Fix resultaat van Farbar Recovery Scan Tool (x64) Versie: 22-03-2020 Gestart door Joost (22-03-2020 13:14:42) Run:1 Gestart vanaf C:\Users\Joost\Desktop Geladen Profielen: Joost (Beschikbare Profielen: Joost & Administrator) Boot Modus: Normal ============================================== fixlist inhoud: ***************** CreateRestorePoint: CloseProcesses: Task: {10EC8EB0-4B26-43E2-B735-4FE017C605F1} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Geen bestand <==== AANDACHT Task: {24260575-8B27-44BF-A7A8-9C55E84F1C9B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Geen bestand <==== AANDACHT Task: {24BD14BE-DC30-4B9A-8649-68F3C54967BC} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Geen bestand <==== AANDACHT Task: {3B2014A4-3415-40A2-BCB5-1E14FB5C67FE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Geen bestand <==== AANDACHT Task: {45E3C4CB-16ED-4C12-8CEE-8D92E03A4108} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Geen bestand <==== AANDACHT Task: {5B7E069E-AFE2-40B1-9E2B-A5312B42EC79} - \Microsoft\Windows\UNP\RunCampaignManager -> Geen bestand <==== AANDACHT Task: {8D3C1988-CDB7-45DD-9DA3-565D16FFA374} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Geen bestand <==== AANDACHT Task: {8E058779-017A-4C43-8794-9E5472D0326C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Geen bestand <==== AANDACHT Task: {981FA3F8-CE60-4139-BF89-12F4A93F005B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Geen bestand <==== AANDACHT Task: {AE437D53-A58E-4375-A54C-4548E6413311} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Geen bestand <==== AANDACHT Task: {CBE2D20D-0142-4B15-9387-1E00D2E10979} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Geen bestand <==== AANDACHT Task: {E57AC28B-FB84-4A80-A284-02F6C7327AE8} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Geen bestand <==== AANDACHT Task: {F5CA01F7-EBE2-40AA-8692-DD6F791748D6} - \WPD\SqmUpload_S-1-5-21-1085769570-3512807385-3274156511-1001 -> Geen bestand <==== AANDACHT Task: {F89A32E7-F145-4BFE-94B2-51E412DB437E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Geen bestand <==== AANDACHT Toolbar: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001 -> Geen Naam - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Geen bestand FF Plugin HKU\S-1-5-21-1085769570-3512807385-3274156511-1001: @easyxplor.com/easyxplore Update;version=3 -> C:\Users\Joost\AppData\Local\easyxplore\Update\1.3.99.0\npeasyxploreUpdate3.dll [Geen bestand] "SegurazoIC" => service is ontgrendeld. <==== AANDACHT R2 SegurazoIC; C:\Program Files (x86)\Segurazo\SegurazoIC.exe [4559568 2019-12-11] (Digital Communications Inc -> Digital Communications Inc) <==== AANDACHT R2 SegurazoSvc; C:\Program Files (x86)\Segurazo\SegurazoService.exe [184016 2020-03-13] (Digital Communications Inc -> Digital Communications Inc) <==== AANDACHT R1 SEGURAZOKD; C:\Program Files (x86)\Segurazo\SegurazoKD.sys [84472 2019-12-11] (Digital Communications Inc. -> Digital Communications Inc) <==== AANDACHT VirusTotal: C:\WINDOWS\System32\DRIVERS\Trufos.sys CustomCLSID: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Joost\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => Geen bestand CustomCLSID: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{20AC803E-49D4-43E9-90D8-787AFD8E85B0}\InprocServer32 -> C:\Users\Joost\AppData\Local\easyxplore\Update\1.3.99.0\psuser_64.dll => Geen bestand CustomCLSID: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Joost\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => Geen bestand CustomCLSID: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Joost\AppData\Local\Microsoft\OneDrive\18.192.0920.0015\amd64\FileSyncShell64.dll => Geen bestand CustomCLSID: HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{8FA6DC22-9574-427B-914B-CD9ACE26E5CB}\InprocServer32 -> C:\Users\Joost\AppData\Local\easyxplore\Update\1.3.99.0\psuser_64.dll => Geen bestand ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Geen bestand ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Geen bestand ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Geen bestand ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Geen bestand FirewallRules: [{C864789F-32CC-4136-B98F-BF3FD27BC7CF}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe Geen bestand FirewallRules: [{BB24D8DD-FB8C-4A5B-BC9D-1F7469D43116}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe Geen bestand FirewallRules: [UDP Query User{75021989-7A9C-4A9D-8734-DDE9CE73FFE9}C:\users\joost\appdata\local\popcorn time ce\nw.exe] => (Allow) C:\users\joost\appdata\local\popcorn time ce\nw.exe Geen bestand FirewallRules: [TCP Query User{221B3519-62F4-49F5-B5A0-88896333F1F3}C:\users\joost\appdata\local\popcorn time ce\nw.exe] => (Allow) C:\users\joost\appdata\local\popcorn time ce\nw.exe Geen bestand FirewallRules: [{98893D7D-EA1B-47DC-8B30-BDEC4E143A9A}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe Geen bestand FirewallRules: [{1BCD90DD-91A1-4993-94E6-0E5D6A31F6E4}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe Geen bestand FirewallRules: [{D899256E-603B-4F8C-9E41-CAF792E6DC64}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe Geen bestand FirewallRules: [{82EDEB42-AA9F-4F65-A198-6F6E03192A8A}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe Geen bestand FirewallRules: [TCP Query User{E1646569-F534-44C1-8384-5FABE7D54FE0}C:\programdata\oracle\java\javapath_target_9221781\java.exe] => (Allow) C:\programdata\oracle\java\javapath_target_9221781\java.exe Geen bestand FirewallRules: [UDP Query User{5A6ED4DC-BAFC-47C8-8C33-39D62DD063FC}C:\programdata\oracle\java\javapath_target_9221781\java.exe] => (Allow) C:\programdata\oracle\java\javapath_target_9221781\java.exe Geen bestand FirewallRules: [TCP Query User{58DE39AB-7D1A-4971-B27E-223FA3E469E3}C:\programdata\oracle\java\javapath_target_9221781\java.exe] => (Block) C:\programdata\oracle\java\javapath_target_9221781\java.exe Geen bestand FirewallRules: [UDP Query User{1EC97CDE-159F-4632-BCB1-253A044FB1B3}C:\programdata\oracle\java\javapath_target_9221781\java.exe] => (Block) C:\programdata\oracle\java\javapath_target_9221781\java.exe Geen bestand FirewallRules: [{93C62A08-D4B8-46F1-B0CC-1A4D92B57BC7}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe Geen bestand FirewallRules: [{ABC69726-BC9C-4B83-B009-B2EDEE4DAE6D}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe Geen bestand VirusTotal: C:\Users\Joost\AppData\Roaming\anh_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt EmptyTemp: Reboot: ***************** Herstelpunt is succesvol gemaakt. Proces succesvol afgesloten. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{10EC8EB0-4B26-43E2-B735-4FE017C605F1}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{10EC8EB0-4B26-43E2-B735-4FE017C605F1}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{24260575-8B27-44BF-A7A8-9C55E84F1C9B}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24260575-8B27-44BF-A7A8-9C55E84F1C9B}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{24BD14BE-DC30-4B9A-8649-68F3C54967BC}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24BD14BE-DC30-4B9A-8649-68F3C54967BC}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B2014A4-3415-40A2-BCB5-1E14FB5C67FE}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B2014A4-3415-40A2-BCB5-1E14FB5C67FE}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{45E3C4CB-16ED-4C12-8CEE-8D92E03A4108}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45E3C4CB-16ED-4C12-8CEE-8D92E03A4108}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B7E069E-AFE2-40B1-9E2B-A5312B42EC79}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B7E069E-AFE2-40B1-9E2B-A5312B42EC79}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => niet gevonden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D3C1988-CDB7-45DD-9DA3-565D16FFA374}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D3C1988-CDB7-45DD-9DA3-565D16FFA374}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E058779-017A-4C43-8794-9E5472D0326C}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E058779-017A-4C43-8794-9E5472D0326C}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{981FA3F8-CE60-4139-BF89-12F4A93F005B}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{981FA3F8-CE60-4139-BF89-12F4A93F005B}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE437D53-A58E-4375-A54C-4548E6413311}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE437D53-A58E-4375-A54C-4548E6413311}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CBE2D20D-0142-4B15-9387-1E00D2E10979}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CBE2D20D-0142-4B15-9387-1E00D2E10979}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E57AC28B-FB84-4A80-A284-02F6C7327AE8}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E57AC28B-FB84-4A80-A284-02F6C7327AE8}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F5CA01F7-EBE2-40AA-8692-DD6F791748D6}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5CA01F7-EBE2-40AA-8692-DD6F791748D6}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-1085769570-3512807385-3274156511-1001" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F89A32E7-F145-4BFE-94B2-51E412DB437E}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F89A32E7-F145-4BFE-94B2-51E412DB437E}" => is succesvol verwijderd "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => is succesvol verwijderd "HKU\S-1-5-21-1085769570-3512807385-3274156511-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F}" => is succesvol verwijderd HKU\S-1-5-21-1085769570-3512807385-3274156511-1001\Software\MozillaPlugins\@easyxplor.com/easyxplore Update;version=3 => is succesvol verwijderd "C:\Users\Joost\AppData\Local\easyxplore\Update\1.3.99.0\npeasyxploreUpdate3.dll" => niet gevonden "SegurazoIC" => service is ontgrendeld. <==== AANDACHT => Fout: Geen automatische fix gevonden voor dit item. SegurazoIC => service niet gevonden. SegurazoSvc => service niet gevonden. SEGURAZOKD => service niet gevonden. "VirusTotal: C:\WINDOWS\System32\DRIVERS\Trufos.sys" => niet gevonden HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => is succesvol verwijderd HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{20AC803E-49D4-43E9-90D8-787AFD8E85B0} => is succesvol verwijderd HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => is succesvol verwijderd HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => is succesvol verwijderd HKU\S-1-5-21-1085769570-3512807385-3274156511-1001_Classes\CLSID\{8FA6DC22-9574-427B-914B-CD9ACE26E5CB} => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => is succesvol verwijderd HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => is succesvol verwijderd HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C864789F-32CC-4136-B98F-BF3FD27BC7CF}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB24D8DD-FB8C-4A5B-BC9D-1F7469D43116}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{75021989-7A9C-4A9D-8734-DDE9CE73FFE9}C:\users\joost\appdata\local\popcorn time ce\nw.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{221B3519-62F4-49F5-B5A0-88896333F1F3}C:\users\joost\appdata\local\popcorn time ce\nw.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{98893D7D-EA1B-47DC-8B30-BDEC4E143A9A}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1BCD90DD-91A1-4993-94E6-0E5D6A31F6E4}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D899256E-603B-4F8C-9E41-CAF792E6DC64}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{82EDEB42-AA9F-4F65-A198-6F6E03192A8A}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E1646569-F534-44C1-8384-5FABE7D54FE0}C:\programdata\oracle\java\javapath_target_9221781\java.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5A6ED4DC-BAFC-47C8-8C33-39D62DD063FC}C:\programdata\oracle\java\javapath_target_9221781\java.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{58DE39AB-7D1A-4971-B27E-223FA3E469E3}C:\programdata\oracle\java\javapath_target_9221781\java.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1EC97CDE-159F-4632-BCB1-253A044FB1B3}C:\programdata\oracle\java\javapath_target_9221781\java.exe" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{93C62A08-D4B8-46F1-B0CC-1A4D92B57BC7}" => is succesvol verwijderd "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ABC69726-BC9C-4B83-B009-B2EDEE4DAE6D}" => is succesvol verwijderd VirusTotal: C:\Users\Joost\AppData\Roaming\anh_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt => https://www.virustotal.com/file/0805ad338a4c0f01e0d3c82de61e4a8679a8f90bb1eff8973fbb72869eeadd6a/analysis/1584879346/ =========== EmptyTemp: ========== BITS transfer queue => 10510336 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 26378225 B Java, Flash, Steam htmlcache => 506 B Windows/system/drivers => 523816866 B Edge => 302682 B Chrome => 54970154 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 6656 B Users => 6656 B ProgramData => 6656 B Public => 6656 B systemprofile => 6656 B systemprofile32 => 6656 B LocalService => 129020 B NetworkService => 129020 B Joost => 51294470 B Administrator => 51308171 B RecycleBin => 117431854 B EmptyTemp: => 797.6 MB tijdelijke gegevens verwijderd. ================================ Het systeem moest herstart worden. ==== Einde van Fixlog 13:17:28 ====