Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 21-09-2016 Gestart door Jasper (23-09-2016 09:57:26) Gestart vanaf D:\Downloads Windows 10 Pro Versie 1511 (X64) (2016-05-20 10:55:43) Boot Modus: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3280333162-937765043-293338858-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3280333162-937765043-293338858-503 - Limited - Disabled) Gast (S-1-5-21-3280333162-937765043-293338858-501 - Limited - Disabled) Jasper (S-1-5-21-3280333162-937765043-293338858-1000 - Administrator - Enabled) => C:\Users\Jasper ==================== Security Center ======================== (Als een item is opgenomen in de fixlist, zal het worden verwijderd.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Geïnstalleerde programma's ====================== (Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.) Adobe Acrobat Reader DC - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.7.0.272 - Adobe Systems Incorporated) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.1.2 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 5.3 64-bit (HKLM\...\{2DD71ACB-552D-402C-9529-7906ACB95C30}) (Version: 5.3.1 - Adobe Systems Incorporated) Canon Inkjet Printer Driver Add-On Module (HKLM\...\CANONIJINBOXADDON100) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.17 - Piriform) EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) MAGIX Content en soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Music Maker 2016 Live (HKLM-x32\...\MX.{C90C9B05-5069-4710-AFE1-B59C6D2F34CA}) (Version: 22.0.3.63 - MAGIX Software GmbH) MAGIX Music Maker 2016 Live (Version: 22.0.3.63 - MAGIX Software GmbH) Hidden MAGIX Music Maker 2016 Trial Live Pads (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Music Maker 2016 Trial Soundpools (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50709.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 48.0.2 (x86 nl) (HKLM-x32\...\Mozilla Firefox 48.0.2 (x86 nl)) (Version: 48.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 48.0.2.6079 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD) (Version: 10.0.50903 - Microsoft Corporation) Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) WinRAR 5.10 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) ==================== Aangepaste CLSID (gefilterd): ========================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) CustomCLSID: HKU\S-1-5-21-3280333162-937765043-293338858-1000_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-2487C6CED52D}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Geen bestand CustomCLSID: HKU\S-1-5-21-3280333162-937765043-293338858-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Jasper\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3280333162-937765043-293338858-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ==================== Geplande Taken (gefilterd) ============= (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {009402B3-75BC-4FA4-B34D-1F6B1713265E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {0DB77A01-14BC-4825-843C-B7DF67E0F2DD} - System32\Tasks\AdobeAAMUpdater-1.0-WINDOWS-3DQ83PL-Jasper => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-05-05] (Adobe Systems Incorporated) Task: {26960F6F-580E-4DBA-B80F-1334D7BE6AAB} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {2832F492-96F4-44CD-9A53-5EE8357FC596} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Geen bestand <==== AANDACHT Task: {3534C7F9-7ECA-4AE0-B11D-09FACCF38E37} - System32\Tasks\Aritisp Launcher => C:\Program Files (x86)\Pleqok\phihuward.exe [2016-09-16] (Kunshan Aunbox software co.,Ltd) Task: {3D1877CC-DEBD-44A0-8B45-EBBBB8ECF8CB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Geen bestand <==== AANDACHT Task: {3D5EEF43-BFB3-4F81-B9A0-E99ADEC7AEDE} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Geen bestand <==== AANDACHT Task: {42534267-653D-457A-97BB-B09E62F33D2D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Geen bestand <==== AANDACHT Task: {4D80EE4F-586B-4ACC-BAC7-5DA13A9AB9FA} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {4EFE6793-9C5D-4205-946E-7385EB831B12} - System32\Tasks\SugarBlast => c:\programdata\{302bbb60-2eea-0a5c-302b-bbb602eeed80}\9177298860804513750b.exe <==== AANDACHT Task: {516C715B-A8B4-4D2A-A5C2-371BF25B6F86} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {589F06E0-B7AE-4F33-9B4E-CE2AA9AC17E8} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Geen bestand <==== AANDACHT Task: {5AB03B96-020B-4082-BC8E-DCF8983BDECE} - \Microsoft\Windows\Setup\gwx\rundetector -> Geen bestand <==== AANDACHT Task: {5BFAD12C-7952-4BF4-A75C-7E8C4D901C93} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Geen bestand <==== AANDACHT Task: {5D829F39-158A-4251-B024-83842A736D96} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {5E4D788E-C03B-4407-A2C7-7E8F969C282D} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {64D03ED7-2C37-41D1-A865-B73ECD33C5CF} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {6E5B5455-7786-44A8-9D89-1DD0F9B08CA8} - System32\Tasks\BloatRemove => c:\programdata\{4a3564fd-c8a5-41e7-4a35-564fdc8a93f7}\5853125071572029307b.exe <==== AANDACHT Task: {6E95E740-2521-4F39-B32C-7A74BD07A6D8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {76D460D9-A1D0-483F-A7F7-80C3BC02C02B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {78738373-3587-4ADD-90EE-64D980C4A068} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Geen bestand <==== AANDACHT Task: {7D25FBCC-3ED1-497F-8F4C-B2D727E0E693} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {8132D32A-AE9D-428C-A0D7-265189A1AE33} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {86C909D4-D526-4CFF-AB92-8117E4CED735} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {87179222-F814-4A7D-9DA4-CE57167662BE} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {8FAD86DC-DB6B-4138-95B9-661D81304441} - System32\Tasks\ChelfNotify Task => C:\ProgramData\ChelfNotify\BrowserUpdate.exe [2016-06-30] (Tencent) <==== AANDACHT Task: {92DC3A4E-EECD-4BF2-85C0-BD00DB2B5A2F} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Geen bestand <==== AANDACHT Task: {952FF6FB-2EFA-4A8A-A4E6-A13EA933A663} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Geen bestand <==== AANDACHT Task: {9C4DB771-3406-42B4-B80A-6751CBBB9B13} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {A1AC4CCF-CB43-4702-B79B-17050E5DC469} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Geen bestand <==== AANDACHT Task: {A3168DEA-A7F1-48C0-B0BB-30705D6AA619} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {A3E9C9F4-D7AF-4F60-9B7F-BF4D9D4ED4BD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-04-15] (Piriform Ltd) Task: {AA7ACC31-48CD-462A-A0E9-73DAF23A48B1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Jasper\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-25] (Microsoft Corporation) Task: {AA8E1F23-2FFF-4ED7-8044-671733795BDF} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {AE1A79D6-9A20-4912-B2AD-589B14284C45} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Geen bestand <==== AANDACHT Task: {B3296BF2-2EBC-4E72-959E-DE06B5E7317C} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {BE4EA547-3ABB-4E97-915D-2788F3D19230} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {BF8E62EC-6CE9-4396-86EC-EEFAD0E91322} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-ypy1982@gmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-05-05] (Adobe Systems Incorporated) Task: {C21C0A2C-4D9C-48A0-BD40-5BAE897AC542} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {D24A3916-8287-404C-9945-9AEB02B86532} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {D70EC45D-C588-4804-87D0-6D648C84B66D} - \AutoPico Daily Restart -> Geen bestand <==== AANDACHT Task: {E07F1B80-BC5F-4505-90C3-D3C5907C3F7C} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Geen bestand <==== AANDACHT Task: {E386E058-23B0-447C-8968-33D1AB719942} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {E5881A83-026C-42D9-A031-E8706A91FCEB} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {E8EDB602-D3FD-4750-9787-17983CB21646} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {EACB1C44-7BD1-46FE-B597-21E86E838949} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {F30A3B70-DFF3-405B-A220-DC4CD9BBD8EC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Geen bestand <==== AANDACHT Task: {F4958715-405A-4779-AE7A-88052E9EE585} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-08] (Adobe Systems Incorporated) (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) Task: C:\WINDOWS\Tasks\BloatRemove.job => c:\programdata\{4a3564fd-c8a5-41e7-4a35-564fdc8a93f7}\5853125071572029307b.exe <==== AANDACHT Task: C:\WINDOWS\Tasks\SugarBlast.job => c:\programdata\{302bbb60-2eea-0a5c-302b-bbb602eeed80}\9177298860804513750b.exe <==== AANDACHT ==================== Snelkoppelingen ============================= (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.) ==================== Geladen Modules (gefilterd) ============== 2015-10-30 09:17 - 2015-10-30 09:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-09-18 16:48 - 2016-09-07 07:39 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-09-18 16:48 - 2016-09-07 07:39 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-22 19:33 - 2016-05-22 19:33 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-08-25 19:36 - 2016-08-25 19:36 - 01864384 _____ () C:\Users\Jasper\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2016-05-20 13:39 - 2016-05-20 13:39 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-02-13 14:57 - 2016-02-13 14:57 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-14 18:46 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-01-06 18:41 - 2016-01-06 18:41 - 00062168 _____ () C:\Program Files\CCleaner\branding.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf 2016-09-18 16:48 - 2016-09-07 06:15 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-09-18 16:51 - 2016-09-07 06:10 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-09-18 16:48 - 2016-09-07 06:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-09-18 16:48 - 2016-09-07 06:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-08-23 19:55 - 2016-08-23 20:03 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-08-23 19:55 - 2016-08-23 20:03 - 13475840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-05 19:57 - 2016-06-05 19:57 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-05-20 13:38 - 2016-05-20 13:38 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-09-23 08:36 - 2016-09-22 11:13 - 00477400 _____ () C:\Program Files (x86)\WinSaber\WinSaber.exe 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2016-09-16 08:58 - 2016-09-16 08:58 - 00323584 _____ () c:\program files (x86)\pleqok\mlsreports.dll 2016-05-20 13:39 - 2016-05-20 13:39 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-05-20 13:39 - 2016-05-20 13:39 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-08-25 19:36 - 2016-08-25 19:36 - 01383616 _____ () C:\Users\Jasper\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\ClientTelemetry.dll 2016-08-25 19:36 - 2016-08-25 19:36 - 00118976 _____ () C:\Users\Jasper\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncViews.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ==================== Alternate Data Streams (gefilterd) ========= (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.) ==================== Veilige Modus (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.) ==================== Bestandskoppeling (gefilterd) =============== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.) ==================== Internet Explorer vertrouwde/beperkte toegang =============== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.) ==================== Hosts inhoud: ========================== (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.) 2009-07-14 04:34 - 2016-09-16 08:59 - 00001006 ____N C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Andere gebieden ============================ (Momenteel is er geen automatische fix voor dit onderdeel.) HKU\S-1-5-21-3280333162-937765043-293338858-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jasper\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{8c5583a9-f901-48e1-884f-2ea19f81f194}.jpg DNS Servers: 192.168.1.254 - 213.75.63.75 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is ingeschakeld. ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items == MSCONFIG\startupfolder: C:^Users^Jasper^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Crack and Setup.lnk => C:\Windows\pss\Crack and Setup.lnk.Startup MSCONFIG\startupreg: EPSON Stylus Photo R1800 => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATI9LA.EXE /FU "C:\Windows\TEMP\E_S9725.tmp" /EF "HKCU" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" ==================== Firewall regels (gefilterd) =============== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{1AED0AFF-C5B4-4108-9A42-F8CE28F71D01}] => (Allow) E:\FlightGear 3.4.0\bin\fgcom.exe FirewallRules: [{26CC63FA-C260-455D-AF84-1BF59551125D}] => (Allow) E:\FlightGear 3.4.0\bin\terrasync.exe FirewallRules: [{82684B15-343C-4571-BAE3-85F5211172F7}] => (Allow) E:\FlightGear 3.4.0\bin\fgfs.exe FirewallRules: [{71DB9166-A7D1-4D7A-883F-0114B4B655FA}] => (Allow) E:\FlightGear 2016.1.1\bin\fgcom.exe FirewallRules: [{58FB1A75-8416-423F-9B70-34AEF5D0BDCD}] => (Allow) E:\FlightGear 2016.1.1\bin\fgcom.exe FirewallRules: [{923D22A2-781A-4C31-9265-C49DE3291701}] => (Allow) E:\FlightGear 2016.1.1\bin\terrasync.exe FirewallRules: [{1C6B788C-B3FB-4DAE-8306-6738C49E6F73}] => (Allow) E:\FlightGear 2016.1.1\bin\terrasync.exe FirewallRules: [{B9CFE015-0EF7-4682-8331-2039A00E0B21}] => (Allow) E:\FlightGear 2016.1.1\bin\metar.exe FirewallRules: [{7D32350D-ED32-4A4A-AFB8-DCE31C60AA78}] => (Allow) E:\FlightGear 2016.1.1\bin\fgfs.exe FirewallRules: [{884DFCC2-FE9E-447E-8D49-4E1058A1C37B}] => (Allow) E:\FlightGear 2016.1.1\bin\fgfs.exe FirewallRules: [{4AD1878F-DA3F-43AF-9107-00925DE4AABA}] => (Allow) E:\FlightGear 2016.1.1\bin\fgcom.exe FirewallRules: [{B8B42567-D643-47D5-8494-BDD777A203B9}] => (Allow) E:\FlightGear 2016.1.1\bin\fgcom.exe FirewallRules: [{93C2307C-6100-4B22-B281-23C318D7664D}] => (Allow) E:\FlightGear 2016.1.1\bin\terrasync.exe FirewallRules: [{55CC20B2-CD2D-4C5F-AB9A-17A08EA5AF0C}] => (Allow) E:\FlightGear 2016.1.1\bin\terrasync.exe FirewallRules: [{03AA61EE-19CB-40F5-AF09-04C8AE03D972}] => (Allow) E:\FlightGear 2016.1.1\bin\metar.exe FirewallRules: [{AD94BFC5-23A4-473F-AAB6-225FECC9D9D6}] => (Allow) E:\FlightGear 2016.1.1\bin\fgfs.exe FirewallRules: [{1F35C0AF-38C3-48F9-A26D-519E6480F38F}] => (Allow) E:\FlightGear 2016.1.1\bin\fgfs.exe FirewallRules: [{3DC69361-35D2-466F-935D-976C8AB21EE5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{7B4F36A8-F13F-4E6D-B78E-3A94CA4F57EC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{B5A01081-F3ED-41DC-AA6E-1F655A9ABE20}] => (Allow) LPort=1688 FirewallRules: [{4BD21740-5E6D-430D-A5B3-01EBD06FC64D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A2B32833-0207-42D7-AD76-FE8EF8254559}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B19F38F7-C798-4879-AC52-EBF78FE331E5}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{D34B1867-D3D9-4CD1-B407-EF87E9F1A01E}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{DDC0C9E0-32E5-4AFD-8771-76371B6E7494}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{CD9C1591-16F1-4560-BDA9-CBBB83E4BC98}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{3802C297-C10E-4C5E-8AE5-D632E73A868F}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{F0FD02D2-0C8F-4E2B-B446-4BE943B1A8F6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{6FE796E6-D863-4340-A191-155727EBEFFB}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{5DA71E69-1288-4E86-AEC1-39E039188D78}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{8BCF0678-76E0-435B-8823-348982BF1D63}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{3C7AC340-FCF8-4E83-9824-9C935EE7E059}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{60CEA867-9B71-4E27-B1C5-76847A55D6EC}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker 2016 Live\MusicMaker.exe FirewallRules: [TCP Query User{DC2A3478-1155-4A89-9F93-C5703E29EA2D}C:\users\jasper\appdata\local\temp\is-lleku.tmp\download\minithunderplatform.exe] => (Block) C:\users\jasper\appdata\local\temp\is-lleku.tmp\download\minithunderplatform.exe FirewallRules: [UDP Query User{9CAE6D2D-4DED-46E8-9246-F83B67775AA3}C:\users\jasper\appdata\local\temp\is-lleku.tmp\download\minithunderplatform.exe] => (Block) C:\users\jasper\appdata\local\temp\is-lleku.tmp\download\minithunderplatform.exe ==================== Herstelpunten ========================= AANDACHT: Systeemherstel is uitgeschakeld ==================== Defecte Apparaatbeheer Apparaten ============= Name: PCI Simple Communications-controller Description: PCI Simple Communications-controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Eventlog fouten: ========================= Applicatiefouten: ================== Error: (09/21/2016 09:31:32 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI is mislukt door de fout -2144927141. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/19/2016 08:36:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/19/2016 07:51:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/18/2016 03:42:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: SystemSettings.exe, versie: 10.0.10586.11, tijdstempel: 0x56457cb1 Naam van module met fout: ntdll.dll, versie: 10.0.10586.306, tijdstempel: 0x571af2eb Uitzonderingscode: 0xc0000409 Foutmarge: 0x00000000000953f7 Id van proces met fout: 0x1abc Starttijd van toepassing met fout: 0x01d211b26d37cafc Pad naar toepassing met fout: C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe Pad naar module met fout: C:\WINDOWS\SYSTEM32\ntdll.dll Rapport-id: 6a10bf5f-a6bd-4f33-9273-3a7971d12916 Volledige pakketnaam met fout: windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy Relatieve toepassings-id van pakket met fout: microsoft.windows.immersivecontrolpanel Error: (09/16/2016 11:02:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: microsoftedgecp.exe, versie: 11.0.10586.20, tijdstempel: 0x56540c35 Naam van module met fout: edgehtml.dll, versie: 11.0.10586.545, tijdstempel: 0x57a1bd6b Uitzonderingscode: 0x80004004 Foutmarge: 0x000000000064f363 Id van proces met fout: 0x1268 Starttijd van toepassing met fout: 0x01d20ff900a85d27 Pad naar toepassing met fout: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe Pad naar module met fout: C:\WINDOWS\SYSTEM32\edgehtml.dll Rapport-id: dc7136a2-557f-4945-9d95-bd7d14c0ecb0 Volledige pakketnaam met fout: Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe Relatieve toepassings-id van pakket met fout: MicrosoftEdge Error: (09/16/2016 10:58:43 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/16/2016 10:47:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/16/2016 10:31:48 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/16/2016 10:23:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Error: (09/16/2016 10:23:22 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-3DQ83PL) Description: Het activeren van de app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 is mislukt door de fout -2147024891. Kijk in het logboek Microsoft-Windows-TWinUI/Operational voor aanvullende informatie. Systeemfouten: ============= Error: (09/23/2016 09:01:47 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x8024200d: Onderdelenupdate naar Windows 10, versie 1607. Error: (09/23/2016 08:33:22 AM) (Source: DCOM) (EventID: 10016) (User: WINDOWS-3DQ83PL) Description: In de machtigingsinstellingen standaard voor deze computer wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} en APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} aan de gebruiker WINDOWS-3DQ83PL\Jasper SID (S-1-5-21-3280333162-937765043-293338858-1000) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer CapsuleDigital.PhotoFunia_5.2.0.0_neutral__yede6ekgzbztc SID (S-1-15-2-3490798887-4175610012-4048354168-3993597651-1203629619-1240133896-111838046). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (09/21/2016 07:28:58 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: De computer is opnieuw opgestart na een bugcontrole. De bugcontrole is 0x00000019 (0x0000000000000020, 0xffffe000d8c40940, 0xffffe000d8c40960, 0x0000000004020008). Er is een dump opgeslagen in: C:\WINDOWS\MEMORY.DMP. Rapport-id: e5de0dde-6f33-4f6f-8f5d-6b20d12303a5. Error: (09/21/2016 07:23:40 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: De vorige afsluiting van het systeem om 18:52:50 op ‎21-‎9-‎2016 is onverwacht gebeurd. Error: (09/21/2016 06:56:03 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: De computer is opnieuw opgestart na een bugcontrole. De bugcontrole is 0x00000019 (0x0000000000000020, 0xffffe0013eb4a8e0, 0xffffe0013eb4a900, 0x0000000004020008). Er is een dump opgeslagen in: C:\WINDOWS\MEMORY.DMP. Rapport-id: 40ccb94f-6d21-4340-9a48-683ea54132b9. Error: (09/21/2016 06:52:50 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: De vorige afsluiting van het systeem om 10:58:41 op ‎21-‎9-‎2016 is onverwacht gebeurd. Error: (09/21/2016 06:42:14 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x8024200d: Onderdelenupdate naar Windows 10, versie 1607. Error: (09/21/2016 06:34:51 PM) (Source: DCOM) (EventID: 10016) (User: WINDOWS-3DQ83PL) Description: In de machtigingsinstellingen standaard voor deze computer wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} en APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} aan de gebruiker WINDOWS-3DQ83PL\Jasper SID (S-1-5-21-3280333162-937765043-293338858-1000) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer CapsuleDigital.PhotoFunia_5.2.0.0_neutral__yede6ekgzbztc SID (S-1-15-2-3490798887-4175610012-4048354168-3993597651-1203629619-1240133896-111838046). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (09/21/2016 09:31:40 AM) (Source: DCOM) (EventID: 10010) (User: WINDOWS-3DQ83PL) Description: De server {D63B10C5-BB46-4990-A94F-E40B9D520160} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd. Error: (09/21/2016 09:31:40 AM) (Source: DCOM) (EventID: 10010) (User: WINDOWS-3DQ83PL) Description: De server {D63B10C5-BB46-4990-A94F-E40B9D520160} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd. CodeIntegrity: =================================== Date: 2016-09-21 20:27:53.865 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:53.819 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:53.782 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:53.727 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:53.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:53.639 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:52.566 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 20:27:52.307 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2016-09-21 18:35:26.454 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-21 09:39:36.439 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Geheugen info =========================== Processor: Intel(R) Core(TM)2 Duo CPU E7500 @ 2.93GHz Percentage geheugen in gebruik: 50% Totaal fysiek RAM-geheugen: 3994.73 MB Beschikbaar fysiek RAM-geheugen: 1975.31 MB Totaal Virtueel geheugen: 8346.73 MB Beschikbaar Virtual geheugen: 6073.93 MB ==================== Schijven ================================ Drive c: () (Fixed) (Total:50.22 GB) (Free:4.99 GB) NTFS Drive d: (Bestanden) (Fixed) (Total:415 GB) (Free:352.22 GB) NTFS Drive e: (2de_schijf) (Fixed) (Total:931.51 GB) (Free:761.14 GB) NTFS ==================== MBR & Partitietabel ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 1535DCCF) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=50.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=415 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: F07BF07B) Partition 2: (Not Active) - (Size=931.5 GB) - (Type=OF Extended) ==================== Eind van Addition.txt ============================