edge, M$Store, M$Account problemen-opgelost-

Spyware is software die in het geheim op je computer wordt geplaatst en die persoonlijke gegevens doorstuurt, reclame toont, enz. Stel hier vragen, leer hoe je ervan af kan komen en hoe het te voorkomen.

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 14:40

Edge kan niet meer op het internet, andere browsers werken normaal en email ook.
Lokaal account werkt nog maar als in terug wil naar mijn Microsoft account geeft dit de nietszeggende fout (Er is iets mis gegaan).

Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 10.02.2018 02
Gestart door papa (Beheerder) op PCI5LIVING (11-02-2018 14:21:13)
Gestart vanaf D:\papa.PCI5LIVING\UpdatePCsoft\PC-beveiliging\FarbarRecoveryScanTool
Geladen Profielen: papa (Beschikbare Profielen: Sem & Lucy & papa)
Platform: Windows 10 Pro Versie 1709 16299.214 (X64) Taal: Nederlands (Nederland)
Internet Explorer Versie 11 (Standaardbrowser: FF)
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processen (gefilterd) =================

(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\MKCHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(MEDION) C:\Program Files (x86)\Erazer\MEDION Gaming Mouse\hid.exe
(MEDION) C:\Program Files (x86)\Erazer\MEDION Gaming Mouse\trayicon.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe

==================== Register (gefilterd) ===========================

(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794888 2017-11-02] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-06-09] (CANON INC.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Erazer MEDION] => C:\Program Files (x86)\Erazer\MEDION Gaming Mouse\Hid.exe [1507840 2012-09-24] (MEDION)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restrictie <==== AANDACHT
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\Run: [Gadwin PrintScreen (64-bit)] => C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe [15216928 2017-09-20] (Gadwin Systems)
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\Run: [AdobeBridge] => [X]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 9.8 PE.lnk [2017-11-22]
ShortcutTarget: PHOTOfunSTUDIO 9.8 PE.lnk -> C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation)
GroupPolicy: Restrictie - Chrome <==== AANDACHT

==================== Internet (gefilterd) ====================

(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)

Hosts: Er zijn meer dan één item in Hosts. Zie Hosts deel van Addition.txt
Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.4
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0eb36bc0-29a6-48dd-ab35-19b38b7436a9}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{25039f1e-006a-40bb-8112-c9ce1d0ab23b}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{2bb4f2c9-5031-4819-aa05-3ce9902e6f8d}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{46d7a398-723c-4612-9086-708b0e682a8f}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{5b06403e-7826-4739-8987-21f587e805bf}: [DhcpNameServer] 195.130.131.4 195.130.130.4
Tcpip\..\Interfaces\{a472971b-8435-4511-aead-907167eb2c85}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{a67c1412-7e97-439c-88a3-3a4be7c83bc1}: [DhcpNameServer] 195.130.131.4 195.130.130.4
Tcpip\..\Interfaces\{f9f7aea8-1dd4-4e56-9cfa-8b16caf1a351}: [NameServer] 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP
SearchScopes: HKU\S-1-5-21-1127049525-478323742-3338971903-1008 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src ... 02&pc=UE04
SearchScopes: HKU\S-1-5-21-1127049525-478323742-3338971903-1008 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src ... 02&pc=UE04
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2018-01-20] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2018-01-20] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: ccg88g4z.default
FF ProfilePath: C:\Users\papa.PCI5LIVING\AppData\Roaming\Mozilla\Firefox\Profiles\ccg88g4z.default [2018-02-11]
FF Homepage: Mozilla\Firefox\Profiles\ccg88g4z.default -> hxxps://www.hln.be/
hxxps://www.seniorennet.be/forum/index.php?sid= ... 93cb814a84
hxxp://www.verkeerscentrum.be/verkeersinfo/kaa ... =antwerpen
hxxps://www.netweters.be/?category.id=TaalNL
FF Extension: (I don't care about cookies) - C:\Users\papa.PCI5LIVING\AppData\Roaming\Mozilla\Firefox\Profiles\ccg88g4z.default\Extensions\jid1-KKzOGWgsW3Ao4Q@jetpack.xpi [2017-12-29]
FF Extension: (uBlock Origin) - C:\Users\papa.PCI5LIVING\AppData\Roaming\Mozilla\Firefox\Profiles\ccg88g4z.default\Extensions\uBlock0@raymondhill.net.xpi [2018-02-04]
FF Extension: (Adblocker for Youtube™) - C:\Program Files\Mozilla Firefox\browser\features\{A5FD4672-4D73-4F90-A1C0-2ABD39DB2565}.xpi [2018-01-08] [ niet getekend]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-05] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2016-04-14] (CANON INC.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2017-11-03] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default [2018-02-11]
CHR Extension: (Presentaties) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-27]
CHR Extension: (Documenten) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-27]
CHR Extension: (Google Drive) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-12-27]
CHR Extension: (YouTube) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-27]
CHR Extension: (Adobe Acrobat) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-12-27]
CHR Extension: (Spreadsheets) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-27]
CHR Extension: (Offline Documenten) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-09]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-12-27]
CHR Extension: (Gmail) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-12-27]
CHR Extension: (Chrome Media Router) - C:\Users\papa.PCI5LIVING\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-27]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (gefilterd) ====================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

R2 CIJSRegister; C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe [144464 2015-02-19] (CANON INC.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7780528 2018-01-15] (Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [389696 2017-07-10] ()
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [186760 2017-11-03] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-11-26] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Bestand niet getekend]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-19] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-19] (Microsoft Corporation)

===================== Drivers (gefilterd) ======================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

R1 MpKsl0b0e6123; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{19A98155-F691-49A0-AF35-E8E227C0D854}\MpKsl0b0e6123.sys [58120 2018-02-11] (Microsoft Corporation)
R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-10-16] (Corel Corporation)
S3 qcusbnet; C:\WINDOWS\System32\drivers\qcusbnet.sys [428600 2017-03-15] (QUALCOMM Incorporated)
S3 qcusbser; C:\WINDOWS\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5707264 2017-09-29] (Realtek Semiconductor Corporation )
R3 SGIDGMS; C:\WINDOWS\system32\drivers\SGIDGMS.sys [25600 2012-09-19] ( )
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-01-19] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2018-01-19] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-19] (Microsoft Corporation)

==================== NetSvcs (gefilterd) ===================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


==================== Een Maand Aangemaakt bestanden en mappen ========

(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)

2018-02-11 10:47 - 2018-02-11 10:47 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-02-11 10:46 - 2018-02-11 10:46 - 097779712 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-02-11 10:43 - 2018-02-11 10:46 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2018-02-11 10:39 - 2018-02-11 10:39 - 000000551 _____ C:\Users\papa.PCI5LIVING\Desktop\JRT.txt
2018-02-11 10:18 - 2018-02-11 10:18 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-02-10 17:39 - 2018-02-10 17:39 - 000000262 __RSH C:\Users\Sem & Lucy\ntuser.pol
2018-02-10 17:39 - 2018-02-10 17:39 - 000000000 ____D C:\Users\Sem & Lucy\AppData\Roaming\Erazer
2018-02-09 23:01 - 2018-01-17 23:19 - 001206688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-02-09 23:01 - 2018-01-17 23:19 - 001055640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-02-09 23:01 - 2018-01-17 23:19 - 000599456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-02-09 23:01 - 2018-01-17 23:18 - 001193192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2018-02-09 23:01 - 2018-01-17 23:18 - 001092016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-02-09 23:01 - 2018-01-17 23:18 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-02-09 23:01 - 2018-01-17 23:18 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-02-09 23:01 - 2018-01-17 23:18 - 000319864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-02-09 23:01 - 2018-01-17 23:18 - 000279456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-02-09 23:01 - 2018-01-17 23:18 - 000077216 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-02-09 23:01 - 2018-01-17 23:15 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-02-09 23:01 - 2018-01-17 23:15 - 002406456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-02-09 23:01 - 2018-01-17 23:15 - 001954560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-02-09 23:01 - 2018-01-17 23:15 - 001415296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-02-09 23:01 - 2018-01-17 23:15 - 001209248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-02-09 23:01 - 2018-01-17 23:15 - 001002600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-02-09 23:01 - 2018-01-17 23:12 - 004537040 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2018-02-09 23:01 - 2018-01-17 23:12 - 001313024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2018-02-09 23:01 - 2018-01-17 23:12 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-02-09 23:01 - 2018-01-17 23:12 - 000711432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-02-09 23:01 - 2018-01-17 23:11 - 001044384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-02-09 23:01 - 2018-01-17 23:10 - 003904296 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-02-09 23:01 - 2018-01-17 23:10 - 003010248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-02-09 23:01 - 2018-01-17 23:10 - 002574232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-02-09 23:01 - 2018-01-17 23:10 - 001416392 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-02-09 23:01 - 2018-01-17 23:10 - 000749984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-02-09 23:01 - 2018-01-17 23:10 - 000408992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-02-09 23:01 - 2018-01-17 23:09 - 007675792 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-02-09 23:01 - 2018-01-17 23:09 - 002709200 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-02-09 23:01 - 2018-01-17 23:09 - 000712096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-02-09 23:01 - 2018-01-17 23:09 - 000436632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2018-02-09 23:01 - 2018-01-17 23:09 - 000246176 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-02-09 23:01 - 2018-01-17 23:09 - 000154528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2018-02-09 23:01 - 2018-01-17 23:09 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2018-02-09 23:01 - 2018-01-17 23:08 - 021351632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 004486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 002447768 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 000824896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 000677792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-02-09 23:01 - 2018-01-17 23:08 - 000614168 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-02-09 23:01 - 2018-01-17 23:08 - 000494496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-02-09 23:01 - 2018-01-17 23:08 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-02-09 23:01 - 2018-01-17 23:08 - 000189344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-02-09 23:01 - 2018-01-17 23:08 - 000100248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 007385080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 006791984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 004506584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 001430760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2018-02-09 23:01 - 2018-01-17 23:07 - 001426672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 001254152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000603928 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-02-09 23:01 - 2018-01-17 23:07 - 000404888 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000096200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-02-09 23:01 - 2018-01-17 23:07 - 000075168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-02-09 23:01 - 2018-01-17 23:06 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-02-09 23:01 - 2018-01-17 23:06 - 000339872 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2018-02-09 23:01 - 2018-01-17 23:06 - 000087392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-02-09 23:01 - 2018-01-17 23:04 - 001103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-02-09 23:01 - 2018-01-17 23:04 - 000628632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-02-09 23:01 - 2018-01-17 22:20 - 000022432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hvsicontainerservice.dll
2018-02-09 23:01 - 2018-01-17 22:19 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-02-09 23:01 - 2018-01-17 22:19 - 000542856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-02-09 23:01 - 2018-01-17 22:16 - 002255120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-02-09 23:01 - 2018-01-17 22:15 - 001145624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-02-09 23:01 - 2018-01-17 22:13 - 004382040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2018-02-09 23:01 - 2018-01-17 22:13 - 001250528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2018-02-09 23:01 - 2018-01-17 22:10 - 025250304 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-02-09 23:01 - 2018-01-17 22:10 - 006092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-02-09 23:01 - 2018-01-17 22:10 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-02-09 23:01 - 2018-01-17 22:10 - 002338784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-02-09 23:01 - 2018-01-17 22:10 - 002192112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-02-09 23:01 - 2018-01-17 22:10 - 001123464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-02-09 23:01 - 2018-01-17 22:10 - 000354200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2018-02-09 23:01 - 2018-01-17 22:09 - 003980720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-02-09 23:01 - 2018-01-17 22:09 - 000527864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2018-02-09 23:01 - 2018-01-17 22:09 - 000123800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2018-02-09 23:01 - 2018-01-17 22:09 - 000089504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2018-02-09 23:01 - 2018-01-17 22:08 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-02-09 23:01 - 2018-01-17 22:08 - 000543920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-02-09 23:01 - 2018-01-17 22:08 - 000083224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 006479560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 006014688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 004670728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 000982536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-02-09 23:01 - 2018-01-17 22:07 - 000662216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-02-09 23:01 - 2018-01-17 22:06 - 001149280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-02-09 23:01 - 2018-01-17 22:06 - 000386432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-02-09 23:01 - 2018-01-17 22:06 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-02-09 23:01 - 2018-01-17 22:06 - 000077552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2018-02-09 23:01 - 2018-01-17 22:06 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-02-09 23:01 - 2018-01-17 22:04 - 000505160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2018-02-09 23:01 - 2018-01-17 21:52 - 017160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-02-09 23:01 - 2018-01-17 21:52 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-02-09 23:01 - 2018-01-17 21:51 - 001664512 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-02-09 23:01 - 2018-01-17 21:51 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-02-09 23:01 - 2018-01-17 21:51 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-02-09 23:01 - 2018-01-17 21:51 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-02-09 23:01 - 2018-01-17 21:50 - 002890240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2018-02-09 23:01 - 2018-01-17 21:49 - 023657984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-02-09 23:01 - 2018-01-17 21:49 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-02-09 23:01 - 2018-01-17 21:49 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-02-09 23:01 - 2018-01-17 21:49 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 013703680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-02-09 23:01 - 2018-01-17 21:48 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCShellCommonProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:47 - 008020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-02-09 23:01 - 2018-01-17 21:47 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2018-02-09 23:01 - 2018-01-17 21:47 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2018-02-09 23:01 - 2018-01-17 21:47 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-02-09 23:01 - 2018-01-17 21:47 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 018921984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe
2018-02-09 23:01 - 2018-01-17 21:46 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2018-02-09 23:01 - 2018-01-17 21:46 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 012831744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 003756032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 001216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 001015296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-02-09 23:01 - 2018-01-17 21:45 - 000859648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2018-02-09 23:01 - 2018-01-17 21:45 - 000580608 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000566272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreCommonProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000311808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2018-02-09 23:01 - 2018-01-17 21:45 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 004113408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 003367936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-02-09 23:01 - 2018-01-17 21:44 - 002873344 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 001425408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 001113600 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2018-02-09 23:01 - 2018-01-17 21:44 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContent.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2018-02-09 23:01 - 2018-01-17 21:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2018-02-09 23:01 - 2018-01-17 21:44 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2018-02-09 23:01 - 2018-01-17 21:43 - 006466560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 003169280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 002976256 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 001495552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 001234432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrSvc.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 001002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000930816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000377856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-02-09 23:01 - 2018-01-17 21:43 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2018-02-09 23:01 - 2018-01-17 21:43 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2018-02-09 23:01 - 2018-01-17 21:42 - 019338240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 006722560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2018-02-09 23:01 - 2018-01-17 21:42 - 005500928 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 003578368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 003405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 002209280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 001167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 000621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2018-02-09 23:01 - 2018-01-17 21:42 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-02-09 23:01 - 2018-01-17 21:42 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 004815360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 002857984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 002741248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 002490880 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-02-09 23:01 - 2018-01-17 21:41 - 001669120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-02-09 23:01 - 2018-01-17 21:41 - 000939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000885248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000863744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000648704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\system32\srchadmin.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2018-02-09 23:01 - 2018-01-17 21:41 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCShellCommonProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 004772352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 002523648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 002035712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 001759744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe
2018-02-09 23:01 - 2018-01-17 21:40 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 006567936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 002677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2018-02-09 23:01 - 2018-01-17 21:39 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000943104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000940544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000886784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2018-02-09 23:01 - 2018-01-17 21:38 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2018-02-09 23:01 - 2018-01-17 21:38 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVXENCD.DLL
2018-02-09 23:01 - 2018-01-17 21:38 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2018-02-09 23:01 - 2018-01-17 21:38 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSENCD.DLL
2018-02-09 23:01 - 2018-01-17 21:38 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreCommonProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2018-02-09 23:01 - 2018-01-17 21:38 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.ProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 011925504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 002983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 001936384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2018-02-09 23:01 - 2018-01-17 21:37 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 001557504 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2018-02-09 23:01 - 2018-01-17 21:37 - 000653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcbase.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysdm.cpl
2018-02-09 23:01 - 2018-01-17 21:37 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2018-02-09 23:01 - 2018-01-17 21:37 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 002184192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 001342464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 000482816 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2018-02-09 23:01 - 2018-01-17 21:36 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2018-02-09 23:01 - 2018-01-17 21:36 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2018-02-09 23:01 - 2018-01-17 21:36 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2018-02-09 23:01 - 2018-01-17 21:35 - 004384768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 004249600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 003287040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 002464768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 002462208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 002413568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000826880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-02-09 23:01 - 2018-01-17 21:35 - 000796160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2018-02-09 23:01 - 2018-01-17 21:35 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 006532096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2018-02-09 23:01 - 2018-01-17 21:34 - 005388800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 002814976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2018-02-09 23:01 - 2018-01-17 21:34 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srchadmin.dll
2018-02-09 23:01 - 2018-01-17 21:33 - 001509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2018-02-09 23:01 - 2018-01-17 21:33 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-02-09 23:01 - 2018-01-17 21:33 - 000620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-02-09 23:01 - 2018-01-17 21:33 - 000604672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-02-09 23:01 - 2018-01-17 21:32 - 002427904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2018-02-09 23:01 - 2018-01-17 21:32 - 001488896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2018-02-09 23:01 - 2018-01-17 21:32 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVXENCD.DLL
2018-02-09 23:01 - 2018-01-17 21:32 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSENCD.DLL
2018-02-09 23:01 - 2018-01-17 21:32 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.ProxyStub.dll
2018-02-09 23:01 - 2018-01-17 21:31 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
2018-02-09 23:01 - 2018-01-17 21:31 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcbase.dll
2018-02-09 23:01 - 2018-01-17 19:47 - 000804240 _____ C:\WINDOWS\SysWOW64\locale.nls
2018-02-09 23:01 - 2018-01-17 19:47 - 000804240 _____ C:\WINDOWS\system32\locale.nls
2018-02-09 23:01 - 2018-01-11 01:52 - 000471968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-02-09 23:01 - 2018-01-11 01:51 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-02-09 21:36 - 2018-02-09 21:36 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2018-02-09 21:36 - 2018-02-09 21:36 - 000002207 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2018-01-25 20:54 - 2018-02-09 21:29 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\LocalLow\Google
2018-01-25 18:39 - 2018-01-25 18:39 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Local\IsolatedStorage
2018-01-20 16:18 - 2018-02-09 21:32 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2018-01-18 22:38 - 2018-01-18 22:42 - 000313560 _____ (Mozilla) C:\Users\papa.PCI5LIVING\Downloads\Firefox Installer.exe

==================== Een Maand Gewijzigd bestanden en mappen ========

(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)

2018-02-11 14:21 - 2017-11-27 10:43 - 000000000 ____D C:\FRST
2018-02-11 14:08 - 2017-11-02 18:16 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-02-11 11:05 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-02-11 11:00 - 2017-11-02 18:24 - 008476468 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-02-11 11:00 - 2017-09-30 15:30 - 004185728 _____ C:\WINDOWS\system32\perfh013.dat
2018-02-11 11:00 - 2017-09-30 15:30 - 001201876 _____ C:\WINDOWS\system32\perfc013.dat
2018-02-11 10:47 - 2017-11-02 18:21 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-02-11 10:42 - 2017-09-29 09:45 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2018-02-11 10:37 - 2017-11-03 14:27 - 000000000 ____D C:\AdwCleaner
2018-02-11 10:26 - 2017-12-27 14:28 - 000000000 ____D C:\Windat
2018-02-11 10:19 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-02-11 10:18 - 2017-11-28 23:30 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\LocalLow\Mozilla
2018-02-11 10:18 - 2017-11-03 14:22 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-02-11 10:18 - 2017-11-03 14:22 - 000002858 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-02-11 09:29 - 2017-12-13 19:11 - 000004186 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{07C47D70-9F0C-42C1-A256-635DD0C7651A}
2018-02-11 00:35 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-02-11 00:28 - 2017-12-27 14:41 - 000000262 __RSH C:\Users\papa.PCI5LIVING\ntuser.pol
2018-02-11 00:28 - 2017-11-28 20:34 - 000000000 ____D C:\Users\papa.PCI5LIVING
2018-02-10 22:25 - 2017-11-28 20:34 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Roaming\Adobe
2018-02-10 21:18 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-02-10 17:44 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-10 17:39 - 2017-11-11 16:56 - 000000000 ___RD C:\Users\Sem & Lucy\3D Objects
2018-02-10 17:39 - 2017-11-11 16:56 - 000000000 ____D C:\Users\Sem & Lucy
2018-02-10 17:39 - 2015-09-10 06:36 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-02-10 17:36 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\registration
2018-02-10 08:50 - 2017-11-28 20:34 - 000000000 ___RD C:\Users\papa.PCI5LIVING\3D Objects
2018-02-10 08:50 - 2017-11-02 18:16 - 004967992 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-02-09 23:51 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-02-09 23:51 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-02-09 23:51 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-02-09 23:51 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-02-09 23:51 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-02-09 23:02 - 2017-09-29 14:41 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-02-09 22:50 - 2017-11-09 11:21 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-02-09 22:50 - 2017-11-09 11:21 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-09 22:36 - 2017-12-27 18:15 - 000001304 _____ C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox.lnk
2018-02-09 22:36 - 2017-11-09 11:21 - 000001005 ____H C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-09 22:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-02-09 22:09 - 2017-11-28 20:34 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Local\Packages
2018-02-09 21:37 - 2017-11-28 20:34 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Local\ConnectedDevicesPlatform
2018-02-09 21:36 - 2017-11-18 22:40 - 000000000 ____D C:\Program Files\Google
2018-02-09 21:36 - 2017-11-03 14:22 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-09 21:32 - 2017-11-12 17:24 - 000000000 ___HD C:\ProgramData\CanonIJScan
2018-02-09 21:32 - 2017-11-03 14:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-02-09 21:32 - 2017-11-03 14:22 - 000000000 ____D C:\Program Files\CCleaner
2018-02-09 21:32 - 2017-11-02 17:54 - 000000000 ____D C:\WINDOWS\containers
2018-02-09 21:32 - 2017-09-30 15:32 - 000000000 ___SD C:\WINDOWS\system32\AppV
2018-02-09 21:32 - 2017-09-30 15:32 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 __RHD C:\Users\Public\Libraries
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ___RD C:\Program Files\Windows Defender
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\setup
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\icsxml
2018-02-09 21:32 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-02-09 21:32 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2018-02-09 21:32 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-02-09 21:32 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\servicing
2018-02-09 21:29 - 2017-12-13 14:09 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Roaming\Erazer
2018-02-09 21:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Web
2018-02-09 21:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Vss
2018-02-09 21:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SystemResources
2018-02-09 21:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-02-09 21:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\appcompat
2018-02-09 21:28 - 2017-11-17 20:51 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-02-09 21:28 - 2017-11-13 22:27 - 000000000 ____D C:\Program Files\Microsoft Office
2018-02-09 21:28 - 2017-11-02 20:35 - 000000000 ____D C:\Program Files (x86)\Belgium Identity Card
2018-02-09 21:28 - 2017-09-29 14:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-02-09 13:18 - 2017-11-11 16:56 - 000000000 ____D C:\Users\Sem & Lucy\AppData\Local\Packages
2018-02-09 13:17 - 2017-11-28 19:56 - 000000000 ____D C:\Users\Sem & Lucy\AppData\Roaming\Canon
2018-02-08 21:54 - 2017-11-28 23:18 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Local\ElevatedDiagnostics
2018-02-08 20:23 - 2017-11-02 19:58 - 000000000 ____D C:\ProgramData\CanonIJPLM
2018-02-08 20:22 - 2017-11-28 20:34 - 000000000 ____D C:\Users\papa.PCI5LIVING\AppData\Roaming\Canon
2018-02-06 03:49 - 2017-12-13 14:17 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-02-06 03:49 - 2017-12-13 14:17 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-05 13:51 - 2017-09-29 14:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-01-24 09:22 - 2017-11-02 15:46 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

==================== Bestanden in de root van sommige mappen =======

2017-12-27 14:27 - 2017-12-27 14:27 - 000140800 _____ () C:\Users\papa.PCI5LIVING\AppData\Local\installer.dat
2017-11-29 22:05 - 2017-11-29 22:05 - 00000
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 14:42

Hier ook Addition.txt

Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 10.02.2018 02
Gestart door papa (11-02-2018 14:21:50)
Gestart vanaf D:\papa.PCI5LIVING\UpdatePCsoft\PC-beveiliging\FarbarRecoveryScanTool
Windows 10 Pro Versie 1709 16299.214 (X64) (2017-11-02 17:22:52)
Boot Modus: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1127049525-478323742-3338971903-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1127049525-478323742-3338971903-503 - Limited - Disabled)
Gast (S-1-5-21-1127049525-478323742-3338971903-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1127049525-478323742-3338971903-1012 - Limited - Enabled)
papa (S-1-5-21-1127049525-478323742-3338971903-1008 - Administrator - Enabled) => C:\Users\papa.PCI5LIVING
Sem & Lucy (S-1-5-21-1127049525-478323742-3338971903-1004 - Administrator - Enabled) => C:\Users\Sem & Lucy
WDAGUtilityAccount (S-1-5-21-1127049525-478323742-3338971903-504 - Limited - Disabled)

==================== Security Center ========================

(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Geïnstalleerde programma's ======================

(Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)

Adobe Acrobat Reader DC - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Belgium e-ID middleware 4.3.2 (build 3551) (HKLM\...\{DB942AEA-93D6-4FE4-8862-180D35A73551}) (Version: 4.3.3551 - Belgian Government)
Belgium e-ID viewer 4.2.11 (build 3344) (HKLM-x32\...\{F3DC7F06-92FF-4C98-87F5-72C0B7863344}) (Version: 4.2.3344 - Belgian Government)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.7.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.20.13 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 5.4.0 - Canon Inc.)
Canon MG5700 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5700_series) (Version: 1.00 - Canon Inc.)
Canon MG5700 series On-screen Manual (HKLM-x32\...\Canon MG5700 series On-screen Manual) (Version: 7.8.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.7.1 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.39 - Piriform)
Erazer MEDION Gamingmuis stuurprogramma V1.0 (HKLM-x32\...\{9F5E2400-A6E8-4B88-B997-06787EC38186}_is1) (Version: 1.00.00.05 - )
G Suite Migration For Microsoft Outlook® 4.0.117.0 (HKLM\...\{A192D75D-8490-405F-82C5-A29906B8DA95}) (Version: 4.0.117.0 - Google, Inc.)
G Suite Sync™ for Microsoft Outlook® 4.0.9.0 (HKLM\...\{CC79BF63-893F-47B8-9754-9353FC415156}) (Version: 4.0.9.0 - Google, Inc.)
Gadwin PrintScreen (64-Bit) (HKLM\...\{9D41A5E9-499A-4B98-8F05-CAB1C879E046}) (Version: 5.8.5.0 - Gadwin Systems)
Gebruikersregistratie voor Canon MG5700 series (HKLM-x32\...\Gebruikersregistratie voor Canon MG5700 series) (Version:  - ‭Canon Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Earth Pro (HKLM\...\{D9EF644E-2FAE-493B-8180-5617CC774C4F}) (Version: 7.3.1.4507 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
KB4023057 (HKLM\...\{B977A833-7734-41A5-B820-1F23D81DC87B}) (Version: 2.6.0.0 - Microsoft Corporation)
Kernel OST Viewer ver 15.0 (HKLM-x32\...\Kernel OST Viewer_is1) (Version:  - Lepide Software Pvt.Ltd.)
Kernel Outlook PST Viewer ver 11.05.01 (HKLM-x32\...\Kernel Outlook PST Viewer_is1) (Version:  - Lepide Software Pvt. Ltd.)
K-Lite Codec Pack 13.6.5 Basic (HKLM-x32\...\KLiteCodecPack_is1) (Version: 13.6.5 - KLCP)
Main Services (HKLM-x32\...\{2E0435A8-9506-4368-BB80-6C05A38DE8FD}) (Version: 1.1.20 - System Native) Hidden <==== AANDACHT
Malwarebytes versie 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
MediaInfo 17.10 (HKLM\...\MediaInfo) (Version: 17.10 - MediaArea.net)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 3.2.116.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - nl-nl (HKLM\...\ProPlusRetail - nl-nl) (Version: 16.0.8827.2148 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (HKLM-x32\...\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}) (Version: 14.11.25325.0 - Microsoft Corporation)
Mozilla Firefox 59.0 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0 (x64 en-US)) (Version: 59.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0 - Mozilla)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0413-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Photodex Presenter (HKLM-x32\...\Photodex Presenter) (Version:  - Photodex Corporation)
PHOTOfunSTUDIO 9.8 PE (HKLM-x32\...\{E2893B75-5EB3-4ED2-AA60-3727A1177EC6}) (Version: 9.08.706.1033 - Panasonic Corporation)
ProfiCAD 8.0.3 (HKLM-x32\...\ProfiCAD_is1) (Version:  - )
ProShow Producer (HKLM-x32\...\ProShow Producer) (Version:  - Photodex Corporation)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.0.0.790 - Samsung Electronics)
Speccy (HKLM\...\Speccy) (Version: 1.31 - Piriform)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
UpdateAssistant (HKLM-x32\...\{DE45508F-369E-4476-8F19-088F4933340E}) (Version: 1.8.0.0 - Microsoft Corporation) Hidden
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Xirrus Wi-Fi Inspector (HKLM-x32\...\{8CED67B5-AB51-4D12-AAA5-395303922641}) (Version: 1.0.0 - Xirrus)

==================== Aangepaste CLSID (gefilterd): ==========================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal)

==================== Geplande Taken (gefilterd) =============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

Task: {3D965ED9-C8E6-4E2C-BBEA-E51982650D10} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2017-10-11] (Microsoft Corporation)
Task: {4B7C26AF-CAEF-40ED-991F-6FF283F3C840} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {4C13F8B2-D1B3-415D-862A-81A35708F656} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {4DBA596C-7147-4FA0-9868-9231A826CD83} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2017-10-11] (Microsoft Corporation)
Task: {7C768F10-C4DB-4E2F-9C29-11D5DE673B14} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {8EE27747-21A8-4839-9E32-3D7F4B4EADDB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
Task: {8FBA7BC8-4279-40B4-8F99-4F1B9D5E2B39} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-01-20] (Microsoft Corporation)
Task: {95DF9ECD-85C1-44DB-8725-7A81497CBBDB} - System32\Tasks\S-1-5-21-1127049525-478323742-3338971903-1008\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-09-29] (Microsoft Corporation)
Task: {96889C61-EFF6-447D-8CA6-0B138B4918DE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-03] (Google Inc.)
Task: {A83BEB72-8B0E-4975-897D-40003E013BEA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
Task: {AEFD5913-CB4F-42BF-A8E8-D5121BFF8127} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2017-10-11] (Microsoft)
Task: {B23CA729-3DA3-46BF-86D7-E892CFB072D8} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-20] (Microsoft Corporation)
Task: {BC361E9B-B913-4BEC-9FF2-1EF7A4D0190C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-03] (Google Inc.)
Task: {BDC6AA4E-F5B4-4A75-9754-3AE4786E1A0C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
Task: {BDF7128A-BB6A-4FC8-818F-7F14FDF4E8F3} - System32\Tasks\S-1-5-21-1127049525-478323742-3338971903-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-09-29] (Microsoft Corporation)
Task: {BE71F7C1-C212-4CB3-8E7A-BC55CF157E06} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {D056EF83-CACF-4C79-B9F9-07D949289C39} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {E494A40D-4920-4188-AEF4-23243CFBF9F5} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2017-10-11] (Microsoft Corporation)
Task: {E974EA37-5093-4B51-97A6-0738F948B1DC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-01-20] (Microsoft Corporation)
Task: {EB104754-7001-4F83-8B7B-F64F320278DA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-20] (Microsoft Corporation)
Task: {EB94FA07-8A1C-4A58-8FF2-2C2006EF2542} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
Task: {ED43E06C-6410-4930-9623-7F7A4A4A58BD} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2017-10-11] (Microsoft Corporation)
Task: {F189806A-8734-4933-92D5-116CEE0C097F} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [2017-02-22] (Samsung Electronics Co. Ltd.)
Task: {F333E36E-4B3A-44F0-9573-C44819D5CA33} - System32\Tasks\Microsoft_MKC_Logon_Task_ceip.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ceip.exe [2017-10-11] (Microsoft)
Task: {F8FC0A69-C86C-41F1-9081-1B28AE9841B8} - System32\Tasks\Mp4 Viewer => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Mp4 Viewer\Mp4 Viewer.dll",hcHzYh <==== AANDACHT

(Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)

Task: C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job => C:\Program Files (x86)\aohGTEheqdnWC\ScuYSTo.dll

==================== Snelkoppelingen & WMI ========================

(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Сhromе.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.emorhc.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Exрlorеr.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.erolpxei.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Мozillа Firefох.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.xoferif.bat (Geen bestand) <==== Cyrillic

==================== Geladen Modules (gefilterd) ==============

2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-11-02 16:28 - 2016-11-14 12:15 - 000135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-11-02 19:58 - 2017-07-10 12:12 - 000389696 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2017-11-03 16:21 - 2017-11-03 16:21 - 000186760 _____ () C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe
2018-02-09 23:01 - 2018-01-17 21:46 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2018-02-09 23:01 - 2018-01-17 21:40 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-30 08:35 - 2018-01-30 08:35 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-30 08:35 - 2018-01-30 08:35 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-30 08:35 - 2018-01-30 08:35 - 025135104 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-30 08:35 - 2018-01-30 08:35 - 002542592 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\skypert.dll
2018-01-30 08:35 - 2018-01-30 08:35 - 000667136 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll

==================== Alternate Data Streams (gefilterd) =========

(Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)


==================== Veilige Modus (gefilterd) ===================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Bestandskoppeling (gefilterd) ===============

(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)


==================== Internet Explorer vertrouwde/beperkte toegang ===============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)


==================== Hosts inhoud: ==========================

(Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)

2015-07-30 23:42 - 2017-12-27 15:00 - 000013622 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 wemsofts.com
127.0.0.1 bongadoom.com
127.0.0.1 wepcmainsystem.com
127.0.0.1 internalcampaigntargets.com
127.0.0.1 bongadoom.com
127.0.0.1 getthefilenow.com
127.0.0.1 bigpicturepop.com
127.0.0.1 wizzcaster.com
127.0.0.1 bestoffersfortoday.com
127.0.0.1 wepcmainsystem.com
127.0.0.1 agent.wizztrakys.com
127.0.0.1 csdimonetize.com
127.0.0.1 dl.azalee.site
127.0.0.1 titiaredh.com
127.0.0.1 wepcdisplaysystem.com
127.0.0.1 wepcanalyticsystem.com
127.0.0.1 healthydownload.com
127.0.0.1 leading2download.com
127.0.0.1 dwl0.wizzlabs.com
127.0.0.1 dwl1.wizzlabs.com
127.0.0.1 mess1.wizzmonetize.com
127.0.0.1 dl.azalee.site
127.0.0.1 dl.smashdl.com
127.0.0.1 downloadmyhost.com
127.0.0.1 lapapahoster.com
127.0.0.1 asedownloadgate.com
127.0.0.1 agent.wizztrakys.com
127.0.0.1 ladomainadeserver.com
127.0.0.1 www.wizzmonetize.com
127.0.0.1    gf.tools.avast.com

Er zijn 361 meer regels.


==================== Andere gebieden ============================

(Momenteel is er geen automatische fix voor dit onderdeel.)

HKU\S-1-5-21-1127049525-478323742-3338971903-1008\Control Panel\Desktop\\Wallpaper -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 195.130.131.4 - 195.130.130.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is ingeschakeld.

==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==

HKLM\...\StartupApproved\StartupFolder: => "PHOTOfunSTUDIO 9.8 PE.lnk"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "AdobeCS5ServiceManager"
HKLM\...\StartupApproved\Run32: => "SwitchBoard"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "AdobeBridge"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "Gadwin PrintScreen (64-bit)"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "mp84pgjGrixF.exe"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "496190"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "YUTGLUIABZ.exe"

==================== Firewall regels (gefilterd) ===============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

FirewallRules: [TCP Query User{D9730A98-05F4-4296-9CA7-BC61B9CC0645}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{CA8CA1AA-4702-48CF-8281-9B519D4514B2}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe

==================== Herstelpunten =========================

09-02-2018 23:22:07 Gepland controlepunt
11-02-2018 10:38:11 JRT Pre-Junkware Removal

==================== Defecte Apparaatbeheer Apparaten =============


==================== Eventlog fouten: =========================

Applicatiefouten:
==================
Error: (02/09/2018 09:35:26 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (3424,R,0) SRUJet: Fout -1811 (0xfffff8ed) is opgetreden tijdens het openen van logboekbestand C:\WINDOWS\system32\SRU\SRU02218.log.

Error: (02/09/2018 09:08:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: SettingSyncHost.exe, versie: 10.0.16299.15, tijdstempel: 0x28b3e5d1
Naam van module met fout: SettingSyncHost.exe, versie: 10.0.16299.15, tijdstempel: 0x28b3e5d1
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00000000000104ed
Id van proces met fout: 0x1f54
Starttijd van toepassing met fout: 0x01d3a1d17d002f24
Pad naar toepassing met fout: C:\WINDOWS\system32\SettingSyncHost.exe
Pad naar module met fout: C:\WINDOWS\system32\SettingSyncHost.exe
Rapport-id: 28d81eae-aaca-4a54-9d51-b34d16cd88ec
Volledige pakketnaam met fout:
Relatieve toepassings-id van pakket met fout:

Error: (02/09/2018 07:05:09 PM) (Source: Outlook) (EventID: 35) (User: )
Description: Kan niet vaststellen of het archief zich in het verkenningsbereik bevindt (fout=0x8007045b).

Error: (02/09/2018 07:05:09 PM) (Source: Outlook) (EventID: 34) (User: )
Description: Kan het bereik van verkennerbeheer niet ophalen. Fout: 0x8007045b.

Error: (02/09/2018 07:05:08 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: De Windows Search-service wordt gestopt vanwege een probleem met de indexeerfunctie, The catalog is corrupt.

Details:
    De catalogus met de inhoudsindex is beschadigd.   0xc0041801 (0xc0041801)

Error: (02/09/2018 07:05:06 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: De zoekservice heeft beschadigde gegevensbestanden ontdekt in de index {id=4810 - onecoreuap\base\appmodel\search\search\ytrip\tripoli\inverted\decodinglayer.cpp (478)}. De service probeert dit probleem automatisch te verhelpen door de index opnieuw samen te stellen.

Details:
    De gegevens zijn ongeldig.   0x8007000d (0x8007000d)

Error: (02/09/2018 06:11:02 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Gepland controlepunt). Aanvullende gegevens: 0x80070005.

Error: (02/09/2018 05:36:28 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Installatieprogramma voor Windows-modules). Aanvullende gegevens: 0x80070005.

Error: (02/09/2018 01:16:48 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Gepland controlepunt). Aanvullende gegevens: 0x80070005.

Error: (02/09/2018 01:07:06 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Gepland controlepunt). Aanvullende gegevens: 0x80070005.


Systeemfouten:
=============
Error: (02/11/2018 11:27:04 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 11:25:04 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 11:21:07 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 11:00:22 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 10:57:33 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 10:55:33 AM) (Source: DCOM) (EventID: 10010) (User: PCI5LIVING)
Description: De server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.

Error: (02/11/2018 10:47:10 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crashdumpinitialisatie is mislukt!

Error: (02/11/2018 10:38:29 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De NVIDIA Display Driver Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.

Error: (02/11/2018 10:26:35 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crashdumpinitialisatie is mislukt!

Error: (02/11/2018 09:25:36 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crashdumpinitialisatie is mislukt!


==================== Geheugen info ===========================

Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
Percentage geheugen in gebruik: 30%
Totaal fysiek RAM-geheugen: 8183.11 MB
Beschikbaar fysiek RAM-geheugen: 5663.7 MB
Totaal Virtueel geheugen: 12183.11 MB
Beschikbaar Virtual geheugen: 9779.66 MB

==================== Schijven ================================

Drive c: () (Fixed) (Total:464.44 GB) (Free:389.56 GB) NTFS
Drive d: (Disk-Intern) (Fixed) (Total:931.41 GB) (Free:428.43 GB) NTFS
Drive x: (BackUp-eSATA) (Fixed) (Total:1863.01 GB) (Free:309.64 GB) NTFS

\\?\Volume{4ef6fcd0-0000-0000-0000-100000000000}\ (Door systeem gereserveerd) (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS
\\?\Volume{4ef6fcd0-0000-0000-0000-d03b74000000}\ () (Fixed) (Total:0.83 GB) (Free:0.46 GB) NTFS

==================== MBR & Partitietabel ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4EF6FCD0)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=464.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=845 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: EC37DD14)
Partition 1: (Not Active) - (Size=101 MB) - (Type=42)
Partition 2: (Active) - (Size=931.4 GB) - (Type=42)
Partition 3: (Not Active) - (Size=1752 KB) - (Type=42)

========================================================
Disk: 2 (Size: 1863 GB) (Disk ID: BE5EBD26)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== Eind van Addition.txt ============================
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

11 feb 2018, 15:29

Hallo,

Ik mis van het logje FRST.txt het laatste stuk.
Zou je vanaf het volgende:
==================== Bestanden in de root van sommige mappen =======

Wat hieronder staat willen plaatsen.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 15:36

==================== Bestanden in de root van sommige mappen =======

2017-12-27 14:27 - 2017-12-27 14:27 - 000140800 _____ () C:\Users\papa.PCI5LIVING\AppData\Local\installer.dat
2017-11-29 22:05 - 2017-11-29 22:05 - 000000017 _____ () C:\Users\papa.PCI5LIVING\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)

C:\WINDOWS\system32\winlogon.exe => Bestand is getekend
C:\WINDOWS\system32\wininit.exe => Bestand is getekend
C:\WINDOWS\explorer.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend
C:\WINDOWS\system32\svchost.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend
C:\WINDOWS\system32\services.exe => Bestand is getekend
C:\WINDOWS\system32\User32.dll => Bestand is getekend
C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend
C:\WINDOWS\system32\userinit.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend
C:\WINDOWS\system32\rpcss.dll => Bestand is getekend
C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend
C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend
C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend

LastRegBack: 2018-02-01 17:27

==================== Eind van FRST.txt ============================
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

11 feb 2018, 15:48

Hallo,

De tool FRST.exe staat in de dik gedrukte map:
vanaf D:\papa.PCI5LIVING\UpdatePCsoft\PC-beveiliging\FarbarRecoveryScanTool <== Sleep de FRST.exe vanuit deze map naar je bureaublad.


Lees eerst de handleiding en voer daarna de fix uit Handleiding Fix

Note: Dit script is speciaal bedoeld voor deze computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.

Klik Windows knop plus R tegelijk in. Afbeelding
"Uitvoeren" opent vul daar Notepad in en klik daarna op "OK", Kladblok opent.
Kopieer onderstaande code en plak dat in "Kladblok"

Code: Selecteer alles

start
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restrictie <==== AANDACHT
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\Run: [AdobeBridge] => [X] 
GroupPolicy: Restrictie - Chrome <==== AANDACHT 
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0eb36bc0-29a6-48dd-ab35-19b38b7436a9}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{25039f1e-006a-40bb-8112-c9ce1d0ab23b}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{2bb4f2c9-5031-4819-aa05-3ce9902e6f8d}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{46d7a398-723c-4612-9086-708b0e682a8f}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{a472971b-8435-4511-aead-907167eb2c85}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{f9f7aea8-1dd4-4e56-9cfa-8b16caf1a351}: [NameServer] 8.8.8.8 
C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job 
C:\Program Files (x86)\aohGTEheqdnWC
Task: C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job => C:\Program Files (x86)\aohGTEheqdnWC\ScuYSTo.dll 
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Сhromе.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.emorhc.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Exрlorеr.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.erolpxei.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Мozillа Firefох.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.xoferif.bat (Geen bestand) <==== Cyrillic 
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "mp84pgjGrixF.exe"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "496190"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "YUTGLUIABZ.exe" 
EmptyTemp:
Reboot:
end

Ga naar Bestand - Opslaan als.
Kies als locatie bureaublad.
Bij "Bestandsnaam" zet je:fixlist.txt
Bij "Opslaan als type" selecteer je: Alle bestanden.

Als het goed is staat er nu een text bestand op je bureaublad?

Start de Farbar Recovery Scan Tool.
Als het programma is geopend klik Yes (Ja) bij de disclaimer. (indien nodig)
Druk op de Fix knop.
Er zal u een logbestand aangemaakt worden (fixlog.txt) op dezelfde plaats vanwaar de 'tool' is gestart.
Kopieer en plak de inhoud van de logbestanden in je het volgende bericht.(als de inhoud te groot is voor één bericht plaats het in meerdere berichten)
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 16:16

Fix resultaat van Farbar Recovery Scan Tool (x64) Versie: 10.02.2018 02
Gestart door papa (11-02-2018 16:12:25) Run:2
Gestart vanaf C:\Users\papa.PCI5LIVING\Desktop
Geladen Profielen: papa (Beschikbare Profielen: Sem & Lucy & papa)
Boot Modus: Normal
==============================================

fixlist inhoud:
*****************
start
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restrictie <==== AANDACHT
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\Run: [AdobeBridge] => [X]
GroupPolicy: Restrictie - Chrome <==== AANDACHT
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0eb36bc0-29a6-48dd-ab35-19b38b7436a9}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{25039f1e-006a-40bb-8112-c9ce1d0ab23b}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{2bb4f2c9-5031-4819-aa05-3ce9902e6f8d}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{46d7a398-723c-4612-9086-708b0e682a8f}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{a472971b-8435-4511-aead-907167eb2c85}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{f9f7aea8-1dd4-4e56-9cfa-8b16caf1a351}: [NameServer] 8.8.8.8
C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job
C:\Program Files (x86)\aohGTEheqdnWC
Task: C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job => C:\Program Files (x86)\aohGTEheqdnWC\ScuYSTo.dll
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G?ogle ?hrom?.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.emorhc.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Int?rn?t Ex?lor?r.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.erolpxei.bat (Geen bestand) <==== Cyrillic
Shortcut: C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\?ozill? Firef??.lnk -> C:\Users\papa.PCI5LIVING\AppData\Roaming\Browsers\exe.xoferif.bat (Geen bestand) <==== Cyrillic
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "mp84pgjGrixF.exe"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "496190"
HKU\S-1-5-21-1127049525-478323742-3338971903-1008\...\StartupApproved\Run: => "YUTGLUIABZ.exe"
EmptyTemp:
Reboot:
end
*****************

Herstelpunt is succesvol gemaakt.
"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => is succesvol verwijderd
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => is succesvol verwijderd
C:\WINDOWS\system32\GroupPolicy\Machine => is succesvol verplaatst
C:\WINDOWS\system32\GroupPolicy\GPT.ini => is succesvol verplaatst
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0eb36bc0-29a6-48dd-ab35-19b38b7436a9}\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25039f1e-006a-40bb-8112-c9ce1d0ab23b}\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2bb4f2c9-5031-4819-aa05-3ce9902e6f8d}\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46d7a398-723c-4612-9086-708b0e682a8f}\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a472971b-8435-4511-aead-907167eb2c85}\\NameServer" => is succesvol verwijderd
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f9f7aea8-1dd4-4e56-9cfa-8b16caf1a351}\\NameServer" => is succesvol verwijderd
C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job => is succesvol verplaatst
"C:\Program Files (x86)\aohGTEheqdnWC" => niet gevonden
"C:\WINDOWS\Tasks\plaAVjRQXWCDePSecyr.job" => niet gevonden
"C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G?ogle ?hrom?.lnk" => Kon niet verplaatsen.
"C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Int?rn?t Ex?lor?r.lnk" => Kon niet verplaatsen.
"C:\Users\papa.PCI5LIVING\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\?ozill? Firef??.lnk" => Kon niet verplaatsen.
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\mp84pgjGrixF.exe" => is succesvol verwijderd
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\mp84pgjGrixF.exe" => niet gevonden
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\496190" => is succesvol verwijderd
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\496190" => niet gevonden
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\YUTGLUIABZ.exe" => is succesvol verwijderd
"HKU\S-1-5-21-1127049525-478323742-3338971903-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\YUTGLUIABZ.exe" => niet gevonden

=========== EmptyTemp: ==========

BITS transfer queue => 12869632 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 67123408 B
Java, Flash, Steam htmlcache => 1097 B
Windows/system/drivers => 1208020 B
Edge => 25600 B
Chrome => 149219 B
Firefox => 45817278 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 31972 B
jcarn => 0 B
Sem & Lucy => 60906 B
papa.PCI5LIVING => 12187251 B

RecycleBin => 0 B
EmptyTemp: => 133 MB tijdelijke gegevens verwijderd.

================================


Het systeem moest herstart worden.

==== Eind van Fixlog 16:12:54 ====
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

11 feb 2018, 16:26

Hallo,

Doe eens een volledige scan met Mbam.
Open Mbam klik links op "Scannen"
Kies Aangepaste scan, vink daar alle opties aan.
Vink daarna alle beschikbare schijven aan en klik op "Scan nu".
Handleiding: https://www.seniorennet.be/forum/viewtopic.php?t=195914
Neem er de tijd voor.



Na het scannen:
Als er bedreigingen zijn gevonden:
  • Klik op "Selectie in quarantaine plaatsen" en daarna op "Voltooien".
  • Er kan gevraagd worden om de computer opnieuw op te starten. Doe dat dan en start daarna opnieuw MBAM.
Start Malwarebytes klik op "Rapporten".
Klik op het recenste "Scanrapport > Rapport bekijken".
Klik op Exporteer en kies Tekstbestand (*.txt).
Afbeelding
Vul een bestandsnaam in en bewaar het op je bureaublad zodat je het makkelijk terugvindt.
Post het logbestand in je volgend bericht.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 16:41

Mbam scan loop op desktop.
Is er ook geen probleem met de hosts file?
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

11 feb 2018, 18:03

janneke dust2 schreef:Mbam scan loop op desktop.
Is er ook geen probleem met de hosts file?
Ja, maar als het goed is heeft FRST het gerepareerd (maar dat kijken we na Mbam na).
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 22:29

Malwarebytes
www.malwarebytes.com

-Logboekdetails-
Scandatum: 11-02-18
Scantijd: 16:39
Logbestand: b2c201e0-0f41-11e8-8489-4061862b78a7.json
Beheerder: Ja

-Software-informatie-
Versie: 3.3.1.2183
Versie componenten: 1.0.262
Update pakketversie: 1.0.3918
Licentie: Gratis

-Systeeminformatie-
Besturingssysteem: Windows 10 (Build 16299.214)
Processor: x64
Bestandssysteem: NTFS
Gebruiker: PCI5LIVING\papa

-Scansamenvatting-
Scantype: Aangepaste scan
Resultaat: Voltooid
Objecten gescand: 661560
Dreigingen herkend: 27
Dreigingen in quarantaine: 27
Verstreken tijd: 5 u., 30 min, 48 sec

-Scanopties-
Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Ingeschakeld
Heuristiek: Ingeschakeld
POP: Detectie
POA: Detectie

-Scandetails-
Proces: 0
(Geen kwaadaardige items gedetecteerd)

Module: 0
(Geen kwaadaardige items gedetecteerd)

Registersleutel: 0
(Geen kwaadaardige items gedetecteerd)

Registerwaarde: 0
(Geen kwaadaardige items gedetecteerd)

Registerdata: 0
(Geen kwaadaardige items gedetecteerd)

Gegevensstroom: 0
(Geen kwaadaardige items gedetecteerd)

Map: 0
(Geen kwaadaardige items gedetecteerd)

Bestand: 27
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\3SOLBPH71Y\MEPQFZTKYZ.EXE, In quarantaine, [174], [476775],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\RQF69AZBLA\QFNJIMIXVEBTE.DLL, In quarantaine, [258], [476772],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\X3CF3EDNHM\PWNUAZO.DLL, In quarantaine, [258], [476771],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\3SOLBPH71Y\REIMAGEPACKAGE.EXE, In quarantaine, [1097], [331559],1.0.3918
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\FRAQBC8WSA\MLEBKQZXGQ.EXE, In quarantaine, [174], [476632],1.0.3918
PUP.Optional.BitCoinMiner, C:\ADWCLEANER\QUARANTINE\RYWTIIZS2T\GPLYRA-UNINST.EXE, In quarantaine, [162], [363441],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\1XVPFVJCRG\REIMAGEREPAIR.EXE, In quarantaine, [1097], [331559],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\FRAQBC8WSA\REIMAGE PROTECTOR\REIGUARD.EXE, In quarantaine, [1097], [327181],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\RYWTIIZS2T\FJMXET.DLL, In quarantaine, [258], [476770],1.0.3918
HackTool.FilePatch, C:\PROGRAM FILES (X86)\PHOTODEX\PROSHOW PRODUCER\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.Babylon, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
RiskWare.Tool.CK, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
Generic.Malware/Suspicious, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\SAMSUNGTVDISK LEZEN\PVRDECODER\SAMYGOPVRDECODER.EXE, In quarantaine, [0], [392686],1.0.3918
PUP.Optional.Babylon, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
RiskWare.Tool.CK, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918
HackTool.FilePatch, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
Generic.Malware/Suspicious, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\SAMSUNGTVDISK LEZEN\PVRDECODER\SAMYGOPVRDECODER.EXE, In quarantaine, [0], [392686],1.0.3918
RiskWare.Tool.CK, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
PUP.Optional.Babylon, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
HackTool.FilePatch, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918

Fysieke sector: 0
(Geen kwaadaardige items gedetecteerd)


(end)
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

11 feb 2018, 22:33

Zonder auto terugloop.


Malwarebytes
www.malwarebytes.com

-Logboekdetails-
Scandatum: 11-02-18
Scantijd: 16:39
Logbestand: b2c201e0-0f41-11e8-8489-4061862b78a7.json
Beheerder: Ja

-Software-informatie-
Versie: 3.3.1.2183
Versie componenten: 1.0.262
Update pakketversie: 1.0.3918
Licentie: Gratis

-Systeeminformatie-
Besturingssysteem: Windows 10 (Build 16299.214)
Processor: x64
Bestandssysteem: NTFS
Gebruiker: PCI5LIVING\papa

-Scansamenvatting-
Scantype: Aangepaste scan
Resultaat: Voltooid
Objecten gescand: 661560
Dreigingen herkend: 27
Dreigingen in quarantaine: 27
Verstreken tijd: 5 u., 30 min, 48 sec

-Scanopties-
Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Ingeschakeld
Heuristiek: Ingeschakeld
POP: Detectie
POA: Detectie

-Scandetails-
Proces: 0
(Geen kwaadaardige items gedetecteerd)

Module: 0
(Geen kwaadaardige items gedetecteerd)

Registersleutel: 0
(Geen kwaadaardige items gedetecteerd)

Registerwaarde: 0
(Geen kwaadaardige items gedetecteerd)

Registerdata: 0
(Geen kwaadaardige items gedetecteerd)

Gegevensstroom: 0
(Geen kwaadaardige items gedetecteerd)

Map: 0
(Geen kwaadaardige items gedetecteerd)

Bestand: 27
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\3SOLBPH71Y\MEPQFZTKYZ.EXE, In quarantaine, [174], [476775],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\RQF69AZBLA\QFNJIMIXVEBTE.DLL, In quarantaine, [258], [476772],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\X3CF3EDNHM\PWNUAZO.DLL, In quarantaine, [258], [476771],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\3SOLBPH71Y\REIMAGEPACKAGE.EXE, In quarantaine, [1097], [331559],1.0.3918
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\FRAQBC8WSA\MLEBKQZXGQ.EXE, In quarantaine, [174], [476632],1.0.3918
PUP.Optional.BitCoinMiner, C:\ADWCLEANER\QUARANTINE\RYWTIIZS2T\GPLYRA-UNINST.EXE, In quarantaine, [162], [363441],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\1XVPFVJCRG\REIMAGEREPAIR.EXE, In quarantaine, [1097], [331559],1.0.3918
PUP.Optional.Reimage, C:\ADWCLEANER\QUARANTINE\FRAQBC8WSA\REIMAGE PROTECTOR\REIGUARD.EXE, In quarantaine, [1097], [327181],1.0.3918
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\RYWTIIZS2T\FJMXET.DLL, In quarantaine, [258], [476770],1.0.3918
HackTool.FilePatch, C:\PROGRAM FILES (X86)\PHOTODEX\PROSHOW PRODUCER\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.Babylon, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
RiskWare.Tool.CK, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, X:\PCMETSSD\BACKUP-COPY-20171128\JCARN-DISK-H\JCARN\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
Generic.Malware/Suspicious, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\SAMSUNGTVDISK LEZEN\PVRDECODER\SAMYGOPVRDECODER.EXE, In quarantaine, [0], [392686],1.0.3918
PUP.Optional.Babylon, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
RiskWare.Tool.CK, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
HackTool.FilePatch, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, X:\PCMETSSD\COPY-PAPAPCILIVINGVANDISKD\PAPA.PCI5LIVING\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918
HackTool.FilePatch, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V6\PPSP.6.0.3410.FULL\PATCH\PROSHOW.PRODUCER.-.GOLD.6.0.3410-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
Generic.Malware/Suspicious, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\SAMSUNGTVDISK LEZEN\PVRDECODER\SAMYGOPVRDECODER.EXE, In quarantaine, [0], [392686],1.0.3918
RiskWare.Tool.CK, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\ADOBE\PREMIERE ELEMENTS V8\PREMIERE-DVD\CORE\KEYGEN.EXE, In quarantaine, [234], [55248],1.0.3918
PUP.Optional.Babylon, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PC-TOOLS\UNLOCKER\UNLOCKER1.9.2.EXE, In quarantaine, [1678], [76260],1.0.3918
HackTool.FilePatch, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\PROSHOWPRODUCER V7\PHOTODEX.PROSHOW.PRODUCER.7.0.3527\PATCH\PROSHOW.PRODUCER.70.3527-PATCH.EXE, In quarantaine, [6979], [281135],1.0.3918
PUP.Optional.AdBundle, D:\PAPA.PCI5LIVING\UPDATEPCSOFT\TV-HDOPNAMENBEWERKEN\MP4FILMSPLITTER\ULTRA VIDEO SPLITTER SETUP.EXE, In quarantaine, [791], [43582],1.0.3918

Fysieke sector: 0
(Geen kwaadaardige items gedetecteerd)


(end)
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

12 feb 2018, 12:10

Hallo,

Ik zie dat je toch ook met illegale software aan de gang bent, je heb een aantal lelijke infecties.
Als we klaar zijn is het aangeraden om al je wachtwoorden te vernieuwen.
We lopen je Hosts nog even na.

Stap 1.
Note: Dit script is speciaal bedoeld voor deze computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.

Klik Windows knop plus R tegelijk in. Afbeelding
"Uitvoeren" opent vul daar Notepad in en klik daarna op "OK", Kladblok opent.
Kopieer onderstaande code en plak dat in "Kladblok"

Code: Selecteer alles

start
CreateRestorePoint:
Hosts:
Reboot:
end

Ga naar Bestand - Opslaan als.
Kies als locatie bureaublad.
Bij "Bestandsnaam" zet je:fixlist.txt
Bij "Opslaan als type" selecteer je: Alle bestanden.

Als het goed is staat er nu een text bestand op je bureaublad?

Start de Farbar Recovery Scan Tool.
Als het programma is geopend klik Yes (Ja) bij de disclaimer. (indien nodig)
Druk op de Fix knop.
Er zal u een logbestand aangemaakt worden (fixlog.txt) op dezelfde plaats vanwaar de 'tool' is gestart.
Kopieer en plak de inhoud van de logbestanden in je het volgende bericht.(als de inhoud te groot is voor één bericht plaats het in meerdere berichten)


Stap 2.
Download de Afbeelding Emsisoft Emergency Kit naar het bureaublad.
Klik hier voor de complete / uitgebreide handleiding van de Emsisoft Emergency Kit.
  • Dubbelklik op "EmsisoftEmergencyKit.exe".
  • Klik vervolgens op de knop "Install" en de bestanden worden nu automatisch uitgepakt naar de systeemschijf "C:\EEK".
  • Wanneer het uitpakken gereed is opent de map "C:\EEK" dubbelklik op "Start Emergency Kit Scanner".
  • "Emsisoft Emergency Kit" gaat de "definities laden" wanneer u de melding "Wilt u nu updaten?" krijgt klikt u op "Ja".
  • Wanneer de update gereed is klikt u in op "Malware scan" wanneer u de melding "op PUP's mee scannen" krijgt klikt u op "Ja".
  • Het scannen begint, gebruik bij voorkeur de computer niet voor andere bezigheden tijdens de scan.
  • BELANGRIJK:Wanneer de scan gereed is en er zijn items gevonden doe daar nog "NIKS" mee we willen eerst zien wat is gevonden.
  • Klik vervolgens op de knop "Rapport bekijken" en plaats de inhoud van dit bestand in uw volgende antwoord.
  • Sluit hierna "EmsisoftEmergencyKit." af zonder een actie uit te voeren.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

12 feb 2018, 13:21

Vroeger had ik nooit degelijke problemen maar de laatste dagen liet ik de kleinkinderen op deze PC.
Zou ik de kleinkinderen niet meer toelaten op deze PC of zou een account voor de kleinkinderen voldoende zijn.

Fix resultaat van Farbar Recovery Scan Tool (x64) Versie: 10.02.2018 02
Gestart door papa (12-02-2018 12:42:24) Run:3
Gestart vanaf C:\Users\papa.PCI5LIVING\Desktop
Geladen Profielen: papa (Beschikbare Profielen: Sem & Lucy & papa)
Boot Modus: Normal
==============================================

fixlist inhoud:
*****************
start
CreateRestorePoint:
Hosts:
Reboot:
end
*****************

Herstelpunt is succesvol gemaakt.
C:\Windows\System32\Drivers\etc\hosts => is succesvol verplaatst
Hosts met succes hersteld.


Het systeem moest herstart worden.

==== Eind van Fixlog 12:42:35 ====

Emsisoft Emergency Kit - Versie 2017.12
Laatste Update: 12/02/2018 13:09:49
Gebruikersaccount: PCI5LIVING\papa
Computernaam: PCI5LIVING
Windows versie: Windows 10x64

Scaninstellingen:

Scanmodus: Malware Scan
Objecten: Rootkits, Geheugen, Sporen, Bestanden

Detecteer PUPs: Aan
Scan archieven: Uit
Scan email data bestanden: Uit
ADS Scan: Aan
Bestandsextensiefilter: Uit
Directe schijftoegang: Uit

Scan gestart:    12/02/2018 13:11:42

Gescand:    76713
Gevonden:    0

Scan geëindigd:    12/02/2018 13:12:53
Scantijd:    0:01:11
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

12 feb 2018, 13:38

janneke dust2 schreef:Vroeger had ik nooit degelijke problemen maar de laatste dagen liet ik de kleinkinderen op deze PC.
Zou ik de kleinkinderen niet meer toelaten op deze PC of zou een account voor de kleinkinderen voldoende zijn.
Dat zou al een goede stap zijn, EEK zag er netjes uit;

Lees het volgende eerst goed door (vooral het Save to text file gedeelte) en neem de tijd voor de volgende scan:

Download de Afbeelding ESET Online Scanner naar je bureaublad.

Eset Online Scanner uitvoeren.
  • Dubbelklik op "esetonlinescanner_enu.exe", "Terms of use" opent vink daar "Download latest version of ESET Online Scanner" aan.
  • Klik vervolgens op de knop "Accept", wanneer u een melding krijgt van het Gebruikersaccountbeheer staat u dit toe.
  • "Computer scan settings" opent, vink daar "Enable detection of potentially unwanted applications" aan.
  • Klik op "Advanced settings", zorg dat daar de volgende items zijn aangevinkt.
    - Enable detection of potentially unsafe applications
    - Enable detection of suspicious applications
    - Scan archives
    - Enable Anti-Stealth technology
    - Clean threats automatically
  • Let op: Schakel nu eerst je eigen virusscanner uit, het scannen met Eset gaat dan sneller. ( zet deze na de scan weer aan)
  • Klik op "Scan", deze scan kan geruime tijd in beslag nemen en gebruik bij voorkeur de computer niet voor andere bezigheden tijdens de scan.
Na het scannen:
  • Als er niks word gevonden klik op "Finish", het scherm "Thank you for trying Eset Online Scanner" mag je ook sluiten.
  • Zijn er bedreigingen gevonden klik dan op "Show list of results", klik op "Save to text file.." geef als Bestandsnaam "Eset.txt" en plaats het op je bureaublad.
  • Klik vervolgens rechts boven op "X" (de bedreigingen zijn dan verwijderd), het scherm "Thank you for trying Eset Online Scanner" mag je ook sluiten.
  • Voeg de inhoud van het logbestand met de naam "Eset.txt" toe aan het volgende bericht.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

janneke dust2
Lid geworden op: 15 jan 2006, 16:31
Locatie: Antwerpen LO

12 feb 2018, 18:32

C:\AdwCleaner\Quarantine\frAQBc8Wsa\exe.emorhc.bat    BAT/Starter.NCH trojan    cleaned by deleting
C:\AdwCleaner\Quarantine\frAQBc8Wsa\exe.erolpxei.bat    BAT/Starter.NCH trojan    cleaned by deleting
C:\AdwCleaner\Quarantine\frAQBc8Wsa\exe.xoferif.bat    BAT/Starter.NCH trojan    cleaned by deleting
C:\ProgramData\System Native\Main Services\updates\Update #21\MainServices2.exe    RAR/CoinMiner.S trojan    cleaned by deleting
C:\Users\jcarn(nietGebruikt)\AppData\Roaming\PopupBlocker\uninstall.exe    a variant of Win32/Adware.BrowSecX.AR application    cleaned by deleting
D:\papa.PCI5LIVING\UpdatePCsoft\Adobe\premiere elements v8\cr-pre80.iso    a variant of Win32/Keygen.BH potentially unsafe application    deleted
D:\papa.PCI5LIVING\UpdatePCsoft\BackUp-EaseUSToDoBackupFree\tb_free.exe    a variant of Win32/TFTPD32.A potentially unsafe application    cleaned by deleting
D:\papa.PCI5LIVING\UpdatePCsoft\PC-beveiliging\Ccleaner\ccsetup539.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
D:\papa.PCI5LIVING\UpdatePCsoft\PC-Drivers-Medion\devicedoctor\DeviceDoctor_Bundle.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    cleaned by deleting
D:\papa.PCI5LIVING\UpdatePCsoft\PC-tools\speccy\spsetup131.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\jcarn-Disk-C\jcarn\AppData\Roaming\PopupBlocker\uninstall.exe    a variant of Win32/Adware.BrowSecX.AR application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\Adobe\premiere elements v8\cr-pre80.iso    a variant of Win32/Keygen.BH potentially unsafe application    deleted
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\BackUp-EaseUSToDoBackupFree\tb_free.exe    a variant of Win32/TFTPD32.A potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\PC-beveiliging\Ccleaner\ccsetup536.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\PC-beveiliging\Ccleaner\ccsetup537-slim.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\PC-Drivers-Medion\devicedoctor\DeviceDoctor_Bundle.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\PC-tools\speccy\spsetup131.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
X:\PCmetSSD\backup-copy-20171128\Jcarn-disk-H\jcarn\UpdatePCsoft\SamsungTVdisk lezen\PVRdecoder\samyGOPVRDecoder.exe    a variant of Win32/RemoteAdmin.NetCat.AD potentially unsafe application    cleaned by deleting
X:\PCmetSSD\copy-papaPCILIVINGvanDiskD\papa.PCI5LIVING\UpdatePCsoft\Adobe\premiere elements v8\cr-pre80.iso    a variant of Win32/Keygen.BH potentially unsafe application    deleted
X:\PCmetSSD\copy-papaPCILIVINGvanDiskD\papa.PCI5LIVING\UpdatePCsoft\BackUp-EaseUSToDoBackupFree\tb_free.exe    a variant of Win32/TFTPD32.A potentially unsafe application    cleaned by deleting
X:\PCmetSSD\copy-papaPCILIVINGvanDiskD\papa.PCI5LIVING\UpdatePCsoft\PC-beveiliging\Ccleaner\ccsetup539.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
X:\PCmetSSD\copy-papaPCILIVINGvanDiskD\papa.PCI5LIVING\UpdatePCsoft\PC-Drivers-Medion\devicedoctor\DeviceDoctor_Bundle.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application    cleaned by deleting
X:\PCmetSSD\copy-papaPCILIVINGvanDiskD\papa.PCI5LIVING\UpdatePCsoft\PC-tools\speccy\spsetup131.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
Acer Nitro N50-600 ,Win11-64b,i7-3GHz,16GB RAM,500GB SSD,1TB HDD
Laptop HP pavilion, win11 64bit, 16GB RAM, SSD 512GB
Firefox, Microsoft Outlook 2019