Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 14.03.2018 Gestart door Gebruiker (13-04-2018 06:09:52) Gestart vanaf C:\Users\Gebruiker\Downloads Windows 10 Pro Versie 1709 16299.371 (X64) (2017-12-01 13:02:41) Boot Modus: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-631523473-924200754-72314143-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-631523473-924200754-72314143-503 - Limited - Disabled) defaultuser0 (S-1-5-21-631523473-924200754-72314143-1000 - Limited - Disabled) => C:\Users\defaultuser0 Gast (S-1-5-21-631523473-924200754-72314143-501 - Limited - Disabled) Gebruiker (S-1-5-21-631523473-924200754-72314143-1001 - Administrator - Enabled) => C:\Users\Gebruiker Myrre (S-1-5-21-631523473-924200754-72314143-1002 - Limited - Enabled) => C:\Users\Myrre WDAGUtilityAccount (S-1-5-21-631523473-924200754-72314143-504 - Limited - Disabled) ==================== Security Center ======================== (Als een item is opgenomen in de fixlist, zal het worden verwijderd.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Geïnstalleerde programma's ====================== (Alleen de adware-programma's met 'verborgen' vlag kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeïnstalleerd worden.) Adobe Acrobat Reader DC - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.5.195 - Adobe Systems, Inc.) ANT Drivers Installer x64 (HKLM\...\{3DE56A70-06BA-4863-8FBB-45D041AF0C7A}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apple Application Support (32-bit) (HKLM-x32\...\{543F829B-4591-4B2F-AF63-6E6E6AE59EB2}) (Version: 6.4 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0ECA3BB5-4410-414B-B226-241FF1C12CD0}) (Version: 6.4 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{A05FDFEC-4377-49E0-82CB-B6D1386E89DA}) (Version: 11.3.0.9 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform) Elevated Installer (HKLM-x32\...\{B7768089-44E1-4B51-9213-737959C689E5}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden Garmin BaseCamp (HKLM-x32\...\{23A4DBD1-D847-4957-995D-8B1CC527E2E2}) (Version: 4.6.2.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{178D3388-656C-4326-BFFF-3607481CA5BB}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (HKLM-x32\...\{aa902576-9ab8-4371-98d1-efde885f775b}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Garmin Express Tray (HKLM-x32\...\{C6C8A534-050C-40E9-92FC-4D06A8A487C8}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (HKLM\...\{B43654C3-C600-3D41-BFF2-D288F5A76162}) (Version: 65.0.3325.181 - Google, Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden HP 3D DriveGuard (HKLM-x32\...\{84663FDA-1374-4048-9869-DD4A8784785A}) (Version: 6.0.16.1 - Hewlett-Packard Company) HP Support Solutions Framework (HKLM-x32\...\{4CBA8ECF-0519-4583-91ED-F098522245EB}) (Version: 12.8.47.1 - HP Inc.) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6496.0 - IDT) IHMC CmapTools v6.03 (HKLM\...\IHMC CmapTools v6.03) (Version: 6.0.3.0 - Institute for Human & Machine Cognition) Image Resizer Powertoy Clone for Windows (64 bit) (HKLM\...\{C862EC05-1C15-4327-B15D-C7788D6CFF73}) (Version: 2.1.1 - Brice Lambson) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.7.3.1001 - Intel Corporation) iTunes (HKLM\...\{589FA0CF-4000-4FC7-948B-52BF1F623502}) (Version: 12.7.4.76 - Apple Inc.) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) K-Lite Codec Pack 12.6.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.6.5 - KLCP) Malwarebytes Anti-Malware versie 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft Office 365 - nl-nl (HKLM\...\O365HomePremRetail - nl-nl) (Version: 16.0.9126.2116 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-631523473-924200754-72314143-1001\...\OneDriveSetup.exe) (Version: 18.025.0204.0009 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.9126.2116 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.9126.2116 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9126.2116 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0413-0000-0000000FF1CE}) (Version: 16.0.9126.2116 - Microsoft Corporation) Hidden Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.15 - Nikon) PremierOpinion (HKLM-x32\...\{eeb86aef-4a5d-4b75-9d74-f16d438fc286}) (Version: 1.3.337.412 - VoiceFive, Inc.) <==== AANDACHT Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.273.49 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek) Spotify (HKU\S-1-5-21-631523473-924200754-72314143-1001\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Stuurprogrammapakket voor Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Stuurprogrammapakket voor Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.63 - Synaptics Incorporated) TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer) ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.8.2 - Nikon) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) Zwift version 1.0.39 (HKLM-x32\...\{E4DA422A-82AB-44A4-B3A5-0AF60F47B7AB}_is1) (Version: 1.0.39 - Zwift, LLC) ==================== Aangepaste CLSID (gefilterd): ========================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Geen bestand ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-01-27] (Intel Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ==================== Geplande Taken (gefilterd) ============= (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {1AC6E660-9B2D-4C8E-A941-457EC6D1228A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-07] (Google Inc.) Task: {3477E9F4-1004-4EF4-AFB3-EF484525B34C} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-24] (Microsoft Corporation) Task: {3D194643-2373-47AE-8724-D71428A5EEEA} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-12-01] () Task: {4107EE03-9354-460C-9E18-788CF1A948E1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-24] (Microsoft Corporation) Task: {410BD6CB-F9AC-47D7-897A-DDDCDB573C8B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated) Task: {4B4A8295-2779-4B4C-9720-2C1E17A94D7F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-01] (Microsoft Corporation) Task: {573E846C-8B59-4478-A3DF-CE5DF44DE224} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-01] (Microsoft Corporation) Task: {5ADD1693-6BE0-4427-AB73-C8A4CCFC4DDF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-01] (Microsoft Corporation) Task: {75CA9357-C2A9-4206-9892-BCD8078CB083} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-07] (Google Inc.) Task: {814B3A04-3452-43CB-936A-B030DBD566CB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.) Task: {879900A2-34C7-4250-8E2D-040A33321944} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-03-31] (Microsoft Corporation) Task: {8C823D02-180E-44D2-9B54-AD499D9879B4} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-03-31] (Microsoft Corporation) Task: {93102186-AEF0-4C96-8EA9-148FFF5FF484} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2018-03-27] () Task: {9DDF7AA8-DCAD-411D-8A3B-BD004603E073} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd) Task: {9F131701-9621-4877-B95C-50AF9AF9F004} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) Task: {D3B5D31F-216A-4B02-AE30-3BDAED3C208B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-01] (Microsoft Corporation) Task: {D92EAE39-46FA-47E8-A452-0406DCF06B44} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-03-31] (Microsoft Corporation) Task: {E8566ED5-47D2-4993-B9D1-8373E40EE41C} - \Microsoft\Windows\UNP\RunCampaignManager -> Geen bestand <==== AANDACHT Task: {EF130918-3489-4EC0-B85B-34395911ED30} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.) (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) ==================== Snelkoppelingen & WMI ======================== (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.) ==================== Geladen Modules (gefilterd) ============== 2017-03-16 11:09 - 2017-03-16 11:09 - 000022528 _____ () C:\WINDOWS\system32\fpCSEvtSvc.exe 2017-12-08 02:48 - 2017-12-08 02:48 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2018-03-16 15:19 - 2018-03-16 15:19 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-12-08 13:40 - 2016-12-08 13:39 - 000100248 _____ () C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\SimpleService.exe 2018-02-14 18:43 - 2018-02-14 18:43 - 000182784 _____ () C:\ProgramData\JWrapper-Remote Access\JWrapper-JWrapper-00053416649-complete\jwutils_win64.dll 2018-02-14 18:43 - 2018-02-14 18:43 - 000182784 _____ () C:\ProgramData\JWrapper-Remote Access\JWrapper-Remote Access-00053416676-complete\jwutils_win64.dll 2018-02-28 09:13 - 2018-02-28 09:13 - 000326656 _____ () C:\ProgramData\JWrapper-Remote Access\JWrapper-Remote Access-00053416676-complete\utils_wnative64.dll 2017-09-29 15:41 - 2017-09-29 15:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-03-14 14:38 - 2018-02-22 02:26 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-03-14 14:38 - 2018-02-22 02:21 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-03-27 07:25 - 2018-03-27 07:25 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.1000_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-03-27 07:25 - 2018-03-27 07:25 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.1000_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-03-27 07:25 - 2018-03-27 07:25 - 022050304 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.1000_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-03-27 07:25 - 2018-03-27 07:25 - 002584576 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.1000_x64__kzf8qxf38zg5c\skypert.dll 2018-03-27 07:25 - 2018-03-27 07:25 - 000657408 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.1000_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-03-28 17:05 - 2018-03-28 17:05 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll 2018-03-28 17:05 - 2018-03-28 17:05 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2017-10-19 07:22 - 2016-09-29 18:46 - 001234840 _____ () C:\Program Files (x86)\Zwift\ZwiftLauncher.exe 2018-04-06 06:36 - 2018-04-06 06:36 - 000178688 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11803.1001.6.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll 2018-03-09 15:30 - 2018-03-09 15:30 - 002250240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11803.1001.6.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-04-03 06:33 - 2018-04-03 06:33 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2018-04-03 06:33 - 2018-04-03 06:33 - 067038720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-10-04 06:58 - 2017-10-04 06:59 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll 2018-02-16 07:44 - 2018-02-16 07:45 - 000010240 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\RenderingPlugin.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 004123648 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\ImagePipelineNative.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll 2018-04-03 06:33 - 2018-04-03 06:33 - 015329792 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 003962368 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\MediaEngine.dll 2018-04-03 06:33 - 2018-04-03 06:33 - 003250176 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\AppCore.Windows.dll 2018-03-02 10:01 - 2018-03-02 10:02 - 001369088 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2018-02-01 07:32 - 2018-02-01 07:33 - 004601048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 000094208 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\BendRealityNode.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 000043008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll 2018-03-30 06:34 - 2018-03-30 06:34 - 000631296 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll 2018-04-03 06:33 - 2018-04-03 06:33 - 000152064 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18022.15810.1000_x64__8wekyb3d8bbwe\SKU.dll 2018-03-23 07:25 - 2018-03-20 08:00 - 004435288 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libglesv2.dll 2018-03-23 07:25 - 2018-03-20 08:00 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll 2016-12-07 21:13 - 2013-12-10 08:27 - 001242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-12-08 16:41 - 2018-01-11 04:05 - 000784672 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-12-08 16:41 - 2018-04-03 01:34 - 002631968 _____ () C:\Program Files (x86)\Steam\video.dll 2016-12-08 16:41 - 2016-09-01 03:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2017-12-15 08:24 - 2017-12-20 03:43 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll 2017-12-15 08:24 - 2017-12-20 03:43 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll 2017-12-15 08:24 - 2017-12-20 03:43 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll 2017-12-15 08:24 - 2017-12-20 03:43 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll 2017-12-15 08:24 - 2017-12-20 03:43 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll 2016-12-08 16:41 - 2016-09-01 03:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-12-08 16:41 - 2016-09-01 03:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-12-08 16:41 - 2018-04-03 01:34 - 000977184 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-12-08 16:41 - 2016-07-05 00:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2017-06-08 07:21 - 2017-09-07 04:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2016-12-13 10:46 - 2017-12-13 23:16 - 071471392 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2016-12-08 16:41 - 2015-09-25 01:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll 2017-10-19 07:22 - 2016-09-29 18:45 - 001419160 _____ () C:\Program Files (x86)\Zwift\Patcher.dll ==================== Alternate Data Streams (gefilterd) ========= (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.) ==================== Veilige Modus (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.) ==================== Bestandskoppeling (gefilterd) =============== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd.) ==================== Internet Explorer vertrouwde/beperkte toegang =============== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd.) IE trusted site: HKU\S-1-5-21-631523473-924200754-72314143-1001\...\sharepoint.com -> hxxps://gerritrietveldcollege-files.sharepoint.com ==================== Hosts inhoud: =============================== (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.) 2016-07-16 13:47 - 2016-07-16 13:45 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere gebieden ============================ (Momenteel is er geen automatische fix voor dit onderdeel.) HKU\S-1-5-21-631523473-924200754-72314143-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Gebruiker\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\DO2017.JPG DNS Servers: 62.58.153.220 - 62.58.48.30 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 5) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is ingeschakeld. ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items == HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "AccelerometerSysTrayApplet" HKU\S-1-5-21-631523473-924200754-72314143-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-631523473-924200754-72314143-1001\...\StartupApproved\Run: => "Skype" ==================== Firewall regels (gefilterd) =============== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) FirewallRules: [UDP Query User{AC28D702-AAE7-49FD-942E-5CA3628534D8}C:\users\gebruiker\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gebruiker\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{264FEF5F-A4E2-44B8-A16A-F462A8EFBBB2}C:\users\gebruiker\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gebruiker\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{27CE8622-F5A2-4E5C-A70A-36369C6F6BBF}C:\users\gebruiker\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\gebruiker\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{C06C5E22-258A-4702-B06C-780A05BF8DAE}C:\users\gebruiker\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\gebruiker\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{4BC2C0CD-D992-4D90-8775-1A15F3ABA60C}C:\users\myrre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\myrre\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{1EDDE574-62C7-46DB-9BC4-6C340A9EEF19}C:\users\myrre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\myrre\appdata\roaming\spotify\spotify.exe FirewallRules: [{C9D97878-81C3-485F-9948-0540551FCA4E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{396CDC95-5C0E-4E81-AB93-D9B0A7414500}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{06F1013F-AC05-4E38-84F5-DAB1BE69DB15}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 2\BloodBowl2.exe FirewallRules: [{BE983FA7-0B9C-467B-909E-541A20ADE2D9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 2\BloodBowl2.exe FirewallRules: [{182BE8B2-B237-44CE-B7CA-CAD812717F57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DeathRally\DeathRally.exe FirewallRules: [{7B41EC93-F6ED-4759-923D-B37F362A4D3B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DeathRally\DeathRally.exe FirewallRules: [{3940EC83-F0FE-44F2-8167-D8A4AEA59A34}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Space Hulk\game.exe FirewallRules: [{B4F7B772-3CA7-4FEF-BF7A-3E07DA1DE715}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Space Hulk\game.exe FirewallRules: [TCP Query User{E1B367AF-077D-4F28-8CEE-B765F834B943}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe FirewallRules: [UDP Query User{75CD9B36-09D1-4BF1-8C61-2C73987278B5}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe FirewallRules: [{A20D8C1E-5455-4D01-A729-3FE343C0F981}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{50B1300F-FBF4-4ECE-B744-412BB18C7E62}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{E96FB217-CDD0-4BA3-B593-85F763EF267C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\New Star Soccer 5\NSS5.exe FirewallRules: [{574A3B34-1299-4540-B147-3DC516B3B886}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\New Star Soccer 5\NSS5.exe FirewallRules: [{133EA0EC-285C-4AA8-A630-7CE339DD1860}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{B2B80E38-989F-4E5B-B273-71BE5CAA73B7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{4B99F20E-E9CB-4F9F-A141-8B03C073B893}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{A1C2CA51-3853-4974-897B-443D2E412735}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{554B8A86-34FA-4EFF-B391-DCA2CAA0F47C}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe FirewallRules: [UDP Query User{468D44BA-20EE-43EB-A84E-07D7E44B82ED}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe FirewallRules: [{31F73F5F-8E8E-420A-8FDB-FAC7D028D6C4}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe FirewallRules: [{B2B201E9-3225-4743-ACFC-C2C50877E87F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{6D461B79-897A-4F4F-B5AB-03BB86794167}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{74EA53A5-0A1A-4B30-AE66-229B4298073A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{3B230E0D-67D8-4D96-B961-4BE9CED6F9EF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{17216DFC-8049-478E-A99B-2A6A4D5EC3FE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{91A4070E-2D08-414C-A8EA-49648420BD60}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00000000000-complete\bin\Remote Access.exe FirewallRules: [{264DA5F6-E37E-46D0-9A12-6712E0FF3383}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00000000000-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{E3861461-0082-43ED-8E20-463D5E8A7A18}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00000000000-complete\bin\Remote AccessLauncher.exe FirewallRules: [{08DEBD85-7F7A-4669-8B90-DB1AF9A5B619}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{443E20DE-DA27-4410-A54E-6341842F63CA}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{39A0EE57-6D83-4A4E-88B1-DD9178F7F49E}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{0960B9B1-E1ED-420E-8AC1-2F813584A6CE}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{13B26240-95B2-4B92-B6EC-728B15C57472}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{E0C2350B-A82E-4DFC-8BA5-E266303D7F0C}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{4ABE00FB-50D4-4D06-8521-7D71AF0C0E53}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{45A2A7EE-94FF-4264-B253-346E24E2840A}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{083256E7-F9FD-4B4E-B5CD-E6768A0C2CAA}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{B6FC4F74-7F52-4FDF-B380-BADEE49FFCC8}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{BF90B8C7-D72C-4D42-ABA7-CC5779E5047A}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{95203FC9-FA82-476B-98C3-968A5EB45702}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{4626EA1B-60FE-49DD-B73A-0C29D9CBBFFA}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{37D06917-543C-4D29-86F4-2D5A83504C62}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{865B4CC0-D664-44C4-9ED6-8F053DC01C16}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{CB3B67A2-8FB9-43F9-9C23-E7C3FD951B13}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{7822201B-7BBA-442F-B2FB-26935F78DDAB}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{397A07C7-882D-4E59-BBF7-7076520D1BD0}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{6BAAD940-C452-4A01-AD57-067E7E00A9A7}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{08A8485B-53F8-45DE-9A04-52B371AB440B}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{DE505338-BF33-441B-BFBF-F8EC4C8DF18B}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{BE02DA80-4BD7-4757-895D-92B882558AC2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{7C1FDAAE-ADE9-4E39-883C-BD0A69D5A348}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{7964699D-1A89-4E66-8F57-1918C3636598}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{987F1F89-8FA2-48F9-BD38-EAA8917826EB}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{262B1A9C-9C91-4D20-ADAD-BC3D885301AA}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{8B642A37-10D4-4FB4-98D5-CF57FD1D5D6C}C:\program files\ihmc cmaptools\jre\bin\javaw.exe] => (Allow) C:\program files\ihmc cmaptools\jre\bin\javaw.exe FirewallRules: [UDP Query User{68AB4737-BCD4-4D95-9032-800849B052F0}C:\program files\ihmc cmaptools\jre\bin\javaw.exe] => (Allow) C:\program files\ihmc cmaptools\jre\bin\javaw.exe FirewallRules: [{4C8F5CD8-3F4D-413D-B503-925FF3A3B1C5}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{1095CB43-7772-4478-A624-A16794ED3E99}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{E8B740FD-20B5-4C7F-AAEE-C31DFB604626}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{83E87051-0FFF-4C4E-BDE2-4C70E5E9F079}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{A171ADFD-6323-4DB6-94A4-EB803361D1AE}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{BE245ED5-CD7A-4F2F-9C03-EC9A432CAFDE}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{450429CF-585F-4368-97C9-08C9ECD1FEBB}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{AC9A36EF-3539-4A4B-8690-F49C4CBDA1A6}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{9FB33083-4509-491A-B0A7-C38508D5D6BF}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{0BFBE7DB-849F-4822-B50D-52A3C75ADB74}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{268C9CD3-4A2F-4451-A452-79BED58F92CA}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{FFDF185D-B99A-4452-8D79-BE068EE925E0}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{8724B038-476F-4C8E-A6EF-B0E6BDDCB3BE}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote Access.exe FirewallRules: [{9CD610A3-F61A-48C9-9EEC-0DA993037045}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessECompatibility.exe FirewallRules: [{813F4DAA-86D8-4ECF-8F0A-0AB93783CEFA}] => (Allow) C:\ProgramData\JWrapper-Remote Access\JWrapper-Windows64JRE-00052950164-complete\bin\Remote AccessLauncher.exe FirewallRules: [{9065612B-D9BF-4A1F-91E8-9EAD23BEB2F3}] => (Allow) C:\Program Files (x86)\PremierOpinion\pmropn.exe FirewallRules: [{7347DFEF-EC4D-45FE-A0AA-AA36241B5454}] => (Allow) C:\Program Files (x86)\PremierOpinion\pmropn.exe ==================== Herstelpunten ========================= 23-03-2018 22:50:42 Gepland controlepunt 31-03-2018 09:57:51 Gepland controlepunt 03-04-2018 06:32:38 Garmin Express 04-04-2018 17:03:17 Windows Movie Maker V6.0.6002.18005 10-04-2018 22:27:06 Windows Update 10-04-2018 22:27:20 Windows Update ==================== Defecte Apparaatbeheer Apparaten ============= ==================== Eventlog fouten: ========================= Applicatiefouten: ================== Error: (04/13/2018 05:57:22 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (04/13/2018 05:54:19 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 25557781 Error: (04/13/2018 05:54:19 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 25557781 Error: (04/13/2018 05:54:19 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2018 05:54:18 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 25556703 Error: (04/13/2018 05:54:18 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 25556703 Error: (04/13/2018 05:54:18 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/12/2018 09:03:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: Spotify.exe, versie: 1.0.77.338, tijdstempel: 0x5ab5464b Naam van module met fout: libcef.dll, versie: 3.3325.1750.0, tijdstempel: 0x5aacca10 Uitzonderingscode: 0xc0000005 Foutmarge: 0x03ff604b Id van proces met fout: 0x2d9c Starttijd van toepassing met fout: 0x01d3d28405e45124 Pad naar toepassing met fout: C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe Pad naar module met fout: C:\Users\Gebruiker\AppData\Roaming\Spotify\libcef.dll Rapport-id: c351ad92-d850-475f-8c16-8831fba8ecfc Volledige pakketnaam met fout: Relatieve toepassings-id van pakket met fout: Systeemfouten: ============= Error: (04/13/2018 06:09:23 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:57:20 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:56:06 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0OC9J6C) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker DESKTOP-0OC9J6C\Gebruiker SID (S-1-5-21-631523473-924200754-72314143-1001) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:54:41 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0OC9J6C) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} en APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} aan de gebruiker DESKTOP-0OC9J6C\Gebruiker SID (S-1-5-21-631523473-924200754-72314143-1001) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:54:22 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:54:22 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:54:22 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Error: (04/13/2018 05:54:22 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} en APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} aan de gebruiker NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services. Windows Defender: =================================== Date: 2018-04-09 11:17:10.600 Description: Scan van Windows Defender Antivirus is gestopt voordat deze was voltooid. Scan-id: {741D7B9E-D7E6-42BF-B476-6F6B94DB12AE} Type scan: Antimalware Scanparameters: Snelle scan Gebruiker: NT AUTHORITY\SYSTEM Date: 2018-03-15 18:03:33.239 Description: Scan van Windows Defender Antivirus is gestopt voordat deze was voltooid. Scan-id: {9C0810B4-A90B-452F-9C13-A813F457D508} Type scan: Antimalware Scanparameters: Snelle scan Gebruiker: NT AUTHORITY\SYSTEM Date: 2018-02-15 16:55:30.867 Description: Scan van Windows Defender Antivirus is gestopt voordat deze was voltooid. Scan-id: {6DC737F7-C33D-4802-9359-104708D26A46} Type scan: Antimalware Scanparameters: Snelle scan Gebruiker: NT AUTHORITY\SYSTEM Date: 2018-01-11 18:11:06.653 Description: Scan van Windows Defender Antivirus is gestopt voordat deze was voltooid. Scan-id: {8EECF8CB-3844-4A3C-AD49-7B72295BA3DF} Type scan: Antimalware Scanparameters: Snelle scan Gebruiker: NT AUTHORITY\SYSTEM Date: 2018-01-05 20:17:06.288 Description: Scan van Windows Defender Antivirus is gestopt voordat deze was voltooid. Scan-id: {3226F8CA-9C05-4FEF-A3AA-1CBF79C65153} Type scan: Antimalware Scanparameters: Snelle scan Gebruiker: NT AUTHORITY\SYSTEM Date: 2018-04-04 21:55:45.118 Description: Windows Defender Antivirus heeft een fout aangetroffen bij het bijwerken van handtekeningen. Nieuwe handtekeningversie: Vorige handtekeningversie: 1.265.51.0 Bron update: Microsoft Centrum voor beveiliging tegen malware Type handtekening: AntiVirus Type update: Volledig Gebruiker: NT AUTHORITY\NETWORK SERVICE Huidige engineversie: Vorige engineversie: 1.1.14700.5 Foutcode: 0x80072ee7 Foutbeschrijving: De naam of het adres van de server kan niet worden omgezet Date: 2018-04-04 21:55:45.117 Description: Windows Defender Antivirus heeft een fout aangetroffen bij het bijwerken van handtekeningen. Nieuwe handtekeningversie: Vorige handtekeningversie: 119.0.0.0 Bron update: Microsoft Centrum voor beveiliging tegen malware Type handtekening: Systeem voor netwerkinspectie Type update: Volledig Gebruiker: NT AUTHORITY\NETWORK SERVICE Huidige engineversie: Vorige engineversie: 2.1.14600.4 Foutcode: 0x80072ee7 Foutbeschrijving: De naam of het adres van de server kan niet worden omgezet Date: 2018-04-04 21:55:25.023 Description: Windows Defender Antivirus heeft een fout aangetroffen bij het bijwerken van handtekeningen. Nieuwe handtekeningversie: Vorige handtekeningversie: 1.265.51.0 Bron update: Microsoft Centrum voor beveiliging tegen malware Type handtekening: AntiVirus Type update: Volledig Gebruiker: NT AUTHORITY\NETWORK SERVICE Huidige engineversie: Vorige engineversie: 1.1.14700.5 Foutcode: 0x80072ee7 Foutbeschrijving: De naam of het adres van de server kan niet worden omgezet Date: 2018-04-04 21:55:25.023 Description: Windows Defender Antivirus heeft een fout aangetroffen bij het bijwerken van handtekeningen. Nieuwe handtekeningversie: Vorige handtekeningversie: 1.265.51.0 Bron update: Microsoft Centrum voor beveiliging tegen malware Type handtekening: AntiSpyware Type update: Volledig Gebruiker: NT AUTHORITY\NETWORK SERVICE Huidige engineversie: Vorige engineversie: 1.1.14700.5 Foutcode: 0x80072ee7 Foutbeschrijving: De naam of het adres van de server kan niet worden omgezet Date: 2018-04-04 21:55:25.022 Description: Windows Defender Antivirus heeft een fout aangetroffen bij het bijwerken van handtekeningen. Nieuwe handtekeningversie: Vorige handtekeningversie: 1.265.51.0 Bron update: Microsoft Centrum voor beveiliging tegen malware Type handtekening: AntiVirus Type update: Volledig Gebruiker: NT AUTHORITY\NETWORK SERVICE Huidige engineversie: Vorige engineversie: 1.1.14700.5 Foutcode: 0x80072ee7 Foutbeschrijving: De naam of het adres van de server kan niet worden omgezet CodeIntegrity: =================================== Date: 2018-04-13 06:09:41.855 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 06:09:18.543 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 06:09:18.542 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 06:05:42.088 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 06:04:41.874 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 05:59:41.850 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 05:59:41.844 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. Date: 2018-04-13 05:59:41.834 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\pmls64.dll that did not meet the Microsoft signing level requirements. ==================== Geheugen info =========================== Processor: Intel(R) Core(TM) i5-4200M CPU @ 2.50GHz Percentage geheugen in gebruik: 69% Totaal fysiek RAM-geheugen: 3977.09 MB Beschikbaar fysiek RAM-geheugen: 1214.42 MB Totaal Virtueel geheugen: 6153.09 MB Beschikbaar Virtual geheugen: 2466.79 MB ==================== Schijven ================================ Drive c: () (Fixed) (Total:237.08 GB) (Free:80.71 GB) NTFS \\?\Volume{1b7fda2a-84a4-4d00-8cd6-b57ed178a82e}\ (Herstel) (Fixed) (Total:0.44 GB) (Free:0.43 GB) NTFS \\?\Volume{0532da41-5020-4c73-92a5-98770ac42eaf}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 \\?\Volume{480f29e4-dd95-4a7f-9461-f9cbd3390061}\ () (Fixed) (Total:0.84 GB) (Free:0.3 GB) NTFS ==================== MBR & Partitietabel ================== ======================================================== Disk: 0 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Eind van Addition.txt ============================