Hoi allemaal,
Ik had laatst last van een virus en die verwijderd (dacht ik), maar na een aantal weken kreeg ik in Chrome last van een extensie die de hele tijd terug komt en pop-ups/reclame pagina's opent (de plugin heet fastncheap als ik het goed herinner, heb hem net weer van chrome verwijderd).
Ik kan de extensie verwijderen, maar na een paar dagen komt hij weer vrolijk terug.
MBAM
Scan Date: 21-11-2014
Scan Time: 18:38:04
Logfile: Scan 21-11.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.21.10
Rootkit Database: v2014.11.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Jesse
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 321676
Time Elapsed: 5 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
ADWcleaner
# AdwCleaner v4.101 - Rapport aangemaakt 21/11/2014 op 18:49:41
# Laatste Update 09/11/2014 door Xplode
# Database : 2014-11-16.1 [Live]
# Besturingssysteem : Windows 8.1 Pro (64 bits)
# Gebruikersnaam : Jesse - JESSEPC
# Gestart vanuit : D:\Downloads\adwcleaner_4.101.exe
# Optie : Scannen
***** [ Services ] *****
***** [ Bestanden / Mappen ] *****
***** [ Taken ] *****
***** [ Snelkoppelingen ] *****
***** [ Register ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v26.0 (en-US)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [3904 octets] - [21/11/2014 18:46:39]
AdwCleaner[R1].txt - [703 octets] - [21/11/2014 18:49:41]
AdwCleaner[S0].txt - [3802 octets] - [21/11/2014 18:47:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [822 octets] ##########
E-Peek
E-Peek v 1.0.5.6 © Emphyrio/Onsia Patrick 2013-2014
Downloaded @ E Dev
Run at vr 21 nov 2014 18:51
.
Windows 8.1 Professional (64 bits)
C:\Windows [NTFS - Fixed]
Default Browser: Google Chrome
Boot mode: Normal boot
User logged in: Jesse
.
Java x86: 1.7.0_71
Java x64: n/a
.
AV : Avira Desktop [Updated - Running]
AV : Windows Defender [Updated - Not Running]
AS : Avira Desktop [Updated - Running]
AS : Windows Defender [Updated - Not Running]
FW : Windows firewall
.
==================== Files and Folders history =================================
Folders Created Last 7 days :
21-11-2014 ##### r-h-s-d+a- C:\Program Files (x86)\E Dev
21-11-2014 ##### r-h-s-d+a- C:\AdwCleaner
Files Modified Last 7 days :
21-11-2014 01826596 r-h-s-d-a+ C:\Windows\system32\PerfStringBackup.INI
21-11-2014 00806500 r-h-s-d-a+ C:\Windows\system32\perfh013.dat
21-11-2014 00723316 r-h-s-d-a+ C:\Windows\system32\perfh009.dat
21-11-2014 00162500 r-h-s-d-a+ C:\Windows\system32\perfc013.dat
21-11-2014 00135930 r-h-s-d-a+ C:\Windows\system32\perfc009.dat
15-11-2014 103374192 r-h-s-d-a+ C:\Windows\system32\MRT.exe
15-11-2014 00482520 r-h-s-d-a+ C:\Windows\system32\FNTCACHE.DAT
Files Created Last 7 days :
19-11-2014 00991232 r-h-s-d-a+ C:\Windows\system32\kerberos.dll
19-11-2014 00806400 r-h-s-d-a+ C:\Windows\SysWOW64\kerberos.dll
19-11-2014 00259584 r-h-s-d-a+ C:\Windows\system32\pku2u.dll
19-11-2014 00208896 r-h-s-d-a+ C:\Windows\SysWOW64\pku2u.dll
==================== RUNNING PROCESSES =========================================
[atieclxx] -SYSTEM- C:\Windows\system32\atieclxx.exe - (AMD)
[avgnt] -Jesse- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe - (Avira Operations GmbH & Co. KG)
[Avira.OE.ServiceHost] -SYSTEM- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe - (Avira Operations GmbH & Co. KG)
[Avira.OE.Systray] -Jesse- C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe - (Avira Operations GmbH & Co. KG)
[avshadow] -SYSTEM- C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe - (Avira Operations GmbH & Co. KG)
[CCC] -Jesse- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe - (ATI Technologies Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[explorer] -Jesse- C:\Windows\Explorer.EXE - (Microsoft Corporation)
[GoogleUpdate] -SYSTEM- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - (Google Inc.)
[IAStorDataMgrSvc] -SYSTEM- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe - (Intel Corporation)
[IAStorIcon] -Jesse- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe - (Intel Corporation)
[jusched] -Jesse- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe - (Oracle Corporation)
[MOM] -Jesse- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe - (Advanced Micro Devices Inc.)
[notepad] -Jesse- C:\Windows\system32\NOTEPAD.EXE - (Microsoft Corporation)
[officeclicktorun] -SYSTEM- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe - (Microsoft Corporation)
[raptr_ep64] -Jesse- C:\Program Files (x86)\Raptr\raptr_ep64.exe - (Raptr Inc.)
[sched] -SYSTEM- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe - (Avira Operations GmbH & Co. KG)
[SearchIndexer] -SYSTEM- C:\Windows\system32\SearchIndexer.exe - (Microsoft Corporation)
[taskeng] -SYSTEM- C:\Windows\system32\taskeng.exe - (Microsoft Corporation)
[winlogon] -SYSTEM- C:\Windows\system32\winlogon.exe - (Microsoft Corporation)
[WmiPrvSE] -NETWORK SERVICE- C:\Windows\system32\wbem\wmiprvse.exe - (Microsoft Corporation)
==================== IE PAGES ==================================================
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\system32\blank.htm
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE04 - HKCU\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [Bing] @ URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE05 - HKCU\..\URLSearchHooks @ {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = C:\Windows\SysWOW64\ieframe.dll
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\SysWOW64\blank.htm
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE10 - HKLM\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE10 - HKLM\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [@ieframe.dll,-12512] @ URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\system32\blank.htm
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE04 x64 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE04 x64 - HKCU\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [Bing] @ URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE05 x64 - HKCU\..\URLSearchHooks @ {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = C:\Windows\System32\ieframe.dll
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\System32\blank.htm
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE10 x64 - HKLM\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE10 x64 - HKLM\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [@ieframe.dll,-12512] @ URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
==================== Auto Load =================================================
AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Userinit = userinit.exe
AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Shell = explorer.exe
AL00 x64 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Userinit = C:\Windows\System32\Userinit.exe,
AL00 x64 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Shell = explorer.exe
==================== Firefox ===================================================
Please update your Firefox !
==================== Google Chrome =============================================
GC - Prefpath: C:\Users\Jesse\AppData\Local\Google\Chrome\User Data\Default\Preferences
GC - Profile Name: Eerste gebruiker
GC - Homepage:
GC - Default Search Provider:
= Known Disabled Extensions =
==================== Windows Host File =========================================
==================== BHO =======================================================
BHO - [Lync Browser Helper] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} @ Default = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
BHO - [Java(tm) Plug-In SSV Helper] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} @ Default = C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO - [Microsoft SkyDrive Pro Browser Helper] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} @ Default = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
BHO - [Java(tm) Plug-In 2 SSV Helper] - {DBC80044-A445-435b-BC74-9C25C1C588A9} @ Default = C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO x64 - [Lync Browser Helper] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} @ Default = C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
BHO x64 - [fastncheap] - {81a8921a-b1f4-4cdc-9111-fed0ff5d2c63} @ Default = C:\ProgramData\fastncheap\cWMeLQtqopRurd.x64.dll
BHO x64 - [Microsoft SkyDrive Pro Browser Helper] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} @ Default = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
==================== Auto Start Programs =======================================
ASP01 - HKLM\..\Run @ avgnt = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
ASP01 - HKLM\..\Run @ Avira Systray = C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
ASP01 - HKLM\..\Run @ Raptr = "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
ASP01 - HKLM\..\Run @ StartCCC = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
ASP01 - HKLM\..\Run @ SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ASP04 - HKCU\..\Run @ DAEMON Tools Lite = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
ASP04 - HKCU\..\Run @ f.lux = "C:\Users\Jesse\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
ASP04 - HKCU\..\Run @ LightShot = C:\Users\Jesse\AppData\Local\Skillbrains\lightshot\Lightshot.exe
ASP04 - HKCU\..\Run @ Sony PC Companion = "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
ASP04 - HKCU\..\Run @ Voobly = "C:\Program Files (x86)\Voobly\voobly.exe" --startup
ASP01 x64 - HKLM\..\Run @ avgnt = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
ASP01 x64 - HKLM\..\Run @ Avira Systray = C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
ASP01 x64 - HKLM\..\Run @ Raptr = "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
ASP01 x64 - HKLM\..\Run @ StartCCC = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
ASP01 x64 - HKLM\..\Run @ SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ASP04 x64 - HKCU\..\Run @ DAEMON Tools Lite = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
ASP04 x64 - HKCU\..\Run @ f.lux = "C:\Users\Jesse\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
ASP04 x64 - HKCU\..\Run @ LightShot = C:\Users\Jesse\AppData\Local\Skillbrains\lightshot\Lightshot.exe
ASP04 x64 - HKCU\..\Run @ Sony PC Companion = "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
ASP04 x64 - HKCU\..\Run @ Voobly = "C:\Program Files (x86)\Voobly\voobly.exe" --startup
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk
ASP - CommonStartup - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
==================== Extra Items IE ============================================
EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCELERATED_GRAPHICS @ Text = Accelerated graphics
EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCESSIBILITY @ Text = Accessibility
EI03 - Adv Opt - HKLM\..\AdvancedOptions\BROWSE @ Text = Browsing
EI03 - Adv Opt - HKLM\..\AdvancedOptions\CRYPTO @ Text = Security
EI03 - Adv Opt - HKLM\..\AdvancedOptions\HTTP @ Text = HTTP settings
EI03 - Adv Opt - HKLM\..\AdvancedOptions\INTERNATIONAL @ Text = International
EI03 - Adv Opt - HKLM\..\AdvancedOptions\MULTIMEDIA @ Text = Multimedia
EI04 - App Ext - HKCU\..\Approved Extensions @ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} = C:\Program Files (x86)\Java\jre7\bin\ssv.dll
EI04 - App Ext - HKCU\..\Approved Extensions @ {DBC80044-A445-435B-BC74-9C25C1C588A9} = C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\ACCELERATED_GRAPHICS @ Text = Accelerated graphics
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\ACCESSIBILITY @ Text = Accessibility
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\BROWSE @ Text = Browsing
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\CRYPTO @ Text = Security
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\HTTP @ Text = HTTP settings
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\INTERNATIONAL @ Text = International
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\MULTIMEDIA @ Text = Multimedia
EI04 x64 - App Ext - HKCU\..\Approved Extensions @ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =
EI04 x64 - App Ext - HKCU\..\Approved Extensions @ {DBC80044-A445-435B-BC74-9C25C1C588A9} =
==================== Internet Default Prefix ===================================
IDP00 - Default - HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix @ Default = http://
IDP01 - WWW - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes @ WWW = http://
IDP00 x64 - Default - HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix @ Default = http://
IDP01 x64 - WWW - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes @ WWW = http://
==================== Default Settings IE - DSIE ================================
DSIE - ieuinit.inf: START_PAGE= "http://go.microsoft.com/fwlink/p/?LinkId
DSIE - ieuinit.inf: SEARCH_PAGE_URL= "http://go.microsoft.com/fwlink/?LinkId
==================== Protocol Hijackers - PH ===================================
PH00 - Handler
sf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} @ = Unknown # C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL # MD5 [405251ed82d69e5893f1e7e923b7f38b]
PH00 x64 - Handler
sf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} @ = Unknown # C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL # MD5 [59ac63d95071da4b8f1f5a9277b7f4fe]
==================== ShellServiceObjectDelayLoad - SSODL =======================
SSODL - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} @ =
SSODL x64 - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} @ =
==================== Extra items - EXT (Torpig/ConduitSearch) ==================
EXT01 - HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
EXT01 - HKCU\SOFTWARE\AppDataLow\Software\Microsoft
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\FileSystem @ {217FC9C0-3AEA-1069-A2DB-08002B30309D}= C:\Windows\system32\shell32.dll
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook @ {DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}= C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\Sharing @ {40dd6e20-7c17-11ce-a804-00aa003ca9f6}= C:\Windows\system32\ntshrui.dll
EXT01 x64 - HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
EXT01 x64 - HKCU\SOFTWARE\AppDataLow\Software\Microsoft
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\FileSystem @ {217FC9C0-3AEA-1069-A2DB-08002B30309D}= C:\Windows\system32\shell32.dll
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook @ {DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}= C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\Sharing @ {40dd6e20-7c17-11ce-a804-00aa003ca9f6}= C:\Windows\system32\ntshrui.dll
==================== DRIVERS and SERVICES ======================================
*** Win32OwnProcess ***
SERV - R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe
SERV - R2 - [AntiVirSchedulerService] - Avira Scheduler - c:\program files (x86)\avira\antivir desktop\sched.exe
SERV - R2 - [AntiVirService] - Avira Real-Time Protection - c:\program files (x86)\avira\antivir desktop\avguard.exe
SERV - R2 - [Avira.OE.ServiceHost] - Avira Service Host - c:\program files (x86)\avira\my avira\avira.oe.servicehost.exe
SERV - R2 - [ClickToRunSvc] - Microsoft Office ClickToRun Service - c:\program files\microsoft office 15\clientx64\officeclicktorun.exe
SERV - R2 - [IAStorDataMgrSvc] - Intel(R) Rapid Storage Technology - c:\program files\intel\intel(r) rapid storage technology\iastordatamgrsvc.exe
SERV - R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
SERV - S2 - [fa6789c5] - VideoCnv - (x86)\videocnv\zet.dll [x]
SERV - S2 - [gupdate] - Google Update-service (gupdate) - c:\program files (x86)\google\update\googleupdate.exe
SERV - S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
SERV - S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
SERV - S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
SERV - S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
SERV - S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
SERV - S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe
SERV - S3 - [gupdatem] - Google Update-service (gupdatem) - c:\program files (x86)\google\update\googleupdate.exe
SERV - S3 - [IDriverT] - InstallDriver Table Manager - c:\program files (x86)\common files\installshield\driver\11\intel 32\idrivert.exe
SERV - S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
SERV - S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
SERV - S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
SERV - S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
SERV - S3 - [ose64] - Office 64 Source Engine - c:\program files\common files\microsoft shared\source engine\ose.exe
SERV - S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
SERV - S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
SERV - S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe
SERV - S3 - [Sony PC Companion] - Sony PC Companion - c:\program files (x86)\sony\sony pc companion\pccservice.exe
SERV - S3 - [Steam Client Service] - Steam Client Service - c:\program files (x86)\common files\steam\steamservice.exe
SERV - S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
SERV - S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
SERV - S3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
SERV - S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
SERV - S3 - [WdNisSvc] - Windows Defender Network Inspection Service - c:\program files\windows defender\nissrv.exe
SERV - S3 - [WinDefend] - Windows Defender Service - c:\program files\windows defender\msmpeng.exe
SERV - S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
SERV - S3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
SERV - S4 - [AntiVirWebService] - Avira Web Protection - c:\program files (x86)\avira\antivir desktop\avwebg7.exe
*** Win32ShareProcess ***
SERV - R2 - [EFS] - Encrypting File System (EFS) - c:\windows\system32\lsass.exe
SERV - R2 - [SamSs] - Security Accounts Manager - c:\windows\system32\lsass.exe
SERV - S3 - [KeyIso] - CNG Key Isolation - c:\windows\system32\lsass.exe
SERV - S3 - [Netlogon] - Netlogon - c:\windows\system32\lsass.exe
SERV - S3 - [VaultSvc] - Credential Manager - c:\windows\system32\lsass.exe
SERV - S4 - [NetTcpPortSharing] - Net.Tcp Port Sharing Service - c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe
*** Others ***
SERV - R2 - [Spooler] - Print Spooler - c:\windows\system32\spoolsv.exe
SERV - S3 - [UI0Detect] - Interactive Services Detection - c:\windows\system32\ui0detect.exe
*** File System Driver ***
DRV - R0 - [FileInfo] - File Information FS MiniFilter - C:\Windows\system32\Drivers\FileInfo.sys
DRV - R0 - [FltMgr] - FltMgr - C:\Windows\system32\Drivers\FltMgr.sys
DRV - R0 - [Mup] - Mup - C:\Windows\system32\Drivers\Mup.sys
DRV - R0 - [Wof] - Windows Overlay File System Filter Driver - C:\Windows\system32\Drivers\Wof.sys
DRV - R1 - [NetBIOS] - NetBIOS Interface - C:\Windows\system32\Drivers\NetBIOS.sys
DRV - R2 - [srv] - Server SMB 1.xxx Driver - C:\Windows\system32\Drivers\srv.sys
DRV - R3 - [srv2] - Server SMB 2.xxx Driver - C:\Windows\system32\Drivers\srv2.sys
*** Kernel Driver ***
DRV - R0 - [ACPI] - Microsoft ACPI-stuurprogramma - C:\Windows\system32\Drivers\ACPI.sys
DRV - R0 - [acpiex] - Microsoft ACPIEx Driver - C:\Windows\system32\Drivers\acpiex.sys
DRV - R0 - [CLFS] - Common Log (CLFS) - C:\Windows\system32\Drivers\CLFS.sys
DRV - R0 - [CNG] - CNG - C:\Windows\system32\Drivers\CNG.sys
DRV - R0 - [disk] - Stuurprogramma voor schijfstations - C:\Windows\system32\Drivers\disk.sys
DRV - R0 - [EhStorClass] - Enhanced Storage Filter Driver - C:\Windows\system32\Drivers\EhStorClass.sys
DRV - R0 - [fvevol] - BitLocker Drive Encryption Filter Driver - C:\Windows\system32\Drivers\fvevol.sys
DRV - R0 - [iaStorA] - iaStorA - C:\Windows\system32\Drivers\iaStorA.sys
DRV - R0 - [intelpep] - Stuurprogramma voor Intel(R) Power Engine-invoegtoepassing - C:\Windows\system32\Drivers\intelpep.sys
DRV - R0 - [KSecDD] - KSecDD - C:\Windows\system32\Drivers\KSecDD.sys
DRV - R0 - [KSecPkg] - KSecPkg - C:\Windows\system32\Drivers\KSecPkg.sys
DRV - R0 - [mountmgr] - Mount Point Manager - C:\Windows\system32\Drivers\mountmgr.sys
DRV - R0 - [msisadrv] - msisadrv - C:\Windows\system32\Drivers\msisadrv.sys
DRV - R0 - [NDIS] - NDIS System Driver - C:\Windows\system32\Drivers\NDIS.sys
DRV - R0 - [partmgr] - Partition Manager - C:\Windows\system32\Drivers\partmgr.sys
DRV - R0 - [pci] - PCI Bus-stuurprogramma - C:\Windows\system32\Drivers\pci.sys
DRV - R0 - [pcw] - Performance Counters for Windows Driver - C:\Windows\system32\Drivers\pcw.sys
DRV - R0 - [pdc] - pdc - C:\Windows\system32\Drivers\pdc.sys
DRV - R0 - [rdyboost] - ReadyBoost - C:\Windows\system32\Drivers\rdyboost.sys
DRV - R0 - [spaceport] - Stuurprogramma voor opslagruimten - C:\Windows\system32\Drivers\spaceport.sys
DRV - R0 - [Tcpip] - Stuurprogramma voor TCP/IP-protocol - C:\Windows\system32\Drivers\Tcpip.sys
DRV - R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator - C:\Windows\system32\Drivers\vdrvroot.sys
DRV - R0 - [volmgr] - Stuurprogramma voor Volumebeheer - C:\Windows\system32\Drivers\volmgr.sys
DRV - R0 - [volmgrx] - Dynamic Volume Manager - C:\Windows\system32\Drivers\volmgrx.sys
DRV - R0 - [volsnap] - Opslagvolumes - C:\Windows\system32\Drivers\volsnap.sys
DRV - R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\Windows\system32\Drivers\Wdf01000.sys
DRV - R0 - [WFPLWFS] - Microsoft Windows Filtering Platform - C:\Windows\system32\Drivers\WFPLWFS.sys
DRV - R1 - [AFD] - Ancillary Function Driver for Winsock - C:\Windows\system32\Drivers\AFD.sys
DRV - R1 - [Beep] - Beep - C:\Windows\system32\Drivers\Beep.sys
DRV - R1 - [tdx] - Stuurprogramma voor ondersteuning van NetIO Legacy TDI - C:\Windows\system32\Drivers\tdx.sys
DRV - R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\Windows\system32\Drivers\tcpipreg.sys
DRV - S0 - [hwpolicy] - Hardware Policy Driver - C:\Windows\system32\Drivers\hwpolicy.sys
DRV - S3 - [atapi] - IDE-kanaal - C:\Windows\system32\Drivers\atapi.sys
==================== SvcHost - White Listed ====================================
All Ok
WOW - All Ok
==================== SigCheck x86 Fast =========================================
Fast Scan All ok
==================== SigCheck x64 Fast =========================================
Fast Scan All ok
==================== Job tasks =================================================
There are no .job files found.
==================== End scanning at vr 21 nov 2014 18:51 (0 Min 4 Sec ) =======
Wie kan mij helpen met het verwijderen van deze vervelende extensie?
Ik had laatst last van een virus en die verwijderd (dacht ik), maar na een aantal weken kreeg ik in Chrome last van een extensie die de hele tijd terug komt en pop-ups/reclame pagina's opent (de plugin heet fastncheap als ik het goed herinner, heb hem net weer van chrome verwijderd).
Ik kan de extensie verwijderen, maar na een paar dagen komt hij weer vrolijk terug.
MBAM
Scan Date: 21-11-2014
Scan Time: 18:38:04
Logfile: Scan 21-11.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.21.10
Rootkit Database: v2014.11.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Jesse
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 321676
Time Elapsed: 5 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
ADWcleaner
# AdwCleaner v4.101 - Rapport aangemaakt 21/11/2014 op 18:49:41
# Laatste Update 09/11/2014 door Xplode
# Database : 2014-11-16.1 [Live]
# Besturingssysteem : Windows 8.1 Pro (64 bits)
# Gebruikersnaam : Jesse - JESSEPC
# Gestart vanuit : D:\Downloads\adwcleaner_4.101.exe
# Optie : Scannen
***** [ Services ] *****
***** [ Bestanden / Mappen ] *****
***** [ Taken ] *****
***** [ Snelkoppelingen ] *****
***** [ Register ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v26.0 (en-US)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [3904 octets] - [21/11/2014 18:46:39]
AdwCleaner[R1].txt - [703 octets] - [21/11/2014 18:49:41]
AdwCleaner[S0].txt - [3802 octets] - [21/11/2014 18:47:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [822 octets] ##########
E-Peek
E-Peek v 1.0.5.6 © Emphyrio/Onsia Patrick 2013-2014
Downloaded @ E Dev
Run at vr 21 nov 2014 18:51
.
Windows 8.1 Professional (64 bits)
C:\Windows [NTFS - Fixed]
Default Browser: Google Chrome
Boot mode: Normal boot
User logged in: Jesse
.
Java x86: 1.7.0_71
Java x64: n/a
.
AV : Avira Desktop [Updated - Running]
AV : Windows Defender [Updated - Not Running]
AS : Avira Desktop [Updated - Running]
AS : Windows Defender [Updated - Not Running]
FW : Windows firewall
.
==================== Files and Folders history =================================
Folders Created Last 7 days :
21-11-2014 ##### r-h-s-d+a- C:\Program Files (x86)\E Dev
21-11-2014 ##### r-h-s-d+a- C:\AdwCleaner
Files Modified Last 7 days :
21-11-2014 01826596 r-h-s-d-a+ C:\Windows\system32\PerfStringBackup.INI
21-11-2014 00806500 r-h-s-d-a+ C:\Windows\system32\perfh013.dat
21-11-2014 00723316 r-h-s-d-a+ C:\Windows\system32\perfh009.dat
21-11-2014 00162500 r-h-s-d-a+ C:\Windows\system32\perfc013.dat
21-11-2014 00135930 r-h-s-d-a+ C:\Windows\system32\perfc009.dat
15-11-2014 103374192 r-h-s-d-a+ C:\Windows\system32\MRT.exe
15-11-2014 00482520 r-h-s-d-a+ C:\Windows\system32\FNTCACHE.DAT
Files Created Last 7 days :
19-11-2014 00991232 r-h-s-d-a+ C:\Windows\system32\kerberos.dll
19-11-2014 00806400 r-h-s-d-a+ C:\Windows\SysWOW64\kerberos.dll
19-11-2014 00259584 r-h-s-d-a+ C:\Windows\system32\pku2u.dll
19-11-2014 00208896 r-h-s-d-a+ C:\Windows\SysWOW64\pku2u.dll
==================== RUNNING PROCESSES =========================================
[atieclxx] -SYSTEM- C:\Windows\system32\atieclxx.exe - (AMD)
[avgnt] -Jesse- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe - (Avira Operations GmbH & Co. KG)
[Avira.OE.ServiceHost] -SYSTEM- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe - (Avira Operations GmbH & Co. KG)
[Avira.OE.Systray] -Jesse- C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe - (Avira Operations GmbH & Co. KG)
[avshadow] -SYSTEM- C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe - (Avira Operations GmbH & Co. KG)
[CCC] -Jesse- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe - (ATI Technologies Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[chrome] -Jesse- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - (Google Inc.)
[explorer] -Jesse- C:\Windows\Explorer.EXE - (Microsoft Corporation)
[GoogleUpdate] -SYSTEM- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - (Google Inc.)
[IAStorDataMgrSvc] -SYSTEM- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe - (Intel Corporation)
[IAStorIcon] -Jesse- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe - (Intel Corporation)
[jusched] -Jesse- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe - (Oracle Corporation)
[MOM] -Jesse- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe - (Advanced Micro Devices Inc.)
[notepad] -Jesse- C:\Windows\system32\NOTEPAD.EXE - (Microsoft Corporation)
[officeclicktorun] -SYSTEM- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe - (Microsoft Corporation)
[raptr_ep64] -Jesse- C:\Program Files (x86)\Raptr\raptr_ep64.exe - (Raptr Inc.)
[sched] -SYSTEM- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe - (Avira Operations GmbH & Co. KG)
[SearchIndexer] -SYSTEM- C:\Windows\system32\SearchIndexer.exe - (Microsoft Corporation)
[taskeng] -SYSTEM- C:\Windows\system32\taskeng.exe - (Microsoft Corporation)
[winlogon] -SYSTEM- C:\Windows\system32\winlogon.exe - (Microsoft Corporation)
[WmiPrvSE] -NETWORK SERVICE- C:\Windows\system32\wbem\wmiprvse.exe - (Microsoft Corporation)
==================== IE PAGES ==================================================
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\system32\blank.htm
IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE04 - HKCU\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [Bing] @ URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE05 - HKCU\..\URLSearchHooks @ {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = C:\Windows\SysWOW64\ieframe.dll
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\SysWOW64\blank.htm
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE10 - HKLM\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE10 - HKLM\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [@ieframe.dll,-12512] @ URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\system32\blank.htm
IE02 x64 - HKCU\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE04 x64 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE04 x64 - HKCU\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [Bing] @ URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE05 x64 - HKCU\..\URLSearchHooks @ {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = C:\Windows\System32\ieframe.dll
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\System32\blank.htm
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE08 x64 - HKLM\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE10 x64 - HKLM\Software\Microsoft\Internet Explorer\SearchScopes @ DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE10 x64 - HKLM\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [@ieframe.dll,-12512] @ URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
==================== Auto Load =================================================
AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Userinit = userinit.exe
AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Shell = explorer.exe
AL00 x64 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Userinit = C:\Windows\System32\Userinit.exe,
AL00 x64 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Shell = explorer.exe
==================== Firefox ===================================================
Please update your Firefox !
==================== Google Chrome =============================================
GC - Prefpath: C:\Users\Jesse\AppData\Local\Google\Chrome\User Data\Default\Preferences
GC - Profile Name: Eerste gebruiker
GC - Homepage:
GC - Default Search Provider:
= Known Disabled Extensions =
==================== Windows Host File =========================================
==================== BHO =======================================================
BHO - [Lync Browser Helper] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} @ Default = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
BHO - [Java(tm) Plug-In SSV Helper] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} @ Default = C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO - [Microsoft SkyDrive Pro Browser Helper] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} @ Default = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
BHO - [Java(tm) Plug-In 2 SSV Helper] - {DBC80044-A445-435b-BC74-9C25C1C588A9} @ Default = C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO x64 - [Lync Browser Helper] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} @ Default = C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
BHO x64 - [fastncheap] - {81a8921a-b1f4-4cdc-9111-fed0ff5d2c63} @ Default = C:\ProgramData\fastncheap\cWMeLQtqopRurd.x64.dll
BHO x64 - [Microsoft SkyDrive Pro Browser Helper] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} @ Default = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
==================== Auto Start Programs =======================================
ASP01 - HKLM\..\Run @ avgnt = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
ASP01 - HKLM\..\Run @ Avira Systray = C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
ASP01 - HKLM\..\Run @ Raptr = "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
ASP01 - HKLM\..\Run @ StartCCC = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
ASP01 - HKLM\..\Run @ SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ASP04 - HKCU\..\Run @ DAEMON Tools Lite = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
ASP04 - HKCU\..\Run @ f.lux = "C:\Users\Jesse\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
ASP04 - HKCU\..\Run @ LightShot = C:\Users\Jesse\AppData\Local\Skillbrains\lightshot\Lightshot.exe
ASP04 - HKCU\..\Run @ Sony PC Companion = "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
ASP04 - HKCU\..\Run @ Voobly = "C:\Program Files (x86)\Voobly\voobly.exe" --startup
ASP01 x64 - HKLM\..\Run @ avgnt = "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
ASP01 x64 - HKLM\..\Run @ Avira Systray = C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
ASP01 x64 - HKLM\..\Run @ Raptr = "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
ASP01 x64 - HKLM\..\Run @ StartCCC = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
ASP01 x64 - HKLM\..\Run @ SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ASP04 x64 - HKCU\..\Run @ DAEMON Tools Lite = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
ASP04 x64 - HKCU\..\Run @ f.lux = "C:\Users\Jesse\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
ASP04 x64 - HKCU\..\Run @ LightShot = C:\Users\Jesse\AppData\Local\Skillbrains\lightshot\Lightshot.exe
ASP04 x64 - HKCU\..\Run @ Sony PC Companion = "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
ASP04 x64 - HKCU\..\Run @ Voobly = "C:\Program Files (x86)\Voobly\voobly.exe" --startup
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ASP - Startup - C:\Users\Jesse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk
ASP - CommonStartup - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
==================== Extra Items IE ============================================
EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCELERATED_GRAPHICS @ Text = Accelerated graphics
EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCESSIBILITY @ Text = Accessibility
EI03 - Adv Opt - HKLM\..\AdvancedOptions\BROWSE @ Text = Browsing
EI03 - Adv Opt - HKLM\..\AdvancedOptions\CRYPTO @ Text = Security
EI03 - Adv Opt - HKLM\..\AdvancedOptions\HTTP @ Text = HTTP settings
EI03 - Adv Opt - HKLM\..\AdvancedOptions\INTERNATIONAL @ Text = International
EI03 - Adv Opt - HKLM\..\AdvancedOptions\MULTIMEDIA @ Text = Multimedia
EI04 - App Ext - HKCU\..\Approved Extensions @ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} = C:\Program Files (x86)\Java\jre7\bin\ssv.dll
EI04 - App Ext - HKCU\..\Approved Extensions @ {DBC80044-A445-435B-BC74-9C25C1C588A9} = C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\ACCELERATED_GRAPHICS @ Text = Accelerated graphics
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\ACCESSIBILITY @ Text = Accessibility
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\BROWSE @ Text = Browsing
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\CRYPTO @ Text = Security
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\HTTP @ Text = HTTP settings
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\INTERNATIONAL @ Text = International
EI03 x64 - Adv Opt - HKLM\..\AdvancedOptions\MULTIMEDIA @ Text = Multimedia
EI04 x64 - App Ext - HKCU\..\Approved Extensions @ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =
EI04 x64 - App Ext - HKCU\..\Approved Extensions @ {DBC80044-A445-435B-BC74-9C25C1C588A9} =
==================== Internet Default Prefix ===================================
IDP00 - Default - HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix @ Default = http://
IDP01 - WWW - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes @ WWW = http://
IDP00 x64 - Default - HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix @ Default = http://
IDP01 x64 - WWW - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes @ WWW = http://
==================== Default Settings IE - DSIE ================================
DSIE - ieuinit.inf: START_PAGE= "http://go.microsoft.com/fwlink/p/?LinkId
DSIE - ieuinit.inf: SEARCH_PAGE_URL= "http://go.microsoft.com/fwlink/?LinkId
==================== Protocol Hijackers - PH ===================================
PH00 - Handler

PH00 x64 - Handler

==================== ShellServiceObjectDelayLoad - SSODL =======================
SSODL - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} @ =
SSODL x64 - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} @ =
==================== Extra items - EXT (Torpig/ConduitSearch) ==================
EXT01 - HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
EXT01 - HKCU\SOFTWARE\AppDataLow\Software\Microsoft
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\FileSystem @ {217FC9C0-3AEA-1069-A2DB-08002B30309D}= C:\Windows\system32\shell32.dll
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook @ {DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}= C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
EXT02 - HKCR\Directory\shellex\CopyHookHandlers\Sharing @ {40dd6e20-7c17-11ce-a804-00aa003ca9f6}= C:\Windows\system32\ntshrui.dll
EXT01 x64 - HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
EXT01 x64 - HKCU\SOFTWARE\AppDataLow\Software\Microsoft
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\FileSystem @ {217FC9C0-3AEA-1069-A2DB-08002B30309D}= C:\Windows\system32\shell32.dll
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook @ {DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}= C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
EXT02 x64 - HKCR\Directory\shellex\CopyHookHandlers\Sharing @ {40dd6e20-7c17-11ce-a804-00aa003ca9f6}= C:\Windows\system32\ntshrui.dll
==================== DRIVERS and SERVICES ======================================
*** Win32OwnProcess ***
SERV - R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe
SERV - R2 - [AntiVirSchedulerService] - Avira Scheduler - c:\program files (x86)\avira\antivir desktop\sched.exe
SERV - R2 - [AntiVirService] - Avira Real-Time Protection - c:\program files (x86)\avira\antivir desktop\avguard.exe
SERV - R2 - [Avira.OE.ServiceHost] - Avira Service Host - c:\program files (x86)\avira\my avira\avira.oe.servicehost.exe
SERV - R2 - [ClickToRunSvc] - Microsoft Office ClickToRun Service - c:\program files\microsoft office 15\clientx64\officeclicktorun.exe
SERV - R2 - [IAStorDataMgrSvc] - Intel(R) Rapid Storage Technology - c:\program files\intel\intel(r) rapid storage technology\iastordatamgrsvc.exe
SERV - R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
SERV - S2 - [fa6789c5] - VideoCnv - (x86)\videocnv\zet.dll [x]
SERV - S2 - [gupdate] - Google Update-service (gupdate) - c:\program files (x86)\google\update\googleupdate.exe
SERV - S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
SERV - S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
SERV - S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
SERV - S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
SERV - S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
SERV - S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe
SERV - S3 - [gupdatem] - Google Update-service (gupdatem) - c:\program files (x86)\google\update\googleupdate.exe
SERV - S3 - [IDriverT] - InstallDriver Table Manager - c:\program files (x86)\common files\installshield\driver\11\intel 32\idrivert.exe
SERV - S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
SERV - S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
SERV - S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
SERV - S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
SERV - S3 - [ose64] - Office 64 Source Engine - c:\program files\common files\microsoft shared\source engine\ose.exe
SERV - S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
SERV - S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
SERV - S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe
SERV - S3 - [Sony PC Companion] - Sony PC Companion - c:\program files (x86)\sony\sony pc companion\pccservice.exe
SERV - S3 - [Steam Client Service] - Steam Client Service - c:\program files (x86)\common files\steam\steamservice.exe
SERV - S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
SERV - S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
SERV - S3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
SERV - S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
SERV - S3 - [WdNisSvc] - Windows Defender Network Inspection Service - c:\program files\windows defender\nissrv.exe
SERV - S3 - [WinDefend] - Windows Defender Service - c:\program files\windows defender\msmpeng.exe
SERV - S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
SERV - S3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
SERV - S4 - [AntiVirWebService] - Avira Web Protection - c:\program files (x86)\avira\antivir desktop\avwebg7.exe
*** Win32ShareProcess ***
SERV - R2 - [EFS] - Encrypting File System (EFS) - c:\windows\system32\lsass.exe
SERV - R2 - [SamSs] - Security Accounts Manager - c:\windows\system32\lsass.exe
SERV - S3 - [KeyIso] - CNG Key Isolation - c:\windows\system32\lsass.exe
SERV - S3 - [Netlogon] - Netlogon - c:\windows\system32\lsass.exe
SERV - S3 - [VaultSvc] - Credential Manager - c:\windows\system32\lsass.exe
SERV - S4 - [NetTcpPortSharing] - Net.Tcp Port Sharing Service - c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe
*** Others ***
SERV - R2 - [Spooler] - Print Spooler - c:\windows\system32\spoolsv.exe
SERV - S3 - [UI0Detect] - Interactive Services Detection - c:\windows\system32\ui0detect.exe
*** File System Driver ***
DRV - R0 - [FileInfo] - File Information FS MiniFilter - C:\Windows\system32\Drivers\FileInfo.sys
DRV - R0 - [FltMgr] - FltMgr - C:\Windows\system32\Drivers\FltMgr.sys
DRV - R0 - [Mup] - Mup - C:\Windows\system32\Drivers\Mup.sys
DRV - R0 - [Wof] - Windows Overlay File System Filter Driver - C:\Windows\system32\Drivers\Wof.sys
DRV - R1 - [NetBIOS] - NetBIOS Interface - C:\Windows\system32\Drivers\NetBIOS.sys
DRV - R2 - [srv] - Server SMB 1.xxx Driver - C:\Windows\system32\Drivers\srv.sys
DRV - R3 - [srv2] - Server SMB 2.xxx Driver - C:\Windows\system32\Drivers\srv2.sys
*** Kernel Driver ***
DRV - R0 - [ACPI] - Microsoft ACPI-stuurprogramma - C:\Windows\system32\Drivers\ACPI.sys
DRV - R0 - [acpiex] - Microsoft ACPIEx Driver - C:\Windows\system32\Drivers\acpiex.sys
DRV - R0 - [CLFS] - Common Log (CLFS) - C:\Windows\system32\Drivers\CLFS.sys
DRV - R0 - [CNG] - CNG - C:\Windows\system32\Drivers\CNG.sys
DRV - R0 - [disk] - Stuurprogramma voor schijfstations - C:\Windows\system32\Drivers\disk.sys
DRV - R0 - [EhStorClass] - Enhanced Storage Filter Driver - C:\Windows\system32\Drivers\EhStorClass.sys
DRV - R0 - [fvevol] - BitLocker Drive Encryption Filter Driver - C:\Windows\system32\Drivers\fvevol.sys
DRV - R0 - [iaStorA] - iaStorA - C:\Windows\system32\Drivers\iaStorA.sys
DRV - R0 - [intelpep] - Stuurprogramma voor Intel(R) Power Engine-invoegtoepassing - C:\Windows\system32\Drivers\intelpep.sys
DRV - R0 - [KSecDD] - KSecDD - C:\Windows\system32\Drivers\KSecDD.sys
DRV - R0 - [KSecPkg] - KSecPkg - C:\Windows\system32\Drivers\KSecPkg.sys
DRV - R0 - [mountmgr] - Mount Point Manager - C:\Windows\system32\Drivers\mountmgr.sys
DRV - R0 - [msisadrv] - msisadrv - C:\Windows\system32\Drivers\msisadrv.sys
DRV - R0 - [NDIS] - NDIS System Driver - C:\Windows\system32\Drivers\NDIS.sys
DRV - R0 - [partmgr] - Partition Manager - C:\Windows\system32\Drivers\partmgr.sys
DRV - R0 - [pci] - PCI Bus-stuurprogramma - C:\Windows\system32\Drivers\pci.sys
DRV - R0 - [pcw] - Performance Counters for Windows Driver - C:\Windows\system32\Drivers\pcw.sys
DRV - R0 - [pdc] - pdc - C:\Windows\system32\Drivers\pdc.sys
DRV - R0 - [rdyboost] - ReadyBoost - C:\Windows\system32\Drivers\rdyboost.sys
DRV - R0 - [spaceport] - Stuurprogramma voor opslagruimten - C:\Windows\system32\Drivers\spaceport.sys
DRV - R0 - [Tcpip] - Stuurprogramma voor TCP/IP-protocol - C:\Windows\system32\Drivers\Tcpip.sys
DRV - R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator - C:\Windows\system32\Drivers\vdrvroot.sys
DRV - R0 - [volmgr] - Stuurprogramma voor Volumebeheer - C:\Windows\system32\Drivers\volmgr.sys
DRV - R0 - [volmgrx] - Dynamic Volume Manager - C:\Windows\system32\Drivers\volmgrx.sys
DRV - R0 - [volsnap] - Opslagvolumes - C:\Windows\system32\Drivers\volsnap.sys
DRV - R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\Windows\system32\Drivers\Wdf01000.sys
DRV - R0 - [WFPLWFS] - Microsoft Windows Filtering Platform - C:\Windows\system32\Drivers\WFPLWFS.sys
DRV - R1 - [AFD] - Ancillary Function Driver for Winsock - C:\Windows\system32\Drivers\AFD.sys
DRV - R1 - [Beep] - Beep - C:\Windows\system32\Drivers\Beep.sys
DRV - R1 - [tdx] - Stuurprogramma voor ondersteuning van NetIO Legacy TDI - C:\Windows\system32\Drivers\tdx.sys
DRV - R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\Windows\system32\Drivers\tcpipreg.sys
DRV - S0 - [hwpolicy] - Hardware Policy Driver - C:\Windows\system32\Drivers\hwpolicy.sys
DRV - S3 - [atapi] - IDE-kanaal - C:\Windows\system32\Drivers\atapi.sys
==================== SvcHost - White Listed ====================================
All Ok
WOW - All Ok
==================== SigCheck x86 Fast =========================================
Fast Scan All ok
==================== SigCheck x64 Fast =========================================
Fast Scan All ok
==================== Job tasks =================================================
There are no .job files found.
==================== End scanning at vr 21 nov 2014 18:51 (0 Min 4 Sec ) =======
Wie kan mij helpen met het verwijderen van deze vervelende extensie?
Comment