Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-10-2014
- Ran by mateo at 2014-10-20 13:13:21
- Running from C:\Users\mateo\Downloads
- Boot Mode: Normal
- ==========================================================
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Kaspersky PURE 3.0 (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
- AS: Kaspersky PURE 3.0 (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
- AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- FW: Kaspersky PURE 3.0 (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
- ==================== Installed Programs ======================
- (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
- Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
- Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
- BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.4.4078 - BlueStack Systems, Inc.)
- BlueStacks Notification Center (HKLM\...\{152E0B21-19D5-4772-9EF8-8E76074B0C0A}) (Version: 0.9.4.4078 - BlueStack Systems, Inc.)
- CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5118 - CDBurnerXP)
- F-Secure CCF Reputation (Version: 2.0.1337.0 - F-Secure) Hidden
- HD-V2.2V16.10 (HKLM\...\HD-V2.2V16.10) (Version: 1.35.9.29 - InfoHD-V2.2V16.10)
- Intel(R) Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3412 - Intel Corporation)
- Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
- ISO Recorder (HKLM\...\{1235083F-52F9-44CC-9DF5-F9B7802BB9B7}) (Version: 3.0.0 - Alex Feinman)
- Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
- Java Auto Updater (Version: 2.8.25.18 - Oracle Corporation) Hidden
- Kaspersky PURE 3.0 (HKLM\...\InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}) (Version: 13.0.2.558 - Kaspersky Lab)
- Kaspersky PURE 3.0 (Version: 13.0.2.558 - Kaspersky Lab) Hidden
- Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
- Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
- Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
- Mozilla Firefox 33.0 (x86 hr) (HKLM\...\Mozilla Firefox 33.0 (x86 hr)) (Version: 33.0 - Mozilla)
- Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla)
- Readon TV Movie Radio Player 7.5.0.0 (HKLM\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
- Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.75.827.2013 - Realtek)
- Realtek Ethernet Diagnostic Utility (HKLM\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 2.0.2.7 - Realtek)
- swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
- Update Service YourFileDownloader (HKCU\...\Update Service YourFileDownloader) (Version: 2.14.42 - http://www.yourfile-downloader.com) <==== ATTENTION
- VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
- WinRAR 5.11 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
- ==================== Custom CLSID (selected items): ==========================
- (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
- ==================== Restore Points =========================
- 16-10-2014 19:40:26 Windows Update
- 16-10-2014 20:25:47 Windows Update
- 16-10-2014 20:32:42 Windows Update
- 16-10-2014 20:36:32 Windows Update
- 16-10-2014 21:12:12 Language Pack Installation
- 16-10-2014 21:28:41 Installed SpyHunter
- 16-10-2014 21:42:50 Checkpoint by HitmanPro
- 16-10-2014 21:43:35 Checkpoint by HitmanPro
- 17-10-2014 03:34:14 Checkpoint by HitmanPro
- 17-10-2014 04:32:22 Installed Readon TV Movie Radio Player 7.5.0.0
- 17-10-2014 05:45:37 Windows Update
- 17-10-2014 20:33:45 Removed SpyHunter
- 18-10-2014 13:32:18 Removed F-Secure
- 18-10-2014 14:54:47 Installed ISO Recorder
- 19-10-2014 18:50:21 Windows Update
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
- ==================== Scheduled Tasks (whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
- Task: {15F289D8-73FE-466D-8BAF-40ABD5F62366} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3281968896-389192867-1985920646-1000
- Task: {860495CB-1C8F-4E79-8473-E864471EEC47} - \Update Service GoForFiles No Task File <==== ATTENTION
- Task: {DC83A2C6-A6CF-48C2-8DB0-CDF12978916F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-17] (Adobe Systems Incorporated)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- Task: C:\Windows\Tasks\JVHNTWG.job => C:\Users\mateo\AppData\Roaming\JVHNTWG.exe <==== ATTENTION
- Task: C:\Windows\Tasks\XHDYOVCG.job => C:\Users\mateo\AppData\Roaming\XHDYOVCG.exe <==== ATTENTION
- ==================== Loaded Modules (whitelisted) =============
- 2012-12-20 18:19 - 2012-12-20 18:19 - 00479752 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll
- 2012-12-20 18:19 - 2012-12-20 18:19 - 01310728 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\kpcengine.2.2.dll
- 2012-12-20 18:20 - 2012-12-20 18:20 - 00068616 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\QtWebKit\qmlwebkitplugin4.dll
- 2014-10-16 15:05 - 2014-10-11 14:53 - 03649648 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
- 2014-10-16 15:09 - 2014-10-16 15:09 - 16832176 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll
- ==================== Alternate Data Streams (whitelisted) =========
- (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
- ==================== Safe Mode (whitelisted) ===================
- (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
- ==================== EXE Association (whitelisted) =============
- (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
- ==================== MSCONFIG/TASK MANAGER disabled items =========
- (Currently there is no automatic fix for this section.)
- ========================= Accounts: ==========================
- Administrator (S-1-5-21-3281968896-389192867-1985920646-500 - Administrator - Disabled)
- Guest (S-1-5-21-3281968896-389192867-1985920646-501 - Limited - Disabled)
- mateo (S-1-5-21-3281968896-389192867-1985920646-1000 - Administrator - Enabled) => C:\Users\mateo
- ==================== Faulty Device Manager Devices =============
- Name:
- Description:
- Class Guid:
- Manufacturer:
- Service:
- Problem: : The drivers for this device are not installed. (Code 28)
- Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
- Name: PCI Simple Communications Controller
- Description: PCI Simple Communications Controller
- Class Guid:
- Manufacturer:
- Service:
- Problem: : The drivers for this device are not installed. (Code 28)
- Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
- Name: Teredo Tunneling Pseudo-Interface
- Description: Microsoft Teredo Tunneling Adapter
- Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
- Manufacturer: Microsoft
- Service: tunnel
- Problem: : This device cannot start. (Code10)
- Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
- On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (10/20/2014 00:53:46 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 11:44:24 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 10:09:27 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:36:16 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:23:37 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:14:49 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/19/2014 08:32:47 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Naziv aplikacije sa greškom: plugin-container.exe, verzija: 33.0.0.5397, vremenski pečat: 0x543924b1
- Naziv modula sa greškom: mozalloc.dll, verzija: 33.0.0.5397, vremenski pečat: 0x5438ffbb
- Kod izuzetka: 0x80000003
- Ofset greške: 0x00001425
- ID procesa sa greškom: 0x61c
- Vrijeme pokretanja aplikacije sa greškom: 0xplugin-container.exe0
- Putanja aplikacije sa greškom: plugin-container.exe1
- Putanja modula sa greškom: plugin-container.exe2
- ID izvještaja: plugin-container.exe3
- Error: (10/19/2014 07:21:26 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Naziv aplikacije sa greškom: FlashPlayerPlugin_15_0_0_189.exe, verzija: 15.0.0.189, vremenski pečat: 0x54233581
- Naziv modula sa greškom: FlashPlayerPlugin_15_0_0_189.exe, verzija: 15.0.0.189, vremenski pečat: 0x54233581
- Kod izuzetka: 0x40000015
- Ofset greške: 0x00017780
- ID procesa sa greškom: 0x1510
- Vrijeme pokretanja aplikacije sa greškom: 0xFlashPlayerPlugin_15_0_0_189.exe0
- Putanja aplikacije sa greškom: FlashPlayerPlugin_15_0_0_189.exe1
- Putanja modula sa greškom: FlashPlayerPlugin_15_0_0_189.exe2
- ID izvještaja: FlashPlayerPlugin_15_0_0_189.exe3
- Error: (10/19/2014 01:48:34 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Naziv aplikacije sa greškom: FlashPlayerPlugin_15_0_0_189.exe, verzija: 15.0.0.189, vremenski pečat: 0x54233581
- Naziv modula sa greškom: FlashPlayerPlugin_15_0_0_189.exe, verzija: 15.0.0.189, vremenski pečat: 0x54233581
- Kod izuzetka: 0x40000015
- Ofset greške: 0x00017780
- ID procesa sa greškom: 0x13a0
- Vrijeme pokretanja aplikacije sa greškom: 0xFlashPlayerPlugin_15_0_0_189.exe0
- Putanja aplikacije sa greškom: FlashPlayerPlugin_15_0_0_189.exe1
- Putanja modula sa greškom: FlashPlayerPlugin_15_0_0_189.exe2
- ID izvještaja: FlashPlayerPlugin_15_0_0_189.exe3
- Error: (10/19/2014 10:45:58 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Naziv aplikacije sa greškom: plugin-container.exe, verzija: 33.0.0.5397, vremenski pečat: 0x543924b1
- Naziv modula sa greškom: mozalloc.dll, verzija: 33.0.0.5397, vremenski pečat: 0x5438ffbb
- Kod izuzetka: 0x80000003
- Ofset greške: 0x00001425
- ID procesa sa greškom: 0x8ac
- Vrijeme pokretanja aplikacije sa greškom: 0xplugin-container.exe0
- Putanja aplikacije sa greškom: plugin-container.exe1
- Putanja modula sa greškom: plugin-container.exe2
- ID izvještaja: plugin-container.exe3
- System errors:
- =============
- Error: (10/20/2014 00:53:46 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The BlueStacks Android Service service terminated with the following error:
- %%1064
- Error: (10/20/2014 00:53:30 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The F-Secure ORSP Client service terminated with the following error:
- %%126
- Error: (10/20/2014 00:53:24 PM) (Source: EventLog) (EventID: 6008) (User: )
- Description: The previous system shutdown at 12:51:59 PM on 10/20/2014 was unexpected.
- Error: (10/20/2014 11:44:24 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The BlueStacks Android Service service terminated with the following error:
- %%1064
- Error: (10/20/2014 11:44:16 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The F-Secure ORSP Client service terminated with the following error:
- %%126
- Error: (10/20/2014 11:38:56 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Proactive Defence service terminated unexpectedly. It has done this 1 time(s).
- Error: (10/20/2014 11:38:53 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The 360 Internet Security Real-time Protection Loading Service service terminated unexpectedly. It has done this 1 time(s).
- Error: (10/20/2014 10:09:27 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The BlueStacks Android Service service terminated with the following error:
- %%1064
- Error: (10/20/2014 10:08:45 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
- Description: The F-Secure ORSP Client service terminated with the following error:
- %%126
- Error: (10/20/2014 09:45:45 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
- Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
- Microsoft Office Sessions:
- =========================
- Error: (10/20/2014 00:53:46 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 11:44:24 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 10:09:27 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:36:16 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:23:37 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/20/2014 09:14:49 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
- Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
- at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
- at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
- Error: (10/19/2014 08:32:47 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: plugin-container.exe33.0.0.5397543924b1mozalloc.dll33.0.0.53975438ffbb800000030000142561c01cfebca8928083dC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll521912b6-57be-11e4-bc1e-a57ef23e546d
- Error: (10/19/2014 07:21:26 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581FlashPlayerPlugin_15_0_0_189.exe15.0.0.189542335814000001500017780151001cfeba3bb44a608C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exeC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe5ad19a3a-57b4-11e4-bd26-40167e66a3f4
- Error: (10/19/2014 01:48:34 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581400000150001778013a001cfeb7e9bb6272eC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exeC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exeda778398-5785-11e4-bd26-40167e66a3f4
- Error: (10/19/2014 10:45:58 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: plugin-container.exe33.0.0.5397543924b1mozalloc.dll33.0.0.53975438ffbb80000003000014258ac01cfeb78355304b9C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll58559e74-576c-11e4-bd26-40167e66a3f4
- ==================== Memory info ===========================
- Processor: Intel(R) Celeron(R) CPU G1820 @ 2.70GHz
- Percentage of memory in use: 47%
- Total physical RAM: 3458.91 MB
- Available physical RAM: 1800.3 MB
- Total Pagefile: 6916.09 MB
- Available Pagefile: 4836.53 MB
- Total Virtual: 2047.88 MB
- Available Virtual: 1860.15 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:465.66 GB) (Free:431.62 GB) NTFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 8FE48FE4)
- Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
- Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
- ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement