|
Plagegeister aller Art und deren Bekämpfung: JollyWallet, Coupon Werbung und unsichtbare Links in ChromeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.07.2015, 06:57 | #16 |
| JollyWallet, Coupon Werbung und unsichtbare Links in Chrome addition.txt: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:30-07-2015 durchgeführt von Admin (2015-07-31 07:52:18) Gestartet von C:\Users\Admin\Desktop Start-Modus: Normal ========================================================== ==================== Konten: ============================= Admin (S-1-5-21-500210103-394823293-4185795276-1000 - Administrator - Enabled) => C:\Users\Admin Administrator (S-1-5-21-500210103-394823293-4185795276-500 - Administrator - Disabled) Dori (S-1-5-21-500210103-394823293-4185795276-1002 - Limited - Enabled) => C:\Users\Dori Gast (S-1-5-21-500210103-394823293-4185795276-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-500210103-394823293-4185795276-1012 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-PDF Split & Merge Version 2.0.3 (Build 264) (HKLM-x32\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.0.3 (Build 264) - 7-PDF, Germany - Thorsten Hodes) ABBYY PDF Transformer+ (HKLM\...\{FA400000-0001-6400-0000-074957833700}) (Version: 4.1.241 - ABBYY Production LLC) abgx360 v1.0.6 (HKLM-x32\...\abgx360) (Version: - ) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated) Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) AI Suite II (HKLM-x32\...\{34D3688E-A737-44C5-9E2A-FF73618728E1}) (Version: 1.02.03 - ASUSTeK Computer Inc.) AMD Catalyst Install Manager (HKLM\...\{14D58A97-B60E-A858-34D8-95469C02F7EC}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.0.0.0 - SlySoft) Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}) (Version: 5.1.1.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Application Verifier (x64) (HKLM\...\{361A49FA-59B3-49FB-8C3E-08AF3EA5791A}) (Version: 4.0.917 - Microsoft Corporation) ARIS Express (HKLM-x32\...\{1252F398-5142-4D81-AD31-8B0204C26E8C}) (Version: 1.00 - Ihr Firmenname) Ashampoo Burning Studio 14 v.14.0.1 (HKLM-x32\...\{91B33C97-7BCF-CDFE-4321-58EBF3E8641C}_is1) (Version: 14.0.1 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.1.0 - Asmedia Technology) Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6086 - AVG Technologies) AVG 2015 (Version: 15.0.4401 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.6086 - AVG Technologies) Hidden AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.5.143 - AVG Technologies) Avidemux 2.5 (HKLM-x32\...\Avidemux 2.5 (64-bit)) (Version: 2.5.6.7716 - ) AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin) Axure RP Pro 7.0 (HKLM-x32\...\Axure RP Pro 7.0) (Version: 7.0.0.3174 - Axure Software Solutions, Inc.) Axure RP Pro 7.0 (x32 Version: 7.0.0.3174 - Axure Software Solutions, Inc.) Hidden Balsamiq Mockups For Desktop (HKLM-x32\...\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1) (Version: 2.2.6 - Balsamiq, SRL) Balsamiq Mockups For Desktop (x32 Version: 2.2.6 - Balsamiq, SRL) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - ) Canon IJ Network Scan Utility (HKLM-x32\...\Canon_IJ_Network_Scan_UTILITY) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) Canon MG5200 series Benutzerregistrierung (HKLM-x32\...\Canon MG5200 series Benutzerregistrierung) (Version: - ) Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version: - ) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.08009 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.08009 - Cisco Systems, Inc.) Hidden CloneCD (HKLM-x32\...\CloneCD) (Version: - SlySoft) CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.2.8 - Elaborate Bytes) Corel PaintShop Pro X7 (HKLM-x32\...\_{176F50D6-6857-49CE-B731-65F757EE3F0D}) (Version: 17.0.0.199 - Corel Corporation) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts) Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.2.0287 - DT Soft Ltd) DATA BECKER BewerbungsGenie 7 (HKLM-x32\...\BewerbungsGenie 7_is1) (Version: 6.0.10.49 - DATA BECKER GmbH & Co. KG) Dear Esther (HKLM-x32\...\Dear Esther_is1) (Version: - ) Debugging Tools for Windows (x64) (HKLM\...\{7F2E5C3B-DBDF-469D-AD8D-F686D3B71176}) (Version: 6.11.1.404 - Microsoft Corporation) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.84 - DivX, LLC) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve ) Dropbox (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Dropbox) (Version: 3.8.5 - Dropbox, Inc.) EA Sports FIFA World (HKLM-x32\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 7.0.0.47449 - Electronic Arts, Inc.) FINAL FANTASY VII (HKLM-x32\...\Steam App 39140) (Version: - Square Enix) FINAL FANTASY VIII (HKLM-x32\...\Steam App 39150) (Version: - SQUARE ENIX) foobar2000 v1.1.10 (HKLM-x32\...\foobar2000) (Version: 1.1.10 - Peter Pawlowski) Football Manager 2014 version 14.1.4 (HKLM-x32\...\Football Manager 2014_is1) (Version: 14.1.4 - Sega) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free YouTube to MP3 Converter version 3.12.50.1122 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1122 - DVDVideoSoft Ltd.) GanttProject (HKLM-x32\...\GanttProject) (Version: - ) Geometry Wars 3 Dimensions (HKLM-x32\...\Geometry Wars 3 Dimensions_is1) (Version: - ) Google Chrome (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Google Chrome) (Version: 44.0.2403.125 - Google Inc.) Google Drive (HKLM-x32\...\{6EA8B94E-D869-4D96-88DF-5E1ECE1D6876}) (Version: 1.23.9648.8824 - Google, Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden HashCheck Shell Extension (x86-32) (HKLM-x32\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu) HashCheck Shell Extension (x86-64) (HKLM\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu) Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2890573) (HKLM-x32\...\{A1F50E06-E514-393D-AAEB-2F989F0B7C68}.KB2890573) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2529927) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2529927) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2548139) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2548139) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2549864) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2549864) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2635973) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2635973) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2890573) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2890573) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB3002340) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB3002340) (Version: 1 - Microsoft Corporation) ICA (x32 Version: 17.0.0.199 - Corel Corporation) Hidden ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!) IPM_PSP_COM64 (Version: 17.0.0.199 - Corel Corporation) Hidden iTunes (HKLM\...\{CF8FFD12-602B-422D-AF1D-511B411E7632}) (Version: 10.6.1.7 - Apple Inc.) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader Packages (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\JDownloader Packages) (Version: - ) <==== ACHTUNG KeyMan V4.0 Build 5 (HKLM-x32\...\{DC627AE5-A2B1-4D16-AF56-178D10EC3E81}) (Version: 4.0.0.5 - ZF Electronics GmbH) K-Lite Codec Pack 8.1.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 8.1.0 - ) KProbe 2.5.2 (HKLM-x32\...\KProbe) (Version: - ) Launchy 2.5 (HKLM-x32\...\Launchy_21344213_is1) (Version: - Code Jelly) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Logitech Gaming Software 8.40 (HKLM\...\Logitech Gaming Software) (Version: 8.40.83 - Logitech Inc.) Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.) Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.) Logitech Webcam Software-Treiberpaket (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - DEU (HKLM-x32\...\{E4E9CBC9-1CF5-48E3-AF6F-1AB44A856346}) (Version: 2.0.50331.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - DEU (HKLM-x32\...\{31C3C6EA-E991-405F-A3AA-2C070CCCC47C}) (Version: 2.0.50331.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Silverlight 3 SDK - Deutsch (HKLM-x32\...\{91F54E1D-804A-46D8-A56C-53EA9C4B3177}) (Version: 3.0.40818.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK - Deutsch (HKLM-x32\...\{803910CC-3A39-45E3-A594-0D5512A60A86}) (Version: 4.0.50826.0 - Microsoft Corporation) Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 Browser (HKLM-x32\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Native Client (HKLM\...\{8325FD0C-2FDB-46C3-921A-3A78385EA972}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{E9089B6A-1FDE-47F3-8D29-175F5B7A0722}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\...\{5ADA62BD-2FC0-4ECE-93AA-C933E69B2AB5}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Transact-SQL-Sprachdienst (HKLM-x32\...\{BB1E119E-CF4B-4183-910E-A8C2B379F2C6}) (Version: 10.50.1752.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Framework (HKLM-x32\...\{919E5477-D20B-4F64-AE8B-8199469F7817}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Projekt (HKLM-x32\...\{103A5E44-DD5B-46D5-AD1E-9DF2260CA023}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\...\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation) Microsoft SQL Server Native Client (HKLM\...\{7C39E0D1-E138-42B1-B083-213EC2CF7692}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{C668416A-9213-4058-B7F2-01A42D85559D}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (HKLM\...\{0D432429-C79C-462D-ABD8-4D82B83A954B}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{28D06854-572C-4A65-83E5-F8CAF26B9FDC}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Sync Framework Runtime v1.0 SP1 (x64) de (HKLM\...\{7AC5FFA7-6815-4AED-B16D-8E0D7CC4B221}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework SDK v1.0 SP1 de (HKLM-x32\...\{08DA8E46-ED67-451A-9246-50E0FF6959C9}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework Services v1.0 SP1 (x64) de (HKLM\...\{EF9A1373-9238-4E11-8FF8-7B83996F5BE5}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) de (HKLM\...\{11EB3D68-A5BE-43EA-8D31-43B08ADB0DA4}) (Version: 2.0.3010.0 - Microsoft Corporation) Microsoft Team Foundation Server 2010-Objektmodell - DEU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - DEU) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 (HKLM\...\{95A2AD24-BD44-3E39-A31F-CE928276577E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x64 (HKLM\...\{965DF723-5688-359E-84D2-417CAFE644B5}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x86 (HKLM-x32\...\{44D9A2CB-0692-3180-B5E2-26F4E807D067}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual F# 2.0 Runtime Language Pack - DEU (HKLM-x32\...\{681F4E9F-34E0-36BD-BF2C-100554E403A5}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 IntelliTrace Collection (x64) (HKLM\...\{E1C1D175-C23E-38F4-9AC1-ABE5167022CF}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010 Ultimate - DEU (HKLM-x32\...\Microsoft Visual Studio 2010 Ultimate - DEU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Macro Tools - DEU Language Pack (HKLM-x32\...\Microsoft Visual Studio Macro Tools - DEU Language Pack) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Macro Tools (HKLM-x32\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Windows SDK for Windows 7 (7.0) (HKLM\...\SDKSetup_7.0.7600.16385.40715) (Version: 7.0.7600.16385.40715 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Middle Earth Shadow of Mordor (HKLM-x32\...\Middle Earth Shadow of Mordor_is1) (Version: - ) Might & Magic Heroes VI (HKLM-x32\...\{745D37C2-26F4-4B65-BA13-F9840EBFA75B}) (Version: 1.1 - Ubisoft) MKVToolNix 6.2.0 (HKLM-x32\...\MKVToolNix) (Version: 6.2.0 - Moritz Bunkus) Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.2 - Mozilla) MyFreeCodec (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\MyFreeCodec) (Version: - ) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger) Nmap 5.51 (HKLM-x32\...\Nmap) (Version: - ) No23 Recorder (HKLM-x32\...\No23 Recorder) (Version: 2.1.0.3 - No23) No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.3 - Notepad++ Team) O&O Defrag Professional (HKLM\...\{C34D47BA-7A0E-4AFE-954B-254CCABCC032}) (Version: 17.0.490 - O&O Software GmbH) One Finger Death Punch (HKLM-x32\...\Steam App 264200) (Version: - Silver Dollar Games) Ontrack EasyRecovery Professional (HKLM-x32\...\InstallShield_{268723B7-A994-4286-9F85-B974D5CAFC7B}) (Version: 6.22.01 - Kroll Ontrack Inc.) Ontrack EasyRecovery Professional (x32 Version: 6.22.01 - Kroll Ontrack Inc.) Hidden Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.) Pesgalaxy.com Patch 2015 (HKLM-x32\...\Pesgalaxy.com Patch 2015 4.00) (Version: 4.00 - Pesgalaxy) Pesgalaxy.com Patch 2015 DLC Installer (HKLM-x32\...\Pesgalaxy.com Patch 2015 DLC Installer 4.00) (Version: 4.00 - Pesgalaxy) Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) Phase 5 HTML-Editor (HKLM-x32\...\{20B1B020-DEAE-48D1-9960-D4C3185D758B}) (Version: 5.6.2.3 - Systemberatung Schommer) Power Manager (HKLM-x32\...\{CA2CE23E-6751-4828-AF8B-66EA06E697F6}) (Version: 4.0.2.1 - Gembird Electronics Ltd.) Pro Evolution Soccer 2015 (HKLM-x32\...\Steam App 287680) (Version: - KONAMI Digital Entertainment) Project CARS (HKLM-x32\...\UHJvamVjdENBUlM=_is1) (Version: 1 - ) Protect Disc License Helper 1.0.125 (IE) (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\Protect Disc License Helper) (Version: 1.0.125 - Protect Disc) ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH) PSPPContent (x32 Version: 17.0.0.199 - Corel Corporation) Hidden PSPPHelp (x32 Version: 17.0.0.199 - Corel Corporation) Hidden PSPPro64 (Version: 17.0.0.199 - Corel Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) QIP 2012 4.0.7058 (HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\QIP 2012) (Version: 4.0.7058 - ) Quake Live (HKLM-x32\...\Steam App 282440) (Version: - id Software) QuickMark (HKLM-x32\...\{53B0213C-CC0C-4340-90BF-BFC7D3FE5BB4}) (Version: 3.8.0 - SimpleAct) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.43.321.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.42 - Piriform) Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version: - Cellar Door Games) Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.) SABnzbd 0.7.20 (HKLM-x32\...\SABnzbd) (Version: 0.7.20 - The SABnzbd Team) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.2.0.12014_18 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.2.0.12014_18 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.) Seagate Dashboard 2.0 (HKLM-x32\...\{43C423D9-E6D6-4607-ADC9-EBB54F690C57}) (Version: 2.0.3602.0 - Seagate) Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Setup (x32 Version: 17.0.0.199 - Ihr Firmenname) Hidden Shrew Soft VPN Client (HKLM\...\Shrew Soft VPN Client) (Version: - ) Sicherheitsupdate für Microsoft Visual Studio 2010 Ultimate - DEU (KB2645410) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2645410) (Version: 1 - Microsoft Corporation) Sid Meiers Civilization Beyond Earth (HKLM-x32\...\U2lkTWVpZXJzQ2l2aWxpemF0aW9uQmV5b25kRWFydGg=_is1) (Version: 1 - ) SiSoftware Sandra Business 2012.SP1 (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1) (Version: 18.24.2012.1 - SiSoftware) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.) SnapaShot Pro 4.0.5.0 (HKLM-x32\...\{CC4A651E-C818-4089-8307-6764AFF04D2E}) (Version: 4.0.50 - NiceKit) SopCast 3.4.8 (HKLM-x32\...\SopCast) (Version: 3.4.8 - www.sopcast.com) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Sweet Home 3D version 4.3 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.41110 - TeamViewer) The Elder Scrolls V - Skyrim (HKLM-x32\...\The Elder Scrolls V - Skyrim_is1) (Version: - ) The Elder Scrolls V Skyrim - High Resolution Texture Pack (HKLM-x32\...\The Elder Scrolls V Skyrim - High Resolution Texture Pack_is1) (Version: - ) The Witcher 2 (HKLM-x32\...\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}) (Version: 1.00.0000 - CD Projekt Red) The Witcher 3 Wild Hunt Version 1.02 (HKLM-x32\...\{0E0E1973-8765-48CD-8CB8-5F3C050A3404}_is1) (Version: 1.02 - Rapid Games) TomTom HOME 2.8.4.2596 (HKLM-x32\...\TomTom HOME) (Version: 2.8.4.2596 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Tor 0.2.3.25 (HKLM-x32\...\Tor) (Version: - ) TreeSize Professional V5.5.3 (HKLM-x32\...\TreeSize Professional_is1) (Version: 5.5.3 - JAM Software) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unified Remote (HKLM-x32\...\{415B4714-4F8C-49C6-B310-881EAF892CFB}_is1) (Version: 3.2.4 - Unified Intents AB) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (HKLM-x32\...\{07629207-FAA0-4F1A-8092-BF5085BE511F}) (Version: 9.00.5000.00 - Microsoft Corporation) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{6AF73222-EE90-434C-AE7E-B96F70A68D89}) (Version: 10.1.2731.0 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2010 Prerequisites - English (HKLM\...\{53952792-BF16-300E-ADF2-E7E4367E00CF}) (Version: 10.0.40219 - Microsoft Corporation) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.0.6 (HKLM-x32\...\VLC media player) (Version: 2.0.6 - VideoLAN) VMware Workstation (HKLM-x32\...\VMware_Workstation) (Version: 10.0.4 - VMware, Inc) VMware Workstation (Version: 10.0.4 - VMware, Inc.) Hidden WCF RIA Services V1.0 SP1 (HKLM-x32\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation) Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation) WhoCrashed 4.01 (HKLM\...\WhoCrashed_is1) (Version: - Resplendence Software Projects Sp.) Wichtiges Update für Microsoft Visual Studio 2010 Ultimate - DEU (KB2938807) (HKLM-x32\...\{4135C790-0387-36D7-9C2A-1B09A5900460}.KB2938807) (Version: 1 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.3-0 - Bitnami) Zotero Standalone 4.0.20 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.20 (x86 en-US)) (Version: 4.0.20 - Zotero) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll Keine Datei CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{DDD5A6D8-BC35-305A-CDA1-5139EBA1CE52}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-500210103-394823293-4185795276-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Admin\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll Keine Datei ==================== Wiederherstellungspunkte ========================= 27-07-2015 13:00:14 LavasoftWeCompanion 27-07-2015 13:17:57 Removed Adobe Reader X (10.1.15) - Deutsch. 27-07-2015 13:59:41 Installed AVG 2015 28-07-2015 14:57:48 AA11 29-07-2015 03:00:11 Windows Update 30-07-2015 10:07:58 JRT Pre-Junkware Removal ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2015-07-28 16:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {09B9908D-D194-4062-BB17-CCC08ACFFA71} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Users\Admin\ASUS\AI Suite\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe [2011-09-10] () Task: {2139FE22-776F-49BA-9F18-B9BE87211895} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2015-01-19] () Task: {263CB289-3979-4C47-ABE3-D6C71ABD2B0B} - System32\Tasks\Admin Merge => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2012-07-02] (Seagate Technology LLC) Task: {3681667D-0AAF-4DA0-A1A9-D1AF1116F664} - System32\Tasks\Admin DBAgent 2 0 => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2012-07-02] (Seagate Technology LLC) Task: {560509F5-4ECB-4FD3-9413-49A9FFD716A8} - System32\Tasks\Admin => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2012-07-02] (Seagate Technology LLC) Task: {5BBDA84B-B6B2-4904-BB1D-CA75E17968AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-14] (Google Inc.) Task: {62AFA439-8983-4AC8-80E3-74307111040C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {87CDCEA4-96CC-4E23-B459-E79786CE5865} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-06-08] (Oracle Corporation) Task: {9BF13928-B45D-4102-954F-212A6CFCAF17} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.) Task: {9FE20538-AF2E-43B7-BC62-E4FF8C1375F9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-14] (Google Inc.) Task: {A108CDCA-2014-446B-A1C3-A491BF7E6674} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.) Task: {DD5AFC66-F422-4A21-9334-F00676F16DAE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-30] (Adobe Systems Incorporated) Task: {E2820C24-A83B-49E2-A05E-0DBF50EB303F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.) Task: {EFEAFE41-75F4-48DF-9ADF-6B6752EC9528} - System32\Tasks\{BBD87979-BAB0-4CD4-A69B-D1BA0B897D68} => Chrome.exe hxxp://ui.skype.com/ui/0/7.2.0.103/de/abandoninstall?page=tsMain Task: {F3D994EE-1EB3-48F9-A952-C99F0EFFF69C} - System32\Tasks\elbyExecuteWithUAC => I:\Program Files (x86)\Elaborate Bytes\CloneDVD2\ExecuteWithUAC.exe [2008-06-27] () Task: {FD8D8F91-0314-4AE8-8EDC-3B0FDC02A92F} - System32\Tasks\ASUS\ASUS AI Suite II Execute => C:\Users\Admin\ASUS\AI Suite\AI Suite II\AsRoutineController.exe [2010-11-26] (ASUSTeK Computer Inc.) Task: {FF0DD1DB-6294-45E6-9493-1D8E036FD7D1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core.job => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA.job => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000Core.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-500210103-394823293-4185795276-1000UA.job => C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-06-23 00:24 - 2015-07-23 13:26 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2015-06-22 21:37 - 2015-06-22 21:37 - 00214528 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Device.dll 2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll 2012-01-24 21:42 - 2011-10-07 12:34 - 00922240 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe 2012-01-24 21:42 - 2011-10-07 12:34 - 00915584 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe 2012-01-24 21:43 - 2011-10-07 12:35 - 00586880 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe 2010-10-08 07:18 - 2010-10-08 07:18 - 00056592 _____ () I:\Program Files\ShrewSoft\VPN Client\dtpd.exe 2010-09-02 09:24 - 2010-09-02 09:24 - 00017920 _____ () I:\Program Files\ShrewSoft\VPN Client\libith.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00019456 _____ () I:\Program Files\ShrewSoft\VPN Client\libdtp.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00026624 _____ () I:\Program Files\ShrewSoft\VPN Client\libidb.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00013312 _____ () I:\Program Files\ShrewSoft\VPN Client\liblog.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00035328 _____ () I:\Program Files\ShrewSoft\VPN Client\libvflt.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00119296 _____ () I:\Program Files\ShrewSoft\VPN Client\libip.dll 2012-01-31 20:06 - 2010-04-05 12:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2010-10-08 07:18 - 2010-10-08 07:18 - 00957712 _____ () I:\Program Files\ShrewSoft\VPN Client\iked.exe 2010-09-02 09:24 - 2010-09-02 09:24 - 00028160 _____ () I:\Program Files\ShrewSoft\VPN Client\libike.dll 2010-09-02 09:25 - 2010-09-02 09:25 - 00040448 _____ () I:\Program Files\ShrewSoft\VPN Client\libvnet.dll 2010-09-02 09:24 - 2010-09-02 09:24 - 00030720 _____ () I:\Program Files\ShrewSoft\VPN Client\libpfk.dll 2010-10-08 07:18 - 2010-10-08 07:18 - 00697616 _____ () I:\Program Files\ShrewSoft\VPN Client\ipsecd.exe 2014-05-29 02:54 - 2014-05-29 02:54 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () I:\Program Files (x86)\Notepad++\NppShell_06.dll 2012-01-15 00:15 - 2010-11-10 20:38 - 00380928 _____ () I:\Program Files (x86)\Launchy\Launchy.exe 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2015-06-22 21:37 - 2015-06-22 21:37 - 00102400 _____ () I:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2015-04-20 17:46 - 2015-04-20 17:46 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2012-02-20 21:29 - 2012-02-20 21:29 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-02-20 21:28 - 2012-02-20 21:28 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-01-24 21:42 - 2015-07-31 07:48 - 00033280 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\PEbiosinterface32.dll 2012-01-24 21:42 - 2011-10-07 12:34 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\ATKEX.dll 2014-10-29 16:01 - 2014-10-29 16:01 - 01261272 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll 2015-07-31 07:49 - 2015-07-31 07:49 - 00098816 _____ () G:\Temp\_MEI68162\win32api.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00110080 _____ () G:\Temp\_MEI68162\pywintypes27.dll 2015-07-31 07:49 - 2015-07-31 07:49 - 00364544 _____ () G:\Temp\_MEI68162\pythoncom27.dll 2015-07-31 07:49 - 2015-07-31 07:49 - 00045568 _____ () G:\Temp\_MEI68162\_socket.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 01161216 _____ () G:\Temp\_MEI68162\_ssl.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00320512 _____ () G:\Temp\_MEI68162\win32com.shell.shell.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00713216 _____ () G:\Temp\_MEI68162\_hashlib.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 01175040 _____ () G:\Temp\_MEI68162\wx._core_.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00805888 _____ () G:\Temp\_MEI68162\wx._gdi_.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00811008 _____ () G:\Temp\_MEI68162\wx._windows_.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 01062400 _____ () G:\Temp\_MEI68162\wx._controls_.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00735232 _____ () G:\Temp\_MEI68162\wx._misc_.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00682496 _____ () G:\Temp\_MEI68162\pysqlite2._sqlite.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00087552 _____ () G:\Temp\_MEI68162\_ctypes.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00119808 _____ () G:\Temp\_MEI68162\win32file.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00108544 _____ () G:\Temp\_MEI68162\win32security.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00007168 _____ () G:\Temp\_MEI68162\hashobjs_ext.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00068096 _____ () G:\Temp\_MEI68162\usb_ext.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00167936 _____ () G:\Temp\_MEI68162\win32gui.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00018432 _____ () G:\Temp\_MEI68162\win32event.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00128512 _____ () G:\Temp\_MEI68162\_elementtree.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00127488 _____ () G:\Temp\_MEI68162\pyexpat.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00013824 _____ () G:\Temp\_MEI68162\common.time34.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00036864 _____ () G:\Temp\_MEI68162\_psutil_windows.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00038912 _____ () G:\Temp\_MEI68162\win32inet.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00011264 _____ () G:\Temp\_MEI68162\win32crypt.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00070656 _____ () G:\Temp\_MEI68162\wx._html2.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00027136 _____ () G:\Temp\_MEI68162\_multiprocessing.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00020480 _____ () G:\Temp\_MEI68162\_yappi.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00035840 _____ () G:\Temp\_MEI68162\win32process.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00686080 _____ () G:\Temp\_MEI68162\unicodedata.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00122368 _____ () G:\Temp\_MEI68162\wx._wizard.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00024064 _____ () G:\Temp\_MEI68162\win32pipe.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00010240 _____ () G:\Temp\_MEI68162\select.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00025600 _____ () G:\Temp\_MEI68162\win32pdh.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00525640 _____ () G:\Temp\_MEI68162\windows._lib_cacheinvalidation.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00017408 _____ () G:\Temp\_MEI68162\win32profile.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00022528 _____ () G:\Temp\_MEI68162\win32ts.pyd 2015-07-31 07:49 - 2015-07-31 07:49 - 00078336 _____ () G:\Temp\_MEI68162\wx._animate.pyd 2012-01-15 00:15 - 2009-12-16 23:13 - 08314880 _____ () I:\Program Files (x86)\Launchy\QtGui4.dll 2012-01-15 00:15 - 2009-12-16 22:54 - 02236416 _____ () I:\Program Files (x86)\Launchy\QtCore4.dll 2012-01-15 00:15 - 2009-12-16 22:56 - 00712704 _____ () I:\Program Files (x86)\Launchy\QtNetwork4.dll 2012-01-15 00:15 - 2009-12-17 01:18 - 00233472 _____ () I:\Program Files (x86)\Launchy\imageformats\qmng4.dll 2012-01-15 00:15 - 2010-11-10 20:39 - 00081920 _____ () I:\Program Files (x86)\Launchy\plugins\calcy.dll 2012-01-15 00:15 - 2010-11-10 20:39 - 00090112 _____ () I:\Program Files (x86)\Launchy\plugins\controly.dll 2012-01-15 00:15 - 2010-11-10 20:38 - 00024064 _____ () I:\Program Files (x86)\Launchy\plugins\gcalc.dll 2012-01-15 00:15 - 2010-11-10 20:38 - 00094208 _____ () I:\Program Files (x86)\Launchy\plugins\runner.dll 2012-01-15 00:15 - 2010-11-10 20:38 - 00057344 _____ () I:\Program Files (x86)\Launchy\plugins\verby.dll 2012-01-15 00:15 - 2010-11-10 20:38 - 00122880 _____ () I:\Program Files (x86)\Launchy\plugins\weby.dll 2015-07-31 07:49 - 2015-07-31 07:49 - 00071168 _____ () g:\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpl3wavg.dll 2015-03-04 23:45 - 2015-07-17 02:31 - 00012800 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll 2015-03-04 23:45 - 2015-07-17 02:31 - 00779776 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-07-30 09:22 - 2015-07-17 02:31 - 00056320 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-03-04 23:45 - 2015-07-17 02:31 - 00012288 _____ () C:\Users\Admin\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll 2012-01-24 21:43 - 2011-07-12 20:14 - 00147456 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\AssistFunc.dll 2012-01-24 21:43 - 2010-10-05 09:22 - 00253952 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\pngio.dll 2012-01-24 21:43 - 2011-08-12 16:48 - 00985088 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\BarGadget\BarGadget.dll 2012-01-24 21:43 - 2011-07-26 17:16 - 00880128 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor\Sensor.dll 2012-01-24 21:43 - 2011-07-29 12:44 - 01611776 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor Graph\SensorGraph.dll 2012-01-24 21:43 - 2011-08-09 13:15 - 01242624 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Settings\Settings.dll 2012-01-24 21:43 - 2011-07-21 10:06 - 00846848 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Splitter\Splitter.dll 2012-01-24 21:43 - 2011-07-21 21:33 - 00885760 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\TabGadget\TabGadget.dll 2012-01-24 21:42 - 2011-10-07 12:34 - 00662016 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMLib.dll 2012-01-24 21:43 - 2010-10-05 09:22 - 00208896 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\ImageHelper.dll 2012-01-24 21:43 - 2010-06-21 16:21 - 00208896 _____ () C:\Users\Admin\ASUS\AI Suite\AI Suite II\Sensor\AlertHelper\ImageHelper.dll 2006-02-22 16:47 - 2006-02-22 16:47 - 00073728 ____R () I:\Program Files (x86)\Cherry\KeyMan\zlib1.dll 2006-02-22 16:47 - 2006-02-22 16:47 - 00114688 ____R () I:\Program Files (x86)\Cherry\KeyMan\libpng13.dll 2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2015-07-29 21:28 - 2015-07-25 10:46 - 01405768 _____ () C:\Users\Admin\AppData\Local\Google\Chrome\Application\44.0.2403.125\libglesv2.dll 2015-07-29 21:28 - 2015-07-25 10:46 - 00081224 _____ () C:\Users\Admin\AppData\Local\Google\Chrome\Application\44.0.2403.125\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer trusted/restricted =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-500210103-394823293-4185795276-1000\...\webcompanion.com -> hxxp://webcompanion.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-500210103-394823293-4185795276-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup MSCONFIG\startupreg: AdAwareTray => "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.7.485.8398\AdAwareTray.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BCSSync => "I:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: CloneCDTray => "I:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s MSCONFIG\startupreg: DAEMON Tools Lite => "I:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DBAgent => "I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart MSCONFIG\startupreg: Google Update => "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: iLivid => "C:\Program Files (x86)\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Infium => "I:\Program Files (x86)\QIP 2012\qip.exe" /autorun MSCONFIG\startupreg: iTunesHelper => "I:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesHelper => I:\Program Files (x86)\Kies\KiesHelper.exe /s MSCONFIG\startupreg: KiesPDLR => I:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesTrayAgent => I:\Program Files (x86)\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: Logitech Vid => "I:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode MSCONFIG\startupreg: LogitechQuickCamRibbon => "I:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe --startup MSCONFIG\startupreg: Steam => "I:\Spiele\Shogun2\Steam.exe" -silent MSCONFIG\startupreg: TomTomHOME.exe => "I:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" MSCONFIG\startupreg: Uploader => I:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe MSCONFIG\startupreg: vmware-tray.exe => "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" MSCONFIG\startupreg: Web Companion => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{DA8B16C5-BE90-40EA-827E-2EB7C52B0EA8}I:\program files (x86)\qip 2012\qip.exe] => (Allow) I:\program files (x86)\qip 2012\qip.exe FirewallRules: [UDP Query User{BBFB236B-3C59-411B-9BA8-13E22649E395}I:\program files (x86)\qip 2012\qip.exe] => (Allow) I:\program files (x86)\qip 2012\qip.exe FirewallRules: [{8BC7C635-B55F-4EF5-8438-6223B40D4A80}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{F4D2F6EF-B0BB-47EE-961A-37C7B153E8F0}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{AFE7696E-2626-4CE4-AB98-864DFF54B436}] => (Allow) I:\Program Files\SiSoftware\SiSoftware Sandra Business 2012.SP1\RpcAgentSrv.exe FirewallRules: [{362EE47C-9839-45F0-B2B5-2BAB03546E58}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe FirewallRules: [{19FA7D7D-FCE5-4133-9E56-A505077BE123}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe FirewallRules: [{FEAA08D5-1F62-4746-8502-6C8E35AD3AD4}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{89D83809-0329-4E93-9BBC-8F29947A1F6C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{7E8D0281-4E3D-42E6-8C8B-CBCE14158C15}] => (Allow) I:\Spiele\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe FirewallRules: [{D2940AD0-EC65-4E66-82FE-5993E30F4857}] => (Allow) I:\Spiele\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe FirewallRules: [{5955373F-CE8A-4702-B083-83FE94F2CF0C}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe FirewallRules: [{C74EA9EC-C3E1-478D-9D8D-4121CD67F358}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe FirewallRules: [{A4B35129-520A-4D22-9439-E769F6464314}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe FirewallRules: [{EDE36322-5FEB-4116-A24C-0A8E37EBE3F7}] => (Allow) I:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe FirewallRules: [{0401DEE8-6C56-46D7-BD3D-68C3DD114DC8}] => (Allow) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{96B950BC-63B4-4374-AD70-0490E0DA7948}] => (Allow) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{07845E60-9CD3-42AF-9DCA-A6493B8D815E}] => (Allow) I:\Program Files (x86)\MirandaFusion\miranda32.exe FirewallRules: [{5ABB16A8-F1E4-4662-94A8-C2218E58E695}] => (Allow) I:\Program Files (x86)\MirandaFusion\miranda32.exe FirewallRules: [{63D7AAF9-70F3-4274-98E8-F1469964D069}] => (Allow) I:\Program Files (x86)\MirandaFusion\fusiontools\updater.exe FirewallRules: [{344C8FB4-5E3B-493C-9EEB-F4E3A503E934}] => (Allow) I:\Program Files (x86)\MirandaFusion\fusiontools\updater.exe FirewallRules: [{0E1CFE8E-8E51-4BAB-BDC6-1F55B40B4BDC}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{60156986-F05F-4B44-B56A-1B6296FFCA4F}] => (Allow) I:\Program Files (x86)\Veetle\Player\VeetleNet.exe FirewallRules: [{0E5E8547-8C1C-4FF2-A6CD-04BE4BDD0BB3}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{D6494379-CA32-419C-9161-11CF8F0CB2E7}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{1C07C517-3B5D-440E-8E59-B9ED88FCE7FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{8EB90E80-4711-408D-9B52-85382808D083}] => (Allow) LPort=2869 FirewallRules: [{E592F7EA-5498-4FD8-84F9-403CAE992B2A}] => (Allow) LPort=1900 FirewallRules: [{3328D48A-C369-48D9-A0DA-BAA29331C542}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{67E46703-985D-4D43-80DC-6D6BE9C1D8B5}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{429B5E54-A9D8-4DDD-81FE-3F7B05676ACD}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{7C722773-66FB-4F9A-89EC-BACA2FFC0C83}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{643EEACE-F60F-4B95-9A5D-6E93AA9AD08C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C25BBC8C-1F24-4F79-B3EC-5493341A9E8D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{1D1C9799-404B-40B7-8F23-58DA1C06B7A6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F057F700-6E39-4191-8C76-8466AD3A371B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D64842BC-1FB7-4B7B-9570-06536E65C93C}] => (Allow) I:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{3A72BC0D-0D37-4F3D-B862-BDEDE8A06E10}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe FirewallRules: [{37722471-2BE3-4C12-8B7C-322EF6D3204E}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2012\pes2012.exe FirewallRules: [{4398A648-238B-4A09-9C0A-FB54437DB8E5}] => (Allow) C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{CA9385B3-F70A-4C01-A51A-D6AF1A5F8B72}] => (Allow) C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{E109636D-820D-4439-B85F-EDF9C1E8D15E}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{AD9987BD-1C12-4441-9B11-2CA40DDFAF81}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{662B62DD-ECC8-4B0C-8C77-0DE526D49089}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe FirewallRules: [{7AE125AE-51A1-49AB-8D30-0EC90E410EC7}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe FirewallRules: [{DBBA6DE9-9593-4D21-AC2B-AA001DF6DE6F}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{53EBF171-B2ED-4236-8462-CD4985D151B7}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\pes2013.exe FirewallRules: [{CF8EBDF8-2147-4186-AC19-DB5F620935CC}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe FirewallRules: [{EC84D4B5-2BDA-4C21-8981-F76E120EF62F}] => (Allow) C:\Spiele\KONAMI\Pro Evolution Soccer 2013\Pesgalaxy.com Patch 2013\pes2013.exe FirewallRules: [{D925962D-FC57-429B-A000-482E648FB0F8}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{724A9BCD-7B6A-46C7-AA37-0458EB6B52CF}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{99905495-7B1E-4A75-AF05-55A63D82FD4B}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{7B456905-3203-44B8-8BD2-444A12450C89}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{7CB416A5-05FE-4A3E-B75C-B6409113D941}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe FirewallRules: [{3C22040D-E846-4702-A26C-61390E0BE1A1}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe FirewallRules: [{C5D49E73-F4DE-4AFB-9E11-1A7AFC9664D4}] => (Allow) C:\Users\Admin\AppData\Roaming\TorrentStream\engine\tsengine.exe FirewallRules: [{0A8E48F2-035F-4B03-A9E3-42F995851267}] => (Allow) C:\Users\Admin\AppData\Roaming\TorrentStream\engine\tsengine.exe FirewallRules: [{8B9EDA0D-15D2-4C54-A967-6514CD0AE0FF}] => (Allow) I:\Program Files\Logitech\Logitech Vid\Vid.exe FirewallRules: [{F68ADFC3-0BCC-43E1-B299-97708A087050}] => (Allow) I:\Program Files\Logitech\Logitech Vid\Vid.exe FirewallRules: [{B7DA221D-BBE0-45C0-8510-AC6ED56BD1D8}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{ADEA4D7E-67C4-41AF-B654-5CC08427F36B}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [TCP Query User{63EC74B4-EB18-4D2F-9AAF-8D7C44BD8D05}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe FirewallRules: [UDP Query User{E690A155-70F6-401D-9D82-5A331677DD59}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe FirewallRules: [TCP Query User{A402614A-8B59-4625-AD98-8961ABDE1A48}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe FirewallRules: [UDP Query User{E1E875BB-7831-43BB-B61B-18414486DE94}I:\program files (x86)\gembird\power manager\pm.exe] => (Allow) I:\program files (x86)\gembird\power manager\pm.exe FirewallRules: [{7A4F5E0B-F7F6-413E-A12D-92A3EBA60213}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{44D41D10-29CC-4163-B2D9-0E3A06E90392}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{009A8772-ED14-4BD7-A60F-08E58C4C84BB}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{98117CFE-02E4-48BE-85E1-01C30A3DBE37}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{4A5727EB-16BD-4B3F-9D7A-93044872A2B0}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{6AE47FEE-E88E-4A59-9F42-2D31017B3378}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{1A11A178-C737-4B29-AB2B-9E48AE7FE104}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{671EAD44-A446-45D5-BBFA-663054284BA5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{DE4BA6E6-ADC4-4C8D-B3C2-C8AF7AD801E3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{C479E420-FD02-4CA6-AC75-DF80AF559421}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{A355DD9E-1308-489B-9C88-DEC05B478FFB}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{39F53DFE-6304-46CC-B2B8-1907E770DD92}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{D71831B4-90C7-4B1A-83AE-74F8BCC1F677}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B4B0A17C-CA89-48D4-A332-36063BD4EA67}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{9FDE980F-979E-4989-A226-E1A50203EF64}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{A172864A-5B49-48BE-B3F0-F9316BB9968F}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B56B05E3-22DD-4E46-B0AC-D8140356E25A}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{9C861C18-776C-416E-A65C-B27AF2BC4209}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe FirewallRules: [{B87C9DD5-5FB0-495F-BA17-8717C92DF98E}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe FirewallRules: [{220A5D30-C98A-4FD8-B0E4-A51F13C9649D}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe FirewallRules: [{6A31F993-39B0-477D-95F5-57FB037FF7B2}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY VIII\FF8_Launcher.exe FirewallRules: [{11486E23-BCDA-47CA-9A48-D744951F54FC}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\FINAL FANTASY VIII\FF8_Launcher.exe FirewallRules: [{3EEF7F57-68BB-4A18-9366-CE65958D55FD}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{0A3759DE-0340-44AB-BB75-D8891789E014}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [TCP Query User{6B7E7A41-8B0B-4E1C-94F4-6A2F4D56D43A}I:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) I:\program files (x86)\libreoffice 4\program\soffice.bin FirewallRules: [UDP Query User{5852FD27-A7C2-4B4E-B036-AFD2F263361B}I:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) I:\program files (x86)\libreoffice 4\program\soffice.bin FirewallRules: [TCP Query User{545628FC-9C6E-4D8C-90D6-F4B9EFF6C0B3}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{C680CB0D-FFD9-4CCA-93E5-081244976B4B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [TCP Query User{307D98F2-08D4-4950-BDCE-F2CCEB1650F4}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe FirewallRules: [UDP Query User{EA45DD32-5B84-4D74-9AF5-F50BF777EEA5}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe FirewallRules: [{1EDF1FB2-4890-4401-88E5-37D3DC463639}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{1BF7DA1B-A913-495E-8D98-3BE627EA07A0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{65D5665E-4A5F-488F-9588-8BBF2DF04991}] => (Allow) I:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{E9BB800C-4E34-44C4-BBDF-879F7C72D334}] => (Allow) I:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [TCP Query User{40774BCD-EBF3-4DBB-82FF-0661E7F415BC}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{C623C620-2E9B-48C0-8978-88D24940F63C}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{6F617A60-D3CE-473A-B6DF-6D99BE718553}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe FirewallRules: [UDP Query User{34CFEEF9-08F7-447D-B03F-3B5FB10811E9}I:\program files (x86)\sopcast\sopcast.exe] => (Allow) I:\program files (x86)\sopcast\sopcast.exe FirewallRules: [TCP Query User{24F2A94C-85DE-4FAD-A84F-97E53F1253CC}I:\spiele\pro evolution soccer 2014\pes2014.exe] => (Allow) I:\spiele\pro evolution soccer 2014\pes2014.exe FirewallRules: [UDP Query User{BFA2FC11-613A-42C0-B65E-3C1A8C923DC6}I:\spiele\pro evolution soccer 2014\pes2014.exe] => (Allow) I:\spiele\pro evolution soccer 2014\pes2014.exe FirewallRules: [{3EFE3C44-E51A-466C-96BE-EF6AFB82E693}] => (Allow) C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe FirewallRules: [{3A1609E6-DFE5-4351-A464-F32D3D0380F7}] => (Allow) C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe FirewallRules: [{6F7FDED0-235E-477D-B7E7-9E3A3CBE4D7D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{2FFCDB85-C562-4715-A56B-6EB4A6ACAB93}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{6221A8D9-C192-4605-B9DC-626D8D97B77C}] => (Allow) G:\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{F279A456-E9E0-430D-BDBB-BF17577BBE95}] => (Allow) G:\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{63EF3EFF-3EBA-49FF-B88C-9DEF3947813F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{2AB36BAA-E192-4477-AA91-2D0D5AC6CB4B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{D7762DF8-BFC1-402B-8B33-FA0F0154D8D7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{E144CEBA-2EAE-44F7-B9AC-E84754133A70}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{FD6A79F4-6AAF-4A40-A1AD-0F9E26721706}] => (Allow) G:\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{0AC8CCAC-4208-438E-883E-97825AB5AC7D}] => (Allow) G:\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{3FF7376C-70FA-41F9-B0DE-86FEDC096268}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{C8CC5276-DABB-4B14-A206-B3E881439B48}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{74881FD2-5264-4BD4-92A6-C8CE47D701FD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{31EA935D-9C24-433F-9617-62DE00A87C88}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [TCP Query User{98CF1771-0E6C-4F52-BF56-29AB4E5D2A92}I:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) I:\spiele\divinity original sin\shipping\eocapp.exe FirewallRules: [UDP Query User{47807778-B09B-4256-B568-86D4DD197A74}I:\spiele\divinity original sin\shipping\eocapp.exe] => (Block) I:\spiele\divinity original sin\shipping\eocapp.exe FirewallRules: [{7E4FBE01-30EE-482F-92D8-438D4179DB1C}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{67AA91B7-07CB-4545-946D-E4B72F9AD57D}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{546527AB-0121-4826-A9B7-2C7ECD5CF209}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe FirewallRules: [{A6EFCFEB-2C91-4FE6-B1C2-4582B05FC7E9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe FirewallRules: [{0644E69B-2437-4DFD-A3A5-83F987C2C4B2}] => (Allow) I:\Program Files (x86)\Origin Games\FIFA World\fifaworld.exe FirewallRules: [{B0E016FB-8173-449F-B4CE-EE19F5008545}] => (Allow) I:\Program Files (x86)\Origin Games\FIFA World\fifaworld.exe FirewallRules: [{20B834F7-169E-4B2A-928D-427DA0C24727}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{DA16898C-69E6-4E29-B779-D1B8DE179DB0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{177E0E07-33DC-4066-B195-F3D169C66AFE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{05238314-5001-4210-AC93-76678CF4B46E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{6CFAA827-F9B0-49EE-9BC3-55B7906A3EFD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe FirewallRules: [{5AD4F365-C0CB-43A9-B446-9E8613459E11}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe FirewallRules: [{1BD42C09-FCC0-4478-8177-F566200EC1AB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{BFD697F0-5884-45D5-97DA-6073C3C82AED}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{AAB3A8FC-D53D-49ED-9531-9898F701143B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{55719414-C766-414B-A666-BEF2582BDE7B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{11C97E03-8523-4A87-8682-53D2DBED28AD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{60E525EF-38B7-4A32-9871-2224D7550405}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{CEF3BA47-48EB-44F9-AF94-5B320B8D7CD5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{DA7D1730-8FC9-4C91-8690-996034BB1C4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{D214B8B2-13E0-4880-9205-DC5490BD2C41}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{63D286EA-1EA1-446F-AD8C-11062C04E028}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe FirewallRules: [{067961E8-23AA-4AD7-9911-C8EB95D4FF4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{85ED6F17-5E2F-4D3E-8E62-81D68D2DAFAE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{FE681703-1045-428D-9CFB-818BA8E07967}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{C76EC2B7-CA42-4C24-8FDF-E7D78D02753B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{88D4F973-FD87-4D3B-8067-DCB8BBD8A337}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{6E51B1CA-57A9-4765-8D59-C3BAAEA903DF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [TCP Query User{9BE1AE84-9D13-4C43-B424-7D6A9B7A9F3B}I:\spiele\pro evolution soccer 2015\pes2015.exe] => (Allow) I:\spiele\pro evolution soccer 2015\pes2015.exe FirewallRules: [UDP Query User{D0AC4E49-CCF8-4CAC-B607-6DF7399BF3E8}I:\spiele\pro evolution soccer 2015\pes2015.exe] => (Allow) I:\spiele\pro evolution soccer 2015\pes2015.exe FirewallRules: [{7122C35C-B6C6-4E6E-86A2-AACBDEF834EE}] => (Allow) G:\SteamLibrary\SteamApps\common\Pro Evolution Soccer 2015\PES2015.exe FirewallRules: [{29462748-3F10-4424-9DEF-90AAB302C1D0}] => (Allow) G:\SteamLibrary\SteamApps\common\Pro Evolution Soccer 2015\PES2015.exe FirewallRules: [{8E8957D1-C55C-4E31-B900-9B46379E6C3A}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgnsa.exe FirewallRules: [{0F26E076-AF8F-4402-865A-A397FBE47234}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgnsa.exe FirewallRules: [{A6460428-A9EE-4551-AAB1-9919A8CB9FE7}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe FirewallRules: [{A33E8FE9-D05D-4FFE-8822-FC73F3DC550A}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe FirewallRules: [{1AC7AE59-22CC-4C22-9325-1B9387438B71}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgemca.exe FirewallRules: [{86AA2786-26BF-4AB7-A66B-6E5E665FACDF}] => (Allow) I:\Program Files (x86)\AVG\AVG2012\avgemca.exe FirewallRules: [TCP Query User{750FD61C-DEBE-412E-9723-59374283BC20}I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe] => (Block) I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe FirewallRules: [UDP Query User{E1E8AA2F-D28F-46E6-912D-0012C96D29E0}I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe] => (Block) I:\spiele\sierra activision aspyr\geometry wars 3 dimensions\gw3.exe FirewallRules: [{B4D9749E-B708-4D9D-9DDC-A48E8A4459BD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{C55D1012-3D11-4966-B4BE-07B0171EF8DE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{D7891E90-3D5E-4E71-91E6-74F2470568D6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [{19BAF5E7-C630-4E87-BFC9-E875AC3E101F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [TCP Query User{934E83F4-23D0-44FF-87C7-0957C34C00B3}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{AFB751F7-169D-440A-BADA-70F25F4545B6}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{97D5122A-DE93-4E9D-94DE-560DDB0A915E}I:\program files\xampp\apache\bin\httpd.exe] => (Allow) I:\program files\xampp\apache\bin\httpd.exe FirewallRules: [UDP Query User{17F86DA3-A1F5-4BAD-83C4-B630DA509607}I:\program files\xampp\apache\bin\httpd.exe] => (Allow) I:\program files\xampp\apache\bin\httpd.exe FirewallRules: [TCP Query User{9268B190-BF64-4AF9-BA9F-73477A9597F5}I:\program files\xampp\mysql\bin\mysqld.exe] => (Allow) I:\program files\xampp\mysql\bin\mysqld.exe FirewallRules: [UDP Query User{A68F1A97-6293-4687-8C2B-C6F7F0BAF8BF}I:\program files\xampp\mysql\bin\mysqld.exe] => (Allow) I:\program files\xampp\mysql\bin\mysqld.exe FirewallRules: [{67B5231F-8ADB-4FF5-B36A-FFC60C1F237C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{26B8BF3D-7228-4D1C-83F2-DE5FF771D4BD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{5264E2C9-606F-4009-B7F1-5024B7B5CF2B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{AA931175-D489-4128-8800-0F69680CD7A3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{239C8B4D-9F39-41AD-B84F-B4B337CA2D72}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{5BE02404-C7E9-47D1-86EF-91C9E127B4B2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{C29A9D4D-8EFB-467C-833B-1BF942E44643}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{66370EA6-F85A-4580-AC31-6AF8A17B72EB}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{392FEB61-2B82-41AF-BCA8-8350B63A0D60}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{93E85BE7-1F1B-4FE5-A119-3E828992E3FA}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{6C8B2C10-6A54-4171-AA94-A2B884369D0C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{27CD20F3-07EF-400F-99B1-E284BFE05B17}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{4C385DC4-C490-457A-9FFF-885810C64C9A}] => (Allow) G:\SteamLibrary\SteamApps\common\Quake Live\quakelive_steam.exe FirewallRules: [{598B1C43-5AC4-46CA-B4CB-0268F622174E}] => (Allow) G:\SteamLibrary\SteamApps\common\Quake Live\quakelive_steam.exe FirewallRules: [TCP Query User{1559CE4F-EBBC-434F-93D4-CBBD3AC0B908}G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe] => (Allow) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe FirewallRules: [UDP Query User{6748B5FC-83AB-49E2-80E3-FF5B2C36DF55}G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe] => (Allow) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe FirewallRules: [{55F96811-D542-4AD3-A2FB-1AAE0741376E}] => (Block) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe FirewallRules: [{B4A5676B-82D8-4F67-A9F8-860D9696FE8D}] => (Block) G:\steamlibrary\steamapps\common\pro evolution soccer 2015\pes2015 - modern - nesa24.exe FirewallRules: [{5AFFAF25-4C99-4203-8748-62E29395211C}] => (Allow) I:\Program Files\SiSoftware\SiSoftware Sandra Business 2012.SP1\WNt500x64\RpcSandraSrv.exe FirewallRules: [{2E8C2002-15B2-4CB1-B0DC-5E9AE99BA086}] => (Allow) I:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe FirewallRules: [{4D1C1F4D-154B-45CE-BB5F-973BADCEB950}] => (Allow) I:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe FirewallRules: [{01FCB0B7-D5E9-4179-8020-3D547D91E3CA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{2323FEB1-3673-4C70-93D5-06706DAF2530}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{A5330042-8A8A-4EFA-BF39-C18DBDFD4D23}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{7178C640-F4BA-45BC-BB03-33F9464587DA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [TCP Query User{B5A2A9B5-8D58-44B8-9693-0C4D838BF8C2}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe FirewallRules: [UDP Query User{BDB94D6A-5650-4EE1-AA64-6085D0B16BAE}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe FirewallRules: [{5B635C6E-0C8C-4864-A333-0AB7C8939BDE}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe FirewallRules: [{FB176797-B9BA-47EE-A426-E8E7CEB16A1A}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\turbohud.exe FirewallRules: [TCP Query User{76D0C968-5490-44BD-B6BE-733CF7C09504}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe FirewallRules: [UDP Query User{9414CF60-207B-468E-963F-CB18B8E6BC85}G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe] => (Allow) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe FirewallRules: [{62800BC7-647B-48D5-A81E-6D264B4FEA39}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe FirewallRules: [{7B24E092-E864-4D79-8896-79718766A4B4}] => (Block) G:\dokumente\downloads\turbohud 15.4.20.0 (v4) stable for diablo iii 2.2.0.30894a\test.exe FirewallRules: [{F92D3E68-0D80-46D4-904E-26645B2B4429}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{760E89FA-6A6E-4026-84AC-7679B006AB6F}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{F0122ABE-D7E4-4882-9DAF-81A5E8B6A7CC}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{2DD7FA52-91FD-4ECB-9953-37FDA3C44AF5}] => (Allow) I:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{67B73862-FB62-474D-8136-1F60B3EE7D96}] => (Allow) G:\SteamLibrary\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe FirewallRules: [{325CD692-B642-48F3-9E67-0F5CA6CB3937}] => (Allow) G:\SteamLibrary\SteamApps\common\FINAL FANTASY VII\FF7_Launcher.exe FirewallRules: [{6E481CEB-2803-4D24-A8E6-201907F17ED9}] => (Allow) G:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{03F2D851-82F7-46F0-A413-27761EAECEE3}] => (Allow) G:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{3589CD91-E258-4B2E-999B-1029301D2301}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{A30CEBE1-2227-4371-B476-4BC0F3C8BCB8}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{DFCC8903-182A-4040-852E-167AC8D41C97}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{70831CAB-C418-4D43-9700-1E0D8C7C3937}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{3732328F-8CC0-4FF7-AEDC-1EE1AB7C90F9}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{9625A327-9DF4-4CB7-9E9A-4948FCEACAED}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{775A1104-026F-47D2-9777-5F64944C47AE}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{0590F458-0DCD-44C3-BDC7-D138CEA53FA9}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{0DDC93C9-951B-4A06-9513-2C62E6756591}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{6F341878-9A59-40A0-B440-202514C4F814}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{224D9513-CAEC-4D16-9E7A-2A1B75DBFA9D}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{D97AE7D4-2DFA-442E-9404-78FB8B31D5A5}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{33E236AB-D19F-4470-8D62-1FE9651AE148}] => (Allow) C:\Users\Dori\AppData\Local\Mozilla Firefox\firefox.exe FirewallRules: [{2D294BBE-ED04-4F16-A9E6-7DACDC47DC1D}] => (Allow) C:\Users\Dori\AppData\Local\Mozilla Firefox\firefox.exe FirewallRules: [{B6030ED4-2A16-4689-B5D0-94B0FFEC7E2D}] => (Allow) C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Shrew Soft Virtual Adapter Description: Shrew Soft Virtual Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Shrew Soft Service: vnet Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (07/31/2015 07:49:11 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 02:55:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 10:17:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 10:01:15 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 09:34:51 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 09:20:57 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2015 03:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2015 04:02:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: AutoKMS.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.ComponentModel.Win32Exception Stapel: bei System.Diagnostics.Process.StartWithCreateProcess(System.Diagnostics.ProcessStartInfo) bei System.Diagnostics.Process.Start(System.Diagnostics.ProcessStartInfo) bei ..(System.String, Boolean, Boolean) bei ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String) bei ..(Boolean, System.String, Boolean, Int32, Boolean, Boolean, Boolean, Boolean, System.String, System.String, Boolean, System.String, ., System.String) bei ..(.) bei ..() Error: (07/28/2015 04:01:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2015 03:46:34 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\wbem\wmiprvse.exe; Beschreibung = ComboFix created restore point; Fehler = 0x8007043c). Systemfehler: ============= Error: (07/30/2015 10:08:48 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/30/2015 10:08:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/30/2015 10:08:45 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Office Software Protection Platform" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/30/2015 10:08:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Cherry Device Interface" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/30/2015 10:08:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "VMware USB Arbitration Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "VMware DHCP Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "VMware Authorization Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/30/2015 10:08:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/30/2015 10:08:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office: ========================= Error: (07/31/2015 07:49:11 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 02:55:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 10:17:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 10:01:15 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 09:34:51 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2015 09:20:57 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2015 03:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2015 04:02:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: AutoKMS.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.ComponentModel.Win32Exception Stapel: bei System.Diagnostics.Process.StartWithCreateProcess(System.Diagnostics.ProcessStartInfo) bei System.Diagnostics.Process.Start(System.Diagnostics.ProcessStartInfo) bei ..(System.String, Boolean, Boolean) bei ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String) bei ..(Boolean, System.String, Boolean, Int32, Boolean, Boolean, Boolean, Boolean, System.String, System.String, Boolean, System.String, ., System.String) bei ..(.) bei ..() Error: (07/28/2015 04:01:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2015 03:46:34 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: C:\Windows\system32\wbem\wmiprvse.exeComboFix created restore point0x8007043c CodeIntegrity: =================================== Date: 2015-07-28 15:57:08.984 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-07-28 15:57:08.922 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-18 12:27:45.986 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-17 11:10:05.788 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-14 12:38:19.578 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-23 16:27:02.842 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-13 14:28:44.599 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-09 15:12:03.689 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-09 14:58:44.987 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-09 08:12:57.673 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Processor: AMD FX(tm)-6100 Six-Core Processor Percentage of memory in use: 49% Total physical RAM: 8138.38 MB Available physical RAM: 4116.63 MB Total Virtual: 16274.96 MB Available Virtual: 11744.44 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.24 GB) (Free:20.07 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive g: (Volume) (Fixed) (Total:1863.01 GB) (Free:371.94 GB) NTFS Drive i: (Software und Spiele) (Fixed) (Total:232.88 GB) (Free:29.4 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 08D508D5) Partition 1: (Not Active) - (Size=232.9 GB) - (Type=42) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 7BE21FF1) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: FDA660FB) Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS) ==================== Ende von log ============================ |
31.07.2015, 21:48 | #17 |
/// TB-Ausbilder | JollyWallet, Coupon Werbung und unsichtbare Links in Chrome Servus,
__________________treten die Probleme nur in Chrome oder auch in Firefox und IE auf? |
01.08.2015, 11:42 | #18 |
| JollyWallet, Coupon Werbung und unsichtbare Links in Chrome die treten nur im chrome auf. firefox nutze ich gerade alternativ und schaue nur nachdem ich deine anweisungen gemacht habe mal im chrome, ob sich etwas geändert hat. hat es aber nicht. hier auf der seite vom trojaner board kommt zb keine werbung, da öffnet sich nur manchmal ein neues tab mit werbung, wenn ich irgendwo hin klicke. auf bild, amazon und solchen seiten ist aber oben ne jollywallet werbeleiste, rechts ist eine für gutscheine bzw coupons, manchmal ist mitten drin noch eine werbebox. die sich öffnenden werbetabs, wenn ich irgendwas anklicke, sind wie gesagt überall, auf jeder seite, wie ein unsichtbarer layer
__________________ |
01.08.2015, 15:43 | #19 |
/// TB-Ausbilder | JollyWallet, Coupon Werbung und unsichtbare Links in Chrome Servus, ok, dann deinstalliere Google Chrome über die Systemsteuerung und setze auch einen Haken bei Alle Browserdaten löschen. Rechner neu starten. Google Chrome neu installieren. CHR::: Setze Google Chrome nach dieser Anleitung zurück. Dann nochmal FRST zur Kontrolle sowie Rückmeldung wie es jetzt läuft:
|
05.08.2015, 22:35 | #20 |
/// TB-Ausbilder | JollyWallet, Coupon Werbung und unsichtbare Links in Chrome Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu JollyWallet, Coupon Werbung und unsichtbare Links in Chrome |
bestimmte, chrome, eingefangen, erweiterung, gelöscht, geändert, guten, installiert, java, java update, jollywallet, laden, link, links, malware / spyware, neu, nichts, probleme, programm, ratlos, seite, seiten, system, tool, update, virus, werbung, zurücksetzen, öffnen |