Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by Carsten at 2015-06-30 21:11:02 Running from C:\Users\Carsten\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-430021374-782043496-2435199758-500 - Administrator - Disabled) Carsten (S-1-5-21-430021374-782043496-2435199758-1001 - Administrator - Enabled) => C:\Users\Carsten Gast (S-1-5-21-430021374-782043496-2435199758-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-430021374-782043496-2435199758-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 7-Zip 15.05 beta x64 (HKLM\...\7-Zip) (Version: - ) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) abgx360 v1.0.6 (HKLM-x32\...\abgx360) (Version: - ) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.194 - Adobe Systems Incorporated) Age of Empires III - The WarChiefs (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Age of Mythology: Extended Edition (HKLM-x32\...\QWdlb2ZNeXRob2xvZ3lFeHRlbmRlZEVkaXRpb24=_is1) (Version: 1 - ) ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.5.8.3 - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: 2.5.8.3 - ASUSTek COMPUTER INC.) Hidden ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.025 - ASUSTek Computer Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Belkin N+ Wireless USB Adapter (HKLM-x32\...\{4FBD5BA1-64F0-46FB-818F-EA689D45C22A}) (Version: 1.00.12 - Belkin International, Inc.) Belkin Storage Manager (HKLM-x32\...\{C12D7D54-7DE8-4DF7-AB2D-8A5ECFB2F89B}) (Version: 1.0.0.21 - Belkin International, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.07 - Piriform) Cyberduck 4.6.5 (17000) (HKLM-x32\...\Cyberduck) (Version: 4.6.5 (17000) - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.) FINAL FANTASY XIV: A Realm Reborn (HKLM-x32\...\Steam App 39210) (Version: - SQUARE ENIX) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GPUTweakStreaming (HKLM-x32\...\InstallShield_{D2A41AA7-4313-43D5-AA39-7E3FBBE0556D}) (Version: 1.0.3.5 - ASUS) GPUTweakStreaming (x32 Version: 1.0.3.5 - ASUS) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) IBM SPSS Statistics 22 (HKLM\...\{104875A1-D083-4A34-BC4F-3F635B7F8EF7}) (Version: 22.0.0.0 - IBM Corp) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware versie 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office 2013 voor Thuisgebruik en Zelfstandigen - nl-nl (HKLM\...\HomeBusinessRetail - nl-nl) (Version: 15.0.4727.1003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\OneDriveSetup.exe) (Version: 17.3.5860.0512 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MPC-HC 1.7.8.95 (4bc936f) Nightly (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.8.95 - MPC-HC Team) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MySQL Fabric 1.5.3 & MySQL Utilities 1.5.3 (HKLM-x32\...\{27DCB9A2-4DEC-4EEC-84D3-35701DB8B7EB}) (Version: 1.5.3 - Oracle Corporation) MySQL For Excel 1.3.3 (HKLM-x32\...\{3A02540C-59C9-4F50-B6D0-FB4641917AD0}) (Version: 1.3.3 - Oracle) MySQL Installer - Community (HKLM-x32\...\{1BF2A017-1067-43B9-873F-9F718CBD97BC}) (Version: 1.4.3.0 - Oracle Corporation) MySQL Notifier 1.1.6 (HKLM-x32\...\{CB76A6E9-B184-461D-A8BE-7D0D73199545}) (Version: 1.1.6 - Oracle) MySQL Server 5.6 (HKLM-x32\...\{7CCB6F2A-B1BD-4453-A669-C47BF88D53CF}) (Version: 5.6.23 - Oracle Corporation) MySQL Workbench 6.2 CE (HKLM-x32\...\{DBE945CB-948B-4A68-9465-FC15BF286625}) (Version: 6.2.4 - Oracle Corporation) NVIDIA 3D Vision controllerstuurprogramma 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision stuurprogramma 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.28 - NVIDIA Corporation) NVIDIA Grafisch stuurprogramma 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation) NVIDIA HD Audio-stuurprogramma 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA Miracast virtuele audio 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.06 - NVIDIA Corporation) NVIDIA PhysX Systeem Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4727.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4727.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4727.1003 - Microsoft Corporation) Hidden OpenSSL 1.0.1h (32-bit) (HKLM-x32\...\OpenSSL (32-bit)_is1) (Version: - OpenSSL Win32 Installer Team) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7111 - Realtek Semiconductor Corp.) Scribblenauts Unlimited (HKLM-x32\...\Scribblenauts Unlimited_is1) (Version: - ) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.28 - NVIDIA Corporation) Hidden Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.9.2833.1 - Hi-Rez Studios) Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD) (Version: 10.0.50903 - Microsoft Corporation) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Witcher 3 (HKLM-x32\...\The Witcher 3_is1) (Version: 1.02 - Релиз от R.G. Steamgames) Winamp Packages (HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\Winamp Packages) (Version: - ) <==== ATTENTION Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Carsten\AppData\Local\Microsoft\OneDrive\17.3.5860.0512\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-430021374-782043496-2435199758-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carsten\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll (Dropbox, Inc.) ==================== Restore Points ========================= 10-06-2015 20:07:22 Windows Update 19-06-2015 17:41:57 Gepland controlepunt 24-06-2015 12:24:05 Windows Update 28-06-2015 19:09:20 WinZip 19.5 is verwijderd ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {07CEFADD-1B21-4084-B84A-5A573285EF80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-14] (Google Inc.) Task: {1684E903-FE0F-4911-8909-1228D1AF9901} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-430021374-782043496-2435199758-1001UA => C:\Users\Carsten\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-28] (Dropbox, Inc.) Task: {25841698-7BFE-4D0D-BABC-B0FAF239D99A} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-08-27] (ASUSTek Computer Inc.) Task: {2DC196C1-8AB2-4C92-B6F4-7CE9F0BD48E1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-18] (Avast Software s.r.o.) Task: {2E62C849-C2D1-4247-AA3F-1A3981725718} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-10] (Microsoft Corporation) Task: {3B468033-5305-4D27-BCE8-41ABBCE94664} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-05-19] (Microsoft Corporation) Task: {45817E58-F137-47B6-9ECA-29F8170B206A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-430021374-782043496-2435199758-1001Core => C:\Users\Carsten\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-28] (Dropbox, Inc.) Task: {55268297-A39D-487A-B006-8C8159196D4C} - System32\Tasks\MySQLNotifierTask => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe Task: {5C90A9C4-0DF9-49DB-B8CB-0425E6060ECF} - System32\Tasks\Microsoft Office 15 Sync Maintenance for PC-CARSTEN-Carsten PC-Carsten => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-05-28] (Microsoft Corporation) Task: {6349942A-FCD7-4A9E-954E-3848CD542AE1} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {722E9DBB-533F-4F54-9C5A-E5F9D99FD782} - System32\Tasks\{E04E377B-2430-4399-939D-2D2D5DC948DB} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe" -c uplay://uninstall/274 Task: {7871C6D7-3C3E-4354-B62A-7A2ECB805F9A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-05-19] (Microsoft Corporation) Task: {792F0332-E2D0-4CF5-9CDB-8F206F3EAFF7} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated) Task: {7D5511D6-E56A-43B4-83CB-1CAEEFB94653} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd) Task: {92F33E4D-1AE0-4E87-89FC-DD75368A099E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-14] (Google Inc.) Task: {9CF3CC54-8FEE-473D-9D24-6EAFC12D6A84} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-430021374-782043496-2435199758-1001 => %localappdata%\Microsoft\OneDrive\OneDrive.exe Task: {E51EC8C7-63AC-47E2-A8AC-1631FE3639FF} - System32\Tasks\MySQL\Installer\ManifestUpdate => C:\Program Files (x86)\MySQL\MySQL Installer for Windows\MySQLInstallerConsole.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-430021374-782043496-2435199758-1001Core.job => C:\Users\Carsten\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-430021374-782043496-2435199758-1001UA.job => C:\Users\Carsten\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2014-06-13 10:12 - 2015-05-28 06:15 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2012-01-17 11:24 - 2012-01-17 11:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2014-06-14 12:42 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2014-06-13 15:28 - 2012-11-01 11:23 - 00089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2014-06-13 15:28 - 2012-11-01 11:21 - 00325120 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2015-06-01 19:28 - 2015-06-01 19:28 - 00065536 _____ () C:\Program Files\CCleaner\lang\lang-1043.dll 2015-06-06 12:47 - 2015-06-06 12:47 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-06-06 12:47 - 2015-06-06 12:47 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-06-30 20:00 - 2015-06-30 20:00 - 02952704 _____ () C:\Program Files\AVAST Software\Avast\defs\15063001\algo.dll 2015-06-03 16:21 - 2015-05-23 03:48 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-06 12:47 - 2015-06-06 12:47 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-06-22 22:25 - 2015-06-20 07:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll 2015-06-22 22:25 - 2015-06-20 07:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Carsten\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-430021374-782043496-2435199758-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.161.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "F5D8055v1" HKLM\...\StartupApproved\Run32: => "UpdReg" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "NCUpdateHelper" HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\StartupApproved\Run: => "EvolveClient" HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-430021374-782043496-2435199758-1001\...\StartupApproved\Run: => "iLivid" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [{49A3594A-B5C8-463D-A395-2B4D385C80EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{B6E848DF-62C9-4274-9E4B-272946CD7284}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{BDD89680-5CD0-4FE3-A3BA-A4A7D1A0F0F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{71CFB7EB-A87C-4BFF-942D-F8A47E8900A8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{4BAC7D65-46CB-4655-B3A5-A712B84620A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{6126539B-FEAE-4CC3-9F6D-240DEA849C37}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [TCP Query User{1E4E2F55-1D6C-4B67-89AD-6F352D4F60A6}C:\program files (x86)\belkin storage manager\storagemanager.exe] => (Allow) C:\program files (x86)\belkin storage manager\storagemanager.exe FirewallRules: [UDP Query User{28017B85-FCDB-40D3-B049-FACF3A3911FB}C:\program files (x86)\belkin storage manager\storagemanager.exe] => (Allow) C:\program files (x86)\belkin storage manager\storagemanager.exe FirewallRules: [TCP Query User{E88367BF-0195-4F83-BEE9-201842702109}C:\program files (x86)\belkin storage manager\storagemanager.exe] => (Allow) C:\program files (x86)\belkin storage manager\storagemanager.exe FirewallRules: [UDP Query User{26480964-6C56-4018-96C3-9A7516784758}C:\program files (x86)\belkin storage manager\storagemanager.exe] => (Allow) C:\program files (x86)\belkin storage manager\storagemanager.exe FirewallRules: [{98E89369-C05A-446B-ACE4-D8D044D137E2}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{E3D1746F-AEE7-4B8E-8AE6-9066D9A0D7F1}] => (Allow) C:\Users\Carsten\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6CC19C34-841E-4CE8-8C14-0DD3BE3F3958}] => (Allow) C:\Users\Carsten\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{4993CFFE-212F-4612-AD65-FC7F809B9DEB}E:\games\smite\hirezgames\smite\binaries\win32\smite.exe] => (Allow) E:\games\smite\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{BA0AC651-D672-4235-96B7-9DC6FAAB09DE}E:\games\smite\hirezgames\smite\binaries\win32\smite.exe] => (Allow) E:\games\smite\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [TCP Query User{A873FC61-4353-42E1-8034-4E66790F4A8D}E:\games\smite\hirezgames\smite\binaries\win32\smite.exe] => (Allow) E:\games\smite\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{EB3632F2-2DDB-4482-BA7F-AD27ED015343}E:\games\smite\hirezgames\smite\binaries\win32\smite.exe] => (Allow) E:\games\smite\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [{7F44E8DF-5134-4D11-8ABD-859BCCAFBA1B}] => (Allow) LPort=7575 FirewallRules: [{AB4A6193-39AB-4DC8-8631-CB1916E6B9B4}] => (Allow) E:\Games\Battle.net\Battle.net.exe FirewallRules: [{DD6F585B-0F7C-4B61-A570-1B58D05958C6}] => (Allow) E:\Games\Battle.net\Battle.net.exe FirewallRules: [{0D3EE0D0-4A43-460E-8825-DEE8E8CACFE4}] => (Allow) E:\Games\Hearthstone\Hearthstone.exe FirewallRules: [{8D934ED3-57CC-4A5D-BEF3-D5DB32EBC587}] => (Allow) E:\Games\Hearthstone\Hearthstone.exe FirewallRules: [{D2976840-F042-4BFE-87E7-AC63A18AB5AB}] => (Allow) LPort=80 FirewallRules: [{4A7938FF-8DFB-483C-93BE-60F4C1E15F1E}] => (Allow) LPort=80 FirewallRules: [{B1B94F58-FA2D-4BAB-98E3-9D3C17641D2D}] => (Allow) LPort=443 FirewallRules: [{297AC3E9-B490-47D1-BB0F-EC199961F88F}] => (Allow) LPort=443 FirewallRules: [{15342E5D-FC79-43F1-905D-3CB73DF61380}] => (Allow) LPort=20010 FirewallRules: [{C73436F5-CF3C-489F-9BC6-355FDEDC9CFB}] => (Allow) LPort=20010 FirewallRules: [{91882281-24FA-405B-9E39-C54BACCAE694}] => (Allow) LPort=3478 FirewallRules: [{3BD790A0-03E7-40DB-A35D-E3AC1BB24C21}] => (Allow) LPort=3478 FirewallRules: [{B9E4E709-37EE-4253-A55F-D195EBD0EB47}] => (Allow) LPort=7850 FirewallRules: [{72E0B7C1-A06E-4FFA-A8DE-4D8437647CF6}] => (Allow) LPort=7850 FirewallRules: [{9BD15D66-AA36-4552-8A21-2FCCF41B8AA9}] => (Allow) LPort=7852 FirewallRules: [{8240459D-8F19-4925-88B1-099AC2FB36B4}] => (Allow) LPort=7852 FirewallRules: [{36F2658D-1C88-4503-8B0D-01837512A09E}] => (Allow) LPort=7853 FirewallRules: [{E1722758-481D-4978-8605-E31AC0FFAF04}] => (Allow) LPort=7853 FirewallRules: [{1C3B08FE-1761-4F32-94D5-D0060EC4E9A3}] => (Allow) LPort=27022 FirewallRules: [{218CF3DE-E775-4D17-A0A4-C6EF3721A515}] => (Allow) LPort=27022 FirewallRules: [{2FEABAB7-283C-422C-90BE-5F8A8E652993}] => (Allow) LPort=6881 FirewallRules: [{32B393BE-2B06-4B31-9316-0E936761E44E}] => (Allow) LPort=6881 FirewallRules: [{7AA77339-C563-4BA1-9BB1-E1D8EC4FF72D}] => (Allow) LPort=33333 FirewallRules: [{7DA590AE-619F-4930-AD08-4531414BFADA}] => (Allow) LPort=33333 FirewallRules: [{CD391AAC-6385-46BA-90F6-DEE26986507C}] => (Allow) LPort=20443 FirewallRules: [{6D655192-572C-45AA-B583-42936D278810}] => (Allow) LPort=20443 FirewallRules: [{E9A0D805-31B9-49CA-83EA-DDF09103458D}] => (Allow) LPort=8090 FirewallRules: [{B7881351-30B3-47A0-8CF2-FA3871404FC3}] => (Allow) LPort=8090 FirewallRules: [{987AACEA-20CD-48FB-AAB8-B0D80D45008A}] => (Allow) C:\Users\Carsten\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{A6314C85-2839-4849-9EC1-CE7C489EB69B}] => (Allow) C:\Users\Carsten\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{72778D90-3B92-451C-B142-79CE5E0545E9}E:\games\hearthstone\hearthstone.exe] => (Allow) E:\games\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{919DF229-A8FB-4CBB-9A61-3F3B6E5E471C}E:\games\hearthstone\hearthstone.exe] => (Allow) E:\games\hearthstone\hearthstone.exe FirewallRules: [{BC7A98CD-DAC2-4464-A6D3-D30D67863F65}] => (Allow) E:\School\stats.com FirewallRules: [{63158AE7-DE93-4F03-A2DB-78FFCE5005F6}] => (Allow) E:\School\stats.exe FirewallRules: [{FACE5459-01AD-4A2B-ACB3-C19C1D53D298}] => (Allow) E:\School\stats.com FirewallRules: [{A86AB84D-BD0B-4E18-92C5-BC872C185925}] => (Allow) E:\School\stats.exe FirewallRules: [{6BD16578-C267-4D12-9086-64024AC90081}] => (Allow) E:\School\WinWrapIDE.exe FirewallRules: [{898D32C0-2282-4416-958A-03E12B2E0A83}] => (Allow) E:\School\WinWrapIDE.exe FirewallRules: [TCP Query User{DE0F3791-2A45-4C99-AB09-FEF8BF7A8AD9}E:\school\jre\bin\javaw.exe] => (Allow) E:\school\jre\bin\javaw.exe FirewallRules: [UDP Query User{A0C4F669-797D-442D-85EA-30F1781B5A5C}E:\school\jre\bin\javaw.exe] => (Allow) E:\school\jre\bin\javaw.exe FirewallRules: [{90E1F71E-EA15-4116-9B58-5D86CFD2378D}] => (Allow) E:\Steam\Steam.exe FirewallRules: [{384D9720-71CB-458E-BA2C-5CDA290EC239}] => (Allow) E:\Steam\Steam.exe FirewallRules: [{42952D8D-9FC1-4995-9143-F638752018BB}] => (Allow) E:\Steam\bin\steamwebhelper.exe FirewallRules: [{73328184-60F5-4D59-B399-FB7A58D13E43}] => (Allow) E:\Steam\bin\steamwebhelper.exe FirewallRules: [{567D179C-9D2F-4BE8-A884-45D3E52040F9}] => (Allow) E:\Steam\steamapps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe FirewallRules: [{380C6B6D-3551-479E-B7A7-D0B017CBB82B}] => (Allow) E:\Steam\steamapps\common\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe FirewallRules: [{8D300901-EA50-48C9-AE2A-8FBB05AA2ADE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{97C9517A-D5D6-4F64-AB44-5D05FB9E635D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{BDDD68B1-1209-4E32-92A5-C7169F4C8612}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{3704522F-871F-4913-B777-8CC5046A6D87}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{ACAD679A-6215-404A-BE7F-F2DFC7EB2732}E:\muziek software\winamp\winamp.exe] => (Allow) E:\muziek software\winamp\winamp.exe FirewallRules: [UDP Query User{7CE0B8FA-E397-4152-959C-A080C888E709}E:\muziek software\winamp\winamp.exe] => (Allow) E:\muziek software\winamp\winamp.exe FirewallRules: [{07FDA02A-7D41-4703-8267-57316481D6AB}] => (Block) E:\muziek software\winamp\winamp.exe FirewallRules: [{E5362EE7-5372-44EE-8EC3-297B74A7E87D}] => (Block) E:\muziek software\winamp\winamp.exe FirewallRules: [{0630AB64-723B-4AC0-99E8-EC3457C5F721}] => (Allow) E:\Limewire Plus 2.0\Limewire Plus.url FirewallRules: [{4E5A2DEC-5394-4423-A763-2062CD3830C1}] => (Allow) E:\Limewire Plus 2.0\Limewire Plus.url FirewallRules: [{1164D8F3-AD91-4DD2-8EA4-7EB85DFDE032}] => (Allow) E:\Limewire Plus 2.0\Limewire Plus.url FirewallRules: [{7FA0CC06-9329-41B2-B751-BB7081EF91AD}] => (Allow) E:\Limewire Plus 2.0\Limewire Plus.url FirewallRules: [TCP Query User{ED07F56D-6310-4250-90DC-420B7EBCBE64}E:\popcorn time\popcorntimedesktop.exe] => (Allow) E:\popcorn time\popcorntimedesktop.exe FirewallRules: [UDP Query User{DCBE51E8-63BD-49B7-B469-8CFA0EF07B30}E:\popcorn time\popcorntimedesktop.exe] => (Allow) E:\popcorn time\popcorntimedesktop.exe FirewallRules: [TCP Query User{79810A03-7530-4205-A740-1623E9E7D35F}C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe FirewallRules: [UDP Query User{CB41478E-6EB7-48C5-A9E9-D4180D6D3416}C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe FirewallRules: [TCP Query User{74310C07-E041-4353-ACE8-AE3577903204}C:\users\carsten\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\carsten\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{44BB565E-17A9-4100-A70E-57D8859BD7C1}C:\users\carsten\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\carsten\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{78BFB4D8-E647-4DA6-BE74-04A41F870018}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{9973D86B-D19D-47A1-9ED2-9093C37161C2}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [TCP Query User{117D0066-15A9-421A-8BCE-77A1B46F91E4}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [UDP Query User{8AD13164-BC3F-48A7-9D6A-C9922F128CC7}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe FirewallRules: [TCP Query User{CE19B11D-C0E5-4263-88F3-9238E9987301}C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe FirewallRules: [UDP Query User{436A3337-2A8E-4C23-8770-0EA65E735D06}C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\carsten\appdata\local\popcorn time\node-webkit\popcorn time.exe FirewallRules: [{98F64304-5C8A-4A94-9CE9-1492AB21981C}] => (Allow) LPort=3306 FirewallRules: [{D926163A-91F9-4D12-B62D-E84A56FEAA48}] => (Allow) LPort=3306 FirewallRules: [TCP Query User{E3CDF784-93CD-466D-9CFF-2D8396D05604}E:\website elody\cyberduck\cyberduck.exe] => (Allow) E:\website elody\cyberduck\cyberduck.exe FirewallRules: [UDP Query User{BAC9B7D4-4330-4881-9EA4-32966184FB2E}E:\website elody\cyberduck\cyberduck.exe] => (Allow) E:\website elody\cyberduck\cyberduck.exe FirewallRules: [{3A0693AE-1BB4-4AA9-B3B5-29F1D2ADEFDF}] => (Allow) E:\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{B65901A2-21D4-4AC3-9585-6A7FC1CB35BB}] => (Allow) E:\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{187ADA32-FB9E-457E-B2EB-19499567E509}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{84E5E669-E5B6-429B-ABD6-AE49D20D3AB8}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{B29DF37C-DB12-4184-A6B5-703D6102B11C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{BE75B17A-FDCB-4C7D-BEA9-FDC6F4207DBD}] => (Allow) LPort=2869 FirewallRules: [{50F9D6FC-5E3C-4F0F-8FC4-7B933468343F}] => (Allow) LPort=1900 FirewallRules: [{00C65CAE-1C2F-48E2-AAFC-BC78DA18C3A2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{14E2F7D3-A9C2-4580-8968-F591907EDBC6}E:\games\age of mythology extended edition\aomx.exe] => (Allow) E:\games\age of mythology extended edition\aomx.exe FirewallRules: [UDP Query User{D9BEF935-5F86-4F1B-A42B-E365E62BCEEF}E:\games\age of mythology extended edition\aomx.exe] => (Allow) E:\games\age of mythology extended edition\aomx.exe FirewallRules: [TCP Query User{3322A8F4-341B-411A-9A05-A2380449BE27}E:\games\age of mythology extended edition\aomx.exe] => (Allow) E:\games\age of mythology extended edition\aomx.exe FirewallRules: [UDP Query User{1D02B358-A92C-4C73-BAF4-6B27B95D366B}E:\games\age of mythology extended edition\aomx.exe] => (Allow) E:\games\age of mythology extended edition\aomx.exe FirewallRules: [TCP Query User{88176928-7008-429B-9EB2-1AE2F9E48B23}E:\games\v3 - deathwings madness - release\_server\mysql\bin\mysqld.exe] => (Allow) E:\games\v3 - deathwings madness - release\_server\mysql\bin\mysqld.exe FirewallRules: [UDP Query User{1D89276C-4F52-449A-ABE6-01EF6F137671}E:\games\v3 - deathwings madness - release\_server\mysql\bin\mysqld.exe] => (Allow) E:\games\v3 - deathwings madness - release\_server\mysql\bin\mysqld.exe FirewallRules: [TCP Query User{33C85528-31D0-4390-8CD6-C027061DACA9}E:\games\v3 - deathwings madness - release\authserver.exe] => (Allow) E:\games\v3 - deathwings madness - release\authserver.exe FirewallRules: [UDP Query User{175291A8-3893-4700-B08A-269205FD27D3}E:\games\v3 - deathwings madness - release\authserver.exe] => (Allow) E:\games\v3 - deathwings madness - release\authserver.exe FirewallRules: [TCP Query User{5F5D825F-53B3-4664-BBDE-DC5569CC5E0D}E:\games\v3 - deathwings madness - release\worldserver.exe] => (Allow) E:\games\v3 - deathwings madness - release\worldserver.exe FirewallRules: [UDP Query User{628DE8BB-7E24-457D-83E0-E0F8128DB35C}E:\games\v3 - deathwings madness - release\worldserver.exe] => (Allow) E:\games\v3 - deathwings madness - release\worldserver.exe FirewallRules: [{CE943312-1472-455A-B7EA-1A01A57089FA}] => (Block) E:\games\v3 - deathwings madness - release\worldserver.exe FirewallRules: [{1F66954D-108C-4DF4-B41E-777499755C4C}] => (Block) E:\games\v3 - deathwings madness - release\worldserver.exe FirewallRules: [{45190E4D-996E-4CBA-A9C3-A1C7F7AF6E48}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{AAD99663-9241-4F3B-BE22-540D076A15DF}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{C70231A7-A49C-433A-94FB-48320C827C31}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: BFTN.L1F% Description: BFTN.L1F% Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Qualcomm Atheros Service: L1c Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/26/2015 06:20:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Naam van module met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Uitzonderingscode: 0xc0000005 Foutmarge: 0x002cecd9 Id van proces met fout: 0x188 Starttijd van toepassing met fout: 0xworldserver.exe0 Pad naar toepassing met fout: worldserver.exe1 Pad naar module met fout: worldserver.exe2 Rapport-id: worldserver.exe3 Volledige pakketnaam met fout: worldserver.exe4 Relatieve toepassings-id van pakket met fout: worldserver.exe5 Error: (06/26/2015 05:50:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Naam van module met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Uitzonderingscode: 0xc0000005 Foutmarge: 0x002cecd9 Id van proces met fout: 0x15ac Starttijd van toepassing met fout: 0xworldserver.exe0 Pad naar toepassing met fout: worldserver.exe1 Pad naar module met fout: worldserver.exe2 Rapport-id: worldserver.exe3 Volledige pakketnaam met fout: worldserver.exe4 Relatieve toepassings-id van pakket met fout: worldserver.exe5 Error: (06/26/2015 00:54:22 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Het volume \\?\Volume{5f7dc217-50c1-40fc-814e-98f6e75f0aed}\ is niet geoptimaliseerd, omdat er een fout is opgetreden: De parameter is onjuist. (0x80070057) Error: (06/26/2015 00:54:21 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Het volume Herstel is niet geoptimaliseerd, omdat er een fout is opgetreden: De parameter is onjuist. (0x80070057) Error: (06/23/2015 02:05:23 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/21/2015 08:35:57 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=0.0.0.0-devel;lang=;guid=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\6c790a7f-14da-400e-a27e-bd438071b05b.dmp Error: (06/21/2015 06:21:13 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=0.0.0.0-devel;lang=;guid=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\3d9de7bb-8bd5-409a-85d6-b40eb50356b6.dmp Error: (06/18/2015 11:58:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: Smite.exe, versie: 2.8.2808.0, tijdstempel: 0x55820666 Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000 Uitzonderingscode: 0xc0000005 Foutmarge: 0x000a000d Id van proces met fout: 0x1650 Starttijd van toepassing met fout: 0xSmite.exe0 Pad naar toepassing met fout: Smite.exe1 Pad naar module met fout: Smite.exe2 Rapport-id: Smite.exe3 Volledige pakketnaam met fout: Smite.exe4 Relatieve toepassings-id van pakket met fout: Smite.exe5 Error: (06/15/2015 09:29:46 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY) Description: There was an error with the Windows Location Provider database Error: (06/14/2015 11:01:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Naam van toepassing met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Naam van module met fout: worldserver.exe, versie: 0.0.0.0, tijdstempel: 0x552d2697 Uitzonderingscode: 0xc0000005 Foutmarge: 0x002cecd9 Id van proces met fout: 0x1414 Starttijd van toepassing met fout: 0xworldserver.exe0 Pad naar toepassing met fout: worldserver.exe1 Pad naar module met fout: worldserver.exe2 Rapport-id: worldserver.exe3 Volledige pakketnaam met fout: worldserver.exe4 Relatieve toepassings-id van pakket met fout: worldserver.exe5 System errors: ============= Error: (06/30/2015 08:18:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Windows Search-service is onverwacht gestopt. Dit is 2 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/30/2015 08:18:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Microsoft Office ClickToRun Service-service is onverwacht gestopt. Dit is 2 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Windows Media Player Network Sharing Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Windows Search-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: De Microsoft Office ClickToRun Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De NVIDIA Streamer Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De NVIDIA Network Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De Hi-Rez Studios Authenticate and Update Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (06/30/2015 08:18:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De NVIDIA GeForce Experience Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Error: (06/30/2015 08:18:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: De ASGT-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd. Microsoft Office: ========================= Error: (06/26/2015 06:20:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: worldserver.exe0.0.0.0552d2697worldserver.exe0.0.0.0552d2697c0000005002cecd918801d0b02827c237d5E:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exeE:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exe49125127-1c1f-11e5-bea0-98d9aafc4ed1 Error: (06/26/2015 05:50:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: worldserver.exe0.0.0.0552d2697worldserver.exe0.0.0.0552d2697c0000005002cecd915ac01d0b0259f4a4350E:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exeE:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exe23550a86-1c1b-11e5-bea0-98d9aafc4ed1 Error: (06/26/2015 00:54:22 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: \\?\Volume{5f7dc217-50c1-40fc-814e-98f6e75f0aed}\De parameter is onjuist. (0x80070057) Error: (06/26/2015 00:54:21 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: HerstelDe parameter is onjuist. (0x80070057) Error: (06/23/2015 02:05:23 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (06/21/2015 08:35:57 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=0.0.0.0-devel;lang=;guid=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\6c790a7f-14da-400e-a27e-bd438071b05b.dmp Error: (06/21/2015 06:21:13 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=0.0.0.0-devel;lang=;guid=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\3d9de7bb-8bd5-409a-85d6-b40eb50356b6.dmp Error: (06/18/2015 11:58:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Smite.exe2.8.2808.055820666unknown0.0.0.000000000c0000005000a000d165001d0aa10848544cdE:\Games\Smite\HiRezGames\smite\binaries\Win32\Smite.exeunknown1a6fd095-1605-11e5-bea0-98d9aafc4ed1 Error: (06/15/2015 09:29:46 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY) Description: -2147024883 Error: (06/14/2015 11:01:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: worldserver.exe0.0.0.0552d2697worldserver.exe0.0.0.0552d2697c0000005002cecd9141401d0a6defd2cabe7E:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exeE:\Games\V3 - Deathwings Madness - RELEASE\worldserver.exe988d727f-12d8-11e5-bea0-98d9aafc4ed1 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4771 CPU @ 3.50GHz Percentage of memory in use: 16% Total physical RAM: 16311.93 MB Available physical RAM: 13630.8 MB Total Pagefile: 18743.93 MB Available Pagefile: 15964.39 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:58.67 GB) (Free:2.25 GB) NTFS Drive e: (NieuwVolume) (Fixed) (Total:1862.89 GB) (Free:1694.99 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 59.6 GB) (Disk ID: 4C0CC192) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================