Hallo

Welkom, Gast. Alsjeblieft inloggen of registreren.

Recent

487 gasten, 0 leden

Welkom, Gast. Alsjeblieft inloggen of registreren.

27 april 2024, 23:13:27

Login met gebruikersnaam, wachtwoord en sessielengte

Nieuws

Welkom op het vernieuwde NL Computer Forum!

Auteur Topic: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?  (gelezen 56455 keer)

0 leden en 1 gast bekijken dit topic.

Offline Peter

  • Sysop
  • *****
  • Berichten: 5.683
  • Geslacht: Man
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #330 Gepost op: 16 januari 2013, 23:20:22 »
Hoi Maria,

Citaat
Hierbij  2 schermafdrukken
1e van Grieks programma
De-installeer maar.

Citaat
ik snap niet goed wat ik met dat Hijack moet doen of wat het doet op mijn pc
De bedoeling van RSIT is om een uitgebreider lijstje te krijgen van de geinstalleerde software om zo van die buitenlandse Windows Live onderdelen af te komen.
RSIT scant alleen je systeem. Het verandert niets en geeft kwaadwillenden geen toegang.


Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #331 Gepost op: 17 januari 2013, 00:12:44 »
Time Written: 20120216072655.328085-000
Event Type: Controle geslaagd
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Calibre2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=18
"PROCESSOR_IDENTIFIER"=AMD64 Family 18 Model 1 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0100
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"AMDAPPSDKROOT"=C:\Program Files (x86)\AMD APP\
"asl.log"=Destination=file

-----------------EOF-----------------

Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #332 Gepost op: 17 januari 2013, 00:13:15 »
Logfile of random's system information tool 1.09 (written by random/random)
Run by Swarts at 2013-01-17 00:10:29
Microsoft Windows 7 Home Premium  Service Pack 1
System drive C: has 806 GB (88%) free of 912 GB
Total RAM: 3576 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:10:45, on 17-1-2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Swarts.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O9 - Extra button: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing)
O9 - Extra 'Tools' menuitem: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing)
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.marktplaats.nl/js/widgets/imageUploader/aurigma/5_7_24_0/ImageUploader5.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #333 Gepost op: 17 januari 2013, 00:16:38 »

nd of file - 10437 bytes


======Listing Processes======


\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe /pipeName=ec89262c-e081-4b31-a028-4e0569720875 /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\5717080b-cb2b-4808-9e79-066607d60a1e-1ac-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2013\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2013" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe"
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2960
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3b4ddafa-0907-42c9-9606-eed92be24bbb -SystemEventPortName:HostProcess-6a9f5b63-f81e-46ab-8352-87a8f679a5ae -IoCancelEventPortName:HostProcess-856f6395-f8b6-4d66-94bc-4a8e53951290 -NonStateChangingEventPortName:HostProcess-f25db045-f0b9-444f-8705-410e40235207 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9d16a534-58c1-45fd-a302-46baa33d66ea -DeviceGroupId:WpdFsGroup
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
taskeng.exe {C8529B2E-5461-4808-BCD4-CA9C631C8438}
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Users\Swarts\Desktop\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe


======Scheduled tasks folder======


C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll []


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll []


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll []


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-12 461216]


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-12 170912]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-05-09 11821160]


[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-08 336384]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2013\avgui.exe [2012-12-11 3147384]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-08-27 59280]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2012-09-09 421776]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv

Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #334 Gepost op: 17 januari 2013, 00:17:23 »

=====File associations======


.js - edit - C:\Windows\System32\Notepad.exe %1


======List of files/folders created in the last 1 month======


2013-01-17 00:10:31 ----D---- C:\Program Files\trend micro
2013-01-17 00:10:29 ----D---- C:\rsit
2013-01-15 11:58:09 ----SHD---- C:\$RECYCLE.BIN
2013-01-13 22:35:27 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-01-13 22:35:27 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-01-13 22:35:27 ----A---- C:\Windows\SYSWOW64\java.exe
2013-01-13 16:35:34 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2013-01-13 12:08:27 ----D---- C:\ProgramData\Avira
2013-01-13 02:21:00 ----SHD---- C:\Windows\SYSWOW64\%APPDATA%
2013-01-13 02:02:04 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-13 02:02:04 ----A---- C:\Windows\system32\win32spl.dll
2013-01-13 02:01:54 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-13 02:01:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-13 02:01:54 ----A---- C:\Windows\system32\msxml6.dll
2013-01-13 02:01:54 ----A---- C:\Windows\system32\msxml3.dll
2013-01-13 02:01:53 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-13 02:01:53 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-13 02:01:53 ----A---- C:\Windows\system32\usp10.dll
2013-01-13 02:01:53 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-13 02:01:48 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-13 02:01:48 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-13 02:01:48 ----A---- C:\Windows\system32\Wpc.dll
2013-01-13 02:01:48 ----A---- C:\Windows\system32\gameux.dll
2013-01-13 02:01:28 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-13 02:01:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-13 02:01:26 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-13 02:01:26 ----A---- C:\Windows\system32\kernel32.dll
2013-01-13 02:01:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-13 02:01:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-13 02:01:25 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-13 02:01:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-13 02:01:25 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-13 02:01:25 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\wow64win.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\wow64.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\winsrv.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-13 02:01:25 ----A---- C:\Windows\system32\conhost.exe
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-13 02:01:24 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-13 02:01:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-13 02:01:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-13 02:01:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-13 02:01:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-13 02:01:21 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-13 02:01:20 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-13 02:01:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-13 02:01:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-13 02:01:18 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-13 02:01:18 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-13 02:01:17 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-13 02:01:00 ----A---- C:\Windows\system32\taskhost.exe
2013-01-13 02:00:59 ----A---- C:\Windows\system32\win32k.sys
2013-01-11 23:41:15 ----A---- C:\LOG.TXT
2013-01-11 21:33:12 ----A---- C:\log2.txt
2013-01-07 01:44:34 ----D---- C:\Windows\temp
2013-01-07 01:44:25 ----A---- C:\ComboFix.txt
2013-01-05 13:16:00 ----D---- C:\Windows\erdnt
2013-01-04 00:32:33 ----A---- C:\AdwCleaner[S2].txt
2013-01-03 00:37:31 ----A---- C:\AdwCleaner[S1].txt
2013-01-02 15:24:04 ----D---- C:\found.002
2013-01-01 15:03:44 ----D---- C:\found.001
2012-12-27 20:40:08 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2012-12-27 19:47:03 ----D---- C:\found.000
2012-12-27 18:51:30 ----D---- C:\ProgramData\HitmanPro
2012-12-27 18:51:00 ----D---- C:\ProgramData\Hitman Pro
2012-12-27 12:49:58 ----A---- C:\scu.dat
2012-12-27 02:35:09 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-27 02:35:09 ----A---- C:\Windows\system32\atmlib.dll
2012-12-27 02:35:08 ----A---- C:\Windows\system32\atmfd.dll
2012-12-27 02:35:07 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-26 21:46:00 ----D---- C:\Users\Swarts\AppData\Roaming\Malwarebytes
2012-12-26 21:45:41 ----D---- C:\ProgramData\Malwarebytes


======List of files/folders modified in the last 1 month======


2013-01-17 00:10:45 ----D---- C:\Windows\Prefetch
2013-01-17 00:10:31 ----RD---- C:\Program Files
2013-01-17 00:10:22 ----SHD---- C:\Windows\Installer
2013-01-17 00:10:04 ----SHD---- C:\System Volume Information
2013-01-16 21:08:47 ----D---- C:\Windows\system32\config
2013-01-16 19:22:10 ----D---- C:\Windows\system32\catroot2
2013-01-16 17:50:34 ----D---- C:\ProgramData\MFAData
2013-01-16 09:49:31 ----D---- C:\Program Files\Google
2013-01-16 09:49:31 ----D---- C:\Program Files (x86)\Google
2013-01-16 00:00:50 ----D---- C:\ProgramData\Google
2013-01-15 11:58:10 ----D---- C:\Windows\SYSWOW64\drivers
2013-01-15 01:13:39 ----D---- C:\Windows
2013-01-15 00:47:33 ----D---- C:\Windows\system32\drivers
2013-01-14 21:32:31 ----D---- C:\Windows\System32
2013-01-14 21:32:31 ----D---- C:\Windows\inf
2013-01-14 21:32:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-13 22:35:27 ----D---- C:\Windows\SysWOW64
2013-01-13 22:35:27 ----D---- C:\Program Files (x86)\Java
2013-01-13 17:23:53 ----D---- C:\Windows\rescache
2013-01-13 16:37:16 ----D---- C:\Program Files (x86)\Common Files
2013-01-13 16:34:12 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-01-13 14:53:37 ----RD---- C:\Program Files (x86)
2013-01-13 13:45:06 ----D---- C:\ProgramData
2013-01-13 13:40:38 ----D---- C:\Windows\system32\Tasks
2013-01-13 13:23:12 ----D---- C:\Windows\Microsoft.NET
2013-01-13 13:23:04 ----RSD---- C:\Windows\assembly
2013-01-13 12:09:26 ----D---- C:\Windows\system32\catroot
2013-01-13 12:09:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-01-13 11:30:08 ----D---- C:\Windows\winsxs
2013-01-13 11:28:10 ----D---- C:\Windows\SYSWOW64\nl-NL
2013-01-13 11:28:09 ----D---- C:\Windows\system32\nl-NL
2013-01-13 11:28:04 ----D---- C:\Windows\AppPatch
2013-01-13 02:26:41 ----D---- C:\ProgramData\Microsoft Help
2013-01-13 02:19:26 ----A---- C:\Windows\system32\MRT.exe
2013-01-12 13:08:45 ----D---- C:\Windows\system32\NDF
2013-01-07 01:29:06 ----A---- C:\Windows\system.ini
2013-01-07 01:28:47 ----D---- C:\Program Files (x86)\Windows Defender
2013-01-07 01:26:42 ----D---- C:\Windows\system32\drivers\etc
2013-01-04 21:28:55 ----D---- C:\Users\Swarts\AppData\Roaming\Skype
2013-01-04 00:19:35 ----SD---- C:\ProgramData\Microsoft
2013-01-02 15:09:04 ----A---- C:\Windows\win.ini
2012-12-27 20:40:34 ----RSD---- C:\Windows\Fonts
2012-12-27 20:40:28 ----D---- C:\Program Files (x86)\Microsoft Works
2012-12-27 20:40:20 ----D---- C:\Program Files (x86)\MSBuild
2012-12-27 20:39:58 ----D---- C:\Windows\ShellNew
2012-12-27 20:31:01 ----D---- C:\Windows\Tasks
2012-12-27 19:59:05 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-27 19:59:02 ----D---- C:\Program Files (x86)\CyberLink
2012-12-27 19:53:07 ----D---- C:\Program Files (x86)\Vose Software
2012-12-27 19:18:34 ----D---- C:\Users\Swarts\AppData\Roaming\BitTorrent
2012-12-27 00:35:27 ----D---- C:\Windows\Downloaded Program Files
2012-12-26 21:32:09 ----D---- C:\Windows\system32\wbem
2012-12-26 21:31:04 ----D---- C:\Windows\system32\wfp
2012-12-26 21:31:04 ----D---- C:\Windows\system32\DriverStore
2012-12-26 21:31:04 ----D---- C:\Program Files\Internet Explorer
2012-12-26 21:30:54 ----D---- C:\Windows\AppCompat
2012-12-26 21:30:33 ----D---- C:\Windows\registration
2012-12-26 21:29:47 ----D---- C:\ProgramData\Skype
2012-12-26 21:29:45 ----D---- C:\ProgramData\Apple Computer
2012-12-26 21:29:45 ----D---- C:\ProgramData\Apple
2012-12-26 21:29:45 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-26 21:29:45 ----D---- C:\Program Files\iTunes
2012-12-26 21:29:45 ----D---- C:\Program Files\iPod
2012-12-26 21:29:44 ----RD---- C:\Program Files (x86)\Skype
2012-12-26 21:29:44 ----D---- C:\Program Files\Common Files\Apple
2012-12-26 21:29:44 ----D---- C:\Program Files (x86)\iTunes
2012-12-26 21:29:26 ----D---- C:\Program Files (x86)\Apple Software Update


======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======


R0 amd_sata;amd_sata; C:\Windows\system32\drivers\amd_sata.sys [2011-04-16 79488]
R0 amd_xata;amd_xata; C:\Windows\system32\drivers\amd_xata.sys [2011-04-16 40064]
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2012-11-15 111968]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2012-11-09 30568]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Afc;PPdus ASPI Shell; C:\Windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdhub30;AMD USB 3.0 Hub Driver; C:\Windows\system32\drivers\amdhub30.sys [2011-03-18 87168]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\drivers\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-08 9884672]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-08 307712]
R3 amdxhc;AMD USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\amdxhc.sys [2011-03-18 188544]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-06-07 231440]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-05-10 2861288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-05-16 533096]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-12-16 47232]
R3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
S3 LVUVC64;Logitech Webcam 250(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-07-09 52736]
S3 VCR2PC;VCR2PC Analog Capture; C:\Windows\system32\DRIVERS\0140_ION.sys [2011-10-18 301504]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 wsvd;wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [2010-09-23 129008]


======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======


R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-08 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-08 365568]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 UMVPFSrv;UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2012-09-09 936848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-04 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-13 251400]
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-04 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-11-13 419624]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-04 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]


-----------------EOF-----------------


Offline Peter

  • Sysop
  • *****
  • Berichten: 5.683
  • Geslacht: Man
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #335 Gepost op: 17 januari 2013, 19:16:55 »
Hoi Maria,

Citaat
In de map C:\RSIT verschijnen nu 2 logbestanden: log.txt en info.txt
Post deze 2 bestanden als bijlage in een nieuw bericht.
Ik mis het een en ander.
Even goed lezen en opnieuw de 2 bestanden als bijlage posten aub, niet in een bericht plakken.


Peter





Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #336 Gepost op: 17 januari 2013, 19:22:52 »
Dag Peter,


wat me vandaag opviel als ik explorer per ongeluk startte, b.v als ik op een link klik,


dat google wel snel zichtbaar wordt , ook de gevonden items, maar dat het dan heel lang duurt voordat een site geladen wordt.




Als ik op verversen klik blijft het ook  heel lang zoeken,


Wie weet help het je


ik hoor weer graag van je


Met vriendelijke groet, Maria



Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #337 Gepost op: 17 januari 2013, 19:24:56 »
hier zijn ze als bijlage


Maria

Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #338 Gepost op: 17 januari 2013, 19:27:15 »
hier rechtstreeks van C:Rsit
vorige had ik zelf meteen ergens opgeslagen maar zouden hetzelfde moeten zijn




Offline Peter

  • Sysop
  • *****
  • Berichten: 5.683
  • Geslacht: Man
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #339 Gepost op: 17 januari 2013, 21:14:30 »
Hoi Maria,

We gaan wat restanten verwijderen, o.a. van AVG 2012.
 
Sluit eerst Internet Explorer
Open Kladblok
Kopieer en plak daarin onderstaande tekst:
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKLM\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
reg delete "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" /f
sc stop catchme
sc delete catchme

Klik op menu Bestand - Opslaan als
Geef als naam remove.bat, selecteer bij "Opslaan als" Alle bestanden en bewaar het op je bureaublad.
Sluit Kladblok

Dubbelklik op remove.bat

Hoe werkt Internet Explorer nu?

Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #340 Gepost op: 17 januari 2013, 21:30:34 »
helaas nog net zo traag.... :(
 Maria

Offline Peter

  • Sysop
  • *****
  • Berichten: 5.683
  • Geslacht: Man
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #341 Gepost op: 17 januari 2013, 22:07:18 »
Hmm, doe eens het volgende:

Start de Opdrachtprompt met administrator rechten.
Kopieer en plak daarin:
MsiExec.exe /X{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}
en druk op Enter
Bevestig de installatie van het programma

Wordt nu dat 'Griekse' onderdeel van Windows Live wel verwijdert en is het ook uit de lijst van geïnstalleerde programma's verdwenen?


Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #342 Gepost op: 17 januari 2013, 22:40:16 »
het griekse programma is al van mijn computer verwijderd.
Tenminste het is niet zichtbaar bij programma's


is het volgens jou nog wel op de computer ergens?


hoe kan ik dan controleren of het weg is?


Ik hoor graag van je


Maria

Offline Peter

  • Sysop
  • *****
  • Berichten: 5.683
  • Geslacht: Man
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #343 Gepost op: 17 januari 2013, 22:47:31 »
Citaat
het griekse programma is al van mijn computer verwijderd.
O, ik zit niet op te letten...

Voer dan eens deze regel uit in de Opdrachtprompt:
MsiExec.exe /X{E59969EA-3B5B-4B24-8B94-43842A7FBFE9}

Daarmee hoort "Fotogalerija Windows Live" verwijdert te worden. Klopt dat?


Start Internet Explorer
Klik rechtsboven oo het tandwieltje en dan op "Over Internet Explorer"
Maak nu een screenshot en post dat als bijlage.



Offline mariavo
  • Forumfan
  • ***
  • Berichten: 229
  • Geslacht: Vrouw
Re: outlook start niet meer op , scanspt.exe gevonden, wat nu nakijken?
« Reactie #344 Gepost op: 17 januari 2013, 22:58:50 »
die kon ik de eerste keer al niet vinden, stond niet in het rijtje samen met de andere die ik opgenoemd heb,
Ik heb ze niet kunnen verwijderen omdat ze er allemaal niet in stonden...


 Sorry als ik onduidelijk was