Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-10-2014 01 |
Ran by jurgen at 2014-10-28 08:36:13 |
Running from C:\Users\jurgen\Desktop |
Boot Mode: Normal |
========================================================== |
==================== Security Center ======================== |
(If an entry is included in the fixlist, it will be removed.) |
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} |
==================== Installed Programs ====================== |
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) |
µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.31515 - BitTorrent Inc.) |
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) |
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2004303102.48.56.11013354 - Audible, Inc.) |
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) |
Forté Agent (HKLM-x32\...\{DA5ECEAB-28C6-4306-9FBB-811DEF6DD780}) (Version: 7.20.1218 - Forté Internet Software, Inc.) |
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.3.99.311 - Foxit Corporation) |
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.2.0.429 - Foxit Corporation) |
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) |
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden |
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) |
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation) |
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) |
Java Auto Updater (x32 Version: 2.8.25.18 - Oracle Corporation) Hidden |
Java SE Development Kit 8 Update 5 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180050}) (Version: 8.0.50 - Oracle Corporation) |
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) |
Media Player Classic - Home Cinema v1.5.2.3456 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.5.2.3456 - MPC-HC Team) |
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) |
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) |
Mozilla Firefox 32.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla) |
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) |
Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) |
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team) |
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) |
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) |
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH) |
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation) |
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden |
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software) |
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden |
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) |
WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) |
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-5 - Bitnami) |
Yahoo Community Smartbar (HKLM-x32\...\{D40BD1FB-10B4-4042-A5AE-8364941019F6}) (Version: 11.47.66.16718 - Linkury Inc.) <==== ATTENTION |
==================== Custom CLSID (selected items): ========================== |
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) |
==================== Restore Points ========================= |
23-10-2014 20:59:32 Installed TuneUp Utilities 2014 |
23-10-2014 21:40:34 TrueCrypt installation |
==================== Hosts content: ========================== |
(If needed Hosts: directive could be included in the fixlist to reset Hosts.) |
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts |
==================== Scheduled Tasks (whitelisted) ============= |
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) |
Task: {37413D34-CC88-4B20-B2BA-7EAC0D089CEE} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software) |
Task: {4A2EAE9A-5DF4-4A23-960F-F31FCF20C3EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.) |
Task: {5C42E255-386F-40A2-A182-5DAC274D48A0} - System32\Tasks\Systweak Support Dock => C:\Program Files (x86)\Systweak Support Dock\SystweakDock.exe |
Task: {C852DF7E-4CD3-4931-82B6-71CD9A994373} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-06] (Adobe Systems Incorporated) |
Task: {EE90785A-98D9-42C6-804E-F8D471B0CBCC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.) |
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe |
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe |
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe |
==================== Loaded Modules (whitelisted) ============= |
2014-07-16 09:24 - 2014-07-16 09:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll |
2014-05-12 10:49 - 2014-05-12 10:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll |
2014-10-06 10:57 - 2014-10-06 10:57 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll |
==================== Alternate Data Streams (whitelisted) ========= |
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) |
==================== Safe Mode (whitelisted) =================== |
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) |
==================== EXE Association (whitelisted) ============= |
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) |
==================== MSCONFIG/TASK MANAGER disabled items ========= |
(Currently there is no automatic fix for this section.) |
========================= Accounts: ========================== |
Administrator (S-1-5-21-1430726004-3267235439-2031741252-500 - Administrator - Disabled) |
Guest (S-1-5-21-1430726004-3267235439-2031741252-501 - Limited - Disabled) |
HomeGroupUser$ (S-1-5-21-1430726004-3267235439-2031741252-1002 - Limited - Enabled) |
jurgen (S-1-5-21-1430726004-3267235439-2031741252-1001 - Administrator - Enabled) => C:\Users\jurgen |
==================== Faulty Device Manager Devices ============= |
Name: |
Description: |
Class Guid: |
Manufacturer: |
Service: |
Problem: : The drivers for this device are not installed. (Code 28) |
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. |
==================== Event log errors: ========================= |
Application errors: |
================== |
Error: (10/28/2014 08:29:10 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/28/2014 01:48:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 08:18:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 08:04:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 09:33:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/26/2014 10:07:23 PM) (Source: SideBySide) (EventID: 80) (User: ) |
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. |
A component version required by the application conflicts with another component version already active. |
Conflicting components are:. |
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. |
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. |
Error: (10/26/2014 10:06:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/24/2014 07:43:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/24/2014 00:39:45 AM) (Source: Application Error) (EventID: 1000) (User: ) |
Description: Faulting application name: notepad++.exe, version: 6.6.9.0, time stamp: 0x540cd326 |
Faulting module name: notepad++.exe, version: 6.6.9.0, time stamp: 0x540cd326 |
Exception code: 0xc0000005 |
Fault offset: 0x0000e358 |
Faulting process id: 0x5e4 |
Faulting application start time: 0xnotepad++.exe0 |
Faulting application path: notepad++.exe1 |
Faulting module path: notepad++.exe2 |
Report Id: notepad++.exe3 |
Error: (10/24/2014 00:38:41 AM) (Source: Application Error) (EventID: 1000) (User: ) |
Description: Faulting application name: plugin-container.exe, version: 32.0.3.5379, time stamp: 0x54224e6b |
Faulting module name: mozalloc.dll, version: 32.0.3.5379, time stamp: 0x54221b67 |
Exception code: 0x80000003 |
Fault offset: 0x0000141b |
Faulting process id: 0x71c |
Faulting application start time: 0xplugin-container.exe0 |
Faulting application path: plugin-container.exe1 |
Faulting module path: plugin-container.exe2 |
Report Id: plugin-container.exe3 |
System errors: |
============= |
Error: (10/28/2014 08:28:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
Error: (10/28/2014 08:27:34 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
Description: The following boot-start or system-start driver(s) failed to load: |
cdrom |
Error: (10/28/2014 01:48:16 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
Error: (10/28/2014 01:47:16 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
Description: The following boot-start or system-start driver(s) failed to load: |
cdrom |
Error: (10/27/2014 08:17:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
Error: (10/27/2014 08:03:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) |
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) |
Error: (10/27/2014 11:50:09 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: ) |
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system. |
Error: (10/27/2014 09:31:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
Description: The following boot-start or system-start driver(s) failed to load: |
cdrom |
Error: (10/26/2014 10:05:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) |
Description: The following boot-start or system-start driver(s) failed to load: |
cdrom |
Error: (10/26/2014 10:05:15 PM) (Source: EventLog) (EventID: 6008) (User: ) |
Description: The previous system shutdown at 10:11:47 on 24.10.2014 was unexpected. |
Microsoft Office Sessions: |
========================= |
Error: (10/28/2014 08:29:10 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/28/2014 01:48:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 08:18:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 08:04:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/27/2014 09:33:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/26/2014 10:07:23 PM) (Source: SideBySide) (EventID: 80) (User: ) |
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\jurgen\Desktop\esetsmartinstaller_enu(1).exe |
Error: (10/26/2014 10:06:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/24/2014 07:43:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) |
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 |
Error: (10/24/2014 00:39:45 AM) (Source: Application Error) (EventID: 1000) (User: ) |
Description: notepad++.exe6.6.9.0540cd326notepad++.exe6.6.9.0540cd326c00000050000e3585e401cfef00cbe91debC:\Program Files (x86)\Notepad++\notepad++.exeC:\Program Files (x86)\Notepad++\notepad++.exede00567d-5b0d-11e4-bd62-001e8c1fccbd |
Error: (10/24/2014 00:38:41 AM) (Source: Application Error) (EventID: 1000) (User: ) |
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b71c01cfef0a97340266C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllb7de463d-5b0d-11e4-bd62-001e8c1fccbd |
CodeIntegrity Errors: |
=================================== |
Date: 2014-06-17 17:16:10.657 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-17 17:16:10.657 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-17 17:16:10.657 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-17 17:16:10.642 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-17 17:16:10.626 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-17 17:16:10.626 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-15 16:01:59.960 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-15 16:01:59.960 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-15 16:01:59.960 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. |
Date: 2014-06-15 16:01:59.913 |
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. |