Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 07-12-2016 Gestart door Jacco (12-12-2016 13:02:40) Gestart vanaf C:\Users\Jacco\Desktop Windows 10 Home Versie 1607 (X64) (2016-11-19 14:30:03) Boot Modus: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3217320804-809556438-773013679-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3217320804-809556438-773013679-503 - Limited - Disabled) Gast (S-1-5-21-3217320804-809556438-773013679-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3217320804-809556438-773013679-1003 - Limited - Enabled) Jacco (S-1-5-21-3217320804-809556438-773013679-1001 - Administrator - Enabled) => C:\Users\Jacco ==================== Security Center ======================== (Als een item is opgenomen in de fixlist, zal het worden verwijderd.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: Bitdefender Antivirus (Enabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371} AS: Bitdefender Antispyware (Enabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {078AF241-05A3-0EFF-40E0-3E0D69EA140A} ==================== Geïnstalleerde programma's ====================== (Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.) Ansel (Version: 376.19 - NVIDIA Corporation) Hidden Apowersoft Online Launcher versie 1.4.6 (HKLM-x32\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.4.6 - APOWERSOFT LIMITED) Apple Application Support (32-bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) AudioFXSetup (Version: 1.2.901 - Nahimic) Hidden Battery Calibration (HKLM-x32\...\InstallShield_{634AC01E-49DB-4AD2-B87C-90D4DCC6AFA1}) (Version: 1.0.1508.1001 - Micro-Star International Co., Ltd.) Battery Calibration (x32 Version: 1.0.1508.1001 - Micro-Star International Co., Ltd.) Hidden Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 21.0.21.970 - Bitdefender) Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 21.0.21.976 - Bitdefender) Bitdefender Total Security 2017 (HKLM\...\Bitdefender) (Version: 21.0.21.976 - Bitdefender) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Boot Configure (HKLM-x32\...\{449D0FA3-CC16-4DEB-A2CE-215BE0F66C25}) (Version: 20.015.12293 - Micro-Star International Co., Ltd.) BurnRecovery (HKLM-x32\...\InstallShield_{92A6B009-1343-4C44-AFB1-8849137CA3F0}) (Version: 5.0.1509.201 - Application) BurnRecovery (x32 Version: 5.0.1509.201 - Application) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.24 - Piriform) CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5307.55 - CyberLink Corp.) De Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.25.136.1020 - Electronic Arts Inc.) Dragon Gaming Center (HKLM-x32\...\InstallShield_{965B16C7-0778-4C45-B7D1-83A59E6FBBCB}) (Version: 1.0.1501.2801 - Micro-Star International Co., Ltd.) Dragon Gaming Center (x32 Version: 1.0.1501.2801 - Micro-Star International Co., Ltd.) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 15.4.22 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Help Desk (HKLM-x32\...\InstallShield_{7E8181AF-9679-49B3-B133-C265709B6927}) (Version: 1.0.1609.3001 - Micro-Star International Co., Ltd.) Help Desk (x32 Version: 1.0.1609.3001 - Micro-Star International Co., Ltd.) Hidden HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.15.281 - SurfRight B.V.) HP DeskJet 3630 series Basissoftware van het apparaat (HKLM\...\{979F69E3-8E17-4895-BAD4-4653FE24914F}) (Version: 40.5.1092.16309 - HP Inc.) HP DeskJet 3630 series Help (HKLM-x32\...\{084F0EAA-EB34-4CC3-9CED-B7FF666AF300}) (Version: 35.0.0 - Hewlett Packard) HP Dropbox Plugin (HKLM-x32\...\{2E5A25A3-C329-40FB-9A09-E2C75B746935}) (Version: 36.0.41.58587 - HP) HP Google Drive Plugin (HKLM-x32\...\{CF37027C-AA2E-46B8-B741-6205E001C4F4}) (Version: 36.0.41.58587 - HP) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Support Solutions Framework (HKLM-x32\...\{4CBA8ECF-0519-4583-91ED-F098522245EB}) (Version: 12.5.32.37 - HP Inc.) HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard) iCloud (HKLM\...\{29AAC3D3-23FC-496D-8266-0E3833686758}) (Version: 6.0.2.10 - Apple Inc.) Intel(R) Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4300 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{31C74FA2-2AB9-41C3-BFBE-693283E4C28B}) (Version: 17.1.1527.1534 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{795ee3a0-97fa-489a-9543-7564ccc43be4}) (Version: 18.12.0 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.) KB9X Radio Switch Driver (HKLM\...\EC950B206B0E7722C96A318DF396BABFBB057BC0) (Version: 1.1.2.0 - ENE TECHNOLOGY INC.) LauncherSetup (Version: 1.2.901 - Nahimic) Hidden Malwarebytes versie 3.0.4.1269 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.4.1269 - Malwarebytes) Microsoft Office 365 - nl-nl (HKLM\...\O365HomePremRetail - nl-nl) (Version: 16.0.7466.2038 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) MSI Remind Manager (HKLM-x32\...\InstallShield_{3E23F267-3E35-40F9-B6BF-BC034D214717}) (Version: 1.0.1510.1901 - Micro-Star International Co., Ltd.) MSI Remind Manager (x32 Version: 1.0.1510.1901 - Micro-Star International Co., Ltd.) Hidden MSI Social Media Collection (HKLM-x32\...\{7ADEC426-BE95-48EF-84D4-086BD0F4D331}) (Version: 1.14.2251 - Micro-Star International Co., Ltd.) Nahimic for MSI (HKLM-x32\...\{c941ec8c-c7a7-4f06-bd8c-1d679896f19b}) (Version: 1.2.9 - Nahimic) NahimicSettingsConfigurator (Version: 1.2.901 - Nahimic) Hidden NVIDIA GeForce Experience 3.1.2.31 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.1.2.31 - NVIDIA Corporation) NVIDIA Grafisch stuurprogramma 376.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.19 - NVIDIA Corporation) NVIDIA PhysX Systeem Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.1.2.31 - NVIDIA Corporation) Hidden NvTelemetry (Version: 1.2.0.0 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7466.2038 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7426.1015 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7466.2038 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7466.2038 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Planet Coaster (HKLM\...\Steam App 493340) (Version: - Frontier Developments) PrivaZer (HKLM-x32\...\PrivaZer) (Version: 3.0.13.0 - Goversoft LLC) ProductDaemonSetup (Version: 1.2.901 - Nahimic) Hidden Productverbeteringsonderzoek voor HP DeskJet 3630 series (HKLM\...\{3B2DF5F0-0677-4DFA-BD68-3F0398460E65}) (Version: 40.5.1092.16309 - HP Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7576 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.0.8 - Rockstar Games) SCM (HKLM\...\{716E4961-5876-45A5-AC78-F91B1D31F98B}) (Version: 13.015.10156 - Application) SHIELD Streaming (Version: 7.1.0340 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.1.2.31 - NVIDIA Corporation) Hidden Sizing Options (HKLM-x32\...\InstallShield_{DFAB6DE8-E45F-4D5D-95C0-E54C58993F9F}) (Version: 3.0.1512.0101 - Application) Sizing Options (x32 Version: 3.0.1512.0101 - Application) Hidden Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.103 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\Spotify) (Version: 1.0.44.100.ga60c0ce1 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SUPER CHARGER (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.024 - MSI) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.6.1 - Synaptics Incorporated) UIInstallUpgrade (Version: 1.2.901 - Nahimic) Hidden Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WinZip 17.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. ) ==================== Aangepaste CLSID (gefilterd): ========================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Geplande Taken (gefilterd) ============= (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {00CEB2DF-5530-414B-B583-0DEB448696FC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-11-17] (NVIDIA Corporation) Task: {1F458F31-24BE-4B06-803E-983EAE5B769A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-10-30] (Microsoft Corporation) Task: {21409A4C-B552-4C5A-93E6-F7BC10DA5EA7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.) Task: {325EFCE8-177A-48D1-ACC0-E85C6DF896EF} - System32\Tasks\MSI_Dragon Gaming Center => C:\Program Files (x86)\MSI\Dragon Gaming Center\mDispatch.exe [2014-01-24] (TODO: <公司名稱>) Task: {49A81F6B-0CAB-433D-9925-9D411243B112} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2016-10-05] (Apple Inc.) Task: {4B27CB9B-38BF-41B2-B8C1-15AC2C62D862} - System32\Tasks\NahimicMSIsvc32Run => C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIsvc32.exe [2015-10-12] () Task: {56B5F772-F3F5-44FB-A82E-F7EA51876918} - System32\Tasks\MSI_Help_Desk_Agent => C:\Program Files (x86)\MSI\Help Desk\MSI Update Agent.exe [2016-09-30] (Micro-Star International Co., Ltd.) Task: {65477BCC-534C-47C1-A232-693D8BEE36DB} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2016-10-21] (Bitdefender) Task: {68BF0C26-A7BA-4BD4-858F-94DC9F6D062A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-11-17] (NVIDIA Corporation) Task: {6CF5D4D3-AD4E-4BD7-8B49-AF8D46E30915} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2016-10-31] (HP Inc.) Task: {7375ACB4-22ED-4979-BBFE-E8231BE0631D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.) Task: {747F3714-EB4B-47E4-AF2C-19AE0FAA190C} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-12-28] (Synaptics Incorporated) Task: {7A45CB2C-3C94-4523-8A51-053247E01B76} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-11-17] (NVIDIA Corporation) Task: {7CFB5B81-6298-44DC-A7DD-BB17FA069F6B} - System32\Tasks\PDVDServ12 Task => C:\Program Files (x86)\CyberLink\PowerDVD12\PDVD12Serv.exe [2015-05-11] (CyberLink Corp.) Task: {89F5DF76-3331-4F2B-9BF0-F94114DCE8A2} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-24] (Dropbox, Inc.) Task: {8AFE5CCF-098C-4233-9C93-919007559F66} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-24] (Dropbox, Inc.) Task: {961BB2E7-E0F6-4A0A-B335-791CDD07D5EF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-07-04] (HP Inc.) Task: {9BEA9AF6-525E-41FC-B76F-7CC3BC7F569D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {A0B88E73-36FA-423E-B877-F9FF15122E1A} - System32\Tasks\EVGAPrecisionX => D:\Program Files (x86)\Steam\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe Task: {A12A7EC0-B9C1-4FB5-9BDE-7A52DF25F77C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-10-30] (Microsoft Corporation) Task: {A54CF267-33F9-43C0-BF17-8ECE61745E70} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-11-17] (NVIDIA Corporation) Task: {A58491AE-B3FB-4C5C-BBBF-D351FCC9375E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-11-17] (NVIDIA Corporation) Task: {A5A0B5D8-C6D0-4150-965D-A932B78E864C} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.) Task: {AA0DB673-E8D3-4F00-8DE2-BBFB61A9B9E5} - System32\Tasks\HPCeeScheduleForJacco => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-05-12] (HP Development Company, L.P.) Task: {ADFBF241-9B1E-41BC-82D1-8F4292BCB1F0} - System32\Tasks\PrivaZer_SkipUAC => D:\PrivaZer\PrivaZer.exe [2016-12-10] (Goversoft LLC) Task: {B4A3A6E9-5F99-4748-B0CE-E1112D659500} - System32\Tasks\NahimicMSIUILauncherRun => C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIUILauncher.exe [2015-10-12] () Task: {B7D3213E-5B52-4F31-B56A-09785E997297} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-11-15] (Piriform Ltd) Task: {B98DE9DC-CF61-4C59-B0DC-85CB5935B5EF} - System32\Tasks\HPCustParticipation HP DeskJet 3630 series => C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPCustPartic.exe [2016-11-04] (HP Inc.) Task: {CB56449C-62A7-4D81-9BB3-FDB8870F36B3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-15] (Google Inc.) Task: {DB21EAF0-BB86-4EA0-ABA9-5BAEABDBE3A3} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-11-17] (NVIDIA Corporation) Task: {DDC31C75-FBF3-4853-B6DE-5BB0120C2E2C} - System32\Tasks\PrivaZer_automatic_cleanup => D:\PrivaZer\PrivaZer.exe [2016-12-10] (Goversoft LLC) Task: {DF06458F-926A-4D70-93DF-23A87124B133} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-15] (Google Inc.) Task: {E2638DD4-9B1C-4002-B9BD-668C2DF5DCBA} - System32\Tasks\NahimicMSIsvc64Run => C:\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIsvc64.exe [2015-10-12] () Task: {E789E8D3-D2AD-4C8C-B0FA-FB8CFCD64686} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-08-03] (HP Inc.) Task: {F78AD30A-BFC5-4646-B9B9-6F10F372B6FC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-11-02] (Microsoft Corporation) (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForJacco.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Snelkoppelingen ============================= (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.) ==================== Geladen Modules (gefilterd) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-10 20:25 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-15 20:16 - 2013-09-03 14:29 - 00111832 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\bdmetrics.dll 2016-11-15 20:16 - 2016-12-10 18:27 - 00138880 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\ECEvents.dll 2016-11-15 20:21 - 2016-11-15 20:21 - 01008448 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpbr.mdl 2016-11-15 20:21 - 2016-11-15 20:21 - 00541952 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpdsp.mdl 2016-11-15 20:21 - 2016-11-15 20:21 - 03202816 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpph.mdl 2016-11-15 20:21 - 2016-11-15 20:21 - 01542976 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttprbl.mdl 2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 00418752 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\_nvspserviceplugin64.dll 2016-12-12 10:57 - 2016-11-29 06:27 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2016-12-12 10:57 - 2016-11-29 06:27 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-12-12 10:57 - 2016-11-29 06:27 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-11-19 15:22 - 2016-12-01 18:32 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-12-10 20:25 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-12-10 15:59 - 2016-12-10 15:59 - 03525431 _____ () D:\PrivaZer\PrivaMenu5.dll 2016-11-19 15:39 - 2016-11-19 15:39 - 01864384 _____ () C:\Users\Jacco\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-12-10 20:24 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-19 15:15 - 2016-11-19 15:15 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-10-12 18:47 - 2015-10-12 18:47 - 00184800 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIDevProps.dll 2015-10-12 18:47 - 2015-10-12 18:47 - 00276960 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIOSD.dll 2016-11-20 12:11 - 2016-11-20 12:11 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-20 12:11 - 2016-11-20 12:11 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-20 12:11 - 2016-11-20 12:11 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2014-01-22 19:44 - 2014-01-22 19:44 - 00075912 _____ () C:\Program Files (x86)\MSI\Dragon Gaming Center\WinIo64.dll 2015-10-12 18:42 - 2015-10-12 18:42 - 00535008 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIUILauncher.exe 2015-10-12 18:42 - 2015-10-12 18:42 - 00821248 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIsvc32.exe 2015-10-12 18:48 - 2015-10-12 18:48 - 00268800 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIsvc64.exe 2016-12-10 19:33 - 2016-11-17 14:42 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_system-vc120-mt-1_58.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\nvstreamsrv\boost_regex-vc120-mt-1_58.dll 2016-11-15 20:16 - 2016-12-10 18:27 - 00023840 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\lang\nl-NL\bdsystray.txtui 2016-12-03 13:24 - 2016-12-03 13:25 - 00743424 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WinUAPEntry.exe 2016-12-10 22:15 - 2016-12-10 20:34 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2015-12-29 23:58 - 2016-11-17 14:42 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2015-10-12 18:40 - 2015-10-12 18:40 - 00156640 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIDevProps.dll 2015-10-12 18:41 - 2015-10-12 18:41 - 00245216 _____ () C:\Program Files\Nahimic\NahimicMSI\UserInterface\NahimicMSIOSD.dll 2016-12-10 19:33 - 2016-11-17 11:20 - 00506424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-12-10 19:33 - 2016-11-17 11:20 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-12-10 19:33 - 2016-11-17 11:20 - 02809912 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-12-10 19:33 - 2016-11-17 11:20 - 00245184 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-12-10 19:33 - 2016-11-17 11:20 - 00436792 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node 2016-12-10 19:33 - 2016-11-17 11:20 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-12-10 19:33 - 2016-11-17 11:20 - 00968248 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node 2016-11-19 15:39 - 2016-11-19 15:39 - 01383616 _____ () C:\Users\Jacco\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll 2016-11-19 15:39 - 2016-11-19 15:39 - 00118976 _____ () C:\Users\Jacco\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 60817344 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2015-08-07 10:09 - 2015-08-07 10:09 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00013312 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WP8MSVCCommon.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00382464 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WP8MSVCBridge.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00079872 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WinPhoneBridge_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00992768 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\System_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00107520 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\pthreadVC_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00641536 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\CrossPortability_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00210432 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\system_malloc_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 57809184 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00081422 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\unwind_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00152576 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\exif_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00702464 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\ffmpeg_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00153088 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\z_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 01111040 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\c++_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00411136 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\SystemResources_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 01530880 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WRTBridge_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00163840 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WinMediaFoundation_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00126976 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\EGL_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 01155072 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\GLESv2_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 175928112 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\App.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 01085440 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\iconv_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 00397312 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\OpenAL_osmeta.dll 2016-12-03 13:24 - 2016-12-03 13:25 - 27976982 _____ () C:\Program Files\WindowsApps\Facebook.Facebook_71.684.7263.0_x86__8xx8rvfyw5nnt\WebCore_osmeta.dll 2016-12-10 19:33 - 2016-11-17 14:42 - 00018880 _____ () c:\program files (x86)\nvidia corporation\nvstreamsrv\detoured.dll 2016-11-15 20:12 - 2016-11-08 21:29 - 01819240 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll 2016-11-15 20:12 - 2016-11-08 21:29 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll ==================== Alternate Data Streams (gefilterd) ========= (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.) AlternateDataStreams: C:\Users\Jacco\Desktop\FRST64.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\apowersoft-online-launcher.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\BitdefenderRemovalPoweliks.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\GeForce_Experience_v3.1.2.31.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\HitmanPro_x64.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\HPSupportSolutionsFramework-12.5.26.37.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\mb3-setup-consumer-3.0.4.1269.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\OriginThinSetup (1).exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\OriginThinSetup.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\PrivaZer_for_donors (1).exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\PrivaZer_for_donors.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\privazer_free.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\SpotifySetup.exe:BDU [0] AlternateDataStreams: C:\Users\Jacco\Downloads\video-download-capture-saas.exe:BDU [0] ==================== Veilige Modus (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Bestandskoppeling (gefilterd) =============== (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.) ==================== Internet Explorer vertrouwde/beperkte toegang =============== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.) ==================== Hosts inhoud: =============================== (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.) 2015-10-30 08:24 - 2016-12-12 12:47 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere gebieden ============================ (Momenteel is er geen automatische fix voor dit onderdeel.) HKU\S-1-5-21-3217320804-809556438-773013679-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\System32\oobe\info\Wallpaper\backgroundDefault.jpg DNS Servers: 192.168.2.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is ingeschakeld. ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items == HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "Dropbox" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "AppleIEDAV" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "iCloudDrive" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "iCloudPhotos" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "iCloudServices" HKU\S-1-5-21-3217320804-809556438-773013679-1001\...\StartupApproved\Run: => "EADM" ==================== Firewall regels (gefilterd) =============== (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{9006FD96-6EB2-4EAF-99FF-A85F71220AE3}] => D:\Program Files (x86)\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe FirewallRules: [{972E5909-8115-4680-BE7D-8787518D4F36}] => D:\Program Files (x86)\Steam\steamapps\common\Planet Coaster\PlanetCoaster.exe FirewallRules: [{DB8819C7-E086-40B9-A01E-FF8856514371}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{42FE0CE9-56E4-4601-A463-8EB27D0C4D8D}] => C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{0D29D703-C881-46B9-AE78-240ADA50ABC0}] => C:\Program Files\iTunes\iTunes.exe FirewallRules: [{7DFF1811-CCD2-4A98-8AD2-8F9E828CB355}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{818B0738-0305-4255-84ED-2229FA86D878}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C3EAA91F-F74D-48A8-9A31-BEBFDD309E99}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{AD4C830A-735E-4E63-806D-91C51E506459}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A38A23EA-B326-4D04-88AF-70EB1C2A9A9A}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2E60238B-EA2A-4313-BA64-C0FC504FE361}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{F24A36C7-0493-4B99-B46B-18724AF6BB08}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{D2F12693-55EB-4898-ACF8-3D1C5E8A305C}] => C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe FirewallRules: [{2206C5C3-22A8-49F9-B6DD-7732BD9EAA96}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{E99369C6-5A4E-47D3-82FB-4AF99F01FFF8}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{DE6E0F15-B041-4D35-9066-2706CDA7E186}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F499368B-5A16-46F6-B57F-E6DBE4A1FCFD}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{DDA25374-77B9-4BA1-8F87-4D30592BB54D}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{F93F4432-BEB8-42D0-BD75-239D2289EBB2}] => C:\Program Files\HP\HP DeskJet 3630 series\Bin\DeviceSetup.exe FirewallRules: [{6428D3A8-189A-419D-B6FB-3C410014984C}] => LPort=5357 FirewallRules: [{276882A4-4FC4-4D06-887D-D90596DD42BB}] => C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{74D2484D-0091-447D-86B4-D7E5AE63632C}] => D:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [{07DA59AD-DAD2-4E68-8888-AB01C17FA07E}] => D:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [{5EE520EB-117E-40FC-9E2B-6CD04E73AB72}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{C7F362A4-A008-4D8F-BE1F-948889193EC1}] => C:\Users\Jacco\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe FirewallRules: [{B0097029-0C63-446B-A24F-60421382303B}] => C:\Users\Jacco\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe FirewallRules: [{4F0D2B1A-8356-4BAE-BEF8-71AD61716171}] => C:\Users\Jacco\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe FirewallRules: [{8B55BA15-FE9C-49E0-9A4D-38E2DCE96637}] => C:\Users\Jacco\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe FirewallRules: [{C68A97C0-33EF-4272-B5E0-9BC67B864EFA}] => D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{C9C0ABB3-59DB-423B-8065-2550FE37D280}] => D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{4C0CABCE-F494-43CD-A7E8-210D92A0BCBD}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{12AA0721-AE31-4EF9-B557-26A514DAE4CB}] => D:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{77FED1DF-DBAB-48CD-BCB6-C63148767A22}] => D:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{D37EF9DE-622A-452F-98B2-D15243244ACD}] => C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{EF2F2A35-71EB-4497-9D83-9A56A5C29FD1}] => C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{53AA9813-BEC4-4AD2-988A-C228A874E783}] => C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{29E89F61-D833-4A4B-9821-773915380A96}] => C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe FirewallRules: [{C55CF6C7-A345-4174-8408-6A980C696345}] => D:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe FirewallRules: [{D9093503-2B42-44EF-A2B5-36AB92B97B77}] => D:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe ==================== Herstelpunten ========================= AANDACHT: Systeemherstel is uitgeschakeld ==================== Defecte Apparaatbeheer Apparaten ============= ==================== Eventlog fouten: ========================= Applicatiefouten: ================== Error: (12/12/2016 11:47:56 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 13 7.2.D.5.A.E.C.C.3.9.B.5.E.C.9.E.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR MSI-2.local. Error: (12/12/2016 11:47:56 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.2.112:5353 11 7.2.D.5.A.E.C.C.3.9.B.5.E.C.9.E.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR MSI.local. Error: (12/12/2016 11:47:56 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 13 112.2.168.192.in-addr.arpa. PTR MSI-2.local. Error: (12/12/2016 11:47:56 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.2.112:5353 11 112.2.168.192.in-addr.arpa. PTR MSI.local. Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname MSI.local already in use; will try MSI-2.local instead Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 MSI.local. Addr 192.168.2.112 Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.2.112:5353 16 MSI.local. AAAA 2A02:A442:64D7:0001:E9CE:5B93:CCEA:5D27 Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Resetting to Probing: 16 MSI.local. AAAA FE80:0000:0000:0000:E9CE:5B93:CCEA:5D27 Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.2.112:5353 16 MSI.local. AAAA 2A02:A442:64D7:0001:E9CE:5B93:CCEA:5D27 Error: (12/12/2016 11:47:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Resetting to Probing: 4 MSI.local. Addr 192.168.2.112 Systeemfouten: ============= Error: (12/12/2016 11:47:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 11:47:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 11:47:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} en APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} aan de gebruiker NT AUTHORITY\SYSTEM SID (S-1-5-18) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 11:41:39 AM) (Source: DCOM) (EventID: 10010) (User: MSI) Description: De server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd. Error: (12/12/2016 11:41:39 AM) (Source: DCOM) (EventID: 10010) (User: MSI) Description: De server App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd. Error: (12/12/2016 09:30:33 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker NT AUTHORITY\SYSTEM SID (S-1-5-18) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 09:28:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 09:28:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 09:28:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} en APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} aan de gebruiker NT AUTHORITY\SYSTEM SID (S-1-5-18) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (12/12/2016 02:39:58 AM) (Source: DCOM) (EventID: 10010) (User: MSI) Description: De server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd. CodeIntegrity: =================================== Date: 2016-12-12 11:47:20.185 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-11 23:24:46.169 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-10 22:04:40.431 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-10 21:47:49.316 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-10 18:12:16.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-08 14:35:28.392 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-05 13:33:55.983 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIOSD.dll that did not meet the Store signing level requirements. Date: 2016-12-05 13:33:55.979 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIDevProps.dll that did not meet the Store signing level requirements. Date: 2016-12-05 13:33:36.222 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIOSD.dll that did not meet the Store signing level requirements. Date: 2016-12-05 13:33:36.219 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Nahimic\NahimicMSI\UserInterface\x64\NahimicMSIDevProps.dll that did not meet the Store signing level requirements. ==================== Geheugen info =========================== Processor: Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz Percentage geheugen in gebruik: 30% Totaal fysiek RAM-geheugen: 16294.6 MB Beschikbaar fysiek RAM-geheugen: 11304.73 MB Totaal Virtueel geheugen: 18726.6 MB Beschikbaar Virtual geheugen: 13281.05 MB ==================== Schijven ================================ Drive c: (OS_Install) (Fixed) (Total:117.16 GB) (Free:49.73 GB) NTFS Drive d: (Data) (Fixed) (Total:913.2 GB) (Free:752.82 GB) NTFS ==================== MBR & Partitietabel ================== ======================================================== Disk: 0 (Size: 119.2 GB) (Disk ID: C5E86819) Partition: GPT. ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: C5E8683A) Partition: GPT. ==================== Eind van Addition.txt ============================