Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 15-03-2017 Gestart door Sippo (Beheerder) op SIPPO-PC (16-03-2017 20:48:16) Gestart vanaf C:\Users\Sippo\Desktop Geladen Profielen: Sippo (Beschikbare Profielen: Sippo & DefaultAppPool) Platform: Windows 10 Home Versie 1607 (X64) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1") Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (AMD) C:\Windows\System32\atiesrxx.exe (IEC) C:\Program Files (x86)\BikaQRss\BikaQ.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe () C:\Users\Sippo\AppData\Roaming\Kyubey\Kyubey.exe (NCP engineering GmbH) C:\Program Files (x86)\NCP\SecureClient\ncpclcfg.exe (NCP Engineering GmbH) C:\Program Files (x86)\NCP\SecureClient\ncprwsnt.exe () C:\Program Files (x86)\NCP\SecureClient\ncpsec.exe (NCP engineering GmbH) C:\Program Files (x86)\NCP\SecureClient\rwsrsu.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (AMD) C:\Windows\System32\atieclxx.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe ==================== Register (gefilterd) ==================== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [MRT] => C:\WINDOWS\system32\MRT.exe [138634176 2017-03-15] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-10] (AVAST Software) HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\...\MountPoints2: {87397d1d-368c-11e5-9bc2-806e6f6e6963} - "F:\grbnew\groenwin.exe" HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [456224 2010-07-29] () ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-10] (AVAST Software) ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{646f4ae7-2a8c-41ac-981c-39c212b05ed8}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{bdf78266-c677-45e9-9bc8-7ad5d189fdf3}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131340695127494432&GUID=A68DA5DC-DA75-41A8-9AE8-E50911452EBC HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms} HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX HKU\S-1-5-21-3808174966-3550055594-1478129862-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 SearchScopes: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} SearchScopes: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 SearchScopes: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> {EEF338A5-41AF-4934-8C0A-8BCCA4B10F06} URL = hxxps://www.google.com/search?q={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation) BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.) BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.) BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-10] (Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-10] (Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-3808174966-3550055594-1478129862-1000 -> hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX FireFox: ======== FF ProfilePath: C:\Users\Sippo\AppData\Roaming\TomTom\HOME\Profiles\w1iwm6sy.default [2016-12-17] FF Extension: (Emulator) - C:\Users\Sippo\AppData\Roaming\TomTom\HOME\Profiles\w1iwm6sy.default\Extensions\Navcore.9.540.1497205@tomtom.com [2016-12-17] [ niet getekend] FF Extension: (Geen Naam) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [niet gevonden] FF ProfilePath: C:\Users\Sippo\AppData\Roaming\Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112 [2017-03-16] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112 -> Google FF SelectedSearchEngine: Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112 -> Google FF Homepage: Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112 -> hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX FF Extension: (Adblock Plus) - C:\Users\Sippo\AppData\Roaming\Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23] FF SearchPlugin: C:\Users\Sippo\AppData\Roaming\Mozilla\Firefox\Profiles\huirt2q0.default-1448099985112\searchplugins\startpageing123.xml [2017-03-16] FF ProfilePath: C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112 [2017-03-16] FF SelectedSearchEngine: Firefox\Firefox\Profiles\huirt2q0.default-1448099985112 -> Google FF Extension: (SimilarWeb) - C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-03-16] [ niet getekend] FF Extension: (FF Adr) - C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-03-16] [ niet getekend] FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112\Extensions\langpack-nl@firefox.mozilla.org.xpi [2017-03-16] [ niet getekend] FF Extension: (Adblock Plus) - C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23] FF SearchPlugin: C:\Users\Sippo\AppData\Roaming\Firefox\Firefox\Profiles\huirt2q0.default-1448099985112\searchplugins\startsearch.xml [2017-03-16] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-10] FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-10] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-03-04] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-03-04] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-10] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-10] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [Geen bestand] FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX Chrome: ======= CHR DefaultProfile: ChromeDefaultData CHR HomePage: ChromeDefaultData -> hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX CHR StartupUrls: ChromeDefaultData -> "hxxp://www.startpageing123.com/?type=hp&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX" CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.startpageing123.com/search/?type=ds&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX&q={searchTerms} CHR DefaultSearchKeyword: ChromeDefaultData -> startpageing123 CHR Profile: C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-16] <==== AANDACHT CHR Extension: (Google Presentaties) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-05] CHR Extension: (Google Documenten) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05] CHR Extension: (Google Drive) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07] CHR Extension: (YouTube) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26] CHR Extension: (Google Search) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08] CHR Extension: (Fair AdBlocker App (by STANDS)) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\dcnofaichneijfbkdkghmhjjbepjmble [2016-09-03] CHR Extension: (Google Spreadsheets) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-05] CHR Extension: (Offline Documenten) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19] CHR Extension: (Adblocker voor Youtube™) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-03-10] CHR Extension: (Fair AdBlocker (by STANDS)) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lgblnfidahcdcjddiepkckcfdhpknnjh [2017-03-10] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10] CHR Extension: (Gmail) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR Extension: (Chrome Media Router) - C:\Users\Sippo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.startpageing123.com/?type=sc&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX Opera: ======= StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.startpageing123.com/?type=sc&ts=1489664067&z=de3e0df172e08e7feee1077gbzdb2tcq1q0z8e3qdm&from=che0812&uid=HitachiXHTS547550A9E384_J2160051H6AZPDH6AZPDX ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 AdvancedSystemCareService10; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [462624 2016-10-14] (IObit) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [Bestand niet getekend] S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 AppleSrv; C:\ProgramData\Apple\Apple Application\DeviceCfg.dll [118784 2017-03-15] () [Bestand niet getekend] R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-10] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-10] (AVAST Software) S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2015\DfsdkS64.exe [544768 2009-08-24] (mst software GmbH, Germany) [Bestand niet getekend] R2 Kyubey; C:\Users\Sippo\AppData\Roaming\Kyubey\Kyubey.exe [113152 2017-03-16] () [Bestand niet getekend] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 ncpclcfg; C:\Program Files (x86)\NCP\SecureClient\ncpclcfg.exe [575752 2015-11-26] (NCP engineering GmbH) R2 ncprwsnt; C:\Program Files (x86)\NCP\SecureClient\ncprwsnt.exe [1863944 2015-11-26] (NCP Engineering GmbH) R2 ncpsec; C:\Program Files (x86)\NCP\SecureClient\ncpsec.exe [125440 2015-11-26] () [Bestand niet getekend] S3 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation) R2 rwsrsu; C:\Program Files (x86)\NCP\SecureClient\rwsrsu.exe [869128 2015-11-26] (NCP engineering GmbH) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2017-01-17] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) R2 WinSAPSvc; C:\Users\Sippo\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-03-16] (Windows) [Bestand niet getekend] R2 WinSnare; C:\Users\Sippo\AppData\Roaming\WinSnare\WinSnare.dll [776704 2017-03-16] (InterSect Alliance Pty Ltd) [Bestand niet getekend] <==== AANDACHT S2 ed2kidle; "C:\Program Files (x86)\amulell\ed2k.exe" -downloadwhenidle [X] S2 FirefoxU; "C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe" [X] ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [229056 2014-10-28] (AppEx Networks Corporation) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [309272 2017-03-10] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [189768 2017-03-10] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334600 2017-03-10] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [48528 2017-03-10] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-03-10] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32088 2017-03-10] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [126600 2017-03-10] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [100640 2017-03-10] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-03-10] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [993608 2017-03-10] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [548928 2017-03-10] (AVAST Software) R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [162528 2017-03-10] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [337592 2017-03-14] (AVAST Software) R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2016-03-31] (Advanced Micro Devices) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77408 2017-02-24] () R1 FNETURPX; C:\WINDOWS\SysWOW64\drivers\FNETURPX.SYS [16648 2015-10-13] (FNet Co., Ltd.) S3 fwdrv; C:\WINDOWS\system32\DRIVERS\fwdrv.sys [27840 2014-03-22] (Web Solution Mart) S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [54736 2017-03-12] () R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-12-08] (REALiX(tm)) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-03-16] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-03-16] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-16] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [92088 2017-03-16] (Malwarebytes) S3 ncpfilt; C:\WINDOWS\system32\DRIVERS\ncplelhp.sys [110864 2015-11-26] (NCP Engineering GmbH) R3 ncplelhp; C:\WINDOWS\System32\drivers\ncplelhp.sys [110864 2015-11-26] (NCP Engineering GmbH) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [407768 2015-12-11] (Realsil Semiconductor Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tapSF0901; C:\WINDOWS\System32\DRIVERS\tapSF0901.sys [39104 2015-05-13] (Spotflux, Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-03-12] (Zemana Ltd.) R0 ZAM_EarlyBoot; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-03-12] (Zemana Ltd.) R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-03-12] (Zemana Ltd.) U3 idsvc; geen ImagePath ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Aangemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-03-16 15:05 - 2017-03-16 15:05 - 00000000 _____ C:\WINDOWS\SysWOW64\1 2017-03-16 15:01 - 2017-03-16 15:01 - 00000008 __RSH C:\Users\Sippo\ntuser.pol 2017-03-16 15:01 - 2017-03-16 15:01 - 00000008 __RSH C:\ProgramData\ntuser.pol 2017-03-16 15:00 - 2017-03-16 20:48 - 00072490 _____ C:\WINDOWS\ZAM.krnl.trace 2017-03-16 15:00 - 2017-03-16 20:48 - 00038003 _____ C:\WINDOWS\ZAM_Guard.krnl.trace 2017-03-16 15:00 - 2017-03-16 15:00 - 00464208 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-03-16 14:56 - 2017-03-16 14:58 - 00013944 _____ C:\Users\Sippo\Desktop\Fixlog.txt 2017-03-16 14:42 - 2017-03-16 14:42 - 00003346 _____ C:\Users\Sippo\Downloads\fixlist.txt 2017-03-16 12:35 - 2017-03-16 12:35 - 00000000 ____D C:\Users\Sippo\AppData\Local\Hipmy 2017-03-16 12:35 - 2017-03-16 12:35 - 00000000 ____D C:\Program Files (x86)\Hipmy 2017-03-16 12:34 - 2017-03-16 15:03 - 00000000 _____ C:\Users\Public\Documents\temp.dat 2017-03-16 12:34 - 2017-03-16 12:34 - 00000394 _____ C:\WINDOWS\SysWOW64\data.bin 2017-03-16 12:34 - 2017-03-16 12:34 - 00000000 ____D C:\Users\Sippo\AppData\Local\Firefox 2017-03-16 12:33 - 2017-03-16 14:43 - 00000000 _____ C:\Users\Public\Documents\report.dat 2017-03-16 12:33 - 2017-03-16 12:37 - 00000000 _____ C:\WINDOWS\SysWOW64\4 2017-03-16 12:33 - 2017-03-16 12:37 - 00000000 _____ C:\WINDOWS\SysWOW64\3 2017-03-16 12:33 - 2017-03-16 12:33 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Firefox 2017-03-16 12:33 - 2017-03-16 12:33 - 00000000 ____D C:\Program Files (x86)\Firefox 2017-03-16 12:33 - 2017-03-16 12:33 - 00000000 ____D C:\Program Files (x86)\58CA77F9_cacayima 2017-03-16 12:32 - 2017-03-16 15:04 - 00000000 ____D C:\Program Files (x86)\amulell 2017-03-16 12:32 - 2017-03-16 12:32 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC 2017-03-16 12:32 - 2017-03-16 12:32 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\aMule 2017-03-16 12:31 - 2017-03-16 15:56 - 00000000 ____D C:\Program Files (x86)\MIO 2017-03-16 12:31 - 2017-03-16 12:32 - 00003674 _____ C:\WINDOWS\System32\Tasks\Milimili 2017-03-16 12:31 - 2017-03-16 12:32 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.3.2) 2017-03-16 12:31 - 2017-03-16 12:32 - 00000000 ____D C:\Program Files (x86)\BikaQRss 2017-03-16 12:31 - 2017-03-16 12:31 - 00003328 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel 2017-03-16 12:31 - 2017-03-16 12:31 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\WinSnare 2017-03-16 12:31 - 2017-03-16 12:31 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\WinSAPSvc 2017-03-16 12:31 - 2017-03-16 12:31 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Kyubey 2017-03-16 12:31 - 2017-03-16 12:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ 2017-03-16 12:28 - 2017-03-16 12:31 - 00000000 ____D C:\Program Files (x86)\MK 2017-03-15 17:56 - 2017-03-16 15:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-15 17:38 - 2017-03-16 12:35 - 00002178 _____ C:\Users\Sippo\Desktop\Google Chrome.lnk 2017-03-15 17:27 - 2017-03-10 06:17 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-03-15 17:27 - 2017-03-10 06:17 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-03-15 16:58 - 2017-03-16 14:52 - 00060998 _____ C:\Users\Sippo\Desktop\Addition.txt 2017-03-15 16:54 - 2017-03-16 20:50 - 00029947 _____ C:\Users\Sippo\Desktop\FRST.txt 2017-03-15 16:54 - 2017-03-16 20:48 - 00000000 ____D C:\FRST 2017-03-15 16:52 - 2017-03-15 16:52 - 02424832 _____ (Farbar) C:\Users\Sippo\Desktop\FRST64.exe 2017-03-14 19:31 - 2017-03-14 19:31 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-03-14 17:16 - 2017-03-14 17:16 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys 2017-03-14 17:09 - 2017-03-14 17:10 - 00000000 ____D C:\ProgramData\ProductData 2017-03-14 17:03 - 2017-03-14 17:03 - 00005899 _____ C:\Users\Sippo\Documents\JRT.txt 2017-03-14 16:58 - 2017-03-14 16:58 - 00005899 _____ C:\Users\Sippo\Desktop\JRT.txt 2017-03-14 16:50 - 2017-03-14 16:50 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2017-03-14 06:51 - 2017-03-14 06:51 - 00000000 ____D C:\WINDOWS\pss 2017-03-13 19:23 - 2017-03-13 19:23 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sippo\Downloads\HijackThis(1).exe 2017-03-13 19:19 - 2017-03-14 06:55 - 00000000 ____D C:\Users\Sippo\Downloads\backups 2017-03-13 19:12 - 2017-03-13 19:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sippo\Downloads\HijackThis.exe 2017-03-12 14:51 - 2017-03-12 14:51 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A} 2017-03-12 14:44 - 2017-03-12 14:44 - 00000000 ____D C:\Users\TEMP.Sippo-PC.000\AppData\Roaming\AVAST Software 2017-03-12 14:29 - 2017-03-12 14:44 - 00000000 ____D C:\Users\TEMP.Sippo-PC.000\AppData\Local\Packages 2017-03-12 14:27 - 2017-03-12 14:44 - 00000000 ____D C:\Users\TEMP.Sippo-PC.000 2017-03-12 14:24 - 2017-03-12 14:24 - 00002010 _____ C:\WINDOWS\system32\.crusader 2017-03-12 13:42 - 2017-03-12 14:26 - 00054736 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys 2017-03-12 13:41 - 2017-03-12 14:25 - 00000000 ____D C:\ProgramData\HitmanPro 2017-03-12 13:40 - 2017-03-12 13:41 - 11581544 _____ (SurfRight B.V.) C:\Users\Sippo\Downloads\HitmanPro_x64.exe 2017-03-12 12:31 - 2017-03-12 12:31 - 00003276 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-03-12 12:19 - 2017-03-12 12:19 - 00000000 ____D C:\Users\TEMP.Sippo-PC\AppData\Roaming\AVAST Software 2017-03-12 12:05 - 2017-03-12 12:39 - 00000000 ____D C:\Users\TEMP.Sippo-PC\AppData\Local\Packages 2017-03-12 12:04 - 2017-03-12 12:39 - 00000000 ____D C:\Users\TEMP.Sippo-PC 2017-03-12 11:55 - 2017-03-12 12:03 - 00000000 ____D C:\Users\TEMP 2017-03-12 11:12 - 2017-03-16 20:16 - 00092088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-03-12 11:12 - 2017-03-16 15:02 - 00186304 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-03-12 11:12 - 2017-03-14 06:53 - 00111544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-03-12 11:11 - 2017-03-16 15:02 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-03-12 11:11 - 2017-03-16 15:01 - 00251840 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-03-12 11:11 - 2017-03-12 11:11 - 00001924 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-03-12 11:10 - 2017-03-12 11:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-12 11:10 - 2017-03-12 11:10 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-12 11:10 - 2017-02-24 06:23 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-03-12 10:52 - 2017-03-12 10:53 - 57131432 _____ (Malwarebytes ) C:\Users\Sippo\Downloads\mb3-setup-consumer-3.0.6.1469-1075(1).exe 2017-03-12 10:46 - 2017-03-12 10:47 - 57131432 _____ (Malwarebytes ) C:\Users\Sippo\Downloads\mb3-setup-consumer-3.0.6.1469-1075.exe 2017-03-12 10:21 - 2017-03-12 10:21 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys 2017-03-12 10:21 - 2017-03-12 10:21 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys 2017-03-12 10:21 - 2017-03-12 10:21 - 00000000 ____D C:\Users\Sippo\AppData\Local\Zemana 2017-03-12 08:15 - 2017-03-12 08:15 - 00004008 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1489125157 2017-03-12 08:15 - 2017-03-12 08:15 - 00001098 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2017-03-10 18:48 - 2017-03-10 18:48 - 00548928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys 2017-03-10 08:03 - 2017-03-10 08:03 - 00003250 _____ C:\WINDOWS\System32\Tasks\{68370195-F2A7-4DC1-8FC0-4078D884704C} 2017-03-10 07:29 - 2017-03-10 07:29 - 00000000 ___HD C:\$AV_ASW 2017-03-10 07:12 - 2017-03-10 07:12 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2017-03-10 06:52 - 2017-03-10 06:52 - 00001098 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2017-03-10 06:51 - 2017-03-10 06:51 - 00032088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2017-03-10 06:49 - 2017-03-10 06:49 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\AVAST Software 2017-03-10 06:48 - 2017-03-10 06:48 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2017-03-10 06:48 - 2017-03-10 06:48 - 00001989 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2017-03-10 06:48 - 2017-03-10 06:48 - 00001977 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2017-03-10 06:48 - 2017-03-10 06:48 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software 2017-03-10 06:48 - 2017-03-10 06:48 - 00000000 ____D C:\Program Files\Common Files\AV 2017-03-10 06:48 - 2017-03-10 06:47 - 00162528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2017-03-10 06:48 - 2017-03-10 06:47 - 00126600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2017-03-10 06:48 - 2017-03-10 06:47 - 00100640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2017-03-10 06:48 - 2017-03-10 06:47 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2017-03-10 06:48 - 2017-03-10 06:47 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2017-03-10 06:48 - 2017-03-10 06:46 - 00993608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2017-03-10 06:48 - 2017-03-10 06:46 - 00334600 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys 2017-03-10 06:48 - 2017-03-10 06:46 - 00309272 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2017-03-10 06:48 - 2017-03-10 06:46 - 00189768 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2017-03-10 06:48 - 2017-03-10 06:46 - 00048528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys 2017-03-10 06:47 - 2017-03-10 06:47 - 00398408 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2017-03-10 06:44 - 2017-03-10 07:37 - 00000000 ____D C:\ProgramData\AVAST Software 2017-03-10 06:44 - 2017-03-10 06:51 - 00000000 ____D C:\Program Files\AVAST Software 2017-03-10 06:44 - 2017-03-10 06:44 - 06334872 _____ (AVAST Software) C:\Users\Sippo\Downloads\avast_free_antivirus_setup_online.exe 2017-03-10 06:44 - 2017-03-10 06:44 - 00000039 _____ C:\Users\Sippo\Downloads\Stats.ini 2017-03-10 06:27 - 2017-03-16 12:27 - 00000000 ____D C:\Program Files (x86)\Chopik 2017-03-10 06:27 - 2017-03-10 08:04 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Lamkpruzi 2017-03-10 06:27 - 2017-03-10 06:48 - 00000000 ____D C:\WINDOWS\system32\SSL 2017-03-10 06:27 - 2017-03-10 06:30 - 00000000 ____D C:\Users\Sippo\AppData\Local\Qodsedodale 2017-03-03 18:38 - 2017-03-03 18:38 - 109215744 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit 2017-03-03 18:38 - 2017-03-03 18:38 - 00356352 _____ C:\WINDOWS\system32\config\DEFAULT.iobit 2017-03-03 18:38 - 2017-03-03 18:38 - 00028672 _____ C:\WINDOWS\system32\config\SECURITY.iobit 2017-03-03 18:38 - 2017-03-03 18:38 - 00028672 _____ C:\WINDOWS\system32\config\SAM.iobit 2017-03-01 20:57 - 2017-03-01 20:57 - 00003956 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1459279198 2017-03-01 20:57 - 2017-03-01 20:57 - 00001124 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2017-02-23 21:21 - 2017-02-23 21:21 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-23 13:53 - 2017-02-23 13:53 - 00002429 _____ C:\Users\Sippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-02-18 10:31 - 2017-02-18 10:31 - 00000000 ____D C:\Users\Sippo\Documents\Vuze Downloads 2017-02-14 16:12 - 2017-02-14 16:12 - 00000000 ____D C:\Users\Sippo\Documents\Serif 2017-02-14 16:11 - 2017-02-14 16:11 - 00001808 _____ C:\Users\Sippo\Desktop\WebPlus - Snelkoppeling.lnk ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-03-16 19:59 - 2016-08-26 23:49 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-03-16 16:15 - 2016-11-19 08:44 - 00000000 ____D C:\Users\Sippo\AppData\LocalLow\Mozilla 2017-03-16 16:14 - 2014-12-15 12:37 - 00002288 ____H C:\Users\Sippo\Documents\Default.rdp 2017-03-16 15:01 - 2016-08-27 00:00 - 00000000 ____D C:\Users\Sippo 2017-03-16 15:01 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2017-03-16 15:00 - 2016-08-27 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-03-16 15:00 - 2015-09-09 19:26 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-03-16 15:00 - 2015-09-09 19:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-03-16 15:00 - 2015-08-17 05:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-16 14:59 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI 2017-03-16 14:58 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-03-16 14:31 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-03-16 12:35 - 2016-05-20 20:33 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2017-03-16 12:35 - 2016-05-20 20:33 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-apps 2017-03-16 12:35 - 2015-06-19 16:23 - 00000000 ____D C:\ProgramData\Apple 2017-03-16 12:35 - 2014-12-17 21:52 - 00002574 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-03-16 12:33 - 2016-11-19 08:43 - 00002006 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-03-16 12:33 - 2015-08-17 05:27 - 00002076 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-03-15 22:45 - 2016-08-26 23:59 - 03886178 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-03-15 22:45 - 2016-07-16 23:15 - 01726620 _____ C:\WINDOWS\system32\perfh013.dat 2017-03-15 22:45 - 2016-07-16 23:15 - 00459506 _____ C:\WINDOWS\system32\perfc013.dat 2017-03-15 18:34 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-03-15 18:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-03-15 17:58 - 2016-02-21 10:54 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2017-03-15 17:31 - 2014-12-15 19:59 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-03-15 17:30 - 2014-12-15 19:59 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-03-15 17:27 - 2015-09-09 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-03-14 17:45 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-03-14 17:09 - 2016-12-06 06:41 - 00002256 _____ C:\Users\Public\Desktop\Advanced SystemCare 10.lnk 2017-03-12 14:42 - 2016-08-26 21:41 - 00000000 ____D C:\Windows10Upgrade 2017-03-12 14:30 - 2015-07-30 09:48 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-03-12 12:51 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\registration 2017-03-12 11:10 - 2014-12-19 13:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-12 11:07 - 2016-09-19 11:00 - 00000000 ____D C:\AdwCleaner 2017-03-12 10:43 - 2016-06-02 20:43 - 00000000 ____D C:\Program Files (x86)\Navigator15 2017-03-12 10:39 - 2016-10-14 20:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2017-03-12 10:37 - 2015-02-07 13:46 - 00000000 ____D C:\Program Files (x86)\SlimCleaner 2017-03-10 07:12 - 2015-03-21 08:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-03-10 07:11 - 2015-03-21 08:02 - 00000000 ____D C:\Program Files (x86)\Java 2017-03-08 19:30 - 2015-04-27 08:53 - 00000625 _____ C:\Users\Sippo\Desktop\eva number.txt 2017-03-04 07:51 - 2015-01-02 15:30 - 00000000 ____D C:\Users\Sippo\AppData\Local\Adobe 2017-03-04 07:47 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-03-04 07:47 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-03-01 20:57 - 2016-03-29 20:19 - 00000000 ____D C:\Program Files (x86)\Opera 2017-02-27 03:20 - 2016-07-29 20:33 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-02-23 13:53 - 2015-07-30 09:57 - 00000000 ___RD C:\Users\Sippo\OneDrive 2017-02-22 10:13 - 2016-08-27 00:45 - 00004142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-02-21 16:40 - 2015-07-30 09:48 - 00000000 ____D C:\Users\Sippo\AppData\Local\Packages 2017-02-19 11:14 - 2014-12-20 13:43 - 00000000 ____D C:\ProgramData\Ashampoo 2017-02-18 11:19 - 2014-12-19 11:28 - 00000000 ____D C:\Users\Sippo\AppData\Roaming\Azureus 2017-02-18 10:23 - 2014-12-19 11:27 - 00000000 ____D C:\Program Files\Vuze ==================== Bestanden in de root van sommige mappen ======= 2015-12-28 23:41 - 2012-06-06 22:15 - 0015086 _____ () C:\Users\Sippo\AppData\Roaming\shshortcut.ico 2015-06-20 10:31 - 2015-06-20 10:31 - 0003584 _____ () C:\Users\Sippo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-30 22:06 - 2014-12-30 22:06 - 0007667 _____ () C:\Users\Sippo\AppData\Local\Resmon.ResmonCfg 2016-08-26 23:53 - 2016-08-26 23:53 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\WINDOWS\system32\winlogon.exe => Bestand is getekend C:\WINDOWS\system32\wininit.exe => Bestand is getekend C:\WINDOWS\explorer.exe => Bestand is getekend C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend C:\WINDOWS\system32\svchost.exe => Bestand is getekend C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend C:\WINDOWS\system32\services.exe => Bestand is getekend C:\WINDOWS\system32\User32.dll => Bestand is getekend C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend C:\WINDOWS\system32\userinit.exe => Bestand is getekend C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend C:\WINDOWS\system32\rpcss.dll => Bestand is getekend C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2017-03-16 09:26 ==================== Eind van FRST.txt ============================