Scanresultaten van Farbar Recovery Scan Tool (FRST) (x86) Versie: 15-10-2017 Gestart door Glowing Starter (Beheerder) op GLOWINGSTARTER (16-10-2017 15:52:36) Gestart vanaf C:\Users\Glowing Starter\Downloads Geladen Profielen: Glowing Starter (Beschikbare Profielen: Glowing Starter) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: Chrome) Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.) (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Sentelic Corporation) C:\Program Files\FSP\FspUip.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Bison Inc.) C:\Program Files\BisonCam\DeLay.exe (mychat) C:\Program Files\BisonCam\BisonHK.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (HP) C:\Windows\System32\HPSIsvc.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Symantec Corporation) C:\Program Files\Norton Security\Engine\22.10.1.10\ns.exe () C:\Program Files\Hotkey\PowerBiosServer.exe (f.lux Software LLC) C:\Users\Glowing Starter\AppData\Local\FluxSoftware\Flux\flux.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe () C:\Program Files\Hotkey\Hotkey.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Popcorn Time) C:\Program Files\Popcorn Time\Updater.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Symantec Corporation) C:\Program Files\Norton Security\Engine\22.10.1.10\ns.exe (Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Dropbox, Inc.) C:\Users\Glowing Starter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) C:\Users\Glowing Starter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) C:\Users\Glowing Starter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Symantec Corporation) C:\Program Files\Norton Security\Engine\22.10.1.10\conathst.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Register (gefilterd) =========================== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [3342336 2009-08-31] (Sentelic Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7739936 2009-09-21] (Realtek Semiconductor) HKLM\...\Run: [DeLay] => C:\Program Files\BisonCam\DeLay.exe*‰***Ø!****à!*****X** ü*‰******Ø!* ü*p4ávŸ4ávÀ¬Õv°**Ü+****€** €**ð**X***%&'€**a**à!*4567á**<=>?‰***DEFGHIJKLMNO (de data item heeft 59 mee tekens). HKLM\...\Run: [BisonHK] => C:\Program Files\BisonCam\BisonHK.exe [77824 2009-06-09] (mychat) HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKU\S-1-5-21-70928346-524487458-456366203-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [143360 2006-12-23] (Nero AG) HKU\S-1-5-21-70928346-524487458-456366203-1000\...\Run: [f.lux] => C:\Users\Glowing Starter\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC) HKU\S-1-5-21-70928346-524487458-456366203-1000\...\Run: [Dropbox Update] => C:\Users\Glowing Starter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) HKU\S-1-5-21-70928346-524487458-456366203-1000\...\Run: [HP ENVY 5530 series (NET)] => C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe [2427400 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-70928346-524487458-456366203-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-70928346-524487458-456366203-1000\...\RunOnce: [Uninstall C:\Users\Glowing Starter\AppData\Local\Microsoft\OneDrive\17.3.4604.0120] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Glowing Starter\AppData\Local\Microsoft\OneDrive\17.3.4604.0120" HKU\S-1-5-21-70928346-524487458-456366203-1000\...\MountPoints2: {7a9d0826-b842-11df-ad73-0090f59c7105} - F:\LaunchU3.exe -a HKU\S-1-5-21-70928346-524487458-456366203-1000\...\MountPoints2: {d53e9868-b23b-11e2-b9cf-e09153128731} - F:\LaunchU3.exe -a HKU\S-1-5-21-70928346-524487458-456366203-1000\...\MountPoints2: {dfd3d8c1-8e1b-11e2-a322-0090f59c7105} - F:\SISetup.exe HKU\S-1-5-21-70928346-524487458-456366203-1000\...0c966feabec1\InprocServer32: [Default-shell32] AANDACHT HKU\S-1-5-21-70928346-524487458-456366203-1000\...A8F59079A8D5}\localserver32: <==== AANDACHT Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk [2010-06-01] ShortcutTarget: Hotkey.lnk -> C:\Program Files\Hotkey\Hotkey.exe () Startup: C:\Users\Glowing Starter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk [2010-06-13] ShortcutTarget: OneNote 2007 Schermopname en Snel starten.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Glowing Starter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-09-07] ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Geen bestand) BootExecute: GroupPolicy: Restrictie - Chrome <==== AANDACHT ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) ProxyEnable: [.DEFAULT] => Proxy is ingeschakeld. ProxyServer: [.DEFAULT] => http=127.0.0.1:50065;https=127.0.0.1:50065 AutoConfigURL: [.DEFAULT] => http=127.0.0.1:50065;https=127.0.0.1:50065 Winsock: Catalog9 12 C:\Program Files\Ansithershalopy\Proxy32.dll [790016 2016-09-27] () Winsock: Catalog9 13 C:\Program Files\Ansithershalopy\Proxy32.dll [790016 2016-09-27] () Winsock: Catalog9 14 C:\Program Files\Ansithershalopy\Proxy32.dll [790016 2016-09-27] () Winsock: Catalog9 15 C:\Program Files\Ansithershalopy\Proxy32.dll [790016 2016-09-27] () Tcpip\Parameters: [DhcpNameServer] 130.37.236.48 130.37.236.49 130.37.236.50 Tcpip\..\Interfaces\{A0A5B79A-DD29-4C63-BE59-0C7A9462743E}: [DhcpNameServer] 62.58.153.220 62.58.48.30 192.168.1.1 Tcpip\..\Interfaces\{A4E30119-DCA7-4F99-8F61-DEA22BEEC64F}: [DhcpNameServer] 130.37.236.48 130.37.236.49 130.37.236.50 Internet Explorer: ================== HKU\S-1-5-21-70928346-524487458-456366203-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES007&pc=UE06 SearchScopes: HKU\.DEFAULT -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL = SearchScopes: HKU\S-1-5-19 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL = SearchScopes: HKU\S-1-5-20 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL = SearchScopes: HKU\S-1-5-21-70928346-524487458-456366203-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-70928346-524487458-456366203-1000 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL = BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security\Engine\22.10.1.10\coIEPlg.dll [2017-08-24] (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-11] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2017-05-25] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-11] (Oracle Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security\Engine\22.10.1.10\coIEPlg.dll [2017-08-24] (Symantec Corporation) DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-25] (Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-25] (Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-25] (Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-25] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF DefaultProfile: b106xsnh.default FF ProfilePath: C:\Users\Glowing Starter\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\b106xsnh.default\Profiles\b106xsnh.default [niet gevonden] <==== AANDACHT FF ProfilePath: C:\Users\Glowing Starter\AppData\Roaming\Mozilla\Firefox\Profiles\b106xsnh.default [2017-10-05] FF NewTab: Mozilla\Firefox\Profiles\b106xsnh.default -> hxxp://www.trotux.com/?z=93b7f2eef6471b90f581af2g9z6mez5t3q8wez2qce&from=isr&uid=FUJITSUXMHZ2320BJXG2_K82BTA22643CTA22643CX&type=hp FF DefaultSearchEngine: Mozilla\Firefox\Profiles\b106xsnh.default -> trotux FF SelectedSearchEngine: Mozilla\Firefox\Profiles\b106xsnh.default -> trotux FF Homepage: Mozilla\Firefox\Profiles\b106xsnh.default -> hxxp://www.trotux.com/?z=93b7f2eef6471b90f581af2g9z6mez5t3q8wez2qce&from=isr&uid=FUJITSUXMHZ2320BJXG2_K82BTA22643CTA22643CX&type=hp FF Extension: (Adblock Plus) - C:\Users\Glowing Starter\AppData\Roaming\Mozilla\Firefox\Profiles\b106xsnh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-21] [niet getekend] FF SearchPlugin: C:\Users\Glowing Starter\AppData\Roaming\Mozilla\Firefox\Profiles\b106xsnh.default\searchplugins\fdjhpszy.xml [2016-09-27] FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.10.0.85\coFFAddon => niet gevonden FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_159.dll [2017-10-11] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-11] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-11] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2010-06-30] (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-25] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-70928346-524487458-456366203-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Glowing Starter\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [Geen bestand] Chrome: ======= CHR DefaultProfile: Profile 1 CHR StartupUrls: Profile 1 -> "hxxps://www.google.nl/" CHR Profile: C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-09-27] <==== AANDACHT CHR Extension: (Google Drive) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-04] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== AANDACHT CHR Extension: (YouTube) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24] CHR Extension: (Adblock Plus) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-28] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== AANDACHT CHR Extension: (Google Search) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Google Docs Offline) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16] CHR Extension: (Google Wallet) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-28] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== AANDACHT CHR Extension: (Gmail) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29] CHR Extension: (Chrome Media Router) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-27] CHR Profile: C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-10-16] CHR Extension: (Norton Security Toolbar) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-10-04] CHR Extension: (Adblock for Youtube™) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2017-06-14] CHR Extension: (Adobe Acrobat) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-03] CHR Extension: (AdBlock) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-10-06] CHR Extension: (Norton Identity Safe) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-08-19] CHR Extension: (Chrome Web Store Payments) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Chrome Media Router) - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-19] CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security\Engine\22.10.1.10\Exts\Chrome.crx CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-70928346-524487458-456366203-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx StartMenuInternet: Google Chrome.3DSDQ2XVF5SN2SLOIOS33XEU44 - C:\Users\Glowing Starter\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2585800 2017-05-14] (Microsoft Corporation) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Bestand niet getekend] R3 NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [Bestand niet getekend] R2 NS; C:\Program Files\Norton Security\Engine\22.10.1.10\NS.exe [288504 2017-08-24] (Symantec Corporation) R2 PowerBiosServer; C:\Program Files\Hotkey\PowerBiosServer.exe [31744 2009-10-06] () [Bestand niet getekend] R2 Update service; C:\Program Files\Popcorn Time\Updater.exe [339968 2015-10-19] (Popcorn Time) [Bestand niet getekend] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 EraserSvc11720; "C:\Program Files\Common Files\Symantec Shared\EENGINE\NS.exe" /h ccCommon [X] ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R1 BHDrvx86; C:\Program Files\Norton Security\NortonData\22.10.0.85\Definitions\BASHDefs\20171011.003\BHDrvx86.sys [1367712 2017-09-07] (Symantec Corporation) S3 Cam5607; C:\Windows\System32\Drivers\BisonC07.sys [1182320 2009-07-25] (Bison Electronics. Inc. ) R1 ccSet_NS; C:\Windows\system32\drivers\NS\160A010.00A\ccSetx86.sys [147072 2017-07-14] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [393344 2017-06-16] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [126592 2017-10-11] (Symantec Corporation) R1 IDSVix86; C:\Program Files\Norton Security\NortonData\22.10.0.85\Definitions\IPSDefs\20171013.001\IDSvix86.sys [845976 2017-10-14] (Symantec Corporation) R1 SRTSP; C:\Windows\System32\Drivers\NS\160A010.00A\SRTSP.SYS [659616 2017-07-14] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NS\160A010.00A\SRTSPX.SYS [41112 2017-07-14] (Symantec Corporation) R0 SymEFASI; C:\Windows\System32\drivers\NS\160A010.00A\SYMEFASI.SYS [1393792 2017-07-14] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [89264 2017-08-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NS\160A010.00A\Ironx86.SYS [241888 2017-07-14] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NS\160A010.00A\SYMNETS.SYS [423552 2017-07-14] (Symantec Corporation) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [42496 2011-08-02] (Apple, Inc.) [Bestand niet getekend] S1 hbmmqidx; \??\C:\Windows\system32\drivers\hbmmqidx.sys [X] S1 hdzpwkda; \??\C:\Windows\system32\drivers\hdzpwkda.sys [X] S1 lsmxhfye; \??\C:\Windows\system32\drivers\lsmxhfye.sys [X] S1 mcixzepl; \??\C:\Windows\system32\drivers\mcixzepl.sys [X] S1 tdjppldq; \??\C:\Windows\system32\drivers\tdjppldq.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X] ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Gemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-10-16 15:52 - 2017-10-16 15:54 - 000022158 _____ C:\Users\Glowing Starter\Downloads\FRST.txt 2017-10-16 15:51 - 2017-10-16 15:51 - 001798144 _____ (Farbar) C:\Users\Glowing Starter\Downloads\FRST (1).exe 2017-10-16 15:46 - 2017-10-16 15:52 - 000000000 ____D C:\FRST 2017-10-16 15:44 - 2017-10-16 15:45 - 001798144 _____ (Farbar) C:\Users\Glowing Starter\Downloads\FRST.exe 2017-10-16 11:22 - 2017-10-16 11:22 - 000651238 _____ C:\Users\Glowing Starter\Downloads\retouretiket (1).pdf 2017-10-16 10:58 - 2017-10-16 10:58 - 000002131 _____ C:\Users\Glowing Starter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk 2017-10-12 13:35 - 2017-10-12 13:35 - 007840539 _____ C:\Users\Glowing Starter\Downloads\literatuur (1).zip 2017-10-12 13:33 - 2017-10-12 13:33 - 000070431 _____ C:\Users\Glowing Starter\Downloads\Kerken-vinden-elkaar-weer.pdf 2017-10-12 13:33 - 2017-10-12 13:33 - 000070431 _____ C:\Users\Glowing Starter\Desktop\Kerken-vinden-elkaar-weer.pdf 2017-10-12 12:40 - 2017-10-12 12:40 - 000187671 _____ C:\Users\Glowing Starter\Downloads\Dordse-Leerregels-Protestantse-Pers-Heerenveen-2009.pdf 2017-10-11 23:11 - 2017-10-11 23:11 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-11 22:56 - 2017-10-11 22:56 - 001982463 _____ C:\Users\Glowing Starter\Desktop\god_blijft_in_nederland.pdf 2017-10-11 18:22 - 2017-10-11 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune 2017-10-11 18:22 - 2017-10-11 18:22 - 000000000 ____D C:\Program Files\HD Tune 2017-10-11 18:21 - 2017-10-11 18:21 - 000642632 _____ (EFD Software ) C:\Users\Glowing Starter\Downloads\hdtune_255.exe 2017-10-11 15:54 - 2017-10-11 15:54 - 000343902 _____ C:\Users\Glowing Starter\Downloads\Over-dopen-in-de-Protestantse-Kerk-handreiking-voor-gesprek-kerkenraden-2012.pdf 2017-10-11 15:54 - 2017-10-11 15:54 - 000343902 _____ C:\Users\Glowing Starter\Desktop\Over-dopen-in-de-Protestantse-Kerk-handreiking-voor-gesprek-kerkenraden-2012.pdf 2017-10-11 11:59 - 2017-10-11 12:00 - 026529741 _____ C:\Users\Glowing Starter\Downloads\Presentatie Winsum.pptx 2017-10-11 10:23 - 2017-09-13 17:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2017-10-11 10:23 - 2017-09-13 17:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-11 10:23 - 2017-09-13 17:13 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-11 10:23 - 2017-09-13 17:13 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-11 10:23 - 2017-09-13 17:10 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-11 10:23 - 2017-09-13 17:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-11 10:23 - 2017-09-13 17:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-11 10:23 - 2017-09-13 16:53 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-11 10:23 - 2017-09-13 16:50 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-11 10:23 - 2017-09-13 16:50 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-11 10:23 - 2017-09-13 16:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-11 10:23 - 2017-09-13 16:50 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-11 10:23 - 2017-09-13 16:50 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-11 10:23 - 2017-09-13 16:48 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-11 10:23 - 2017-09-13 16:46 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-11 10:23 - 2017-09-13 16:46 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-11 10:23 - 2017-09-13 16:46 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-11 10:23 - 2017-09-13 16:46 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-11 10:23 - 2017-09-13 16:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-11 10:23 - 2017-09-13 16:46 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-11 10:23 - 2017-09-13 16:46 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-11 10:23 - 2017-09-09 01:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-11 10:23 - 2017-09-08 17:14 - 001213672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-11 10:23 - 2017-09-08 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-11 10:23 - 2017-09-08 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-11 10:23 - 2017-09-08 17:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-11 10:23 - 2017-09-08 17:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-11 10:23 - 2017-09-08 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-11 10:23 - 2017-09-08 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-11 10:23 - 2017-09-08 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-11 10:23 - 2017-09-08 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-11 10:23 - 2017-09-08 16:50 - 002402304 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-11 10:23 - 2017-09-08 16:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll 2017-10-11 10:23 - 2017-09-08 16:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll 2017-10-11 10:23 - 2017-09-08 16:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll 2017-10-11 10:23 - 2017-09-07 21:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-11 10:23 - 2017-09-07 21:26 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-11 10:23 - 2017-09-07 21:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-11 10:23 - 2017-09-07 21:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-11 10:23 - 2017-09-07 21:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-11 10:23 - 2017-09-07 21:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-11 10:23 - 2017-09-07 21:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-11 10:23 - 2017-09-07 21:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-11 10:23 - 2017-09-07 21:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-11 10:23 - 2017-09-07 21:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-11 10:23 - 2017-09-07 21:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-11 10:23 - 2017-09-07 20:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-11 10:23 - 2017-09-07 20:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-11 10:23 - 2017-09-07 20:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-11 10:23 - 2017-09-07 20:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-11 10:23 - 2017-09-07 20:58 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-11 10:23 - 2017-09-07 20:52 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-11 10:23 - 2017-09-07 20:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-11 10:23 - 2017-09-07 20:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-11 10:23 - 2017-09-07 20:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-11 10:23 - 2017-09-07 20:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-11 10:23 - 2017-09-07 20:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-11 10:23 - 2017-09-07 20:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-11 10:23 - 2017-09-07 20:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-11 10:23 - 2017-09-07 20:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-11 10:23 - 2017-09-07 20:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-11 10:23 - 2017-09-07 20:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-11 10:23 - 2017-09-07 20:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-11 10:23 - 2017-09-07 20:26 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-11 10:23 - 2017-09-07 20:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-11 10:23 - 2017-09-07 20:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-11 10:23 - 2017-09-07 20:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-11 10:23 - 2017-09-07 20:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-11 10:23 - 2017-09-07 19:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-11 10:23 - 2017-09-07 19:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-11 10:23 - 2017-09-07 17:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-11 10:23 - 2017-09-07 16:48 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-11 10:23 - 2017-09-07 16:48 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-11 10:23 - 2017-09-07 16:48 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-11 10:23 - 2017-08-19 17:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-10-11 10:23 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-10-11 10:23 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-10-11 10:23 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-10-11 10:23 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-10-11 10:23 - 2017-08-14 19:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-10-11 10:23 - 2017-08-14 19:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-10-11 10:23 - 2017-08-13 23:35 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-10-10 18:13 - 2017-10-10 18:13 - 000000000 ____D C:\ProgramData\RICOH 2017-10-10 18:12 - 2017-10-10 18:12 - 039592031 _____ (Igor Pavlov) C:\Users\Glowing Starter\Downloads\PrinterDriverInstaller64Bit.exe 2017-10-10 14:40 - 2017-10-10 14:40 - 001906871 _____ C:\Users\Glowing Starter\Desktop\Regeerakkoord+2017-2021.pdf 2017-10-09 18:27 - 2017-10-09 18:27 - 000436605 _____ C:\Users\Glowing Starter\Desktop\HdR - Symposium Leeuwarden.pdf 2017-10-09 13:09 - 2017-10-09 13:10 - 002611464 _____ C:\Users\Glowing Starter\Desktop\Monday-Morning-Success-2015.pdf 2017-10-06 18:46 - 2017-10-06 18:46 - 000919581 _____ C:\Users\Glowing Starter\Downloads\Kring 2.zip 2017-10-05 19:57 - 2017-10-05 19:57 - 000162985 _____ C:\Users\Glowing Starter\Desktop\Spiritualiteit.pdf 2017-10-05 19:56 - 2017-10-05 19:56 - 000162985 _____ C:\Users\Glowing Starter\Downloads\Spiritualiteit.pdf 2017-10-05 12:51 - 2017-10-05 12:52 - 001306150 _____ C:\Users\Glowing Starter\Downloads\Autoruns.zip 2017-10-05 12:50 - 2017-10-05 12:50 - 000141864 _____ C:\Users\Glowing Starter\Downloads\bluescreenview_setup (1).exe 2017-10-05 12:47 - 2017-10-05 12:47 - 000000000 ____D C:\Users\Glowing Starter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView 2017-10-05 12:47 - 2017-10-05 12:47 - 000000000 ____D C:\Program Files\NirSoft 2017-10-05 12:46 - 2017-10-05 12:46 - 000141864 _____ C:\Users\Glowing Starter\Downloads\bluescreenview_setup.exe 2017-10-05 12:41 - 2017-10-05 12:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2017-10-05 12:41 - 2017-10-05 12:41 - 000000000 ____D C:\Program Files\Speccy 2017-10-05 12:37 - 2017-10-05 12:41 - 006299336 _____ (Piriform Ltd) C:\Users\Glowing Starter\Downloads\spsetup131 (1).exe 2017-10-05 12:37 - 2017-10-05 12:39 - 006299336 _____ (Piriform Ltd) C:\Users\Glowing Starter\Downloads\spsetup131.exe 2017-10-05 11:30 - 2017-10-05 11:30 - 000009904 _____ C:\Users\Glowing Starter\Downloads\ING - Afschrift zakelijke betaalrekening NL18INGB0002808331 - 2017 - 8.pdf 2017-10-05 11:00 - 2017-10-05 11:00 - 000000000 ____D C:\Users\Glowing Starter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-10-04 11:42 - 2017-10-04 11:42 - 000010181 _____ C:\Users\Glowing Starter\Downloads\ING - Afschrift zakelijke betaalrekening NL18INGB0002808331 - 2017 - 7.pdf 2017-10-04 11:35 - 2017-10-04 11:35 - 000006351 _____ C:\Users\Glowing Starter\Downloads\NL18INGB0002808331_10-06-2017_03-10-2017.csv 2017-10-04 11:03 - 2017-10-04 11:03 - 023708300 _____ C:\Users\Glowing Starter\Downloads\Heineken l When You Drive Never Drink.mp4 2017-10-02 12:15 - 2017-10-02 12:15 - 003315911 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_9_sw.pdf 2017-10-02 12:15 - 2017-10-02 12:15 - 001700566 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_10_sw.pdf 2017-10-02 12:14 - 2017-10-02 12:14 - 006126729 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_6_sw.pdf 2017-10-02 12:14 - 2017-10-02 12:14 - 003947001 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_7_sw.pdf 2017-10-02 12:14 - 2017-10-02 12:14 - 003754318 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_8_sw.pdf 2017-10-02 12:13 - 2017-10-02 12:14 - 006609506 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_5_sw.pdf 2017-10-02 12:12 - 2017-10-02 12:12 - 006010434 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_4_sw.pdf 2017-10-02 11:50 - 2017-10-02 11:51 - 005076942 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_3_sw.pdf 2017-10-02 11:49 - 2017-10-02 11:49 - 003212871 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_1.2_sw.pdf 2017-10-02 11:47 - 2017-10-02 11:47 - 004071718 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_1.1_sw.pdf 2017-10-02 11:44 - 2017-10-02 11:44 - 004636929 _____ C:\Users\Glowing Starter\Downloads\doctoraalscriptie_Jasper_Kuik_1.1pdf_sw.pdf 2017-09-29 10:29 - 2017-09-29 10:29 - 004540816 _____ C:\Users\Glowing Starter\Downloads\29-09_Den_Dulk_Een_huis_naast_de_synagoge_136-159_sw.pdf 2017-09-28 12:42 - 2017-09-28 12:42 - 007979349 _____ C:\Users\Glowing Starter\Downloads\Worship in the Network Culture, H9.pdf 2017-09-27 16:50 - 2017-09-27 16:50 - 000203142 _____ C:\Users\Glowing Starter\Downloads\24 september 2017 middagdienst.pptx 2017-09-26 16:15 - 2017-09-26 16:15 - 007698440 _____ C:\Users\Glowing Starter\Downloads\73785_thesis ezechiel.pdf 2017-09-25 14:17 - 2017-09-25 14:17 - 001100337 _____ C:\Users\Glowing Starter\Downloads\Pionieren Verkenning monastiek pionieren_okt2015.pdf 2017-09-25 09:39 - 2017-09-25 09:39 - 010200641 _____ C:\Users\Glowing Starter\Downloads\Kring 1.zip 2017-09-23 11:57 - 2017-09-23 11:58 - 001911577 _____ C:\Users\Glowing Starter\Downloads\Glossa ordinaria Rom 1.pdf 2017-09-21 10:36 - 2017-09-21 10:36 - 075092502 _____ C:\Users\Glowing Starter\Downloads\waar_leven_geheel.pdf 2017-09-21 10:23 - 2017-10-11 19:29 - 000000000 ____D C:\Users\Glowing Starter\AppData\Local\CrashDumps 2017-09-20 17:56 - 2017-09-20 17:56 - 001979235 _____ C:\Users\Glowing Starter\Downloads\waar_leven_sw.pdf 2017-09-20 10:05 - 2017-09-20 10:05 - 006703212 _____ C:\Users\Glowing Starter\Downloads\Literatuur.zip 2017-09-18 16:31 - 2017-09-18 16:31 - 000215952 _____ C:\Users\Glowing Starter\Downloads\GISBERTUS+VOETIUS,+GEREFORMEERD+SCHOLASTICUS.pdf ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-10-16 15:50 - 2009-07-14 06:34 - 000023568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-16 15:50 - 2009-07-14 06:34 - 000023568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-16 14:56 - 2015-06-17 19:30 - 000001064 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-70928346-524487458-456366203-1000UA.job 2017-10-16 14:44 - 2017-07-26 11:41 - 000000000 ____D C:\Users\Glowing Starter\AppData\LocalLow\Mozilla 2017-10-16 14:43 - 2017-08-19 13:53 - 000065536 _____ C:\Windows\system32\Ikeext.etl 2017-10-16 14:43 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-15 13:21 - 2010-06-01 14:53 - 000000000 ____D C:\Program Files\Hotkey 2017-10-14 17:18 - 2017-07-26 11:41 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service 2017-10-14 16:20 - 2016-11-23 18:01 - 000000000 ____D C:\Users\Glowing Starter\Documents\pastoraal werk wijkgemeente martinikerk 2017-10-14 16:00 - 2017-07-26 21:04 - 000000000 ____D C:\Program Files\Mozilla Thunderbird 2017-10-14 11:08 - 2016-02-24 14:02 - 000000000 ____D C:\Program Files\BibleWorks 8 2017-10-13 17:52 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache 2017-10-12 12:43 - 2010-06-01 20:43 - 001670960 _____ C:\Windows\system32\PerfStringBackup.INI 2017-10-12 12:43 - 2009-07-14 10:27 - 000746014 _____ C:\Windows\system32\perfh013.dat 2017-10-12 12:43 - 2009-07-14 10:27 - 000153934 _____ C:\Windows\system32\perfc013.dat 2017-10-12 12:43 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf 2017-10-12 12:36 - 2009-07-14 06:33 - 000341952 _____ C:\Windows\system32\FNTCACHE.DAT 2017-10-11 23:32 - 2013-08-14 14:35 - 000000000 ____D C:\Windows\system32\MRT 2017-10-11 23:10 - 2010-06-26 16:58 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-11 18:21 - 2011-01-27 16:27 - 000001912 _____ C:\Windows\epplauncher.mif 2017-10-11 12:00 - 2010-09-04 19:54 - 000009728 _____ C:\Users\Glowing Starter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-10-11 10:17 - 2012-03-31 12:36 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2017-10-11 10:17 - 2011-05-23 21:44 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2017-10-11 10:17 - 2010-06-13 18:45 - 000000000 ____D C:\Windows\system32\Macromed 2017-10-09 18:14 - 2012-05-09 20:30 - 000000000 ___RD C:\Users\Glowing Starter\Dropbox 2017-10-05 11:00 - 2012-05-09 20:20 - 000000000 ____D C:\Users\Glowing Starter\AppData\Roaming\Dropbox 2017-10-04 09:56 - 2015-06-17 19:30 - 000001012 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-70928346-524487458-456366203-1000Core.job 2017-10-01 21:22 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\NDF 2017-09-22 08:07 - 2016-01-30 10:51 - 000002161 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ==================== Bestanden in de root van sommige mappen ======= 2015-01-27 21:14 - 2015-01-27 21:14 - 000000079 _____ () C:\Program Files\prefs.js 2010-09-04 19:54 - 2017-10-11 12:00 - 000009728 _____ () C:\Users\Glowing Starter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-09-27 10:38 - 2016-09-27 10:38 - 000002560 _____ () C:\Users\Glowing Starter\AppData\Local\uninstallro.exe 2011-05-08 01:53 - 2011-05-08 01:53 - 000025214 ____H () C:\ProgramData\68225e52-c3bd-4db8-ba27-7fec34636b04.ico 2017-08-12 15:32 - 2017-08-12 15:32 - 000000057 _____ () C:\ProgramData\Ament.ini Sommige nul byte grootte bestanden/mappen: ========================== C:\Windows\System32\nsprs.dll C:\Windows\System32\serauth1.dll C:\Windows\System32\serauth2.dll ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\Windows\explorer.exe => Bestand is getekend C:\Windows\system32\winlogon.exe => Bestand is getekend C:\Windows\system32\wininit.exe => Bestand is getekend C:\Windows\system32\svchost.exe => Bestand is getekend C:\Windows\system32\services.exe => Bestand is getekend C:\Windows\system32\User32.dll => Bestand is getekend C:\Windows\system32\userinit.exe => Bestand is getekend C:\Windows\system32\rpcss.dll => Bestand is getekend C:\Windows\system32\dnsapi.dll => Bestand is getekend C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2017-10-13 17:41 ==================== Eind van FRST.txt ============================