Jannes2000 | 10.08.2014 14:14 | Hallo,
vielen Dank für die schnelle Reaktion und die angebotene Unterstützung.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:10-08-2014
Ran by Administrator (administrator) on THOMAS-PC on 10-08-2014 15:07:41
Running from C:\tmp
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-06-23] (Microsoft Corporation)
HKU\S-1-5-21-3510325832-4164964488-3438324388-500\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3510325832-4164964488-3438324388-500\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: 0 => 0 File Not Found
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x30F3306A09B4CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKCU - DefaultScope {7633DDE8-C74E-41A3-B6A2-9E14D7ABF3D0} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {7633DDE8-C74E-41A3-B6A2-9E14D7ABF3D0} URL = https://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ChromeFrame BHO -> {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} -> C:\Program Files\Google\Chrome Frame\Application\32.0.1700.107\npchrome_frame.dll (Google Inc.)
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\32.0.1700.107\npchrome_frame.dll (Google Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR Extension: (Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-10]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-10]
CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-10]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-10]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-08-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-04] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-09-19] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-09-19] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1905488 2014-07-21] (LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-07-16] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2014-01-09] (Enigma Software Group USA, LLC.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26032 2013-06-02] (Wondershare)
S3 athur; C:\Windows\System32\DRIVERS\athur.sys [1500160 2012-05-31] (Atheros Communications, Inc.)
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2013-08-17] () [File not signed]
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-09-19] (BlueStack Systems)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15384 2014-01-07] ()
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 iscreenyfilter; C:\Windows\iscreenyfilter.sys [41632 2014-06-25] (NetFilterSDK.com)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2013-08-16] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 NVFLASH; C:\Windows\system32\drivers\nvflash.sys [13344 2013-04-19] ()
S3 RTL8187B; C:\Windows\System32\DRIVERS\rtl8187B.sys [379904 2010-03-31] (Realtek Semiconductor Corporation )
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-28] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-28] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-28] (Logitech Inc.)
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X]
S3 XDva405; \??\C:\Windows\system32\XDva405.sys [X]
S3 XDva410; \??\C:\Windows\system32\XDva410.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-10 12:46 - 2014-08-10 15:07 - 00000000 ____D () C:\FRST
2014-08-10 12:07 - 2014-08-10 12:07 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-10 12:07 - 2014-08-10 12:07 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-10 02:04 - 2014-08-10 02:07 - 00000860 _____ () C:\1.reg
2014-08-10 02:02 - 2014-08-10 02:21 - 00000686 _____ () C:\exe.reg
2014-08-10 01:52 - 2014-08-10 01:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Apps\2.0
2014-08-10 01:37 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-08-10 01:36 - 2014-08-10 03:04 - 00000000 ____D () C:\AdwCleaner
2014-08-10 01:17 - 2014-08-10 01:17 - 00000000 ____D () C:\Users\Administrator\Documents\Fax
2014-08-09 22:13 - 2014-08-09 22:13 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Origin
2014-08-09 22:13 - 2014-08-09 22:13 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Origin
2014-08-09 22:07 - 2014-08-10 15:03 - 00000282 _____ () C:\sh4_service.log
2014-08-09 22:05 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\system32\sh4native.exe
2014-08-09 21:58 - 2014-08-10 14:22 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-09 21:57 - 2014-08-09 21:57 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-09 21:57 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-09 21:57 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-09 21:57 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-09 21:40 - 2014-08-09 21:40 - 00002258 _____ () C:\Users\Administrator\Desktop\SpyHunter.lnk
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\sh4ldr
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-09 21:39 - 2014-08-09 21:40 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-08-09 21:39 - 2014-08-09 21:39 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieUserList
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieSiteList
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2014-08-09 21:25 - 2014-08-09 21:25 - 00000434 _____ () C:\Users\Thomas\Documents\Exe.reg
2014-08-09 21:10 - 2014-08-10 15:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LogMeIn Hamachi
2014-08-09 21:10 - 2014-08-09 21:10 - 00109280 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-09 21:10 - 2014-08-09 21:10 - 00001421 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-09 21:10 - 2014-08-09 21:10 - 00000818 __RSH () C:\Users\Administrator\ntuser.pol
2014-08-09 21:10 - 2014-08-09 21:10 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LogMeIn
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator
2014-08-09 21:10 - 2013-08-09 21:04 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help
2014-08-09 21:10 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-09 21:10 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-08-09 14:07 - 2014-08-09 14:07 - 00000000 ____D () C:\Windows\system32\Adobe
2014-08-05 08:15 - 2014-08-05 08:15 - 00000000 ____D () C:\Users\Thomas\Desktop\OperationCrackedServer
2014-08-05 08:14 - 2014-08-09 22:06 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Seventh
2014-08-04 13:38 - 2014-08-04 13:55 - 00000000 ____D () C:\Program Files\Brick-Force
2014-08-04 13:38 - 2014-08-04 13:38 - 00001000 _____ () C:\Users\Public\Desktop\Brick-Force.lnk
2014-08-04 13:38 - 2014-08-04 13:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brick-Force
2014-08-04 13:34 - 2014-08-04 13:41 - 257425680 _____ (Infernum Productions AG ) C:\Users\Thomas\Downloads\BrickForceSetup_EU.exe
2014-08-04 12:09 - 2014-08-04 13:41 - 05269663 _____ () C:\Users\Thomas\Documents\minecraft.jar
2014-08-04 12:00 - 2014-08-04 12:00 - 00137728 _____ () C:\Users\Thomas\Documents\OperationCrackedServer.exe
2014-08-04 11:59 - 2014-08-04 11:59 - 00137728 _____ () C:\Users\Thomas\Documents\OperationCrackedServer.zip
2014-08-04 11:59 - 2014-08-04 11:59 - 00000000 ____D () C:\Users\Thomas\Documents\OperationCrackedServer
2014-08-04 11:52 - 2012-07-25 12:03 - 00017136 _____ () C:\Windows\system32\sasnative32.exe
2014-08-04 11:50 - 2014-08-04 11:50 - 00000000 ____D () C:\Users\Thomas\AppData\Local\onlysearch
2014-08-04 11:36 - 2014-08-04 11:48 - 00349128 _____ () C:\Users\Thomas\Downloads\beatCelebPlayer.exe
2014-08-04 11:35 - 2014-08-04 11:35 - 00010719 _____ () C:\Users\Thomas\Downloads\ForcePermissionsV2.0[Minecraft 1.5.2] (1).rar
2014-08-04 11:33 - 2014-08-04 11:33 - 00010719 _____ () C:\Users\Thomas\Downloads\ForcePermissionsV2.0[Minecraft 1.5.2].rar
2014-08-04 11:11 - 2014-08-04 11:11 - 00137728 _____ () C:\Users\Thomas\Desktop\OperationCrackedServer.zip
2014-07-28 14:33 - 2014-07-28 14:33 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-07-28 14:26 - 2014-07-28 14:27 - 00000000 ____D () C:\Users\Thomas\Desktop\Musik
2014-07-28 14:25 - 2014-08-10 10:37 - 00000000 ____D () C:\Users\Thomas\Desktop\Minecraft
2014-07-27 06:40 - 2014-07-27 06:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-27 06:40 - 2014-07-27 06:40 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi
2014-07-22 18:32 - 2014-07-22 18:32 - 05981830 _____ (Tim Kosse) C:\Users\Thomas\Downloads\FileZilla_3.9.0.1_win32-setup.exe
2014-07-16 17:26 - 2014-07-16 17:29 - 00000000 ____D () C:\ProgramData\UqkoQazup
2014-07-15 19:46 - 2014-07-15 19:46 - 00000052 _____ () C:\Users\Thomas\Documents\20Tim01.yml
2014-07-15 19:40 - 2014-07-15 19:40 - 00000677 _____ () C:\Users\Thomas\Documents\config.yml
2014-07-15 19:40 - 2014-07-15 19:40 - 00000051 _____ () C:\Users\Thomas\Documents\ChillCrafter3000.yml
2014-07-15 19:34 - 2014-07-15 19:34 - 00000574 _____ () C:\Users\Thomas\Documents\server.properties
2014-07-15 19:24 - 2014-07-15 19:24 - 00021448 _____ () C:\Users\Thomas\Documents\rasions.yml
2014-07-15 19:23 - 2014-07-15 19:23 - 00021448 _____ () C:\Users\Thomas\Documents\permissions.yml
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-10 15:08 - 2013-06-22 18:45 - 01050327 _____ () C:\Windows\WindowsUpdate.log
2014-08-10 15:07 - 2014-08-10 12:46 - 00000000 ____D () C:\FRST
2014-08-10 15:07 - 2013-06-25 23:12 - 00000000 ____D () C:\tmp
2014-08-10 15:04 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LogMeIn Hamachi
2014-08-10 15:03 - 2014-08-09 22:07 - 00000282 _____ () C:\sh4_service.log
2014-08-10 15:03 - 2014-01-12 18:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-10 15:03 - 2009-07-14 06:39 - 00085302 _____ () C:\Windows\setupact.log
2014-08-10 15:02 - 2013-06-23 02:17 - 00285330 _____ () C:\Windows\PFRO.log
2014-08-10 14:22 - 2014-08-09 21:58 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-10 12:51 - 2009-07-14 06:34 - 00025392 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-10 12:51 - 2009-07-14 06:34 - 00025392 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-10 12:07 - 2014-08-10 12:07 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-10 12:07 - 2014-08-10 12:07 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-10 12:07 - 2013-06-23 01:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-10 12:07 - 2013-06-23 01:29 - 00000000 ____D () C:\ProgramData\Avira
2014-08-10 12:07 - 2013-06-23 01:29 - 00000000 ____D () C:\Program Files\Avira
2014-08-10 10:43 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Vss
2014-08-10 10:37 - 2014-07-28 14:25 - 00000000 ____D () C:\Users\Thomas\Desktop\Minecraft
2014-08-10 03:04 - 2014-08-10 01:36 - 00000000 ____D () C:\AdwCleaner
2014-08-10 02:21 - 2014-08-10 02:02 - 00000686 _____ () C:\exe.reg
2014-08-10 02:07 - 2014-08-10 02:04 - 00000860 _____ () C:\1.reg
2014-08-10 01:52 - 2014-08-10 01:52 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Apps\2.0
2014-08-10 01:40 - 2014-02-01 15:52 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Common
2014-08-10 01:40 - 2013-06-23 00:27 - 00000000 ____D () C:\Users\Thomas
2014-08-10 01:17 - 2014-08-10 01:17 - 00000000 ____D () C:\Users\Administrator\Documents\Fax
2014-08-09 22:54 - 2014-03-08 19:28 - 00000000 ____D () C:\Users\Thomas\AppData\Local\LogMeIn Hamachi
2014-08-09 22:13 - 2014-08-09 22:13 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Origin
2014-08-09 22:13 - 2014-08-09 22:13 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Origin
2014-08-09 22:13 - 2013-10-08 08:57 - 00000000 ____D () C:\Program Files\Origin
2014-08-09 22:06 - 2014-08-05 08:14 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Seventh
2014-08-09 21:57 - 2014-08-09 21:57 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-09 21:57 - 2014-08-09 21:57 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-09 21:46 - 2013-06-23 01:41 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\vlc
2014-08-09 21:40 - 2014-08-09 21:40 - 00002258 _____ () C:\Users\Administrator\Desktop\SpyHunter.lnk
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\sh4ldr
2014-08-09 21:40 - 2014-08-09 21:40 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-09 21:40 - 2014-08-09 21:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-08-09 21:39 - 2014-08-09 21:39 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieUserList
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieSiteList
2014-08-09 21:37 - 2014-08-09 21:37 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2014-08-09 21:25 - 2014-08-09 21:25 - 00000434 _____ () C:\Users\Thomas\Documents\Exe.reg
2014-08-09 21:10 - 2014-08-09 21:10 - 00109280 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-09 21:10 - 2014-08-09 21:10 - 00001421 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-09 21:10 - 2014-08-09 21:10 - 00000818 __RSH () C:\Users\Administrator\ntuser.pol
2014-08-09 21:10 - 2014-08-09 21:10 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LogMeIn
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-08-09 21:10 - 2014-08-09 21:10 - 00000000 ____D () C:\Users\Administrator
2014-08-09 21:10 - 2009-07-14 06:46 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-08-09 16:17 - 2013-09-16 14:56 - 00000736 _____ () C:\Users\Thomas\Desktop\Paintball2.lnk
2014-08-09 14:07 - 2014-08-09 14:07 - 00000000 ____D () C:\Windows\system32\Adobe
2014-08-09 12:52 - 2014-02-01 09:11 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-09 12:52 - 2014-02-01 09:11 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-06 10:19 - 2013-08-09 18:28 - 00000000 ___RD () C:\Program Files\Skype
2014-08-05 09:40 - 2014-06-01 10:14 - 00001999 _____ () C:\Users\Thomas\Desktop\Hunting Unlimited 2010.lnk
2014-08-05 08:22 - 2013-11-10 12:13 - 00000818 __RSH () C:\Users\Thomas\ntuser.pol
2014-08-05 08:20 - 2009-07-14 04:04 - 00000678 _____ () C:\Windows\win.ini
2014-08-05 08:17 - 2013-08-09 18:28 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Skype
2014-08-05 08:15 - 2014-08-05 08:15 - 00000000 ____D () C:\Users\Thomas\Desktop\OperationCrackedServer
2014-08-05 08:13 - 2013-12-24 20:27 - 00000000 ____D () C:\Program Files\Steam
2014-08-04 13:55 - 2014-08-04 13:38 - 00000000 ____D () C:\Program Files\Brick-Force
2014-08-04 13:41 - 2014-08-04 13:34 - 257425680 _____ (Infernum Productions AG ) C:\Users\Thomas\Downloads\BrickForceSetup_EU.exe
2014-08-04 13:41 - 2014-08-04 12:09 - 05269663 _____ () C:\Users\Thomas\Documents\minecraft.jar
2014-08-04 13:38 - 2014-08-04 13:38 - 00001000 _____ () C:\Users\Public\Desktop\Brick-Force.lnk
2014-08-04 13:38 - 2014-08-04 13:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brick-Force
2014-08-04 13:22 - 2013-08-10 08:53 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\.minecraft
2014-08-04 12:00 - 2014-08-04 12:00 - 00137728 _____ () C:\Users\Thomas\Documents\OperationCrackedServer.exe
2014-08-04 11:59 - 2014-08-04 11:59 - 00137728 _____ () C:\Users\Thomas\Documents\OperationCrackedServer.zip
2014-08-04 11:59 - 2014-08-04 11:59 - 00000000 ____D () C:\Users\Thomas\Documents\OperationCrackedServer
2014-08-04 11:50 - 2014-08-04 11:50 - 00000000 ____D () C:\Users\Thomas\AppData\Local\onlysearch
2014-08-04 11:48 - 2014-08-04 11:36 - 00349128 _____ () C:\Users\Thomas\Downloads\beatCelebPlayer.exe
2014-08-04 11:35 - 2014-08-04 11:35 - 00010719 _____ () C:\Users\Thomas\Downloads\ForcePermissionsV2.0[Minecraft 1.5.2] (1).rar
2014-08-04 11:33 - 2014-08-04 11:33 - 00010719 _____ () C:\Users\Thomas\Downloads\ForcePermissionsV2.0[Minecraft 1.5.2].rar
2014-08-04 11:11 - 2014-08-04 11:11 - 00137728 _____ () C:\Users\Thomas\Desktop\OperationCrackedServer.zip
2014-07-28 15:27 - 2013-08-10 08:45 - 00000000 ____D () C:\ProgramData\Origin
2014-07-28 14:33 - 2014-07-28 14:33 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-07-28 14:33 - 2013-08-09 18:28 - 00000000 ____D () C:\ProgramData\Skype
2014-07-28 14:27 - 2014-07-28 14:26 - 00000000 ____D () C:\Users\Thomas\Desktop\Musik
2014-07-27 13:00 - 2013-06-22 18:51 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-27 10:24 - 2014-02-08 13:41 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\TS3Client
2014-07-27 06:40 - 2014-07-27 06:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-27 06:40 - 2014-07-27 06:40 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi
2014-07-26 13:18 - 2013-12-16 20:15 - 00000000 ____D () C:\Users\Thomas\Documents\FIFA 13
2014-07-24 16:31 - 2014-07-07 15:08 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\FileZilla
2014-07-23 16:45 - 2014-07-07 15:08 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2014-07-22 18:35 - 2014-07-07 15:08 - 00001950 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2014-07-22 18:35 - 2014-07-07 15:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-07-22 18:32 - 2014-07-22 18:32 - 05981830 _____ (Tim Kosse) C:\Users\Thomas\Downloads\FileZilla_3.9.0.1_win32-setup.exe
2014-07-22 17:53 - 2013-12-24 20:28 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-07-19 16:23 - 2014-06-14 21:31 - 00000000 ____D () C:\Users\Thomas\Documents\FIFA World
2014-07-19 16:05 - 2014-01-26 20:21 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-18 16:37 - 2014-07-05 18:27 - 00000000 ____D () C:\Users\Thomas\Documents\kms
2014-07-17 15:20 - 2014-06-14 21:22 - 00001147 _____ () C:\Users\Public\Desktop\EA Sports FIFA World.lnk
2014-07-16 17:29 - 2014-07-16 17:26 - 00000000 ____D () C:\ProgramData\UqkoQazup
2014-07-16 17:25 - 2013-08-10 09:16 - 00000000 ____D () C:\Program Files\Origin Games
2014-07-16 17:25 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-07-15 19:46 - 2014-07-15 19:46 - 00000052 _____ () C:\Users\Thomas\Documents\20Tim01.yml
2014-07-15 19:40 - 2014-07-15 19:40 - 00000677 _____ () C:\Users\Thomas\Documents\config.yml
2014-07-15 19:40 - 2014-07-15 19:40 - 00000051 _____ () C:\Users\Thomas\Documents\ChillCrafter3000.yml
2014-07-15 19:34 - 2014-07-15 19:34 - 00000574 _____ () C:\Users\Thomas\Documents\server.properties
2014-07-15 19:24 - 2014-07-15 19:24 - 00021448 _____ () C:\Users\Thomas\Documents\rasions.yml
2014-07-15 19:23 - 2014-07-15 19:23 - 00021448 _____ () C:\Users\Thomas\Documents\permissions.yml
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\SHSetup.exe
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Thomas\AppData\Local\Temp\6_Offer_17.exe
C:\Users\Thomas\AppData\Local\Temp\APNSetup.exe
C:\Users\Thomas\AppData\Local\Temp\AutoRun.exe
C:\Users\Thomas\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Thomas\AppData\Local\Temp\avgnt.exe
C:\Users\Thomas\AppData\Local\Temp\BackupSetup.exe
C:\Users\Thomas\AppData\Local\Temp\bdfilters.dll
C:\Users\Thomas\AppData\Local\Temp\burnsetup.exe
C:\Users\Thomas\AppData\Local\Temp\comver.dll
C:\Users\Thomas\AppData\Local\Temp\Delta.exe
C:\Users\Thomas\AppData\Local\Temp\EAInstall.dll
C:\Users\Thomas\AppData\Local\Temp\focusbaseUntemp.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel0.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel1.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel2.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel3.exe
C:\Users\Thomas\AppData\Local\Temp\IEHistory.exe
C:\Users\Thomas\AppData\Local\Temp\InstalledPrograms.exe
C:\Users\Thomas\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R1.0-1-gf46bd58-b2793jnks.dll
C:\Users\Thomas\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Thomas\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Thomas\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Thomas\AppData\Local\Temp\oi_{9FF85A88-0FAA-43F9-848A-80E64D2D7697}.exe
C:\Users\Thomas\AppData\Local\Temp\oi_{F81439C3-4DA8-4360-9C0D-500BE64ADD0B}.exe
C:\Users\Thomas\AppData\Local\Temp\propsys.dll
C:\Users\Thomas\AppData\Local\Temp\ShoppinHelper2new2.exe
C:\Users\Thomas\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Thomas\AppData\Local\Temp\Softonic_chr_1-8-29-3_cn.exe
C:\Users\Thomas\AppData\Local\Temp\Softonic_DE_1-5-11_DE-Production_10_CleanRelease.exe
C:\Users\Thomas\AppData\Local\Temp\Softonic_DE_1-5-7.exe
C:\Users\Thomas\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Thomas\AppData\Local\Temp\uninst1.exe
C:\Users\Thomas\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Thomas\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Thomas\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\Thomas\AppData\Local\Temp\WSSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-09-11 15:14
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:9-08-2014 01
Ran by Administrator at 2014-08-10 12:48:26
Running from C:\tmp
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Avira (HKLM\...\{9590977b-7b6f-467e-a11a-efa1fae804da}) (Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
SpyHunter (HKLM\...\{AF549236-6258-4AC6-A043-5B5B89C6EB61}) (Version: 4.17.6.4336 - Enigma Software Group USA, LLC)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
10-08-2014 00:36:23 Installed Microsoft Fix it 50194
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {2EE32873-3616-452B-B889-2796E882B83A} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {33AF1FCF-C36C-48E2-BC70-4CFCD02B706D} - \BrowserDefendert No Task File <==== ATTENTION
Task: {4B036B25-8271-4DB0-96F4-E7F0760C796F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-11] (Adobe Systems Incorporated)
Task: {92967870-8ACE-4D31-99E6-A8DBCE023225} - \LyricsContainer Update No Task File <==== ATTENTION
Task: {DB71E212-2C12-49FA-BEC0-DE2E0DE67A61} - System32\Tasks\{83A38BB6-DD21-403D-8F20-F6F9F400649A} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.7.0.102/de/abandoninstall?source=lightinstaller&page=tsInstall
Task: {EF515692-901D-4B30-8CD0-AAB9D2E9AD0E} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\WINDOWS\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\Desk 365 RunAsStdUser.job => C:\Program Files\Desk 365\desk365.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf8baa843c803a.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photosmart 5510 series.exe_{D9BDD8E8-B799-4CCB-9CE9-A6BF7B05D604}.job => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HP Photosmart 5510 series.exe
Task: C:\Windows\Tasks\Opera D1.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D2.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D3.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D4.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D5.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D6.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera D7.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\Opera N.job => C:\Program Files\Opera\launcher.exe
Task: C:\Windows\Tasks\RunOW.job => C:\Program Files\Overwolf\Overwolf.exe
Task: C:\Windows\Tasks\ScanToPCActivationApp.exe_{10D200E6-A842-4EE6-A1FB-2CA8D9B79D3F}.job => C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
Task: C:\Windows\Tasks\Systweak Support Dock.job => C:\Program Files\Systweak Support Dock\SystweakDock.exe
Task: C:\Windows\Tasks\Toolbox.exe_{D8864932-1413-493A-9CD5-D3B9E0720CB1}.job => C:\Program Files\HP\HP Photosmart 5510 series\Bin\Toolbox.exe
Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files\TuneUp Utilities 2014\OneClick.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{F0C35313-02EA-433E-B9B7-B4752647DD0D}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) =============
2014-01-12 17:59 - 2013-03-15 04:59 - 00078624 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-07-24 11:50 - 2014-07-24 11:50 - 00137296 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll
2014-07-24 11:49 - 2014-07-24 11:49 - 00065104 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Advanced System Protector_startup => "C:\Program Files\Advanced System Protector\AdvancedSystemProtector.exe" autolaunch
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: Browser Infrastructure Helper => C:\Users\Thomas\AppData\Local\Smartbar\Application\Smartbar.exe startup
MSCONFIG\startupreg: BrowserSafeguard => "C:\Users\Thomas\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe"
MSCONFIG\startupreg: BrowserSafeguard Update Task => "C:\Users\Thomas\AppData\Local\BrowserSafeguard\uninstall.BrowserSafeguard.exe" /CheckUpdate=true
MSCONFIG\startupreg: iLivid => "C:\Users\Thomas\AppData\Local\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: Intermediate => "C:\Users\Thomas\AppData\Roaming\Intermediate\Intermediate.exe"
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: Thomas-PC)
Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren.
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: Thomas-PC)
Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden.
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1502) (User: Thomas-PC)
Description: Das lokal gespeicherte Profil kann nicht geladen werden. Mögliche Fehlerursachen sind nicht ausreichende Sicherheitsrechte oder ein beschädigtes lokales Profil.
Details - Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT-AUTORITÄT)
Description: Die Registrierung konnte nicht geladen werden. Dieses Problem wird oft durch zuwenig Arbeitsspeicher oder nicht ausreichende Sicherheitsberechtigungen verursacht.
Details - Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
for C:\Users\UpdatusUser\ntuser.dat
Error: (08/10/2014 00:01:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 11:59:23 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: DVSShellContextMenuExtension.dll, Version: 1.0.0.1, Zeitstempel: 0x5242ec17
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a7d8
ID des fehlerhaften Prozesses: 0x6ec
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (08/10/2014 03:09:11 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 03:05:27 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 01:51:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: DVSShellContextMenuExtension.dll, Version: 1.0.0.1, Zeitstempel: 0x5242ec17
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a7d8
ID des fehlerhaften Prozesses: 0xd9c
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (08/10/2014 01:41:49 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
System errors:
=============
Error: (08/10/2014 00:01:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064
Error: (08/10/2014 00:01:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275
Error: (08/10/2014 00:01:47 PM) (Source: Application Popup) (EventID: 875) (User: )
Description: Treiber atksgt.sys konnte nicht geladen werden.
Error: (08/10/2014 11:59:49 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:49 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:49 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (08/10/2014 11:59:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Microsoft Office Sessions:
=========================
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: Thomas-PC)
Description:
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: Thomas-PC)
Description:
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1502) (User: Thomas-PC)
Description: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
Error: (08/10/2014 00:04:10 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT-AUTORITÄT)
Description: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
C:\Users\UpdatusUser\ntuser.dat
Error: (08/10/2014 00:01:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 11:59:23 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d6727a7DVSShellContextMenuExtension.dll1.0.0.15242ec17c00000050000a7d86ec01cfb47732f23865C:\Windows\Explorer.EXEC:\Program Files\Common Files\DVDVideoSoft\lib\DVSShellContextMenuExtension.dll00865638-2075-11e4-b1c4-842b2bab3bd7
Error: (08/10/2014 03:09:11 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 03:05:27 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/10/2014 01:51:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d6727a7DVSShellContextMenuExtension.dll1.0.0.15242ec17c00000050000a7d8d9c01cfb42b83590657C:\Windows\Explorer.EXEC:\Program Files\Common Files\DVDVideoSoft\lib\DVSShellContextMenuExtension.dll18ce3882-2020-11e4-9707-842b2bab3bd7
Error: (08/10/2014 01:41:49 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
|