Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 14.03.2018 Gestart door jan (Beheerder) op KAMERPC (25-03-2018 11:55:55) Gestart vanaf C:\Users\jan\Desktop Geladen Profielen: jan (Beschikbare Profielen: jan) Platform: Windows 10 Home Versie 1607 14393.693 (X64) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: Chrome) Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, zal het proces worden gesloten. Het bestand zal niet worden verplaatst.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (ABN AMRO) C:\Program Files (x86)\ABN AMRO e.dentifier2\wss\becwssvr.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\fshoster32.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\apps\CCF_Reputation\fsorsp.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Anti-Virus\fsgk32.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Common\FSMA32.EXE (F-Secure Corporation) C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Common\FSHDLL64.EXE (F-Secure Corporation) C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Anti-Virus\fssm32.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (F-Secure Corporation) C:\Program Files (x86)\Safe Online\fshoster32.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (CyberLink Corp.) C:\Program Files (x86)\Power2Go8\Power2GoExpress8.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (© 2015 Microsoft Corporation) C:\Users\jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Avanquest Software) C:\Users\jan\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (LG Electronics) C:\Program Files (x86)\LG Electronics\Screen Split\bin\ScreenSplit.exe (TODO: ) C:\Program Files (x86)\LG Electronics\Screen Split\bin\ScreenSplitterHook64App.exe (Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Microsoft Corporation) C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.exe (Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (CyberLink) C:\Program Files (x86)\Power2Go8\CLMLSvc_P2G8.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (ABN AMRO) C:\Program Files (x86)\ABN AMRO e.dentifier2\wss\becwsupa.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Agent\WDDriveAgent.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe () C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\CNext\CCCSlim\MOM.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\CNext\CCCSlim\CCC.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.16122.10291.0_x64__8wekyb3d8bbwe\Video.UI.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40785.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40785.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.16122.10271.0_x64__8wekyb3d8bbwe\Music.UI.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Register (gefilterd) =========================== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [8027016 2016-11-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-02] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567936 2018-03-15] (Dropbox, Inc.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Power2Go8\VirtualDrive.exe [490760 2013-08-19] (CyberLink Corp.) HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare) HKLM-x32\...\Run: [Becwsupa] => C:\Program Files (x86)\ABN AMRO e.dentifier2\wss\becwsupa.exe [162136 2014-11-28] (ABN AMRO) HKLM-x32\...\Run: [UpdatePDRShortCut] => E:\Program Files (x86)\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [56265184 2018-02-20] (Western Digital Corporation) HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2017-10-04] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WDDriveAgent] => C:\Program Files (x86)\Western Digital\WD Drive Agent\WDDriveAgent.exe [2310432 2018-01-31] (Western Digital Technologies, Inc.) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [Power2GoExpress8] => C:\Program Files (x86)\Power2Go8\Power2GoExpress8.exe [1713416 2013-08-19] (CyberLink Corp.) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [912480 2015-09-02] (Microsoft Corporation) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [BingSvc] => C:\Users\jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [Avanquest Message] => C:\Users\jan\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [498152 2017-10-27] (Avanquest Software) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [ScreenSplitter] => C:\Program Files (x86)\LG Electronics\Screen Split\bin\ScreenSplit.exe [1964528 2015-09-24] (LG Electronics) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [17488872 2018-02-15] (Plex, Inc.) HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [37376 2016-07-16] (Microsoft Corporation) SSODL: WDFSMountNotificator-wdfsconnect2017 - {C901B1E5-10FF-482B-905A-4970D1AEFF0C} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {C901B1E5-10FF-482B-905A-4970D1AEFF0C} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2016-04-15] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.exe [2016-07-16] (Microsoft Corporation) ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== AANDACHT (Restrictie - ProxySettings) ProxyEnable: [HKLM] => Proxy is ingeschakeld. ProxyEnable: [HKLM-x32] => Proxy is ingeschakeld. ProxyServer: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080 ProxyServer: [HKLM-x32] => http=127.0.0.1:8080;https=127.0.0.1:8080 AutoConfigURL: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080 Tcpip\Parameters: [DhcpNameServer] 89.101.251.229 89.101.251.228 Tcpip\..\Interfaces\{2cbb3a27-3c3d-4ab2-812f-539daac9cff2}: [DhcpNameServer] 89.101.251.229 89.101.251.228 ManualProxies: 1http=127.0.0.1:8080;https=127.0.0.1:8080 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <==== AANDACHT HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-dd__alt__ddc_dsssyc_bd_com BHO: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2017-11-01] (F-Secure Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Geen Naam -> {C901B1E5-10FF-482B-905A-4970D1AEFF0C}' -> Geen bestand BHO-x32: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2017-11-01] (F-Secure Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Geen Naam -> {C901B1E5-10FF-482B-905A-4970D1AEFF0C}' -> Geen bestand FireFox: ======== FF HKLM\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi FF Extension: (Browsing Protection by F-Secure) - C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi [2017-11-01] FF HKLM-x32\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @ABNAMRO/BECON,version=1.00 -> C:\Program Files (x86)\ABN AMRO e.dentifier2\Mozilla\npBECON.dll [2014-11-28] (ABN AMRO) FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://services.srchnet.net/search/{searchTerms} CHR DefaultSearchKeyword: Default -> SearchWeb CHR DefaultSuggestURL: Default -> hxxps://sug.srchnet.net/sug/?s={searchTerms} CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default [2018-03-25] CHR Extension: (Presentaties) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15] CHR Extension: (Documenten) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15] CHR Extension: (Google Drive) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-26] CHR Extension: (YouTube) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-26] CHR Extension: (Google Search) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-26] CHR Extension: (Adobe Acrobat) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05] CHR Extension: (Spreadsheets) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15] CHR Extension: (Offline Documenten) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Browsing Protection by F-Secure) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2018-02-09] CHR Extension: (Skype) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-02] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27] CHR Extension: (SearchWeb) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oegkbllcpodhifmcjdakmipcpjajjobc [2017-12-21] CHR Extension: (Gmail) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-26] CHR Extension: (Chrome Media Router) - C:\Users\jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-02] CHR Profile: C:\Users\jan\AppData\Local\Google\Chrome\User Data\System Profile [2017-09-30] CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2660865958-1059967550-4289563984-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [155016 2016-11-21] () R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] () R2 becwssvr; C:\Program Files (x86)\ABN AMRO e.dentifier2\wss\becwssvr.exe [1758552 2014-11-28] (ABN AMRO) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-27] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-27] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2018-03-15] (Dropbox, Inc.) R2 fshoster; C:\Program Files (x86)\Safe Online\fshoster32.exe [181216 2017-01-05] (F-Secure Corporation) R3 FSMA; C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Common\FSMA32.EXE [218080 2016-10-26] (F-Secure Corporation) R2 fsnethoster; C:\Program Files (x86)\Safe Online\fshoster32.exe [181216 2017-01-05] (F-Secure Corporation) R2 FSORSPClient; C:\Program Files (x86)\Safe Online\apps\CCF_Reputation\fsorsp.exe [67640 2017-07-26] (F-Secure Corporation) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] () S3 Media Jukebox 14 Service; C:\Program Files (x86)\J River\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.) R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2209256 2018-02-15] (Plex, Inc.) R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2008-12-31] () S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [523040 2018-01-31] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X] S3 WD Backup Drive Helper; C:\WINDOWS\SysWoW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} S3 WD Backup Snapshot; C:\WINDOWS\SysWoW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) S3 61883; C:\WINDOWS\System32\drivers\61883.sys [61952 2016-07-16] (Microsoft Corporation) S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.) R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [26568848 2017-01-25] (Advanced Micro Devices, Inc.) R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [536600 2017-01-25] (Advanced Micro Devices, Inc.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] () R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-07-24] (Advanced Micro Devices) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 e.dentifier2; C:\WINDOWS\system32\DRIVERS\aabed2.sys [28672 2008-03-20] (Todos Data System AB) R3 F-Secure Gatekeeper; C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\Anti-Virus\minifilter\FSgk.sys [230552 2017-07-26] (F-Secure Corporation) R1 F-Secure HIPS; C:\Program Files (x86)\Safe Online\apps\ComputerSecurity\HIPS\drivers\fshs.sys [106648 2018-02-28] (F-Secure Corporation) R0 fsbts; C:\WINDOWS\System32\Drivers\fsbts.sys [73928 2017-07-26] () R3 fsni; C:\Program Files (x86)\Safe Online\apps\CCF_Scanning\bin\fsni64.sys [120520 2017-11-01] (F-Secure Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek ) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Western Digital Technologies, Inc.) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Western Digital Technologies, Inc.) S3 dbx; system32\DRIVERS\dbx.sys [X] S3 DrvAgent64; \??\C:\WINDOWS\SysWoW64\Drivers\DrvAgent64.SYS [X] ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Aangemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2018-03-25 11:55 - 2018-03-25 11:56 - 000023363 _____ C:\Users\jan\Desktop\FRST.txt 2018-03-25 11:55 - 2018-03-25 11:55 - 000000000 ____D C:\FRST 2018-03-25 11:54 - 2018-03-25 11:48 - 002403328 _____ (Farbar) C:\Users\jan\Desktop\FRST64.exe 2018-03-18 17:22 - 2018-03-18 17:22 - 000131764 _____ C:\Users\jan\Documents\the white stallion dvd hoes.el6 2018-03-18 17:22 - 2018-03-18 17:22 - 000000000 ____D C:\Users\jan\Documents\the white stallion dvd hoes.el6.Data 2018-03-18 16:42 - 2018-03-18 16:43 - 000693520 _____ (NCH Software) C:\Users\jan\Downloads\disketchpsetup (1).exe 2018-03-16 20:38 - 2018-03-16 20:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2018-03-15 13:50 - 2018-03-15 13:50 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2018-03-15 13:50 - 2018-03-15 13:50 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2018-03-15 13:50 - 2018-03-15 13:50 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2018-03-15 13:50 - 2018-03-15 13:50 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2018-03-11 21:50 - 2018-03-11 21:50 - 002086399 _____ C:\Users\jan\Downloads\Bourtange-GL-route.pdf 2018-03-10 22:47 - 2018-03-10 22:47 - 000048446 _____ C:\Users\jan\Downloads\1063075895.pdf 2018-03-10 22:47 - 2018-03-10 22:47 - 000048446 _____ C:\Users\jan\Downloads\1063075895 (1).pdf 2018-02-28 23:02 - 2018-02-28 23:02 - 000044677 _____ C:\Users\jan\Downloads\608800711 (2).pdf 2018-02-28 22:59 - 2018-02-28 22:59 - 000192066 _____ C:\Users\jan\Downloads\745541103.pdf 2018-02-28 22:59 - 2018-02-28 22:59 - 000043707 _____ C:\Users\jan\Downloads\1034117396.pdf 2018-02-28 22:58 - 2018-02-28 22:58 - 000113521 _____ C:\Users\jan\Downloads\887287141 (1).pdf 2018-02-28 22:58 - 2018-02-28 22:58 - 000045069 _____ C:\Users\jan\Downloads\872225405 (2).pdf 2018-02-24 16:41 - 2018-02-24 16:41 - 000142816 _____ C:\Users\jan\Downloads\aanslagbiljet.pdf 2018-02-24 14:25 - 2018-02-24 14:25 - 000070352 _____ C:\Users\jan\Downloads\aanvraag-aow.pdf ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2018-03-25 11:50 - 2016-10-02 03:49 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-03-25 11:47 - 2016-05-01 19:48 - 000000000 ____D C:\Users\jan\AppData\Roaming\Skype 2018-03-25 10:32 - 2017-06-24 21:39 - 000004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F45A2705-E7D5-4FC5-8E0A-8B56E701B231} 2018-03-25 10:32 - 2016-07-17 00:15 - 002450158 _____ C:\WINDOWS\system32\perfh013.dat 2018-03-25 10:32 - 2016-07-17 00:15 - 000685302 _____ C:\WINDOWS\system32\perfc013.dat 2018-03-25 10:32 - 2015-12-26 18:18 - 005278736 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2018-03-25 10:31 - 2016-10-02 03:51 - 000000000 ____D C:\Users\jan 2018-03-25 10:30 - 2018-02-10 20:58 - 000000000 ____D C:\Users\jan\AppData\Roaming\WD Discovery 2018-03-25 10:30 - 2018-02-10 20:58 - 000000000 ____D C:\Users\jan\.wdc 2018-03-25 10:28 - 2016-10-02 03:57 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-03-24 17:15 - 2016-01-10 22:09 - 000000000 ____D C:\Users\jan\AppData\Roaming\vlc 2018-03-24 17:04 - 2017-06-24 22:29 - 000000000 ____D C:\AdwCleaner 2018-03-24 17:04 - 2016-10-02 03:50 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2018-03-24 17:04 - 2016-07-16 08:04 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2018-03-24 15:09 - 2015-12-27 00:13 - 000000000 ____D C:\Users\jan\AppData\Local\Dropbox 2018-03-24 15:04 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\system32\NDF 2018-03-24 14:57 - 2014-10-20 16:45 - 000000000 ____D C:\Users\jan\Documents\Outlook-bestanden 2018-03-24 12:35 - 2016-07-16 08:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2018-03-24 00:42 - 2014-09-26 21:39 - 000000000 __RDO C:\Users\jan\OneDrive 2018-03-24 00:03 - 2016-01-10 22:10 - 000000000 ____D C:\Users\jan\AppData\Roaming\dvdcss 2018-03-23 16:27 - 2015-12-26 20:15 - 000002321 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-03-23 16:27 - 2015-12-26 20:15 - 000002280 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-03-23 16:25 - 2015-12-30 21:57 - 000000000 ____D C:\ProgramData\CanonIJPLM 2018-03-23 16:19 - 2016-01-15 23:18 - 000000000 ____D C:\Program Files (x86)\NCH Software 2018-03-18 23:02 - 2014-09-29 21:58 - 000050688 ___SH C:\Users\jan\Desktop\Thumbs.db 2018-03-18 17:28 - 2016-01-15 23:18 - 000000000 ____D C:\ProgramData\NCH Software 2018-03-18 17:28 - 2016-01-15 23:17 - 000000000 ____D C:\Users\jan\AppData\Roaming\NCH Software 2018-03-18 17:24 - 2017-02-12 12:27 - 000000000 ____D C:\Program Files (x86)\Ashampoo 2018-03-18 17:22 - 2016-01-26 23:16 - 000000000 ____D C:\Users\jan\AppData\Local\Canon Easy-PhotoPrint EX 2018-03-18 16:49 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\system32\FxsTmp 2018-03-18 16:43 - 2018-02-05 15:08 - 000001237 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disketch Disc Label Software.lnk 2018-03-18 16:43 - 2018-02-05 15:08 - 000001225 _____ C:\Users\Public\Desktop\Disketch Disc Label Software.lnk 2018-03-16 20:38 - 2015-12-27 00:13 - 000000000 ____D C:\Program Files (x86)\Dropbox 2018-03-10 15:46 - 2017-07-31 20:40 - 000003358 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2660865958-1059967550-4289563984-1001 2018-03-10 15:46 - 2015-12-26 18:59 - 000002418 _____ C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-03-05 21:28 - 2015-12-26 21:03 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2018-02-28 23:21 - 2015-12-27 22:48 - 000000000 ____D C:\Users\jan\AppData\Roaming\MAGIX 2018-02-28 23:21 - 2015-12-27 22:21 - 000000000 ____D C:\ProgramData\MAGIX 2018-02-26 22:09 - 2017-04-25 15:49 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2018-02-26 22:09 - 2016-02-16 18:00 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2018-02-26 10:46 - 2014-12-30 18:24 - 000209408 ___SH C:\Users\jan\Downloads\Thumbs.db Sommige bestanden in TEMP: ==================== 2018-03-14 21:59 - 2018-03-14 21:59 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\16E1.tmp.exe 2018-02-19 22:09 - 2018-02-19 22:09 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\17E0.tmp.exe 2018-02-26 10:36 - 2018-02-26 10:36 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\19C3.tmp.exe 2018-02-20 15:52 - 2018-02-20 15:52 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\1A83.tmp.exe 2018-02-14 20:35 - 2018-02-14 20:35 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\1BD9.tmp.exe 2018-02-14 20:35 - 2018-02-14 20:35 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\1C09.tmp.exe 2018-03-06 21:36 - 2018-03-06 21:36 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\1DDD.tmp.exe 2018-02-12 20:58 - 2018-02-12 20:58 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\1F3.tmp.exe 2018-02-12 20:58 - 2018-02-12 20:58 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\203.tmp.exe 2018-03-18 12:43 - 2018-03-18 12:43 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\21BB.tmp.exe 2018-03-18 12:43 - 2018-03-18 12:43 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\21EB.tmp.exe 2018-03-23 16:20 - 2018-03-23 16:20 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\223.tmp.exe 2018-02-16 17:18 - 2018-02-16 17:18 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\23F9.tmp.exe 2018-02-10 20:58 - 2018-02-10 20:58 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\240.tmp.exe 2018-03-23 16:20 - 2018-03-23 16:20 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\253.tmp.exe 2018-03-24 11:45 - 2018-03-24 11:45 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\26B2.tmp.exe 2018-03-24 11:45 - 2018-03-24 11:45 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\26E2.tmp.exe 2018-02-19 22:09 - 2018-02-19 22:09 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\2734.tmp.exe 2018-03-24 13:18 - 2018-03-24 13:18 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\28E5.tmp.exe 2018-03-24 13:18 - 2018-03-24 13:18 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\28F5.tmp.exe 2018-02-20 16:36 - 2018-02-20 16:36 - 000651776 _____ (Igor Pavlov) C:\Users\jan\AppData\Local\Temp\2987.tmp.exe 2018-02-24 14:14 - 2018-02-24 14:14 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\30BD.tmp.exe 2018-02-24 14:14 - 2018-02-24 14:14 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\30FC.tmp.exe 2018-02-20 16:38 - 2018-02-20 16:38 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\3344.tmp.exe 2018-02-20 16:38 - 2018-02-20 16:38 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\3354.tmp.exe 2018-02-16 17:18 - 2018-02-16 17:18 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\36CA.tmp.exe 2018-02-20 15:52 - 2018-02-20 15:52 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\3A16.tmp.exe 2018-02-25 15:11 - 2018-02-25 15:11 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\3A32.tmp.exe 2018-02-20 15:52 - 2018-02-20 15:52 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\3A46.tmp.exe 2018-02-11 12:59 - 2018-02-11 12:59 - 000651776 _____ (Igor Pavlov) C:\Users\jan\AppData\Local\Temp\3AC6.tmp.exe 2018-02-20 16:36 - 2018-02-20 16:36 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\3AD5.tmp.exe 2018-02-26 22:06 - 2018-02-26 22:06 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\41B1.tmp.exe 2018-03-10 21:48 - 2018-03-10 21:48 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\43AF.tmp.exe 2018-03-13 21:46 - 2018-03-13 21:46 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\45B6.tmp.exe 2018-02-20 16:35 - 2018-02-20 16:35 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\4922.tmp.exe 2018-02-16 17:18 - 2018-02-16 17:18 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\4949.tmp.exe 2018-02-23 16:36 - 2018-02-23 16:36 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\4D01.tmp.exe 2018-02-23 16:36 - 2018-02-23 16:36 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\4D51.tmp.exe 2018-03-04 19:59 - 2018-03-04 19:59 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\52F3.tmp.exe 2018-03-06 21:36 - 2018-03-06 21:36 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\5358.tmp.exe 2018-03-06 21:36 - 2018-03-06 21:36 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\5378.tmp.exe 2018-03-23 22:10 - 2018-03-23 22:10 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\54D2.tmp.exe 2018-02-12 11:58 - 2018-02-12 11:58 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\559D.tmp.exe 2018-02-26 10:37 - 2018-02-26 10:37 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\5857.tmp.exe 2018-02-26 10:37 - 2018-02-26 10:37 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\5887.tmp.exe 2018-03-07 22:00 - 2018-03-07 22:00 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\5C28.tmp.exe 2018-03-11 11:17 - 2018-03-11 11:17 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\5D03.tmp.exe 2018-02-25 15:11 - 2018-02-25 15:11 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\6194.tmp.exe 2018-02-13 20:12 - 2018-02-13 20:12 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\619E.tmp.exe 2018-02-25 15:11 - 2018-02-25 15:11 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\61C4.tmp.exe 2018-03-02 12:58 - 2018-03-02 12:58 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\627C.tmp.exe 2018-03-05 21:26 - 2018-03-05 21:26 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\629.tmp.exe 2018-02-15 21:55 - 2018-02-15 21:55 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\6498.tmp.exe 2018-02-20 17:08 - 2018-02-20 17:08 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\652D.tmp.exe 2018-03-05 21:26 - 2018-03-05 21:26 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\659.tmp.exe 2018-03-11 21:00 - 2018-03-11 21:00 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\667F.tmp.exe 2018-02-20 16:36 - 2018-02-20 16:36 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\66F0.tmp.exe 2018-03-10 21:48 - 2018-03-10 21:48 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\6768.tmp.exe 2018-03-10 21:48 - 2018-03-10 21:48 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\6778.tmp.exe 2018-02-19 22:09 - 2018-02-19 22:09 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\686.tmp.exe 2018-02-17 11:27 - 2018-02-17 11:27 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\68C1.tmp.exe 2018-02-20 16:36 - 2018-02-20 16:36 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\6A8B.tmp.exe 2018-02-11 12:53 - 2018-02-11 12:53 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\6B40.tmp.exe 2018-02-21 21:32 - 2018-02-21 21:32 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\6F01.tmp.exe 2018-02-12 11:58 - 2018-02-12 11:58 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\75FB.tmp.exe 2018-02-12 11:58 - 2018-02-12 11:58 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\761B.tmp.exe 2018-03-07 22:00 - 2018-03-07 22:00 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\764C.tmp.exe 2018-03-04 19:59 - 2018-03-04 19:59 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\76DB.tmp.exe 2018-03-04 19:59 - 2018-03-04 19:59 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\76EB.tmp.exe 2018-03-11 11:15 - 2018-03-11 11:15 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\7738.tmp.exe 2018-03-16 15:01 - 2018-03-16 15:01 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\7A6B.tmp.exe 2018-02-26 22:06 - 2018-02-26 22:06 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\7BDF.tmp.exe 2018-03-23 22:10 - 2018-03-23 22:10 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\7D2F.tmp.exe 2018-03-23 22:10 - 2018-03-23 22:10 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\7D30.tmp.exe 2018-02-15 21:55 - 2018-02-15 21:55 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\836F.tmp.exe 2018-02-15 21:55 - 2018-02-15 21:55 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\839F.tmp.exe 2018-02-13 20:12 - 2018-02-13 20:12 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\873B.tmp.exe 2018-02-13 20:12 - 2018-02-13 20:12 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\875B.tmp.exe 2018-02-17 11:27 - 2018-02-17 11:27 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\87C8.tmp.exe 2018-02-17 11:27 - 2018-02-17 11:27 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\87F7.tmp.exe 2018-03-02 12:58 - 2018-03-02 12:58 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\8B46.tmp.exe 2018-03-02 12:58 - 2018-03-02 12:58 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\8B76.tmp.exe 2018-02-20 17:08 - 2018-02-20 17:08 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\8D89.tmp.exe 2018-02-27 21:52 - 2018-02-27 21:52 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\8DE1.tmp.exe 2018-02-28 21:40 - 2018-02-28 21:40 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\8E64.tmp.exe 2018-02-11 12:53 - 2018-02-11 12:53 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\8E8B.tmp.exe 2018-02-11 12:53 - 2018-02-11 12:53 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\8EBB.tmp.exe 2018-03-04 11:51 - 2018-03-04 11:51 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\8FF8.tmp.exe 2018-02-20 17:08 - 2018-02-20 17:08 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\9385.tmp.exe 2018-02-21 21:32 - 2018-02-21 21:32 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\9411.tmp.exe 2018-02-21 21:32 - 2018-02-21 21:32 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\9460.tmp.exe 2018-03-07 22:00 - 2018-03-07 22:00 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\9790.tmp.exe 2018-03-16 15:01 - 2018-03-16 15:01 - 000651776 _____ (Igor Pavlov) C:\Users\jan\AppData\Local\Temp\98F3.tmp.exe 2018-03-03 15:08 - 2018-03-03 15:08 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\9A09.tmp.exe 2018-03-24 11:53 - 2018-03-24 11:53 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\A090.tmp.exe 2018-02-19 23:01 - 2018-02-19 23:01 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\A12.tmp.exe 2018-02-19 23:01 - 2018-02-19 23:01 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\A23.tmp.exe 2018-03-16 15:01 - 2018-03-16 15:01 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\A690.tmp.exe 2018-03-16 15:01 - 2018-03-16 15:01 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\A6B1.tmp.exe 2018-03-24 17:05 - 2018-03-24 17:05 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\AAE.tmp.exe 2018-03-24 17:05 - 2018-03-24 17:05 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\ABF.tmp.exe 2018-03-10 15:45 - 2018-03-10 15:45 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\AF29.tmp.exe 2018-02-26 22:06 - 2018-02-26 22:06 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\B4D3.tmp.exe 2018-03-04 11:51 - 2018-03-04 11:51 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\B72B.tmp.exe 2018-03-04 11:51 - 2018-03-04 11:51 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\B76B.tmp.exe 2018-02-10 20:58 - 2018-02-10 20:58 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\BBCC.tmp.exe 2018-02-27 21:52 - 2018-02-27 21:52 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\BF07.tmp.exe 2018-03-11 21:01 - 2018-03-11 21:01 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\BFEE.tmp.exe 2018-02-23 16:35 - 2018-02-23 16:35 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\C06D.tmp.exe 2018-03-03 15:08 - 2018-03-03 15:08 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\C0B0.tmp.exe 2018-02-20 16:37 - 2018-02-20 16:37 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\C0BE.tmp.exe 2018-03-03 15:08 - 2018-03-03 15:08 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\C0D0.tmp.exe 2018-02-27 21:52 - 2018-02-27 21:52 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\C33E.tmp.exe 2018-02-28 21:40 - 2018-02-28 21:40 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\CE40.tmp.exe 2018-02-28 21:40 - 2018-02-28 21:40 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\CE70.tmp.exe 2018-02-12 20:57 - 2018-02-12 20:57 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\D428.tmp.exe 2018-03-25 10:30 - 2018-03-25 10:30 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\D56B.tmp.exe 2018-03-24 17:05 - 2018-03-24 17:05 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\D5ED.tmp.exe 2018-02-20 16:37 - 2018-02-20 16:37 - 000651776 _____ (Igor Pavlov) C:\Users\jan\AppData\Local\Temp\D803.tmp.exe 2018-03-10 15:46 - 2018-03-10 15:46 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\D96A.tmp.exe 2018-03-10 15:46 - 2018-03-10 15:46 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\D98A.tmp.exe 2018-03-23 16:20 - 2018-03-23 16:20 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\DA52.tmp.exe 2018-03-05 21:26 - 2018-03-05 21:26 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\DD50.tmp.exe 2018-02-10 20:59 - 2018-02-10 20:59 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\DEAA.tmp.exe 2018-02-10 20:59 - 2018-02-10 20:59 - 000044544 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\DECA.tmp.exe 2017-08-13 21:07 - 2017-08-13 21:14 - 000139264 _____ () C:\Users\jan\AppData\Local\Temp\DevSetup32.dll 2017-08-13 21:07 - 2017-08-13 21:14 - 000139264 _____ () C:\Users\jan\AppData\Local\Temp\DevSetup64.dll 2017-08-13 21:07 - 2017-08-13 21:14 - 000094208 _____ () C:\Users\jan\AppData\Local\Temp\DriverInstall32.exe 2017-08-13 21:07 - 2017-08-13 21:14 - 000094208 _____ () C:\Users\jan\AppData\Local\Temp\DriverInstall64.exe 2018-02-19 23:00 - 2018-02-19 23:00 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\E781.tmp.exe 2018-03-24 16:58 - 2018-03-24 16:58 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\E85C.tmp.exe 2018-03-24 11:53 - 2018-03-24 11:53 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\EBF6.tmp.exe 2018-03-24 11:53 - 2018-03-24 11:53 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\EC07.tmp.exe 2018-03-18 12:43 - 2018-03-18 12:43 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\EFD8.tmp.exe 2018-03-24 17:00 - 2018-03-24 17:00 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\F388.tmp.exe 2018-03-24 17:00 - 2018-03-24 17:00 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\F473.tmp.exe 2018-02-14 20:35 - 2018-02-14 20:35 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\F66B.tmp.exe 2018-03-24 13:18 - 2018-03-24 13:18 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\F954.tmp.exe 2018-03-25 10:30 - 2018-03-25 10:30 - 000103424 _____ () C:\Users\jan\AppData\Local\Temp\FACB.tmp.exe 2018-03-25 10:30 - 2018-03-25 10:30 - 000058336 _____ (NirSoft) C:\Users\jan\AppData\Local\Temp\FAFB.tmp.exe 2018-02-24 14:13 - 2018-02-24 14:13 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\FBBE.tmp.exe 2018-03-14 21:59 - 2018-03-14 21:59 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\FD2B.tmp.exe 2018-03-24 11:45 - 2018-03-24 11:45 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\FE26.tmp.exe 2018-03-13 21:46 - 2018-03-13 21:46 - 000073728 _____ () C:\Users\jan\AppData\Local\Temp\FE39.tmp.exe 2018-01-05 22:47 - 2018-01-05 22:47 - 002366464 _____ (CamStudio) C:\Users\jan\AppData\Local\Temp\ICReinstall_camstudio.exe 2018-02-05 15:01 - 2017-01-20 09:29 - 000053056 _____ () C:\Users\jan\AppData\Local\Temp\setup_2907.exe 2018-02-05 15:01 - 2018-02-05 15:02 - 092638488 _____ (Ashampoo GmbH & Co. KG ) C:\Users\jan\AppData\Local\Temp\tmp1099.exe 2017-09-03 16:53 - 2017-09-03 16:53 - 030950664 _____ () C:\Users\jan\AppData\Local\Temp\vlc-2.2.6-win32.exe ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\WINDOWS\system32\winlogon.exe => Bestand is getekend C:\WINDOWS\system32\wininit.exe => Bestand is getekend C:\WINDOWS\explorer.exe => Bestand is getekend C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend C:\WINDOWS\system32\svchost.exe => Bestand is getekend C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend C:\WINDOWS\system32\services.exe => Bestand is getekend C:\WINDOWS\system32\User32.dll => Bestand is getekend C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend C:\WINDOWS\system32\userinit.exe => Bestand is getekend C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend C:\WINDOWS\system32\rpcss.dll => Bestand is getekend C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2017-02-04 23:06 ==================== Eind van FRST.txt ============================