Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 12-11-2017 Gestart door Qtera69 (Beheerder) op QTERA69-TOSH (12-11-2017 16:40:04) Gestart vanaf C:\Users\Qtera69\Downloads Geladen Profielen: Qtera69 (Beschikbare Profielen: Qtera69) Platform: Windows 10 Home Versie 1703 15063.674 (X64) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: Chrome) Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.225\WsAppService.exe (Wondershare) C:\Program Files (x86)\Wondershare\dr.fone toolkit voor iOS\Library\DriverInstaller\DriverInstall.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Megaify Software Co., Ltd.) C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Polar Electro Oy) C:\Program Files (x86)\Polar\Polar FlowSync\flowsync.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe ==================== Register (gefilterd) =========================== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-12] (AVAST Software) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-10-20] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-06-09] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [235624 2015-01-09] (CANON INC.) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1053144 2017-06-07] (DivX, LLC) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== AANDACHT HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9364696 2017-03-03] (Piriform Ltd) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\Office15\lync.exe [28163792 2017-09-12] (Microsoft Corporation) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-10-19] (Apple Inc.) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-10-19] (Apple Inc.) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [TomTom MySports Connect.exe] => C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe [638464 2017-08-23] (TomTom) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [1906088 2017-01-17] (TomTom) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [uTorrent] => C:\Users\Qtera69\AppData\Roaming\uTorrent\uTorrent.exe [1982144 2017-09-29] (BitTorrent Inc.) HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\...\Run: [Polar FlowSync] => C:\Program Files (x86)\Polar\Polar FlowSync\FlowSync.exe [1191936 2015-11-19] (Polar Electro Oy) GroupPolicy: Restrictie - Chrome <==== AANDACHT ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.4 Tcpip\..\Interfaces\{0959ac1d-93f2-4133-8502-393b1be0397b}: [DhcpNameServer] 195.130.131.4 195.130.130.4 Internet Explorer: ================== HKU\S-1-5-21-3587330891-1572245818-3806218168-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/nl-be/?ocid=iehp BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-09-12] (Microsoft Corporation) BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-09-26] (Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-26] (Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2017-08-15] (Microsoft Corporation) FireFox: ======== FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2015-10-29] (CANON INC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2017-06-06] (DivX, LLC) FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-09-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-09-26] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-08-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2017-08-24] (Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Profile 2 CHR StartupUrls: Profile 2 -> "hxxps://www.google.be/" CHR Profile: C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-17] CHR Profile: C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2 [2017-11-12] CHR Extension: (Presentaties) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15] CHR Extension: (Documenten) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15] CHR Extension: (Google Drive) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-30] CHR Extension: (YouTube) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-30] CHR Extension: (Adblock Plus) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-27] CHR Extension: (Avast SafePrice) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-10-19] CHR Extension: (iCloud-bladwijzers) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-10-11] CHR Extension: (Offline Documenten) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-30] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Gmail) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-30] CHR Extension: (Chrome Media Router) - C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-27] CHR Profile: C:\Users\Qtera69\AppData\Local\Google\Chrome\User Data\System Profile [2017-09-27] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-10-11] (Apple Inc.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7549928 2017-11-12] (AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-12] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [332368 2017-11-12] (AVAST Software) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-25] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-25] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [387144 2016-02-04] () R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [5286152 2016-05-16] (INCA Internet Co., Ltd.) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-05-04] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-11] (Microsoft Corporation) R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.225\WsAppService.exe [473824 2017-05-05] (Wondershare) R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone toolkit voor iOS\Library\DriverInstaller\DriverInstall.exe [119008 2017-06-28] (Wondershare) S2 RtkAudioService; "C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe" [X] ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [183584 2017-11-12] (AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [321032 2017-11-12] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [198968 2017-11-12] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343288 2017-11-12] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57728 2017-11-12] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [47008 2017-11-12] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41832 2017-09-12] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [148288 2017-11-12] (AVAST Software) R1 aswNetSec; C:\WINDOWS\System32\drivers\aswNetSec.sys [570152 2017-11-12] (AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110376 2017-11-12] (AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84416 2017-11-12] (AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1026232 2017-11-12] (AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [455384 2017-11-12] (AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [203976 2017-11-12] (AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [364464 2017-11-12] (AVAST Software) R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77432 2017-11-01] () R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193464 2017-11-12] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2017-11-12] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [46008 2017-11-12] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2017-11-12] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2017-11-12] (Malwarebytes) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek ) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [51392 2016-11-23] (Synaptics Incorporated) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 tapoas; C:\WINDOWS\System32\drivers\tapoas.sys [30720 2012-07-15] (The OpenVPN Project) R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [54424 2015-08-03] (Toshiba Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Aangemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-11-12 16:40 - 2017-11-12 16:40 - 000020621 _____ C:\Users\Qtera69\Downloads\FRST.txt 2017-11-12 16:40 - 2017-11-12 16:40 - 000000000 ____D C:\FRST 2017-11-12 16:39 - 2017-11-12 16:39 - 002392576 _____ (Farbar) C:\Users\Qtera69\Downloads\FRST64.exe 2017-11-12 16:39 - 2017-11-12 16:39 - 000000000 ____D C:\ProgramData\SWCUTemp 2017-11-12 14:52 - 2017-11-12 14:57 - 000000000 ____D C:\Program Files\KMSpico 2017-11-12 14:16 - 2017-11-12 16:32 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-11-12 14:16 - 2017-11-12 16:32 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-11-12 14:16 - 2017-11-12 16:32 - 000046008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-11-12 14:16 - 2017-11-12 14:16 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2017-11-12 14:16 - 2017-11-12 14:16 - 000193464 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2017-11-12 14:16 - 2017-11-12 14:16 - 000001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-11-12 14:16 - 2017-11-12 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-11-12 14:16 - 2017-11-12 14:16 - 000000000 ____D C:\Program Files\Malwarebytes 2017-11-12 14:16 - 2017-11-01 08:54 - 000077432 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-11-12 14:15 - 2017-11-12 14:15 - 000000000 ____D C:\ProgramData\MB2Migration 2017-11-12 13:07 - 2017-11-12 13:07 - 000000262 __RSH C:\Users\Qtera69\ntuser.pol 2017-11-12 13:06 - 2017-11-12 13:05 - 000183584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2017-11-12 13:05 - 2017-11-12 13:05 - 000365168 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2017-11-12 13:02 - 2017-11-12 13:02 - 000000262 __RSH C:\ProgramData\ntuser.pol 2017-11-12 13:01 - 2017-11-12 13:31 - 000000000 ____D C:\Users\Qtera69\AppData\Local\AdService 2017-11-12 13:01 - 2017-11-12 13:01 - 000140800 _____ C:\Users\Qtera69\AppData\Local\installer.dat 2017-11-12 13:01 - 2017-11-12 13:01 - 000003726 _____ C:\WINDOWS\System32\Tasks\{C0489643-44C5-F8B8-C343-DB054549A834} 2017-11-12 13:01 - 2017-11-12 13:01 - 000000000 ____D C:\Users\Qtera69\AppData\Local\AdvinstAnalytics 2017-11-12 12:58 - 2017-11-12 13:28 - 000000000 ____D C:\Program Files\Office 2016 KMS Activator Ultimate v1.1 Final 2017-11-12 12:58 - 2017-11-12 12:58 - 000001290 _____ C:\Users\Public\Desktop\Office 2016 KMS Activator Ultimate v1.1.lnk 2017-11-12 12:57 - 2017-11-12 16:19 - 000000000 ____D C:\Users\Qtera69\Downloads\DriverPack Solution 17.7.73 Multilingual 2017-11-09 19:43 - 2017-11-09 19:43 - 000241986 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (6).xlsx 2017-11-07 17:14 - 2017-11-07 17:14 - 000237611 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (5).xlsx 2017-11-07 16:08 - 2017-11-07 16:08 - 000237209 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (4).xlsx 2017-11-07 13:37 - 2017-11-07 13:37 - 000068255 _____ C:\Users\Qtera69\Downloads\bpost-label (1).pdf 2017-11-06 21:50 - 2017-11-06 21:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2017-11-06 21:49 - 2017-11-06 21:49 - 000001823 _____ C:\Users\Public\Desktop\iTunes.lnk 2017-11-06 21:49 - 2017-11-06 21:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2017-11-06 21:49 - 2017-11-06 21:49 - 000000000 ____D C:\Program Files\iTunes 2017-11-06 21:49 - 2017-11-06 21:49 - 000000000 ____D C:\Program Files\iPod 2017-11-04 13:29 - 2017-11-04 13:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-11-01 17:48 - 2017-11-01 18:04 - 000000000 ____D C:\Users\Qtera69\Downloads\Deepwater.Horizon.2016.HDRip.XViD-ETRG 2017-11-01 17:20 - 2017-11-01 17:32 - 1276621466 _____ C:\Users\Qtera69\Downloads\Deepwater.Horizon.2016.1080p.WEB.DL.HEVC.2CH.x265.mkv 2017-11-01 12:58 - 2017-11-01 12:58 - 000051016 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2017-11-01 12:58 - 2017-11-01 12:58 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2017-10-31 22:46 - 2017-10-31 22:46 - 000030711 _____ C:\Users\Qtera69\Downloads\The.Assignment.2016.720p.BluRay.x264.[YTS.AG] Dutch.zip 2017-10-26 13:30 - 2017-10-26 13:30 - 000113547 _____ C:\Users\Qtera69\Downloads\dagstaten overzicht ploegen20171026.xlsx 2017-10-25 14:49 - 2017-10-25 14:49 - 000217020 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (3).xlsx 2017-10-25 14:47 - 2017-10-25 14:47 - 000279718 _____ C:\Users\Qtera69\Downloads\Ref 5 Sept - Okt 2017 (8).xlsx 2017-10-23 15:07 - 2017-10-23 15:07 - 000210407 _____ C:\Users\Qtera69\Downloads\SS11184226-20171017.pdf 2017-10-22 18:44 - 2017-10-31 12:08 - 000000000 ____D C:\ProgramData\boost_interprocess 2017-10-22 18:44 - 2017-10-22 18:44 - 000001239 _____ C:\Users\Public\Desktop\Polar FlowSync.lnk 2017-10-22 18:44 - 2017-10-22 18:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Polar 2017-10-22 18:44 - 2017-10-22 18:44 - 000000000 ____D C:\Program Files (x86)\Polar 2017-10-22 18:42 - 2017-10-22 18:42 - 023793864 _____ (Polar Electro Oy ) C:\Users\Qtera69\Downloads\FlowSync_2.6.2 (2).exe 2017-10-22 10:20 - 2017-10-22 10:20 - 000184850 _____ C:\Users\Qtera69\Downloads\7063491317.pdf 2017-10-20 15:42 - 2017-10-20 15:42 - 000278257 _____ C:\Users\Qtera69\Downloads\Ref 5 Sept - Okt 2017 (7).xlsx 2017-10-20 15:39 - 2017-10-20 15:39 - 000216666 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (2).xlsx 2017-10-20 10:41 - 2017-10-20 10:41 - 000278170 _____ C:\Users\Qtera69\Downloads\Ref 5 Sept - Okt 2017 (6).xlsx 2017-10-19 19:38 - 2017-10-19 19:38 - 000000000 ____D C:\Users\Qtera69\Downloads\P!nk - Beautiful Trauma [2017] 320 KBPS MP3 2017-10-19 15:59 - 2017-10-19 15:59 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2017-10-19 15:59 - 2017-10-19 15:59 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple 2017-10-19 15:59 - 2017-10-19 15:59 - 000000000 ____D C:\Program Files (x86)\Apple Software Update 2017-10-19 15:54 - 2017-10-19 15:56 - 260623688 _____ (Apple Inc.) C:\Users\Qtera69\Downloads\iTunes64Setup.exe 2017-10-19 15:51 - 2017-10-19 15:53 - 200228680 _____ (Apple Inc.) C:\Users\Qtera69\Downloads\iTunesSetup (1).exe 2017-10-18 16:53 - 2017-10-18 16:53 - 000212853 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017 (1).xlsx 2017-10-17 16:00 - 2017-10-17 16:00 - 000219676 _____ C:\Users\Qtera69\Downloads\REf 6 Nov - Dec 2017.xlsx 2017-10-15 20:21 - 2017-10-15 20:24 - 000000000 ____D C:\Users\Qtera69\Downloads\Harley.And.The.Davidsons.2016.COMPLETE.MINI-SERIES.720p.BrRip.2CH.x265.HEVC-PSA 2017-10-15 16:44 - 2017-10-15 17:05 - 000477271 _____ C:\Users\Qtera69\Downloads\QL4 Espace lecture - Les gestes (2).odt 2017-10-13 14:56 - 2017-10-13 14:56 - 000216964 _____ C:\Users\Qtera69\Downloads\SSDGPI_T_17_1001313.pdf ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-11-12 16:38 - 2017-09-30 13:46 - 006078184 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-11-12 16:38 - 2017-03-20 04:54 - 003006678 _____ C:\WINDOWS\system32\perfh013.dat 2017-11-12 16:38 - 2017-03-20 04:54 - 000811138 _____ C:\WINDOWS\system32\perfc013.dat 2017-11-12 16:32 - 2017-09-30 16:05 - 000000388 _____ C:\WINDOWS\Tasks\DriverToolkit Autorun.job 2017-11-12 16:32 - 2017-09-30 13:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-11-12 16:32 - 2017-03-18 12:40 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2017-11-12 16:32 - 2016-04-22 18:23 - 000000000 ____D C:\Users\Qtera69\AppData\Roaming\uTorrent 2017-11-12 16:32 - 2016-04-22 15:56 - 000000000 ____D C:\Users\Qtera69\Documents\Outlook Files 2017-11-12 16:04 - 2017-09-30 13:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2017-11-12 14:16 - 2016-06-14 07:45 - 000000000 ____D C:\ProgramData\Malwarebytes 2017-11-12 14:15 - 2017-09-29 17:20 - 000000000 ___DC C:\WINDOWS\Panther 2017-11-12 14:15 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF 2017-11-12 13:31 - 2017-09-30 13:33 - 000000000 ____D C:\Users\Qtera69 2017-11-12 13:31 - 2017-08-30 09:24 - 000000000 _____ C:\WINDOWS\SysWOW64\last.dump 2017-11-12 13:31 - 2017-03-18 22:03 - 000000000 ___RD C:\WINDOWS\Offline Web Pages 2017-11-12 13:13 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps 2017-11-12 13:13 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-11-12 13:06 - 2017-09-30 13:41 - 000003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2017-11-12 13:06 - 2017-06-07 07:38 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-11-12 13:05 - 2017-02-09 08:13 - 000343288 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys 2017-11-12 13:05 - 2017-02-09 08:13 - 000321032 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2017-11-12 13:05 - 2017-02-09 08:13 - 000198968 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2017-11-12 13:05 - 2017-02-09 08:13 - 000057728 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys 2017-11-12 13:05 - 2016-05-21 11:02 - 000570152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 001026232 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000455384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000364464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000203976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000148288 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2017-11-12 13:05 - 2016-04-22 18:29 - 000047008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2017-11-12 13:02 - 2016-04-22 13:45 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-11-12 11:59 - 2017-09-30 13:41 - 000004198 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{410998AA-9647-4F0A-BD83-06741B5BDE76} 2017-11-08 11:33 - 2017-03-17 13:22 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-11-08 11:33 - 2017-03-17 13:22 - 000002287 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-11-07 07:58 - 2017-09-30 13:49 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3587330891-1572245818-3806218168-1001 2017-11-07 07:58 - 2016-04-22 14:13 - 000002400 _____ C:\Users\Qtera69\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-11-07 07:58 - 2015-08-03 12:40 - 000000000 ___RD C:\Users\Qtera69\OneDrive 2017-11-07 07:56 - 2017-01-03 12:35 - 000000000 ____D C:\Users\Qtera69\AppData\Local\597B98B5-9F6C-4815-91AA-EACF4B0872F8.aplzod 2017-11-07 07:54 - 2017-01-03 12:35 - 000000000 ___RD C:\Users\Qtera69\iCloudDrive 2017-11-05 21:39 - 2017-05-30 19:24 - 000000000 ____D C:\ProgramData\CanonIJPLM 2017-11-04 13:29 - 2016-10-25 11:57 - 000000000 ____D C:\Program Files (x86)\Dropbox 2017-10-24 13:36 - 2017-01-03 12:35 - 000000000 ____D C:\Users\Qtera69\AppData\Local\Apple Inc 2017-10-24 13:36 - 2016-05-22 12:48 - 000000000 ____D C:\Users\Qtera69\AppData\Local\Apple 2017-10-24 13:35 - 2016-05-22 12:49 - 000000000 ____D C:\Users\Qtera69\AppData\Local\Apple Computer 2017-10-19 17:09 - 2016-04-22 14:08 - 000000000 ____D C:\Users\Qtera69\AppData\Local\Packages 2017-10-19 16:01 - 2016-05-22 12:49 - 000000000 ____D C:\Users\Qtera69\AppData\Roaming\Apple Computer 2017-10-19 15:59 - 2016-05-22 12:48 - 000000000 ____D C:\Program Files\Common Files\Apple 2017-10-19 15:58 - 2016-05-22 12:47 - 000000000 ____D C:\ProgramData\Apple 2017-10-18 10:49 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp 2017-10-15 20:09 - 2015-02-27 16:34 - 000000000 ____D C:\Users\Qtera69\Documents\killian's map voor alles derp 2017-10-15 19:34 - 2016-04-22 18:12 - 000000000 ____D C:\ProgramData\AVAST Software 2017-10-13 15:15 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache 2017-10-13 01:21 - 2017-03-18 22:06 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-10-13 01:21 - 2017-03-18 22:06 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bestanden in de root van sommige mappen ======= 2017-11-12 13:01 - 2017-11-12 13:01 - 000140800 _____ () C:\Users\Qtera69\AppData\Local\installer.dat ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\WINDOWS\system32\winlogon.exe => Bestand is getekend C:\WINDOWS\system32\wininit.exe => Bestand is getekend C:\WINDOWS\explorer.exe => Bestand is getekend C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend C:\WINDOWS\system32\svchost.exe => Bestand is getekend C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend C:\WINDOWS\system32\services.exe => Bestand is getekend C:\WINDOWS\system32\User32.dll => Bestand is getekend C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend C:\WINDOWS\system32\userinit.exe => Bestand is getekend C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend C:\WINDOWS\system32\rpcss.dll => Bestand is getekend C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2017-10-31 14:10 ==================== Eind van FRST.txt ============================