Re: weer veel reclame pop-ups, met name bij Na.Comp.For.
Ja, dat begrijp ik wel dat FF niet zo maar 1,2,3, verwijderd kan worden.
Hier het ADW log (39 bedreigingen gevonden)
# AdwCleaner v6.045 - Logfile created 31/03/2017 at 18:59:45
# Updated on 28/03/2017 by Malwarebytes
# Database : 2017-03-30.1 [Server]
# Operating System : Windows 10 Home (X64)
# Username : F.J.Stols - AZERTY
# Running from : C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\INetCache\IE\R8KDAHJJ\adwcleaner_6.045.exe
# Mode: Scan
# Support :
https://www.malwarebytes.com/support
***** [ Services ] *****
Service Found: WinSAPSvc
Service Found: WinSnare
Service Found: FirefoxDL
Service Found: Kyubey
***** [ Folders ] *****
Folder Found: C:\Users\Gebruiker\AppData\Roaming\Kyubey
Folder Found: C:\Users\Gebruiker\AppData\Roaming\Wise Euask
Folder Found: C:\WINDOWS\SysNative\Tasks\WiseCleaner
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Folder Found: C:\Program Files (x86)\deskapp
Folder Found: C:\Program Files (x86)\Firefox
Folder Found: C:\Users\Gebruiker\AppData\Roaming\Firefox
Folder Found: C:\Users\Gebruiker\AppData\Local\Firefox
***** [ Files ] *****
File Found: C:\Users\Public\Documents\temp.dat
File Found: C:\Users\Public\Documents\report.dat
File Found: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\guykot6p.default-1469904827259\searchplugins\startpageing123.xml
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious keys found.
***** [ Shortcuts ] *****
Shortcut infected: C:\Users\Gebruiker\Desktop\Internet Explorer.lnk ( hxxp://www.startpageing123.com/?type=sc&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o4z5zcg&from=che0812&uid=WDCXWD10EZEX-00ZF5A0_WD-WCC1S1590
Shortcut infected: C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk ( hxxp://www.startpageing123.com/?type=sc&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6
Shortcut infected: C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ( hxxp://www.startpageing123.com/?type=sc&ts=1490952441&z=a762b2b8cc120951740c781g
***** [ Scheduled Tasks ] *****
Task Found: Milimili
Task Found: WiseCleaner
***** [ Registry ] *****
Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found: HKU\S-1-5-21-1916800224-2560957495-3225600593-1001\Software\deskapp
Key Found: HKCU\Software\deskapp
Key Found: HKLM\SOFTWARE\ScreenShot
Key Found: HKLM\SOFTWARE\startpageing123Software
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{59B5A9CD-253D-4C41-A073-B387D4C9672D}
Key Found: [x64] HKCU\Software\deskapp
Key Found: [x64] HKLM\SOFTWARE\InterSect Alliance
Data Found: HKU\S-1-5-21-1916800224-2560957495-3225600593-1001\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o
Data Found: HKU\S-1-5-21-1916800224-2560957495-3225600593-1001\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4tae
Data Found: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o4z5zcg&from=che0812&uid=WDCXWD10EZEX-00ZF5A0_W
Data Found: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o4z5zcg&from=che0812&uid=WDCXWD10EZEX-00Z
Data Found: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o4z5zcg&from=che0812&uid=WDCXWD10EZEX-00ZF5A0
Data Found: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.startpageing123.com/?type=hp&ts=1490952441&z=a762b2b8cc120951740c781gfz4taeet4w6o4z5zcg&from=che0812&uid=WDCXWD10EZEX-0
Key Found: HKU\S-1-5-21-1916800224-2560957495-3225600593-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Found: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
***** [ Web browsers ] *****
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [1422 Bytes] - [13/03/2017 17:13:50]
C:\AdwCleaner\AdwCleaner[C2].txt - [7230 Bytes] - [15/03/2017 09:40:12]
C:\AdwCleaner\AdwCleaner[S0].txt - [1497 Bytes] - [13/03/2017 17:13:34]
C:\AdwCleaner\AdwCleaner[S1].txt - [9183 Bytes] - [15/03/2017 09:39:10]
C:\AdwCleaner\AdwCleaner[S2].txt - [1946 Bytes] - [20/03/2017 13:06:48]
C:\AdwCleaner\AdwCleaner[S3].txt - [5071 Bytes] - [31/03/2017 18:59:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [5144 Bytes] ##########
en hier een heel kort JRT logje:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.2 (03.10.2017)
Operating System: Windows 10 Home x64
Ran by F.J.Stols (Administrator) on vr 31-03-2017 at 18:52:55,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 2
Successfully deleted: C:\ProgramData\ytd video downloader (Folder)
Successfully deleted: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\guykot6p.default-1469904827259\extensions\trash (Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on vr 31-03-2017 at 18:55:33,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~