensions.incredibar.instlRef", "");
Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.3.2722:01:54");
Found : user_pref("extensions.incredibar.newTab", false);
Found : user_pref("extensions.incredibar.noFFXTlbr", false);
Found : user_pref("extensions.incredibar.ppd", "");
Found : user_pref("extensions.incredibar.prdct", "incredibar");
Found : user_pref("extensions.incredibar.productid", "26");
Found : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar.sg", "none");
Found : user_pref("extensions.incredibar.smplGrp", "none");
Found : user_pref("extensions.incredibar.tlbrId", "base");
Found : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6Oyvu4X7t6&loc=IB_T[...]
Found : user_pref("extensions.incredibar.upn2", "6Oyvu4X7t6");
Found : user_pref("extensions.incredibar.upn2n", "92261047817920656");
Found : user_pref("extensions.incredibar.vrsn", "1.5.3.27");
Found : user_pref("extensions.incredibar.vrsnTs", "1.5.3.2722:01:54");
Found : user_pref("extensions.incredibar.vrsni", "1.5.3.27");
Found : user_pref("extensions.incredibar_i.aflt", "orgnl");
Found : user_pref("extensions.incredibar_i.dfltLng", "");
Found : user_pref("extensions.incredibar_i.did", "10595");
Found : user_pref("extensions.incredibar_i.excTlbr", "false");
Found : user_pref("extensions.incredibar_i.hardId", "0c1b6784000000000000000cf643be6f");
Found : user_pref("extensions.incredibar_i.id", "0c1b6784000000000000000cf643be6f");
Found : user_pref("extensions.incredibar_i.installerproductid", "26");
Found : user_pref("extensions.incredibar_i.instlDay", "15410");
Found : user_pref("extensions.incredibar_i.instlRef", "");
Found : user_pref("extensions.incredibar_i.ms_url_id", "");
Found : user_pref("extensions.incredibar_i.newTab", false);
Found : user_pref("extensions.incredibar_i.ppd", "");
Found : user_pref("extensions.incredibar_i.prdct", "incredibar");
Found : user_pref("extensions.incredibar_i.productid", "26");
Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar_i.smplGrp", "none");
Found : user_pref("extensions.incredibar_i.tlbrId", "base");
Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6Oyvu4X7t6&loc=IB[...]
Found : user_pref("extensions.incredibar_i.upn2", "6Oyvu4X7t6");
Found : user_pref("extensions.incredibar_i.upn2n", "92261047817920656");
Found : user_pref("extensions.incredibar_i.vrsn", "1.5.3.27");
Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.3.2722:01:54");
Found : user_pref("extensions.incredibar_i.vrsni", "1.5.3.27");
Found : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid=%7B74243e4f-f03b-47b7-ae62-b1b596d7d148%[...]

*************************

AdwCleaner[R1].txt - [23751 octets] - [14/06/2012 20:16:08]

########## EOF - C:\AdwCleaner[R1].txt - [23880 octets] ##########

Juisterr

Legacy Member
Sluit alle openstaande vensters
Start AdwCleaner en klik Delete
Klik bij AdwCleaner &#8211; Information op OK
Klik bij AdwCleaner &#8211; Restart Required op OK
Alle icoontjes verdwijnen van het Bureaublad,dit is normaal
Je PC word opnieuw opgestart en er een opent logfile (C:\ AdwCleaner[xx].txt) post de inhoud hier op het Forum
Als je Startpagina ook gehijackt was,stel dan de zoekmachine opnieuw,deze word standaard door AdwCleaner terug gezet naar Google.fr

Ignorance:)

Legacy Member
Zal de komende dagen niet kunnen reageren,wegens operatie.
Hier is alvast het logje.
AdwCleaner v1.609 - Logfile created 06/19/2012 at 20:47:51
# Updated 10/06/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Santiago - SANTIAGO-PC
# Running from : C:\Users\Santiago\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Santiago\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Santiago\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Santiago\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\Conduit
Folder Deleted : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\ConduitCommon
Folder Deleted : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\extensions\[email protected]
Folder Deleted : C:\Program Files (x86)\Common Files\spigot
File Deleted : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\searchplugins\MyStart Search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml

***** [Registry] *****

[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2865317
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=102866&gct=hp --> hxxp://www.google.com

-\\ Mozilla Firefox v13.0.1 (nl)

Profile name : default
File : C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\prefs.js

C:\Users\Santiago\AppData\Roaming\Mozilla\Firefox\Profiles\6dfrmzxw.default\user.js ... Deleted !

Deleted : user_pref("CT2865317..clientLogIsEnabled", true);
Deleted : user_pref("CT2865317..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2865317..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2865317.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2865317.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2865317.AppTrackingLastCheckTime", "Fri Sep 23 2011 19:48:52 GMT+0200 (Romance (zomerti[...]
Deleted : user_pref("CT2865317.CTID", "CT2865317");
Deleted : user_pref("CT2865317.CurrentServerDate", "25-11-2011");
Deleted : user_pref("CT2865317.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2865317.DialogsGetterLastCheckTime", "Thu Nov 24 2011 18:33:03 GMT+0100 (Romance (stand[...]
Deleted : user_pref("CT2865317.DownloadReferralCookieData", "");
Deleted : user_pref("CT2865317.EMailNotifierPollDate", "Thu Nov 24 2011 23:28:02 GMT+0100 (Romance (standaardt[...]
Deleted : user_pref("CT2865317.FeedLastCount5397019970362056034", 501);
Deleted : user_pref("CT2865317.FeedPollDate2429156812186649977", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813040823546", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813130095866", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813224203613", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813230837251", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813454291735", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813729834876", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156813860870021", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156814264681793", "Thu Nov 24 2011 22:33:03 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156814863075366", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedPollDate2429156815257761081", "Thu Nov 24 2011 22:33:02 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.FeedTTL2429156813040823546", 15);
Deleted : user_pref("CT2865317.FeedTTL2429156813130095866", 10);
Deleted : user_pref("CT2865317.FeedTTL2429156813454291735", 5);
Deleted : user_pref("CT2865317.FeedTTL2429156814264681793", 5);
Deleted : user_pref("CT2865317.FirstServerDate", "10-6-2011");
Deleted : user_pref("CT2865317.FirstTime", true);
Deleted : user_pref("CT2865317.FirstTimeFF3", true);
Deleted : user_pref("CT2865317.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2865317.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2865317.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2865317.HasUserGlobalKeys", true);
Deleted : user_pref("CT2865317.HomePageProtectorEnabled", false);
Deleted : user_pref("CT2865317.Initialize", true);
Deleted : user_pref("CT2865317.InitializeCommonPrefs", true);
Deleted : user_pref("CT2865317.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2865317.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2865317.InstalledDate", "Fri Jun 10 2011 21:23:23 GMT+0200 (Romance (zomertijd))");
Deleted : user_pref("CT2865317.IsAlertDBUpdated", true);
Deleted : user_pref("CT2865317.IsGrouping", false);
Deleted : user_pref("CT2865317.IsMulticommunity", false);
Deleted : user_pref("CT2865317.IsOpenThankYouPage", true);
Deleted : user_pref("CT2865317.IsOpenUninstallPage", false);
Deleted : user_pref("CT2865317.LanguagePackLastCheckTime", "Thu Nov 24 2011 18:32:58 GMT+0100 (Romance (standa[...]
Deleted : user_pref("CT2865317.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2865317.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2865317.LastLogin_3.3.3.2", "Thu Jul 07 2011 11:17:30 GMT+0200 (Romance (zomertijd))");
Deleted : user_pref("CT2865317.LastLogin_3.5.0.12", "Mon Aug 15 2011 22:48:36 GMT+0200 (Romance (zomertijd))")[...]
Deleted : user_pref("CT2865317.LastLogin_3.6.0.10", "Thu Sep 22 2011 20:00:16 GMT+0200 (Romance (zomertijd))")[...]
Deleted : user_pref("CT2865317.LastLogin_3.7.0.6", "Thu Nov 10 2011 00:08:11 GMT+0100 (Romance (standaardtijd)[...]
Deleted : user_pref("CT2865317.LastLogin_3.8.0.8", "Thu Nov 24 2011 22:33:01 GMT+0100 (Romance (standaardtijd)[...]
Deleted : user_pref("CT2865317.LatestVersion", "3.8.0.8");
Deleted : user_pref("CT2865317.Locale", "nl");
Deleted : user_pref("CT2865317.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2865317.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2865317.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2865317.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2865317.SearchBoxWidth", 148);
Deleted : user_pref("CT2865317.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("CT2865317.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2865317.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT286[...]
Deleted : user_pref("CT2865317.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2865317.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2865317.SearchInNewTabLastCheckTime", "Thu Nov 24 2011 18:32:56 GMT+0100 (Romance (stan[...]
Deleted : user_pref("CT2865317.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2865317.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Deleted : user_pref("CT2865317.SearchProtectorEnabled", false);
Deleted : user_pref("CT2865317.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2865317.ServiceMapLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (Romance (standaar[...]
Deleted : user_pref("CT2865317.SettingsLastCheckTime", "Thu Nov 24 2011 18:32:56 GMT+0100 (Romance (standaardt[...]
Deleted : user_pref("CT2865317.SettingsLastUpdate", "1321973127");
Deleted : user_pref("CT2865317.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2865317.ThirdPartyComponentsLastCheck", "Sat Nov 12 2011 10:52:16 GMT+0100 (Romance (st[...]
Deleted : user_pref("CT2865317.ThirdPartyComponentsLastUpdate", "1256026239");
Deleted : user_pref("CT2865317.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2865317.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2865317");
Deleted : user_pref("CT2865317.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2865317.UserID", "UN54127799129869083");
Deleted : user_pref("CT2865317.ValidationData_Search", 2);
Deleted : user_pref("CT2865317.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2865317.WeatherNetwork", "");
Deleted : user_pref("CT2865317.WeatherPollDate", "Thu Nov 24 2011 23:03:06 GMT+0100 (Romance (standaardtijd))"[...]
Deleted : user_pref("CT2865317.WeatherUnit", "C");
Deleted : user_pref("CT2865317.alertChannelId", "1257316");
Deleted : user_pref("CT2865317.backendstorage.cbfirsttime", "546875204E6F7620323420323031312031383A33333A30322[...]
Deleted : user_pref("CT2865317.backendstorage.enableinj", "");
Deleted : user_pref("CT2865317.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Deleted : user_pref("CT2865317.backendstorage.url_history", "687474703A2F2F7868616D737465722E636F6D2F757365722[...]
Deleted : user_pref("CT2865317.backendstorage.url_history_time", "31333232313537353339353736");
Deleted : user_pref("CT2865317.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2865317.globalFirstTimeInfoLastCheckTime", "Thu Nov 24 2011 22:32:59 GMT+0100 (Romance [...]
Deleted : user_pref("CT2865317.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2865317.initDone", true);
Deleted : user_pref("CT2865317.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2865317.myStuffEnabled", true);
Deleted : user_pref("CT2865317.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2865317.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2865317.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2865317.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2865317.oldAppsList", "129363015615025603,129363015615338104,1000234,129363015615494356[...]
Deleted : user_pref("CT2865317.revertSettingsEnabled", true);
Deleted : user_pref("CT2865317.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2865317.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2865317.testingCtid", "");
Deleted : user_pref("CT2865317.toolbarAppMetaDataLastCheckTime", "Thu Nov 24 2011 18:32:58 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.toolbarContextMenuLastCheckTime", "Sat Nov 12 2011 18:59:27 GMT+0100 (Romance ([...]
Deleted : user_pref("CT2865317.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1257316/1252989/BE", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/BE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2865317", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2865317",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2865317&octid=[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2865317/CT2865317[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=nl", "\"1ec[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{87775fdb-6972-41f9-ae51-8326e38cb206}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar_nl");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Santiago\\AppData\\Roaming\\Mozilla[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://cdn.triplegames.com/shared/apps/gamearcad[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2865317");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{87775fdb-6972-41f9-ae51-8326e38cb206}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar_nl");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2865317");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2865317");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Jun 10 2011 21:23:25 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Jul 07 2011 11:17:38 GMT+0200 (Roman[...]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Jul 07 2011 11:17:30 GMT+0200 (Romance ([...]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "972f69a3-3590-4e31-9647-c77e470e4bba");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (Rom[...]
Deleted : user_pref("CommunityToolbar.globalUserId", "766cd580-33de-471b-b459-5f590c63e658");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.killedEngine", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Nov 20 2011 19:30:4[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 24 2011 18:33:05 GMT+010[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 24 2011 18:32:57 GMT+0100 (R[...]
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "02498136-fb07-4fca-b871-c07bcbbd09e5");
Deleted : user_pref("CommunityToolbar.undefined", "");
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.enabledAddons", "[email protected]:1.5.0,{73a6fe31-595d-460b-a920-fcc0f88[...]
Deleted : user_pref("extensions.incredibar.actvtyRptTime", "1340115333840");
Deleted : user_pref("extensions.incredibar.admin", false);
Deleted : user_pref("extensions.incredibar.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar.cntry", "BE");
Deleted : user_pref("extensions.incredibar.dfltLng", "");
Deleted : user_pref("extensions.incredibar.dfltSrch", false);
Deleted : user_pref("extensions.incredibar.did", "10595");
Deleted : user_pref("extensions.incredibar.hdrMd5", "FE908C0A993F4340C26B59622D133746");
Deleted : user_pref("extensions.incredibar.hmpg", false);
Deleted : user_pref("extensions.incredibar.id", "0c1b6784000000000000000cf643be6f");
Deleted : user_pref("extensions.incredibar.installerproductid", "26");
Deleted : user_pref("extensions.incredibar.instlDay", "15410");
Deleted : user_pref("extensions.incredibar.instlRef", "");
Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.3.2722:01:54");
Deleted : user_pref("extensions.incredibar.newTab", false);
Deleted : user_pref("extensions.incredibar.noFFXTlbr", false);
Deleted : user_pref("extensions.incredibar.ppd", "");
Deleted : user_pref("extensions.incredibar.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar.productid", "26");
Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar.sg", "none");
Deleted : user_pref("extensions.incredibar.smplGrp", "none");
Deleted : user_pref("extensions.incredibar.tlbrId", "base");
Deleted : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6Oyvu4X7t6&loc=IB_T[...]
Deleted : user_pref("extensions.incredibar.upn2", "6Oyvu4X7t6");
Deleted : user_pref("extensions.incredibar.upn2n", "92261047817920656");
Deleted : user_pref("extensions.incredibar.vrsn", "1.5.3.27");
Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.3.2722:01:54");
Deleted : user_pref("extensions.incredibar.vrsni", "1.5.3.27");
Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Deleted : user_pref("extensions.incredibar_i.did", "10595");
Deleted : user_pref("extensions.incredibar_i.excTlbr", "false");
Deleted : user_pref("extensions.incredibar_i.hardId", "0c1b6784000000000000000cf643be6f");
Deleted : user_pref("extensions.incredibar_i.id", "0c1b6784000000000000000cf643be6f");
Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Deleted : user_pref("extensions.incredibar_i.instlDay", "15410");
Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Deleted : user_pref("extensions.incredibar_i.newTab", false);
Deleted : user_pref("extensions.incredibar_i.ppd", "");
Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar_i.productid", "26");
Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6Oyvu4X7t6&loc=IB[...]
Deleted : user_pref("extensions.incredibar_i.upn2", "6Oyvu4X7t6");
Deleted : user_pref("extensions.incredibar_i.upn2n", "92261047817920656");
Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.3.27");
Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.3.2722:01:54");
Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.3.27");
Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid=%7B74243e4f-f03b-47b7-ae62-b1b596d7d148%[...]

*************************

AdwCleaner[R1].txt - [23854 octets] - [14/06/2012 20:16:08]
AdwCleaner[S1].txt - [23472 octets] - [19/06/2012 20:47:51]

########## EOF - C:\AdwCleaner[S1].txt - [23601 octets] ##########

Ignorance:)

Legacy Member
Was het logje inorde?
Er zijn nog problemen met men 3dkaart,ligt het aan de drivers.
Ik had er een logje van gepost wil je er eens hene kijken,bedankt.

Jurgenv1

Legacy Member
Ik zie niets verkeerd, ga met uw 3D kaart problemen eens naar de software sectie. :)
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan