Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-06-2015 Ran by Ihsane at 2015-06-19 20:26:05 Running from C:\Users\Ihsane\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2279217210-3855026583-970737385-500 - Administrator - Disabled) Gast (S-1-5-21-2279217210-3855026583-970737385-501 - Limited - Disabled) Ihsane (S-1-5-21-2279217210-3855026583-970737385-1003 - Administrator - Enabled) => C:\Users\Ihsane Rachid (S-1-5-21-2279217210-3855026583-970737385-1001 - Administrator - Enabled) => C:\Users\Rachid Thuis (S-1-5-21-2279217210-3855026583-970737385-1002 - Limited - Enabled) => C:\Users\Thuis ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Emsisoft Anti-Malware (Enabled - Up to date) {2F44E1F9-850B-1C7A-0E56-EB2E0A3E20C9} AV: McAfee Antivirus en antispyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} AS: Emsisoft Anti-Malware (Enabled - Up to date) {9425001D-A331-13F4-34E6-D05C71B96A74} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Antivirus en antispyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB} FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-2279217210-3855026583-970737385-1003\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden Adblock Plus voor IE (32-bit en 64-bit) (HKLM\...\{3156E6CF-341C-4BAB-BF93-DCE3B598C80D}) (Version: 1.4 - Eyeo GmbH) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team) AVEO UVC Like Driver (HKLM-x32\...\{21A196EC-241B-4A79-970B-E9585F1CE90C}) (Version: 2.7.0.0 - aveotek) B110 (x32 Version: 140.0.142.000 - Hewlett-Packard) Hidden BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.10.3096 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM-x32\...\{0BED0B96-70B8-4893-884B-DC485DC8C1B7}) (Version: 0.8.10.3096 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom NetXtreme-I Netlink Driver and Management Installer (HKLM\...\{47B8DBFC-2891-480C-92D6-92143AD0D027}) (Version: 16.8.2.1 - Broadcom Corporation) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.124 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Performance Advisor (HKLM-x32\...\{A41ED7E1-DDAB-46E0-98EE-963642D35443}) (Version: 1.2.2813 - Hewlett-Packard Company) HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 7 (HKLM\...\{014E482A-0C27-47E3-BA82-307E9DCA2F47}) (Version: 14.0 - HP) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Support Assistant (HKLM-x32\...\{E92D47A1-D27D-430A-8368-0BAFD956507D}) (Version: 5.2.9.2 - Hewlett-Packard Company) HP Support Solutions Framework (HKLM-x32\...\{69FD2930-C361-47F6-822E-71B021526778}) (Version: 11.50.0015 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden IBM SPSS Statistics 21 Developer (HKLM\...\{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}) (Version: 21.0.0.0 - IBM Corp) iCloud (HKLM\...\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden McAfee Total Protection (HKLM-x32\...\MSC) (Version: 14.0.1029 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.316 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Language Pack 2010 - Dutch/Nederlands (HKLM-x32\...\Office14.OMUI.nl-nl) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Network64 (Version: 140.0.212.000 - Hewlett-Packard) Hidden Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden NVIDIA Grafisch stuurprogramma 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation) NVIDIA nView 141.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 141.36 - NVIDIA Corporation) NVIDIA WMI 2.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.18.0 - NVIDIA Corporation) PS_AIO_07_B110_SW_Min (x32 Version: 140.0.142.000 - Hewlett-Packard) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6080 - Realtek Semiconductor Corp.) Scan (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0413-0000-0000000FF1CE}_Office14.OMUI.nl-nl_{2ABAC676-CF18-432C-B4B2-54F12AD59929}) (Version: - Microsoft) Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Syncios versie 4.1.9 (HKLM-x32\...\{068A5D84-8419-4BDE-9689-FE65F412EFBB}_is1) (Version: 4.1.9 - Anvsoft, Inc.) Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD) (Version: 10.0.50903 - Microsoft Corporation) Toolbox (x32 Version: 140.0.424.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2279217210-3855026583-970737385-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Thuis\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File ==================== Restore Points ========================= 24-04-2015 11:32:22 Windows Update 28-04-2015 18:08:00 Windows Update 01-05-2015 19:35:38 Windows Update 05-05-2015 18:14:35 Windows Update 09-05-2015 19:32:44 Windows Update 13-05-2015 19:28:44 Windows Update 13-05-2015 22:12:14 Windows Update 15-05-2015 16:27:44 avast! antivirus system restore point 15-05-2015 17:05:15 Removed Broadcom NetXtreme-I Netlink Driver and Management Installer. 22-05-2015 18:40:22 Windows Update 22-05-2015 22:08:01 Windows Update 29-05-2015 18:25:45 Windows Update 06-06-2015 18:15:45 Windows Update 12-06-2015 19:04:18 Windows Update 12-06-2015 22:29:27 Windows Update 15-06-2015 22:49:49 Windows Update 15-06-2015 22:58:46 Windows Update 16-06-2015 12:50:47 Installed Adblock Plus for IE (32-bit and 64-bit) 16-06-2015 13:16:45 avast! antivirus system restore point 16-06-2015 21:59:44 zoek.exe restore point ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0823BD5E-383F-4EE0-8CF5-BAEC2DFBC708} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation) Task: {132E5F12-F14D-41C0-9BF4-7D09C093ADC0} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {20B94E41-27C5-428F-95FE-0FE2E235FEB2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {223E5557-DC7A-455A-A1BC-8A813968CCED} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation) Task: {414A801D-90BB-4680-A482-CB9E0419DF1D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-02-23] (Hewlett-Packard Company) Task: {6AD0AE59-628C-4374-ADB4-06A68B82A532} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {78505558-C19B-4C69-A4FB-C83C62FC49BE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-12] (Adobe Systems Incorporated) Task: {8B9FB97F-CE17-4A34-9782-ACFFF6AA3BBC} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-02] (Microsoft Corporation) Task: {955A59FA-9E3A-43A6-B048-A411E209ACC1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21] (Google Inc.) Task: {964722AD-14F8-42BC-B589-3C02AC8819A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21] (Google Inc.) Task: {D222BC29-7491-49C3-A077-1631794FC29B} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {D309842C-FA63-4D82-B0A2-2B5EE0281684} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {EC730622-216E-4562-A771-5277AC33414B} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {FBE22C4B-6F62-4516-A192-E6EE2F4BB659} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-02-23] (Hewlett-Packard Company) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-04-20 21:14 - 2015-04-20 21:12 - 02692296 _____ () C:\Windows\system32\nvwmi64.exe 2011-05-31 05:54 - 2015-02-04 04:21 - 00115400 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2014-05-02 01:30 - 2015-04-20 21:12 - 00710288 _____ () C:\Program Files\NVIDIA Corporation\nview\nvshell.dll 2014-12-29 22:25 - 2014-11-27 15:38 - 00749056 _____ () C:\Program Files (x86)\Syncios\SynciosDeviceService.exe 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-12-29 22:25 - 2014-12-18 17:04 - 00386560 _____ () C:\Program Files (x86)\Syncios\DuiLib.dll 2014-12-29 22:25 - 2013-03-01 11:30 - 00059904 _____ () C:\Program Files (x86)\Syncios\zlib.dll 2014-12-29 22:25 - 2013-03-01 11:30 - 00526848 _____ () C:\Program Files (x86)\Syncios\sqlite3.dll 2014-12-29 22:25 - 2014-01-06 12:24 - 00671744 _____ () C:\Program Files (x86)\Syncios\hashab.dll 2014-10-11 14:05 - 2014-10-11 14:05 - 00237352 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2015-06-16 13:54 - 2015-06-05 20:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\libglesv2.dll 2015-06-16 13:54 - 2015-06-05 20:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2279217210-3855026583-970737385-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Ihsane\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{C962090A-B02C-4EE1-B1EB-59F018EF35E3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{DF26BDD8-F242-4746-8651-93CB7CB28BFE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{61EA7CC8-E296-42C6-8F15-F8ADB089F626}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{7C38D00F-94E9-44C0-8022-1DAD00AC41BA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{472A3AD3-19BA-41FB-B13D-1F90DDBA0D65}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{400675B8-29A0-4343-A035-2C150424C475}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{5ECDCEB3-86F0-4B70-8831-4F3D58B9C963}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{6368FE25-853C-41CA-ACE3-ED9B88F33F0A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{1A158031-1D4F-4A3B-BC9C-4B205CA29551}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{F07A44F8-5AB0-46A0-A1F7-3055673008D8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{9A8FF942-DB77-484A-891A-1267C15F2A4A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{5EE70384-6750-4EDB-8CF4-EFDC8724A178}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{076E4389-0BB2-4AE9-A252-425CCB14A0EC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{45082DB6-7AA3-4670-B370-CC7D00902CE1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{1ECF759A-65EB-433B-8BAD-1571021A31D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{0BE95691-A641-4C79-99D7-62A59F212E49}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{96BABDE2-96C3-4DB1-8A0A-BB78D3628D9B}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{C00A1D21-8AC9-4A64-8FAB-8DFD11784124}] => (Allow) C:\Users\Rachid\AppData\Local\Temp\7zS7C93\setup\hpznui40.exe FirewallRules: [{98F1D33A-D889-4421-A39E-786E80D28582}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{94B9B8D3-92CF-437D-8F48-F1DEEA80321D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{A0053EB6-364C-403D-A653-0A7FD3666449}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\stats.com FirewallRules: [{3D3D2FB1-5518-4E84-9A08-E9AC54E9706B}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\WinWrapIDE.exe FirewallRules: [{C83971A4-CD57-4990-B7A5-D1BA56747EE2}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\stats.exe FirewallRules: [{EE76B666-9491-4A14-A4B9-5CB3A41D3A80}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\stats.com FirewallRules: [{08378CBB-08C9-4694-8513-7B57F355C735}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\WinWrapIDE.exe FirewallRules: [{D5A9D9EB-7497-44E1-A07D-30C70EB59076}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\21\stats.exe FirewallRules: [TCP Query User{279F9CED-3C01-487E-8522-AC5EF7889F16}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe FirewallRules: [UDP Query User{9A862DE4-5016-43D9-AE01-9DF617D7D261}C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\21\jre\bin\javaw.exe FirewallRules: [{AA859DD8-7A8A-4615-AC6E-C421603AC0C3}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{231F6EB1-99FD-4F0D-B420-FA4C2ADCF0FF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{F8E33E64-C2A2-4DC0-A8B8-B78E94743785}] => (Allow) C:\Users\Thuis\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FA2A49BB-87B0-44D9-8D4B-BDD36B3B8DAC}] => (Allow) C:\Users\Thuis\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{B50DDE31-D2B1-447C-A276-1064853B8CCD}C:\users\thuis\desktop\mw2\codmw2mp\iw4m.exe] => (Allow) C:\users\thuis\desktop\mw2\codmw2mp\iw4m.exe FirewallRules: [UDP Query User{4BFE1F19-96CC-4A9B-9BB4-246E57CD737C}C:\users\thuis\desktop\mw2\codmw2mp\iw4m.exe] => (Allow) C:\users\thuis\desktop\mw2\codmw2mp\iw4m.exe FirewallRules: [TCP Query User{0BD040BA-6674-4D3A-AEDB-898E09CD92F3}C:\users\ihsane\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\ihsane\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{38DDBFA4-A964-4048-ACA9-F99FEE5466E3}C:\users\ihsane\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\ihsane\appdata\roaming\utorrent\utorrent.exe FirewallRules: [TCP Query User{7470F58E-B16C-466D-AD98-18D578A9C7FC}C:\users\ihsane\desktop\nieuwe map\mw2\codmw2mp\iw4m.exe] => (Allow) C:\users\ihsane\desktop\nieuwe map\mw2\codmw2mp\iw4m.exe FirewallRules: [UDP Query User{A967815F-B87F-43BD-8BA0-359B3E06C3A1}C:\users\ihsane\desktop\nieuwe map\mw2\codmw2mp\iw4m.exe] => (Allow) C:\users\ihsane\desktop\nieuwe map\mw2\codmw2mp\iw4m.exe FirewallRules: [TCP Query User{0482D6B9-8AB7-4095-B478-220374696EB5}C:\program files (x86)\modern 2\iw4m.exe] => (Allow) C:\program files (x86)\modern 2\iw4m.exe FirewallRules: [UDP Query User{FE132937-6D36-4BE9-ACAD-01005008C31A}C:\program files (x86)\modern 2\iw4m.exe] => (Allow) C:\program files (x86)\modern 2\iw4m.exe FirewallRules: [TCP Query User{71152BC2-3EC1-4478-9614-B452D208FF40}C:\users\thuis\appdata\roaming\utorrent\updates\3.4.3_40298.exe] => (Block) C:\users\thuis\appdata\roaming\utorrent\updates\3.4.3_40298.exe FirewallRules: [UDP Query User{F93A6E6B-FDD8-4605-9270-880612F1E782}C:\users\thuis\appdata\roaming\utorrent\updates\3.4.3_40298.exe] => (Block) C:\users\thuis\appdata\roaming\utorrent\updates\3.4.3_40298.exe FirewallRules: [{C88B5778-29D2-4852-A669-CB13A9BB6EE7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{E18D685F-7ABB-46DE-AA86-01D3A0FF0D12}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/19/2015 08:20:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/19/2015 08:20:08 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 10:51:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 10:50:44 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:59:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 09:59:03 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:53:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 09:53:30 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:39:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 08:25:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (06/19/2015 08:20:08 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: De BlueStacks Android Service-service is gestopt met de volgende foutcode: %%1064. Error: (06/18/2015 10:50:44 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: De BlueStacks Android Service-service is gestopt met de volgende foutcode: %%1064. Error: (06/18/2015 09:59:03 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: De BlueStacks Android Service-service is gestopt met de volgende foutcode: %%1064. Error: (06/18/2015 09:53:30 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: De BlueStacks Android Service-service is gestopt met de volgende foutcode: %%1064. Error: (06/18/2015 09:51:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Emsisoft Protection Service-service is onverwacht gestopt. Dit is 2 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/18/2015 09:51:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Software Protection-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 120000 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/18/2015 09:51:34 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Emsisoft Protection Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/18/2015 09:51:33 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De iPod-service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (06/18/2015 09:51:33 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Windows Search-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/18/2015 09:51:32 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De HP Health Check Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service opnieuw starten. Microsoft Office: ========================= Error: (06/19/2015 08:20:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/19/2015 08:20:08 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 10:51:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 10:50:44 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:59:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 09:59:03 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:53:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 09:53:30 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/18/2015 09:39:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 08:25:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: Intel(R) Xeon(R) CPU W3540 @ 2.93GHz Percentage of memory in use: 52% Total physical RAM: 6127.26 MB Available physical RAM: 2933.31 MB Total Pagefile: 12252.73 MB Available Pagefile: 8926.07 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:929.51 GB) (Free:682.91 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: CFBFEA5A) Partition 1: (Active) - (Size=2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=929.5 GB) - (Type=07 NTFS) ==================== End of log ============================