| Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-10-2014 01 |
| Ran by jurgen at 2014-10-28 08:36:13 |
| Running from C:\Users\jurgen\Desktop |
| Boot Mode: Normal |
| ========================================================== |
| ==================== Security Center ======================== |
| (If an entry is included in the fixlist, it will be removed.) |
| AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} |
| ==================== Installed Programs ====================== |
| (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) |
| µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.31515 - BitTorrent Inc.) |
| Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) |
| AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2004303102.48.56.11013354 - Audible, Inc.) |
| ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) |
| Forté Agent (HKLM-x32\...\{DA5ECEAB-28C6-4306-9FBB-811DEF6DD780}) (Version: 7.20.1218 - Forté Internet Software, Inc.) |
| Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.3.99.311 - Foxit Corporation) |
| Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.2.0.429 - Foxit Corporation) |
| Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) |
| Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden |
| IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) |
| Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation) |
| Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) |
| Java Auto Updater (x32 Version: 2.8.25.18 - Oracle Corporation) Hidden |
| Java SE Development Kit 8 Update 5 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180050}) (Version: 8.0.50 - Oracle Corporation) |
| McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) |
| Media Player Classic - Home Cinema v1.5.2.3456 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.5.2.3456 - MPC-HC Team) |
| Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) |
| Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) |
| Mozilla Firefox 32.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla) |
| Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) |
| Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) |
| Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team) |
| Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) |
| Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) |
| Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH) |
| TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation) |
| TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden |
| TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software) |
| TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden |
| VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) |
| WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) |
| XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-5 - Bitnami) |
| Yahoo Community Smartbar (HKLM-x32\...\{D40BD1FB-10B4-4042-A5AE-8364941019F6}) (Version: 11.47.66.16718 - Linkury Inc.) <==== ATTENTION |
| ==================== Custom CLSID (selected items): ========================== |
| (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) |
| ==================== Restore Points ========================= |
| 23-10-2014 20:59:32 Installed TuneUp Utilities 2014 |
| 23-10-2014 21:40:34 TrueCrypt installation |
| ==================== Hosts content: ========================== |
| (If needed Hosts: directive could be included in the fixlist to reset Hosts.) |
| 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts |
| ==================== Scheduled Tasks (whitelisted) ============= |
| (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) |
| Task: {37413D34-CC88-4B20-B2BA-7EAC0D089CEE} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software) |
| Task: {4A2EAE9A-5DF4-4A23-960F-F31FCF20C3EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.) |
| Task: {5C42E255-386F-40A2-A182-5DAC274D48A0} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe |
| Task: {C852DF7E-4CD3-4931-82B6-71CD9A994373} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-06] (Adobe Systems Incorporated) |
| Task: {EE90785A-98D9-42C6-804E-F8D471B0CBCC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.) |
| Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe |
| Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe |
| Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe |
| ==================== Loaded Modules (whitelisted) ============= |
| 2014-07-16 09:24 - 2014-07-16 09:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll |
| 2014-05-12 10:49 - 2014-05-12 10:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll |
| 2014-10-06 10:57 - 2014-10-06 10:57 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll |
| ==================== Alternate Data Streams (whitelisted) ========= |
| (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) |
| ==================== Safe Mode (whitelisted) =================== |
| (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) |
| ==================== EXE Association (whitelisted) ============= |
| (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) |
| ==================== MSCONFIG/TASK MANAGER disabled items ========= |
| (Currently there is no automatic fix for this section.) |
| ========================= Accounts: ========================== |
| Administrator (S-1-5-21-1430726004-3267235439-2031741252-500 - Administrator - Disabled) |
| Guest (S-1-5-21-1430726004-3267235439-2031741252-501 - Limited - Disabled) |
| HomeGroupUser$ (S-1-5-21-1430726004-3267235439-2031741252-1002 - Limited - Enabled) |
| jurgen (S-1-5-21-1430726004-3267235439-2031741252-1001 - Administrator - Enabled) => C:\Users\jurgen |
| ==================== Faulty Device Manager Devices ============= |
| Name: |
| Description: |
| Class Guid: |
| Manufacturer: |
| Service: |
| Problem: : The drivers for this device are not installed. (Code 28) |
| Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. |
| ==================== Event log errors: ========================= |
| Application errors: |
| ================== |
| Error: (10/28/2014 08:29:10 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/28/2014 01:48:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 08:18:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 08:04:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 09:33:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/26/2014 10:07:23 PM) (Source: SideBySide) (EventID: 80) (User: ) |
| Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. |
| A component version required by the application conflicts with another component version already active. |
| Conflicting components are:. |
| Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. |
| Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. |
| Error: (10/26/2014 10:06:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/24/2014 07:43:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/24/2014 00:39:45 AM) (Source: Application Error) (EventID: 1000) (User: ) |
| Description: Faulting application name: notepad++.exe, version: 6.6.9.0, time stamp: 0x540cd326 |
| Faulting module name: notepad++.exe, version: 6.6.9.0, time stamp: 0x540cd326 |
| Exception code: 0xc0000005 |
| Fault offset: 0x0000e358 |
| Faulting process id: 0x5e4 |
| Faulting application start time: 0xnotepad++.exe0 |
| Faulting application path: notepad++.exe1 |
| Faulting module path: notepad++.exe2 |
| Report Id: notepad++.exe3 |
| Error: (10/24/2014 00:38:41 AM) (Source: Application Error) (EventID: 1000) (User: ) |
| Description: Faulting application name: plugin-container.exe, version: 32.0.3.5379, time stamp: 0x54224e6b |
| Faulting module name: mozalloc.dll, version: 32.0.3.5379, time stamp: 0x54221b67 |
| Exception code: 0x80000003 |
| Fault offset: 0x0000141b |
| Faulting process id: 0x71c |
| Faulting application start time: 0xplugin-container.exe0 |
| Faulting application path: plugin-container.exe1 |
| Faulting module path: plugin-container.exe2 |
| Report Id: plugin-container.exe3 |
| System errors: |
| ============= |
| Error: (10/28/2014 08:28:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
| Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
| Error: (10/28/2014 08:27:34 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
| Description: The following boot-start or system-start driver(s) failed to load: |
| cdrom |
| Error: (10/28/2014 01:48:16 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
| Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
| Error: (10/28/2014 01:47:16 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
| Description: The following boot-start or system-start driver(s) failed to load: |
| cdrom |
| Error: (10/27/2014 08:17:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
| Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
| Error: (10/27/2014 08:03:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
| Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
| Error: (10/27/2014 11:50:09 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: ) |
| Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system. |
| Error: (10/27/2014 09:31:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
| Description: The following boot-start or system-start driver(s) failed to load: |
| cdrom |
| Error: (10/26/2014 10:05:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
| Description: The following boot-start or system-start driver(s) failed to load: |
| cdrom |
| Error: (10/26/2014 10:05:15 PM) (Source: EventLog) (EventID: 6008) (User: ) |
| Description: The previous system shutdown at 10:11:47 on 24.10.2014 was unexpected. |
| Microsoft Office Sessions: |
| ========================= |
| Error: (10/28/2014 08:29:10 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/28/2014 01:48:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 08:18:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 08:04:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/27/2014 09:33:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/26/2014 10:07:23 PM) (Source: SideBySide) (EventID: 80) (User: ) |
| Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\jurgen\Desktop\esetsmartinstaller_enu(1).exe |
| Error: (10/26/2014 10:06:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/24/2014 07:43:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
| Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
| Error: (10/24/2014 00:39:45 AM) (Source: Application Error) (EventID: 1000) (User: ) |
| Description: notepad++.exe6.6.9.0540cd326notepad++.exe6.6.9.0540cd326c00000050000e3585e401cfef00cbe91debC:\Program Files (x86)\Notepad++\notepad++.exeC:\Program Files (x86)\Notepad++\notepad++.exede00567d-5b0d-11e4-bd62-001e8c1fccbd |
| Error: (10/24/2014 00:38:41 AM) (Source: Application Error) (EventID: 1000) (User: ) |
| Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b71c01cfef0a97340266C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllb7de463d-5b0d-11e4-bd62-001e8c1fccbd |
| CodeIntegrity Errors: |
| =================================== |
| Date: 2014-06-17 17:16:10.657 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-17 17:16:10.657 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-17 17:16:10.657 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-17 17:16:10.642 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-17 17:16:10.626 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-17 17:16:10.626 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-15 16:01:59.960 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-15 16:01:59.960 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-15 16:01:59.960 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
| Date: 2014-06-15 16:01:59.913 |
| Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |