Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-08-17 11:57:03
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000030 ST500LM012_HN-M500MBB rev.2AR10002 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Amir\AppData\Local\Temp\pxrdypoc.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\wininit.exe[744] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\winlogon.exe[788] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\services.exe[832] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\lsass.exe[840] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[944] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\dwm.exe[304] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[252] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[740] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\igfxCUIService.exe[936] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\System32\spoolsv.exe[1480] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[1508] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1956] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\dashost.exe[2012] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\svchost.exe[2056] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\EscSvc64.exe[2368] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\EscSvc64.exe[2368] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8e1ac169a 4 bytes [AC, E1, F8, 7F]
.text C:\WINDOWS\system32\EscSvc64.exe[2368] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8e1ac16a2 4 bytes [AC, E1, F8, 7F]
.text C:\WINDOWS\system32\EscSvc64.exe[2368] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8e1ac181a 4 bytes [AC, E1, F8, 7F]
.text C:\WINDOWS\system32\EscSvc64.exe[2368] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8e1ac1832 4 bytes [AC, E1, F8, 7F]
.text C:\WINDOWS\system32\svchost.exe[2592] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\System32\svchost.exe[3032] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\taskhostex.exe[3168] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\Explorer.EXE[3292] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3504] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3808] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\igfxext.exe[2852] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe[3076] C:\WINDOWS\system32\KERNEL32.dll!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\DllHost.exe[3208] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Windows\System32\RuntimeBroker.exe[3764] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\SearchIndexer.exe[3324] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\igfxEM.exe[3276] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\igfxHK.exe[3352] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\igfxTray.exe[3856] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Windows\System32\skydrive.exe[4120] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4344] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4344] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8cb771f6a 4 bytes [77, CB, F8, 7F]
.text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[4344] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8cb771f82 4 bytes [77, CB, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4352] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4352] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8e1ac169a 4 bytes [AC, E1, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4352] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8e1ac16a2 4 bytes [AC, E1, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4352] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8e1ac181a 4 bytes [AC, E1, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4352] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8e1ac1832 4 bytes [AC, E1, F8, 7F]
.text C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe[4532] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4592] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4592] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8e1ac169a 4 bytes [AC, E1, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4592] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8e1ac16a2 4 bytes [AC, E1, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4592] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8e1ac181a 4 bytes [AC, E1, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4592] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8e1ac1832 4 bytes [AC, E1, F8, 7F]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[4988] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\Windows\System32\SettingSyncHost.exe[1456] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\AUDIODG.EXE[5628] C:\WINDOWS\SYSTEM32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\System32\svchost.exe[5896] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\SearchProtocolHost.exe[5860] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
.text C:\WINDOWS\system32\SearchFilterHost.exe[5436] C:\WINDOWS\system32\KERNEL32.DLL!GetBinaryTypeW + 165 00007ff8e34e553d 1 byte [62]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [736:752] fffff960009b9b90
Thread C:\WINDOWS\system32\svchost.exe [1508:1620] 00007ff8da161584
Thread C:\WINDOWS\system32\svchost.exe [1508:1728] 00007ff8d75e1b40
Thread C:\WINDOWS\Explorer.EXE [3292:1396] 00007ff8ce446220
Thread C:\WINDOWS\Explorer.EXE [3292:968] 00007ff8c932e7e8
Thread C:\WINDOWS\Explorer.EXE [3292:2336] 00007ff8c8d7a760
Thread C:\WINDOWS\Explorer.EXE [3292:5684] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:3896] 00007ff8d7a91120
Thread C:\WINDOWS\Explorer.EXE [3292:5824] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:5336] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:5884] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:1164] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:1832] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:4136] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:4180] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:1276] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:5356] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:4164] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:5364] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:2024] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:6120] 00007ff8c969d73c
Thread C:\WINDOWS\Explorer.EXE [3292:3912] 00007ff8c969d73c
Thread C:\Windows\System32\WWAHost.exe [5972:5996] 00007ff8e3e70310
Thread C:\Windows\System32\WWAHost.exe [5972:6000] 00007ff8dfbaa1f0
Thread C:\Windows\System32\WWAHost.exe [5972:6004] 00007ff8da18c78c
Thread C:\Windows\System32\WWAHost.exe [5972:6008] 00007ff8dfba9870
Thread C:\Windows\System32\WWAHost.exe [5972:6012] 00007ff8e02acb88
Thread C:\Windows\System32\WWAHost.exe [5972:6016] 00007ff8c66ab2a8
Thread C:\Windows\System32\WWAHost.exe [5972:6020] 00007ff8c66af3e0
Thread C:\Windows\System32\WWAHost.exe [5972:6024] 00007ff8c669a5f4
Thread C:\Windows\System32\WWAHost.exe [5972:6028] 00007ff8c66af3e0
Thread C:\Windows\System32\WWAHost.exe [5972:6032] 00007ff8e1b499b0
Thread C:\Windows\System32\WWAHost.exe [5972:6036] 00007ff8e1b499b0
Thread C:\Windows\System32\WWAHost.exe [5972:6040] 00007ff8c66af3e0
Thread C:\Windows\System32\WWAHost.exe [5972:6044] 00007ff8c66af3e0
Thread C:\Windows\System32\WWAHost.exe [5972:6052] 00007ff8c8358000
Thread C:\Windows\System32\WWAHost.exe [5972:6056] 00007ff8e3e70310
Thread C:\Windows\System32\WWAHost.exe [5972:6060] 00007ff8e3e70310
Thread C:\Windows\System32\WWAHost.exe [5972:6064] 00007ff8c833e10c
Thread C:\Windows\System32\WWAHost.exe [5972:6068] 00007ff8e1f7979c
Thread C:\Windows\System32\WWAHost.exe [5972:6072] 00007ff8c8384808
---- Processes - GMER 2.1 ----
Process C:\Users\Amir\AppData\Local\ContextFree\cntcmd.exe (*** suspicious ***) @ C:\Users\Amir\AppData\Local\ContextFree\cntcmd.exe [4416](2014-07-01 12:26:52) 0000000000400000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- Addition
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-08-2014 04
Ran by Amir at 2014-08-17 10:58:36
Running from C:\Users\Amir\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden
Adobe Reader X (10.1.11) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
ContextFree (HKCU\...\ContextFree) (Version: - )
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.0.1912 - CyberLink Corp.) Hidden
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4421.02 - CyberLink Corp.)
CyberLink PowerDVD 10 (x32 Version: 10.0.4421.02 - CyberLink Corp.) Hidden
Download Navigator (HKLM-x32\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
DriverIdentifier 4.2.8 (HKLM-x32\...\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1) (Version: - DriverIdentifier)
Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON XP-402 403 405 406 Series Printer Uninstall (HKLM\...\EPSON XP-402 403 405 406 Series) (Version: - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
FormatFactory 3.3.4.0 (HKLM-x32\...\FormatFactory) (Version: 3.3.4.0 - Format Factory)
Free YouTube to MP3 Converter version 3.12.27.225 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.27.225 - DVDVideoSoft Ltd.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.306 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Quick Starter (HKLM\...\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.2 - Samsung Electronics CO., LTD.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6702 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.12.10 - Samsung Electronics CO., LTD.)
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
Support Center (HKLM\...\{AB0DEFBB-1A16-47B5-86D2-39F0A2B24AE4}) (Version: 2.1.1210 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.14 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{D2B5F1E3-EA56-4D84-A453-A213B32974CB}) (Version: 2.1.25 - Samsung Electronics CO., LTD.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.14.2 - Synaptics Incorporated)
Windows-Treiberpaket - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3040086041-597881826-2770244332-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
09-08-2014 06:43:22 Windows Update
10-08-2014 08:16:52 Removed SlimCleaner Plus
12-08-2014 09:00:34 PROPLUS
13-08-2014 15:34:42 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {198B1B11-4EC3-4304-B456-1319FFE48CE9} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2014-03-21] (SEC)
Task: {1DE0CA86-2FC0-42EE-B3E5-675AE49C6571} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2559CBD2-D54B-411A-84C9-E2A689E2115A} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3AF93411-431B-46C0-80BC-5F3537BA5420} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {4246594E-21C4-4B0A-8EF3-CD92D17F6E8B} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2014-01-29] (Samsung Electronics CO., LTD.)
Task: {48F00B5F-2A96-4E17-A2E4-AFC5B1EC4AC9} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SAMSUNG-Amir SAMSUNG => C:\Program Files\Microsoft Office\Office15\MsoSync.exe
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4D7BF402-04E9-4799-B9B7-06ECC0961D0F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {4E39D30C-C5E7-49EF-B965-31961F5C1F53} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7BB1EC61-3140-48A7-9245-3DD56ECC42BA} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {8529FBE0-BD00-4845-BE5C-9E80CBC5628A} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - Amir) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9421C6C8-0392-47FB-B68E-4431D2CFD32A} - System32\Tasks\DriverUpdate Daily Scan => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A395F264-2878-4BFE-9342-9386EC9D51F0} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {AECFC2EA-1BC5-4429-A48D-3E4EDB3229F6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-21] (AVAST Software)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D4F1838F-B2D1-4B45-AEF2-FB800DF0E0ED} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DAC4896E-2E11-4EED-86D9-1CE6B09E1908} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-08-14] (Microsoft Corporation)
Task: {DC7B4C30-CABC-413D-8623-A18DE13B3C29} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2014-08-12] ()
Task: {E385F7CA-F2C4-4665-8923-33822FB32F79} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: C:\WINDOWS\Tasks\DriverUpdate Daily Scan.job => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe
Task: C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Amir).job => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
==================== Loaded Modules (whitelisted) =============
2014-01-29 13:20 - 2014-01-29 13:20 - 00084800 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2013-09-25 03:04 - 2013-09-25 03:04 - 00011264 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2013-09-25 03:01 - 2013-09-25 03:01 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll
2014-07-01 14:26 - 2014-07-01 14:26 - 00596480 _____ () C:\Users\Amir\AppData\Local\ContextFree\cntcmd.exe
2013-09-25 03:08 - 2013-09-25 03:08 - 00012928 _____ () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
2014-03-19 11:41 - 2014-03-19 11:41 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2014-07-21 10:00 - 2014-07-21 10:00 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-08-17 09:41 - 2014-08-17 09:41 - 02797568 _____ () C:\Program Files\AVAST Software\Avast\defs\14081700\algo.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00027968 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 01141056 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00025920 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00059712 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00102720 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2014-07-21 10:00 - 2014-07-21 10:00 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-11 11:13 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-08-11 08:43 - 2014-08-11 08:43 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\f95a84be655dce46534e2570f3b8bef6\PSIClient.ni.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Amir\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "RtHDVCpl"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKCU\...\StartupApproved\Run: => "EPLTarget\P0000000000000001"
HKCU\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKCU\...\StartupApproved\Run: => "Quick Starter"
HKCU\...\StartupApproved\Run: => "SlimCleaner Plus"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/14/2014 03:37:31 PM) (Source: Emulex HBA Management) (EventID: 260) (User: )
Description:
Error: (08/14/2014 03:35:00 PM) (Source: Emulex HBA Management) (EventID: 260) (User: )
Description:
Error: (08/13/2014 06:38:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm PhotoSketch.exe, Version 1.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: de8
Startzeit: 01cfb714df99a270
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnp\PhotoSketch.exe
Berichts-ID: 26e25420-2308-11e4-becf-1867b057de3f
Vollständiger Name des fehlerhaften Pakets: 44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnp
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (08/13/2014 06:37:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SAMSUNG)
Description: Bei der Aktivierung der App „44364DreamMobileStudio.PencilSketchCollage-PhotoEf_kktfx1x8prfnp!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (08/13/2014 06:37:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: SAMSUNG)
Description: Die App „44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnp+App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (08/13/2014 05:52:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SWMAgent.exe, Version: 2.1.25.4, Zeitstempel: 0x533e60a9
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x944
Startzeit der fehlerhaften Anwendung: 0xSWMAgent.exe0
Pfad der fehlerhaften Anwendung: SWMAgent.exe1
Pfad des fehlerhaften Moduls: SWMAgent.exe2
Berichtskennung: SWMAgent.exe3
Vollständiger Name des fehlerhaften Pakets: SWMAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: SWMAgent.exe5
Error: (08/13/2014 05:52:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: EasyLauncher.exe, Version: 2.0.0.10, Zeitstempel: 0x52e7528a
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x7f0
Startzeit der fehlerhaften Anwendung: 0xEasyLauncher.exe0
Pfad der fehlerhaften Anwendung: EasyLauncher.exe1
Pfad des fehlerhaften Moduls: EasyLauncher.exe2
Berichtskennung: EasyLauncher.exe3
Vollständiger Name des fehlerhaften Pakets: EasyLauncher.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: EasyLauncher.exe5
Error: (08/12/2014 00:23:22 PM) (Source: WindowsMangerProtect) (EventID: 102) (User: )
Description: WindowsMangerProtect
Error: (08/12/2014 00:06:10 PM) (Source: Registry Helper Service) (EventID: 109) (User: )
Description: Service started
Error: (08/12/2014 00:04:50 PM) (Source: WindowsMangerProtect) (EventID: 102) (User: )
Description: WindowsMangerProtect
System errors:
=============
Error: (08/17/2014 09:08:14 AM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (08/17/2014 09:08:14 AM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (08/17/2014 08:29:13 AM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (08/17/2014 08:16:59 AM) (Source: Tcpip) (EventID: 4199) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 2a02:8108:400:a54::2 mit dem Computer mit der
Netzwerkhardwareadresse B8-78-2E-82-16-8B ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.
Error: (08/16/2014 11:36:07 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst FontCache3.0.0.0 erreicht.
Error: (08/14/2014 03:38:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (08/14/2014 03:38:00 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.
Error: (08/14/2014 03:37:57 PM) (Source: DCOM) (EventID: 10016) (User: SAMSUNG)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SAMSUNGAmirS-1-5-21-3040086041-597881826-2770244332-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (08/14/2014 01:54:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (08/14/2014 01:54:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.
Microsoft Office Sessions:
=========================
Error: (08/14/2014 03:37:31 PM) (Source: Emulex HBA Management) (EventID: 260) (User: )
Description:
Error: (08/14/2014 03:35:00 PM) (Source: Emulex HBA Management) (EventID: 260) (User: )
Description:
Error: (08/13/2014 06:38:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: PhotoSketch.exe1.0.0.0de801cfb714df99a2704294967295C:\Program Files\WindowsApps\44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnp\PhotoSketch.exe26e25420-2308-11e4-becf-1867b057de3f44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnpApp
Error: (08/13/2014 06:37:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SAMSUNG)
Description: 44364DreamMobileStudio.PencilSketchCollage-PhotoEf_kktfx1x8prfnp!App-2144927142
Error: (08/13/2014 06:37:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: SAMSUNG)
Description: 44364DreamMobileStudio.PencilSketchCollage-PhotoEf_2.1.0.1_x64__kktfx1x8prfnp+App
Error: (08/13/2014 05:52:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: SWMAgent.exe2.1.25.4533e60a9unknown0.0.0.000000000c00000050000000094401cfb663bc7d7566C:\ProgramData\Samsung\SW Update Service\SWMAgent.exeunknownc6334a8e-2301-11e4-bece-1867b057de3f
Error: (08/13/2014 05:52:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasyLauncher.exe2.0.0.1052e7528aunknown0.0.0.000000000c0000005000000007f001cfb66371a79db0C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exeunknownc633237e-2301-11e4-bece-1867b057de3f
Error: (08/12/2014 00:23:22 PM) (Source: WindowsMangerProtect) (EventID: 102) (User: )
Description: WindowsMangerProtect
Error: (08/12/2014 00:06:10 PM) (Source: Registry Helper Service) (EventID: 109) (User: )
Description: Service started
Error: (08/12/2014 00:04:50 PM) (Source: WindowsMangerProtect) (EventID: 102) (User: )
Description: WindowsMangerProtect
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 30%
Total physical RAM: 3987.67 MB
Available physical RAM: 2769.79 MB
Total Pagefile: 4691.68 MB
Available Pagefile: 3354.55 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:435.87 GB) (Free:391.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 6F73E4D6)
Partition: GPT Partition Type.
==================== End Of Log ============================ --- --- --- |