Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2015 Ran by Laurens at 2015-04-21 18:43:01 Running from C:\Users\Laurens\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Antivirus en antispyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Antivirus en antispyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB} FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3635746246-4039717782-239317034-1004\...\uTorrent) (Version: 3.4.3.39944 - BitTorrent Inc.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Age of Empires III (HKLM-x32\...\InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Amazon.co.uk (HKLM-x32\...\{A74F16FA-1D5B-405B-8D8D-1BC6F9DAED8B}) (Version: - Amazon EU S.a.r.L.) Apple Application Support (HKLM-x32\...\{CCE825DB-347A-4004-A186-5F4A6FDD8547}) (Version: 2.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}) (Version: 6.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.27 - Atheros Communications Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.0 - Atheros) Basissoftware voor HP Officejet Pro 8500 A910 (HKLM\...\{E72B796E-BB9B-44D5-BDCB-36AC39E0C5D0}) (Version: 22.50.231.0 - Hewlett-Packard Co.) Belgium e-ID middleware 4.0.7 (build 7453) (HKLM\...\{824563DE-75AD-4166-9DC0-B6482F207453}) (Version: 4.0.7453 - Belgian Government) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.4.0.8 - ) Canon Internet Library for ZoomBrowser EX (HKLM-x32\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.0.3 - ) Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 2.5.0.15 - ) Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 3.0.0.18 - ) Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.0.0.8 - ) Canon Utilities CameraWindow DC (HKLM-x32\...\CameraWindowDC) (Version: 7.0.1.16 - ) Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowDVC6) (Version: 6.4.1.15 - ) Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 6.4.0.5 - ) Canon Utilities MyCamera DC (HKLM-x32\...\MyCameraDC) (Version: 7.0.0.5 - ) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.20.44 - ) Canon Utilities RemoteCapture DC (HKLM-x32\...\RemoteCaptureDC) (Version: 3.0.1.8 - ) Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.7.1.9 - ) Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.0.0.246 - ) Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.0.0.19 - ) CCleaner (HKLM\...\CCleaner) (Version: 3.13 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.111.0.64 - Conexant) Creative Centrale (HKLM-x32\...\Creative Centrale) (Version: 1.18.05 - Creative Technology Ltd.) Creative Centrale (x32 Version: 1.18.05 - Creative Technology Ltd.) Hidden Creative Software Update (x32 Version: 1.03.01 - Creative Technology Ltd.) Hidden Creative ZEN X-Fi Style Documentatie (HKLM-x32\...\ZENXFISTYLEUG) (Version: - Creative Technology Ltd.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd.) Free M4a to MP3 Converter 7.0 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GoldWave v5.67 (HKLM-x32\...\GoldWave v5.67) (Version: - ) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.240 - SurfRight B.V.) HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Officejet 6500 E710a-f Basissoftware van het apparaat (HKLM\...\{8A7C08FA-6472-4A5E-BB87-21B5BF00947C}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6500 E710a-f Haelp (HKLM-x32\...\{037CD593-D760-4A00-B030-7BBAFA1123FE}) (Version: 140.0.2.2 - Hewlett Packard) HP Officejet 6500 E710a-f Productverbeteringsonderzoek (HKLM\...\{DF37117B-E553-44A9-BD4D-EFFB740D4D93}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6600 Basissoftware van het apparaat (HKLM\...\{C6FF31F6-7505-49BC-BE55-911F23A4F125}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet Pro 8500 A910 Haelp (HKLM-x32\...\{871B2A9D-0F12-44B3-88C1-E0CB10A232E4}) (Version: 140.0.2.2 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Inkscape 0.48.4 (HKLM-x32\...\Inkscape) (Version: 0.48.4 - ) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2086 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{22D8AE6F-3C6B-47E8-8F04-629F23DBE978}) (Version: 11.0.0.163 - Apple Inc.) Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden McAfee Online Backup (Version: 1.16.4.0 - McAfee, Inc.) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) McAfee SecurityCenter (HKLM-x32\...\MSC) (Version: 14.0.339 - McAfee, Inc.) McAfee Virtual Technician (HKLM-x32\...\McAfee Virtual Technician) (Version: 7.1.0.2483 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 37.0.1 (x86 nl) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 nl)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Nero 9 Essentials (HKLM-x32\...\{35938e7d-ffc5-4d03-b988-6e82edc6baeb}) (Version: - Nero AG) Nero BackItUp (HKLM-x32\...\{0420F95C-11FF-4E02-B967-6CC22B188F9F}) (Version: 5.2.21001 - Nero AG) Nero BackItUp and Burn (HKLM-x32\...\{E08CC458-41FB-4BB5-9B08-2C83DB55A5B9}) (Version: 1.2.0030 - Nero AG) Nero BurnRights (HKLM-x32\...\{397516AE-7DFE-4F90-84E0-BD616D559434}) (Version: 3.6.26001 - Nero AG) Nero Express (HKLM-x32\...\{6C3CF7AC-5AB0-42D9-93C0-68166A57AFB6}) (Version: 9.6.16000 - Nero AG) Nero RescueAgent (HKLM-x32\...\{51E2F9B3-A972-4F58-B4EF-4D9676D9F5D1}) (Version: 2.6.25002 - Nero AG) OLYMPUS Viewer 3 (HKLM-x32\...\{4F1E9C9C-76F2-4D01-9463-F44B6CB5C92E}) (Version: 1.4.0 - OLYMPUS IMAGING CORP.) Photo Service - powered by myphotobook (HKLM-x32\...\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.0.7-279 - myphotobook GmbH) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) QuickTime (HKLM-x32\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.) RawTherapee 3.0.1 (HKLM\...\RawTherapee 3.0.1) (Version: 3.0.1.0 - RT Team) RealDownloader (x32 Version: 17.0.13 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30111 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) SiteAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.206 - McAfee, Inc.) Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) SmartDraw 2014 (HKLM-x32\...\SmartDraw 2014) (Version: - SmartDraw, LLC) SoMud 1.4.1 (HKLM-x32\...\SoMud) (Version: 1.4.1 - SoMud) Spotify (HKU\S-1-5-21-3635746246-4039717782-239317034-1004\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Stuurprogrammapakket voor Windows - Fedict SmartCard (03/25/2014 4.0.7.4) (HKLM\...\B02255EDA75F867B4D85C5A5D23E13D9EF71E8AE) (Version: 03/25/2014 4.0.7.4 - Fedict) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated) System Requirements Lab (HKLM-x32\...\{4DE938F7-C196-43D7-8EEB-411CDE0A96B1}) (Version: 4.3.1.0 - Husdawg, LLC) Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD) (Version: 10.0.50903 - Microsoft Corporation) TOEFL Sample Questions (HKLM-x32\...\{8026256E-BA16-4125-B350-EE6F31E7A638}) (Version: 3.00.0000 - ETS) Toshiba Assist (HKLM-x32\...\{1B87C40B-A60B-4EF3-9A68-706CF4B69978}) (Version: 3.00.11 - TOSHIBA CORPORATION) TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}) (Version: 1.6.07.64 - TOSHIBA Corporation) TOSHIBA ConfigFree (HKLM-x32\...\{607BE7BF-7C28-4ADB-A4A0-385962B901C3}) (Version: 8.0.28 - TOSHIBA Corporation) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation) TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.3.64 - TOSHIBA Corporation) TOSHIBA Hardware Setup (HKLM-x32\...\{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}) (Version: 2.00.06 - TOSHIBA Corporation) TOSHIBA HDD/SSD-waarschuwing (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.6 - TOSHIBA Corporation) Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.01 - TOSHIBA) TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: 1.0.80.3.64 - TOSHIBA CORPORATION) TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.4.9 - TOSHIBA CORPORATION) TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 2.09.0001 - TOSHIBA) TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.4 x64 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA) TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}) (Version: 1.6.06.64 - TOSHIBA Corporation) TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.9 - TOSHIBA) TOSHIBA Supervisor Password (HKLM-x32\...\{073B89C3-BA88-41B5-965F-B35A88EAE838}) (Version: 2.00.03 - TOSHIBA Corporation) Toshiba TEMPRO (HKLM-x32\...\{DBB7021A-3437-446F-ACE5-7261644A972C}) (Version: 3.33 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.3.3.64 - TOSHIBA Corporation) TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.15 - TOSHIBA Corporation) TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: - ) TRORMCLauncher (Version: 1.0.0.9 - TOSHIBA) Hidden UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden VASCO Card Reader Plug-In (64-Bit) (Version: 3.2.3.2 - VASCO Data Security) Hidden VASCO Smart Card Reader Plug-In (User) (HKU\S-1-5-21-3635746246-4039717782-239317034-1004\...\{8bc0c044-0d13-4fe6-90c1-af39c36cb927}) (Version: 3.2.3.2 - VASCO Data Security) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{CD19EDD9-1632-4002-9212-7478E4BA0423}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows-stuurprogrammapakket - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0) (HKLM\...\2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB) (Version: 09/09/2009 1.0.0.0 - OLYMPUS IMAGING CORP.) WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ZHPDiag 2015 (HKLM-x32\...\ZHPDiag_is1) (Version: 2015 - Nicolas Coolman) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3635746246-4039717782-239317034-1004_Classes\CLSID\{9E436272-69C3-5FBA-9C1D-15694337F4AC}\InprocServer32 -> C:\Users\Laurens\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin64.dll (VASCO Data Security) ==================== Restore Points ========================= 15-04-2015 18:16:45 Windows Update 21-04-2015 17:33:16 Windows Update 21-04-2015 18:15:02 Controlepunt van HitmanPro 21-04-2015 18:17:03 Controlepunt van HitmanPro ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1232170B-DA0B-4795-8093-4FF7764428CA} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {31A81F31-54F0-4F90-8616-BF834473855F} - System32\Tasks\SDMsgUpdate (Local) => C:\Program Files (x86)\SmartDraw 2014\Messages\SDNotify.exe [2012-08-13] () Task: {3C343AA0-F61F-4191-8A30-39EC9ACBCB4E} - System32\Tasks\disco_games_notification_service => C:\Program Files (x86)\disco games\disco_games_notification_service.exe <==== ATTENTION Task: {494A2B8A-EED5-42D6-8766-331A70E62152} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw 2014\Messages\SDNotify.exe [2012-08-13] () Task: {4E96319B-5D75-48C8-B8F1-27B3626B8BEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {5171D280-B497-4B56-8A12-C130C9636992} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {51A3A03C-B378-4C57-A6B1-8F729C37432F} - System32\Tasks\User NBAgent => C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [2010-03-09] (Nero AG) Task: {53896A05-C7C6-43CC-AE0C-F020B6248AD9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-14] (Google Inc.) Task: {5BD772E6-7894-4C44-A499-BD5633E52F9E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {5DC62EE6-0F23-4C06-A7B3-43294CDBC347} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {64A36665-E4D5-4A55-997B-FFCD119AFB60} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated) Task: {6AC4BFF8-7A50-40EA-8A56-80563B5DA5EA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-14] (Google Inc.) Task: {7005E74E-429E-4269-A022-224BC09B7A39} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-02-22] (TOSHIBA CORPORATION) Task: {712C4E44-AF04-4DE8-87E4-B629E8548EBE} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {793C7A59-3837-4F88-A7D4-D57E4B3BD110} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {A744B3D8-1FE3-4FD2-B6AE-08323606082C} - System32\Tasks\{EDD1E00A-89D5-4591-AFB7-345169E39BAF} => pcalua.exe -a C:\Users\User\Downloads\2360(1)\Support\SETUP.EXE -d C:\Users\User\Downloads\2360(1)\Support Task: {ADBAF369-AD25-4916-AB6B-54D731949DB5} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {AE03F680-5EC3-4B15-BC6E-0FC7B9B48000} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {B0BC568A-8D8D-47C1-802B-A72A2DB250DE} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {C3F1AA99-E27E-4674-B79E-63A35659A8D6} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {D85CF975-7081-4144-B8DE-637289EF998E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\disco_games_notification_service.job => C:\Program Files (x86)\disco games\disco_games_notification_service.exeç/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='disco games' /appid='73143' /srcid='2913' /bic='65ab1202ed63986add27d2bdcef0d1dd' /verifier='36c88945bab501f6743e5f368e0e059d' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SDMsgUpdate (Local).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe`-PLocal -V21010005 -SSDNI.ini -A -Mhttp:/www.smartdraw.com/msgs/messagecheck.asp Task: C:\Windows\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe\-PTE -V21010005 -SSDU.ini -A -Mhttp:/www.smartdraw.com/msgs/messagecheck.asp ==================== Loaded Modules (whitelisted) ============== 2014-07-30 02:17 - 2014-07-30 02:17 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2014-07-30 05:04 - 2014-07-30 05:04 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe 2010-03-03 14:15 - 2010-03-03 14:15 - 08762680 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll 2009-11-03 13:26 - 2009-11-03 13:26 - 00053560 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll 2010-03-03 14:15 - 2010-03-03 14:15 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF10.dll 2010-03-03 14:15 - 2010-03-03 14:15 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF11.dll 2010-04-20 15:19 - 2009-06-22 14:40 - 00022328 _____ () C:\Program Files\TOSHIBA\Toshiba Assist\NotifyX.dll 2009-03-12 19:08 - 2009-03-12 19:08 - 00048640 _____ () C:\Program Files (x86)\Toshiba\PCDiag\NotifyPCD.dll 2009-07-25 16:38 - 2009-07-25 16:38 - 00017800 _____ () C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll 2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-10-09 19:23 - 2014-10-09 19:23 - 00864856 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll 2015-04-15 17:44 - 2015-04-15 17:44 - 16863920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:63238B95 AlternateDataStreams: C:\ProgramData\TEMP:661DFA1C AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3635746246-4039717782-239317034-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Laurens\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 195.130.131.4 - 195.130.130.132 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup MSCONFIG\startupfolder: C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f.lnk => C:\Windows\pss\Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f.lnk.Startup MSCONFIG\startupfolder: C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk).lnk => C:\Windows\pss\Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk).lnk.Startup MSCONFIG\startupfolder: C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^StartUp^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: HP Officejet 6600 (NET) => "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN43R8R0N905RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1 MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: NBAgent => "c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" /WinStart MSCONFIG\startupreg: OV3_Monitor => "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe" -NoStart MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SmartFaceVWatcher => %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe MSCONFIG\startupreg: SoMud => "C:\Program Files (x86)\SoMud\somud.exe" /bg MSCONFIG\startupreg: Spotify => "C:\Users\Laurens\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Laurens\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot MSCONFIG\startupreg: TOSHIBA Online Product Information => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe MSCONFIG\startupreg: Toshiba TEMPRO => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe MSCONFIG\startupreg: ToshibaServiceStation => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe MSCONFIG\startupreg: TosReelTimeMonitor => %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe MSCONFIG\startupreg: TWebCamera => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun ==================== Accounts: ============================= Administrator (S-1-5-21-3635746246-4039717782-239317034-500 - Administrator - Disabled) Gast (S-1-5-21-3635746246-4039717782-239317034-501 - Limited - Disabled) => C:\Users\Gast HomeGroupUser$ (S-1-5-21-3635746246-4039717782-239317034-1002 - Limited - Enabled) Laurens (S-1-5-21-3635746246-4039717782-239317034-1004 - Administrator - Enabled) => C:\Users\Laurens User (S-1-5-21-3635746246-4039717782-239317034-1000 - Limited - Enabled) => C:\Users\User ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/21/2015 06:18:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: 196: ERROR: read_msg errno 0 (De bewerking is voltooid.) Error: (04/21/2015 06:18:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x00000330,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000001BCEAB0.72). hr = 0x80070005, Toegang geweigerd. . Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x00000738,(null),0,REG_BINARY,0000000000B9DDC0.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Naam van schrijver: WMI Writer Instantie-id van schrijver: {69f34a24-3217-4965-b5c5-a78d817d4b91} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x00000d40,(null),0,REG_BINARY,0000000005AFE120.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Naam van schrijver: MSSearch Service Writer Instantie-id van schrijver: {59e1b2b5-7e0d-425a-9476-735bbc68fe79} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x000002e8,(null),0,REG_BINARY,0000000005EFE360.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220} Naam van schrijver: System Writer Instantie-id van schrijver: {a49d321c-f761-4f90-9022-4655605711b8} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x00000738,(null),0,REG_BINARY,0000000000B9DDC0.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Naam van schrijver: WMI Writer Instantie-id van schrijver: {69f34a24-3217-4965-b5c5-a78d817d4b91} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x00000d40,(null),0,REG_BINARY,0000000005AFE120.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Naam van schrijver: MSSearch Service Writer Instantie-id van schrijver: {59e1b2b5-7e0d-425a-9476-735bbc68fe79} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000001C7E8A0.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Naam van schrijver: Shadow Copy Optimization Writer Instantie-id van schrijver: {a92c1139-7181-40f6-8456-9b2428ffa1f4} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000001E7F110.72). hr = 0x80070005, Toegang geweigerd. . Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {542da469-d3e1-473c-9f4f-7847f01fc64f} Naam van schrijver: COM+ REGDB Writer Instantie-id van schrijver: {62ee35f7-2d1e-418d-9af2-ff6d6ff8bd82} System errors: ============= Error: (04/21/2015 06:25:47 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {209500FC-6B45-4693-8871-6296C4843751} Error: (04/21/2015 06:20:27 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: De HitmanPro 3.7 Crusader (Boot)-service is gestopt met de specifieke servicefout %%0. Error: (04/20/2015 08:37:32 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Notebook Performance Tuning Service (TEMPRO). Error: (04/16/2015 07:35:25 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {209500FC-6B45-4693-8871-6296C4843751} Error: (04/16/2015 07:35:21 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (04/16/2015 07:33:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: De Emsisoft Protection Service-service kan vanwege de volgende fout niet worden gestart: %%1053 Error: (04/16/2015 07:32:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Emsisoft Protection Service. Error: (04/16/2015 03:04:37 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (04/16/2015 08:57:11 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Notebook Performance Tuning Service (TEMPRO). Error: (04/15/2015 01:52:52 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58} Microsoft Office Sessions: ========================= Error: (04/21/2015 06:18:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: 196: ERROR: read_msg errno 0 (De bewerking is voltooid.) Error: (04/21/2015 06:18:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000330,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000001BCEAB0.72)0x80070005, Toegang geweigerd. Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000738,(null),0,REG_BINARY,0000000000B9DDC0.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Naam van schrijver: WMI Writer Instantie-id van schrijver: {69f34a24-3217-4965-b5c5-a78d817d4b91} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000d40,(null),0,REG_BINARY,0000000005AFE120.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Naam van schrijver: MSSearch Service Writer Instantie-id van schrijver: {59e1b2b5-7e0d-425a-9476-735bbc68fe79} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000002e8,(null),0,REG_BINARY,0000000005EFE360.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220} Naam van schrijver: System Writer Instantie-id van schrijver: {a49d321c-f761-4f90-9022-4655605711b8} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000738,(null),0,REG_BINARY,0000000000B9DDC0.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Naam van schrijver: WMI Writer Instantie-id van schrijver: {69f34a24-3217-4965-b5c5-a78d817d4b91} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000d40,(null),0,REG_BINARY,0000000005AFE120.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Naam van schrijver: MSSearch Service Writer Instantie-id van schrijver: {59e1b2b5-7e0d-425a-9476-735bbc68fe79} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000001C7E8A0.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Naam van schrijver: Shadow Copy Optimization Writer Instantie-id van schrijver: {a92c1139-7181-40f6-8456-9b2428ffa1f4} Error: (04/21/2015 06:18:14 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000001E7F110.72)0x80070005, Toegang geweigerd. Bewerking: BackupShutdown-gebeurtenis Context: Uitvoeringscontext: Writer Klasse-id van schrijver: {542da469-d3e1-473c-9f4f-7847f01fc64f} Naam van schrijver: COM+ REGDB Writer Instantie-id van schrijver: {62ee35f7-2d1e-418d-9af2-ff6d6ff8bd82} CodeIntegrity Errors: =================================== Date: 2015-02-25 17:21:57.578 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC7973.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2015-02-25 17:21:57.562 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC7973.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2015-02-25 17:21:57.562 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC7973.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2015-02-25 17:21:57.484 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC7973.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-12-24 15:58:29.283 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC46A1.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-12-24 15:58:29.267 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC46A1.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-12-24 15:58:29.267 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC46A1.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-12-24 15:58:29.267 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSC46A1.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-10-16 16:43:04.212 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSCE407.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. Date: 2014-10-16 16:43:04.212 Description: De integriteit van de kopie voor het bestand \Device\HarddiskVolume2\Program Files\Common Files\McAfee\VSCore_4_6\VSCE407.tmp\vscore\mfeelamk.sys kan niet worden geverifieerd omdat de reeks kopie-hashes per pagina niet is gevonden op het systeem. ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz Percentage of memory in use: 67% Total physical RAM: 2939.97 MB Available physical RAM: 950.59 MB Total Pagefile: 5878.13 MB Available Pagefile: 3168.8 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (WINDOWS) (Fixed) (Total:116.21 GB) (Free:9.04 GB) NTFS Drive d: (Data) (Fixed) (Total:116.28 GB) (Free:38.49 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: EC1EE8C0) Partition 1: (Active) - (Size=400 MB) - (Type=27) Partition 2: (Not Active) - (Size=116.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=116.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================