Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 20.06.2018 Gestart door hcoor (08-07-2018 19:39:15) Gestart vanaf C:\Users\hcoor\Downloads Windows 10 Home Versie 1803 17134.112 (X64) (2018-06-07 17:23:33) Boot Modus: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1326076328-647220812-2880691162-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1326076328-647220812-2880691162-503 - Limited - Disabled) Gast (S-1-5-21-1326076328-647220812-2880691162-501 - Limited - Disabled) hcoor (S-1-5-21-1326076328-647220812-2880691162-1002 - Administrator - Enabled) => C:\Users\hcoor HomeGroupUser$ (S-1-5-21-1326076328-647220812-2880691162-1004 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-1326076328-647220812-2880691162-504 - Limited - Disabled) ==================== Security Center ======================== (Als een item is opgenomen in de fixlist, zal het worden verwijderd.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Ziggo Safe Online by F-Secure (Enabled - Up to date) {35BE5FA4-2DEA-00F8-DC55-FD8AF743F44F} AS: Ziggo Safe Online by F-Secure (Enabled - Up to date) {8EDFBE40-0BD0-0F76-E6E5-C6F88CC4BEF2} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Geïnstalleerde programma's ====================== (Alleen de adware-programma's met 'verborgen' vlag kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeïnstalleerd worden.) Adobe Acrobat Reader DC - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.7.157 - Adobe Systems, Inc.) AMD Catalyst Install Manager (HKLM\...\{A30D3EA3-B90A-DDD5-949E-6DDE67E64FE6}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Computer Security 17.204.106.0 (release) (HKLM-x32\...\{658FDBCA-B7A1-43E4-A849-9F0812473331}) (Version: 17.204.106.0 - F-Secure Corporation) Hidden CyberLink PhotoDirector (HKLM\...\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.6.7006 - Uw bedrijfsnaam) Hidden CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.6.7006 - CyberLink Corp.) CyberLink Power Media Player 14 (HKLM-x32\...\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.6.7428 - CyberLink Corp.) CyberLink PowerDirector 12 (HKLM\...\{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.5.4601 - Uw bedrijfsnaam) Hidden CyberLink PowerDirector 12 (HKLM-x32\...\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.5.4601 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.2.4627 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden DisableMSDefender (HKLM\...\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden Dropbox 25 GB (HKLM-x32\...\{0867A88D-764F-366E-9E21-130DA8B472C3}) (Version: 3.1.18.0 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden DVD Decrypter (Remove Only) (HKLM-x32\...\DVD Decrypter) (Version: - ) EasyPDFCombine Internet Explorer Homepage and New Tab (HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\EasyPDFCombineTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== AANDACHT Energy Star (HKLM\...\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC}) (Version: 1.0.9 - Hewlett-Packard Company) Epson Connect Guide (HKLM-x32\...\Epson Connect Guide) (Version: - ) Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.0 - Seiko Epson Corporation) Epson Event Manager (HKLM-x32\...\{8F01524C-0676-4CC1-B4AE-64753C723391}) (Version: 3.01.0005 - Seiko Epson Corporation) Epson E-Web Print (HKLM-x32\...\{6BF9F374-EC67-4808-A90C-F127DE6D989D}) (Version: 1.23.0000 - SEIKO EPSON CORPORATION) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.31.00 - SEIKO EPSON CORPORATION) Epson Gebruikershandleiding WF-2540 Series (HKLM-x32\...\WF-2540 Series Useg) (Version: - ) Epson Netwerkhandleiding WF-2540 Series (HKLM-x32\...\WF-2540 Series Netg) (Version: - ) EPSON Printer Finder (HKLM-x32\...\{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}) (Version: 1.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{29F4F2C2-CB73-418D-BA99-7BB5ECD9F7BF}) (Version: 4.4.6 - Seiko Epson Corporation) EPSON WF-2540 Series Printer Uninstall (HKLM\...\EPSON WF-2540 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Eusing Free Registry Cleaner (HKLM-x32\...\Eusing Free Registry Cleaner) (Version: - Eusing Software) Evernote v. 5.8.13 (HKLM-x32\...\{A229420E-204B-11E5-B844-0050569584E9}) (Version: 5.8.13.8152 - Evernote Corp.) F-Secure Ultralight 1.1.14.0 (release) (HKLM-x32\...\{55079DAB-EB0E-4946-8AC2-64CD27AA3146}) (Version: 1.1.14.0 - F-Secure Corporation) Hidden Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.107 - Google Inc.) Hidden HP Documentation (HKLM\...\HP_Documentation) (Version: - HP) HP ePrint SW (HKLM-x32\...\{88970959-baf7-4864-a39a-69a58e8ae5cf}) (Version: 5.0.18701 - HP) HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.8305.5282 - Hewlett-Packard) HP Support Solutions Framework (HKLM-x32\...\{59F431E1-0983-40D8-A872-6EF8EE3A5DAA}) (Version: 12.9.24.3 - Hewlett-Packard Company) HP System Event Utility (HKLM-x32\...\{D17A3B70-B75E-4C49-83D6-C17DDF65B35F}) (Version: 1.3.4 - Hewlett-Packard Company) HP Touchpoint Analytics Client (HKLM\...\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.) HP Welcome (HKLM\...\HPWelcome) (Version: 1.0 - HP Inc.) Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 - nl-nl (HKLM\...\ProPlusRetail - nl-nl) (Version: 15.0.5041.1001 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{DC5E5027-65E8-41CB-815C-9AAB48BFB8E2}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 59.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.3 (x64 en-US)) (Version: 59.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla) MyFreeCodec (HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\MyFreeCodec) (Version: - ) OEM Application Profile (HKLM-x32\...\{B4B7FD8F-06FC-E277-4F29-8F75F8281D8F}) (Version: 1.00.0000 - Uw bedrijfsnaam) Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5041.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5041.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0413-0000-0000000FF1CE}) (Version: 15.0.5041.1001 - Microsoft Corporation) Hidden Online Safety 2.204.7118.12 (HKLM-x32\...\{86CBD388-8B4D-4275-9872-60F6BF7211FA}) (Version: 2.204.7118.12 - F-Secure Corporation) Hidden OnlineMapFinder Internet Explorer Homepage and New Tab (HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\OnlineMapFinderTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== AANDACHT PCMSCAN (HKLM-x32\...\{979B748C-6095-4A5A-BC7B-C15E720529D6}) (Version: 2.4.12 - Palmer Performance Engineering) Popcorn-Time (HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\Popcorn-Time) (Version: 0.3.10 - Popcorn Time) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7944 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.64 - REALTEK Semiconductor Corp.) Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.) ScanMaster-ELM 2.1.104.771 (HKLM\...\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories) Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (HKLM-x32\...\{A3EBD6B2-C317-43BD-B26A-C58FFBA30F9C}) (Version: 6.5 - Silicon Laboratories, Inc.) Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7_2 (c:\SiLabs\MCU\CP210x\Windows_XP_S2K3_Vista_7_2) (HKLM-x32\...\{F15381C6-3109-4C2A-B186-730B0A04821E}) (Version: 6.5 - Silicon Laboratories, Inc.) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Spotnet (HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\Spotnet) (Version: 2.0.0.265 - Spotnet) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated) Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD) (Version: 10.0.50903 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.8 - VideoLAN) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinZip 22.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2411B}) (Version: 22.5.13114 - Corel Corporation) Wise Care 365 4.55 (HKLM-x32\...\Wise Care 365_is1) (Version: 4.55 - WiseCleaner.com, Inc.) Wise Program Uninstaller 1.93 (HKLM-x32\...\Wise Program Uninstaller_is1) (Version: 1.93 - WiseCleaner.com, Inc.) Ziggo Safe Online (HKLM-x32\...\{5B2DB883-3BBC-4BC7-8CB4-93DA19DE75B2}) (Version: 3.04.148.0 - F-Secure Corporation) Hidden Ziggo Safe Online (HKLM-x32\...\F-Secure ServiceEnabler 45123) (Version: 3.04.148.0 - F-Secure Corporation) ==================== Aangepaste CLSID (gefilterd): ========================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) CustomCLSID: HKU\S-1-5-21-1326076328-647220812-2880691162-1002_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll () ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Geen bestand ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Geen bestand ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2018-04-24] (WinZip Computing) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2018-04-24] (WinZip Computing) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-08-06] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2018-04-24] (WinZip Computing) ==================== Geplande Taken (gefilterd) ============= (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {02A7FBBA-8CF6-4A1A-9089-6C60A40987C7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-05-02] (HP Inc.) Task: {0C22FD3B-47BF-4045-8702-7224A2DD5D4C} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2018-04-24] (Corel Corporation) Task: {16E116CC-2876-4EEB-8C4F-C035E6BEC078} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.) Task: {1AFA2385-F371-4A8D-A8C0-FBCB225AB834} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.) Task: {2947B8F0-B682-4121-9D36-E09F8688F8CF} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation) Task: {3D889287-B5C1-4407-9E95-A8EDD3431212} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [2015-10-29] (CyberLink Corp.) Task: {4A941B77-FD52-4E74-A0F2-7EF0100C2360} - \Microsoft\Windows\UNP\RunCampaignManager -> Geen bestand <==== AANDACHT Task: {604EF41C-7E10-4946-9176-ADE04B46C44A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-08] (Dropbox, Inc.) Task: {63BEB2DE-85C3-4310-A934-DC8D2CED7630} - System32\Tasks\HPCeeScheduleForhcoor => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] () Task: {6D190007-0B2F-4AB2-9BB7-1FB1B4E79619} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2018-04-24] (Corel Corporation) Task: {8B5226FD-936A-4089-B52A-CB437A6D5DB1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-27] (Google Inc.) Task: {9101496F-14BD-40C0-9022-EF330A2CF88F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-06-24] (Piriform Ltd) Task: {96E88501-009D-43AA-9BF8-C9FB08AA45DF} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-08] (Dropbox, Inc.) Task: {A5422105-561E-41C6-A124-DAE7E17EBD7D} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-21] () Task: {A7481E86-D9E1-4700-82A3-E9291C967446} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-07-08] (AVAST Software) Task: {B37A60CB-B916-429A-A70C-B8073AE8F5FD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-05-02] (HP Inc.) Task: {B97DB79F-8931-4933-A4A9-2F87829DB404} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-27] (Google Inc.) Task: {C88962AD-C19E-4E10-A1DF-4DFBC9B6931E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-05-11] (HP Inc.) Task: {CC1F93D9-F53E-4327-8E0E-B219E864AC88} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) Task: {CE02A2E4-590F-444B-B039-3C82C1A65254} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.) Task: {E4495FC8-8A80-420B-A074-3C8CB53D3C17} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2018-04-24] (Corel Corporation) Task: {EB37AB52-7849-46E0-9509-88AB41A9D9FC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) Task: {F8E372ED-E506-4B7D-9018-F6B6F99121C7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation) Task: {FCD34F4C-9B29-4D8E-827C-65D0EEE7E14E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-06-24] (Piriform Ltd) Task: {FE83044C-968C-4866-AAD3-E6509E78D887} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-09-21] () (Als een item is opgenomen in de fixlist, wordt de taak (job) bestand verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForhcoor.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Snelkoppelingen & WMI ======================== (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.com.lnk -> C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe () -> hxxp://www.booking.com/index.html?aid=398438&label=square ==================== Geladen Modules (gefilterd) ============== 2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2015-08-06 22:39 - 2015-08-06 22:39 - 000127488 _____ () c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2016-06-27 18:20 - 2017-01-17 04:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2018-06-26 14:28 - 2018-06-26 14:28 - 000418784 _____ () C:\Program Files (x86)\Safe Online\apps\Ultralight\ulcore\1530012511\daas2_x64.dll 2016-03-22 03:48 - 2014-04-14 19:59 - 000389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2018-06-26 14:28 - 2018-06-26 14:28 - 000319968 _____ () C:\Program Files (x86)\Safe Online\apps\Ultralight\ulcore\1530012511\senddump_fshoster_plugin64.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2015-08-06 22:39 - 2015-08-06 22:39 - 000138752 _____ () c:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe 2018-06-14 09:12 - 2018-06-08 10:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-05-22 19:12 - 2018-05-22 19:13 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-05-22 19:12 - 2018-05-22 19:13 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-05-22 19:12 - 2018-05-22 19:13 - 022374400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-05-22 19:12 - 2018-05-22 19:13 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\skypert.dll 2018-05-22 19:12 - 2018-05-22 19:13 - 000654848 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-06-26 22:17 - 2018-06-26 22:18 - 027126784 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe 2018-06-26 22:17 - 2018-06-26 22:18 - 000306176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\SharedUI.dll 2018-06-26 22:17 - 2018-06-26 22:18 - 006735872 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\EntCommon.dll 2018-02-09 13:29 - 2018-02-09 13:30 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-06-26 22:17 - 2018-06-26 22:18 - 009360384 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\EntPlat.dll 2017-11-28 12:22 - 2017-11-28 12:22 - 000210912 _____ () C:\Program Files (x86)\Safe Online\zlib_32.dll 2017-11-28 12:22 - 2017-11-28 12:22 - 000254944 _____ () C:\Program Files (x86)\Safe Online\daas2.dll 2014-03-31 21:35 - 2014-03-31 21:35 - 000278208 _____ () C:\Program Files (x86)\Windows Live\Writer\nl\WindowsLive.Writer.Localization.resources.dll ==================== Alternate Data Streams (gefilterd) ========= (Als een item is opgenomen in de fixlist, wordt alleen de ADS verwijderd.) AlternateDataStreams: C:\Users\hcoor\Cookies:gs5sys [5632] AlternateDataStreams: C:\Users\hcoor\Desktop\desktop.ini:gs5sys [5888] AlternateDataStreams: C:\Users\hcoor\AppData\Local\Geschiedenis:gs5sys [8192] AlternateDataStreams: C:\Users\hcoor\Documents\desktop.ini:gs5sys [7168] ==================== Veilige Modus (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. De waarde van "AlternateShell" wordt hersteld.) ==================== Bestandskoppeling (gefilterd) =============== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd.) ==================== Internet Explorer vertrouwde/beperkte toegang =============== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd.) ==================== Hosts inhoud: =============================== (Indien nodig kan Hosts:-opdracht worden opgenomen in de fixlist om Hosts te resetten.) 2015-10-30 09:24 - 2015-10-30 09:21 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere gebieden ============================ (Momenteel is er geen automatische fix voor dit onderdeel.) HKU\S-1-5-21-1326076328-647220812-2880691162-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\hcoor\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 89.101.251.229 - 89.101.251.228 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is ingeschakeld. ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items == HKLM\...\StartupApproved\Run32: => "StartCCC" HKLM\...\StartupApproved\Run32: => "FUFAXRCV" HKLM\...\StartupApproved\Run32: => "FUFAXSTM" HKLM\...\StartupApproved\Run32: => "EEventManager" HKLM\...\StartupApproved\Run32: => "KiesTrayAgent" HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\StartupApproved\StartupFolder: => "Verzenden naar OneNote.lnk" HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\StartupApproved\Run: => "KiesPreload" HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-1326076328-647220812-2880691162-1002\...\StartupApproved\Run: => "Steam" ==================== Firewall regels (gefilterd) =============== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) FirewallRules: [{82D4A72E-98F9-4290-B3F5-C647D8BF0FE5}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{55B179FE-CA75-424F-B480-2A21170AF4A8}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{0D1F8D02-32CD-4F63-AD4E-5C8167468644}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{EF39D3FF-1D9C-41E8-90E4-FB4A3B4523DA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{F30E6306-3DB3-419D-BC9A-627CA9ECB41A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{95FBC148-E2BB-4890-92F4-696A35FB87B4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{BFED827E-C7FB-4518-93C6-4F170F3E93BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia\Game.exe FirewallRules: [{97D83219-AD6C-4F05-9817-23AFF9AC3008}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia\Game.exe FirewallRules: [{73A24E34-9D80-4CA6-A615-A66346A549FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia 2\Syberia2.exe FirewallRules: [{7E69F3A4-77C4-48D1-AB33-A37B44DA262C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia 2\Syberia2.exe FirewallRules: [{2820519D-22F3-487B-83EF-8FC676852A9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia 2\Game.exe FirewallRules: [{99FF4619-8688-4D74-84AB-1FF69EC0DA88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia 2\Game.exe FirewallRules: [{2996928B-FE95-4DDD-9760-451D00529E4F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia3\Syberia3.exe FirewallRules: [{B4D74D20-B386-4CBA-9F1A-1ABCF692BEA9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Syberia3\Syberia3.exe FirewallRules: [{76C8E47D-215F-44BC-A21C-3430A55BDE84}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{8A72B9E0-4BEF-4FEB-9084-3F8856059239}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{1D222AE8-A774-477A-8A87-E88B379F389A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{4AEE81FD-CDCD-4F61-B057-71377CC30409}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{77489760-A655-4E26-BDA7-31B4BCF82DF5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe FirewallRules: [{B63357C3-207E-4C19-B5D1-3668E372EDC7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe FirewallRules: [UDP Query User{C6EDFD8D-0263-4451-851A-71B666539CA8}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{49F7ED96-4363-4C84-9CF2-1AEFC067B3AB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{83A5869D-F29B-41B3-B1F0-58CDF346E3C2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe FirewallRules: [{E476FD56-A87F-4A18-80AD-7115B747A471}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{2777F5CC-23F1-41B5-8675-7E1BCD5519D7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{B4BE8E0C-1DF4-452E-B461-65FBFEB4BC82}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{308CE289-A137-4695-AC0F-01C4DF446430}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0DCB23C2-A1E5-4B04-B4D5-1FBE348CEB6F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{AF883DE5-B507-44C8-85BE-ED0F4E18CC59}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{093FC67F-90B9-4C72-B7E9-1584527A5F97}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{A7EAC0EF-2608-4E28-9216-2788E2181B3D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{ABCCC057-CD28-476F-BEEA-8CDEC12DC333}] => (Allow) LPort=2869 FirewallRules: [{B62AE0D2-2CFF-4B74-9DDB-259EC9A506C1}] => (Allow) LPort=1900 FirewallRules: [{A08EE841-7607-49C7-8D2E-54FC5D03B55D}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{CC9717B1-0FDF-4EA1-8EE2-FE1067DA0F6A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{3A0C7F56-B28E-485F-ABBC-F085CC535FD0}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [TCP Query User{F5EDA20D-5351-4BC6-ABD4-5BFB852CE9EB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{8ACBE24E-4E0C-4B57-954D-212D0672F40B}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{B7DBC6E5-C831-49C2-81B9-E478EB25F501}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{D2F8B0C2-89CA-4220-BF64-303563D88298}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{2257315F-8DBA-401D-8CCE-85857C55BFAE}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{A05A5E2C-F8CD-4E3A-ABD0-AD9C1639A553}C:\users\hcoor\appdata\local\popcorn-time\popcorn-time.exe] => (Block) C:\users\hcoor\appdata\local\popcorn-time\popcorn-time.exe FirewallRules: [UDP Query User{878A1D89-38D4-4556-96B9-591F8AF6763E}C:\users\hcoor\appdata\local\popcorn-time\popcorn-time.exe] => (Block) C:\users\hcoor\appdata\local\popcorn-time\popcorn-time.exe FirewallRules: [{1A660BA8-5CFA-4A7E-911C-478F7A569F31}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{78090268-A5C7-4A86-84BB-6B50D1FCE5D7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{DA870D3C-434D-46DE-ACF4-C43A09C2C53A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{B9ABF730-E4BC-45A4-A61F-8BD8CD568DC4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{6409FB8D-C4F0-4D5D-980E-E5E0C61ED70F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{E99EA642-4B12-4686-8B5C-F9B6E868B250}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{1F43BDE4-DE72-4BD7-A902-9537D47DD0E0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{02D47780-ABD6-4807-BE0D-029971F27F85}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{0533D6CD-FCF6-488B-AB2E-6805173CD0A4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{6E40398D-F1E2-49D4-8A37-1F7DDF374558}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{5946373B-65B2-4FD1-BFB1-693A6C7E8D2C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [{634518F7-479E-485A-A380-570FF7AF4B87}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [{29789C4B-E423-4A60-AB53-66FDAE490E50}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe FirewallRules: [{C9237978-E1E4-44B1-9378-25498F09F15F}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe ==================== Herstelpunten ========================= 23-06-2018 19:07:26 Installed Epson Software Updater 04-07-2018 09:50:48 Gepland controlepunt ==================== Defecte Apparaatbeheer Apparaten ============= ==================== Eventlog fouten: ========================= Applicatiefouten: ================== Error: (07/08/2018 01:44:49 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: De openprocedure voor de WmiApRpl-service in DLL-bestand C:\WINDOWS\system32\wbem\wmiaprpl.dll is mislukt. Prestatiemetergegevens voor deze service zijn niet beschikbaar. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de foutcode. Error: (07/08/2018 01:44:49 PM) (Source: PerfNet) (EventID: 2004) (User: ) Description: Kan het prestatieobject voor dee Server-service niet openen. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de statuscode. Error: (07/08/2018 01:44:49 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: De openprocedure voor de MSDTC-service in DLL-bestand C:\WINDOWS\system32\msdtcuiu.DLL is mislukt. Prestatiemetergegevens voor deze service zijn niet beschikbaar. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de foutcode. Error: (07/08/2018 01:44:48 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: De openprocedure voor de Lsa-service in DLL-bestand C:\Windows\System32\Secur32.dll is mislukt. Prestatiemetergegevens voor deze service zijn niet beschikbaar. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de foutcode. Error: (07/08/2018 01:44:48 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: De openprocedure voor de ESENT-service in DLL-bestand C:\WINDOWS\system32\esentprf.dll is mislukt. Prestatiemetergegevens voor deze service zijn niet beschikbaar. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de foutcode. Error: (07/08/2018 01:44:48 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: De openprocedure voor de BITS-service in DLL-bestand C:\Windows\System32\bitsperf.dll is mislukt. Prestatiemetergegevens voor deze service zijn niet beschikbaar. De eerste vier bytes (DWORD) in de sectie Gegevens bevatten de foutcode. Error: (07/08/2018 01:20:52 PM) (Source: ESENT) (EventID: 455) (User: ) Description: SettingSyncHost (8528,R,98) {E66CADE9-7748-4C2B-8A50-634A5422A2A6}: Fout -1811 (0xfffff8ed) is opgetreden tijdens het openen van logboekbestand C:\Users\hcoor\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb0000C.log. Error: (07/08/2018 01:07:25 PM) (Source: ESENT) (EventID: 455) (User: ) Description: SettingSyncHost (8528,R,98) {DC5E6310-4348-4AF0-A3CB-05649A86BCEC}: Fout -1811 (0xfffff8ed) is opgetreden tijdens het openen van logboekbestand C:\Users\hcoor\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb0001F.log. Systeemfouten: ============= Error: (07/08/2018 07:30:35 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (07/08/2018 07:27:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Starten niet verleend aan Lokaal voor de COM-servertoepassing met CLSID Windows.SecurityCenter.WscBrokerManager en APPID Niet beschikbaar aan de gebruiker NT AUTHORITY\SYSTEM SID (S-1-5-18) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (07/08/2018 07:25:11 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-SFJV4A2O) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker LAPTOP-SFJV4A2O\hcoor SID (S-1-5-21-1326076328-647220812-2880691162-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0 SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (07/08/2018 07:24:51 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: De Delivery Optimization-service is bij het starten vastgelopen. Error: (07/08/2018 07:20:24 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: De vorige afsluiting van het systeem om 18:52:52 op ‎8-‎7-‎2018 is onverwacht gebeurd. Error: (07/08/2018 06:57:45 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-SFJV4A2O) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker LAPTOP-SFJV4A2O\hcoor SID (S-1-5-21-1326076328-647220812-2880691162-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer SpotifyAB.SpotifyMusic_1.84.344.0_x86__zpdnekdrzrea0 SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (07/08/2018 06:57:14 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: De Delivery Optimization-service is bij het starten vastgelopen. Error: (07/08/2018 06:52:52 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: De vorige afsluiting van het systeem om 13:56:10 op ‎8-‎7-‎2018 is onverwacht gebeurd. CodeIntegrity: =================================== Date: 2018-06-13 09:14:11.887 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.9328.1700.0_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Safe Online\apps\Ultralight\ulcore\1527600882\fshook64.dll that did not meet the Store signing level requirements. ==================== Geheugen info =========================== Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics Percentage geheugen in gebruik: 31% Totaal fysiek RAM-geheugen: 7633.01 MB Beschikbaar fysiek RAM-geheugen: 5202.55 MB Totaal Virtueel geheugen: 8849.01 MB Beschikbaar Virtueel geheugen: 6247.45 MB ==================== Schijven ================================ Drive c: (Windows) (Fixed) (Total:916.76 GB) (Free:673.18 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.63 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)] \\?\Volume{4cee7b05-45cb-4c96-9c08-492c38d32081}\ () (Fixed) (Total:0.93 GB) (Free:0.43 GB) NTFS \\?\Volume{d7464a7e-45c5-45a4-acf8-a3bd024a0ab8}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.19 GB) FAT32 ==================== MBR & Partitietabel ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 3C536B2A) Partition: GPT. ==================== Eind van Addition.txt ============================