Bedankt hierbij de beide logs!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.2 (03.10.2017)
Operating System: Windows 10 Pro x64
Ran by Marijn (Administrator) on di 14-03-2017 at 18:01:42,04
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 12
Failed to delete: C:\Program Files (x86)\Common Files\avg secure search\vtoolbarupdater (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0116av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0316av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0415av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0615av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0715av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_0915av (Folder)
Successfully deleted: C:\ProgramData\Avg_Update_1215av (Folder)
Successfully deleted: C:\Users\Marijn\AppData\Roaming\Mozilla\Firefox\Profiles\ooo1wrh2.default-1424354465315\searchplugins\avg-secure-search.xml (File)
Successfully deleted: C:\WINDOWS\Tasks\0415avUpdateInfo.job (Task)
Successfully deleted: C:\WINDOWS\Tasks\0615avUpdateInfo.job (Task)
Successfully deleted: C:\WINDOWS\Tasks\0715avUpdateInfo.job (Task)
Registry: 6
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\vToolbarUpdater40.3.7 (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on di 14-03-2017 at 18:02:18,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
En de tweede
# AdwCleaner v6.044 - Logbestand aangemaakt 14/03/2017 op 18:15:45
# Bijgewerkt op 28/02/2017 door Malwarebytes
# Database : 2017-03-14.1 [Server]
# Besturingssysteem : Windows 10 Pro (X64)
# Gebruikersnaam : Marijn - MARIJN
# Gestart vanuit : C:\Users\Marijn\Desktop\adwcleaner_6.044.exe
# Mode: Verwijderen
# Ondersteuning :
https://www.malwarebytes.com/support
***** [ Services ] *****
[-] Service verwijderd: WtuSystemSupport
[-] Service verwijderd: Update service
***** [ Mappen ] *****
[-] Map verwijderd: C:\ProgramData\Avg_Update_0215avt
[-] Map verwijderd: C:\Users\Marijn\AppData\Local\avg web tuneup
[-] Map verwijderd: C:\Program Files\avg web tuneup
[-] Map verwijderd: C:\Program Files\Common Files\AVG Secure Search
[-] Map verwijderd: C:\ProgramData\avg web tuneup
[#] Map verwijderd tijdens herstart: C:\ProgramData\Application Data\avg web tuneup
[-] Map verwijderd: C:\Program Files (x86)\avg web tuneup
[-] Map verwijderd: C:\Program Files (x86)\Common Files\AVG Secure Search
***** [ Bestanden ] *****
[-] Bestand verwijderd: C:\Users\Marijn\AppData\Roaming\Mozilla\Firefox\Profiles\ooo1wrh2.default-1424354465315\extensions\Avg@toolbar.xpi
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Snelkoppelingen ] *****
***** [ Geplande Taken ] *****
***** [ Register ] *****
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Sleutel verwijderd: HKLM\SOFTWARE\AVG Tuneup
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\AVG Secure Search
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
[-] Waarde verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt]
[-] Sleutel verwijderd: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Sleutel verwijderd: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
***** [ Browsers ] *****
*************************
:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [4747 bytes] - [14/03/2017 18:15:45]
C:\AdwCleaner\AdwCleaner[S0].txt - [4729 bytes] - [14/03/2017 18:14:49]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4893 bytes] ##########