Tactical | 27.02.2015 21:35 | Habe jetzt die Schritte gemacht die du mir beschrieben hast
AdwCleaner Code:
# AdwCleaner v4.111 - Bericht erstellt 27/02/2015 um 20:22:31
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-02-18.3 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x86)
# Benutzername : Julian - JULIAN-PC
# Gestarted von : C:\Users\Julian\Desktop\Neuer Ordner\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : iSafeKrnlMon
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\~Browser Manager
Ordner Gelöscht : C:\ProgramData\Rabatt-Finder
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Ordner Gelöscht : C:\Program Files\~Web Assistant
Ordner Gelöscht : C:\Program Files\vGrabber-software
Ordner Gelöscht : C:\Program Files\WinZipper
Ordner Gelöscht : C:\Program Files\YourFileDownloader
Ordner Gelöscht : C:\Program Files\YourFileDownloaderUpdater
Ordner Gelöscht : C:\Program Files\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Windows\system32\SearchProtect
Ordner Gelöscht : C:\Users\Julian\AppData\Local\DriverTuner
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\eUpdate
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\pccustubinstaller
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\webssearches
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\WinZipper
Ordner Gelöscht : C:\Users\Nostale\AppData\Roaming\WinZipper
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011\Extensions\faststartff@gmail.com
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\icgpkjefocaefijlgcpfodhflgeimbmp
Datei Gelöscht : C:\Program Files\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\4jfte2bv.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Nostale\AppData\Roaming\Mozilla\Firefox\Profiles\qc1ybrh2.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Program Files\Mozilla Firefox\browser\searchplugins\webssearches.xml
Datei Gelöscht : C:\Program Files\Mozilla Firefox\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : Browser Manager
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Julian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox1.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{9309FA47-1B48-4768-AFA4-9E0556F5DC81}]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\lollipop.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\SweetIM
Schlüssel Gelöscht : HKCU\Software\V9
Schlüssel Gelöscht : HKCU\Software\DriverTuner_Init
Schlüssel Gelöscht : HKCU\Software\DriverTuner
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricspal
Schlüssel Gelöscht : HKLM\SOFTWARE\delta-homesSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\hdcode
Schlüssel Gelöscht : HKLM\SOFTWARE\SweetIM
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\V9
Schlüssel Gelöscht : HKLM\SOFTWARE\webssearchesSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\winzipersvc
Schlüssel Gelöscht : HKLM\SOFTWARE\YourFileDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\DriverTuner_Init
Schlüssel Gelöscht : HKLM\SOFTWARE\DriverTuner
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\YourFileDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17631
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v36.0 (x86 de)
[4jfte2bv.default\prefs.js] - Zeile Gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7[...]
[4jfte2bv.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[4jfte2bv.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7-LaD0tpcxxXs8[...]
[4jfte2bv.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7-LapKT[...]
[njr71bvj.default-1402167148011\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[njr71bvj.default-1402167148011\prefs.js] - Zeile Gelöscht : user_pref("browser.search.hiddenOneOffs", "Yahoo,Amazon.de,AVG Secure Search,Bing,eBay,LEO Eng-Deu,Sichere Suche,Wikipedia (de),1&1 Suche,DuckDuckGo,Englische Ergebnisse,GMX Suche,Web Search,WEB.DE Bi[...]
[njr71bvj.default-1402167148011\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[njr71bvj.default-1402167148011\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[qc1ybrh2.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7-LapKT[...]
[qc1ybrh2.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
[qc1ybrh2.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[qc1ybrh2.default\prefs.js] - Zeile Gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7[...]
[qc1ybrh2.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwEZqA_FE8m8vFsdBYXrrsV0lnfXywdsY_NG6gKg-nItcAQEBinq7uoCUVYuNFI5naCKKFup7Vo071ggTIqOxq1b6U7-LaD0tpcxxXs8[...]
-\\ Google Chrome v
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : jifflliplgeajjdhmkcfnngfpgbjonjg
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : licjnkifamhpbaefhdpacpmihicfbomb
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : mmiopbgcekanlhpjkonogoljpfmhpkhf
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : nikpibnbobmbdbheedjfogjlikpgpnhp
[C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : icgpkjefocaefijlgcpfodhflgeimbmp
*************************
AdwCleaner[R0].txt - [10694 Bytes] - [27/02/2015 20:20:07]
AdwCleaner[S0].txt - [9996 Bytes] - [27/02/2015 20:22:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10055 Bytes] ########## mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 27.02.2015 20:36:38, SYSTEM, JULIAN-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 27.02.2015 20:36:38, SYSTEM, JULIAN-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.25.1,
Update, 27.02.2015 20:37:04, SYSTEM, JULIAN-PC, Manual, Malware Database, 2014.11.20.6, 2015.2.27.7,
(end) Jrt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Ultimate x86
Ran by Julian on 27.02.2015 at 21:22:21,30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Julian\start menu\programs\browser manager"
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Julian\AppData\Roaming\mozilla\firefox\profiles\njr71bvj.default-1402167148011\extensions\toolbar@web.de
Emptied folder: C:\Users\Julian\AppData\Roaming\mozilla\firefox\profiles\njr71bvj.default-1402167148011\minidumps [507 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.02.2015 at 21:25:45,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Frst/Addition
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-02-2015 01
Ran by Julian (administrator) on JULIAN-PC on 27-02-2015 21:28:33
Running from C:\Users\Julian\Desktop
Loaded Profiles: Julian & (Available profiles: Julian & Nostale & Gast)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\System32\PnkBstrA.exe
(NVIDIA Corporation) C:\Windows\System32\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Akamai Technologies, Inc.) C:\Users\Julian\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Julian\AppData\Local\Akamai\netsession_win.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-09] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-22] (Realtek Semiconductor)
HKLM\...\Run: [Aeria Ignite] => C:\Program Files\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-11-21] (Malwarebytes Corporation)
HKU\S-1-5-21-2387073909-981941339-3964768359-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Julian\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Akamai NetSession Interface] => C:\Users\Julian\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [Akamai NetSession Interface] => C:\Users\Julian\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-1004-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={F1FD8442-FCBE-478F-ACD1-8DAB903E97E3}&mid=a297a2f87e0d42b1b2e7c23bb4512575-35a2c3ae5ac1757a9316dfa173ba0f7dd2ac51d4&lang=de&ds=wa011&pr=&d=2012-09-16 18:39:50&v=13.2.0.5&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={F1FD8442-FCBE-478F-ACD1-8DAB903E97E3}&mid=a297a2f87e0d42b1b2e7c23bb4512575-35a2c3ae5ac1757a9316dfa173ba0f7dd2ac51d4&lang=de&ds=wa011&pr=&d=2012-09-16 18:39:50&v=13.2.0.5&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={F1FD8442-FCBE-478F-ACD1-8DAB903E97E3}&mid=a297a2f87e0d42b1b2e7c23bb4512575-35a2c3ae5ac1757a9316dfa173ba0f7dd2ac51d4&lang=de&ds=wa011&pr=&d=2012-09-16 18:39:50&v=13.2.0.5&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> BrowserMngrDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={F1FD8442-FCBE-478F-ACD1-8DAB903E97E3}&mid=a297a2f87e0d42b1b2e7c23bb4512575-35a2c3ae5ac1757a9316dfa173ba0f7dd2ac51d4&lang=de&ds=wa011&pr=&d=2012-09-16 18:39:50&v=13.2.0.5&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb178/?search={searchTerms}&loc=IB_DS&a=6R8C9TZabu&i=26
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin -> C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @nexon.com/NxGame -> C:\ProgramData\Nexon\NGM\npNxGame.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-2387073909-981941339-3964768359-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Julian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Julian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011\searchplugins\youtube-videosuche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF Extension: Battlefield Heroes Updater - C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011\Extensions\battlefieldheroespatcher@ea.com [2014-07-12]
FF Extension: Adblock Plus - C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\njr71bvj.default-1402167148011\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-07]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2012-08-18]
Chrome:
=======
CHR Profile: C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-29]
CHR Extension: (Google Drive) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-29]
CHR Extension: (YouTube) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-29]
CHR Extension: (Google Search) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-29]
CHR Extension: (SiteAdvisor) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-03-29]
CHR Extension: (Gmail) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2015-01-13]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
S2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R2 McAfee SiteAdvisor Service; c:\Program Files\McAfee\SiteAdvisor\McSACore.exe [131136 2014-12-03] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
S3 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2014-07-13] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [85776 2012-12-16] (SANDBOXIE L.T.D)
R2 Stereo Service; C:\Windows\System32\nvSCPAPISvr.exe [239208 2009-12-11] (NVIDIA Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-06-26] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 drvr; C:\Windows\system32\drivers\drvr.sys [8704 2010-03-09] () [File not signed]
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [157776 2012-12-16] (SANDBOXIE L.T.D)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U0 whaifxho; C:\Windows\System32\drivers\ckaqxi.sys [52440 2015-02-27] (Malwarebytes Corporation)
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [X]
S3 XDva398; \??\C:\Windows\system32\XDva398.sys [X]
S3 XDva399; \??\C:\Windows\system32\XDva399.sys [X]
S3 XDva400; \??\C:\Windows\system32\XDva400.sys [X]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X]
S3 XDva402; \??\C:\Windows\system32\XDva402.sys [X]
S3 XDva404; \??\C:\Windows\system32\XDva404.sys [X]
S3 XDva405; \??\C:\Windows\system32\XDva405.sys [X]
S3 XDva407; \??\C:\Windows\system32\XDva407.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-27 21:28 - 2015-02-27 21:29 - 00016068 _____ () C:\Users\Julian\Desktop\FRST.txt
2015-02-27 21:23 - 2015-02-27 21:23 - 00052440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\ckaqxi.sys
2015-02-27 20:36 - 2015-02-27 20:37 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-27 20:36 - 2015-02-27 20:36 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-27 20:36 - 2015-02-27 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-27 20:35 - 2015-02-27 20:36 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-27 20:35 - 2015-02-27 20:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-27 20:35 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-27 20:35 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-27 20:35 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-27 20:30 - 2015-02-27 21:26 - 00000000 ____D () C:\Users\Julian\Desktop\AdwCleaner
2015-02-27 20:20 - 2015-02-27 20:22 - 00000000 ____D () C:\AdwCleaner
2015-02-27 20:16 - 2015-02-27 20:17 - 00000000 ____D () C:\Users\Julian\Desktop\Neuer Ordner
2015-02-26 20:18 - 2015-02-27 20:22 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-02-25 22:19 - 2015-02-25 22:19 - 00258258 _____ () C:\Windows\msxml4-KB2758694-enu.LOG
2015-02-25 16:11 - 2015-02-25 16:11 - 00000967 _____ () C:\Users\Julian\Desktop\CCleaner.lnk
2015-02-25 15:59 - 2015-02-25 15:59 - 00160552 _____ () C:\Windows\Minidump\022515-26613-01.dmp
2015-02-25 15:51 - 2015-02-25 15:51 - 00160504 _____ () C:\Windows\Minidump\022515-17284-01.dmp
2015-02-24 21:03 - 2015-02-24 21:03 - 00160504 _____ () C:\Windows\Minidump\022415-17316-01.dmp
2015-02-24 20:57 - 2015-02-24 20:57 - 00160504 _____ () C:\Windows\Minidump\022415-18532-01.dmp
2015-02-24 20:18 - 2015-02-27 21:28 - 00000000 ____D () C:\FRST
2015-02-24 20:18 - 2015-02-24 20:17 - 02087424 _____ (Farbar) C:\Users\Julian\Desktop\FRST64.exe
2015-02-24 20:16 - 2015-02-24 20:13 - 01127424 _____ (Farbar) C:\Users\Julian\Desktop\FRST.exe
2015-02-24 20:14 - 2015-02-24 20:14 - 00160504 _____ () C:\Windows\Minidump\022415-16707-01.dmp
2015-02-24 19:59 - 2015-02-24 19:59 - 00160504 _____ () C:\Windows\Minidump\022415-23571-01.dmp
2015-02-24 19:53 - 2015-02-24 19:53 - 00139920 _____ () C:\Windows\Minidump\022415-23680-01.dmp
2015-02-24 19:49 - 2015-02-24 19:49 - 00000000 _____ () C:\Windows\Minidump\022415-18595-01.dmp
2015-02-24 19:02 - 2015-02-24 19:34 - 00000000 ____D () C:\Users\Julian\Desktop\blueee
2015-02-24 19:02 - 2015-02-24 19:00 - 00067310 _____ () C:\Users\Julian\Desktop\bluescreenview_v1.55.zip
2015-02-24 18:56 - 2015-02-24 18:56 - 00000000 ____D () C:\Users\Julian\Desktop\blue
2015-02-24 18:55 - 2015-02-24 18:55 - 00160504 _____ () C:\Windows\Minidump\022415-17986-01.dmp
2015-02-24 18:53 - 2015-02-24 18:54 - 00139968 _____ () C:\Windows\Minidump\022415-24913-01.dmp
2015-02-24 15:13 - 2015-02-24 15:13 - 00000000 _____ () C:\Windows\Minidump\022415-18064-01.dmp
2015-02-24 15:12 - 2015-02-24 15:12 - 00160552 _____ () C:\Windows\Minidump\022415-25116-01.dmp
2015-02-24 13:39 - 2015-02-24 13:39 - 00139968 _____ () C:\Windows\Minidump\022415-19390-01.dmp
2015-02-24 13:38 - 2015-02-24 13:38 - 00000000 _____ () C:\Windows\Minidump\022415-18891-01.dmp
2015-02-24 13:36 - 2015-02-24 13:36 - 00000000 _____ () C:\Windows\Minidump\022415-19375-01.dmp
2015-02-24 07:19 - 2015-02-24 07:19 - 00139968 _____ () C:\Windows\Minidump\022415-13634-01.dmp
2015-02-24 07:18 - 2015-02-24 07:18 - 00000000 _____ () C:\Windows\Minidump\022415-20311-01.dmp
2015-02-24 07:17 - 2015-02-24 07:17 - 00160552 _____ () C:\Windows\Minidump\022415-13837-01.dmp
2015-02-24 07:16 - 2015-02-24 07:16 - 00000000 _____ () C:\Windows\Minidump\022415-23836-01.dmp
2015-02-23 19:15 - 2015-02-25 16:21 - 00000000 ____D () C:\Users\Julian\AppData\Local\Downloaded Installations
2015-02-23 19:15 - 2015-02-23 19:15 - 00012828 _____ () C:\Windows\DPINST.LOG
2015-02-23 19:15 - 2015-02-23 19:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
2015-02-23 19:14 - 2015-02-25 16:21 - 00000000 ____D () C:\Program Files\HTC
2015-02-23 19:14 - 2015-02-23 19:14 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-02-23 19:14 - 2015-02-23 19:14 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-02-23 19:14 - 2015-02-23 19:14 - 00000000 ____D () C:\Program Files\Spirent Communications
2015-02-23 19:14 - 2015-02-23 19:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-02-23 19:13 - 2015-02-23 19:13 - 00000000 ____D () C:\Program Files\MSXML 4.0
2015-02-23 19:03 - 2015-02-23 19:03 - 01203488 _____ () C:\Users\Julian\Downloads\HTC Sync - CHIP-Installer.exe
2015-02-12 12:48 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 12:48 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 15:00 - 2015-01-15 08:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 15:00 - 2015-01-15 08:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 15:00 - 2015-01-15 08:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 15:00 - 2015-01-15 08:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 15:00 - 2015-01-15 08:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 15:00 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 15:00 - 2015-01-15 08:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 15:00 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 15:00 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 15:00 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 15:00 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 15:00 - 2015-01-15 05:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 15:00 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 15:00 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 15:00 - 2015-01-09 02:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 14:59 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 14:59 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 14:59 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 14:59 - 2015-01-12 03:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:59 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 14:59 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 14:59 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:59 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:59 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 14:59 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 14:59 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 14:59 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 14:59 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 14:59 - 2015-01-12 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:59 - 2015-01-12 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:59 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 14:59 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:59 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 14:59 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 14:59 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 14:59 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 14:59 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 14:59 - 2015-01-12 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 14:59 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:59 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 14:59 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 14:59 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 14:59 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 14:59 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 14:58 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 14:57 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-27 21:23 - 2013-09-03 17:42 - 00000000 ____D () C:\Users\Julian\AppData\Local\DM
2015-02-27 21:23 - 2013-06-29 17:48 - 00000000 ____D () C:\Program Files\Chromer
2015-02-27 21:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help
2015-02-27 20:40 - 2013-03-12 13:17 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-27 20:37 - 2009-07-14 05:34 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-27 20:37 - 2009-07-14 05:34 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-27 20:33 - 2012-08-18 17:02 - 01754319 _____ () C:\Windows\WindowsUpdate.log
2015-02-27 20:24 - 2014-03-03 08:27 - 00085049 _____ () C:\Windows\setupact.log
2015-02-27 20:24 - 2013-03-12 13:17 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-27 20:24 - 2012-07-02 20:17 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-27 20:24 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-27 20:22 - 2013-03-29 16:11 - 00001152 _____ () C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-27 20:12 - 2014-01-07 18:02 - 00000000 ____D () C:\Users\Julian\AppData\Roaming\Skype
2015-02-27 07:01 - 2012-09-13 09:58 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-02-25 20:59 - 2014-03-07 23:15 - 00000000 ____D () C:\Users\Julian\AppData\Roaming\tor
2015-02-25 15:59 - 2012-07-02 20:03 - 00000000 ____D () C:\Windows\Minidump
2015-02-24 21:03 - 2014-03-08 09:08 - 01679148 _____ () C:\Windows\PFRO.log
2015-02-24 07:20 - 2014-01-03 17:24 - 08954368 ___SH () C:\Users\Julian\Desktop\Thumbs.db
2015-02-23 19:14 - 2014-05-11 07:43 - 00000000 ____D () C:\Program Files\Adobe
2015-02-23 19:14 - 2013-11-25 15:26 - 00000000 ____D () C:\Users\Julian\AppData\Local\Adobe
2015-02-23 19:14 - 2012-08-18 20:18 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-23 19:14 - 2012-07-02 19:08 - 00000000 ____D () C:\Users\Julian\AppData\Roaming\Adobe
2015-02-22 17:05 - 2014-08-11 14:30 - 00000000 ____D () C:\Program Files\osu!
2015-02-17 17:50 - 2012-11-01 14:28 - 00003072 ____H () C:\Users\Julian\Desktop\photothumb.db
2015-02-17 17:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-02-11 19:02 - 2009-07-14 05:33 - 00427984 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-11 19:00 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-02-11 16:12 - 2013-07-22 14:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 16:02 - 2012-08-25 15:00 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-11 14:48 - 2013-05-02 10:32 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-11 14:48 - 2012-11-02 14:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-11 14:47 - 2012-11-02 14:38 - 00000000 ____D () C:\Program Files\Avira
==================== Files in the root of some directories =======
2013-06-26 20:20 - 2013-06-26 20:21 - 0003716 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2014-07-12 22:08 - 2014-07-12 22:08 - 0138056 _____ () C:\Users\Julian\AppData\Roaming\PnkBstrK.sys
2013-08-29 10:04 - 2013-08-29 10:04 - 0000218 _____ () C:\Users\Julian\AppData\Local\recently-used.xbel
2012-08-25 13:39 - 2013-06-18 14:04 - 0007600 _____ () C:\Users\Julian\AppData\Local\Resmon.ResmonCfg
2012-09-16 17:45 - 2012-09-16 17:45 - 0877747 ____N () C:\Users\Julian\AppData\Local\Tempmusic.ogg
2014-01-07 18:15 - 2014-01-07 18:15 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Some content of TEMP:
====================
C:\Users\Julian\AppData\Local\Temp\avgnt.exe
C:\Users\Julian\AppData\Local\Temp\Quarantine.exe
C:\Users\Julian\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-17 17:16
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-02-2015 01
Ran by Julian at 2015-02-27 21:29:31
Running from C:\Users\Julian\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4K Video Downloader 3.4 (HKLM\...\4K Video Downloader_is1) (Version: 3.4.3.1485 - Open Media LLC)
AbiWord 2.9.4 (HKLM\...\AbiWord2) (Version: 2.9.4 - AbiSource Developers)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.3.300.271 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.9.900.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Aeria Ignite (HKLM\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-2387073909-981941339-3964768359-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Akamai) (Version: - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Akamai) (Version: - Akamai Technologies, Inc)
ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0056 - ASUS)
AudioCon (HKLM\...\AudioCon) (Version: 1.0 - Basement Softworks)
Avira (HKLM\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
CCleaner (HKLM\...\CCleaner) (Version: 3.20 - Piriform)
Cheat Engine 6.2 (HKLM\...\Cheat Engine 6.2_is1) (Version: - Dark Byte)
Chromer (HKLM\...\Chromer) (Version: 1.27.153.7 - David Rosenau)
Deluge 1.3.6 (HKLM\...\Deluge) (Version: - )
EVEREST Ultimate Edition v5.50 (HKLM\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
Free Studio version 2014 (HKLM\...\Free Studio_is1) (Version: 6.3.4.604 - DVDVideoSoft Ltd.)
Free YouTube Download version 3.2.20.1230 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.20.1230 - DVDVideoSoft Ltd.)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HTC BMP USB Driver (HKLM\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.5.0.001 - HTC Corporation)
IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC)
Java 7 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.400 - Oracle)
Lagarith Lossless Codec (1.3.27) (HKLM\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.0.318.3 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.156 - McAfee, Inc.)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - German/Deutsch (HKLM\...\Office14.OMUI.de-de) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office ScreenTip Language 2010 - Deutsch (HKLM\...\{90140000-00BD-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM\...\{cde5fd82-4a8f-483e-adf0-ca7343d00433}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Web Platform Installer 4.0 (HKLM\...\{1F4DF099-EA5C-482D-9901-C0A8B539B417}) (Version: 4.0.1622 - Microsoft Corporation)
Mozilla Firefox 36.0 (x86 de) (HKLM\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MP3 Skype Recorder (HKLM\...\{CB606F47-7D0E-40DF-95BB-0E5413A1295F}) (Version: 3.1.3 - Alexander Nikiforov)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Network_Me (HKU\S-1-5-21-2387073909-981941339-3964768359-1001\...\vveett) (Version: - )
Network_Me (HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\vveett) (Version: - )
Nostale(DE) (HKLM\...\NosTale(DE)_is1) (Version: - Gameforge 4D GmbH)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (HKLM\...\NVIDIAStereo) (Version: 7.16.11.8836 - NVIDIA Corporation)
OpenOffice.org 3.4.1 (HKLM\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation)
osu! (HKLM\...\{c482a533-4188-4476-948c-5b36dc4c3464}) (Version: latest - ppy Pty Ltd)
Pamela RME 2.0 (HKLM\...\MoodEditor) (Version: 2.0 - Scendix Software-Vertriebsges. mbH)
PDF Architect 2 (HKLM\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM\...\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PE Explorer 1.99 R6 (HKLM\...\PE Explorer_is1) (Version: 1.99.6 - Heaventools Software)
PhotoScape (HKLM\...\PhotoScape) (Version: - )
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6010 - Realtek Semiconductor Corp.)
S4 League (HKLM\...\S4 League) (Version: - )
Sandboxie 3.76 (32-bit) (HKLM\...\Sandboxie) (Version: 3.76 - SANDBOXIE L.T.D)
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SRS Premium Sound Control Panel (HKLM\...\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}) (Version: 1.8.2900 - SRS Labs, Inc.)
Unity Web Player (HKU\S-1-5-21-2387073909-981941339-3964768359-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Update Service YourFileDownloader (HKU\S-1-5-21-2387073909-981941339-3964768359-1001\...\Update Service YourFileDownloader) (Version: 2.14.33 - hxxp://yourfiledownloader.biz) <==== ATTENTION
Update Service YourFileDownloader (HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Update Service YourFileDownloader) (Version: 2.14.33 - hxxp://yourfiledownloader.biz) <==== ATTENTION
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{10DD084E-A5AE-456F-A3BE-DA67EBE6B090}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{15B6FEE5-5FB3-4071-AC1F-7AEDC0E2A6BB}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{1BCA4635-F1FC-44C8-B829-48229AEB32E3}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{222C0F35-3D78-4570-9F6D-BAEE289D0304}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{29DCD339-D184-469B-8BFB-199A2CCF014E}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{2DBCDA9F-1248-400B-A382-A56D71BF7B15}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{2EEAB6D0-491E-4962-BBA1-FF1CCA6D4DD0}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{3506CDB7-8BC6-40C0-B108-CEA0B9480130}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{3D3E7C1B-79A7-4CC7-8925-41FA813E9913}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{3E01D8E0-A72B-4C9F-99BD-8A6E7B97A48D}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{42FE718B-A148-41D6-885B-01A0AFAE8723}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Julian\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{452CCB69-6A95-4370-9E5A-B3EFB06A7651}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{4B42750B-57A1-47E7-B340-8EAE0E3126A4}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{52071016-E648-4D3B-B57E-2B46CC993CE0}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{5792FC7D-5E1D-4F1A-BD4F-A7A50F92BC6E}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{5E541E71-A474-4EAD-8FCB-24D400D023B7}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{61F8FAF0-82D0-407C-AE97-31441483AE40}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{6AC51E9C-7947-4B46-A978-0AD601C4EFC9}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{6FA10A39-4760-4C94-A210-2398848618EC}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{7ACDC5B4-76A1-4BDF-918D-6962FCABBAD3}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{7B030003-037D-490D-9169-A4F391B3D831}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\ooofilt.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{830690FC-BF2F-47A6-AC2D-330BCB402664}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{89DD2F9D-C325-48BF-A615-96BD039BBC83}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{9017071A-2E34-4C3A-9BBB-688CBB5A9FF2}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{9D073235-D787-497D-8D1F-929559F1C621}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{A7DF2611-D752-4C9F-A90A-B56F18485EE9}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{A8109DB9-88E0-42FE-98EA-8A12BE5394C6}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{A983C9EC-D73E-4364-B89B-ACD1E405674F}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{B09AC3FF-0D5D-41C6-A34E-7C3F58A3127C}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{B0FE88F0-C92F-46D6-878F-31599BEA944C}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{CC461FC3-C9BE-41FB-8E47-E0115CBC01CC}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{D26B1D42-9C42-4E7B-BB73-86384C4B4345}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{DD0E8ED5-1494-4B87-A35C-39F6ED4B1153}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{E1BC9147-C3E3-4E8A-8304-5E6B5C1C0774}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{F278D870-7AF7-4957-96EE-E6AC72D0B109}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{F3188CF3-EF22-4C5B-92CB-605964761C3B}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
CustomCLSID: HKU\S-1-5-21-2387073909-981941339-3964768359-1001_Classes\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}\InprocServer32 -> C:\Program Files\MP3 Skype Recorder\Skype4COM.dll (Skype Technologies)
==================== Restore Points =========================
25-02-2015 16:07:40 Windows Update
25-02-2015 16:19:44 Removed HTC Sync.
25-02-2015 22:19:07 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0B117E92-91E3-4616-9C1C-1FA740FC44FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-06-22] (Piriform Ltd)
Task: {2B2E4E5F-6663-4752-AEAA-93DCB60EEEDD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {4082450E-351D-4DF9-BFDB-091043412ADD} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {4F7E02DC-CFE2-40FA-B2A5-272486C8C140} - System32\Tasks\{7D04E16C-69BE-45F2-BEED-B383B38A5161} => pcalua.exe -a C:\Users\Julian\Downloads\S4League-Up2Date-Installer.exe -d C:\Users\Julian\Downloads
Task: {52E7C94E-B0D4-486D-B7FE-99DDA6911CF4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12] (Google Inc.)
Task: {702BBE6C-96DA-43E4-9B5B-36890D362AB2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12] (Google Inc.)
Task: {8723B04C-9180-4C27-977F-683EECB9818C} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8EA166BB-D9C6-4C3B-9B0E-3A7343D40430} - System32\Tasks\{76C5A62B-5404-4CB0-9D8F-A0C9DD21C98E} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {DA3C4353-E444-44C4-9C50-7E1C24C8E1C5} - System32\Tasks\{1BA77861-0805-469E-B225-D6AD729A3D32} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {DC1900EC-88A0-4BF6-A92D-7A0949968E89} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Task: {DF011BC1-A556-4E8D-89B6-85510D4F45D4} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files\IObit\Game Booster 3\AutoUpdate.exe
Task: {E93E73E9-0D78-4589-A7B3-51D727F2E772} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-25] (Adobe Systems Incorporated)
Task: {FF78FE28-4861-4716-8732-66469043F796} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{6F7F8466-DEB4-40EB-80EB-177DCB61DA2F}.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2015-02-23 19:15 - 2012-12-07 17:26 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2014-07-12 22:08 - 2014-07-13 01:00 - 00076888 _____ () C:\Windows\system32\PnkBstrA.exe
2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2387073909-981941339-3964768359-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
HKU\S-1-5-21-2387073909-981941339-3964768359-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
HKU\S-1-5-21-2387073909-981941339-3964768359-1004-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Nexus\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2387073909-981941339-3964768359-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Nexus\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2387073909-981941339-3964768359-1006-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Nostale\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2387073909-981941339-3964768359-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Nostale\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2387073909-981941339-3964768359-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS Premium Sound.lnk => C:\Windows\pss\SRS Premium Sound.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Julian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vveett.lnk => C:\Windows\pss\vveett.lnk.Startup
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Dxtory Update Checker 2.0 => C:\Program Files\Dxtory Software\Dxtory2.0\UpdateChecker.exe
MSCONFIG\startupreg: Google Update => "C:\Users\Julian\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: HControlUser => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
MSCONFIG\startupreg: MP3 Skype Recorder => C:\Program Files\MP3 Skype Recorder\MP3 Skype Recorder.exe
MSCONFIG\startupreg: Overwolf => C:\Program Files\Overwolf\Overwolf.exe -silent
MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: vveett => "c:\users\julian\appdata\local\vveett.exe" /r
==================== Accounts: =============================
Administrator (S-1-5-21-2387073909-981941339-3964768359-500 - Administrator - Disabled)
Gast (S-1-5-21-2387073909-981941339-3964768359-501 - Limited - Disabled) => C:\Users\Gast
HomeGroupUser$ (S-1-5-21-2387073909-981941339-3964768359-1002 - Limited - Enabled)
Julian (S-1-5-21-2387073909-981941339-3964768359-1001 - Administrator - Enabled) => C:\Users\Julian
Nostale (S-1-5-21-2387073909-981941339-3964768359-1006 - Limited - Enabled) => C:\Users\Nostale
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T6670 @ 2.20GHz
Percentage of memory in use: 28%
Total physical RAM: 3583.27 MB
Available physical RAM: 2546.57 MB
Total Pagefile: 7164.83 MB
Available Pagefile: 5908.58 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.38 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:74.52 GB) (Free:12.4 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:208.92 GB) (Free:205.31 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 76692CA8)
Partition 1: (Not Active) - (Size=14.6 GB) - (Type=1C)
Partition 2: (Active) - (Size=74.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=208.9 GB) - (Type=OF Extended)
==================== End Of Log ============================ |