OTL Extras logfile created on: 26/02/2017 10:50:47 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\ 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17031) Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy 7.90 Gb Total Physical Memory | 6.28 Gb Available Physical Memory | 79.44% Memory free 15.90 Gb Paging File | 14.07 Gb Available in Paging File | 88.49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 167.34 Gb Total Space | 81.92 Gb Free Space | 48.95% Space Free | Partition Type: NTFS Drive D: | 931.51 Gb Total Space | 926.11 Gb Free Space | 99.42% Space Free | Partition Type: NTFS Drive F: | 931.48 Gb Total Space | 925.59 Gb Free Space | 99.37% Space Free | Partition Type: NTFS Drive G: | 931.39 Gb Total Space | 652.69 Gb Free Space | 70.08% Space Free | Partition Type: NTFS Drive J: | 69.48 Mb Total Space | 58.37 Mb Free Space | 84.01% Space Free | Partition Type: FAT Drive K: | 931.19 Gb Total Space | 871.21 Gb Free Space | 93.56% Space Free | Partition Type: NTFS Drive L: | 59.59 Gb Total Space | 57.04 Gb Free Space | 95.71% Space Free | Partition Type: exFAT Computer Name: LEVEL-PC | User Name: Hubert | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\WINDOWS\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\WINDOWS\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWow64\mshta.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf[@ = inffile] -- C:\WINDOWS\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\WINDOWS\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\WINDOWS\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\WINDOWS\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\WINDOWS\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\WINDOWS\SysNative\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- .wsf[@ = WSFFile] -- C:\WINDOWS\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\WINDOWS\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\WINDOWS\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWow64\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf [@ = inffile] -- C:\WINDOWS\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\WINDOWS\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\WINDOWS\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\WINDOWS\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\WINDOWS\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\WINDOWS\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\WINDOWS\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\WINDOWS\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- .wsf [@ = WSFFile] -- C:\WINDOWS\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\WINDOWS\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-968216198-1619183050-819724312-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWow64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- vbsfile [open] -- vbsfile [print] -- wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWow64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- vbsfile [open] -- vbsfile [print] -- wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== System Restore Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C16A150-2A85-4A75-A07E-0F40AB3FF1C2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{19C4F65E-CCAF-4AC0-AE5F-0A14A34F6A6F}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{22FF0810-804D-4CEE-A6A1-61B64B158CF4}" = rport=137 | protocol=17 | dir=out | app=system | "{311B58E3-62E4-408A-9E30-D52500856754}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3F417902-30FF-49AB-AB45-160B157DA5A4}" = lport=138 | protocol=17 | dir=in | app=system | "{4C2FDA15-4434-4D55-80FA-3CD40B2E1304}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe | "{4D7FC065-2058-4907-A3EB-EFFC13DEEAA6}" = lport=5357 | protocol=6 | dir=in | name=ws-eventing tcp-poort 5357 | "{4DD0AE74-3B60-43EA-8C03-4837D83085A6}" = rport=138 | protocol=17 | dir=out | app=system | "{4EBCF0FD-AEF1-4F02-A495-4E35DABEB27C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4EECAEC7-F9E2-4E5B-88FE-C15041BEAAA7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{559970AC-1B63-44D5-A47A-D1C1AEE1387B}" = lport=10243 | protocol=6 | dir=in | app=system | "{57BDE062-6AA0-402F-A42D-F85EBB642BC8}" = lport=137 | protocol=17 | dir=in | app=system | "{61BF9E70-49CB-4931-9FCB-5D41CAB797BD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6441A857-2BE2-4F80-9CD3-D4938E6718C9}" = rport=445 | protocol=6 | dir=out | app=system | "{6A6029CF-6A90-4DB0-98BC-CED3081D0D37}" = lport=2869 | protocol=6 | dir=in | app=system | "{6D59CBDB-2B46-4FEC-B78F-EA79758325F9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{86B8CA50-B459-4E0F-9C97-3CE2E4D7242F}" = rport=139 | protocol=6 | dir=out | app=system | "{8C820063-E024-4569-8CF1-566D76AD0973}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8CDACEA5-DB42-4872-93D9-AD24315773C6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{94CC00C2-03E3-46D4-834E-CA95C9EDEEE6}" = lport=445 | protocol=6 | dir=in | app=system | "{9A0012EF-F83D-4BA2-84C5-52553771C48F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9FB8A9F2-6F33-4D5E-9EB0-3518E8674698}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9FF876A7-E40A-47E5-BFBA-68F4057138AD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C29B272B-3080-4421-8541-7C7D943B30FE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C2D1A823-95FC-4BE3-846A-37ABE0DB6E09}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C82B0CEF-7D54-46C9-9248-8862A0E68671}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CD417129-40AB-4539-9A24-8DCE1B7C43E8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D0A77F89-C027-4A61-8714-5D2BDC7CC81D}" = rport=10243 | protocol=6 | dir=out | app=system | "{D100A445-0CA3-40BA-B3A2-043CD48C88C2}" = lport=139 | protocol=6 | dir=in | app=system | "{D45F9354-D5BA-48FD-B109-6F9491D41D89}" = rport=10243 | protocol=6 | dir=out | app=system | "{D6939409-49D1-42D4-A52D-E55689991D09}" = lport=2869 | protocol=6 | dir=in | app=system | "{E6F28E8D-EAAC-42C9-9F3E-AFA70969C183}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{F4CA97EA-40DB-4C53-B8F1-5C0A4C1382ED}" = lport=10243 | protocol=6 | dir=in | app=system | "{F7D1193F-71F1-4FB4-90FD-DCBC1E86F633}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F85938EE-89BF-465F-8994-50CBC6D4C0C1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0209B7DB-2D8A-46F0-8954-9007998EE065}" = dir=in | app=c:\program files (x86)\common files\acronis\mobilebackupserver\mobile_backup_server.exe | "{026993A5-E0DA-48CD-B2A9-E3C67CA24FAA}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{061D4942-C1FE-4659-9A4B-01DB2F99D0A8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{06A2709F-7B78-49FC-A7FE-AA2626E23B0E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0725483C-4D95-4CC3-9B83-63F53FDCD41F}" = dir=out | name=@{microsoft.bingmaps_2.0.2009.2356_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{07C60E9E-8BCF-41A8-BAA3-12E3C6CFC7F1}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0B73DFDF-63B7-4123-B4B0-711D4E91E9EF}" = protocol=17 | dir=in | app=c:\program files\common files\common desktop agent\cdasrv.exe | "{0D7ACA47-DAA3-49B8-9DE7-07B0702D92A6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{137E8B30-2159-4DAF-A74C-F89904DAD30E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{13D31CAD-10D8-454B-BECE-CB657F29DBA4}" = dir=in | app=c:\program files (x86)\common files\acronis\mobilebackupserver\mobile_backup_server.exe | "{172AB6FB-6478-41E5-B2FB-83ECAEF54BCD}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{176B159C-4785-4843-B1DC-7C0BA8EAF4B3}" = dir=out | name=@{microsoft.bingweather_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{18BA6510-A74C-46E5-8DA8-5C0850AA88B0}" = dir=out | name=@{microsoft.bingsports_3.0.4.345_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{1912C3E4-2315-4DFE-A3AE-C29389573725}" = protocol=6 | dir=out | app=system | "{1D05CC39-0900-4A30-B9C7-1166A1809F75}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{2071E4F4-E9E9-4957-9C15-4A7B85EB4C34}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\cdas2pc\cdas2pc.exe | "{209FEB39-A286-4780-B131-AF8FF6FBBEC7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2513B592-D076-4681-8813-3C250BDDB10B}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{2947272A-4F67-4A0F-A825-E1B7D81B7F12}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2C1D8AB5-B567-44B6-9591-4564108FDC46}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2E44855B-F20E-4F1E-9E16-31E6B760DA77}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\uninstall.exe | "{31870FC6-0097-4DB8-8973-9509BCE2BD21}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{33FA78CF-D105-4576-8216-DFE34C56542C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3685174B-890A-4277-9A90-751D67C8CA18}" = dir=out | name=samsung printer experience | "{3688B67B-4F80-4433-88C4-47D683E47665}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{37276B49-71F2-4A57-996C-0F41A01A06E9}" = dir=out | name=windows_ie_ac_001 | "{383EA6B7-B9C9-42C8-88DE-5CDFAE2CC35A}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{38990E57-7802-48F1-82B3-A226AA6B112F}" = dir=out | name=@{microsoft.bingnews_3.0.2.261_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{3952F480-F565-4D6B-A306-491FDE4A38DC}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ids.application.exe | "{39E7E0D3-936A-4A04-B047-960D205A98A5}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{3ACE5822-1254-44D4-85DB-262C07F80886}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{3B8902D3-825D-42D1-96EF-469C94301132}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe | "{3D31450F-3DA6-42B7-82E8-A2AA379F4FA8}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "{3F9EBDA7-9604-4EBF-A0FF-A5BC3AFFE8EC}" = protocol=6 | dir=out | app=system | "{402C24D5-8AC2-40AC-8DB4-3EA99B2F8973}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ordersupplies.exe | "{41CE4680-0EC3-4F8A-A202-8E38AC337B89}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{44BB7C9B-C61A-4010-8DD7-86C82B6BB080}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\cdas2pc\cdas2pc.exe | "{465628FA-6520-4B40-987D-770A3BA92BFF}" = dir=out | name=@{microsoft.zunevideo_1.5.299.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{46BFF788-8608-45A7-95F2-DD8C709C18A6}" = dir=in | app=c:\program files\hp\hp envy 5530 series\bin\hpnetworkcommunicatorcom.exe | "{47C7C7BC-82CA-48FC-8ABA-F1D7F0634004}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{4874C88D-9518-4FA8-9363-7E61A91E3FC8}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{4AB61431-CEE5-418F-98D9-C0C46D0251C9}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{4D9C554A-E50B-4348-82FD-B933CCFBB93A}" = dir=out | name=@{microsoft.bingtravel_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{4FF1D99A-2049-4B2E-982D-301632A432D9}" = dir=in | name=skype | "{5158FFA2-3057-4AE7-8DAA-7D7DAE2DFB94}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{524BB6C5-725B-4263-A028-72D5D3374F1A}" = dir=out | name=check point vpn | "{53E6A834-EFE9-4C24-AA13-5F766BF7ED88}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{547DD2F1-8617-453E-AE6A-A454CC0A9F9C}" = protocol=6 | dir=in | app=c:\program files (x86)\applian technologies\replay music 7\jrmp.exe | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{55A97FDA-19C0-48D5-B591-C7A794920EF5}" = dir=in | app=c:\program files (x86)\iobit\advanced systemcare\surfing protection\ffnativemessage.exe | "{55CF7247-D60C-46E5-B4EF-4447A8B681BB}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{563AFB26-ED39-4C1F-881A-D2CCF0CBFC69}" = dir=out | name=@{microsoft.bingnews_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{5F469EE9-888B-4C55-9418-8CADE9CB2AE3}" = dir=out | name=@{microsoft.bingfinance_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{604F5CC0-6D29-43F3-B453-922E4ECCA056}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{615BE989-41AB-4CDC-ADE5-BA8B29FBBB0A}" = dir=in | app=c:\program files (x86)\common files\acronis\mobilebackupserver\mobile_backup_server.exe | "{62C0D405-6F55-4B32-A37E-41106B2995BD}" = dir=out | name=@{microsoft.xboxlivegames_2.0.20.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{6421BBE9-11B8-4EC8-A1EB-F810DA72F37B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{64EAD18C-E37E-40D7-9400-73E6FFAE4941}" = dir=out | name=@{microsoft.zunevideo_2.6.446.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{64FA1996-EF78-4CCD-A803-3EB4DCEB43B7}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{65A814E8-505D-4705-84D0-148169801D97}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{6604ACBE-0CE6-4814-AAB3-9CDB4526FFD0}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.1.177_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{66BE11F1-510F-4C1D-AA61-D7B97206CFEE}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{676C940D-A76E-48D0-A9EB-44AAE81FA618}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{6A0C0F6B-AC48-4E23-9045-4D15375D04E0}" = dir=in | app=c:\program files (x86)\common files\acronis\mobilebackupserver\mobile_backup_server.exe | "{6B6B9971-92E3-466F-A84D-F190184EE7D4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6C1FBD3E-8D21-4266-A6EF-8FC4180DD04A}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{6F1E7465-1496-453C-89A0-C6C1303F0588}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{7153262C-0FA8-4F56-AE53-2F671A9D8D6E}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{7227E9FF-3723-449C-9E6F-6F2DF2EA40B9}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{73B5F273-398A-4077-B80E-9D7A32E8CDED}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\uninstall.exe | "{765121A1-9431-4E6A-92DD-D958537A1DAF}" = dir=out | name=@{microsoft.bingtravel_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{7A3B460E-9D6F-4879-BC57-2C11803EE29C}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{7D2D643A-1820-4E3F-89CE-C3763DA22F6D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{802FF96A-FA86-4D59-9CEB-AAD4553AF214}" = dir=out | name=canon inkjet print utility | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{825D49C5-2820-4419-B39D-BB0897AD2DFB}" = protocol=17 | dir=in | app=c:\program files (x86)\applian technologies\replay music 7\jrmp.exe | "{83AFA28E-E694-40E0-A6AD-919E6E346645}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\idsalert.exe | "{850FB24E-DFBA-489C-B8DA-B50B2CD2261E}" = dir=out | name=@{microsoft.zunemusic_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{85F97409-3DDE-458F-8D0D-B9BF122645E8}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{86744785-EEC4-48B1-B60F-82DCA245DD72}" = dir=out | app=c:\program files (x86)\iobit\advanced systemcare\surfing protection\ffnativemessage.exe | "{8FA03135-9F09-4044-8761-F260A610CB9F}" = dir=in | name=samsung printer experience | "{8FECBC43-E388-4113-B617-590DD9C09AD1}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{90CC338D-31A3-46E2-91FC-28B0DB933CEE}" = dir=in | name=skype | "{9164CE01-BF6D-4D76-B1B0-F99C49D8062C}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{937380C9-4436-4FB4-8F20-4A77D34E5E55}" = dir=out | name=@{microsoft.zunemusic_1.5.214.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{93B6CFE3-9C7D-410E-AC33-58B9B36F533E}" = dir=out | name=juniper networks junos pulse | "{94BA28DB-8C6D-4117-98EE-B7FBDDBF3890}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{94BD52DF-D1DE-4947-ACAF-75AF674C7731}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{97B7AB73-02FF-4E64-8AD5-C3CF114E6FBB}" = dir=out | name=@{microsoft.bingnews_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{9965CB1E-7292-4F41-B445-2D86C9037D6E}" = dir=out | name=samsung printer experience | "{9A2F6825-9EC1-4A86-B65D-A7FA5EE9E487}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ordersupplies.exe | "{9C292D06-5335-4EC3-9D36-8BB471BF7FE9}" = dir=out | name=@{microsoft.bingfinance_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{9F1A3B32-C3E1-40F7-AD14-8AD90DCF3365}" = dir=out | name=@{microsoft.bingtravel_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{A02306F9-FB26-4FD4-8F64-B75E133CBE33}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A05CC6EE-E547-407F-9EBC-FFAD32EFB060}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{A1E7A6FC-40E2-42A7-B5AE-6447846BE090}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe | "{A1FF8D38-05C6-4573-8E98-28EB48C9C49D}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{A32BAB51-6C69-41EC-9DDC-04F6B30168AE}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{A7EB2A13-AD8C-4C24-AD55-E2EA980E1BC7}" = dir=out | name=@{microsoft.bingtravel_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{A8EA8FCE-4E08-415D-B8E0-B0E2F0995031}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AA0D93CD-20D4-49F4-A7D3-F2F1E7026681}" = dir=in | name=juniper networks junos pulse | "{AB7E9AB8-25E9-4FBA-A734-C9C9AC0D00E6}" = protocol=6 | dir=in | app=c:\program files\common files\common desktop agent\cdasrv.exe | "{AD381641-57C1-4D76-BF6E-D870991EABBF}" = dir=out | name=@{microsoft.bingfinance_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{AF416682-01B1-41FE-A3D9-C6F290253754}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{AFA319BC-7E51-4B79-8141-F88F0F9BF982}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{B0A56FBB-B658-4962-A20B-C1441F55ED90}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "{B1476847-1BD3-4309-9917-615C1B001B81}" = dir=out | name=@{microsoft.bingweather_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{B37483C5-8B21-4178-8AF0-C9ED18D823DF}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{B41396F5-2E89-45E5-B5C3-4873396C454C}" = dir=out | name=@{microsoft.zunemusic_2.2.902.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{B4CAD245-DD01-4A1A-8F18-5A31ADD13659}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B7E17F99-E727-430E-9373-46F56A15B586}" = dir=out | name=@{microsoft.zunevideo_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{B8CB1106-F906-4834-A511-F92200F95CAE}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{B9B88661-9B6D-41F6-ABE6-F43048531558}" = dir=out | name=winzip for windows 8 | "{BBAC305B-7CD3-4A3F-88E9-8A668BBC353B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{BC3F0BEE-6733-40B4-98CA-FB4385481B72}" = dir=out | name=@{microsoft.zunemusic_2.6.672.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{BE2FE10F-BFE7-40B6-9661-D59738576B06}" = dir=in | name=check point vpn | "{C0A6FE5E-06E4-4EFE-9449-6FEF41052543}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C126790F-1479-49CA-8511-6B4509DC7F56}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{C166BAB6-C94C-4B0C-9F1D-FEB738A997AB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C24521AD-BA84-49EE-9D1D-20F0F7B91AD1}" = dir=in | name=f5 vpn | "{C272D115-82F8-4AFB-AE13-8DF8E26D9E92}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{C28E8345-1836-4FFC-AF36-88E82FB8442E}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{C3433546-3960-4746-8714-421B3DCA1924}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{C3EBC8C3-D07A-48DD-BB31-5C1B90B5263A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C75BF0B9-A750-4CA1-BF5B-CBF6505E676E}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ids.application.exe | "{C84421F7-647F-4DEB-93A9-7337B6163F8B}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{D01F099D-6B72-411E-A340-DC1F856F1DB8}" = dir=out | name=@{microsoft.bingweather_3.0.4.350_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{D20E4646-DD59-4ABB-BE18-5CEF378FCA6B}" = dir=in | name=canon inkjet print utility | "{D44447B5-F043-4E94-B6F7-3E4BE0C5FD5F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D64E7F6A-950F-41C7-80FD-DCA00811D3BD}" = dir=out | name=sonicwall mobile connect | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{DA1BBC98-EB79-4A3F-BF69-C1CC476E7C33}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.1.176_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{DA20EC75-1C25-45C5-BEAC-EB35A4234E9B}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{DAF0E82B-68BA-4DFB-8B02-4883647153B3}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{DEC1F62D-9BDD-4648-B9A6-D376CA404D1A}" = dir=out | name=@{microsoft.bingsports_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{E2597E99-AEF1-4630-89C0-A1B1DC071376}" = dir=in | name=samsung printer experience | "{E29BE5A7-07DE-40D2-974F-01EFE2EC484A}" = dir=out | name=f5 vpn | "{E5787E9B-7E31-495C-A64F-865F9714C930}" = dir=in | app=c:\program files\hp\hp envy 5530 series\bin\devicesetup.exe | "{E5E9A699-1CF7-40D8-ACC7-0BD2CA166769}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe | "{E6761ECC-87BB-4CBE-A29A-1B75C98B7792}" = dir=out | name=windows_ie_ac_001 | "{E77E2F84-3A96-4698-A0E0-53AC75B5AA06}" = dir=out | name=@{microsoft.bingnews_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EB06FF7C-1AC5-4970-AF72-CE08FF95253F}" = dir=in | name=sonicwall mobile connect | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{ECFAFA78-C3A8-4660-AC75-7C4DB3ADC4D1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{ED0A56D2-D2DC-43D9-98B5-6FE0473B302C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{ED5E965A-BF6E-43E5-9315-BB89E7A8DC77}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{ED807402-BF6D-4888-ACEE-089BD71E5765}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F09F2A64-5157-4465-BCAC-6C03F4B7D755}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{F0E9A5A8-665C-4D34-B8C7-09C171CB99A3}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\idsalert.exe | "{F2FB70DE-B167-4F29-A282-CE24EACE5AC2}" = dir=in | app=c:\program files (x86)\common files\acronis\infrastructure\mms_mini.exe | "{F460A4C3-06A0-4302-8FCC-DC0EF126D025}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F55FE2E3-9C5B-432E-9DD3-32AE7B7B9DC5}" = dir=out | name=skype | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F8709567-33D0-46E9-AA4F-AC18CFB54595}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{FA20E800-2B00-4900-806B-9502533CADEF}" = dir=in | app=c:\program files (x86)\acronis\trueimagehome\mobile_backup_status_server.exe | "{FC1759E7-36E8-46F4-82F1-D402E08C41B7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FD743C71-C693-46E9-A09E-B60CF7C87192}" = dir=in | app=c:\program files (x86)\common files\acronis\syncagent\syncagentsrv.exe | "{FDA74D92-F038-479B-A35C-1967D104693C}" = dir=out | name=skype | "{FDBF22E2-B6B1-4194-A4EB-10F4FDD5563A}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{FDEC5F79-CE9F-4B5E-BA1D-391E0C522F3D}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "TCP Query User{1DF91BDA-60EE-4BD8-BBC8-6D54B9D169C5}C:\users\hubert\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\hubert\appdata\roaming\spotify\spotify.exe | "TCP Query User{3C759559-A63D-4638-A25A-B10A58BF6696}C:\users\hubert\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\hubert\appdata\roaming\spotify\spotify.exe | "TCP Query User{6E05F9D7-89B9-47CE-BFFB-D2F50B9F44B5}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "TCP Query User{ADC566FD-1CEB-43AB-9722-2AA90FB498EF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "UDP Query User{5D1D3E2E-C837-480B-9BBC-7F2DFC96BBF2}C:\users\hubert\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\hubert\appdata\roaming\spotify\spotify.exe | "UDP Query User{6A6272C9-FC28-47CD-A966-825A63DA2647}C:\users\hubert\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\hubert\appdata\roaming\spotify\spotify.exe | "UDP Query User{9ADB01E8-261A-476C-A8A2-954F2977C0A2}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "UDP Query User{B41C78C6-8680-45D7-8268-6DA1F1B2462A}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{031A0E14-0413-4C97-9772-2639B782F46F}" = Common Desktop Agent "{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer "{08FB88A2-3FB6-4E82-AD55-393EBAD0E967}" = Productverbeteringsonderzoek voor HP Deskjet 2540 series "{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{2368907C-E8F6-4750-A023-254C3E2B5E8D}" = Classic Shell "{24F88BAE-96B6-4D18-BDCC-E1746EBD30C6}" = HP ENVY 5530 series Basissoftware van het apparaat "{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}" = Microsoft SQL Server 2008 Native Client "{2B7A8C9C-465A-42F0-B9C3-180FDAAB2C4B}" = Intel(R) Network Connections 18.8.136.0 "{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program "{37B5A3DE-A3C2-4EB8-84EF-941F5DDA2B3F}" = WD SmartWare "{393CA5BF-0362-42FD-ABC2-BA9D22EF925E}" = Microsoft SQL Server 2008 Setup Support Files "{3E8FC93E-90B7-4A22-8865-0AF3DE25E377}" = Rebit 5: Viewer components (64 bit) "{3FD0B1D8-9ADC-4732-8F07-8B146AC1B9DB}" = Rebit 5: core components (64 bit) "{3FF59A46-2208-3A7A-BC8E-5DC0BBBA1A87}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD "{41DDB7C5-8BC8-46B7-B416-463B4F8B6CFA}" = Intel(R) ME UninstallLegacy "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.1.8 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A89A9DD-9ED4-4532-AE8A-863B291D9472}" = ACS Unified PC/SC Driver 4.0.0.0 "{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0413-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Dutch) 2010 "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component "{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver "{B2CD1132-75C5-427F-8B06-9DA507A5A2B6}" = AccountService "{B47AA9C8-ACBE-47CF-A4BA-CE1D58AD1F36}" = Intel(R) Management Engine Components "{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU "{C3EAE456-7E7A-451F-80EF-F34C7A13C558}" = Microsoft SQL Server Compact 3.5 SP2 x64 DEU "{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared "{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU "{DB942AEA-93D6-4FE4-8862-180D35A71730}" = Belgium e-ID middleware 4.1.18 (build 1730) "{DE17F6E4-FC32-468C-A407-113E414E3A3C}" = Intel(R) Management Engine Components "{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared "{EAB6B77C-0E46-48EF-8660-7ABA400F7FB4}" = Adblock Plus voor IE (32-bit en 64-bit) "{F2E3F45F-6244-43D2-A7BB-BC708CA8E06A}" = Rebit 5: custom runtimes (64 bit) "{F4A2F4E7-870C-44AC-A99E-DA2E8A80D91E}" = Intel(R) Management Engine Components "{F90EBFDE-7581-4062-AE57-29F2105C5FA2}" = Productverbeteringsonderzoek voor HP ENVY 5530 series "{F94A63D7-9A61-403B-8F6F-90B1BF77211A}" = RegHunter "{FA00A3CC-7440-4938-A271-F186F50DD40D}" = Intel® Trusted Connect Service Client "{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services "{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services "{FC510C5E-3D08-4BEB-9470-EFDAEB1D3DB1}" = PCKLang.nl "{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0 "017E462195A49B92E61A2EE9F52F341D2A5D6C3B" = Stuurprogrammapakket voor Windows - Advanced Card Systems Ltd. Unified PC/SC Driver (10/10/2013 4.0.0.0) "9F46F7AB1E3B1B5F5482EA8D97F401B04FBF7958" = Stuurprogrammapakket voor Windows - Fedict SmartCard (08/08/2015 4.1.5) "Bandizip" = Bandizip "CCleaner" = CCleaner "GIMP-2_is1" = GIMP 2.8.16 "Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit) "Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit) "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "Mozilla Firefox 51.0.1 (x64 nl)" = Mozilla Firefox 51.0.1 (x64 nl) "ProPlusRetail - nl-nl" = Microsoft Office Professional Plus 2013 - nl-nl "PROSetDX" = Intel(R) Network Connections 18.8.136.0 "Recuva" = Recuva "Speccy" = Speccy "StartpageToolbar" = StartpageToolbar (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0094D07C-1FFB-4450-8D10-AD7E05A318DF}_is1" = Advanced Fix 2013 version 2.1.3.83 "{0125D081-30D0-4A97-82A8-C28D444B6256}" = Microsoft SQL Server Compact 3.5 SP2 DEU "{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime "{031C88EF-4EA5-4A9D-A77D-857A914CAFA5}" = ScanSoft RealSpeak "{044E00C0-9149-45C6-A806-F2BF9CFCE762}" = Encarta Naslagbibliotheek Winkler Prins "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video "{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help "{0A3925EA-5B0E-401B-A189-7419149747B2}" = Adobe AIR "{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 "{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1B1BF50E-ACE8-4481-B362-89544FB1CD4B}" = Citrix Online Launcher "{1BD54C18-9C0F-4529-B1FC-ECD871560C76}" = OmniPage Pro 12.0 "{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help "{1F976B1D-7CFD-44F6-B016-1D3B0FFA937A}" = TuneUp Utilities Language Pack (nl-NL) "{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin "{22025051-1991-48EB-8BE8-7A3329DAE7ED}" = IIS 7.5 Express "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help "{249644e6-451a-4a5c-bd5c-21eeb9eec79d}" = WD Security "{257FD4D4-11F0-464B-AC42-11535B70A279}" = 4Team Safe PST Backup Free Edition "{26A24AE4-039D-4CA4-87B4-2F32180121F0}" = Java 8 Update 121 "{2D18E04C-2EFC-48C6-A17F-F53FC9D8564C}" = Acronis True Image "{2D18E04C-2EFC-48C6-A17F-F53FC9D8564C}Visible" = Acronis True Image "{319D91C6-3D44-436C-9F79-36C0D22372DC}" = TP-LINK Wireless Configuration Utility "{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed "{35827710-D042-428B-A1E5-E20E12D2FEB9}" = SparkTrust PC Cleaner Plus "{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode "{35A1FA23-AD44-4E6E-9CFD-AAC967677B13}" = HP ENVY 5530 series Help "{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent "{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT "{3FD0C489-0F02-481a-A3E1-9754CD396761}" = Intel® Watchdog Timer Driver (Intel® WDT) "{418BAAD1-754D-48B4-B078-46EF4F25AF42}" = Google Drive "{42812A46-01AB-466D-A5DB-03050C64AF82}" = DJ3520FWUpdateAlert "{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision "{4555885d-a64c-4234-9aac-72a8a6b5590b}" = WD SmartWare Installer "{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support "{48996CDD-DD81-4197-93FE-0971E73C5CA7}" = WD Drive Utilities "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AACAFC7-951A-4215-B430-3DFCFF2E6CED}" = WD Backup "{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}" = Windows Phone app for desktop "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{56EC47AA-5813-4FF6-8E75-544026FBEA83}" = Apple Software Update "{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress "{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3 "{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision "{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help "{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help "{616C6F39-4CE1-3434-A665-2F6A04C09A7F}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools "{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner "{6312D34F-CB70-4AD3-9C5F-D184AAFBA375}" = Rebit 5: MicroApp Extensions "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection "{75939021-3B68-419D-8DC1-E9823BFF9658}" = Google Drive "{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart "{778EACF8-06C1-47AA-9284-91550E9BAD39}" = Samsung Easy Color Manager "{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help "{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights "{7852F4B3-4647-4161-8FCF-637B0DF8C4A7}" = Microsoft Rekenmachine Plus "{7CC2EDF2-83EC-4707-BDD3-72469236A6CC}" = WD Security "{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher "{85243696-5e58-4357-9cf8-3498c609941d}" = NeroLiveGadget Help "{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software "{90120000-0020-0413-0000-0000000FF1CE}" = Compatibiliteitspakket voor het 2007 Microsoft Office system "{90140000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2010 "{90140000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2010 "{90140000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2010 "{90140000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2010 "{90140000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2010 "{90140000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2010 "{90140000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2010 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2010 "{90140000-00A1-0413-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2010 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component "{90150000-008C-0413-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component "{912D30CF-F39E-4B31-AD9A-123C6B794EE2}" = HP Update "{9262B08F-E183-4FED-A2BD-23FF1A84EB79}" = HPDiagnosticCoreDll "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help "{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C450606-ED24-4958-92BA-B8940C99D441}" = PixiePack Codec Pack "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin "{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap "{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget "{A106D33E-6B43-42C0-9BFC-D03303261FA7}" = Microsoft SQL Server 2008 R2 Management Objects "{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor "{a8c9535a-ecd9-4172-a330-0cb5ff9dbed9}" = WD Backup "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{AC76BA86-0804-1033-1959-001824211354}" = Adobe Refresh Manager "{AC76BA86-7AD7-1043-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Nederlands "{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help "{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles "{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center "{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}" = HPDiagnosticAlert "{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit "{BBEC10F9-AC15-41EE-A271-0B1077F53740}" = Adobe AIR "{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter "{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable "{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax "{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Reservekopie van persoonlijke mappen "{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed "{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 "{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help "{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech-webcamsoftware "{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime "{DC92E62C-4A63-44C7-AC9B-5EDA965E3271}_is1" = Car DV Player version 1.119 "{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live "{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit "{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed "{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help "{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer "{eab1fb93-61fb-48de-b815-b4e9b68d2ef1}" = WD Drive Utilities "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget "{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter "{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 "{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool "{FC965A47-4839-40CA-B618-18F486F042C6}" = Skype™ 7.32 "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook "{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}" = Bing Bar "7-Zip" = 7-Zip 9.22beta "Adobe AIR" = Adobe AIR "Adobe Flash Player NPAPI" = Adobe Flash Player 24 NPAPI "Advanced SystemCare_is1" = Advanced SystemCare 10 "AI RoboForm" = RoboForm 7-9-24-4 (All Users) "Applian Director3.0" = Applian Director "Applian Director3.01" = Applian Director 3 "Audacity®_is1" = Audacity 2.1.2 "AVS Audio Converter_is1" = AVS Audio Converter 8.1.1 "Compare and Merge_is1" = Compare and Merge 2.3 "Doxillion" = Doxillion Document Converter "Easy Wireless Setup" = Samsung Easy Wireless Setup "FreeCommander XE_is1" = FreeCommander XE "FreeFixer1.13" = FreeFixer "Generic USB Card Reader Driver" = Generic USB Card Reader Driver v2.3 "Handset WinDriver" = Handset WinDriver 1.02.01.00 "HD Tune_is1" = HD Tune 2.55 "IObit_StartMenu8_is1" = Start Menu 8 "Kernel for Outlook PST Repair - Evaluation Version_is1" = Kernel for Outlook PST Repair Evaluation ver 13.05.01 "LAME_is1" = LAME v3.99.3 (for Windows) "LHTTSDUN" = L&H TTS3000 Nederlands "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware versie 2.2.1.1043 "MozillaMaintenanceService" = Mozilla Maintenance Service "NirSoft ProduKey" = NirSoft ProduKey "Picasa 3" = Picasa 3 "Replay Music 7" = Replay Music 7 (7.0.1.54) "ReplayMusic6.10" = Replay Music 6 "Samsung C410 Series" = Samsung C410 Series "Samsung Easy Printer Manager" = Samsung Easy Printer Manager "Samsung Printer Live Update" = Samsung Printer Live Update "Smart Defrag_is1" = Smart Defrag 5 "Tweaking.com - Windows Repair" = Tweaking.com - Windows Repair "TweakNow RegCleaner_is1" = TweakNow RegCleaner "View User Guide" = Gebruikershandleiding weergeven "VLC media player" = VLC media player "WinPcapInst" = WinPcap 4.1.2 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-968216198-1619183050-819724312-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dashlane" = Dashlane "Download & Installeer Packages" = Download & Installeer Packages "HP Photo Creations" = HP Photo Creations "Java Packages" = Java Packages "Spotify" = Spotify [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 26/02/2017 5:42:51 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3006 Description = Error - 26/02/2017 5:42:51 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3007 Description = Error - 26/02/2017 5:42:51 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 10021 Description = Error - 26/02/2017 5:44:09 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3006 Description = Error - 26/02/2017 5:44:09 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3007 Description = Error - 26/02/2017 5:44:09 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 10021 Description = Error - 26/02/2017 5:45:42 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3006 Description = Error - 26/02/2017 5:45:42 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 3007 Description = Error - 26/02/2017 5:45:42 | Computer Name = LEVEL-PC | Source = Windows Search Service | ID = 10021 Description = Error - 26/02/2017 5:50:04 | Computer Name = LEVEL-PC | Source = Application Hang | ID = 1002 Description = Het programma OTL.exe, versie 3.2.69.0 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm. Proces-id: 1054 Starttijd: 01d290156c742957 Eindtijd: 4294967295 Toepassingspad: C:\OTL.exe Rapport-id: f22b2d45-fc08-11e6-8542-4c72b92741f3 Volledige pakketnaam met fout: Relatieve toepassings-id van pakket met fout: [ OAlerts Events ] Error - 16/07/2016 6:11:59 | Computer Name = LEVEL-PC | Source = Microsoft Office 15 Alerts | ID = 300 Description = Nieuwe App voor Office Deze app is afkomstig van de Office Store. Als u de app vertrouwt, heeft deze toegang tot de inhoud van het document waarvan de app deel uitmaakt. Meer informatie. P1: Apps for Office P2: 15.0.4823.1000 P3: 0x80042FAC P4: Error - 16/07/2016 6:12:36 | Computer Name = LEVEL-PC | Source = Microsoft Office 15 Alerts | ID = 300 Description = Aanmelding vereist Als u deze app wilt gebruiken, moet u zich aanmelden bij Office met uw Microsoft-account. P1: Apps for Office P2: 15.0.4823.1000 P3: 0x80043255 P4: Error - 1/08/2016 3:38:21 | Computer Name = LEVEL-PC | Source = Microsoft Office 15 Alerts | ID = 300 Description = Nieuwe App voor Office Deze app is afkomstig van de Office Store. Als u de app vertrouwt, heeft deze toegang tot de inhoud van het document waarvan de app deel uitmaakt. Meer informatie. P1: Apps for Office P2: 15.0.4841.1000 P3: 0x80042FAC P4: [ System Events ] Error - 26/02/2017 5:37:24 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7034 Description = De Intel(R) Dynamic Application Loader Host Interface Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error - 26/02/2017 5:37:24 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7031 Description = De Acronis Sync Agent Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten. Error - 26/02/2017 5:37:24 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7031 Description = De Windows Modules Installer-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 120000 milliseconden worden uitgevoerd: Service opnieuw starten. Error - 26/02/2017 5:37:24 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7034 Description = De Volume Shadow Copy-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error - 26/02/2017 5:37:31 | Computer Name = LEVEL-PC | Source = DCOM | ID = 10016 Description = Error - 26/02/2017 5:37:34 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7000 Description = De Acronis Sync Agent Service-service kan vanwege de volgende fout niet worden gestart: %%109 Error - 26/02/2017 5:42:23 | Computer Name = LEVEL-PC | Source = NETLOGON | ID = 3095 Description = Deze computer is geconfigureerd als lid van een werkgroep, niet als lid van een domein. De NetLogon-service hoeft niet te worden gestart in deze configuratie. Error - 26/02/2017 5:42:26 | Computer Name = LEVEL-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = WLAN-uitbreidingsmodule kan niet worden gestart. Pad naar module: C:\WINDOWS\system32\athExt.dll Foutcode: 126 Error - 26/02/2017 5:42:34 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7034 Description = De SQL Server (SQLEXPRESS)-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error - 26/02/2017 5:44:34 | Computer Name = LEVEL-PC | Source = Service Control Manager | ID = 7023 Description = De HP Network Devices Support-service is gestopt met de volgende foutcode: %%2. < End of report >