|
Log-Analyse und Auswertung: PUP.Optional.InstallBrain.A - Laptop sehr langsamWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.11.2014, 19:24 | #1 |
| PUP.Optional.InstallBrain.A - Laptop sehr langsam Hallo liebe Forumsteilnehmer, habe hier den Laptop von einem Arbeitskollegen, der voll mit Malware, und sehr sehr langsam ist. Zum hochfahren braucht er ca. 10 Minuten. Und im Taskmanager sind über 100 Prozesse am laufen. MBAM findet verschiedene Varianten von PUP.Optional Den Scan Mit MBAM habe ich ohne update gemacht, da immer wieder die Fehlemeldung kam: Keine Verbindung zum Server. Es handelt sich hier um einem Intel i7 - 2670QM @2.2 Ghz mit 8GB Speicher. Betriebsystem: Windows 7 - 64 bit Hersteller: Samsung Ich hoffe Ihr könnt mir helfen den Laptop zu bereinigen !!! Danke !!!! FRST: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014 Ran by ***** at 2014-11-12 17:56:18 Running from C:\Users\*****\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden „Windows Live Messenger“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.4.634 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Agatha Christie - Death on the Nile (x32 Version: 2.2.0.82 - WildTangent) Hidden Akamai NetSession Interface (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Akamai) (Version: - ) Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk Design Review Browser Add-on v1.2 (HKLM-x32\...\{CD49E43B-88B1-48AD-A3AF-43FAAAB41CB8}) (Version: 1.2.0 - Autodesk) BatteryLifeExtender (HKLM-x32\...\{FFD0E594-823B-4E2B-B680-720B3C852588}) (Version: 1.0.11 - Samsung) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Build-a-lot (x32 Version: 2.2.0.82 - WildTangent) Hidden Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC) <==== ATTENTION Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) Canon MP140 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series) (Version: - ) Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform) ChargeableUSB (HKLM-x32\...\{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}) (Version: 1.0.0.0 - SAMSUNG) Chuzzle Deluxe (x32 Version: 2.2.0.82 - WildTangent) Hidden ClearThink (HKLM\...\ClearThink) (Version: 2014.08.14.181036 - ClearThink) <==== ATTENTION Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.) CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.) CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.) CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.) CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.4207 - CyberLink Corp.) CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3029.52 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.82 - WildTangent) Hidden DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) DolbyFiles (x32 Version: 0.1 - Nero AG) Hidden DRIVERfighter (HKLM-x32\...\DRIVERfighter) (Version: 1.0.140 - SPAMfighter ApS) DRIVERfighter (x32 Version: 1.0.140 - SPAMfighter ApS) Hidden DWG TrueView 2012 (HKLM\...\DWG TrueView 2012) (Version: 18.2.51.0 - Autodesk) DWG TrueView 2012 (Version: 18.2.51.0 - Autodesk) Hidden Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD) Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM-x32\...\{8732818E-CA78-4ACB-B077-22311BF4C0E4}) (Version: 4.4.7 - Samsung) Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung) EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung) ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\...\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Farm Frenzy (x32 Version: 2.2.0.82 - WildTangent) Hidden Fast Search (HKLM-x32\...\Surf Canyon) (Version: 4.0.3 - Surf Canyon) Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG) FastPlayer (HKLM-x32\...\FastPlayer) (Version: v1.0.0.2 - ) <==== ATTENTION Final Media Player 2014 (HKLM-x32\...\FinalMediaPlayer_is1) (Version: 2014.08.04.00 - Bitberry Software) <==== ATTENTION FineDealSoft (HKLM-x32\...\{0D566ABB-889B-AF39-7B6A-23D4C5D54542}) (Version: - finedeal) <==== ATTENTION Fotoattēlu galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogaléria (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foto-galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleri (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foxtab (HKLM-x32\...\foxtab) (Version: - FoxTab) <==== ATTENTION Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerija fotografija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Gameo (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Gameo) (Version: 0.10.5 - Fried Cookie Software) Gameo (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Gameo) (Version: 0.10.5 - Fried Cookie Software) GoldenCoupon (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - GoldenCoupon) <==== ATTENTION Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden InetStat (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\InetStat) (Version: 0.5b - InetStat) InetStat (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\InetStat) (Version: 0.5b - InetStat) Insaniquarium Deluxe (x32 Version: 2.2.0.82 - WildTangent) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{006B5C65-3938-4246-B182-994A7E415EDE}) (Version: 1.1.0.0537 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation) Internet Explorer Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Internet Explorer Packages) (Version: - ) <==== ATTENTION Internet Explorer Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Internet Explorer Packages) (Version: - ) <==== ATTENTION Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) John Deere Drive Green (x32 Version: 2.2.0.82 - WildTangent) Hidden Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 33.0 (x86 hr) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 hr)) (Version: 33.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Multimedia POP (HKLM-x32\...\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.0 - ) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION Nero 9 Essentials (HKLM-x32\...\{aad5de85-ba48-4353-ac89-88bb1a6661be}) (Version: - Nero AG) Nero BackItUp (HKLM-x32\...\{0450A697-C87E-42C2-9331-29E19901F72A}) (Version: 15.2.7.14 - Nero AG) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) Nokia Music Player (HKLM-x32\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player) Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia) Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.48.0 - Nokia) Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia) NVIDIA Grafiktreiber 266.72 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.72 - NVIDIA Corporation) OfferBLVDUpdate (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\PennyBee) (Version: - OfferBLVDUpdate) OfferBLVDUpdate (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\PennyBee) (Version: - OfferBLVDUpdate) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) Peggle (x32 Version: 2.2.0.82 - WildTangent) Hidden Penguins! (x32 Version: 2.2.0.82 - WildTangent) Hidden PhoneShare (HKLM-x32\...\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Plants vs. Zombies (x32 Version: 2.2.0.82 - WildTangent) Hidden Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Polar Golfer (x32 Version: 2.2.0.82 - WildTangent) Hidden Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Price-Horse (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\pricehorse) (Version: - Price-Horse) Price-Horse (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\pricehorse) (Version: - Price-Horse) Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden ProConOS OPC-Server 2.0 Desktop (HKLM-x32\...\KW-Software) (Version: - ) Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden RealConverter Free Download Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\RealConverter Free Download Packages) (Version: - ) <==== ATTENTION RealConverter Free Download Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\RealConverter Free Download Packages) (Version: - ) <==== ATTENTION RealDownloader (x32 Version: 17.0.13 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.13 - RealNetworks) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.) Samsung Drive Manager (HKLM-x32\...\{9F1A6A24-4901-42F6-A355-5DD2B82E62AE}) (Version: 1.0.148 - Clarus) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: - Samsung Electronics Co., Ltd.) Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.9 - Samsung) Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype Web Plugin (HKLM-x32\...\{B51DD93B-3CB5-4D9D-BFF2-FD19DBBBFD9A}) (Version: 2.9.13008.18866 - Skype Technologies S.A.) Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 4.2.01.15030 - Sony Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden TuneUp Utilities 2014 (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel) UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.5 - ) Valokuvavalikoima (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.1.5 - WildTangent) WildTangent ORB Game Console (x32 Version: - WildTangent) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.623 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows-Treiberpaket - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia) Windows-Treiberpaket - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WordCaptureX Pro (HKLM-x32\...\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience) Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden Фотоальбом (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотогалерия (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотографии (общедоступная версия) (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden גלריית התמונות (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2012\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2012\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 08-11-2014 16:09:59 Installed User Guide 08-11-2014 16:24:35 Installed Multimedia POP 08-11-2014 16:27:37 Installed Mid_Low 08-11-2014 16:28:59 Konfiguriert YouCam 09-11-2014 18:00:22 Windows-Sicherung 10-11-2014 14:35:48 Windows-Sicherung 11-11-2014 19:26:46 Removed Norton Online Backup 11-11-2014 21:09:56 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {01D4A7F9-5150-4EC5-B7F8-30C2AADE48CB} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.) Task: {121BCA27-C43E-49A5-BB5F-19FCD438B49D} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {13FD9D44-A723-4667-8A72-62104D4E3C3E} - System32\Tasks\Price-Horse Udpater => C:\Users\*****\AppData\Local\pricehorse\pricehorse\1.3.13.12\playsetup.exe Task: {14560D6D-3A82-4C3E-9C9A-F446C9F861FF} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-23] (Samsung Electronics) Task: {1D339B8F-9578-47CB-899F-8E4431772CFE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-17] (Adobe Systems Incorporated) Task: {25799A6E-14E0-4EB4-8AF3-FCFB26C9F270} - System32\Tasks\QtraxPlayer => 521189571.portal.qtrax.com Task: {2697FB7F-875A-417C-937D-636F7E6F9DB5} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {29016D0D-D292-412E-8711-87920D3702FE} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.) Task: {2F44A089-D6FA-4882-B198-5EBEAD95AEDF} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004Core => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-01] (Facebook Inc.) Task: {3415EB95-B0C1-4095-80F2-2D078003C35D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-10] (Google Inc.) Task: {3619C950-F637-43BD-8512-45DC90F8D40C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-10] (Google Inc.) Task: {39007D5E-CE71-4DCE-BB3C-6F2FDB69B0E7} - System32\Tasks\Price-Horse => C:\Users\*****\AppData\Local\pricehorse\pricehorse\1.3.13.12\pricehorse.exe Task: {3FD35EC7-C4DD-4C6F-8772-516ED7FE711C} - System32\Tasks\PennyBee => C:\Users\*****\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {45AFD236-26A0-4F24-AF3C-78F68685763F} - System32\Tasks\Final Media Player Update Checker => C:\Program Files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe [2013-03-25] (Bitberry Software) Task: {480E67C3-326B-44FF-9D84-59E488C8EEE9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {4E2D1193-F0D3-4AC9-BC2B-35AA38BC9D79} - System32\Tasks\FoxTab => C:\Users\*****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {56701BE3-A92D-43AE-AF5C-F0ABCD18AEC5} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe Task: {5D5E441B-7C50-4F44-A6FB-4E68337378DB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-07-30] (RealNetworks, Inc.) Task: {5DE573FC-4FA7-48B3-BE7C-CEE77B763D1A} - System32\Tasks\Start Registry Reviver => C:\Program Files (x86)\Reviversoft\Registry Reviver\RegistryReviver.exe Task: {6BD1D4DF-540F-4AC5-99AB-C5B6D7F8CC85} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {6BFB994E-4975-4A4D-9FF9-1E668F7FD63A} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe Task: {70D81A84-CDE6-4E3E-B7DA-75B349285CF9} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {71208500-F42E-4D78-A946-C751222D0756} - System32\Tasks\***** NBAgent 15 0 => C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exe [2014-09-29] (Nero AG) Task: {76CA9B62-1D48-48A3-8F8B-E3BDF91DD9DC} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001UA => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-24] (Facebook Inc.) Task: {76D7C559-5751-4190-AB9D-28CA8A6E6010} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {8835EEC0-C390-4DC5-82CC-EE552F2093EA} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics) Task: {90A69BAF-30C2-4ECD-BD31-6226849F17C4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-23] (Piriform Ltd) Task: {94702489-9C9A-4D62-9FAD-8DC07AB496F1} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION Task: {A363F639-9E4A-496B-8BC4-6916AA3AF700} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {A8ED1470-DB9B-40A7-80DF-0512421C1690} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004UA => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-01] (Facebook Inc.) Task: {B8F13F3B-0DB4-4A99-9710-5B8C0B5CD4CF} - System32\Tasks\{179FFD91-B173-44F7-9249-516C6801592C} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.2.0.169.411/de/go/help.faq.installer?LastError=1603 Task: {C275C624-7D97-46F7-BBC0-4E14717BE19A} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {C304D9BA-DD1E-4728-AF0A-786A137D404A} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-18] (Samsung Electronics. Co. Ltd.) Task: {D534AE7F-B34E-4322-BE5D-9417608B5ECA} - System32\Tasks\DRIVERfighter Auto Start => C:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe [2012-09-28] () Task: {D5B99F5F-83EE-408B-98ED-A117C2F2D83D} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {DFEE3E57-6693-44D6-8D78-C4A0B21F0EE5} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {E64E75B9-3AAF-455E-9684-D3FB4A9791B0} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: {E7110FB6-91D1-4C30-99AC-E10225F61CAD} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-11-29] (Samsung Electronics Co., Ltd.) Task: {E87DA5B9-4D35-4893-BCE2-C8014991C057} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2011-01-11] (Samsung Electronics) Task: {F0D980F1-114C-49F9-88AB-50FAEB18A24F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001Core => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-24] (Facebook Inc.) Task: {F34F1D07-F7DC-4535-8DC4-B24F4B11E7FC} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-12225A02\EPM.exe Task: {F35C9474-2139-4111-8DD0-2B83F0508187} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {F5933323-65D4-456A-B119-5005FD0A25A4} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-10-13] (MyPC Backup) <==== ATTENTION Task: {FEE2F150-F394-4963-83B3-DAD1AA3FB459} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {FF31C52D-7E5E-4C54-B7A2-87C2469793D8} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-11-10] (CyberLink) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\DRIVERfighter Auto Start.job => C:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001Core.job => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001UA.job => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004Core.job => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004UA.job => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\Final Media Player Update Checker.job => C:\Program Files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe Task: C:\windows\Tasks\FoxTab.job => C:\Users\*****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\PennyBee.job => C:\Users\*****\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-09-06 05:52 - 2008-06-05 00:53 - 00027648 _____ () C:\windows\System32\spd__l.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 04303360 _____ () C:\ProgramData\Performance Optimizer\PerformanceOptimizer_x64.dll 2014-09-30 16:52 - 2014-09-30 16:52 - 00011776 _____ () C:\Program Files (x86)\FastPlayer\FastPlayerUpdaterService.exe 2012-04-07 23:41 - 2010-04-05 20:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2014-10-29 20:22 - 2014-10-13 11:00 - 00158720 _____ () C:\Users\*****\AppData\Local\OCRSchemaTask\OCRSchemaTask.exe 2014-07-30 01:17 - 2014-07-30 01:17 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2014-07-30 04:04 - 2014-07-30 04:04 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe 2011-09-06 01:44 - 2009-12-01 08:21 - 00244904 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2014-10-17 17:32 - 2014-10-17 11:54 - 04834816 _____ () C:\windows\score.exe 2013-08-30 08:51 - 2013-08-30 08:51 - 00757048 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2014-10-29 20:22 - 2014-10-13 11:00 - 00366592 _____ () C:\Users\*****\AppData\Local\OCRSchemaTask\SoftwareTextWYSIWYG.exe 2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-10-17 17:40 - 2014-11-05 18:11 - 00702478 _____ () C:\Users\*****\AppData\Roaming\InetStat\inetstat.exe 2014-10-23 20:19 - 2014-10-23 20:19 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2011-09-06 05:48 - 2010-12-17 02:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll 2014-10-29 20:21 - 2014-10-29 20:21 - 00060453 _____ () C:\windows\SysWOW64\CodecProcessSoftware\CodecProcessSoftware.exe 2014-10-29 20:22 - 2014-10-13 11:01 - 00068096 _____ () C:\windows\SysWOW64\DaemonDirect3dTask\DaemonDirect3dTask.exe 2011-09-06 05:52 - 2010-10-21 19:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 04125184 _____ () c:\ProgramData\Performance Optimizer\PerformanceOptimizer.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 00186192 _____ () c:\ProgramData\Performance Optimizer\PerformanceOptimizerSvc.dll 2011-09-06 01:54 - 2006-08-12 12:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2011-09-06 01:52 - 2010-05-07 15:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2014-11-08 17:05 - 2010-07-05 19:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll 2009-11-02 06:20 - 2009-11-02 06:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 06:23 - 2009-11-02 06:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^*****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk => C:\windows\pss\PMB Medien-Prüfung.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\*****\AppData\Local\Akamai\netsession_win.exe" MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\update\realsched.exe" -osboot MSCONFIG\startupreg: WinampAgent => "C:\Program Files (x86)\Winamp\winampa.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-1739335617-45622530-1743251556-500 - Administrator - Disabled) ***** (S-1-5-21-1739335617-45622530-1743251556-1001 - Administrator - Enabled) => C:\Users\***** Gast (S-1-5-21-1739335617-45622530-1743251556-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1739335617-45622530-1743251556-1003 - Limited - Enabled) **** (S-1-5-21-1739335617-45622530-1743251556-1004 - Limited - Enabled) => C:\Users\**** UpdatusUser (S-1-5-21-1739335617-45622530-1743251556-1005 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= Name: TuneUpUtilitiesDrv Description: TuneUpUtilitiesDrv Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: TuneUpUtilitiesDrv Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: BHDrvx64 Description: BHDrvx64 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: BHDrvx64 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/12/2014 05:46:43 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:39:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Name des fehlerhaften Moduls: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Ausnahmecode: 0xc0000417 Fehleroffset: 0x000802d1 ID des fehlerhaften Prozesses: 0x100c Startzeit der fehlerhaften Anwendung: 0xDRIVERfighter.exe0 Pfad der fehlerhaften Anwendung: DRIVERfighter.exe1 Pfad des fehlerhaften Moduls: DRIVERfighter.exe2 Berichtskennung: DRIVERfighter.exe3 Error: (11/12/2014 05:37:38 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:37:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Name des fehlerhaften Moduls: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00026e56 ID des fehlerhaften Prozesses: 0x1324 Startzeit der fehlerhaften Anwendung: 0xNBAgent.exe0 Pfad der fehlerhaften Anwendung: NBAgent.exe1 Pfad des fehlerhaften Moduls: NBAgent.exe2 Berichtskennung: NBAgent.exe3 Error: (11/12/2014 05:37:01 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NBAgent.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei <Module>._wWinMainCRTStartup() Error: (11/12/2014 05:33:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2014 04:52:28 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:47:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Name des fehlerhaften Moduls: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Ausnahmecode: 0xc0000417 Fehleroffset: 0x000802d1 ID des fehlerhaften Prozesses: 0x121c Startzeit der fehlerhaften Anwendung: 0xDRIVERfighter.exe0 Pfad der fehlerhaften Anwendung: DRIVERfighter.exe1 Pfad des fehlerhaften Moduls: DRIVERfighter.exe2 Berichtskennung: DRIVERfighter.exe3 Error: (11/12/2014 04:44:51 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:44:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Name des fehlerhaften Moduls: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00026e56 ID des fehlerhaften Prozesses: 0x10c8 Startzeit der fehlerhaften Anwendung: 0xNBAgent.exe0 Pfad der fehlerhaften Anwendung: NBAgent.exe1 Pfad des fehlerhaften Moduls: NBAgent.exe2 Berichtskennung: NBAgent.exe3 System errors: ============= Error: (11/12/2014 05:41:15 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "DaemonDirect3dTask" wurde nicht richtig gestartet. Error: (11/12/2014 05:39:02 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "CodecProcessSoftware" wurde nicht richtig gestartet. Error: (11/12/2014 05:35:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUpUtilitiesDrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/12/2014 05:34:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: BHDrvx64 Error: (11/12/2014 05:34:56 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "OCRSchemaTask.exe" wurde nicht richtig gestartet. Error: (11/12/2014 05:32:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (11/12/2014 05:32:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (11/12/2014 04:49:16 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "DaemonDirect3dTask" wurde nicht richtig gestartet. Error: (11/12/2014 04:47:11 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "CodecProcessSoftware" wurde nicht richtig gestartet. Error: (11/12/2014 04:43:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUpUtilitiesDrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (11/12/2014 05:46:43 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:39:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DRIVERfighter.exe0.0.0.0506599eeDRIVERfighter.exe0.0.0.0506599eec0000417000802d1100c01cffe96c15a098aC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exeC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe7d27b445-6a8a-11e4-8950-dca9715029f3 Error: (11/12/2014 05:37:38 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:37:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NBAgent.exe15.2.7.145428e839NBAgent.exe15.2.7.145428e839c000000500026e56132401cffe96b4e739a4C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exeC:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exe243d2581-6a8a-11e4-8950-dca9715029f3 Error: (11/12/2014 05:37:01 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NBAgent.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei <Module>._wWinMainCRTStartup() Error: (11/12/2014 05:33:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2014 04:52:28 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:47:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DRIVERfighter.exe0.0.0.0506599eeDRIVERfighter.exe0.0.0.0506599eec0000417000802d1121c01cffe8f86bea0dbC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exeC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe2eaac901-6a83-11e4-920e-dca9715029f3 Error: (11/12/2014 04:44:51 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:44:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NBAgent.exe15.2.7.145428e839NBAgent.exe15.2.7.145428e839c000000500026e5610c801cffe8f84cabfe1C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exeC:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exed2dcc965-6a82-11e4-920e-dca9715029f3 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz Percentage of memory in use: 28% Total physical RAM: 8104.29 MB Available physical RAM: 5784.97 MB Total Pagefile: 16206.76 MB Available Pagefile: 13612.89 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:165 GB) (Free:48.99 GB) NTFS Drive d: () (Fixed) (Total:509.87 GB) (Free:123.45 GB) NTFS Drive f: (STORE N GO) (Removable) (Total:14.44 GB) (Free:14.42 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 817D105E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=165 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=509.9 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=23.7 GB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 14.5 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=14.5 GB) - (Type=0C) ==================== End Of Log ============================ |
12.11.2014, 19:25 | #2 |
| PUP.Optional.InstallBrain.A - Laptop sehr langsam Addition:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014 Ran by ***** at 2014-11-12 17:56:18 Running from C:\Users\*****\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden „Windows Live Messenger“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.4.634 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Agatha Christie - Death on the Nile (x32 Version: 2.2.0.82 - WildTangent) Hidden Akamai NetSession Interface (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Akamai) (Version: - ) Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk Design Review Browser Add-on v1.2 (HKLM-x32\...\{CD49E43B-88B1-48AD-A3AF-43FAAAB41CB8}) (Version: 1.2.0 - Autodesk) BatteryLifeExtender (HKLM-x32\...\{FFD0E594-823B-4E2B-B680-720B3C852588}) (Version: 1.0.11 - Samsung) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Build-a-lot (x32 Version: 2.2.0.82 - WildTangent) Hidden Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC) <==== ATTENTION Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) Canon MP140 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series) (Version: - ) Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform) ChargeableUSB (HKLM-x32\...\{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}) (Version: 1.0.0.0 - SAMSUNG) Chuzzle Deluxe (x32 Version: 2.2.0.82 - WildTangent) Hidden ClearThink (HKLM\...\ClearThink) (Version: 2014.08.14.181036 - ClearThink) <==== ATTENTION Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.) CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.) CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.) CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.) CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.4207 - CyberLink Corp.) CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3029.52 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.82 - WildTangent) Hidden DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) DolbyFiles (x32 Version: 0.1 - Nero AG) Hidden DRIVERfighter (HKLM-x32\...\DRIVERfighter) (Version: 1.0.140 - SPAMfighter ApS) DRIVERfighter (x32 Version: 1.0.140 - SPAMfighter ApS) Hidden DWG TrueView 2012 (HKLM\...\DWG TrueView 2012) (Version: 18.2.51.0 - Autodesk) DWG TrueView 2012 (Version: 18.2.51.0 - Autodesk) Hidden Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD) Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Easy Network Manager (HKLM-x32\...\{8732818E-CA78-4ACB-B077-22311BF4C0E4}) (Version: 4.4.7 - Samsung) Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung) EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung) ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\...\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Farm Frenzy (x32 Version: 2.2.0.82 - WildTangent) Hidden Fast Search (HKLM-x32\...\Surf Canyon) (Version: 4.0.3 - Surf Canyon) Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG) FastPlayer (HKLM-x32\...\FastPlayer) (Version: v1.0.0.2 - ) <==== ATTENTION Final Media Player 2014 (HKLM-x32\...\FinalMediaPlayer_is1) (Version: 2014.08.04.00 - Bitberry Software) <==== ATTENTION FineDealSoft (HKLM-x32\...\{0D566ABB-889B-AF39-7B6A-23D4C5D54542}) (Version: - finedeal) <==== ATTENTION Fotoattēlu galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogaléria (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foto-galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleri (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Foxtab (HKLM-x32\...\foxtab) (Version: - FoxTab) <==== ATTENTION Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerija fotografija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Gameo (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Gameo) (Version: 0.10.5 - Fried Cookie Software) Gameo (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Gameo) (Version: 0.10.5 - Fried Cookie Software) GoldenCoupon (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - GoldenCoupon) <==== ATTENTION Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden InetStat (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\InetStat) (Version: 0.5b - InetStat) InetStat (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\InetStat) (Version: 0.5b - InetStat) Insaniquarium Deluxe (x32 Version: 2.2.0.82 - WildTangent) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{006B5C65-3938-4246-B182-994A7E415EDE}) (Version: 1.1.0.0537 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation) Internet Explorer Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Internet Explorer Packages) (Version: - ) <==== ATTENTION Internet Explorer Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Internet Explorer Packages) (Version: - ) <==== ATTENTION Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) John Deere Drive Green (x32 Version: 2.2.0.82 - WildTangent) Hidden Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 33.0 (x86 hr) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 hr)) (Version: 33.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Multimedia POP (HKLM-x32\...\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.0 - ) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION Nero 9 Essentials (HKLM-x32\...\{aad5de85-ba48-4353-ac89-88bb1a6661be}) (Version: - Nero AG) Nero BackItUp (HKLM-x32\...\{0450A697-C87E-42C2-9331-29E19901F72A}) (Version: 15.2.7.14 - Nero AG) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) Nokia Music Player (HKLM-x32\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player) Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia) Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.48.0 - Nokia) Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia) NVIDIA Grafiktreiber 266.72 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.72 - NVIDIA Corporation) OfferBLVDUpdate (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\PennyBee) (Version: - OfferBLVDUpdate) OfferBLVDUpdate (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\PennyBee) (Version: - OfferBLVDUpdate) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) Peggle (x32 Version: 2.2.0.82 - WildTangent) Hidden Penguins! (x32 Version: 2.2.0.82 - WildTangent) Hidden PhoneShare (HKLM-x32\...\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Plants vs. Zombies (x32 Version: 2.2.0.82 - WildTangent) Hidden Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Polar Golfer (x32 Version: 2.2.0.82 - WildTangent) Hidden Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Price-Horse (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\pricehorse) (Version: - Price-Horse) Price-Horse (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\pricehorse) (Version: - Price-Horse) Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden ProConOS OPC-Server 2.0 Desktop (HKLM-x32\...\KW-Software) (Version: - ) Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden RealConverter Free Download Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\RealConverter Free Download Packages) (Version: - ) <==== ATTENTION RealConverter Free Download Packages (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\RealConverter Free Download Packages) (Version: - ) <==== ATTENTION RealDownloader (x32 Version: 17.0.13 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.13 - RealNetworks) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.) Samsung Drive Manager (HKLM-x32\...\{9F1A6A24-4901-42F6-A355-5DD2B82E62AE}) (Version: 1.0.148 - Clarus) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: - Samsung Electronics Co., Ltd.) Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.9 - Samsung) Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.) Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype Web Plugin (HKLM-x32\...\{B51DD93B-3CB5-4D9D-BFF2-FD19DBBBFD9A}) (Version: 2.9.13008.18866 - Skype Technologies S.A.) Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 4.2.01.15030 - Sony Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden TuneUp Utilities 2014 (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel) UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.5 - ) Valokuvavalikoima (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.1.5 - WildTangent) WildTangent ORB Game Console (x32 Version: - WildTangent) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.623 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1739335617-45622530-1743251556-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1739335617-45622530-1743251556-1005\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows-Treiberpaket - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia) Windows-Treiberpaket - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WordCaptureX Pro (HKLM-x32\...\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience) Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden Фотоальбом (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотогалерия (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Фотографии (общедоступная версия) (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden גלריית התמונות (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden 照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2012\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2012\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\*****\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 08-11-2014 16:09:59 Installed User Guide 08-11-2014 16:24:35 Installed Multimedia POP 08-11-2014 16:27:37 Installed Mid_Low 08-11-2014 16:28:59 Konfiguriert YouCam 09-11-2014 18:00:22 Windows-Sicherung 10-11-2014 14:35:48 Windows-Sicherung 11-11-2014 19:26:46 Removed Norton Online Backup 11-11-2014 21:09:56 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {01D4A7F9-5150-4EC5-B7F8-30C2AADE48CB} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.) Task: {121BCA27-C43E-49A5-BB5F-19FCD438B49D} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {13FD9D44-A723-4667-8A72-62104D4E3C3E} - System32\Tasks\Price-Horse Udpater => C:\Users\*****\AppData\Local\pricehorse\pricehorse\1.3.13.12\playsetup.exe Task: {14560D6D-3A82-4C3E-9C9A-F446C9F861FF} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-23] (Samsung Electronics) Task: {1D339B8F-9578-47CB-899F-8E4431772CFE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-17] (Adobe Systems Incorporated) Task: {25799A6E-14E0-4EB4-8AF3-FCFB26C9F270} - System32\Tasks\QtraxPlayer => 521189571.portal.qtrax.com Task: {2697FB7F-875A-417C-937D-636F7E6F9DB5} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {29016D0D-D292-412E-8711-87920D3702FE} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.) Task: {2F44A089-D6FA-4882-B198-5EBEAD95AEDF} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004Core => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-01] (Facebook Inc.) Task: {3415EB95-B0C1-4095-80F2-2D078003C35D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-10] (Google Inc.) Task: {3619C950-F637-43BD-8512-45DC90F8D40C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-10] (Google Inc.) Task: {39007D5E-CE71-4DCE-BB3C-6F2FDB69B0E7} - System32\Tasks\Price-Horse => C:\Users\*****\AppData\Local\pricehorse\pricehorse\1.3.13.12\pricehorse.exe Task: {3FD35EC7-C4DD-4C6F-8772-516ED7FE711C} - System32\Tasks\PennyBee => C:\Users\*****\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {45AFD236-26A0-4F24-AF3C-78F68685763F} - System32\Tasks\Final Media Player Update Checker => C:\Program Files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe [2013-03-25] (Bitberry Software) Task: {480E67C3-326B-44FF-9D84-59E488C8EEE9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {4E2D1193-F0D3-4AC9-BC2B-35AA38BC9D79} - System32\Tasks\FoxTab => C:\Users\*****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {56701BE3-A92D-43AE-AF5C-F0ABCD18AEC5} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe Task: {5D5E441B-7C50-4F44-A6FB-4E68337378DB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-07-30] (RealNetworks, Inc.) Task: {5DE573FC-4FA7-48B3-BE7C-CEE77B763D1A} - System32\Tasks\Start Registry Reviver => C:\Program Files (x86)\Reviversoft\Registry Reviver\RegistryReviver.exe Task: {6BD1D4DF-540F-4AC5-99AB-C5B6D7F8CC85} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {6BFB994E-4975-4A4D-9FF9-1E668F7FD63A} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe Task: {70D81A84-CDE6-4E3E-B7DA-75B349285CF9} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {71208500-F42E-4D78-A946-C751222D0756} - System32\Tasks\***** NBAgent 15 0 => C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exe [2014-09-29] (Nero AG) Task: {76CA9B62-1D48-48A3-8F8B-E3BDF91DD9DC} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001UA => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-24] (Facebook Inc.) Task: {76D7C559-5751-4190-AB9D-28CA8A6E6010} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {8835EEC0-C390-4DC5-82CC-EE552F2093EA} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics) Task: {90A69BAF-30C2-4ECD-BD31-6226849F17C4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-23] (Piriform Ltd) Task: {94702489-9C9A-4D62-9FAD-8DC07AB496F1} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION Task: {A363F639-9E4A-496B-8BC4-6916AA3AF700} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {A8ED1470-DB9B-40A7-80DF-0512421C1690} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004UA => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-01] (Facebook Inc.) Task: {B8F13F3B-0DB4-4A99-9710-5B8C0B5CD4CF} - System32\Tasks\{179FFD91-B173-44F7-9249-516C6801592C} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.2.0.169.411/de/go/help.faq.installer?LastError=1603 Task: {C275C624-7D97-46F7-BBC0-4E14717BE19A} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {C304D9BA-DD1E-4728-AF0A-786A137D404A} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-18] (Samsung Electronics. Co. Ltd.) Task: {D534AE7F-B34E-4322-BE5D-9417608B5ECA} - System32\Tasks\DRIVERfighter Auto Start => C:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe [2012-09-28] () Task: {D5B99F5F-83EE-408B-98ED-A117C2F2D83D} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {DFEE3E57-6693-44D6-8D78-C4A0B21F0EE5} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {E64E75B9-3AAF-455E-9684-D3FB4A9791B0} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: {E7110FB6-91D1-4C30-99AC-E10225F61CAD} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-11-29] (Samsung Electronics Co., Ltd.) Task: {E87DA5B9-4D35-4893-BCE2-C8014991C057} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2011-01-11] (Samsung Electronics) Task: {F0D980F1-114C-49F9-88AB-50FAEB18A24F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001Core => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-24] (Facebook Inc.) Task: {F34F1D07-F7DC-4535-8DC4-B24F4B11E7FC} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-12225A02\EPM.exe Task: {F35C9474-2139-4111-8DD0-2B83F0508187} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1739335617-45622530-1743251556-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-07-30] (RealNetworks, Inc.) Task: {F5933323-65D4-456A-B119-5005FD0A25A4} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-10-13] (MyPC Backup) <==== ATTENTION Task: {FEE2F150-F394-4963-83B3-DAD1AA3FB459} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {FF31C52D-7E5E-4C54-B7A2-87C2469793D8} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-11-10] (CyberLink) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\DRIVERfighter Auto Start.job => C:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001Core.job => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1001UA.job => C:\Users\*****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004Core.job => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1739335617-45622530-1743251556-1004UA.job => C:\Users\****\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\Final Media Player Update Checker.job => C:\Program Files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe Task: C:\windows\Tasks\FoxTab.job => C:\Users\*****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\PennyBee.job => C:\Users\*****\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-09-06 05:52 - 2008-06-05 00:53 - 00027648 _____ () C:\windows\System32\spd__l.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 04303360 _____ () C:\ProgramData\Performance Optimizer\PerformanceOptimizer_x64.dll 2014-09-30 16:52 - 2014-09-30 16:52 - 00011776 _____ () C:\Program Files (x86)\FastPlayer\FastPlayerUpdaterService.exe 2012-04-07 23:41 - 2010-04-05 20:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2014-10-29 20:22 - 2014-10-13 11:00 - 00158720 _____ () C:\Users\*****\AppData\Local\OCRSchemaTask\OCRSchemaTask.exe 2014-07-30 01:17 - 2014-07-30 01:17 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2014-07-30 04:04 - 2014-07-30 04:04 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe 2011-09-06 01:44 - 2009-12-01 08:21 - 00244904 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2014-10-17 17:32 - 2014-10-17 11:54 - 04834816 _____ () C:\windows\score.exe 2013-08-30 08:51 - 2013-08-30 08:51 - 00757048 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2014-10-29 20:22 - 2014-10-13 11:00 - 00366592 _____ () C:\Users\*****\AppData\Local\OCRSchemaTask\SoftwareTextWYSIWYG.exe 2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-10-17 17:40 - 2014-11-05 18:11 - 00702478 _____ () C:\Users\*****\AppData\Roaming\InetStat\inetstat.exe 2014-10-23 20:19 - 2014-10-23 20:19 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2011-09-06 05:48 - 2010-12-17 02:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll 2014-10-29 20:21 - 2014-10-29 20:21 - 00060453 _____ () C:\windows\SysWOW64\CodecProcessSoftware\CodecProcessSoftware.exe 2014-10-29 20:22 - 2014-10-13 11:01 - 00068096 _____ () C:\windows\SysWOW64\DaemonDirect3dTask\DaemonDirect3dTask.exe 2011-09-06 05:52 - 2010-10-21 19:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 04125184 _____ () c:\ProgramData\Performance Optimizer\PerformanceOptimizer.dll 2014-09-07 20:03 - 2014-09-07 20:03 - 00186192 _____ () c:\ProgramData\Performance Optimizer\PerformanceOptimizerSvc.dll 2011-09-06 01:54 - 2006-08-12 12:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2011-09-06 01:52 - 2010-05-07 15:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2014-11-08 17:05 - 2010-07-05 19:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll 2009-11-02 06:20 - 2009-11-02 06:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 06:23 - 2009-11-02 06:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318} => "default"="DiskDrive" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^*****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PMB Medien-Prüfung.lnk => C:\windows\pss\PMB Medien-Prüfung.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\*****\AppData\Local\Akamai\netsession_win.exe" MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\update\realsched.exe" -osboot MSCONFIG\startupreg: WinampAgent => "C:\Program Files (x86)\Winamp\winampa.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-1739335617-45622530-1743251556-500 - Administrator - Disabled) ***** (S-1-5-21-1739335617-45622530-1743251556-1001 - Administrator - Enabled) => C:\Users\***** Gast (S-1-5-21-1739335617-45622530-1743251556-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1739335617-45622530-1743251556-1003 - Limited - Enabled) **** (S-1-5-21-1739335617-45622530-1743251556-1004 - Limited - Enabled) => C:\Users\**** UpdatusUser (S-1-5-21-1739335617-45622530-1743251556-1005 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= Name: TuneUpUtilitiesDrv Description: TuneUpUtilitiesDrv Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: TuneUpUtilitiesDrv Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: BHDrvx64 Description: BHDrvx64 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: BHDrvx64 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/12/2014 05:46:43 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:39:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Name des fehlerhaften Moduls: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Ausnahmecode: 0xc0000417 Fehleroffset: 0x000802d1 ID des fehlerhaften Prozesses: 0x100c Startzeit der fehlerhaften Anwendung: 0xDRIVERfighter.exe0 Pfad der fehlerhaften Anwendung: DRIVERfighter.exe1 Pfad des fehlerhaften Moduls: DRIVERfighter.exe2 Berichtskennung: DRIVERfighter.exe3 Error: (11/12/2014 05:37:38 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:37:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Name des fehlerhaften Moduls: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00026e56 ID des fehlerhaften Prozesses: 0x1324 Startzeit der fehlerhaften Anwendung: 0xNBAgent.exe0 Pfad der fehlerhaften Anwendung: NBAgent.exe1 Pfad des fehlerhaften Moduls: NBAgent.exe2 Berichtskennung: NBAgent.exe3 Error: (11/12/2014 05:37:01 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NBAgent.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei <Module>._wWinMainCRTStartup() Error: (11/12/2014 05:33:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2014 04:52:28 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:47:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Name des fehlerhaften Moduls: DRIVERfighter.exe, Version: 0.0.0.0, Zeitstempel: 0x506599ee Ausnahmecode: 0xc0000417 Fehleroffset: 0x000802d1 ID des fehlerhaften Prozesses: 0x121c Startzeit der fehlerhaften Anwendung: 0xDRIVERfighter.exe0 Pfad der fehlerhaften Anwendung: DRIVERfighter.exe1 Pfad des fehlerhaften Moduls: DRIVERfighter.exe2 Berichtskennung: DRIVERfighter.exe3 Error: (11/12/2014 04:44:51 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:44:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Name des fehlerhaften Moduls: NBAgent.exe, Version: 15.2.7.14, Zeitstempel: 0x5428e839 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00026e56 ID des fehlerhaften Prozesses: 0x10c8 Startzeit der fehlerhaften Anwendung: 0xNBAgent.exe0 Pfad der fehlerhaften Anwendung: NBAgent.exe1 Pfad des fehlerhaften Moduls: NBAgent.exe2 Berichtskennung: NBAgent.exe3 System errors: ============= Error: (11/12/2014 05:41:15 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "DaemonDirect3dTask" wurde nicht richtig gestartet. Error: (11/12/2014 05:39:02 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "CodecProcessSoftware" wurde nicht richtig gestartet. Error: (11/12/2014 05:35:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUpUtilitiesDrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (11/12/2014 05:34:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: BHDrvx64 Error: (11/12/2014 05:34:56 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "OCRSchemaTask.exe" wurde nicht richtig gestartet. Error: (11/12/2014 05:32:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (11/12/2014 05:32:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (11/12/2014 04:49:16 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "DaemonDirect3dTask" wurde nicht richtig gestartet. Error: (11/12/2014 04:47:11 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "CodecProcessSoftware" wurde nicht richtig gestartet. Error: (11/12/2014 04:43:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUpUtilitiesDrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (11/12/2014 05:46:43 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:39:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DRIVERfighter.exe0.0.0.0506599eeDRIVERfighter.exe0.0.0.0506599eec0000417000802d1100c01cffe96c15a098aC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exeC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe7d27b445-6a8a-11e4-8950-dca9715029f3 Error: (11/12/2014 05:37:38 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:30707, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 05:37:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NBAgent.exe15.2.7.145428e839NBAgent.exe15.2.7.145428e839c000000500026e56132401cffe96b4e739a4C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exeC:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exe243d2581-6a8a-11e4-8950-dca9715029f3 Error: (11/12/2014 05:37:01 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NBAgent.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei <Module>._wWinMainCRTStartup() Error: (11/12/2014 05:33:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/12/2014 04:52:28 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:47:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DRIVERfighter.exe0.0.0.0506599eeDRIVERfighter.exe0.0.0.0506599eec0000417000802d1121c01cffe8f86bea0dbC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exeC:\Program Files (x86)\Fighters\DRIVERfighter\DRIVERfighter.exe2eaac901-6a83-11e4-920e-dca9715029f3 Error: (11/12/2014 04:44:51 PM) (Source: Google Update) (EventID: 20) (User: *****-PCSamsung) Description: Network Request Error. Error: 0x80040880. Http status code: 200. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, named proxy=http=127.0.0.1:23665, bypass=<local>;*origin.com;*ea.com;*akamaihd.net. trying CUP:WinHTTP. Send request returned 0x80040880. Http status code 200. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=, direct connection. trying CUP:WinHTTP. Send request returned 0x80072efd. Http status code 0. trying WinHTTP. Send request returned 0x80072efd. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, named Error: (11/12/2014 04:44:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NBAgent.exe15.2.7.145428e839NBAgent.exe15.2.7.145428e839c000000500026e5610c801cffe8f84cabfe1C:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exeC:\Program Files (x86)\Nero\Nero BackItUp\NBAgent.exed2dcc965-6a82-11e4-920e-dca9715029f3 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz Percentage of memory in use: 28% Total physical RAM: 8104.29 MB Available physical RAM: 5784.97 MB Total Pagefile: 16206.76 MB Available Pagefile: 13612.89 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:165 GB) (Free:48.99 GB) NTFS Drive d: () (Fixed) (Total:509.87 GB) (Free:123.45 GB) NTFS Drive f: (STORE N GO) (Removable) (Total:14.44 GB) (Free:14.42 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 817D105E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=165 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=509.9 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=23.7 GB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 14.5 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=14.5 GB) - (Type=0C) ==================== End Of Log ============================ Danke om voraus für die Hilfe |
14.11.2014, 16:39 | #3 |
/// the machine /// TB-Ausbilder | PUP.Optional.InstallBrain.A - Laptop sehr langsam hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |