Jump to content

Charlottevantricht

Members
  • Content Count

    17
  • Joined

  • Last visited

About Charlottevantricht

  • Rank
    New Member
  1. No, I haven't. Thank you Log: # DelFix v1.013 - Logfile created 23/08/2017 at 17:44:54 # Updated 17/04/2016 by Xplode # Username : Gebruiker - DESKTOP-2G14IHI # Operating System : Windows 10 Home (64 bits) ~ Activating UAC ... OK ~ Removing disinfection tools ... Deleted : C:\FRST Deleted : C:\AdwCleaner Deleted : C:\Users\Gebruiker\Desktop\AdwCleaner.exe Deleted : C:\Users\Gebruiker\Desktop\FRST64.exe Deleted : C:\Users\Gebruiker\Desktop\JRT.exe ~ Creating registry backup ... OK ~ Cleaning system restore ... Deleted : RP #12 [Gepland controlepunt | 08/13/2017 11:22:36] Deleted : RP #15 [JRT Pre-Junkware Removal | 08/16/2017 12:15:37] New restore point created ! ~ Resetting system settings ... OK ########## - EOF - ##########
  2. This is the page it leads me to, though I haven't had any message asking for money or bitcoin https://www.bleepingcomputer.com/news/security/truecrypter-ransomware-accepts-payment-in-bitcoins-or-amazon-gift-card/
  3. There seem to be no ads popping up, also no block anymore. Is it 'safe' again to save passwords on google chrome? Also my word/powerpoint/excel files were encrypted. Is there a way to fix this problem? They're all .ENC-files Thank you for your help!
  4. Yes, also still a russian site which opens.. There's a screenshot in attachment.
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.4 (07.09.2017) Operating System: Windows 10 Home x64 Ran by Gebruiker (Administrator) on wo 16/08/2017 at 14:15:32,63 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 1 Successfully deleted: C:\Users\Gebruiker\AppData\Roaming\dll-files.com (Folder) Registry: 3 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C606FF28-DCF4-4A54-BBDD-3A0FD80F7828} (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{C606FF28-DCF4-4A54-BBDD-3A0FD80F7828} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on wo 16/08/2017 at 14:20:29,69 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. # AdwCleaner 7.0.1.0 - Logfile created on Wed Aug 16 12:05:51 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 10 Home (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\ProgramData\Mail.Ru Deleted: C:\ProgramData\Application Data\Mail.Ru Deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Mail.Ru Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Mail.Ru Deleted: C:\Users\All Users\Mail.Ru Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics Deleted: C:\ProgramData\Auslogics Deleted: C:\ProgramData\Application Data\Auslogics Deleted: C:\Program Files (x86)\Auslogics Deleted: C:\Windows\SysNative\Tasks\Auslogics Deleted: C:\Users\All Users\Auslogics Deleted: C:\ProgramData\{C6FA530F-BB98-4D9F-BA00-45FD0698077C} ***** [ Files ] ***** Deleted: C:\Users\Gebruiker\Favorites\Mail.Ru.url Deleted: C:\Users\Gebruiker\Favorites\Mail.Ru Агент - используй для общения!.url ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\Mail.Ru Deleted: [Key] - HKU\.DEFAULT\Software\Mail.Ru Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Mail.Ru Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\AppDataLow\Software\Mail.Ru Deleted: [Key] - HKU\S-1-5-18\Software\Mail.Ru Deleted: [Key] - HKCU\Software\Mail.Ru Deleted: [Key] - HKCU\Software\AppDataLow\Software\Mail.Ru Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Xpom Deleted: [Key] - HKCU\Software\Xpom Deleted: [Key] - HKLM\SOFTWARE\CLASSES\CLSID\{278029E0-2347-4254-A65E-204AC55E2508} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\TYPELIB\{FE9301D5-9266-4A2F-8767-85482115CAB0} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\INTERFACE\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\APPID\{278029E0-2347-4254-A65E-204AC55E2508} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-00DB857103B2} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\INTERFACE\{6855F0CE-00B1-483F-8633-33B650EE4310} Deleted: [Key] - HKLM\SOFTWARE\CLASSES\APPID\{93469602-4134-4012-A6BC-D46FF1C671E9} Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ask.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\azlyrics.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\chrome.nl.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d30ke5tqu2tkyx.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d30ke5tqu2tkyx.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dasnice.be Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\divxcrawler.tv Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\gamingwonderland.dl.tb.ask.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\land.pckeeper.software Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pathways.nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pckeeper.software Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\safebrowsing.bullguard.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\solvusoft.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\st.chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\st.chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\winrar-64bit.nl.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.azlyrics.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.dasnice.be Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.divxcrawler.tv Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.solvusoft.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ask.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\azlyrics.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\chrome.nl.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d30ke5tqu2tkyx.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d30ke5tqu2tkyx.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dasnice.be Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\divxcrawler.tv Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\gamingwonderland.dl.tb.ask.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\land.pckeeper.software Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pathways.nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pckeeper.software Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\safebrowsing.bullguard.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\solvusoft.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\st.chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\st.chatango.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\winrar-64bit.nl.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.azlyrics.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.dasnice.be Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.divxcrawler.tv Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nice.org.uk Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.solvusoft.com Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{AF325768-7360-49D4-832F-C19B91616299}C:\users\gebruiker\appdata\local\popcorn time\nw.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{2E9729FD-F45D-4DAE-9731-1599D39579E4}C:\users\gebruiker\appdata\local\popcorn time\nw.exe Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Gosearchq Deleted: [Key] - HKCU\Software\Microsoft\Gosearchq Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Gosearch Deleted: [Key] - HKCU\Software\Microsoft\Gosearch Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\APN PIP Deleted: [Key] - HKCU\Software\APN PIP Deleted: [Key] - HKLM\SOFTWARE\PIP Deleted: [Key] - HKLM\SOFTWARE\mweshield Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{3E0DB45B-9FCC-4064-B48C-080BD03A99A4} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{C81BED3B-31BD-491F-813D-78EFC2638CE1} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{278029E0-2347-4254-A65E-204AC55E2508} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508} Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\flix123.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\flix123.com Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\MICROSOFT\KometaInstaller Deleted: [Key] - HKCU\Software\MICROSOFT\KometaInstaller Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\NETBOX\Kometa Deleted: [Key] - HKCU\Software\NETBOX\Kometa Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1 Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\ssn Deleted: [Key] - HKCU\Software\ssn Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\setupsk Deleted: [Key] - HKCU\Software\setupsk Deleted: [Key] - HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Amigo Deleted: [Key] - HKCU\Software\Amigo Deleted: [Key] - HKLM\SOFTWARE\Auslogics ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [20015 B] - [2017/8/16 12:2:17] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
  7. Fix resultaat van Farbar Recovery Scan Tool (x64) Versie: 12-08-2017 Gestart door Gebruiker (16-08-2017 10:47:31) Run:1 Gestart vanaf C:\Users\Gebruiker\Desktop Geladen Profielen: Gebruiker (Beschikbare Profielen: Gebruiker) Boot Modus: Normal ============================================== fixlist inhoud: ***************** CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\Run: [setupsk_upd] => "C:\Users\GEBRUI~1\AppData\Roaming\SETUPS~1\python\pythonw.exe" "C:\Users\GEBRUI~1\AppData\Roaming\SETUPS~1\ml.py" --APPNAME="setupsk_upd" <==== AANDACHT HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\Run: [setupsk] => "C:\Users\GEBRUI~1\AppData\Roaming\setupsk\python\pythonw.exe" "C:\Users\GEBRUI~1\AppData\Roaming\setupsk\ml.py" --APPNAME="setupsk" <==== AANDACHT HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\Run: [ycAutoLaunch_C99D706015ACEA666F13C434030273C2] => "C:\Users\Gebruiker\AppData\Local\yc\Application\yc.exe" /prefetch:5 HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\Run: [KometaLaunchPanel] => C:\Users\Gebruiker\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\Run: [StartButton] => C:\Users\Gebruiker\AppData\Local\Kometa\StartButton\kometastartvx64.exe GroupPolicy: Restrictie <==== AANDACHT GroupPolicy\User: Restrictie <==== AANDACHT Task: {5B36FF61-3355-4F38-BCF2-C761B45DAFF4} - System32\Tasks\DLL-Files.Com Fixer_Updates => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: {5E812DE3-A144-40FE-BCAA-287A4B6CBF5E} - System32\Tasks\DLL-Files FixerASKUSER => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: {9CDBAB1B-0599-4397-919C-26D442AB3D54} - System32\Tasks\DLL-Files.Com Fixer_MONTHLY => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: {A0FAD93D-461E-407B-B44A-425574E4E26C} - System32\Tasks\RDReminder => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\DLL-Files FixerASKUSER.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\WINDOWS\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\StartupApproved\Run: => "KometaLaunchPanel" HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\StartupApproved\Run: => "StartButton" HKU\S-1-5-21-404570740-1478191909-1450172760-1001\...\StartupApproved\Run: => "ycAutoLaunch_C99D706015ACEA666F13C434030273C2" FirewallRules: [{0B3669A5-04F1-45D7-94F3-D223159D7508}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{E72F0AA3-9E63-4680-8378-D715843000D1}] => (Allow) C:\Users\Gebruiker\AppData\Local\yc\Application\yc.exe C:\Program Files (x86)\Dll-Files.com Fixer C:\Users\Gebruiker\AppData\Local\yc C:\Users\Gebruiker\AppData\Local\Kometa C:\Users\GEBRUI~1\AppData\Roaming\SETUPS~1 C:\Users\GEBRUI~1\AppData\Roaming\setupsk EmptyTemp: ***************** Proces succesvol afgesloten. Herstelpunt is succesvol gemaakt. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\setupsk_upd => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\setupsk => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ycAutoLaunch_C99D706015ACEA666F13C434030273C2 => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\KometaLaunchPanel => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\StartButton => waarde is succesvol verwijderd C:\WINDOWS\system32\GroupPolicy\Machine => is succesvol verplaatst C:\WINDOWS\system32\GroupPolicy\GPT.ini => is succesvol verplaatst C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => is succesvol verplaatst C:\WINDOWS\system32\GroupPolicy\User => is succesvol verplaatst HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B36FF61-3355-4F38-BCF2-C761B45DAFF4} => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B36FF61-3355-4F38-BCF2-C761B45DAFF4} => sleutel is succesvol verwijderd C:\WINDOWS\System32\Tasks\DLL-Files.Com Fixer_Updates => is succesvol verplaatst HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DLL-Files.Com Fixer_Updates => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5E812DE3-A144-40FE-BCAA-287A4B6CBF5E} => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E812DE3-A144-40FE-BCAA-287A4B6CBF5E} => sleutel is succesvol verwijderd C:\WINDOWS\System32\Tasks\DLL-Files FixerASKUSER => is succesvol verplaatst HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DLL-Files FixerASKUSER => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9CDBAB1B-0599-4397-919C-26D442AB3D54} => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CDBAB1B-0599-4397-919C-26D442AB3D54} => sleutel is succesvol verwijderd C:\WINDOWS\System32\Tasks\DLL-Files.Com Fixer_MONTHLY => is succesvol verplaatst HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DLL-Files.Com Fixer_MONTHLY => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A0FAD93D-461E-407B-B44A-425574E4E26C} => sleutel is succesvol verwijderd HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0FAD93D-461E-407B-B44A-425574E4E26C} => sleutel is succesvol verwijderd C:\WINDOWS\System32\Tasks\RDReminder => is succesvol verplaatst HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RDReminder => sleutel is succesvol verwijderd C:\WINDOWS\Tasks\DLL-Files FixerASKUSER.job => is succesvol verplaatst C:\WINDOWS\Tasks\DLL-Files.Com Fixer_MONTHLY.job => is succesvol verplaatst C:\WINDOWS\Tasks\DLL-Files.Com Fixer_Updates.job => is succesvol verplaatst HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\KometaLaunchPanel => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KometaLaunchPanel => waarde niet gevonden. HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\StartButton => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\StartButton => waarde niet gevonden. HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\ycAutoLaunch_C99D706015ACEA666F13C434030273C2 => waarde is succesvol verwijderd HKU\S-1-5-21-404570740-1478191909-1450172760-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ycAutoLaunch_C99D706015ACEA666F13C434030273C2 => waarde niet gevonden. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0B3669A5-04F1-45D7-94F3-D223159D7508} => waarde is succesvol verwijderd HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E72F0AA3-9E63-4680-8378-D715843000D1} => waarde is succesvol verwijderd "C:\Program Files (x86)\Dll-Files.com Fixer" => niet gevonden. "C:\Users\Gebruiker\AppData\Local\yc" => niet gevonden. "C:\Users\Gebruiker\AppData\Local\Kometa" => niet gevonden. "C:\Users\GEBRUI~1\AppData\Roaming\SETUPS~1" => niet gevonden. "C:\Users\GEBRUI~1\AppData\Roaming\setupsk" => niet gevonden. =========== EmptyTemp: ========== BITS transfer queue => 7888896 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40807602 B Java, Flash, Steam htmlcache => 18777 B Windows/system/drivers => 16781709 B Edge => 281494623 B Chrome => 400318643 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 128 B LocalService => 29594 B NetworkService => 14096 B Gebruiker => 33603646 B RecycleBin => 0 B EmptyTemp: => 744.8 MB tijdelijke gegevens verwijderd. ================================ Het systeem moest herstart worden. ==== Eind van Fixlog 11:03:33 ====
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.