Fix result of Farbar Recovery Scan Tool (x64) Version: 14-02-2017
Ran by Philipp (14-02-2017 03:58:58) Run:3
Running from C:\Users\Philipp\Desktop\Neuer Ordner
Loaded Profiles: Philipp (Available Profiles: Philipp)
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CloseProcesses:
createrestorepoint:
emptytemp:
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-09] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-09] (Google Inc.)
cmd: sc stop Hamachi2Svc
cmd: sc config "Hamachi2Svc" start= disabled
cmd: sc stop nlsvc
cmd: sc config "nlsvc" start= disabled
cmd: sc stop WinDefend
cmd: sc config "WinDefend" start= disabled
2017-02-09 14:03 - 2017-02-09 14:11 - 00003542 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-02-09 14:03 - 2017-02-09 14:11 - 00003414 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-01-28 01:38 - 2017-01-29 02:08 - 00016116 ____H C:\Users\Philipp\Desktop\~WRL1563.tmp
2017-02-05 04:03 - 2015-04-04 15:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2017-02-03 01:05 - 2013-08-27 18:41 - 00000000 ____D C:\Users\Philipp\AppData\LocalLow\Temp
2017-02-02 18:48 - 2016-11-10 23:32 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-01-31 17:16 - 2016-11-10 23:33 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-01-28 18:56 - 2014-04-01 19:52 - 03706368 ___SH C:\Users\Philipp\Desktop\Thumbs.db
Task: {17A04F93-676E-4E99-B675-8B2DB981C33D} - \Microsoft\Windows\Media Center\MediaCenterRecoveryTask -> No File <==== ATTENTION
Task: {28EF2A43-8120-46C3-9F99-EDC30F620B95} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {368A74BB-1374-4137-84E3-B04331E2B02D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-09] (Google Inc.)
Task: {6E3EEA2F-3B8E-43CC-B912-97B99F5EDEE4} - \Microsoft\Windows\Media Center\PvrScheduleTask -> No File <==== ATTENTION
Task: {76CFC989-BCF3-4C97-8873-C3917A7D2C5D} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {81540B9F-B5BF-47EB-9C95-BE195BF2C664} - \Microsoft\Windows\NetTrace\GatherNetworkInfo -> No File <==== ATTENTION
Task: {84A4DE72-FAF7-4371-A0E4-CDB4EE46ECBF} - \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask -> No File <==== ATTENTION
Task: {DEEDAE8C-2633-409C-BB39-696D01265C77} - \Microsoft\Windows\Media Center\SqlLiteRecoveryTask -> No File <==== ATTENTION
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\101hotteens.com -> 101hotteens.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\101lottery.com -> 101lottery.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\123expressview.com -> 123expressview.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\123found.com -> 123found.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\123keno.com -> 123keno.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\12don.info -> 12don.info
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\143fuck.com -> 143fuck.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\17gamo.com -> 17gamo.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\17webplace.com -> 17webplace.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\180solutions.com -> 180solutions.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1autocity.com -> 1autocity.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1ive.net -> 1ive.net
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1se.ru -> 1se.ru
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1sexparty.com -> 1sexparty.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1stfind.com -> 1stfind.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1stpagehere.com -> 1stpagehere.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1traff.us -> 1traff.us
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\1ze.net -> 1ze.net
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\2-antispyware.com -> 2-antispyware.com
IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\...\2004search.cc -> 2004search.cc
StartBatch:
netsh advfirewall reset
netsh advfirewall set allprofiles state ON
ipconfig /flushdns
netsh winsock reset All
netsh int ip reset c:\resetlog.txt
ipconfig /release
ipconfig /renew
netsh int ipv4 reset
netsh int ipv6 reset
bitsadmin /reset /allusers
reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
netsh interface ipv6 6to4 set state state=disabled undoonstop=disabled
netsh interface ipv6 isatap set state state=disabled
netsh interface teredo set state disabled
netsh interface tcp set global autotuning=disabled
reg add hklm\system\currentcontrolset\services\tcpip6\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF
for /F "tokens=*" %%a in ('wevtutil.exe el') DO wevtutil.exe cl "%%a"
EndBatch:
emptytemp:
reboot:
end
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3 => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9 => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => not found.
========= sc stop Hamachi2Svc =========
[SC] ControlService FEHLER 1062:
Der Dienst wurde nicht gestartet.
========= End of CMD: =========
========= sc config "Hamachi2Svc" start= disabled =========
[SC] ChangeServiceConfig ERFOLG
========= End of CMD: =========
========= sc stop nlsvc =========
[SC] ControlService FEHLER 1053:
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.
========= End of CMD: =========
========= sc config "nlsvc" start= disabled =========
[SC] ChangeServiceConfig ERFOLG
========= End of CMD: =========
========= sc stop WinDefend =========
SERVICE_NAME: WinDefend
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 4 RUNNING
(STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
========= End of CMD: =========
========= sc config "WinDefend" start= disabled =========
[SC] ChangeServiceConfig ERFOLG
========= End of CMD: =========
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Users\Philipp\Desktop\~WRL1563.tmp => moved successfully
C:\Windows\SysWOW64\GWX => moved successfully
C:\Users\Philipp\AppData\LocalLow\Temp => moved successfully
C:\Users\Public\Documents\temp.dat => moved successfully
C:\Users\Public\Documents\report.dat => moved successfully
C:\Users\Philipp\Desktop\Thumbs.db => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17A04F93-676E-4E99-B675-8B2DB981C33D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17A04F93-676E-4E99-B675-8B2DB981C33D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28EF2A43-8120-46C3-9F99-EDC30F620B95} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28EF2A43-8120-46C3-9F99-EDC30F620B95} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{368A74BB-1374-4137-84E3-B04331E2B02D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{368A74BB-1374-4137-84E3-B04331E2B02D} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E3EEA2F-3B8E-43CC-B912-97B99F5EDEE4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E3EEA2F-3B8E-43CC-B912-97B99F5EDEE4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{76CFC989-BCF3-4C97-8873-C3917A7D2C5D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76CFC989-BCF3-4C97-8873-C3917A7D2C5D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{81540B9F-B5BF-47EB-9C95-BE195BF2C664} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81540B9F-B5BF-47EB-9C95-BE195BF2C664} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetTrace\GatherNetworkInfo => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{84A4DE72-FAF7-4371-A0E4-CDB4EE46ECBF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{84A4DE72-FAF7-4371-A0E4-CDB4EE46ECBF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DEEDAE8C-2633-409C-BB39-696D01265C77} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEEDAE8C-2633-409C-BB39-696D01265C77} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\101hotteens.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\101lottery.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123expressview.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123found.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123keno.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\12don.info => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\143fuck.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\17gamo.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\17webplace.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\180solutions.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1autocity.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1ive.net => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1se.ru => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1sexparty.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1stfind.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1stpagehere.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1traff.us => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1ze.net => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2-antispyware.com => key removed successfully
HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2004search.cc => key removed successfully
========= Batch: =========
OK.
OK.
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
Schnittstelle wird zurckgesetzt, OK!
Starten Sie den Computer neu, um die Aktion abzuschlieáen.
Windows-IP-Konfiguration
Es kann kein Vorgang auf Drahtlosnetzwerkverbindung 2 ausgefhrt werden, solange dessen Medium nicht
verbunden ist.
Ethernet-Adapter LAN-Verbindung:
Medienstatus. . . . . . . . . . . : Medium getrennt
Verbindungsspezifisches DNS-Suffix:
Ethernet-Adapter Hamachi:
Verbindungsspezifisches DNS-Suffix:
www.youtube.de
IPv6-Adresse. . . . . . . . . . . : 2620:9b::191e:9649
Verbindungslokale IPv6-Adresse . : fe80::499e:3325:fea6:3498%21
Standardgateway . . . . . . . . . : 2620:9b::1900:1
Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 2:
Medienstatus. . . . . . . . . . . : Medium getrennt
Verbindungsspezifisches DNS-Suffix:
Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung:
Verbindungsspezifisches DNS-Suffix:
Verbindungslokale IPv6-Adresse . : fe80::a597:d9e3:f83e:e196%15
Standardgateway . . . . . . . . . :
Windows-IP-Konfiguration
Es kann kein Vorgang auf LAN-Verbindung ausgefhrt werden, solange dessen Medium nicht
verbunden ist.
Es kann kein Vorgang auf Drahtlosnetzwerkverbindung 2 ausgefhrt werden, solange dessen Medium nicht
verbunden ist.
Ethernet-Adapter LAN-Verbindung:
Medienstatus. . . . . . . . . . . : Medium getrennt
Verbindungsspezifisches DNS-Suffix:
Ethernet-Adapter Hamachi:
Verbindungsspezifisches DNS-Suffix:
www.youtube.de
IPv6-Adresse. . . . . . . . . . . : 2620:9b::191e:9649
Verbindungslokale IPv6-Adresse . : fe80::499e:3325:fea6:3498%21
IPv4-Adresse . . . . . . . . . . : 25.30.150.73
Subnetzmaske . . . . . . . . . . : 255.0.0.0
Standardgateway . . . . . . . . . : 2620:9b::1900:1
Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 2:
Medienstatus. . . . . . . . . . . : Medium getrennt
Verbindungsspezifisches DNS-Suffix:
Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung:
Verbindungsspezifisches DNS-Suffix:
Verbindungslokale IPv6-Adresse . : fe80::a597:d9e3:f83e:e196%15
IPv4-Adresse . . . . . . . . . . : 192.168.0.101
Subnetzmaske . . . . . . . . . . : 255.255.255.0
Standardgateway . . . . . . . . . : 192.168.0.1
Schnittstelle wird zurckgesetzt, OK!
Starten Sie den Computer neu, um die Aktion abzuschlieáen.
Unicastadresse wird zurckgesetzt, OK!
Route wird zurckgesetzt, OK!
Starten Sie den Computer neu, um die Aktion abzuschlieáen.
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {B2628311-CDD8-4FF1-86E9-3EF1BAAC3928}.
0 out of 1 jobs canceled.
Der Vorgang wurde erfolgreich beendet.
Der Vorgang wurde erfolgreich beendet.
Ein an das System angeschlossenes Ger„t funktioniert nicht.
OK.
OK.
OK.
Der Wert DisabledComponents ist vorhanden. šberschreiben (J/N)?
========= End of Batch: =========
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 3997682 B
Java, Flash, Steam htmlcache => 142270272 B