Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 21-10-2017 Gestart door wilfr (Beheerder) op DESKTOP-0GEVP4A (23-10-2017 13:14:39) Gestart vanaf C:\Users\wilfr\Downloads Geladen Profielen: wilfr (Beschikbare Profielen: wilfr) Platform: Windows 10 Home Versie 1607 14393.1770 (X64) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: FF) Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe () C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (TomTom) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe (BitTorrent Inc.) C:\Users\wilfr\AppData\Roaming\uTorrent\uTorrent.exe (Digital Wave Ltd) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe (BitTorrent Inc.) C:\Users\wilfr\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe (BitTorrent Inc.) C:\Users\wilfr\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe (Facebook) C:\Users\wilfr\AppData\Local\Facebook\Games\FacebookGameroom.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Corel Corporation) C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (The CefSharp Authors) C:\Users\wilfr\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe () C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17083.18321.0_x64__8wekyb3d8bbwe\Music.UI.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.13610.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8600.40525.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8600.40525.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Freemake) C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVC.exe ==================== Register (gefilterd) =========================== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16152792 2015-07-17] (Realtek Semiconductor) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [230104 2015-07-10] (Realtek Semiconductor Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1761120 2015-12-07] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [1918696 2017-05-08] (TomTom) HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Run: [uTorrent] => C:\Users\wilfr\AppData\Roaming\uTorrent\uTorrent.exe [1982144 2017-09-29] (BitTorrent Inc.) HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Run: [vidnotifier.exe] => C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\vidnotifier\vidnotifier.exe [1222632 2017-09-22] (Digital Wave Ltd) HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Run: [OSDownloaderUpdate] => C:\Program Files (x86)\OSDownloader\OSDownloaderUpdate.exe [3921920 2017-03-22] (Opensubtitles.org) HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Run: [OSDownloader] => C:\Program Files (x86)\OSDownloader\OSDownloader.exe [5652992 2017-04-12] (OpenSubtitles.org) HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\MountPoints2: {05c484ac-2d60-11e7-9ce8-74da386da0bc} - "K:\setup.EXE" /AUTORUN HKU\S-1-5-21-1228691392-3513963491-2876946990-1003\...\MountPoints2: {d640926f-b17d-11e6-9c2c-806e6f6e6963} - "F:\WD Drive Unlock.exe" autoplay=true Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2016-11-06] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\wilfr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-09-24] ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\wilfr\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook) Startup: C:\Users\wilfr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\µTorrent [2016-10-22] () BootExecute: autocheck autochk * bootdelete ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{313c7240-4d5a-439f-b043-8ec520718019}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com SearchScopes: HKU\S-1-5-21-1228691392-3513963491-2876946990-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security) BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-07] (AO Kaspersky Lab) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security) BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2016-12-07] (AO Kaspersky Lab) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-21] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-21] (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-07] (AO Kaspersky Lab) Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2016-12-07] (AO Kaspersky Lab) FireFox: ======== FF DefaultProfile: tb0kjmpu.default-1505230851596 FF ProfilePath: C:\Users\wilfr\AppData\Roaming\Mozilla\Firefox\Profiles\tb0kjmpu.default-1505230851596 [2017-10-23] FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\wilfr\AppData\Roaming\Mozilla\Firefox\Profiles\tb0kjmpu.default-1505230851596\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-12] FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Bescherming) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-10-14] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_170.dll [2017-10-16] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_170.dll [2017-10-16] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-21] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-21] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-09] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-09] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: ChromeDefaultData CHR Profile: C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-09-19] <==== AANDACHT CHR Extension: (Google Presentaties) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-09] CHR Extension: (Google Documenten) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-15] CHR Extension: (Google Drive) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-15] CHR Extension: (YouTube) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-15] CHR Extension: (Google Spreadsheets) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-09] CHR Extension: (Kaspersky Bescherming) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-02-15] CHR Extension: (Offline Documenten) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-15] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Gmail) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-15] CHR Extension: (Chrome Media Router) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-09] CHR Profile: C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default [2017-09-19] CHR Extension: (Google Presentaties) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-07] CHR Extension: (Google Documenten) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-07] CHR Extension: (Google Drive) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-07] CHR Extension: (YouTube) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-07] CHR Extension: (Google Spreadsheets) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-07] CHR Extension: (Kaspersky Bescherming) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-07-07] CHR Extension: (Offline Documenten) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-18] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-07] CHR Extension: (Gmail) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-07] CHR Extension: (Chrome Media Router) - C:\Users\wilfr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-18] CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab) S4 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [41176 2015-03-02] (Realtek Semiconductor Corporation) S4 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [121560 2015-07-20] () S3 cplspcon; C:\WINDOWS\system32\IntelCpHDCPSvc.exe [440304 2017-04-04] (Intel Corporation) R2 CybereasonRansomFree; C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe [13824 2017-10-08] (Cybereason) [Bestand niet getekend] R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-09-22] (Digital Wave Ltd.) S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [104448 2017-07-03] (Freemake) [Bestand niet getekend] R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [Bestand niet getekend] R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [365040 2017-04-04] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Bestand niet getekend] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Bestand niet getekend] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-22] (Intel Corporation) S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab) R2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [452576 2016-02-09] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [901088 2016-02-09] (Malwarebytes Corporation) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Bestand niet getekend] S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Bestand niet getekend] R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2017-06-26] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2017-06-26] (McAfee, Inc.) S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2017-06-26] (McAfee, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [308088 2015-12-07] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2017-08-08] (Microsoft Corporation) R2 WinZip Smart Monitor Service; C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe [495616 2017-04-11] () [Bestand niet getekend] ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab) R3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2016-04-02] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2016-04-02] (Windows (R) Win 7 DDK provider) R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab) R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab) R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab) R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab) S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab) R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [197344 2017-10-14] (AO Kaspersky Lab) R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [520152 2017-07-24] (AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [186184 2017-10-23] (AO Kaspersky Lab) R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1021656 2017-10-14] (AO Kaspersky Lab) R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [57424 2016-12-07] (AO Kaspersky Lab) R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab) R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab) R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project) R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [229288 2017-07-04] (AO Kaspersky Lab) R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [87584 2017-10-12] (AO Kaspersky Lab) R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [251656 2017-07-04] (AO Kaspersky Lab) R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [112912 2017-07-04] (AO Kaspersky Lab) R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [173144 2017-07-04] (AO Kaspersky Lab) R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab) R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [136416 2017-03-14] (AO Kaspersky Lab) R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [199640 2017-07-24] (AO Kaspersky Lab) S3 ksapi64; C:\WINDOWS\system32\drivers\ksapi64.sys [56680 2016-06-03] (Kingsoft Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-02-09] (Malwarebytes Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [887552 2015-07-15] (Realtek ) S3 RtkAvrcp; C:\WINDOWS\System32\drivers\RtkAvrcp.sys [67840 2015-09-10] (Realtek Semiconductor Corporation) S3 RtkAvrcpCtrlr; C:\WINDOWS\System32\drivers\RtkAvrcpCtrlr.sys [70672 2015-05-12] (Realtek Semiconductor Corporation) R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [611096 2015-09-16] (Realtek Semiconductor Corporation) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5195776 2016-07-16] (Realtek Semiconductor Corporation ) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [X] ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Aangemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-10-23 13:12 - 2017-10-23 13:12 - 000053770 _____ C:\Users\wilfr\Downloads\Addition.txt 2017-10-23 13:11 - 2017-10-23 13:14 - 000024942 _____ C:\Users\wilfr\Downloads\FRST.txt 2017-10-23 13:09 - 2017-10-23 13:14 - 000000000 ____D C:\FRST 2017-10-23 13:09 - 2017-10-23 13:09 - 000001468 _____ C:\Users\wilfr\Downloads\FRST64.exe - Snelkoppeling.lnk 2017-10-23 13:08 - 2017-10-23 13:08 - 002402816 _____ (Farbar) C:\Users\wilfr\Downloads\FRST64.exe 2017-10-23 08:02 - 2017-10-23 08:02 - 000000000 ____D C:\Users\wilfr\AppData\LocalLow\uTorrent 2017-10-23 08:01 - 2017-10-23 08:01 - 000000000 __SHD C:\Users\wilfr\Desktop\0K, this directory is for Ransomware detection (just leave it here) 2017-10-23 08:01 - 2017-10-23 08:01 - 000000000 ___HD C:\Users\wilfr\Documents\1 versions115 2017-10-23 08:01 - 2017-10-23 08:01 - 000000000 ___HD C:\Users\wilfr\Documents\_svalues17 2017-10-23 07:05 - 2017-10-23 07:05 - 000523421 ____N C:\Users\Akfum0u\shorten_rural_extremely.xlsx 2017-10-23 07:05 - 2017-10-23 07:05 - 000513923 ____N C:\Users\xobxr\weeks-lands-wagner.xlsx 2017-10-23 07:05 - 2017-10-23 07:05 - 000220219 ____N C:\Users\xobxr\sections.spirit.mike.mdb 2017-10-23 07:05 - 2017-10-23 07:05 - 000205262 ____N C:\Users\Akfum0u\dissatisfaction.location.slavery.mdb 2017-10-23 07:05 - 2017-10-23 07:05 - 000078424 ____N C:\Users\Akfum0u\tim-medical.xls 2017-10-23 07:05 - 2017-10-23 07:05 - 000071361 ____N C:\Users\xobxr\nights-watson-adoption-must.xls 2017-10-23 07:05 - 2017-10-23 07:05 - 000055001 ____N C:\Users\xobxr\journal_coincide_oral_making.pem 2017-10-23 07:05 - 2017-10-23 07:05 - 000053797 ____N C:\Users\Akfum0u\contend-policies-axe-reasons.pem 2017-10-23 07:05 - 2017-10-23 07:05 - 000036482 ____N C:\Users\xobxr\package fewer.txt 2017-10-23 07:05 - 2017-10-23 07:05 - 000031945 ____N C:\Users\Akfum0u\rhode_hasten_beak.txt 2017-10-23 07:05 - 2017-10-23 07:05 - 000024794 ____N C:\Users\xobxr\weeksustainlived.sql 2017-10-23 07:05 - 2017-10-23 07:05 - 000024154 ____N C:\Users\Akfum0u\diagram.elections.pressing.expenditures.sql 2017-10-23 07:05 - 2017-10-23 07:05 - 000000000 ___HD C:\Users\xobxr 2017-10-23 07:05 - 2017-10-23 07:05 - 000000000 ___HD C:\Users\Akfum0u 2017-10-23 07:05 - 2017-10-23 07:05 - 000000000 ____D C:\zpstorage10 2017-10-23 07:05 - 2017-10-23 07:05 - 000000000 ____D C:\Acprogram21 2017-10-22 10:48 - 2017-10-22 10:48 - 000000000 ____D C:\Users\wilfr\AppData\Local\Microsoft_Corporation 2017-10-16 07:27 - 2017-10-16 07:27 - 000000000 ____D C:\Users\wilfr\AppData\Local\Hewlett-Packard 2017-10-12 17:55 - 2017-10-12 17:55 - 000087584 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys 2017-10-11 14:02 - 2017-10-11 14:02 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe 2017-10-11 14:01 - 2017-09-18 05:27 - 000218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2017-10-11 14:01 - 2017-09-18 05:09 - 007780192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-10-11 14:01 - 2017-09-18 05:09 - 002213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-10-11 14:01 - 2017-09-18 05:09 - 000646688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2017-10-11 14:01 - 2017-09-18 05:09 - 000133984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys 2017-10-11 14:01 - 2017-09-18 05:08 - 000998920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2017-10-11 14:01 - 2017-09-18 05:05 - 001177688 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2017-10-11 14:01 - 2017-09-18 05:05 - 000497424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2017-10-11 14:01 - 2017-09-18 05:05 - 000172536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2017-10-11 14:01 - 2017-09-18 05:04 - 001706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-10-11 14:01 - 2017-09-18 05:04 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2017-10-11 14:01 - 2017-09-18 05:03 - 000791272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2017-10-11 14:01 - 2017-09-18 05:02 - 007213464 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-10-11 14:01 - 2017-09-18 05:02 - 001860288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-10-11 14:01 - 2017-09-18 05:01 - 000431456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2017-10-11 14:01 - 2017-09-18 05:01 - 000223072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2017-10-11 14:01 - 2017-09-18 05:00 - 001072248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 022220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 008173672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 004260072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 001983408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 001702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2017-10-11 14:01 - 2017-09-18 04:59 - 000341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-10-11 14:01 - 2017-09-18 04:56 - 000057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe 2017-10-11 14:01 - 2017-09-18 04:55 - 005722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-10-11 14:01 - 2017-09-18 04:55 - 001431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-10-11 14:01 - 2017-09-18 04:54 - 001980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 020967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 006672680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 004023560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 001845512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 001360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 001277856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2017-10-11 14:01 - 2017-09-18 04:52 - 000981888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2017-10-11 14:01 - 2017-09-18 04:51 - 000178016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll 2017-10-11 14:01 - 2017-09-18 04:49 - 001435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2017-10-11 14:01 - 2017-09-18 04:49 - 001412128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-10-11 14:01 - 2017-09-18 04:49 - 001260784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-10-11 14:01 - 2017-09-18 04:48 - 000117792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2017-10-11 14:01 - 2017-09-18 04:36 - 022570496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-10-11 14:01 - 2017-09-18 04:35 - 000372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2017-10-11 14:01 - 2017-09-18 04:34 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-10-11 14:01 - 2017-09-18 04:33 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2017-10-11 14:01 - 2017-09-18 04:33 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-10-11 14:01 - 2017-09-18 04:32 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-10-11 14:01 - 2017-09-18 04:32 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll 2017-10-11 14:01 - 2017-09-18 04:31 - 006288384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-10-11 14:01 - 2017-09-18 04:31 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2017-10-11 14:01 - 2017-09-18 04:31 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-10-11 14:01 - 2017-09-18 04:31 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll 2017-10-11 14:01 - 2017-09-18 04:31 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2017-10-11 14:01 - 2017-09-18 04:30 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll 2017-10-11 14:01 - 2017-09-18 04:30 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2017-10-11 14:01 - 2017-09-18 04:29 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2017-10-11 14:01 - 2017-09-18 04:29 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll 2017-10-11 14:01 - 2017-09-18 04:29 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2017-10-11 14:01 - 2017-09-18 04:29 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll 2017-10-11 14:01 - 2017-09-18 04:28 - 000536064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2017-10-11 14:01 - 2017-09-18 04:28 - 000406016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll 2017-10-11 14:01 - 2017-09-18 04:28 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll 2017-10-11 14:01 - 2017-09-18 04:28 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2017-10-11 14:01 - 2017-09-18 04:28 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2017-10-11 14:01 - 2017-09-18 04:27 - 004615168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-10-11 14:01 - 2017-09-18 04:27 - 000719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2017-10-11 14:01 - 2017-09-18 04:27 - 000641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2017-10-11 14:01 - 2017-09-18 04:27 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2017-10-11 14:01 - 2017-09-18 04:27 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2017-10-11 14:01 - 2017-09-18 04:27 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2017-10-11 14:01 - 2017-09-18 04:27 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000538112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2017-10-11 14:01 - 2017-09-18 04:26 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2017-10-11 14:01 - 2017-09-18 04:26 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2017-10-11 14:01 - 2017-09-18 04:25 - 002333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2017-10-11 14:01 - 2017-09-18 04:25 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2017-10-11 14:01 - 2017-09-18 04:25 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 013107712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 007626240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 001589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 000819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 000755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2017-10-11 14:01 - 2017-09-18 04:24 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-10-11 14:01 - 2017-09-18 04:24 - 000409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2017-10-11 14:01 - 2017-09-18 04:23 - 000857600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2017-10-11 14:01 - 2017-09-18 04:23 - 000816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll 2017-10-11 14:01 - 2017-09-18 04:23 - 000636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2017-10-11 14:01 - 2017-09-18 04:23 - 000442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll 2017-10-11 14:01 - 2017-09-18 04:23 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2017-10-11 14:01 - 2017-09-18 04:23 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2017-10-11 14:01 - 2017-09-18 04:23 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2017-10-11 14:01 - 2017-09-18 04:22 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2017-10-11 14:01 - 2017-09-18 04:22 - 001137664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2017-10-11 14:01 - 2017-09-18 04:21 - 018364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 023677952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 019414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 002641920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 000937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll 2017-10-11 14:01 - 2017-09-18 04:20 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-10-11 14:01 - 2017-09-18 04:19 - 002750976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2017-10-11 14:01 - 2017-09-18 04:19 - 000549376 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-10-11 14:01 - 2017-09-18 04:19 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe 2017-10-11 14:01 - 2017-09-18 04:19 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 012204032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 008114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 008077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 007470592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 001145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2017-10-11 14:01 - 2017-09-18 04:18 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll 2017-10-11 14:01 - 2017-09-18 04:17 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-10-11 14:01 - 2017-09-18 04:17 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-10-11 14:01 - 2017-09-18 04:17 - 000641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2017-10-11 14:01 - 2017-09-18 04:16 - 004743168 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-10-11 14:01 - 2017-09-18 04:16 - 004596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe 2017-10-11 14:01 - 2017-09-18 04:16 - 003520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2017-10-11 14:01 - 2017-09-18 04:15 - 006065152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-10-11 14:01 - 2017-09-18 04:15 - 003202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2017-10-11 14:01 - 2017-09-18 04:15 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2017-10-11 14:01 - 2017-09-18 04:15 - 002538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-10-11 14:01 - 2017-09-18 04:15 - 002370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2017-10-11 14:01 - 2017-09-18 04:15 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 006474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-10-11 14:01 - 2017-09-18 04:14 - 003663360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 002997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-10-11 14:01 - 2017-09-18 04:14 - 002897408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 002740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 002682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 002649600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 002483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 001988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 001599488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 001556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 001518080 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-10-11 14:01 - 2017-09-18 04:14 - 001328640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 001170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000983552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2017-10-11 14:01 - 2017-09-18 04:14 - 000827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000657408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2017-10-11 14:01 - 2017-09-18 04:14 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 001013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2017-10-11 14:01 - 2017-09-18 04:13 - 000751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll 2017-10-11 14:01 - 2017-09-18 04:13 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll 2017-10-11 14:01 - 2017-09-18 04:12 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2017-10-11 14:01 - 2017-09-18 04:12 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2017-10-11 14:01 - 2017-09-18 04:12 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe 2017-10-11 14:01 - 2017-09-18 04:11 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2017-10-11 14:01 - 2017-09-18 04:11 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2017-10-11 14:01 - 2017-09-15 01:05 - 001302136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2017-10-11 14:01 - 2017-09-15 00:59 - 000096064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll 2017-10-11 14:01 - 2017-09-15 00:52 - 000136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll 2017-10-11 14:01 - 2017-09-15 00:49 - 001202936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2017-10-11 14:01 - 2017-09-15 00:34 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys 2017-10-11 14:01 - 2017-09-15 00:32 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollUI.dll 2017-10-11 14:01 - 2017-09-15 00:32 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll 2017-10-11 14:01 - 2017-09-15 00:31 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollUI.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000194560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB7.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll 2017-10-11 14:01 - 2017-09-15 00:30 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.UserConsentVerifier.dll 2017-10-11 14:01 - 2017-09-15 00:28 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll 2017-10-11 14:01 - 2017-09-15 00:28 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll 2017-10-11 14:01 - 2017-09-15 00:27 - 000662528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll 2017-10-11 14:01 - 2017-09-15 00:26 - 001167360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe 2017-10-11 14:01 - 2017-09-15 00:26 - 000636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll 2017-10-11 14:01 - 2017-09-15 00:26 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe 2017-10-11 14:01 - 2017-09-15 00:25 - 000529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2017-10-11 14:01 - 2017-09-15 00:24 - 000981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2017-10-11 14:01 - 2017-09-15 00:22 - 000987648 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2017-10-11 14:01 - 2017-09-15 00:22 - 000634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2017-10-11 14:01 - 2017-09-15 00:18 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2017-10-11 14:01 - 2017-09-15 00:18 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll 2017-10-11 14:01 - 2017-09-15 00:16 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\npfs.sys 2017-10-11 14:01 - 2017-09-15 00:15 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2017-10-11 14:01 - 2017-09-14 04:04 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll 2017-10-11 14:01 - 2017-09-14 04:04 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2017-10-11 14:01 - 2017-09-14 04:04 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll 2017-10-11 14:01 - 2017-03-04 08:28 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2017-10-11 14:01 - 2017-03-04 08:25 - 000748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2017-10-11 14:01 - 2017-03-04 08:24 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll 2017-10-11 14:01 - 2017-03-04 08:23 - 001184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2017-10-11 14:01 - 2017-03-04 08:23 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2017-10-11 14:01 - 2017-03-04 08:18 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2017-10-11 14:01 - 2017-03-04 08:16 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2017-10-11 14:01 - 2017-03-04 08:00 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-10-11 14:01 - 2017-03-04 08:00 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2017-10-11 14:01 - 2016-08-27 07:12 - 000244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2017-10-11 14:01 - 2016-08-02 10:13 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2017-10-11 14:00 - 2017-09-18 05:17 - 001564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2017-10-11 14:00 - 2017-09-18 05:17 - 000245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2017-10-11 14:00 - 2017-09-18 05:17 - 000136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2017-10-11 14:00 - 2017-09-18 05:08 - 002253664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2017-10-11 14:00 - 2017-09-18 05:05 - 000168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2017-10-11 14:00 - 2017-09-18 05:04 - 000404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-10-11 14:00 - 2017-09-18 05:01 - 002446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2017-10-11 14:00 - 2017-09-18 05:01 - 000624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2017-10-11 14:00 - 2017-09-18 04:59 - 000241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-10-11 14:00 - 2017-09-18 04:58 - 001600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2017-10-11 14:00 - 2017-09-18 04:58 - 000206688 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll 2017-10-11 14:00 - 2017-09-18 04:57 - 001566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-10-11 14:00 - 2017-09-18 04:57 - 001460696 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2017-10-11 14:00 - 2017-09-18 04:57 - 001415712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-10-11 14:00 - 2017-09-18 04:33 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransliterationRanker.dll 2017-10-11 14:00 - 2017-09-18 04:32 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2017-10-11 14:00 - 2017-09-18 04:32 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpninputrouter.dll 2017-10-11 14:00 - 2017-09-18 04:32 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmojiDS.dll 2017-10-11 14:00 - 2017-09-18 04:31 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuleBasedDS.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpnranker.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000174592 _____ C:\WINDOWS\system32\IHDS.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\VocabRoamingHandler.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\StaticDictDS.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll 2017-10-11 14:00 - 2017-09-18 04:30 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxranker.dll 2017-10-11 14:00 - 2017-09-18 04:29 - 009129984 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-10-11 14:00 - 2017-09-18 04:29 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChsStrokeDS.dll 2017-10-11 14:00 - 2017-09-18 04:28 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtHkStrokeDS.dll 2017-10-11 14:00 - 2017-09-18 04:28 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChsPinyinRanker.dll 2017-10-11 14:00 - 2017-09-18 04:28 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtfDecoder.dll 2017-10-11 14:00 - 2017-09-18 04:28 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll 2017-10-11 14:00 - 2017-09-18 04:28 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000626176 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxAPDS.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimeChsPinyinMainDS.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxHAPDS.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtCangjieDS.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtQuickDS.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpndecoder.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxinputrouter.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000326656 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll 2017-10-11 14:00 - 2017-09-18 04:27 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-10-11 14:00 - 2017-09-18 04:26 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2017-10-11 14:00 - 2017-09-18 04:26 - 000686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe 2017-10-11 14:00 - 2017-09-18 04:26 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2017-10-11 14:00 - 2017-09-18 04:26 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll 2017-10-11 14:00 - 2017-09-18 04:26 - 000396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvsc.dll 2017-10-11 14:00 - 2017-09-18 04:26 - 000176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2017-10-11 14:00 - 2017-09-18 04:25 - 001914368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2017-10-11 14:00 - 2017-09-18 04:25 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll 2017-10-11 14:00 - 2017-09-18 04:25 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2017-10-11 14:00 - 2017-09-18 04:24 - 002103808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2017-10-11 14:00 - 2017-09-18 04:24 - 001584640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2017-10-11 14:00 - 2017-09-18 04:22 - 004749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-10-11 14:00 - 2017-09-18 04:22 - 003291648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2017-10-11 14:00 - 2017-09-18 04:22 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2017-10-11 14:00 - 2017-09-18 04:22 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2017-10-11 14:00 - 2017-09-18 04:22 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll 2017-10-11 14:00 - 2017-09-18 04:19 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll 2017-10-11 14:00 - 2017-09-18 04:19 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2017-10-11 14:00 - 2017-09-18 04:18 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-10-11 14:00 - 2017-09-18 04:18 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-10-11 14:00 - 2017-09-18 04:18 - 000932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2017-10-11 14:00 - 2017-09-18 04:17 - 002279424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-10-11 14:00 - 2017-09-18 04:16 - 001484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2017-10-11 14:00 - 2017-09-18 04:15 - 002919936 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2017-10-11 14:00 - 2017-09-18 04:15 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-10-11 14:00 - 2017-09-18 04:15 - 001282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2017-10-11 14:00 - 2017-09-18 04:15 - 001231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-10-11 14:00 - 2017-09-18 04:15 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2017-10-11 14:00 - 2017-09-18 04:14 - 003615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-10-11 14:00 - 2017-09-18 04:14 - 002321408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-10-11 14:00 - 2017-09-18 04:14 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll 2017-10-11 14:00 - 2017-09-18 04:14 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2017-10-11 14:00 - 2017-09-18 04:14 - 000799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2017-10-11 14:00 - 2017-09-18 04:14 - 000650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-10-11 14:00 - 2017-09-18 04:13 - 001726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-10-11 14:00 - 2017-09-18 04:13 - 001121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-10-11 14:00 - 2017-09-18 04:13 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll 2017-10-11 14:00 - 2017-09-18 04:11 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\trie.dll 2017-10-11 14:00 - 2017-09-18 04:11 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFFuzzyDS.dll 2017-10-11 14:00 - 2017-09-18 04:11 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFSpellcheckDS.dll 2017-10-11 14:00 - 2017-09-15 01:14 - 000119328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll 2017-10-11 14:00 - 2017-09-15 00:32 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB7.dll 2017-10-11 14:00 - 2017-09-15 00:32 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll 2017-10-11 14:00 - 2017-09-15 00:32 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll 2017-10-11 14:00 - 2017-09-15 00:31 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-10-11 14:00 - 2017-09-15 00:31 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll 2017-10-11 14:00 - 2017-09-15 00:29 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll 2017-10-11 14:00 - 2017-09-15 00:25 - 000821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\comuid.dll 2017-10-11 14:00 - 2017-09-15 00:24 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe 2017-10-11 14:00 - 2017-09-15 00:23 - 000560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-10-11 14:00 - 2017-09-15 00:22 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2017-10-11 14:00 - 2017-09-15 00:20 - 002852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-10-11 14:00 - 2017-09-15 00:19 - 001421824 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe 2017-10-11 14:00 - 2017-09-15 00:19 - 000928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll 2017-10-11 14:00 - 2017-03-04 09:10 - 000360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-10-11 14:00 - 2017-03-04 08:11 - 001643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2017-10-11 14:00 - 2017-03-04 08:07 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-10-11 14:00 - 2016-08-06 06:16 - 000026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2017-10-10 12:32 - 2017-10-10 12:32 - 000004090 _____ C:\WINDOWS\System32\Tasks\Cybereason RansomFree Keepalive 2017-10-10 12:32 - 2017-10-10 12:32 - 000003196 _____ C:\WINDOWS\System32\Tasks\Cybereason RansomFree Autostart 2017-10-10 12:32 - 2017-10-10 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cybereason RansomFree 2017-10-05 15:17 - 2017-10-05 15:17 - 000000000 ____D C:\Users\wilfr\AppData\Local\YouTubeDownloader 2017-10-05 15:17 - 2017-10-05 15:17 - 000000000 ____D C:\Users\wilfr\AppData\Local\MediaHuman 2017-10-01 18:07 - 2017-10-01 18:08 - 000000000 ____D C:\ProgramData\OSDownloader 2017-10-01 18:07 - 2017-10-01 18:07 - 000001132 _____ C:\Users\Public\Desktop\OSDownloader.lnk 2017-10-01 18:07 - 2017-10-01 18:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OSDownloader 2017-10-01 18:07 - 2017-10-01 18:07 - 000000000 ____D C:\Program Files (x86)\OSDownloader 2017-10-01 18:06 - 2017-10-01 18:07 - 004511963 _____ (OpenSubtitles.org ) C:\Users\wilfr\Downloads\OSDownloader.exe 2017-09-30 17:32 - 2017-09-30 17:32 - 000000000 ____D C:\Users\wilfr\Documents\13 2017-09-29 12:31 - 2017-10-13 12:43 - 000000000 ____D C:\Program Files\rempl 2017-09-27 18:20 - 2017-09-27 18:20 - 034552912 _____ (Digital Wave Ltd ) C:\Users\wilfr\Downloads\FreeYouTubeToMP3Converter_4.1.41.323_o.exe 2017-09-26 12:31 - 2017-09-26 12:34 - 000000000 ____D C:\Intel 2017-09-23 18:42 - 2017-09-23 18:45 - 000000000 ____D C:\Users\wilfr\AppData\Local\IIIQF 2017-09-23 08:28 - 2017-09-23 08:28 - 000001369 _____ C:\Users\Public\Desktop\Freemake YouTube To MP3 Boom.lnk 2017-09-23 08:28 - 2017-09-23 08:28 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\YoutubeToMp3Converter 2017-09-23 08:27 - 2017-09-23 08:27 - 001832640 _____ (Ellora Assets Corporation ) C:\Users\wilfr\Downloads\FreemakeYouTubeToMP3BoomSetup.exe ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-10-23 13:14 - 2016-04-02 18:02 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\uTorrent 2017-10-23 13:12 - 2016-07-16 13:45 - 000000000 ____D C:\WINDOWS\INF 2017-10-23 13:10 - 2016-04-04 15:35 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\vlc 2017-10-23 13:05 - 2016-10-22 13:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2017-10-23 11:24 - 2016-10-22 13:45 - 000000000 ____D C:\Users\wilfr 2017-10-23 08:02 - 2016-11-17 13:35 - 000000000 ____D C:\Users\wilfr\AppData\LocalLow\Mozilla 2017-10-23 08:02 - 2016-04-16 09:51 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2017-10-23 08:01 - 2016-10-22 13:42 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-10-23 08:01 - 2016-04-01 19:43 - 000000000 __SHD C:\Users\wilfr\IntelGraphicsProfiles 2017-10-23 07:09 - 2016-07-17 00:15 - 000202926 _____ C:\WINDOWS\system32\perfh013.dat 2017-10-23 07:09 - 2016-07-17 00:15 - 000064778 _____ C:\WINDOWS\system32\perfc013.dat 2017-10-23 07:09 - 2015-07-25 19:00 - 001476496 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-10-23 07:05 - 2016-10-22 13:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-10-22 20:28 - 2016-07-16 08:04 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2017-10-22 14:52 - 2016-04-30 07:54 - 000000000 ____D C:\Users\wilfr\Downloads\U-TORRENT 2017-10-21 16:59 - 2016-04-23 16:59 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\dvdcss 2017-10-21 13:38 - 2017-07-26 14:45 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1228691392-3513963491-2876946990-1003 2017-10-21 13:38 - 2016-12-15 18:01 - 000000000 ___RD C:\Users\wilfr\OneDrive 2017-10-21 13:38 - 2016-04-01 19:45 - 000002391 _____ C:\Users\wilfr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-10-20 11:36 - 2016-09-04 07:30 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-10-19 16:06 - 2016-08-20 14:29 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\DVDVideoSoft 2017-10-19 15:42 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-10-18 12:40 - 2016-07-16 13:47 - 000000000 ___HD C:\Program Files\WindowsApps 2017-10-18 12:31 - 2016-07-16 13:36 - 000000000 ____D C:\WINDOWS\CbsTemp 2017-10-16 13:59 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-10-16 13:59 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\system32\Macromed 2017-10-14 17:55 - 2016-04-16 09:51 - 001021656 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys 2017-10-14 17:55 - 2016-04-16 09:51 - 000197344 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys 2017-10-14 12:00 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\rescache 2017-10-13 00:27 - 2017-03-17 13:31 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-10-13 00:27 - 2017-03-17 13:31 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-12 12:32 - 2016-02-13 15:33 - 000000000 __RHD C:\Users\Public\AccountPictures 2017-10-12 12:27 - 2017-09-08 12:28 - 000413344 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-10-11 19:50 - 2016-07-16 13:47 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-10-11 19:50 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\system32\oobe 2017-10-11 19:50 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\ShellExperiences 2017-10-11 14:04 - 2016-04-02 15:12 - 000000000 ____D C:\WINDOWS\system32\MRT 2017-10-11 14:02 - 2015-11-17 10:29 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-10-07 07:29 - 2016-11-23 16:03 - 000000000 ____D C:\Program Files\Mozilla Firefox 2017-10-07 07:29 - 2016-11-23 16:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-09-30 22:47 - 2016-04-28 15:49 - 000000000 ____D C:\Users\wilfr\AppData\Local\tkdata 2017-09-28 12:29 - 2016-04-01 19:45 - 000002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-09-28 12:29 - 2016-04-01 19:45 - 000002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-09-27 18:21 - 2017-09-22 20:41 - 000001479 _____ C:\Users\Public\Desktop\Free YouTube To MP3 Converter.lnk 2017-09-27 18:21 - 2017-09-22 20:41 - 000001416 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2017-09-27 18:21 - 2017-09-22 20:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-09-27 18:21 - 2017-09-22 20:41 - 000000000 ____D C:\Program Files (x86)\DVDVideoSoft 2017-09-26 12:31 - 2016-10-22 13:42 - 000000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2017-09-25 17:56 - 2015-07-25 19:19 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-09-25 17:55 - 2015-07-25 19:15 - 000000000 ____D C:\ProgramData\Temp 2017-09-25 14:50 - 2017-01-23 16:30 - 000000000 ____D C:\Users\wilfr\AppData\Local\Adobe 2017-09-24 16:04 - 2016-11-25 17:20 - 000001247 _____ C:\Users\wilfr\Desktop\Facebook Gameroom.lnk 2017-09-24 16:04 - 2016-11-25 17:20 - 000000000 ____D C:\Users\wilfr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook 2017-09-24 16:04 - 2016-11-25 17:20 - 000000000 ____D C:\Users\wilfr\AppData\Local\Facebook 2017-09-24 14:54 - 2016-09-28 18:33 - 000000608 _____ C:\Users\wilfr\Desktop\WDTVLiveHub (WDTVLIVEHUB2) (Z) - Snelkoppeling.lnk 2017-09-24 05:51 - 2017-02-27 18:13 - 000000000 ____D C:\ProgramData\Belgium Identity Card 2017-09-24 05:51 - 2016-06-02 14:56 - 000000000 ____D C:\Program Files (x86)\Belgium Identity Card 2017-09-24 05:49 - 2017-06-06 15:17 - 000000000 ____D C:\ProgramData\WinZip 2017-09-23 18:43 - 2015-07-10 13:04 - 000000222 _____ C:\WINDOWS\win.ini 2017-09-23 08:28 - 2016-05-17 15:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake 2017-09-23 08:28 - 2016-05-17 15:42 - 000000000 ____D C:\ProgramData\Freemake 2017-09-23 08:28 - 2016-05-17 15:42 - 000000000 ____D C:\Program Files (x86)\Freemake ==================== Bestanden in de root van sommige mappen ======= 2016-10-22 13:43 - 2016-10-22 13:43 - 000000000 ____H () C:\ProgramData\DP45977C.lfl 2016-12-26 18:09 - 2017-01-02 14:11 - 000001261 _____ () C:\ProgramData\hpzinstall.log 2017-07-18 16:39 - 2017-07-18 16:39 - 000000032 _____ () C:\ProgramData\Temp.log ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\WINDOWS\system32\winlogon.exe => Bestand is getekend C:\WINDOWS\system32\wininit.exe => Bestand is getekend C:\WINDOWS\explorer.exe => Bestand is getekend C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend C:\WINDOWS\system32\svchost.exe => Bestand is getekend C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend C:\WINDOWS\system32\services.exe => Bestand is getekend C:\WINDOWS\system32\User32.dll => Bestand is getekend C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend C:\WINDOWS\system32\userinit.exe => Bestand is getekend C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend C:\WINDOWS\system32\rpcss.dll => Bestand is getekend C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2017-10-17 12:36 ==================== Eind van FRST.txt ============================