OTL Extras logfile created on: 10-12-2014 16:20:44 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rene\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17416) Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy 7,69 Gb Total Physical Memory | 5,29 Gb Available Physical Memory | 68,81% Memory free 8,87 Gb Paging File | 5,81 Gb Available in Paging File | 65,46% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 118,29 Gb Total Space | 83,44 Gb Free Space | 70,54% Space Free | Partition Type: NTFS Drive D: | 1862,89 Gb Total Space | 1650,41 Gb Free Space | 88,59% Space Free | Partition Type: NTFS Computer Name: PRAKTIJK-JR | User Name: Rene | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05381FFD-8432-438A-82A9-E1FB5E1F1AF2}" = lport=10243 | protocol=6 | dir=in | app=system | "{05D8523E-3EA1-438B-AA85-65610C9333EF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2AE9CEFC-BE3C-415E-8270-234D362A53DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{398684E0-AFFF-4BA0-988C-B4435E5010A4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{523F8663-A26E-4FC1-B9CA-8FABD774E888}" = rport=10243 | protocol=6 | dir=out | app=system | "{5344F9E8-B72C-4786-8D1F-6B258F6A9B5D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{80971F2A-0C0A-44AE-A571-35D6EE10AD58}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9C4D450A-261F-4FCB-8FD3-7EEC4424DA36}" = lport=2869 | protocol=6 | dir=in | app=system | "{A9515D1C-885C-415D-A7BE-024AD1E754CD}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner | "{B39E256F-76A8-4C59-8927-5F14A34B2088}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{CD40F4F6-3C16-465A-BEE0-009117FB3CC6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{F3F47C44-9E02-49BA-9A7B-A090685EF59C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{023C2C29-C565-4DFC-B114-765A13227164}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{055A0A7D-74B8-41D6-92F9-752DEFD8DC0F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{07D266F8-9C93-4892-A890-53065639224E}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{1320D737-F6AB-475F-B3C4-39761EDC30BD}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{16AF5D11-A268-4343-880F-ABE066698791}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{1705BB6F-6EDE-4BE9-8305-6B9C2A710267}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{1E0EFDCB-4371-4305-BE37-BF548ED66050}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{1F064B59-7E37-406A-87B0-5A61BD6ACC3A}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{202E1A01-E27F-4ABF-A076-9DC4A5186321}" = protocol=6 | dir=in | app=c:\program files (x86)\pervasive software\psql\bin\w3dbsmgr.exe | "{2CDF11BB-C0A6-45FD-8FB4-04EA2A27DCAF}" = protocol=17 | dir=in | app=c:\program files (x86)\pervasive software\psql\bin\w3dbsmgr.exe | "{2F263FD3-7DF5-4115-B76B-C2B94734591A}" = dir=out | name=onenote | "{2F6EF125-A6FF-41F9-A0C4-C9BB78857C05}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{3616E18C-3A5D-45D9-8726-881D2C56B17B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{37484893-A8E8-4278-B27E-8228E69699B0}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{39957B0A-69AF-4E7C-A5C5-6B85C0EA5AD4}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{418C53CD-7122-45FC-902C-070A4DE9FDB6}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{4E80A202-21EF-4B3F-BA94-EC99A107CF8E}" = dir=in | name=skype | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{5AC577BD-6B93-47B8-8BD1-E493791074F9}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{5BAC9484-0395-4633-888B-FDCCADE6F2EF}" = protocol=6 | dir=in | app=c:\users\rene\appdata\roaming\utorrent\utorrent.exe | "{5CB9CB11-3180-42FE-9752-AC725BD44FE3}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{62CC2609-8ABB-4A3A-933A-1B21A0E084E4}" = dir=out | name=windows_ie_ac_001 | "{63C5DE2E-6F0F-4658-9C43-D0993394D8D0}" = dir=out | name=@{microsoft.zunevideo_2.6.432.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{640CCCE5-778E-435D-ABAD-CEEADEFDE1C8}" = protocol=17 | dir=in | app=c:\users\rene\appdata\roaming\utorrent\utorrent.exe | "{642DE997-DD8C-4449-9FBC-CC8583D592CB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{676460EC-E832-42C7-A394-757337812ACF}" = protocol=6 | dir=in | app=c:\program files (x86)\brother\brmfl10f\faxrx.exe | "{6AFFD6DD-839D-452B-BFBF-3E065F881B96}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7439527E-E7C1-483B-9A88-FABC9A36B7EF}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{7A5D53AD-9470-408D-993D-9074FEDB7669}" = protocol=6 | dir=out | app=system | "{7EE9B1A7-F69E-418A-B830-EAF8927377C6}" = dir=in | name=check point vpn | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{85A36676-950B-47CB-A654-597C3CA922FA}" = dir=in | name=f5 vpn | "{886B8136-92D7-4470-8763-34D9BA7C5C36}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{8A6DDAA5-3FF2-4FC6-9AFC-86BFB857B1B3}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{8DEEFE86-2230-403B-AF59-DF7236B237C9}" = protocol=6 | dir=in | app=c:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe | "{9180BDD6-DAB7-46C0-AF6F-0C735423EA4C}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{9AEBE4EE-855C-470C-A066-C44C0140D156}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{9ECB4AC6-F091-49A6-AF42-C40CFE418919}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{9F8F4FF3-1AF7-48C4-A975-D132EBAA274F}" = dir=out | name=f5 vpn | "{A866F146-82EA-4AE5-98C2-0C41E2FA5576}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{A8C54EA9-A6C2-4CF0-8594-8CAB3F2723C2}" = protocol=17 | dir=in | app=c:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe | "{A9A8319A-A762-488B-B25D-A0CE7061B302}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{A9CBA4DB-3190-4FD9-8EE5-DA48F0541533}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{AAD959E7-8BFA-4305-AC5F-A97F8C8846D3}" = dir=in | name=sonicwall mobile connect | "{B30F060B-82C1-4AC8-A7EF-9C7444B06DE6}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{B316ACE7-8657-4E06-B76B-6820A697F694}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B3D688D0-1E9A-4ECC-992F-BE0685F7AB6F}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{B44E0DEC-C0B4-41D0-917D-2DD3C6CFC101}" = dir=out | name=sonicwall mobile connect | "{BC228637-7C63-4DCA-9683-12D39B68AC8C}" = dir=out | name=skype | "{BEF3B2FB-1C71-4506-B3F3-371FC259D1BD}" = protocol=17 | dir=in | app=c:\program files (x86)\brother\brmfl10f\faxrx.exe | "{BF53A22C-6AAC-40B7-9E47-DC645FB58A0B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{C3C9B499-9310-473A-9A38-93435D7486F7}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{C3CD0E36-C672-4642-A56B-56254938C266}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{C54B5066-8E7C-40D4-99E7-A741DFE01F9A}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{C58C7BF7-4B71-450E-BF7C-8CFBA132F7C2}" = dir=out | name=check point vpn | "{CF370A93-EFA6-4807-98E3-0DFDBF645D42}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D1E5CB36-1E79-40DE-8300-9DFB39FCA21D}" = dir=out | name=windows_ie_ac_001 | "{D3E2326D-E81F-4402-AF17-4ED0CDA56CFD}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D778EB46-6143-474D-983F-1E6D5542BD68}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D7AF46CC-6BAC-45ED-8732-9463741E3C10}" = dir=in | name=onenote | "{D9029F3E-BF22-4476-944A-AE0990D416AC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{DA06CC49-99E5-4A1C-9C01-FA5AE37459A0}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{DC2BDD7F-108A-48FF-B539-600112756FAD}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{DE27DC71-F0D3-45E7-B39E-F40556696C8F}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{E2C3FCB8-5B2F-49B9-BA65-6D23D9E81467}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E8F2544F-DAC1-49AF-ABA9-8B4FDF9D08C6}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{E945317A-D1E2-4C3D-8DB2-E81EE8BC6D06}" = dir=in | name=juniper networks junos pulse | "{E988FC09-0714-4108-B5DA-1EEE791AF647}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{F402F520-9536-496D-BD17-41D45AC85C57}" = dir=out | name=juniper networks junos pulse | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F7EE808D-EC64-489A-96A5-09D58497DF33}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F82C0825-01D5-47D8-9ACF-1A8574C51118}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "TCP Query User{59FD1FD6-DA06-4B2A-91F3-ACF68693BE68}C:\program files (x86)\synology\assistant\dsassistant.exe" = protocol=6 | dir=in | app=c:\program files (x86)\synology\assistant\dsassistant.exe | "TCP Query User{9CEEFA15-CAF6-4895-9096-6A56CE16D428}C:\users\rene\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\rene\appdata\roaming\spotify\spotify.exe | "TCP Query User{DC6CB33E-239F-4B41-A78D-8C93F4C1306D}C:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{51F0F157-1FE7-4ED2-9C7A-A64714E24D05}C:\program files (x86)\synology\assistant\dsassistant.exe" = protocol=17 | dir=in | app=c:\program files (x86)\synology\assistant\dsassistant.exe | "UDP Query User{7CDBF63D-BF72-4B47-BA14-D381926C2138}C:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\rene\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{A171EB74-F83B-45E6-96AF-CDE6F624F7A1}C:\users\rene\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\rene\appdata\roaming\spotify\spotify.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0413-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Dutch) 2007 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "ASRock XFast RAM_is1" = ASRock XFast RAM v2.0.28 "CCleaner" = CCleaner "HitmanPro37" = HitmanPro 3.7 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0A3238D7-AB32-1030-B717-F3E3F18B4A8C}" = Pervasive PSQL v10 SP3 Workgroup (32-bit) "{11D08055-939C-432b-98C3-E072478A0CD7}" = PSE10 STI Installer "{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer "{26A24AE4-039D-4CA4-87B4-2F83218025F0}" = Java 8 Update 25 "{26F54DF4-CF84-4BD2-A3ED-A4CC7CCF3492}" = ITbrain Agent "{2B4B4082-8043-4646-8334-B0A29E641211}" = Adobe Illustrator CC 2014 "{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 "{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite MFC-7460DN "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{55BF7E3E-F00A-4A3D-BB76-09228B35FFD6}" = ABN AMRO e.dentifier2 software "{65D723DD-8568-46CA-BAAC-12F2EE99E68C}" = Intramed "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{90120000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2007 "{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007 "{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007 "{90120000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2007 "{90120000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2007 "{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007 "{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0413-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Dutch) 2007 "{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007 "{90120000-00A1-0413-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2007 "{90120000-00BA-0413-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Dutch) 2007 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1043-7B44-AB0000000001}" = Adobe Reader XI (11.0.09) - Nederlands "{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{CCDCB9C4-72BA-1014-A3F8-D123F2F18BC2}" = Adobe InDesign CC 2014 "{D95E6F4F-C11C-42B8-94F0-D59A0CBCA22D}" = ITbrain Agent "{EE549AF9-8FAA-4584-83B2-ECF1BC9DC1FF}" = Adobe Photoshop Elements 10 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F12000FE-0001-0000-0000-074957833700}" = ABBYY FineReader 12 Professional "Adobe AIR" = Adobe AIR "Adobe Photoshop Elements 10" = Adobe Photoshop Elements 10 "Ashampoo Burning Studio 6" = Ashampoo Burning Studio 6 "ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.407 "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "DAEMON Tools Lite" = DAEMON Tools Lite "ENTERPRISE" = Microsoft Office Enterprise 2007 "Google Chrome" = Google Chrome "ITbrain Agent" = ITbrain Agent "KeePass Password Safe_is1" = KeePass Password Safe 1.28 "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware versie 2.0.4.1028 "Pervasive PSQL v10 SP3 Workgroup (32-bit)" = Pervasive PSQL v10 SP3 Workgroup (32-bit) "QuickPar" = QuickPar 0.9 "Synology Assistant" = Synology Assistant (remove only) "TeamViewer 9" = TeamViewer 9 "WinRAR archiver" = WinRAR "ZHPDiag_is1" = ZHPDiag 2014 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3158923719-191908326-2329777105-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Spotify" = Spotify "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 25-11-2014 04:51:50 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 25-11-2014 08:42:52 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-LocationProvider | ID = 2006 Description = There was an error with the Windows Location Provider database Error - 28-11-2014 22:50:19 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 28-11-2014 22:50:19 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 5-12-2014 12:25:39 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 5-12-2014 12:25:40 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 5-12-2014 12:45:17 | Computer Name = Praktijk-JR | Source = Application Error | ID = 1000 Description = Naam van toepassing met fout: dsisetup13030414372.exe, versie: 0.0.0.0, tijdstempel: 0x2a425e19 Naam van module met fout: dsisetup13030414372.exe, versie: 0.0.0.0, tijdstempel: 0x2a425e19 Uitzonderingscode: 0xc0000005 Foutmarge: 0x00002810 Id van proces met fout: 0x1cf0 Starttijd van toepassing met fout: 0x01d010aad847ec1e Pad naar toepassing met fout: C:\Users\Rene\AppData\Local\dsisetup13030414372.exe Pad naar module met fout: C:\Users\Rene\AppData\Local\dsisetup13030414372.exe Rapport-id: 17894821-7c9e-11e4-be71-bc5ff47122ab Volledige pakketnaam met fout: Relatieve toepassings-id van pakket met fout: Error - 5-12-2014 12:54:32 | Computer Name = Praktijk-JR | Source = COM | ID = 18221 Description = Error - 5-12-2014 13:13:03 | Computer Name = Praktijk-JR | Source = VSS | ID = 8194 Description = Error - 5-12-2014 13:22:55 | Computer Name = Praktijk-JR | Source = Microsoft-Windows-LocationProvider | ID = 2006 Description = There was an error with the Windows Location Provider database [ System Events ] Error - 8-12-2014 10:24:12 | Computer Name = Praktijk-JR | Source = Service Control Manager | ID = 7030 Description = De PEVSystemStart-service staat aangeduid als een interactieve service. Het systeem is echter zodanig geconfigureerd dat interactieve services niet zijn toegestaan. Deze service werkt mogelijk niet juist. Error - 8-12-2014 10:24:13 | Computer Name = Praktijk-JR | Source = Service Control Manager | ID = 7030 Description = De PEVSystemStart-service staat aangeduid als een interactieve service. Het systeem is echter zodanig geconfigureerd dat interactieve services niet zijn toegestaan. Deze service werkt mogelijk niet juist. Error - 8-12-2014 10:24:13 | Computer Name = Praktijk-JR | Source = Service Control Manager | ID = 7030 Description = De PEVSystemStart-service staat aangeduid als een interactieve service. Het systeem is echter zodanig geconfigureerd dat interactieve services niet zijn toegestaan. Deze service werkt mogelijk niet juist. Error - 8-12-2014 10:24:13 | Computer Name = Praktijk-JR | Source = Service Control Manager | ID = 7030 Description = De PEVSystemStart-service staat aangeduid als een interactieve service. Het systeem is echter zodanig geconfigureerd dat interactieve services niet zijn toegestaan. Deze service werkt mogelijk niet juist. Error - 8-12-2014 10:34:28 | Computer Name = Praktijk-JR | Source = Service Control Manager | ID = 7009 Description = Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Optimizer Pro Crash Monitor. Error - 8-12-2014 14:22:31 | Computer Name = Praktijk-JR | Source = Schannel | ID = 36887 Description = Een melding van een onherstelbare fout is ontvangen van het externe eindpunt. De door het TLS-protocol gedefinieerde meldingcode van de onherstelbare fout is 20. Error - 8-12-2014 16:18:23 | Computer Name = Praktijk-JR | Source = Schannel | ID = 36887 Description = Een melding van een onherstelbare fout is ontvangen van het externe eindpunt. De door het TLS-protocol gedefinieerde meldingcode van de onherstelbare fout is 20. Error - 8-12-2014 19:09:34 | Computer Name = Praktijk-JR | Source = Schannel | ID = 36887 Description = Een melding van een onherstelbare fout is ontvangen van het externe eindpunt. De door het TLS-protocol gedefinieerde meldingcode van de onherstelbare fout is 20. Error - 9-12-2014 14:27:49 | Computer Name = Praktijk-JR | Source = Schannel | ID = 36887 Description = Een melding van een onherstelbare fout is ontvangen van het externe eindpunt. De door het TLS-protocol gedefinieerde meldingcode van de onherstelbare fout is 20. Error - 10-12-2014 00:42:14 | Computer Name = Praktijk-JR | Source = Schannel | ID = 36887 Description = Een melding van een onherstelbare fout is ontvangen van het externe eindpunt. De door het TLS-protocol gedefinieerde meldingcode van de onherstelbare fout is 20. < End of report >