Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 01-03-2017 Gestart door Willem (Beheerder) op PC-THUIS (03-03-2017 14:10:01) Gestart vanaf C:\Users\Willem\Downloads Geladen Profielen: Willem (Beschikbare Profielen: Willem) Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland) Internet Explorer Versie 11 (Standaardbrowser: FF) Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (AVAST Software) C:\Program Files\AVAST Software\Cleanup\CleanupSvc.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe (Flux Software LLC) C:\Users\Willem\AppData\Local\FluxSoftware\Flux\flux.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (AVAST Software) C:\Program Files\AVAST Software\Cleanup\CleanupUI.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe (SecureW2 B.V.) C:\Program Files (x86)\SecureW2\sw2_tray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Kerio) C:\Users\Willem\AppData\Local\KerioConnect\app-9.2.2.7788\KerioConnect.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Kerio) C:\Users\Willem\AppData\Local\KerioConnect\app-9.2.2.7788\KerioConnect.exe (Kerio) C:\Users\Willem\AppData\Local\KerioConnect\app-9.2.2.7788\KerioConnect.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\scalc.exe (The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.exe (The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.bin (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\System32\mspaint.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Register (gefilterd) ==================== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software) HKLM-x32\...\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1533728 2015-04-01] (Seagate Technology LLC) HKLM-x32\...\Run: [SecureW2 Tray] => C:\Program Files (x86)\SecureW2\sw2_tray.exe [267496 2016-01-29] (SecureW2 B.V.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKU\S-1-5-21-203689384-3566404974-2290648612-1001\...\Run: [f.lux] => C:\Users\Willem\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC) HKU\S-1-5-21-203689384-3566404974-2290648612-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd) HKU\S-1-5-21-203689384-3566404974-2290648612-1001\...\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127304 2015-04-01] (Seagate Technology LLC) HKU\S-1-5-21-203689384-3566404974-2290648612-1001\...\Run: [Dropbox Update] => C:\Users\Willem\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.) HKU\S-1-5-21-203689384-3566404974-2290648612-1001\...\Policies\Explorer: [NoInternetOpenWith] 1 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-26] (AVAST Software) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Willem\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\avast! Cleanup.lnk [2016-10-31] ShortcutTarget: avast! Cleanup.lnk -> C:\Program Files\AVAST Software\Cleanup\CleanupUI.exe (AVAST Software) Startup: C:\Users\Willem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Slack.lnk [2017-03-01] ShortcutTarget: Slack.lnk -> C:\Users\Willem\AppData\Local\slack\slack.exe (Slack Technologies) GroupPolicy: Restrictie <======= AANDACHT ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 192.168.1.1 Tcpip\..\Interfaces\{3BAF1B29-6FCD-458C-B69C-F74AA3C085B6}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{4C2AC81C-D3F4-4F71-9BDE-66570B91F2FA}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{714E87C4-41E9-4B35-BB2B-CCE1163D64C3}: [DhcpNameServer] 8.8.8.8 8.8.4.4 Tcpip\..\Interfaces\{E108EFE9-882A-4AB0-86DA-0DF6BD5066EF}: [DhcpNameServer] 8.8.8.8 8.8.4.4 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <======= AANDACHT HKU\S-1-5-21-203689384-3566404974-2290648612-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <======= AANDACHT HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-203689384-3566404974-2290648612-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-203689384-3566404974-2290648612-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://vaioportal.sony.eu/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-203689384-3566404974-2290648612-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-203689384-3566404974-2290648612-1001 -> {55049559-47A3-42FB-A709-CCAFBB308BE7} URL = hxxp://rover.ebay.com/rover/1/1346-81661-16445-14/4?mpre=hxxp://shop.ebay.nl/?oemInLn=ieSrch-Q212&_nkw={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-05] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-05] (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab FireFox: ======== FF ProfilePath: C:\Users\Willem\AppData\Roaming\TomTom\HOME\Profiles\qrcqy6dc.default [2015-02-12] FF Extension: (Emulator) - C:\Users\Willem\AppData\Roaming\TomTom\HOME\Profiles\qrcqy6dc.default\Extensions\[removed] [2012-08-24] [ niet getekend] FF Extension: (Geen Naam) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[removed] [niet gevonden] FF ProfilePath: C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default [2016-11-04] FF Extension: (7digital Music Store) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2012-11-01] [ niet getekend] FF Extension: (Last.fm) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (BirdQuizz) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2012-09-28] [ niet getekend] FF Extension: (CD Rip Support) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (Gracenote Metadata Lookup Provider) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (mashTape) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (MSC Device Support) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (MTP Device Support) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (Murphy) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2012-09-28] [ niet getekend] FF Extension: (QuickTime Playback) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (SongbirdRemote (from 779Media) ) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-01-20] [ niet getekend] FF Extension: (Geen Naam) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed]-trash [2015-02-12] [ niet getekend] FF Extension: (Songbird.me) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (Windows Media Playback) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\[removed] [2013-03-05] [ niet getekend] FF Extension: (Last.fm Album Art) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\{0fab887c-69db-4e79-a797-6e37e18a7062} [2012-09-28] [ niet getekend] FF Extension: (MinimizeToTray (Songbird version)) - C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\Extensions\{31513E58-F253-47ad-86DB-D5F21E905429} [2012-09-28] [ niet getekend] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF Extension: (Geen Naam) - C:\Program Files (x86)\Songbird\extensions\[removed] [niet gevonden] FF SearchPlugin: C:\Users\Willem\AppData\Roaming\Songbird2\Profiles\094gbr9g.default\searchplugins\7digital.xml [2012-09-27] FF ProfilePath: C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092 [2017-03-03] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092 -> DuckDuckGo FF Extension: (Grammarly for Firefox) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\[removed] [2017-02-22] FF Extension: (Firefox Hotfix) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\[removed] [2016-08-31] FF Extension: (Ghostery) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\[removed] [2017-02-13] FF Extension: (Video DownloadHelper) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-31] FF Extension: (Adblock Plus) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24] FF Extension: (DownThemAll!) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-10-01] FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\features\{3ab174ea-cd97-4a67-8681-663e48ac455e}\[removed] [2017-03-01] FF Extension: (TLS 1.3 Compatibility Testing 3) - C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\ohi5iib1.default-1435227633092\features\{3ab174ea-cd97-4a67-8681-663e48ac455e}\[removed] [2017-03-01] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-26] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-26] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] () FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.0-git -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-10-26] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-05] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 -> C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll [2011-08-03] (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll [2011-08-02] (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-01-18] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-203689384-3566404974-2290648612-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Willem\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-27] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-203689384-3566404974-2290648612-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-12-19] () FF Plugin ProgramFiles/Appdata: C:\Users\Willem\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2010-12-27] (Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default [2016-11-25] CHR Extension: (Google Drive) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-03] CHR Extension: (YouTube) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-03] CHR Extension: (Google Cast) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-11-03] CHR Extension: (Google Zoeken) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-18] CHR Extension: (Avast SafePrice) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-11-03] CHR Extension: (Google Spreadsheets) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-03] CHR Extension: (Offline Documenten) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-03] CHR Extension: (Avast Online Security) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-03] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-03] CHR Extension: (Gmail) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-03] CHR Extension: (Chrome Media Router) - C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-03] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Services (gefilterd) ==================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-01-19] (Atheros Commnucations) [Bestand niet getekend] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-26] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [223600 2016-09-26] (AVAST Software) S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com) R2 CleanupSvc; C:\Program Files\AVAST Software\Cleanup\CleanupSvc.exe [2360432 2016-10-05] (AVAST Software) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [112256 2012-03-21] (Atheros Communication Inc.) [Bestand niet getekend] R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] () [Bestand niet getekend] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] () [Bestand niet getekend] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [473960 2012-02-21] (Sony Corporation) S4 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation) R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16216 2015-04-01] (Seagate Technology LLC) R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157992 2015-04-01] (Seagate Technology LLC) S4 Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [155320 2012-01-18] (Avanquest Software) [Bestand niet getekend] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH) S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [960160 2011-12-29] (Sony Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-01-19] (Atheros) [Bestand niet getekend] ===================== Drivers (gefilterd) ====================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-26] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-26] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-26] (AVAST Software) R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [28312 2016-09-26] (AVAST Software) R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [453192 2016-09-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-26] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-26] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software) S3 BTATH_VDP; C:\Windows\System32\drivers\btath_vdp.sys [421664 2012-01-19] (Atheros) S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [170280 2015-02-11] (ESET) S3 GEARAspiWDM; C:\Windows\SysWOW64\Drivers\GEARAspiWDM.sys [15664 2013-02-04] (GEAR Software Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X] ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een Maand Aangemaakt bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-03-03 14:10 - 2017-03-03 14:11 - 00031678 _____ C:\Users\Willem\Downloads\FRST.txt 2017-03-03 14:09 - 2017-03-03 14:10 - 00000000 ____D C:\FRST 2017-03-03 14:08 - 2017-03-03 14:08 - 02423808 _____ (Farbar) C:\Users\Willem\Downloads\FRST64.exe 2017-03-03 10:50 - 2017-03-03 10:50 - 00000022 _____ C:\Windows\S.dirmngr 2017-02-28 14:16 - 2017-02-28 14:17 - 00138967 _____ C:\Users\Willem\Downloads\contract-2017-02-22_17-28-11.pdf 2017-02-28 10:52 - 2017-02-28 10:52 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-02-23 13:36 - 2017-02-23 13:41 - 00009769 _____ C:\Users\Willem\Downloads\Vrijwilligers campagne FvD regio Den Bosch - Eindhoven eo.xlsx 2017-02-21 13:00 - 2017-02-21 13:00 - 00128412 _____ C:\Users\Willem\Downloads\Locaties verkiezingsborden TKverkiezing 2017.pdf 2017-02-21 09:31 - 2017-03-03 13:40 - 00000000 ____D C:\Users\Willem\Desktop\Verkiezingen 2017-02-20 20:57 - 2017-03-03 10:57 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Kerio Connect 2017-02-20 20:57 - 2017-02-21 16:36 - 00002270 _____ C:\Users\Willem\Desktop\Kerio Connect.lnk 2017-02-20 20:57 - 2017-02-21 16:36 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kerio 2017-02-20 20:56 - 2017-02-21 16:35 - 00000000 ____D C:\Users\Willem\AppData\Local\KerioConnect 2017-02-20 18:25 - 2017-02-20 18:25 - 00031867 _____ C:\Users\Willem\Desktop\Kritiek Rousseau.odt 2017-02-20 18:15 - 2017-02-20 18:15 - 01126367 _____ C:\Users\Willem\Downloads\[removed].uk_20160707_161350(1).pdf 2017-02-19 20:13 - 2017-02-19 20:13 - 00002169 _____ C:\Users\Willem\AppData\Local\recently-used.xbel 2017-02-19 20:12 - 2017-02-19 20:12 - 02911418 _____ C:\Users\Willem\Documents\fb header reisman.xcf 2017-02-19 20:11 - 2017-02-19 20:11 - 00084859 _____ C:\Users\Willem\Downloads\bell-mt-58a9edef6e4b9.ttf 2017-02-19 19:56 - 2017-02-19 19:56 - 00417292 _____ C:\Users\Willem\Downloads\c6d01ee9be7c943a6156e4b9ca008c87.jpeg 2017-02-18 23:22 - 2017-02-19 17:38 - 00026382 _____ C:\Users\Willem\Desktop\veeger bureaucratie en stemrecth.odt 2017-02-17 14:23 - 2017-02-17 18:13 - 00011925 _____ C:\Users\Willem\Desktop\benthin cornax.odt 2017-02-16 09:44 - 2017-02-16 09:44 - 00210316 _____ C:\Users\Willem\Downloads\ecfin_forecast_winter_1317_uk_en_0.pdf 2017-02-15 12:04 - 2017-02-15 13:04 - 20359768 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2017-02-07 16:23 - 2017-02-07 16:26 - 13739496 _____ C:\Users\Willem\Downloads\Third_Age_Reforged(1).rar 2017-02-07 16:13 - 2017-02-07 16:16 - 153795931 _____ C:\Users\Willem\Downloads\Third_Age_Reforged.rar 2017-02-07 15:33 - 2017-02-07 15:55 - 2644559899 _____ C:\Users\Willem\Downloads\Third_Age_Reforged.1.rar 2017-02-02 09:25 - 2017-02-02 09:25 - 02223093 _____ C:\Users\Willem\Downloads\Italy-2017-01-19.pdf ==================== Een Maand Gewijzigd bestanden en mappen ======== (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.) 2017-03-03 14:04 - 2013-03-07 10:40 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-03-03 13:37 - 2016-11-16 16:18 - 00000000 ____D C:\Users\Willem\AppData\LocalLow\Mozilla 2017-03-03 13:36 - 2017-01-02 10:13 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Slack 2017-03-03 13:33 - 2015-06-25 10:32 - 00001028 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-203689384-3566404974-2290648612-1001UA.job 2017-03-03 13:28 - 2012-06-20 21:42 - 00000000 ____D C:\Users\Willem\dwhelper 2017-03-03 11:08 - 2009-07-14 05:45 - 00028848 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-03 11:08 - 2009-07-14 05:45 - 00028848 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-03 10:50 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-02 20:33 - 2015-06-25 10:32 - 00000976 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-203689384-3566404974-2290648612-1001Core.job 2017-03-02 20:07 - 2015-08-05 16:42 - 00003962 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{FF0A1E7C-496E-4B26-93E3-039204E1E7A4} 2017-03-01 23:15 - 2016-12-31 10:59 - 00000000 ____D C:\Users\Willem\Desktop\Testsite 2017-03-01 17:31 - 2013-01-02 10:47 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Belastingdienst 2017-03-01 17:30 - 2017-01-02 10:13 - 00002129 _____ C:\Users\Willem\Desktop\Slack.lnk 2017-03-01 17:30 - 2017-01-02 10:13 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies 2017-03-01 17:30 - 2017-01-02 10:12 - 00000000 ____D C:\Users\Willem\AppData\Local\slack 2017-03-01 17:28 - 2017-01-02 10:12 - 00000000 ____D C:\Users\Willem\AppData\Local\SquirrelTemp 2017-02-28 10:52 - 2014-07-09 10:20 - 00000000 ____D C:\Users\Willem\AppData\Roaming\Dropbox 2017-02-25 13:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-02-23 11:36 - 2012-06-13 18:21 - 00000000 ____D C:\ProgramData\Skype 2017-02-21 18:59 - 2017-01-28 16:13 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-20 09:53 - 2012-06-20 14:03 - 00083600 _____ C:\Users\Willem\AppData\Local\GDIPFONTCACHEV1.DAT 2017-02-20 09:49 - 2009-07-14 05:45 - 00362968 _____ C:\Windows\system32\FNTCACHE.DAT 2017-02-19 21:08 - 2014-11-10 16:15 - 00000000 ____D C:\Users\Willem\.gimp-2.8 2017-02-17 20:19 - 2012-06-20 18:40 - 00000000 ____D C:\Users\Willem\AppData\Roaming\vlc 2017-02-16 01:07 - 2012-07-10 22:10 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2017-02-15 13:04 - 2013-03-07 10:40 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-02-15 13:04 - 2012-07-05 15:39 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-02-15 13:04 - 2012-07-05 15:39 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-02-15 13:04 - 2012-06-13 18:06 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-02-15 13:04 - 2012-06-13 18:06 - 00000000 ____D C:\Windows\system32\Macromed 2017-02-08 16:15 - 2015-04-14 19:01 - 00000000 ____D C:\Users\Willem\AppData\Local\CrashDumps 2017-02-08 15:14 - 2012-07-08 20:50 - 00000000 ____D C:\Program Files (x86)\Steam 2017-02-08 15:07 - 2013-01-01 21:01 - 00000000 ____D C:\Users\Willem\AppData\Local\ElevatedDiagnostics 2017-02-05 23:24 - 2016-08-05 11:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-02-05 23:23 - 2016-08-05 11:21 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2017-02-05 23:23 - 2016-08-05 11:20 - 00000000 ____D C:\Program Files (x86)\Java 2017-02-05 23:17 - 2014-07-05 15:38 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-02-05 23:16 - 2014-07-05 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2017-02-05 23:16 - 2014-07-05 15:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2017-02-05 23:16 - 2013-03-06 13:14 - 00001062 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2017-02-03 10:05 - 2016-09-27 06:42 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-02-01 23:22 - 2015-02-12 12:10 - 10134579 ____H C:\Users\Willem\AppData\Local\IconCache.db.backup ==================== Bestanden in de root van sommige mappen ======= 2015-02-12 05:53 - 2015-02-12 05:53 - 0186208 _____ () C:\Users\Willem\AppData\Local\ars.cache 2015-02-12 05:53 - 2015-02-12 05:53 - 7023069 _____ () C:\Users\Willem\AppData\Local\census.cache 2014-09-08 13:42 - 2014-09-08 14:00 - 0007680 _____ () C:\Users\Willem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-02-11 15:28 - 2015-02-11 15:28 - 0000036 _____ () C:\Users\Willem\AppData\Local\housecall.guid.cache 2017-02-19 20:13 - 2017-02-19 20:13 - 0002169 _____ () C:\Users\Willem\AppData\Local\recently-used.xbel 2015-02-11 15:51 - 2015-02-11 15:51 - 0000010 _____ () C:\Users\Willem\AppData\Local\sponge.last.runtime.cache ==================== Bamital & volsnap ====================== (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) C:\Windows\system32\winlogon.exe => Bestand is getekend C:\Windows\system32\wininit.exe => Bestand is getekend C:\Windows\SysWOW64\wininit.exe => Bestand is getekend C:\Windows\explorer.exe => Bestand is getekend C:\Windows\SysWOW64\explorer.exe => Bestand is getekend C:\Windows\system32\svchost.exe => Bestand is getekend C:\Windows\SysWOW64\svchost.exe => Bestand is getekend C:\Windows\system32\services.exe => Bestand is getekend C:\Windows\system32\User32.dll => Bestand is getekend C:\Windows\SysWOW64\User32.dll => Bestand is getekend C:\Windows\system32\userinit.exe => Bestand is getekend C:\Windows\SysWOW64\userinit.exe => Bestand is getekend C:\Windows\system32\rpcss.dll => Bestand is getekend C:\Windows\system32\dnsapi.dll => Bestand is getekend C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend LastRegBack: 2016-11-04 15:29 ==================== Eind van FRST.txt ============================