|
Log-Analyse und Auswertung: Windows 7 3-4 Webseiten öffnen sich nach Opera startWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
18.01.2017, 17:29 | #1 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Hallo Trojaner Board'ler, Als ich heute Mittag (18.01.2017) eine vermeintlich sichere Datei, die ich vor Wochen von einer vermeintlich sicheren Quelle/Seite, geladen habe, kam es zu massiven Problem mit meinem Opera-Browser auf dem Desktop kam plötzlich auch Werbung. Dieser öffnet sporadisch irgendwelche Werbeseiten (3-4 Seiten). Die vermeintlich sichere Datei war eine Demo-Version von Daemontools-Lite (ohne irgendwelche Cracks, Keygens etc.) Leider kann ich euch nicht mehr genau sagen um welche Seite es sich gehandelt hat. Direkt nach dem doppelklick auf die .exe schlug dierekt mein Avira an. Danach habe ich direkt kompletten System-Scan gestartet. Habe Bereits aus der Host-Datei 100 Einträge mit gleicher IP-Adresse entfernt. nach dem ist die Desktop Werbung verschwunden. Dummerweise hab ich das erste Logfile überschrieben. Alles was jetzt noch zu tun ist übersteigt meine Kompetenzen. Deswegen benötige ich eure Hilfe. Alle Schritte die bisher unternommen wurden: Scan mit Avira Scan mit Hijackthis Scan mit Malwarebytes Anti-Rootkit BETA 1.09.3.1001 Scan mit FRST Avira Logfile Code:
ATTFilter 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.xbjke [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\ziengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'TR/Strictor.gccpn [trojan]' detected in file 'C:\Program Files (x86)\OtherSearch\updengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.spdug [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdengine.dll. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.tphcr [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdenginecert.dll. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Komodia.exmaw [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\kke.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:23 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.onczr [adware]' detected in file 'C:\Windows\c562f3940e043920f3565bdb0653e17a.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:21 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.dtsqs [adware]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\c562f3940e043920f3565bdb0653e17a.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:18 [Real-Time Protection] Malware found The pattern of 'TR/Symmi.npyqa [trojan]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\cc3ef4cb9c0b487ee043ca733e1cda27.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:17 [Real-Time Protection] Malware found The pattern of 'TR/Symmi.npyqa [trojan]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\cc3ef4cb9c0b487ee043ca733e1cda27.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:08 [Real-Time Protection] Malware found The pattern of 'ADWARE/Sokuxuan.qrdkg [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029727\51477.top.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.fycvv [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\kpzip.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.ufptv [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029724\service.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'TR/Agent.bryzl [trojan]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\RandomDelJiheReg.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Yeabests.oibru [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\hp.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:05 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.totp [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\newAutoTime_51477.jpg. Action performed: Move file to quarantine 18.01.2017, 10:54:00 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.sslj [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\OfferInstaller.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:58 [Real-Time Protection] Malware found The pattern of 'ADWARE/ConvertAd.51270 [adware]' detected in file 'C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6\Uninstall.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:57 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.3030016.8 [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\fsd4DE2.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:56 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.letsk [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:56 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.jqayd [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\ziengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:55 [Real-Time Protection] Malware found The pattern of 'ADWARE/ConvertAd.A.1926 [adware]' detected in file 'C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6\qnso4EAE.tmp. Action performed: Move file to quarantine HiJackThis Log Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 15:44:02, on 18.01.2017 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.18525) FIREFOX: 50.1.0 (x86 de) Boot mode: Normal Running processes: C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe C:\Program Files (x86)\Thunder Master\THPanel.exe C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe C:\Program Files (x86)\Avira\Antivirus\avgnt.exe C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe C:\Program Files (x86)\Dropbox\Client\Dropbox.exe C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe C:\Users\Alex\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe C:\Users\Alex\Desktop\HijackThis_2.0.5.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll O2 - BHO: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL O2 - BHO: AviraBrowserSafety.BrowserSafety - {c3c77255-42c0-499f-b664-6e981a0b1647} - mscoree.dll (file missing) O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll O4 - HKLM\..\Run: [Sound Blaster Cinema 2] "C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe" /r O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe O4 - HKLM\..\Run: [Super Charger] C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup O4 - HKLM\..\Run: [Command Center] C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe O4 - HKCU\..\Run: [THPanel] "C:\Program Files (x86)\Thunder Master\THPanel.exe" /A O4 - HKCU\..\Run: [STUISpeedLauncher] "C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe" -speedlauncher -minVer:6.6.58.0 O4 - HKCU\..\Run: [OneDrive] "C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun O4 - HKCU\..\Run: [msiql] C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe /RUNNING O4 - HKCU\..\Run: [ProxyGate] C:\Users\Alex\AppData\Roaming\ProxyGate\MainService.exe O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user') O4 - Global Startup: Blue Manager Suite.lnk = C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe O4 - Global Startup: Killer Network Manager.lnk = C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: Avira Browser Safety - {d8f67242-b229-4065-95fa-391b077ed6ca} - mscoree.dll (file missing) O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O23 - Service: 5f997e823c149616faed2a7953b94672 - Unknown owner - C:\Program Files\5f997e823c149616faed2a7953b94672\4be4ee7ec1a7db4d36fdb985186936b5.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe O23 - Service: Dropbox-Update-Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: Dropbox-Update-Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: DbxSvc - Unknown owner - C:\Windows\system32\DbxSvc.exe (file missing) O23 - Service: Digital Wave Update Service (DigitalWave.Update.Service) - Digital Wave Ltd. - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe O23 - Service: Disc Soft Ultra Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Sentinel LDK License Manager (hasplms) - Unknown owner - C:\Windows\system32\hasplms.exe (file missing) O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Killer Service V2 - Rivet Networks - C:\Program Files\Killer Networking\Network Manager\KillerService.exe O23 - Service: Logitech Gaming Registry Service (LogiRegistryService) - Logitech Inc. - C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe O23 - Service: Autodesk Simulation Moldflow MITSI 2017 Job-Manager (mitsijm2017) - Autodesk, Inc. - E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: MSI Command Center Clock Service (MSIClock_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe O23 - Service: MSI Command Center Comm Service (MSICOMM_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\MSICommService.exe O23 - Service: MSI Command Center CPU Service (MSICPU_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe O23 - Service: MSI Command Center control Service (MSICTL_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe O23 - Service: MSI Command Center DDR Service (MSIDDR_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe O23 - Service: MSI Command Center SMBus Service (MSISMB_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe O23 - Service: MSI Command Center SuperIO Service (MSISuperIO_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Users\Alex\Origin\OriginWebHelperService.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Samsung Printer Dianostics Service - Unknown owner - C:\Windows\system32\\spdsvc.exe O23 - Service: Samsung UPD Utility Service (SamsungUPDUtilSvc) - Unknown owner - C:\Windows\SysWOW64\SecUPDUtilSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: Survarium-Steam Update Service - Unknown owner - H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 15744 bytes Malwarebytes Anti-Rootkit Log Code:
ATTFilter --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.3.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.18524 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED, J:\ DRIVE_FIXED, K:\ DRIVE_FIXED, L:\ DRIVE_FIXED, M:\ DRIVE_FIXED, P:\ DRIVE_FIXED CPU speed: 4.400000 GHz Memory total: 8552493056, free: 5017292800 Downloaded database version: v2017.01.18.06 Downloaded database version: v2016.11.20.01 Downloaded database version: v2016.12.16.01 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 01/18/2017 15:57:31 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\mpio.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\intelide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\aliide.sys \SystemRoot\system32\drivers\amdide.sys \SystemRoot\system32\drivers\cmdide.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\nvraid.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\pciide.sys \SystemRoot\system32\drivers\viaide.sys \SystemRoot\system32\drivers\iaStorV.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\lsi_sas.sys \SystemRoot\system32\drivers\storport.sys \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\DRIVERS\amd_sata.sys \SystemRoot\system32\DRIVERS\amd_xata.sys \SystemRoot\system32\DRIVERS\dtlitescsibus.sys \SystemRoot\system32\DRIVERS\dtultrascsibus.sys \SystemRoot\system32\drivers\HpSAMD.sys \SystemRoot\system32\drivers\adp94xx.sys \SystemRoot\system32\drivers\adpahci.sys \SystemRoot\system32\drivers\adpu320.sys \SystemRoot\system32\drivers\amdsata.sys \SystemRoot\system32\drivers\amdsbs.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\arc.sys \SystemRoot\system32\drivers\arcsas.sys \SystemRoot\system32\drivers\bxfcoe.sys \SystemRoot\system32\drivers\bxois.sys \SystemRoot\system32\drivers\elxstor.sys \SystemRoot\system32\drivers\iirsp.sys \SystemRoot\system32\drivers\lsi_fc.sys \SystemRoot\system32\drivers\lsi_sas2.sys \SystemRoot\system32\drivers\lsi_scsi.sys \SystemRoot\system32\drivers\megasas.sys \SystemRoot\system32\drivers\MegaSR.sys \SystemRoot\system32\drivers\nfrd960.sys \SystemRoot\system32\drivers\nvstor.sys \SystemRoot\system32\drivers\ql2300.sys \SystemRoot\system32\drivers\ql40xx.sys \SystemRoot\system32\drivers\SiSRaid2.sys \SystemRoot\system32\drivers\sisraid4.sys \SystemRoot\system32\drivers\stexstor.sys \SystemRoot\system32\drivers\vhdmp.sys \SystemRoot\system32\drivers\FLTMGR.SYS \SystemRoot\system32\drivers\FSDEPENDS.SYS \SystemRoot\system32\drivers\vsmraid.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\storvsc.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\vmstorfl.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\msiscsi.sys \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\System32\Drivers\BtHidBus.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\drivers\afd.sys \??\C:\Windows\system32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\bflwfx64.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\avkmgr.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\nvlddmkm.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\xhcdrv.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\usbfilter.sys \SystemRoot\system32\drivers\usbohci.sys \SystemRoot\system32\drivers\USBPORT.SYS \SystemRoot\system32\drivers\usbehci.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\e22w7x64.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\amdppm.sys \SystemRoot\system32\DRIVERS\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\amdiox64.sys \SystemRoot\system32\drivers\LGBusEnum.sys \SystemRoot\system32\drivers\LGJoyXlCore.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\drivers\nvvad64v.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\DRIVERS\dtultrausbbus.sys \SystemRoot\system32\drivers\I2cHkBurn.sys \SystemRoot\system32\DRIVERS\ViaHub3.sys \SystemRoot\system32\drivers\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\nvhda64v.sys \SystemRoot\system32\drivers\RTKVHD64.sys \SystemRoot\system32\drivers\MBfilt64.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\system32\DRIVERS\LGSHidFilt.Sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_amd_sata.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \??\C:\Windows\system32\drivers\aksdf.sys \SystemRoot\System32\Drivers\fastfat.SYS \??\C:\Windows\system32\drivers\aksfridge.sys \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys \SystemRoot\system32\DRIVERS\avnetflt.sys \??\C:\Windows\system32\drivers\hardlock.sys \??\C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys \SystemRoot\system32\drivers\peauth.sys \??\C:\Windows\SysWOW64\speedfan.sys \SystemRoot\System32\DRIVERS\srvnet.sys \??\C:\Windows\system32\Drivers\SSPORT.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\SYSTEM32\DRIVERS\WibuKey64.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\LGVirHid.sys \??\C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\WUDFRd.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe ----------- End ----------- Done! Scan started Database versions: main: v2017.01.18.06 rootkit: v2016.11.20.01 <<<2>>> Physical Sector Size: 512 Drive: 1, DevicePointer: 0xfffffa8007675060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8007675b20, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8007675060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8006de0ac0, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa8007456060, DeviceName: \Device\000000a8\, DriverName: \Driver\amd_sata\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... Done! Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8007674060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8007674b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8007674060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80074555f0, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa8007452630, DeviceName: \Device\000000a6\, DriverName: \Driver\amd_sata\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6015DB08 Partition information: Partition 0 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 1985 Partition is not bootable Partition 1 type is Dynamic (0x42) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 2 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 206848 Numsec = 209715200 Partition is not bootable Partition file system is NTFS Partition 3 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 209922048 Numsec = 1743601072 Partition is not bootable Partition file system is NTFS Disk Size: 1000204886016 bytes Sector size: 512 bytes Done! Drive 1 This is a System drive Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: 619C2244 Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2048 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 208896 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 413696 Numsec = 468443136 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 240057409536 bytes Sector size: 512 bytes Done! Physical Sector Size: 512 Drive: 2, DevicePointer: 0xfffffa8008a77060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8008a56580, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8008a77060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8008a5a8c0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa8008a4a5a0, DeviceName: \Device\000000c1\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 2 Scanning MBR on drive 2... Inspecting partition table: MBR Signature: 55AA Disk Signature: 57A43849 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 2018699264 Partition is bootable Partition file system is NTFS Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 2018701312 Numsec = 839682048 Partition is not bootable Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2858383360 Numsec = 524288000 Partition is not bootable Partition file system is NTFS Partition 3 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 3382671360 Numsec = 524288000 Partition is not bootable Partition file system is NTFS Disk Size: 2000365289472 bytes Sector size: 512 bytes Done! Physical Sector Size: 0 Drive: 3, DevicePointer: 0xfffffa80094a3510, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a6040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a3510, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a1440, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949b720, DeviceName: \Device\000000ec\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 4, DevicePointer: 0xfffffa80094a8060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a8b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a8060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a2040, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800946c060, DeviceName: \Device\000000ed\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 5, DevicePointer: 0xfffffa80094a5060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a5b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a5060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a2bf0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949a530, DeviceName: \Device\000000ee\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 6, DevicePointer: 0xfffffa80094ab790, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094aa040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094ab790, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a27a0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949cb60, DeviceName: \Device\000000ef\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Infected: C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe --> [Adware.Agent] Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|msiql --> [Adware.Agent] Infected: C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe --> [Adware.Agent] File C:\Windows\System32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys will be destroyed Infected: C:\Windows\System32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys --> [Adware.Wajam.Generic] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\d9eee9dfd1d1e926566fcb6f68590575 --> [Adware.Wajam.Generic] Infected: C:\$Recycle.Bin\S-1-5-21-844601699-3614358154-429673199-1000\$RMG8ZNU.tmp\Un_A.exe --> [Adware.OptimizerEliteMax] Infected: C:\$Recycle.Bin\S-1-5-21-844601699-3614358154-429673199-1000\$R49C5J1\onesystemcare.exe --> [Adware.OptimizerEliteMax] Infected: C:\Users\Alex\Desktop\Camtasia Studio 9\camtasia 9 patch.exe --> [RiskWare.FilePatcher] Scan finished Creating System Restore point... Cleaning up... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action cmd.exe... Success! Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.3.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.18524 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED, K:\ DRIVE_FIXED CPU speed: 4.400000 GHz Memory total: 8552493056, free: 5128929280 Downloaded database version: v2017.01.18.07 ======================================= Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017 durchgeführt von Alex (Administrator) auf ALEX-PC (18-01-2017 16:32:44) Gestartet von C:\Users\Alex\Desktop Geladene Profile: Alex (Verfügbare Profile: Alex) Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Opera) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe (SafeNet Inc.) C:\Windows\System32\hasplms.exe (VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Palit Microsystems Ltd.) C:\Program Files (x86)\Thunder Master\THPanel.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (iAnywhere Solutions) C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (Autodesk, Inc.) E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe (MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () C:\Windows\System32\PnkBstrA.exe () C:\Windows\SysWOW64\spdsvc.exe () C:\Windows\SysWOW64\SecUPDUtilSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8801024 2016-04-22] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15112312 2016-02-09] (Logitech Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] () HKLM-x32\...\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-11-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] () HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1015808 2016-05-19] (MSI) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26287016 2017-01-06] (Dropbox, Inc.) HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MSI) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [THPanel] => C:\Program Files (x86)\Thunder Master\THPanel.exe [2197472 2015-07-22] (Palit Microsystems Ltd.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [4644184 2015-06-10] (Disc Soft Ltd) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [ProxyGate] => C:\Users\Alex\AppData\Roaming\ProxyGate\MainService.exe <===== ACHTUNG HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Policies\Explorer: [] HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {2a7e694d-afe4-11e5-881f-806e6f6e6963} - F:\DVDSetup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} - R:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} - G:\startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} - M:\Startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {b7167805-aff4-11e5-89b3-d8cb8a9bbec6} - Q:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {dddedf48-3336-11e6-9221-d8cb8a9bbec6} - D:\setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {fd345007-2950-11e6-980e-d8cb8a9bbec6} - Y:\Setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283112 2016-02-02] (Autodesk, Inc.) HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2016-02-07] (Autodesk, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Blue Manager Suite.lnk [2016-01-16] ShortcutTarget: Blue Manager Suite.lnk -> C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (iAnywhere Solutions) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-06-08] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Winsock: Catalog9-x64 01 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 02 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 03 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 04 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 15 C:\Windows\system32\zdengine64.dll Keine Datei Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-844601699-3614358154-429673199-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-10-11] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default [2017-01-13] FF Homepage: Mozilla\Firefox\Profiles\qiF99tHm.default -> hxxps://www.google.de FF Session Restore: Mozilla\Firefox\Profiles\qiF99tHm.default -> ist aktiviert. FF Extension: (Avira Browser Safety) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\abs@avira.com.xpi [2016-11-27] FF Extension: (Firefox Hotfix) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-03] FF Extension: (MEGA) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox@mega.co.nz.xpi [2017-01-12] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-13] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-18] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @lattice3d.com/XVL Player -> C:\Program Files\Lattice\Player3_x86\npxvlplay.dll [2015-02-23] (Lattice Technology Co.,Ltd.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-01-12] CHR Extension: (Google Präsentationen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-14] CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-14] CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-14] CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-14] CHR Extension: (Adobe Acrobat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-12] CHR Extension: (Google Tabellen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-14] CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-12-14] CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-14] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-14] CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-14] CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-14] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-10-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 5f997e823c149616faed2a7953b94672; C:\Program Files\5f997e823c149616faed2a7953b94672\4be4ee7ec1a7db4d36fdb985186936b5.exe [39237120 2017-01-17] () [Datei ist nicht signiert] <==== ACHTUNG S4 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk Inc.) S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-14] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-12] () S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51504 2017-01-06] (Dropbox, Inc.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [392168 2016-08-31] (Digital Wave Ltd.) R3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1345368 2015-06-10] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [249104 2016-11-11] (EasyAntiCheat Ltd) R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.) R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.) R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-01] (SafeNet Inc.) S2 HiPatchService; H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-01-28] (Rivet Networks) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2016-02-09] (Logitech Inc.) R2 mitsijm2017; E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe [967456 2015-08-04] (Autodesk, Inc.) S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MSI) S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2204768 2016-09-29] (MSI) S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4162656 2016-09-29] (MSI) R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2015328 2016-09-29] (MSI) R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2327648 2016-09-29] (MSI) S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-09-29] (MSI) S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [607160 2016-09-29] (MSI) R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2248144 2016-04-28] (Micro-Star INT'L CO., LTD.) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation) S4 Origin Client Service; C:\Users\Alex\Origin\OriginClientService.exe [2119688 2016-12-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Users\Alex\Origin\OriginWebHelperService.exe [2180624 2016-12-24] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-01-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-01-02] () S4 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc) R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-05-01] () R2 SamsungUPDUtilSvc; C:\Windows\SysWOW64\SecUPDUtilSvc.exe [143664 2016-06-06] () S4 SanDisk SSD Dashboard Service; C:\Program Files (x86)\SanDisk\SSD Dashboard\SanDiskSSDDashboardService.exe [373760 2016-06-24] (SanDisk) [Datei ist nicht signiert] S3 Survarium-Steam Update Service; H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-11-14] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-12-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-05-11] (Avira Operations GmbH & Co. KG) S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-01-24] (Rivet Networks, LLC.) S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT Corporation.) S3 btiaa2dp; C:\Windows\System32\drivers\btiaa2dp.sys [82944 2008-09-16] (iAnywhere Solutions) S3 BTiAPan; C:\Windows\System32\DRIVERS\btiapan.sys [37888 2008-09-16] (iAnywhere Solutions) S3 btiarcp; C:\Windows\System32\DRIVERS\btiarcp.sys [10880 2008-07-30] (iAnywhere Solutions) S3 btiaspp; C:\Windows\System32\DRIVERS\btiaspp.sys [92160 2008-09-16] (iAnywhere Solutions) S3 BTIAUSB; C:\Windows\System32\DRIVERS\btiausb.sys [31744 2008-11-14] (iAnywhere Solutions) S3 BTPROT; C:\Windows\System32\DRIVERS\btprot.sys [517632 2008-11-14] (iAnywhere Solutions) R0 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation) R0 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation) R0 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-31] (Disc Soft Ltd) S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-31] (Disc Soft Ltd) R0 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2016-03-15] (Disc Soft Ltd) R3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47160 2016-03-15] (Disc Soft Ltd) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc) R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-01] (SafeNet Inc.) R3 I2cHkBurn; C:\Windows\System32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.) S3 iAnywhere_btAudio; C:\Windows\System32\drivers\btiasco.sys [25088 2008-07-30] (iAnywhere Solutions) S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.) S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [125488 2015-03-18] (Qualcomm Atheros, Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2016-07-30] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Datei ist nicht signiert] R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [106760 2015-10-14] (WIBU-SYSTEMS AG) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) S3 ALSysIO; \??\C:\Users\Alex\AppData\Local\Temp\ALSysIO64.sys [X] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 BTCOM; system32\DRIVERS\btcomport.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 cpuz137; \??\C:\Users\Alex\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X] S3 cpuz138; \??\C:\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] S3 xspirit; \??\C:\Windows\xspirit.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 16:32 - 2017-01-18 16:33 - 00035949 _____ C:\Users\Alex\Desktop\FRST.txt 2017-01-18 16:32 - 2017-01-18 16:32 - 00000000 ____D C:\FRST 2017-01-18 16:31 - 2017-01-18 16:31 - 02419200 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe 2017-01-18 16:21 - 2017-01-18 16:21 - 00000000 ___HD C:\OneDriveTemp 2017-01-18 15:57 - 2017-01-18 16:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-01-18 15:55 - 2017-01-18 16:12 - 00000000 ____D C:\Users\Alex\Desktop\mbar 2017-01-18 15:54 - 2017-01-18 15:54 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Alex\Desktop\mbar-1.09.3.1001.exe 2017-01-18 15:48 - 2017-01-18 15:48 - 00000000 ____D C:\Users\Alex\Desktop\backups 2017-01-18 15:34 - 2017-01-18 15:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alex\Desktop\HijackThis_2.0.5.exe 2017-01-18 11:07 - 2017-01-18 16:21 - 00000318 ____H C:\Windows\Tasks\MSIOSDx86_Host.job 2017-01-18 11:07 - 2017-01-18 16:21 - 00000318 ____H C:\Windows\Tasks\MSIOSDx64_Host.job 2017-01-18 11:07 - 2017-01-18 16:21 - 00000252 ____H C:\Windows\Tasks\MSISW_Host.job 2017-01-18 10:54 - 2017-01-18 10:55 - 00000000 ____D C:\Windows\system32\SSL 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\Users\Alex\AppData\Local\app 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\ProgramData\b1fa982f-78d5-0 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\ProgramData\b1fa982f-2e57-1 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\Program Files\5f997e823c149616faed2a7953b94672 2017-01-18 10:53 - 2017-01-18 11:05 - 00000000 ____D C:\Program Files (x86)\8c019856-45eb-468e-bf17-e8408cf047bf1484733219 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Note-UP 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 ____D C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 _____ C:\TOSTACK 2017-01-18 10:07 - 2017-01-18 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-01-18 10:06 - 2017-01-18 10:07 - 00000000 ____D C:\Users\Alex\AppData\Roaming\DVDVideoSoft 2017-01-18 10:04 - 2017-01-18 10:05 - 00000000 ____D C:\Users\Alex\Documents\psynetic-gifx 2017-01-18 10:04 - 2017-01-18 10:04 - 00000000 ____D C:\Users\Alex\AppData\Local\psynetic-imageconverter 2017-01-18 10:03 - 2017-01-18 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\psynetic 2017-01-13 12:28 - 2017-01-13 12:28 - 00000000 ____D C:\Users\Alex\Desktop\CINEBENCHR15.03 2017-01-12 22:36 - 2017-01-12 22:50 - 00000028 _____ C:\Users\Alex\Desktop\Neues Textdokument.txt 2017-01-12 08:37 - 2017-01-12 08:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-01-09 16:16 - 2017-01-09 16:22 - 04407342 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V4.0 inkl. Mittelabflußplan.xlsx 2017-01-08 20:53 - 2017-01-08 20:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-01-08 20:53 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-01-08 20:53 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-01-08 20:53 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe 2017-01-08 20:50 - 2016-12-12 03:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-01-08 20:50 - 2016-12-12 03:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-01-06 01:04 - 2017-01-06 01:04 - 00051504 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-01-04 00:21 - 2017-01-04 00:22 - 00000000 ____D C:\Program Files (x86)\OBS 2017-01-04 00:21 - 2017-01-04 00:21 - 00000935 _____ C:\Users\Alex\Desktop\Open Broadcaster Software.lnk 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Program Files\OBS 2017-01-03 12:12 - 2017-01-12 22:40 - 00000000 ____D C:\Users\Alex\Desktop\Gifs 2017-01-02 15:07 - 2017-01-02 15:07 - 00000000 ____D C:\Crash 2017-01-01 23:15 - 2017-01-02 15:06 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Daybreak Game Company 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\SCE 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\Daybreak Game Company 2016-12-26 19:26 - 2016-12-26 19:26 - 00000000 ____D C:\Users\Alex\AppData\Local\TechSmith 2016-12-26 19:02 - 2017-01-18 16:21 - 00002938 _____ C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 16:20 - 00004984 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2016-12-26 19:02 - 2016-12-26 19:02 - 00004236 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-12-26 19:02 - 2016-12-12 15:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2016-12-25 17:44 - 2016-12-25 17:44 - 00000000 ____D C:\Users\Alex\AppData\Local\4A Games 2016-12-22 20:53 - 2016-12-22 20:53 - 00000000 ____D C:\Users\Alex\AppData\Local\HirezLauncherUI 2016-12-22 20:52 - 2016-12-22 21:01 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2016-12-22 20:52 - 2016-12-22 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios 2016-12-22 17:26 - 2016-12-22 17:26 - 00788918 _____ C:\Users\Alex\Desktop\Nachtragsmanagement_MB.pdf 2016-12-22 17:26 - 2016-12-22 17:26 - 00317552 _____ C:\Users\Alex\Desktop\1.Verfahrensbeschreibungen (1).pdf 2016-12-22 14:13 - 2016-12-22 14:13 - 04464334 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V1 für Ausbau.xlsx 2016-12-21 14:05 - 2016-12-22 14:45 - 00000000 ____D C:\Users\Alex\Desktop\Mittelabflußplan 2016-12-21 07:52 - 2016-12-21 07:52 - 00018407 _____ C:\Users\Alex\AppData\Local\recently-used.xbel 2016-12-20 17:02 - 2016-12-20 17:03 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TeamViewer 2016-12-20 17:02 - 2016-12-20 17:02 - 12971088 _____ (TeamViewer GmbH) C:\Users\Alex\Desktop\TeamViewer_Setup_de.exe 2016-12-20 12:07 - 2017-01-18 09:48 - 00003018 _____ C:\Windows\System32\Tasks\MSIAfterburner ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 16:28 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-18 16:28 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-18 16:27 - 2016-01-05 19:15 - 00000000 ____D C:\Users\Alex\Documents\Outlook-Dateien 2017-01-18 16:24 - 2016-07-21 15:35 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-01-18 16:21 - 2016-03-25 12:05 - 00000000 ___RD C:\Users\Alex\Dropbox 2017-01-18 16:21 - 2016-01-06 21:03 - 00000000 ___RD C:\Users\Alex\OneDrive 2017-01-18 16:21 - 2016-01-05 13:46 - 00000000 ____D C:\Users\Alex\AppData\Local\CrashDumps 2017-01-18 16:21 - 2015-12-31 19:02 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-18 16:21 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-01-18 16:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-18 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2017-01-18 16:12 - 2008-05-09 16:08 - 00001891 _____ C:\Users\Alex\AppData\Local\bmarchive.bms 2017-01-18 15:57 - 2016-07-21 15:36 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-18 15:57 - 2016-07-21 15:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-01-18 11:19 - 2016-12-14 15:41 - 00002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-18 11:07 - 2016-02-21 22:19 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-01-18 10:56 - 2016-05-21 18:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-18 10:55 - 2016-11-23 12:46 - 00000000 ____D C:\Users\Public\Documents\AdobeGC 2017-01-18 10:46 - 2016-11-23 11:43 - 00000000 ____D C:\Users\Alex\Documents\Camtasia Studio 2017-01-18 10:45 - 2016-03-25 11:59 - 00001210 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-01-18 10:17 - 2016-10-14 10:13 - 00719098 _____ C:\Windows\system32\perfh019.dat 2017-01-18 10:17 - 2016-10-14 10:13 - 00151344 _____ C:\Windows\system32\perfc019.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00702730 _____ C:\Windows\system32\perfh007.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00150314 _____ C:\Windows\system32\perfc007.dat 2017-01-18 10:17 - 2009-07-14 06:13 - 02498584 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-18 10:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-01-18 10:07 - 2016-11-20 19:00 - 00000000 ____D C:\Users\Alex\.gimp-2.8 2017-01-18 09:59 - 2016-02-21 22:17 - 00000000 ____D C:\Users\Alex\AppData\Local\Adobe 2017-01-18 09:56 - 2016-05-21 18:00 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-18 09:56 - 2016-02-21 22:19 - 00003936 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-01-18 09:56 - 2016-01-04 20:38 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-18 09:56 - 2016-01-04 20:38 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-18 09:48 - 2016-11-23 10:04 - 00003490 _____ C:\Windows\System32\Tasks\AutoKMS 2017-01-18 09:48 - 2016-03-25 11:59 - 00001206 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-01-13 12:30 - 2016-02-18 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2017-01-13 12:29 - 2016-01-04 12:16 - 00000000 ____D C:\Users\Alex\AppData\Roaming\MAXON 2017-01-13 12:18 - 2016-12-01 19:09 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mozilla 2017-01-13 03:57 - 2016-01-05 20:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client 2017-01-12 18:36 - 2016-11-27 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-01-12 08:37 - 2016-02-20 15:08 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-01-11 21:10 - 2016-03-07 20:07 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-01-11 21:09 - 2016-03-07 20:07 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-01-10 16:14 - 2016-07-29 13:57 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS 2017-01-08 20:54 - 2016-11-15 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-01-08 20:54 - 2016-03-18 15:26 - 00000000 ____D C:\Temp 2017-01-08 20:54 - 2015-12-31 19:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-01-04 13:34 - 2016-01-04 14:47 - 00000000 ___RD C:\Users\Alex\Desktop\Games 2017-01-04 12:19 - 2015-12-31 16:47 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-01-01 23:09 - 2016-01-01 16:51 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Origin 2017-01-01 23:09 - 2016-01-01 16:46 - 00000000 ____D C:\ProgramData\Origin 2016-12-29 10:30 - 2016-01-04 14:50 - 00000000 ___RD C:\Users\Alex\Desktop\MSI 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\Program Files\Core Temp 2016-12-27 16:51 - 2016-11-14 17:01 - 00000000 ____D C:\Users\Alex\Documents\Survarium-Steam 2016-12-26 19:02 - 2016-11-15 14:23 - 00003832 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003820 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003644 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003584 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2015-12-31 19:03 - 00000000 ____D C:\Users\Alex\AppData\Local\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 19:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 18:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-25 17:46 - 2016-12-07 09:16 - 00000000 ____D C:\Users\Alex\Documents\4A Games 2016-12-24 12:47 - 2016-07-02 20:29 - 00000000 ____D C:\Users\Alex\Origin 2016-12-24 12:41 - 2016-11-30 16:24 - 00000000 ____D C:\Users\Public\Documents\.forever 2016-12-24 12:34 - 2016-01-04 14:30 - 00000000 ____D C:\Users\Alex\Desktop\SBOT 2016-12-22 21:00 - 2015-12-31 14:23 - 00000000 ____D C:\Users\Alex\Documents\My Games 2016-12-22 20:52 - 2015-12-31 19:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-12-22 15:37 - 2015-12-31 20:42 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1451590946 2016-12-22 15:37 - 2015-12-31 20:41 - 00000000 ____D C:\Program Files (x86)\Opera 2016-12-20 16:50 - 2016-07-18 14:59 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype 2016-12-20 16:43 - 2016-07-18 16:25 - 00000384 ___RH C:\Windows\sosyambaess.lock 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ____D C:\ProgramData\Skype ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 14:46 - 2016-02-06 14:54 - 0000104 _____ () C:\Users\Alex\AppData\Roaming\mBot.ini 2008-05-09 16:08 - 2017-01-18 16:12 - 0001891 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms 2008-05-09 16:08 - 2016-02-20 19:23 - 0000000 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms~RF1a66bd5.TMP 2016-12-21 07:52 - 2016-12-21 07:52 - 0018407 _____ () C:\Users\Alex\AppData\Local\recently-used.xbel 2015-12-31 18:57 - 2016-01-05 15:11 - 0007605 _____ () C:\Users\Alex\AppData\Local\resmon.resmoncfg 2016-05-13 21:20 - 2016-05-13 21:20 - 0000000 _____ () C:\Users\Alex\AppData\Local\{AF97A572-54D0-441A-A283-15CC4BC2A136} 2016-01-04 16:28 - 2016-01-04 16:28 - 0000016 _____ () C:\ProgramData\mntemp 2016-12-26 19:02 - 2017-01-18 16:21 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 16:20 - 0004984 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-03 12:51 ==================== Ende von FRST.txt ============================ Grüße BauBau |
18.01.2017, 17:30 | #2 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start FRST Addition Log
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017 durchgeführt von Alex (18-01-2017 16:33:06) Gestartet von C:\Users\Alex\Desktop Windows 7 Ultimate Service Pack 1 (X64) (2015-12-31 17:53:35) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844601699-3614358154-429673199-500 - Administrator - Disabled) Alex (S-1-5-21-844601699-3614358154-429673199-1000 - Administrator - Enabled) => C:\Users\Alex Gast (S-1-5-21-844601699-3614358154-429673199-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-844601699-3614358154-429673199-1005 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) A360 Desktop (HKLM\...\{7758802D-9486-4883-9927-CCAC366A3BA4}) (Version: 7.2.3.1800 - Autodesk) ACA & MEP 2017 Object Enabler (Version: 7.9.45.0 - Autodesk) Hidden ACAD Private (Version: 21.0.52.0 - Autodesk) Hidden Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.1.335 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\{C1F3739C-D31D-4062-8788-29261C4A2A68}) (Version: 12.2.4.194 - Adobe Systems, Inc) Age of Mythology: Extended Edition (HKLM\...\Steam App 266840) (Version: - SkyBox Labs) AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.) Ansel (Version: 376.33 - NVIDIA Corporation) Hidden Aperture Tag: The Paint Gun Testing Initiative (HKLM\...\Steam App 280740) (Version: - Aperture Tag Team) AutoCAD 2017 - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 Language Pack - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden Autodesk Advanced Material Library Image Library 2017 (HKLM-x32\...\{8ED2ED41-4455-449D-993C-751C039089B9}) (Version: 15.11.3.0 - Autodesk) Autodesk AutoCAD 2017 - Deutsch (German) (HKLM\...\AutoCAD 2017 - Deutsch (German)) (Version: 21.0.52.0 - Autodesk) Autodesk AutoCAD Performance Feedback Tool 1.2.5 (HKLM-x32\...\{8600F844-9AA5-412E-B6F2-F9C6CBCFD268}) (Version: 1.2.5.0 - Autodesk) Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk) Autodesk Configurator 360 addin (HKLM-x32\...\{E3EE083F-6856-44AB-BC82-445E2FFB8C1A}) (Version: 21.0.11700 - Autodesk) Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk Desktop Connect Service (HKLM\...\{FC772454-BB19-0000-0330-44B459520227}) (Version: 3.30.0 - Autodesk) Autodesk Desktop-App (HKLM-x32\...\Autodesk Desktop App) (Version: 6.2.0.174 - Autodesk) Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.52.0 - Autodesk) Autodesk Guided Tutorial Plugin (HKLM\...\{B3AFC608-D811-0003-0330-21FB25B48D6E}) (Version: 3.30.0 - Autodesk) Autodesk Inventor Content Center Libraries 2017 (Desktop Content) (HKLM\...\{B46DECD1-2164-4EF1-0000-22D71E81877C}) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German)) (Version: 14.0.57.0 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Electrical Catalog Browser 2017 Language Pack - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Professional 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Professional 2017) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Professional 2017 (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk Inventor Professional 2017 Language Pack - Deutsch (German) (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk) Autodesk Material Library 2017 (HKLM-x32\...\{8FB9F735-D64C-4991-8D91-4CDDAB1ABDEE}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Base Resolution Image Library 2017 (HKLM-x32\...\{3FBFBC43-9882-43FA-B979-2D53896747B3}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Low Resolution Image Library 2017 (HKLM-x32\...\{360AC116-6CD4-4E7D-8174-28D47B05E898}) (Version: 15.11.3.0 - Autodesk) Autodesk ReCap 360 (HKLM\...\Autodesk ReCap 360) (Version: 3.0.0.52 - Autodesk) Autodesk ReCap 360 (Version: 3.0.0.52 - Autodesk) Hidden Autodesk Revit Interoperability for Inventor 2017 (HKLM\...\Autodesk Revit Interoperability for Inventor 2017) (Version: 17.0.411.0 - Autodesk) Autodesk Revit Interoperability for Inventor 2017 (Version: 17.0.411.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) (HKLM\...\Autodesk Vault Basic 2017 (Client)) (Version: 22.0.48.0 - Autodesk) Autodesk Vault Basic 2017 (Client) (Version: 22.0.48.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) German Language Pack (Version: 22.0.48.0 - Autodesk) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG) Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG) Avira Connect (HKLM-x32\...\{707e8edf-9482-4417-ae39-c9b5fe605e87}) (Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Avira Connect (x32 Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Hidden Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - ) Blue Manager Suite (HKLM-x32\...\InstallShield_{28B0F39B-C0C6-4CC5-902B-9BF20111804C}) (Version: - ) Blue Manager Suite (Version: 3.3.0 - iAnywhere Solutions) Hidden Body Text Feathering (HKLM-x32\...\PopupProduct) (Version: 1.0.0.0 - Body Text Feathering) <==== ACHTUNG Call of Duty Modern Warfare Remastered MULTi2 1.0 (HKLM-x32\...\Call of Duty Modern Warfare Remastered MULTi2 1.0) (Version: - ) Camtasia 9 (HKLM-x32\...\{b7d38e69-9571-4bb3-98c0-4ec2dfae7acf}) (Version: 9.0.0.1306 - TechSmith Corporation) Camtasia 9 (Version: 9.0.0.1306 - TechSmith Corporation) Hidden CDTS17_Setup_x64 (Version: 17.4 - Corel Corporation) Hidden CleanBrowser (HKLM-x32\...\CleanBrowser) (Version: - ) <==== ACHTUNG Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Contagion (HKLM\...\Steam App 238430) (Version: - Monochrome, Inc) Corel Graphics - Windows Shell Extension (HKLM\...\_{9DA7C2FD-AD83-4E2E-B9F2-9996749318E0}) (Version: 17.4.0.887 - Corel Corporation) Corel Graphics - Windows Shell Extension (Version: 17.4.887 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.4.887 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Capture (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common App (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Connect (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Custom Data (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - DE (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Designer (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Draw (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - EN (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Equation Editor (x32 Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Filters (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FontNav (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FR (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM Content (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM T (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM XVL (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - PHOTO-PAINT (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Photozoom Plugin (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Redist (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Setup Files (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VBA (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VideoBrowser (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Writing Tools (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 (64-Bit) (HKLM\...\_{A4B5A413-B7CF-415F-8994-595DB2EFE848}) (Version: 17.4.0.887 - Corel Corporation) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Crysis WARHEAD(R) (x32 Version: 1.0 - Crytek) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Ultra (HKLM\...\DAEMON Tools Ultra) (Version: 3.1.0.0368 - Disc Soft Ltd) Dropbox (HKLM-x32\...\Dropbox) (Version: 17.4.33 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden DWG TrueView 2017 - English (Version: 21.0.52.0 - Autodesk) Hidden Eco Materials Adviser for Autodesk Inventor 2017 (64-bit) (HKLM\...\{05D87862-35C9-4CB4-92EC-8A1FC97BFF6C}) (Version: 6.4.9.0 - Granta Design Limited) Elegant-Treiber Paket (HKLM-x32\...\Samsung Stylish UI Pack) (Version: 1.01.74.00 (09.02.2015) - Samsung Electronics Co., Ltd.) Euro Truck Simulator 2 Demo (HKLM\...\Steam App 231120) (Version: - SCS Software) FARO LS 1.1.505.0 (64bit) (HKLM-x32\...\{8834451B-6209-4E02-9EF4-4EF9E3C1F70F}) (Version: 5.5.0.44203 - FARO Scanner Production) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company) Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14 (HKLM-x32\...\Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14) (Version: - ) Half-Life: A Place in the West (HKLM\...\Steam App 466270) (Version: - Michael Pelletier) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation) Inventor Connected Desktop for A360 (HKLM\...\{1FA52755-1FBC-0001-0330-7CEA1F3736D8}) (Version: 3.30.0 - Autodesk) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer E220x Drivers (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.57.1125 - Rivet Networks) Lattice3D Player / Lattice3D Player Pro (Ver. 9 oder höher) 64-bit Edition (HKLM-x32\...\{936575FE-E49B-4CE9-9934-0329727476C8}) (Version: 14.0c - Lattice Technology) Lattice3D Studio Corel Edition x64 (HKLM-x32\...\{A7161767-5AFE-4725-9DB0-AED7FB5FBA40}) (Version: 2.0 - Lattice Technology) Logitech Gaming Software 8.79 (HKLM\...\Logitech Gaming Software) (Version: 8.79.77 - Logitech Inc.) mb WorkSuite 2016 (HKLM\...\{1C1D8E70-B1C8-4ACE-ADAB-B37F271E71FC}) (Version: 20.16.010.0 - mb AEC Software GmbH) Metro 2033 Redux (HKLM\...\Steam App 286690) (Version: - 4A GAMES) Metro: Last Light Redux (HKLM\...\Steam App 287390) (Version: - 4A Games) Microsoft .NET Framework 4.6 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Hotfix Rollup (KB3154529) (HKLM\...\{5B71B4F6-A412-3C48-B332-0FA9B9958940}) (Version: 4.6.01081 - Microsoft Corporation) Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation) Middle-earth: Shadow of Mordor (HKLM\...\Steam App 241930) (Version: - Monolith Productions, Inc.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla) MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyMemory (HKLM-x32\...\MyMemoryPackage) (Version: - ) <==== ACHTUNG Need for Speed™ (HKLM-x32\...\{F8643E83-A868-4EE8-A0B9-389386830453}) (Version: 1.3.0.0 - Electronic Arts) NVIDIA 3D Vision Treiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.33 - NVIDIA Corporation) NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Stable 42.0.2393.94 (HKLM-x32\...\Opera 42.0.2393.94) (Version: 42.0.2393.94 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) OtherSearch (HKLM-x32\...\OtherSearch) (Version: 3.0.4.2 - Theudobald Yanko) <==== ACHTUNG Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden Portal 2 (HKLM\...\Steam App 620) (Version: - Valve) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7634 - Realtek Semiconductor Corp.) RivaTuner Statistics Server 6.4.1 (HKLM-x32\...\RTSS) (Version: 6.4.1 - Unwinder) Rocketbirds: Hardboiled Chicken (HKLM\...\Steam App 215510) (Version: - Ratloop Asia) Runtime VS2005 SP1 CRT 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 MFC 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 All 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 CRT 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 OpenMP 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2008 x64 CRT 1 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime_MSI_VS2005_SP1_CRT_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFC_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFCLOC_6195 (x32 Version: 1.00.0000 - Lattice Technology) Hidden Runtime_MSI_VS2005_SP1_x64_CRT_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFC_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFCLOC_6195 (Version: 1.00.0000 - Lattice Technology) Hidden Saints Row IV (HKLM\...\Steam App 206420) (Version: - Deep Silver Volition) Samsung Drucker-Diagnose (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7 - Samsung Electronics Co., Ltd.) Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 2.01.05 (11.02.2015) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.0.0.65 - Samsung Electronics Co., Ltd.) Samsung Printer Center (HKLM-x32\...\Samsung Printer Center) (Version: 1.0.0.21 - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (x32 Version: 1.03.05.19 - Samsung Electronics Co., Ltd.) Hidden Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 3.31.79:03 - Samsung Electronics Co., Ltd.) SanDisk SSD Dashboard (HKLM-x32\...\SanDisk SSD Dashboard) (Version: 1.4.3 - Western Digital Corporation or its affiliates) SanDisk SSD Dashboard Service (HKLM-x32\...\{760A9A9B-238A-4EC2-ABFD-88F340D676BC}) (Version: 1.0.2 - SanDisk Corporation) SetIP (HKLM-x32\...\SetIP) (Version: 1.05.08.00 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden SketchUp-Import 2016-2017 (HKLM-x32\...\{063925DB-9D8C-48E2-8F04-1B7038B6C783}) (Version: 2.2.0 - Autodesk) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) SNS Upload for Easy Document Creator (HKLM-x32\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd) Social2Search (HKLM\...\5f997e823c149616faed2a7953b94672) (Version: 11.12.1.250 (i1.0) - Social2Search) <==== ACHTUNG Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.16.7.201605041511 - Sony Mobile Communications Inc.) Sound Blaster Cinema 2 (HKLM-x32\...\{B4F6F8CC-2C61-42CC-A4CC-76621F25BDC7}) (Version: 1.00.07 - Creative Technology Limited) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survarium (HKLM\...\Steam App 355840) (Version: - Vostok Games) TeamSpeak 3 Client (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Crew (Worldwide) (HKLM-x32\...\Uplay Install 413) (Version: - Ubisoft) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft) Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.8 - Samsung Electronics CO., LTD.) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{5D2260D6-DB16-41DC-915B-A39BF4F66362}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 23.0 - Ubisoft) Verfügbare Autodesk-Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WibuKey Setup (WibuKey Remove) (HKLM\...\{00060000-0000-1004-8002-0000C06B5161}) (Version: Version 6.30b of 2014-Oct-29 (Build 1471) (Setup) - WIBU-SYSTEMS AG) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.30 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) Wireless Password Recovery (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\WIFIPR) (Version: - Passcape) Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> E:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{32CDFF57-8CBA-4960-89B1-EC3FA58FB17A}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxTest.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtCp.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\Inventor.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxApprenticeServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\AcInetUI.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxInventorUtilities.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> E:\Program Files\Autodesk\AutoCAD 2017\de-DE\acadficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvResc.dll (Autodesk) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvTXTStack.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02905C77-3498-4D2F-A56F-E3B47EA4C231} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG) Task: {05E915CC-B891-4A8E-AC29-7C952B785C22} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {0659C071-3026-4CA7-90E9-E65DEC87340D} - System32\Tasks\Opera scheduled Autoupdate 1451590946 => C:\Program Files (x86)\Opera\launcher.exe [2016-12-19] (Opera Software) Task: {0F516764-DEAF-400C-8691-DEE4AEC47730} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {24A13EA0-EBC9-427A-B8F0-D0D5D4F55AA7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} - System32\Tasks\ThunderMaster => C:\Program Files (x86)\Thunder Master\THPanel.exe [2015-07-22] (Palit Microsystems Ltd.) Task: {325AD40C-6C77-4CA5-8EFC-C31A99DA86FB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {35651DCE-DF69-49D6-9E0D-6A040F15E01B} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) Task: {43C7A03F-A873-4A39-8510-7824CE650051} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation) Task: {45255647-EFA0-4FCC-8C71-796086CBF11E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {5CCB9225-F2A7-4EE5-8D55-110FA6DD613B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {638082EF-0C1B-4166-BC60-675738B3412F} - System32\Tasks\AdobeAAMUpdater-1.0-Alex-PC-Alex => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {6866B6C9-A5AD-4D44-A6F8-41F6280510D4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe [2017-01-18] (Adobe Systems Incorporated) Task: {6CA7FD92-E9A3-48DC-99D8-12238875FD2B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {726DEEC1-0C13-4293-BE34-834EDD3F5B7F} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI) Task: {80C2ECA6-96DD-4CBC-82F2-F64315C630DE} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-12-13] (NVIDIA Corporation) Task: {821636C8-9030-4062-80E1-563635D59776} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {9F897098-581F-457B-8254-8C2B94EC77BE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation) Task: {A3F6DB31-0FDA-48CA-A31D-A28855F66463} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {C2029E9F-AB75-4D5D-BF88-81874CF831D8} - System32\Tasks\{E8CB978E-86AF-40D8-A31B-BE2D05DAF746} => pcalua.exe -a "J:\Games 29.07.16\Deadpool.German.Subbed.Edition-RIDDICK - filecrypt.cc\DP-PC\Deadpool German Subbed Edition\DEAD.P_GSE.exe" -d "J:\Games 29.07.16\Deadpool.German.Subbed.Edition-RIDDICK - filecrypt.cc\DP-PC\Deadpool German Subbed Edition" Task: {C7D487D6-F163-4179-B9BF-E64EB67DB5EA} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {CDF883CD-2821-4401-8F81-0EE15451562B} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-12-09] () Task: {D594DE41-D2B2-4D16-80F2-D58F777EBD9A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-18] (Adobe Systems Incorporated) Task: {E09DBBF5-33F2-41F7-8369-159B25B179B0} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {E1E08BC0-43A6-4589-A2DA-ED510EB3F1F1} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [2015-03-08] () Task: {E7FB3A92-28F8-448D-86BE-9077650866C1} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {F503FF41-33BA-4996-BE25-43F70435D03C} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-07-07] () Task: {FEBF9113-7489-4FC8-9DAC-E1372556C3CD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\MSIOSDx64_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe Task: C:\Windows\Tasks\MSIOSDx86_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe Task: C:\Windows\Tasks\MSISW_Host.job => C:\Windows\SysWOW64\muachost.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\Alex\Desktop\Programme\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-05-11 12:56 - 2007-08-14 18:03 - 00022016 _____ () C:\Windows\System32\sst1cl6.dll 2016-03-13 16:46 - 2015-03-12 03:43 - 00022528 _____ () C:\Windows\System32\us003lm.dll 2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-12-17 18:55 - 2016-12-17 18:55 - 01678560 _____ () C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-09-08 12:39 - 2014-09-08 12:39 - 00464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2016-11-15 14:23 - 2016-12-13 00:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-01-02 20:48 - 2016-01-02 20:48 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2016-06-06 18:47 - 2016-05-01 08:38 - 00498488 ____N () C:\Windows\SysWOW64\spdsvc.exe 2016-06-06 18:43 - 2016-06-06 18:43 - 00143664 ____N () C:\Windows\SysWOW64\SecUPDUtilSvc.exe 2016-11-15 14:22 - 2016-12-11 19:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2016-12-17 18:54 - 2016-12-17 18:54 - 01244376 _____ () C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\ClientTelemetry.dll 2015-12-31 19:33 - 2014-02-21 11:20 - 00074240 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2015-12-31 19:33 - 2014-02-21 11:17 - 00274944 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2016-03-25 12:02 - 2016-12-08 02:00 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-01-12 08:37 - 2016-12-08 02:01 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-03-25 12:02 - 2016-12-08 02:04 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-03-25 12:02 - 2016-12-08 02:01 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 01682768 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00021328 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00052032 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-01-12 08:37 - 2016-12-08 02:04 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00381760 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00026464 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-08-06 21:06 - 2016-12-08 02:02 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00023384 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00019792 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00022360 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00024400 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-01-12 08:37 - 2016-12-08 01:57 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-01-12 08:37 - 2017-01-06 01:03 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-01-12 08:37 - 2017-01-06 01:04 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-03-25 12:02 - 2016-12-08 02:01 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 01972536 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00020296 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd 2017-01-12 08:37 - 2016-12-08 02:08 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2017-01-12 08:37 - 2016-12-08 02:08 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-01-12 08:37 - 2017-01-06 01:04 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00024920 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-06-06 18:50 - 2015-01-24 11:22 - 03029504 ____N () C:\Windows\system32\DlgSearchEngine.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 68763736 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\opera.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 01893976 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\libglesv2.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 00086616 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0816.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0817.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0818.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\FHBC_2016-01-12_TEAM-3B_Fasel_Gebäudeklimatik_3_alex.pptx:com.dropbox.attributes [183] AlternateDataStreams: C:\Users\Alex\Desktop\Fräsdateien:com.dropbox.attributes [168] AlternateDataStreams: C:\Users\Alex\Desktop\WLC_Team3B.xlsx:com.dropbox.attributes [168] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Software\Classes\.scr: DWGTrueViewScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2017-01-18 15:38 - 00001188 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\Services: AdAppMgrSvc => 2 MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: dbupdate => 2 MSCONFIG\Services: dbupdatem => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: MSI_LiveUpdate_Service => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: PSI_SVC_2_x64 => 2 MSCONFIG\Services: SanDisk SSD Dashboard Service => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: Sony PC Companion => 3 MSCONFIG\startupreg: ABNotify => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe -auto MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe MSCONFIG\startupreg: DAEMON Tools Lite Automount => "D:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: GammingApp => C:\Program Files (x86)\MSI\Gaming APP\SGamingApp.exe --min MSCONFIG\startupreg: Live Update => C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER MSCONFIG\startupreg: OneDrive => "C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: PDFPrint => "C:\Program Files (x86)\PDF24\pdf24.exe" MSCONFIG\startupreg: RemoteMedia => C:\Program Files (x86)\MSI\Command Center\RemoteMedia.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Spotify => "C:\Users\Alex\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Alex\AppData\Roaming\Spotify\SpotifyWebHelper.exe" MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: Steam => "D:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE MSCONFIG\startupreg: VLC Updater => C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 10 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{4750EED5-6919-45A0-AF08-359CC0076FE6}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D96219C-8301-44E5-953D-283283E7ECE8}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2594068C-343F-45A0-B63B-A62BF7BE6109}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{17446144-B74A-4606-B23A-1C189C8DC88A}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{FC13B60E-B2CD-4613-B4D5-1561FF5C0117}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{8605CED7-70B5-4EF4-A5B2-FE2E89F161D1}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [TCP Query User{EA9176A5-185D-416E-B6F9-75DCC8263276}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{B0C355E0-BADE-488A-8AAA-C0889BBAC615}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [{2D4A4BF4-5136-4465-A5B1-062152156216}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{609FC04D-F38E-4F2E-BD1A-A25D97854517}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{0D496196-3EF6-4E0E-B2AD-B658519A69F7}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9EBCAD6C-18A2-4069-82E8-3B7CA430486E}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{3815C750-D7D9-4D61-951F-DFA54724F5D9}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [UDP Query User{B290F1E3-1B27-40E2-9498-000F83BE3E39}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [TCP Query User{FE4D4A70-D0EC-4213-9CFB-CF908E994DCE}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [UDP Query User{8925978B-51D2-4366-96DA-91CCCA86FFCA}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [TCP Query User{61F753EC-EAAC-42A8-824C-BDD987602F82}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [UDP Query User{E4300497-5118-417A-A3D3-2EB1F7298E46}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [TCP Query User{70CDEF17-711F-456B-98CB-A53300F01430}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [UDP Query User{0FD8297F-CAE6-43A0-BC94-09B833AFBCC4}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [TCP Query User{1EC8A469-10A6-491B-90FF-87A554085014}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{D813B25E-13FC-42EF-9812-CEA6D36F4D9F}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{F7F60636-E730-48B7-BBA8-45191CD3581E}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{917CBFED-C3AD-47EA-BF60-32ADE1F9F846}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5599EFEF-A071-4979-8997-AF2FE258BBD6}] => C:\Windows\system32\hasplms.exe FirewallRules: [TCP Query User{01BB30AF-E5D8-4C9A-BFBE-5F605C6130A7}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [UDP Query User{F31E0C4C-4214-4EA7-9EF7-6127DC71DEC1}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [{9560061A-74CB-425A-B62A-09CABB55046C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [{2B6D10B2-1FE5-4F03-B775-102CAF1CBE0C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [TCP Query User{53A8BFA1-4603-4BB8-BC56-0BC38253F567}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{5A93F2D2-FA0D-495A-8A32-B5006D66BEF4}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{49D98C3B-2A5E-4338-ABE0-F924B6BDD358}] => C:\Program Files (x86)\Samsung\Samsung Printer Center\SamsungPrinterCenter.exe FirewallRules: [{671F46D4-0D24-45E1-B61C-E64153E30CD5}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{14AFAADC-8385-47D0-8098-F0B336385812}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{998C9E6E-A42A-4D65-9B13-EF1DD03CFE85}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe FirewallRules: [{9FD2B1E5-2012-4AEE-93BD-4E8F8180603C}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{6F266D86-6B83-410D-80D5-7CDCF27031BE}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe FirewallRules: [{238B1E07-AF59-40FE-94F1-B424B7242E94}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe FirewallRules: [{C300BE33-DBA4-4C93-B64D-613DDB869137}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{8E98299E-9580-43C8-975C-6192C78E9213}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{BEF0B44F-037E-476F-BFA6-8C2C706FCA5B}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{4454CFB3-19BE-405A-90B4-BC705A0CB1BA}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{57AA4318-1F74-4080-AA39-0AF55ED35C19}] => C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ScanCDLM.exe FirewallRules: [{EAC02C55-DB46-47D3-AE14-5FD27F82990F}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [{AF038FF8-ED4F-433F-9D43-497FDF85B06C}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [TCP Query User{05F95EF4-3FA5-4488-AA43-41AAA67F866B}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [UDP Query User{327CD24E-F107-416B-AA60-405B1F88B17C}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [{46E616EF-3721-4155-B683-CB0555788B21}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{4E173E3B-562E-46CF-89BC-B90CBC5E4579}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{DD361FB4-2DD0-4359-8613-498E04669C10}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{905E93C8-B3A8-4D6C-B4ED-CC16893C5A5D}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A60032BF-F733-4706-BE47-D0572603553F}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D41200A6-6C37-4320-A096-FB3B9B77D06A}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{D9AA500D-DED0-4C38-B29C-FBFFBB753BCF}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{D4F511F5-A3C0-4ACE-9887-29CCB2C1819A}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{6D017BB6-214A-4372-AC51-79A0E0838D38}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{3E3D7043-688B-42F1-BD19-EFEE531CD7EB}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{9D43C6AA-622A-4807-8D85-07C4D8DECC1E}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{DED23947-28C4-4CB0-A3DD-6AB991D002CA}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{7A84FB57-2C5F-4AF1-98D1-CBAA810C5371}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [{581081D7-DE6D-45D1-B024-D42D884F35D5}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{009C2982-F3A9-476A-A6DD-E9BBEFD008C2}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{7647EB15-3CF7-4C2D-BF74-C08E6C60CDAC}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{E67D201B-3D8F-415A-A46E-92FB5C4E6D60}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{9750BBA5-40A8-44F3-A4D9-5279F55675AF}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [{D851D20D-8592-4B90-90EC-C9601103100F}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [TCP Query User{44986407-2FDA-4D19-80D3-3E42B8633EC4}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [UDP Query User{85A8E48D-78B4-43AF-B77D-0A11F4CE797A}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [{6FA9110C-F5F5-43FD-8AAD-97C37F81F712}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{FDDAE222-742C-4755-9036-CC91ADF1A4DC}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{42A06F30-5633-4EC3-8516-22F6677C2947}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{D746E6BD-5966-46EA-B84D-3B9C3BC781C1}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{BB9E6EB6-A015-442E-841A-46B8D8981E0F}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{9FFCE39F-326C-4AA6-8A11-EA1980124981}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{7C92A080-F2E6-471E-B71D-A4BFAFCBA865}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{0BFCBF4F-4452-4086-96B1-8A2D033DECEA}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{7F63544E-5F0F-4CE5-BC77-13090B2B752D}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [{0BB49C5F-0009-48E6-BB0D-947907C8CB77}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [TCP Query User{75A0C3D7-376F-4E92-B796-39FB47CEA324}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{550AA2BC-F80A-4AD6-A9A7-A6E4E59C6263}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{9E8D188F-7A68-4CE1-AE50-776DAE4AC71B}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{97AB60CF-256B-4339-A041-C06A49483DAF}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{12A249D7-B9E5-417A-B4FF-0ED1519D3B57}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{D477E148-CA94-42B1-BDB5-4A107A21CF2C}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{5CFE4309-AE83-45A8-860D-A966B7A66F2E}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{383E1175-6B7C-4EAB-8592-581174AB387A}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{DC6CF8D7-022B-4BF1-A2D4-A01099710A8E}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{A8EDA4A9-1BB0-454F-851A-5C0A66C0935C}] => LPort=2869 FirewallRules: [{9076894C-96AF-4F79-9FC8-872941390765}] => LPort=1900 FirewallRules: [{982C83A7-E965-4A43-AC57-DED5418E1D86}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{34904A3E-2731-4BCA-99E7-0C522E19F596}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{79A4CA0B-FAAD-4F1D-B690-53DCB685F3B7}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{6A68F600-EE62-4D35-A8FD-19C7FC858DD0}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{7ED7E197-1394-431D-9A73-11AE6D10BEB9}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A9235B4D-7631-49AD-9E30-76937AC56F5E}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A350EF63-8725-4AB3-B6BD-33D13DA5F134}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_launcher.exe FirewallRules: [{BDC16B40-7773-4E47-A4A0-23BD74170D09}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{D8AD6045-708F-4629-A4D3-642C3BD4F61F}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{75E6E119-7E57-400A-B104-24F8D32EDD90}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{6D166702-17D2-4E22-B532-DD814E55C422}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{DA796ED4-9458-4BC1-95A0-AB6DD17FDCF5}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{176A26D4-1D56-44E4-9B84-4970448A6B21}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{56374166-7C69-44CF-9232-BAB7964BABCE}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{EDC2E8A6-CB4E-49CA-8B4F-F555651A914C}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{80B41A04-E617-42B5-AFCB-5CA576D9FDBA}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{1D989B94-B275-455F-B721-1C10E62BE0BF}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{991023BE-281F-40DD-A22A-5FF97099B5CB}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{B79C5C21-ACA7-43F6-9284-D0ABD0C7F86D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{BE7CB2A9-F20C-4BB0-87C0-644FD0CDA1D4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{D720B6B9-0A35-42D0-85A5-EE9270EA03BB}] => LPort=8318 FirewallRules: [{B99A897A-B2C5-456B-B3D8-E0B80DAB2FBE}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelDrw.exe FirewallRules: [{699A2E63-2033-4335-A20F-1686EBD94622}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\Designer.exe FirewallRules: [{CB3411CB-51BD-4951-A168-022BAAA9C7CD}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelPP.exe FirewallRules: [{A8ECF176-6083-4C6C-898B-638185759074}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{200F9EE4-2BF0-4ADF-BF03-BE4E5C8E16A2}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{6DF521B4-51CF-4AB3-B0AB-71091788AF8C}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{518CE409-F02B-4BA8-B0E3-16AD4BD4E7D7}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{F78314FA-4E04-4C00-B620-F4342A39F389}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{A9141310-E430-48A0-A42E-EC596D66B4E8}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{E8D911F0-75D3-49D6-811F-7773A97AF5E1}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{CB30BD9A-3C48-4EA5-8F44-A68289BC1E56}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{2E488689-B02A-48F2-9567-DA9848F1A6C5}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [{0A84CC58-F8C4-4E72-8EA1-3019C08D15AD}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [TCP Query User{EDDD8DC6-81D9-43F6-A646-74F92961A6B5}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [UDP Query User{A7DE668B-1E28-4EFE-ACBC-61ACB822FA99}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [{BE76A0A7-9704-4FEE-8174-3305863BAC38}] => C:\Program Files\Autodesk\Desktop Connect\forever\node.exe FirewallRules: [{2BF5D8B6-6403-4A42-8E4A-E21A7420760A}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{2C7B2DC1-7504-4C82-9DA7-D17A3DCDE685}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{DF6B2F65-8DAE-4D51-A95E-6743F086EC2A}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{26765CDE-DB0B-447C-893B-51F1C501186B}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{BE3EF81A-2CD1-45DD-A071-275030320227}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{7ECE005B-97E3-4C60-A29D-BD5D20BBEF43}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{A3D9E1E0-C8EA-4E2E-8FE3-DD48267D9E7C}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{12CAEE74-C739-431C-ABBF-82EA376E1535}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{6908C6EB-7521-4486-A71C-9A94CE4784F3}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{99122A42-4BB1-4FA9-8B82-DB47E74DE65F}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{0B6CE556-8917-4B14-BE1A-B94B057E5923}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{95D44447-AEB3-42E1-9812-FBA20C38F973}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{9705E715-8B84-4FB0-8761-6F399FEA9D5E}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{5E2D4D0F-96FA-4F7E-B60E-47B3927A85B2}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{A2BAFD1F-E6F8-42FA-9191-5E66E402272E}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{E8BA2090-632A-40E1-9E5B-2219C72336AD}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{4B563710-0FFB-4B58-8123-BF4948C0919B}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [TCP Query User{CB0D4FD0-D3EF-4926-9FD3-8DF624B8DBFF}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{07CB26DB-BCA3-4241-A49C-B409B6F95D5F}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{791ADF39-9F27-45E2-8361-5BDCF553233E}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{D13C0897-595A-403E-8BF6-4AB1772FC39D}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{994C4074-9B2E-421D-826C-EFDBEE9BFD18}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{B2C64793-5BD9-45A1-87CF-F19EB0938603}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{487A2954-09F0-495B-AA5E-BF44BC759183}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{63C63B5A-8D62-4FF6-AF78-5C7ED303AD27}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{E800328C-F65F-41A9-9F18-33ECB585C235}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Wiederherstellungspunkte ========================= 29-12-2016 00:33:06 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 29-12-2016 00:33:17 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 30-12-2016 03:01:50 DirectX wurde installiert 06-01-2017 19:41:51 Geplanter Prüfpunkt 09-01-2017 18:57:57 DirectX wurde installiert 18-01-2017 10:06:48 DVDVideoSoftRestorePoint 18-01-2017 11:05:03 Wiederherstellungsvorgang 18-01-2017 16:12:27 Malwarebytes Anti-Rootkit Restore Point ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/18/2017 04:31:49 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2017-01-25T08:47:49Z. Error Code: 0x80070032. Error: (01/18/2017 04:21:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/18/2017 04:21:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NetworkManager.exe, Version: 1.1.57.1125, Zeitstempel: 0x56aa8dfe Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.23569, Zeitstempel: 0x57f7c0b4 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000001a06d ID des fehlerhaften Prozesses: 0xb9c Startzeit der fehlerhaften Anwendung: 0x01d2719e83ca05d5 Pfad der fehlerhaften Anwendung: C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: cc39f179-dd91-11e6-8fa4-d8cb8a9bbec6 Error: (01/18/2017 04:21:21 PM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.InvalidOperationException: Could not start IPC server bei Hirez.Patcher.HiPatchService.InternalStart() bei Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/18/2017 04:21:20 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NetworkManager.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Net.Sockets.SocketException bei System.Net.Sockets.Socket..ctor(System.Net.Sockets.AddressFamily, System.Net.Sockets.SocketType, System.Net.Sockets.ProtocolType) bei System.Net.Sockets.TcpClient.initialize() bei System.Net.Sockets.TcpClient..ctor(System.Net.Sockets.AddressFamily) bei NetworkManager.ServerAPI.ServerPipe.ReadThread() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (01/18/2017 04:21:15 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/18/2017 04:21:14 PM) (Source: Schedule) (EventID: 0) (User: ) Description: Event-ID 0 Error: (01/18/2017 04:14:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/18/2017 04:13:53 PM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.InvalidOperationException: Could not start IPC server bei Hirez.Patcher.HiPatchService.InternalStart() bei Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/18/2017 04:13:48 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Systemfehler: ============= Error: (01/18/2017 04:32:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:32:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:26:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:26:03 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:24:57 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:24:56 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet: Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. Error: (01/18/2017 04:24:46 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: Der Server "{4991D34B-80A1-4291-83B6-3328366B9097}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/18/2017 04:24:16 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147014790 = Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden.. Error: (01/18/2017 04:24:16 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT-AUTORITÄT) Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147952506. Error: (01/18/2017 04:23:39 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet: %%-2147014790 = Der angeforderte Dienstanbieter konnte nicht geladen oder initialisiert werden. CodeIntegrity: =================================== Date: 2016-01-30 22:58:26.996 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.963 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.850 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.817 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.604 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.573 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.430 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.382 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.632 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-6300 Six-Core Processor Prozentuale Nutzung des RAM: 41% Installierter physikalischer RAM: 8156.29 MB Verfügbarer physikalischer RAM: 4753.27 MB Summe virtueller Speicher: 16310.77 MB Verfügbarer virtueller Speicher: 12075.39 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:223.37 GB) (Free:54.19 GB) NTFS Drive e: () (Fixed) (Total:277.17 GB) (Free:56.68 GB) NTFS Drive h: () (Fixed) (Total:277.17 GB) (Free:41.06 GB) NTFS Drive i: () (Fixed) (Total:100 GB) (Free:20.88 GB) NTFS Drive k: (Volume) (Fixed) (Total:277.08 GB) (Free:209.91 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6015DB08) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Active) - (Size=100 MB) - (Type=42) Partition 3: (Not Active) - (Size=100 GB) - (Type=42) Partition 4: (Not Active) - (Size=831.4 GB) - (Type=42) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 619C2244) Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=223.4 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
18.01.2017, 17:55 | #3 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera startMein Name ist Rafael und ich werde dir bei der Bereinigung helfen. Damit ich dir optimal helfen kann, halte dich bitte an folgende Regeln:
Schritt 0 Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Hinweis: Falls bei der Deinstallation zu Beginn ein Fehler auftritt oder du den aufgerufenen Uninstaller nicht bedienen kannst, breche dieses Setup einfach ab und fahre mit der Entfernung durch Revo wie oben beschrieben fort. Schritt 1 Lade dir folgendes Programm herunter und installiere es: Malwarebytes Anti-Malware
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen. Bitte poste in deiner nächsten Antwort also:
__________________ |
18.01.2017, 20:06 | #4 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Hallo Raphael, Erstmal vielen Dank für die schnelle Rückmeldung. Ich gebe mein bestes um die Regeln einzuhalten. Bitte nicht böse sein falls etwas daneben gehen sollte. Schritt 0 CleanBrowser, MyMemory, OtherSearch, Social2Search => wurde von mir bereits "manuell" über Systemsteuerung->Programme deinstalliert. Da ich die selbst als "unerwünscht" betrachtet habe und die nicht zu meinen "Standard" Programmen zählen. Body Text Feathering kann ich nicht finden. Taucht auch nicht in Systemsteuerung->Programme auf. Schritt 1 Ohne Probleme. mbam Logfile Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 18.01.17 Scan-Zeit: 19:26 Protokolldatei: mbam.txt Administrator: Ja -Softwaredaten- Version: 3.0.5.1299 Komponentenversion: 1.0.43 Version des Aktualisierungspakets: 1.0.735 Lizenz: Kostenlos -Systemdaten- Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Alex-PC\Alex -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 400964 Abgelaufene Zeit: 5 Min., 7 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 9 PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [131], [170024],1.0.735 PUP.Optional.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, In Quarantäne, [131], [-1],0.0.0 PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [131], [170024],1.0.735 PUP.Optional.Wajam, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [131], [170024],1.0.735 PUP.Optional.Social2Search, HKLM\SOFTWARE\Socia2Sear Browser Enhancer, In Quarantäne, [445], [345866],1.0.735 PUP.Optional.OtherSearch, HKLM\SOFTWARE\WOW6432NODE\OTHERSEARCH, In Quarantäne, [709], [305744],1.0.735 PUP.Optional.ThunderMaster, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ThunderMaster, In Quarantäne, [17129], [244053],1.0.735 PUP.Optional.Wajam.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\5f997e823c149616faed2a7953b94672, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Social2Search, HKLM\SOFTWARE\WOW6432NODE\Socia2Sear Browser Enhancer, In Quarantäne, [445], [345866],1.0.735 Registrierungswert: 14 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|DhcpNameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{40DBAA5B-6CDD-40E5-AF69-3B7168DAF5A1}|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{6D01CE8B-7659-4887-9FF5-E8F77D6A492F}|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}|DhcpNameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}|NameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}|DhcpNameServer, Ersetzt, [46], [-1],0.0.0 PUP.Optional.Wajam, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [131], [-1],0.0.0 PUP.Optional.Wajam, HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [131], [-1],0.0.0 PUP.Optional.Wajam, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [131], [-1],0.0.0 PUP.Optional.OtherSearch, HKLM\SOFTWARE\WOW6432NODE\OTHERSEARCH|AFFID, In Quarantäne, [709], [305744],1.0.735 PUP.Optional.ProxyGate.PrxySvrRST, HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PROXYGATE, In Quarantäne, [14651], [184419],1.0.735 Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 5 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\b1fa982f-2e57-1, In Quarantäne, [46], [182288],1.0.735 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\b1fa982f-78d5-0, In Quarantäne, [46], [182288],1.0.735 PUP.Optional.NoteUp, C:\USERS\ALEX\APPDATA\ROAMING\NOTE-UP, In Quarantäne, [9224], [246759],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\607fae644efc4eb8a6e84fb4436fcd65, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\PROGRAM FILES\5f997e823c149616faed2a7953b94672, In Quarantäne, [17687], [259462],1.0.735 Datei: 11 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\b1fa982f-2e57-1\BIT4805.tmp, Löschen bei Neustart, [46], [182288],1.0.735 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\b1fa982f-78d5-0\BIT4815.tmp, Löschen bei Neustart, [46], [182288],1.0.735 PUP.Optional.NoteUp, C:\USERS\ALEX\APPDATA\ROAMING\NOTE-UP\NOTE-UP.DB, In Quarantäne, [9224], [246759],1.0.735 PUP.Optional.CleanBrowser, C:\WINDOWS\RUN.VBS, In Quarantäne, [1863], [335008],1.0.735 PUP.Optional.ThunderMaster, C:\WINDOWS\SYSTEM32\TASKS\THUNDERMASTER, In Quarantäne, [17129], [244052],1.0.735 PUP.Optional.Wajam.Gen, C:\PROGRAM FILES\5f997e823c149616faed2a7953b94672\607fae644efc4eb8a6e84fb4436fcd65\58037aa92dc42d27c1b47b96a7a3db46.ico, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\607fae644efc4eb8a6e84fb4436fcd65\601d5de35392c88eabe760eeb49f311a.ico, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\607fae644efc4eb8a6e84fb4436fcd65\94974881198d5a71148b8c9529d460d1.ico, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\4be4ee7ec1a7db4d36fdb985186936b5.exe, Löschen bei Neustart, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\58037aa92dc42d27c1b47b96a7a3db46.ico, In Quarantäne, [17687], [259462],1.0.735 PUP.Optional.Wajam.Gen, C:\Program Files\5f997e823c149616faed2a7953b94672\6a964bcddfa3b4c84bf591288ac3f19b, In Quarantäne, [17687], [259462],1.0.735 Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) Schritt 2 Avira überprüfte die .exe Datei von AdWCleaner danach kam ne Fehlermeldung das Quarantäne nicht installiert werden konnte. jedoch war das Programm installiert beim Start kam eine Fehlermeldung: konnte nicht ausgeführt werden. Habe Avira vorrübergehend deaktiviert dann AdWCleaner deinstalliert und wieder installiert. Nach diesem Schritt konnte ich AdWCleaner ausführen. Code:
ATTFilter # AdwCleaner v6.042 - Bericht erstellt am 18/01/2017 um 19:45:03 # Aktualisiert am 06/01/2017 von Malwarebytes # Datenbank : 2017-01-17.2 [Server] # Betriebssystem : Windows 7 Ultimate Service Pack 1 (X64) # Benutzername : Alex - ALEX-PC # Gestartet von : C:\Users\Alex\Desktop\Neuer Ordner (2)\AdwCleaner_6.042.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6 [-] Ordner gelöscht: C:\Users\Alex\AppData\Local\app ***** [ Dateien ] ***** [-] Datei gelöscht: C:\TOSTACK ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKU\S-1-5-21-844601699-3614358154-429673199-1000\Software\Installer [#] Schlüssel mit Neustart gelöscht: HKCU\Software\Installer [-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564 [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Installer [-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: "Prefetch" Dateien gelöscht :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [1711 Bytes] - [18/01/2017 19:45:03] C:\AdwCleaner\AdwCleaner[S0].txt - [1870 Bytes] - [18/01/2017 19:44:31] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1857 Bytes] ########## Schritt 3 Ohne Probleme. Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017 durchgeführt von Alex (Administrator) auf ALEX-PC (18-01-2017 19:48:06) Gestartet von C:\Users\Alex\Desktop\Neuer Ordner (2) Geladene Profile: Alex (Verfügbare Profile: Alex) Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Opera) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe (MSI) C:\Windows\SysWOW64\muachost.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe (SafeNet Inc.) C:\Windows\System32\hasplms.exe (VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Palit Microsystems Ltd.) C:\Program Files (x86)\Thunder Master\THPanel.exe (iAnywhere Solutions) C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (Hi-Rez Studios) H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Autodesk, Inc.) E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe (Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe (MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe (MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () C:\Windows\System32\PnkBstrA.exe () C:\Windows\SysWOW64\spdsvc.exe () C:\Windows\SysWOW64\SecUPDUtilSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE () C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8801024 2016-04-22] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15112312 2016-02-09] (Logitech Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] () HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes) HKLM-x32\...\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-11-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] () HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1015808 2016-05-19] (MSI) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26287016 2017-01-06] (Dropbox, Inc.) HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MSI) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [THPanel] => C:\Program Files (x86)\Thunder Master\THPanel.exe [2197472 2015-07-22] (Palit Microsystems Ltd.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [4644184 2015-06-10] (Disc Soft Ltd) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Policies\Explorer: [] HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {2a7e694d-afe4-11e5-881f-806e6f6e6963} - F:\DVDSetup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} - R:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} - G:\startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} - M:\Startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {b7167805-aff4-11e5-89b3-d8cb8a9bbec6} - Q:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {dddedf48-3336-11e6-9221-d8cb8a9bbec6} - D:\setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {fd345007-2950-11e6-980e-d8cb8a9bbec6} - Y:\Setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283112 2016-02-02] (Autodesk, Inc.) HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2016-02-07] (Autodesk, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Blue Manager Suite.lnk [2016-01-16] ShortcutTarget: Blue Manager Suite.lnk -> C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (iAnywhere Solutions) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-06-08] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\Parameters: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{40DBAA5B-6CDD-40E5-AF69-3B7168DAF5A1}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{6D01CE8B-7659-4887-9FF5-E8F77D6A492F}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [DhcpNameServer] 8.8.8.8 Internet Explorer: ================== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-844601699-3614358154-429673199-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-10-11] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default [2017-01-13] FF Homepage: Mozilla\Firefox\Profiles\qiF99tHm.default -> hxxps://www.google.de FF Session Restore: Mozilla\Firefox\Profiles\qiF99tHm.default -> ist aktiviert. FF Extension: (Avira Browser Safety) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\abs@avira.com.xpi [2016-11-27] FF Extension: (Firefox Hotfix) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-03] FF Extension: (MEGA) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox@mega.co.nz.xpi [2017-01-12] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-13] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-18] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @lattice3d.com/XVL Player -> C:\Program Files\Lattice\Player3_x86\npxvlplay.dll [2015-02-23] (Lattice Technology Co.,Ltd.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-01-12] CHR Extension: (Google Präsentationen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-14] CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-14] CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-14] CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-14] CHR Extension: (Adobe Acrobat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-12] CHR Extension: (Google Tabellen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-14] CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-12-14] CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-14] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-14] CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-14] CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-14] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-10-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk Inc.) S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-14] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-12] () S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51504 2017-01-06] (Dropbox, Inc.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [392168 2016-08-31] (Digital Wave Ltd.) R3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1345368 2015-06-10] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [249104 2016-11-11] (EasyAntiCheat Ltd) R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.) R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.) R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-01] (SafeNet Inc.) U2 HiPatchService; H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-01-28] (Rivet Networks) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2016-02-09] (Logitech Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes) R2 mitsijm2017; E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe [967456 2015-08-04] (Autodesk, Inc.) S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MSI) S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2204768 2016-09-29] (MSI) S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4162656 2016-09-29] (MSI) R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2015328 2016-09-29] (MSI) R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2327648 2016-09-29] (MSI) S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-09-29] (MSI) S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [607160 2016-09-29] (MSI) R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2248144 2016-04-28] (Micro-Star INT'L CO., LTD.) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation) S4 Origin Client Service; C:\Users\Alex\Origin\OriginClientService.exe [2119688 2016-12-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Users\Alex\Origin\OriginWebHelperService.exe [2180624 2016-12-24] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-01-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-01-02] () S4 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc) R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-05-01] () R2 SamsungUPDUtilSvc; C:\Windows\SysWOW64\SecUPDUtilSvc.exe [143664 2016-06-06] () S4 SanDisk SSD Dashboard Service; C:\Program Files (x86)\SanDisk\SSD Dashboard\SanDiskSSDDashboardService.exe [373760 2016-06-24] (SanDisk) [Datei ist nicht signiert] S3 Survarium-Steam Update Service; H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-11-14] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-12-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-05-11] (Avira Operations GmbH & Co. KG) S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-01-24] (Rivet Networks, LLC.) S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT Corporation.) S3 btiaa2dp; C:\Windows\System32\drivers\btiaa2dp.sys [82944 2008-09-16] (iAnywhere Solutions) S3 BTiAPan; C:\Windows\System32\DRIVERS\btiapan.sys [37888 2008-09-16] (iAnywhere Solutions) S3 btiarcp; C:\Windows\System32\DRIVERS\btiarcp.sys [10880 2008-07-30] (iAnywhere Solutions) S3 btiaspp; C:\Windows\System32\DRIVERS\btiaspp.sys [92160 2008-09-16] (iAnywhere Solutions) S3 BTIAUSB; C:\Windows\System32\DRIVERS\btiausb.sys [31744 2008-11-14] (iAnywhere Solutions) S3 BTPROT; C:\Windows\System32\DRIVERS\btprot.sys [517632 2008-11-14] (iAnywhere Solutions) R0 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation) R0 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation) R0 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-31] (Disc Soft Ltd) S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-31] (Disc Soft Ltd) R0 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2016-03-15] (Disc Soft Ltd) R3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47160 2016-03-15] (Disc Soft Ltd) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc) R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-01] (SafeNet Inc.) R3 I2cHkBurn; C:\Windows\System32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.) S3 iAnywhere_btAudio; C:\Windows\System32\drivers\btiasco.sys [25088 2008-07-30] (iAnywhere Solutions) S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.) S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [125488 2015-03-18] (Qualcomm Atheros, Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [250816 2017-01-18] (Malwarebytes) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2016-07-30] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Datei ist nicht signiert] R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [106760 2015-10-14] (WIBU-SYSTEMS AG) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) S3 ALSysIO; \??\C:\Users\Alex\AppData\Local\Temp\ALSysIO64.sys [X] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 BTCOM; system32\DRIVERS\btcomport.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 cpuz137; \??\C:\Users\Alex\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X] S3 cpuz138; \??\C:\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] S3 xspirit; \??\C:\Windows\xspirit.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 19:43 - 2017-01-18 19:45 - 00000000 ____D C:\AdwCleaner 2017-01-18 19:34 - 2017-01-18 19:34 - 00000000 ___HD C:\OneDriveTemp 2017-01-18 19:24 - 2017-01-18 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-01-18 19:24 - 2017-01-18 19:24 - 00000000 ____D C:\Program Files\Malwarebytes 2017-01-18 19:24 - 2016-12-14 12:55 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-01-18 19:14 - 2017-01-18 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2017-01-18 19:14 - 2017-01-18 19:14 - 00000000 ____D C:\Program Files\VS Revo Group 2017-01-18 17:23 - 2017-01-18 19:48 - 00000000 ____D C:\Users\Alex\Desktop\Neuer Ordner (2) 2017-01-18 16:48 - 2017-01-18 16:49 - 00000000 ____D C:\Users\Alex\Documents\Neuer Ordner (2) 2017-01-18 16:33 - 2017-01-18 16:33 - 00117675 _____ C:\Users\Alex\Desktop\Addition.txt 2017-01-18 16:32 - 2017-01-18 19:48 - 00000000 ____D C:\FRST 2017-01-18 16:32 - 2017-01-18 16:33 - 00056210 _____ C:\Users\Alex\Desktop\FRST.txt 2017-01-18 15:57 - 2017-01-18 16:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-01-18 15:55 - 2017-01-18 16:12 - 00000000 ____D C:\Users\Alex\Desktop\mbar 2017-01-18 15:48 - 2017-01-18 15:48 - 00000000 ____D C:\Users\Alex\Desktop\backups 2017-01-18 15:34 - 2017-01-18 15:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alex\Desktop\HijackThis_2.0.5.exe 2017-01-18 11:07 - 2017-01-18 19:34 - 00000318 ____H C:\Windows\Tasks\MSIOSDx86_Host.job 2017-01-18 11:07 - 2017-01-18 19:34 - 00000318 ____H C:\Windows\Tasks\MSIOSDx64_Host.job 2017-01-18 11:07 - 2017-01-18 19:34 - 00000252 ____H C:\Windows\Tasks\MSISW_Host.job 2017-01-18 10:54 - 2017-01-18 10:55 - 00000000 ____D C:\Windows\system32\SSL 2017-01-18 10:07 - 2017-01-18 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-01-18 10:06 - 2017-01-18 10:07 - 00000000 ____D C:\Users\Alex\AppData\Roaming\DVDVideoSoft 2017-01-18 10:04 - 2017-01-18 10:05 - 00000000 ____D C:\Users\Alex\Documents\psynetic-gifx 2017-01-18 10:04 - 2017-01-18 10:04 - 00000000 ____D C:\Users\Alex\AppData\Local\psynetic-imageconverter 2017-01-18 10:03 - 2017-01-18 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\psynetic 2017-01-13 12:28 - 2017-01-13 12:28 - 00000000 ____D C:\Users\Alex\Desktop\CINEBENCHR15.03 2017-01-12 22:36 - 2017-01-12 22:50 - 00000028 _____ C:\Users\Alex\Desktop\Neues Textdokument.txt 2017-01-12 08:37 - 2017-01-12 08:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-01-09 16:16 - 2017-01-09 16:22 - 04407342 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V4.0 inkl. Mittelabflußplan.xlsx 2017-01-08 20:53 - 2017-01-08 20:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-01-08 20:53 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-01-08 20:53 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-01-08 20:53 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe 2017-01-08 20:50 - 2016-12-12 03:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-01-08 20:50 - 2016-12-12 03:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-01-06 01:04 - 2017-01-06 01:04 - 00051504 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-01-04 00:21 - 2017-01-04 00:22 - 00000000 ____D C:\Program Files (x86)\OBS 2017-01-04 00:21 - 2017-01-04 00:21 - 00000935 _____ C:\Users\Alex\Desktop\Open Broadcaster Software.lnk 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Program Files\OBS 2017-01-03 12:12 - 2017-01-12 22:40 - 00000000 ____D C:\Users\Alex\Desktop\Gifs 2017-01-02 15:07 - 2017-01-02 15:07 - 00000000 ____D C:\Crash 2017-01-01 23:15 - 2017-01-02 15:06 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Daybreak Game Company 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\SCE 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\Daybreak Game Company 2016-12-26 19:26 - 2016-12-26 19:26 - 00000000 ____D C:\Users\Alex\AppData\Local\TechSmith 2016-12-26 19:02 - 2017-01-18 19:46 - 00002938 _____ C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 19:45 - 00005110 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2016-12-26 19:02 - 2016-12-26 19:02 - 00004236 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-12-26 19:02 - 2016-12-12 15:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2016-12-25 17:44 - 2016-12-25 17:44 - 00000000 ____D C:\Users\Alex\AppData\Local\4A Games 2016-12-22 20:53 - 2016-12-22 20:53 - 00000000 ____D C:\Users\Alex\AppData\Local\HirezLauncherUI 2016-12-22 20:52 - 2016-12-22 21:01 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2016-12-22 20:52 - 2016-12-22 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios 2016-12-22 17:26 - 2016-12-22 17:26 - 00788918 _____ C:\Users\Alex\Desktop\Nachtragsmanagement_MB.pdf 2016-12-22 17:26 - 2016-12-22 17:26 - 00317552 _____ C:\Users\Alex\Desktop\1.Verfahrensbeschreibungen (1).pdf 2016-12-22 14:13 - 2016-12-22 14:13 - 04464334 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V1 für Ausbau.xlsx 2016-12-21 14:05 - 2016-12-22 14:45 - 00000000 ____D C:\Users\Alex\Desktop\Mittelabflußplan 2016-12-21 07:52 - 2016-12-21 07:52 - 00018407 _____ C:\Users\Alex\AppData\Local\recently-used.xbel 2016-12-20 17:02 - 2016-12-20 17:03 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TeamViewer 2016-12-20 17:02 - 2016-12-20 17:02 - 12971088 _____ (TeamViewer GmbH) C:\Users\Alex\Desktop\TeamViewer_Setup_de.exe 2016-12-20 12:07 - 2017-01-18 19:46 - 00003018 _____ C:\Windows\System32\Tasks\MSIAfterburner ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 19:48 - 2015-12-31 19:02 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-18 19:46 - 2016-11-23 10:04 - 00003490 _____ C:\Windows\System32\Tasks\AutoKMS 2017-01-18 19:46 - 2016-07-21 15:36 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-18 19:46 - 2016-03-25 12:05 - 00000000 ___RD C:\Users\Alex\Dropbox 2017-01-18 19:46 - 2016-01-06 21:03 - 00000000 ___RD C:\Users\Alex\OneDrive 2017-01-18 19:45 - 2016-03-25 11:59 - 00001206 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-01-18 19:45 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-18 19:45 - 2008-05-09 16:08 - 00001891 _____ C:\Users\Alex\AppData\Local\bmarchive.bms 2017-01-18 19:41 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-18 19:41 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-18 19:34 - 2016-01-05 13:46 - 00000000 ____D C:\Users\Alex\AppData\Local\CrashDumps 2017-01-18 19:34 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-01-18 19:24 - 2016-07-21 15:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-01-18 16:27 - 2016-01-05 19:15 - 00000000 ____D C:\Users\Alex\Documents\Outlook-Dateien 2017-01-18 16:24 - 2016-07-21 15:35 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-01-18 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2017-01-18 11:19 - 2016-12-14 15:41 - 00002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-18 11:07 - 2016-02-21 22:19 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-01-18 10:56 - 2016-05-21 18:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-18 10:55 - 2016-11-23 12:46 - 00000000 ____D C:\Users\Public\Documents\AdobeGC 2017-01-18 10:46 - 2016-11-23 11:43 - 00000000 ____D C:\Users\Alex\Documents\Camtasia Studio 2017-01-18 10:45 - 2016-03-25 11:59 - 00001210 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-01-18 10:17 - 2016-10-14 10:13 - 00719098 _____ C:\Windows\system32\perfh019.dat 2017-01-18 10:17 - 2016-10-14 10:13 - 00151344 _____ C:\Windows\system32\perfc019.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00702730 _____ C:\Windows\system32\perfh007.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00150314 _____ C:\Windows\system32\perfc007.dat 2017-01-18 10:17 - 2009-07-14 06:13 - 02498584 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-18 10:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-01-18 10:07 - 2016-11-20 19:00 - 00000000 ____D C:\Users\Alex\.gimp-2.8 2017-01-18 09:59 - 2016-02-21 22:17 - 00000000 ____D C:\Users\Alex\AppData\Local\Adobe 2017-01-18 09:56 - 2016-05-21 18:00 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-18 09:56 - 2016-02-21 22:19 - 00003936 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-01-18 09:56 - 2016-01-04 20:38 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-18 09:56 - 2016-01-04 20:38 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-13 12:30 - 2016-02-18 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2017-01-13 12:29 - 2016-01-04 12:16 - 00000000 ____D C:\Users\Alex\AppData\Roaming\MAXON 2017-01-13 12:18 - 2016-12-01 19:09 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mozilla 2017-01-13 03:57 - 2016-01-05 20:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client 2017-01-12 18:36 - 2016-11-27 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-01-12 08:37 - 2016-02-20 15:08 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-01-11 21:10 - 2016-03-07 20:07 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-01-11 21:09 - 2016-03-07 20:07 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-01-10 16:14 - 2016-07-29 13:57 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS 2017-01-08 20:54 - 2016-11-15 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-01-08 20:54 - 2016-03-18 15:26 - 00000000 ____D C:\Temp 2017-01-08 20:54 - 2015-12-31 19:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-01-04 13:34 - 2016-01-04 14:47 - 00000000 ___RD C:\Users\Alex\Desktop\Games 2017-01-04 12:19 - 2015-12-31 16:47 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-01-01 23:09 - 2016-01-01 16:51 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Origin 2017-01-01 23:09 - 2016-01-01 16:46 - 00000000 ____D C:\ProgramData\Origin 2016-12-29 10:30 - 2016-01-04 14:50 - 00000000 ___RD C:\Users\Alex\Desktop\MSI 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\Program Files\Core Temp 2016-12-27 16:51 - 2016-11-14 17:01 - 00000000 ____D C:\Users\Alex\Documents\Survarium-Steam 2016-12-26 19:02 - 2016-11-15 14:23 - 00003832 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003820 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003644 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003584 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2015-12-31 19:03 - 00000000 ____D C:\Users\Alex\AppData\Local\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 19:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 18:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-25 17:46 - 2016-12-07 09:16 - 00000000 ____D C:\Users\Alex\Documents\4A Games 2016-12-24 12:47 - 2016-07-02 20:29 - 00000000 ____D C:\Users\Alex\Origin 2016-12-24 12:41 - 2016-11-30 16:24 - 00000000 ____D C:\Users\Public\Documents\.forever 2016-12-24 12:34 - 2016-01-04 14:30 - 00000000 ____D C:\Users\Alex\Desktop\SBOT 2016-12-22 21:00 - 2015-12-31 14:23 - 00000000 ____D C:\Users\Alex\Documents\My Games 2016-12-22 20:52 - 2015-12-31 19:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-12-22 15:37 - 2015-12-31 20:42 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1451590946 2016-12-22 15:37 - 2015-12-31 20:41 - 00000000 ____D C:\Program Files (x86)\Opera 2016-12-20 16:50 - 2016-07-18 14:59 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype 2016-12-20 16:43 - 2016-07-18 16:25 - 00000384 ___RH C:\Windows\sosyambaess.lock 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ____D C:\ProgramData\Skype ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 14:46 - 2016-02-06 14:54 - 0000104 _____ () C:\Users\Alex\AppData\Roaming\mBot.ini 2008-05-09 16:08 - 2017-01-18 19:45 - 0001891 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms 2008-05-09 16:08 - 2016-02-20 19:23 - 0000000 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms~RF1a66bd5.TMP 2016-12-21 07:52 - 2016-12-21 07:52 - 0018407 _____ () C:\Users\Alex\AppData\Local\recently-used.xbel 2015-12-31 18:57 - 2016-01-05 15:11 - 0007605 _____ () C:\Users\Alex\AppData\Local\resmon.resmoncfg 2016-05-13 21:20 - 2016-05-13 21:20 - 0000000 _____ () C:\Users\Alex\AppData\Local\{AF97A572-54D0-441A-A283-15CC4BC2A136} 2016-01-04 16:28 - 2016-01-04 16:28 - 0000016 _____ () C:\ProgramData\mntemp 2016-12-26 19:02 - 2017-01-18 19:46 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 19:45 - 0005110 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-03 12:51 ==================== Ende von FRST.txt ============================ Addition log kommt mit dem nächsten Post. |
18.01.2017, 20:08 | #5 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Addition Log Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017 durchgeführt von Alex (18-01-2017 19:48:27) Gestartet von C:\Users\Alex\Desktop\Neuer Ordner (2) Windows 7 Ultimate Service Pack 1 (X64) (2015-12-31 17:53:35) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844601699-3614358154-429673199-500 - Administrator - Disabled) Alex (S-1-5-21-844601699-3614358154-429673199-1000 - Administrator - Enabled) => C:\Users\Alex Gast (S-1-5-21-844601699-3614358154-429673199-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-844601699-3614358154-429673199-1005 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) A360 Desktop (HKLM\...\{7758802D-9486-4883-9927-CCAC366A3BA4}) (Version: 7.2.3.1800 - Autodesk) ACA & MEP 2017 Object Enabler (Version: 7.9.45.0 - Autodesk) Hidden ACAD Private (Version: 21.0.52.0 - Autodesk) Hidden Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.1.335 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\{C1F3739C-D31D-4062-8788-29261C4A2A68}) (Version: 12.2.4.194 - Adobe Systems, Inc) Age of Mythology: Extended Edition (HKLM\...\Steam App 266840) (Version: - SkyBox Labs) AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.) Ansel (Version: 376.33 - NVIDIA Corporation) Hidden Aperture Tag: The Paint Gun Testing Initiative (HKLM\...\Steam App 280740) (Version: - Aperture Tag Team) AutoCAD 2017 - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 Language Pack - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden Autodesk Advanced Material Library Image Library 2017 (HKLM-x32\...\{8ED2ED41-4455-449D-993C-751C039089B9}) (Version: 15.11.3.0 - Autodesk) Autodesk AutoCAD 2017 - Deutsch (German) (HKLM\...\AutoCAD 2017 - Deutsch (German)) (Version: 21.0.52.0 - Autodesk) Autodesk AutoCAD Performance Feedback Tool 1.2.5 (HKLM-x32\...\{8600F844-9AA5-412E-B6F2-F9C6CBCFD268}) (Version: 1.2.5.0 - Autodesk) Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk) Autodesk Configurator 360 addin (HKLM-x32\...\{E3EE083F-6856-44AB-BC82-445E2FFB8C1A}) (Version: 21.0.11700 - Autodesk) Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk Desktop Connect Service (HKLM\...\{FC772454-BB19-0000-0330-44B459520227}) (Version: 3.30.0 - Autodesk) Autodesk Desktop-App (HKLM-x32\...\Autodesk Desktop App) (Version: 6.2.0.174 - Autodesk) Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.52.0 - Autodesk) Autodesk Guided Tutorial Plugin (HKLM\...\{B3AFC608-D811-0003-0330-21FB25B48D6E}) (Version: 3.30.0 - Autodesk) Autodesk Inventor Content Center Libraries 2017 (Desktop Content) (HKLM\...\{B46DECD1-2164-4EF1-0000-22D71E81877C}) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German)) (Version: 14.0.57.0 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Electrical Catalog Browser 2017 Language Pack - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Professional 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Professional 2017) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Professional 2017 (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk Inventor Professional 2017 Language Pack - Deutsch (German) (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk) Autodesk Material Library 2017 (HKLM-x32\...\{8FB9F735-D64C-4991-8D91-4CDDAB1ABDEE}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Base Resolution Image Library 2017 (HKLM-x32\...\{3FBFBC43-9882-43FA-B979-2D53896747B3}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Low Resolution Image Library 2017 (HKLM-x32\...\{360AC116-6CD4-4E7D-8174-28D47B05E898}) (Version: 15.11.3.0 - Autodesk) Autodesk ReCap 360 (HKLM\...\Autodesk ReCap 360) (Version: 3.0.0.52 - Autodesk) Autodesk ReCap 360 (Version: 3.0.0.52 - Autodesk) Hidden Autodesk Revit Interoperability for Inventor 2017 (HKLM\...\Autodesk Revit Interoperability for Inventor 2017) (Version: 17.0.411.0 - Autodesk) Autodesk Revit Interoperability for Inventor 2017 (Version: 17.0.411.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) (HKLM\...\Autodesk Vault Basic 2017 (Client)) (Version: 22.0.48.0 - Autodesk) Autodesk Vault Basic 2017 (Client) (Version: 22.0.48.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) German Language Pack (Version: 22.0.48.0 - Autodesk) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG) Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG) Avira Connect (HKLM-x32\...\{707e8edf-9482-4417-ae39-c9b5fe605e87}) (Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Avira Connect (x32 Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Hidden Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - ) Blue Manager Suite (HKLM-x32\...\InstallShield_{28B0F39B-C0C6-4CC5-902B-9BF20111804C}) (Version: - ) Blue Manager Suite (Version: 3.3.0 - iAnywhere Solutions) Hidden Call of Duty Modern Warfare Remastered MULTi2 1.0 (HKLM-x32\...\Call of Duty Modern Warfare Remastered MULTi2 1.0) (Version: - ) Camtasia 9 (HKLM-x32\...\{b7d38e69-9571-4bb3-98c0-4ec2dfae7acf}) (Version: 9.0.0.1306 - TechSmith Corporation) Camtasia 9 (Version: 9.0.0.1306 - TechSmith Corporation) Hidden CDTS17_Setup_x64 (Version: 17.4 - Corel Corporation) Hidden Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Contagion (HKLM\...\Steam App 238430) (Version: - Monochrome, Inc) Corel Graphics - Windows Shell Extension (HKLM\...\_{9DA7C2FD-AD83-4E2E-B9F2-9996749318E0}) (Version: 17.4.0.887 - Corel Corporation) Corel Graphics - Windows Shell Extension (Version: 17.4.887 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.4.887 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Capture (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common App (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Connect (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Custom Data (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - DE (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Designer (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Draw (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - EN (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Equation Editor (x32 Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Filters (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FontNav (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FR (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM Content (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM T (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM XVL (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - PHOTO-PAINT (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Photozoom Plugin (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Redist (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Setup Files (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VBA (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VideoBrowser (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Writing Tools (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 (64-Bit) (HKLM\...\_{A4B5A413-B7CF-415F-8994-595DB2EFE848}) (Version: 17.4.0.887 - Corel Corporation) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Crysis WARHEAD(R) (x32 Version: 1.0 - Crytek) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Ultra (HKLM\...\DAEMON Tools Ultra) (Version: 3.1.0.0368 - Disc Soft Ltd) Dropbox (HKLM-x32\...\Dropbox) (Version: 17.4.33 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden DWG TrueView 2017 - English (Version: 21.0.52.0 - Autodesk) Hidden Eco Materials Adviser for Autodesk Inventor 2017 (64-bit) (HKLM\...\{05D87862-35C9-4CB4-92EC-8A1FC97BFF6C}) (Version: 6.4.9.0 - Granta Design Limited) Elegant-Treiber Paket (HKLM-x32\...\Samsung Stylish UI Pack) (Version: 1.01.74.00 (09.02.2015) - Samsung Electronics Co., Ltd.) Euro Truck Simulator 2 Demo (HKLM\...\Steam App 231120) (Version: - SCS Software) FARO LS 1.1.505.0 (64bit) (HKLM-x32\...\{8834451B-6209-4E02-9EF4-4EF9E3C1F70F}) (Version: 5.5.0.44203 - FARO Scanner Production) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company) Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14 (HKLM-x32\...\Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14) (Version: - ) Half-Life: A Place in the West (HKLM\...\Steam App 466270) (Version: - Michael Pelletier) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation) Inventor Connected Desktop for A360 (HKLM\...\{1FA52755-1FBC-0001-0330-7CEA1F3736D8}) (Version: 3.30.0 - Autodesk) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer E220x Drivers (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.57.1125 - Rivet Networks) Lattice3D Player / Lattice3D Player Pro (Ver. 9 oder höher) 64-bit Edition (HKLM-x32\...\{936575FE-E49B-4CE9-9934-0329727476C8}) (Version: 14.0c - Lattice Technology) Lattice3D Studio Corel Edition x64 (HKLM-x32\...\{A7161767-5AFE-4725-9DB0-AED7FB5FBA40}) (Version: 2.0 - Lattice Technology) Logitech Gaming Software 8.79 (HKLM\...\Logitech Gaming Software) (Version: 8.79.77 - Logitech Inc.) Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes) mb WorkSuite 2016 (HKLM\...\{1C1D8E70-B1C8-4ACE-ADAB-B37F271E71FC}) (Version: 20.16.010.0 - mb AEC Software GmbH) Metro 2033 Redux (HKLM\...\Steam App 286690) (Version: - 4A GAMES) Metro: Last Light Redux (HKLM\...\Steam App 287390) (Version: - 4A Games) Microsoft .NET Framework 4.6 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Hotfix Rollup (KB3154529) (HKLM\...\{5B71B4F6-A412-3C48-B332-0FA9B9958940}) (Version: 4.6.01081 - Microsoft Corporation) Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation) Middle-earth: Shadow of Mordor (HKLM\...\Steam App 241930) (Version: - Monolith Productions, Inc.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla) MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Need for Speed™ (HKLM-x32\...\{F8643E83-A868-4EE8-A0B9-389386830453}) (Version: 1.3.0.0 - Electronic Arts) NVIDIA 3D Vision Treiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.33 - NVIDIA Corporation) NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Stable 42.0.2393.94 (HKLM-x32\...\Opera 42.0.2393.94) (Version: 42.0.2393.94 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden Portal 2 (HKLM\...\Steam App 620) (Version: - Valve) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7634 - Realtek Semiconductor Corp.) Revo Uninstaller 2.0.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.2 - VS Revo Group, Ltd.) RivaTuner Statistics Server 6.4.1 (HKLM-x32\...\RTSS) (Version: 6.4.1 - Unwinder) Rocketbirds: Hardboiled Chicken (HKLM\...\Steam App 215510) (Version: - Ratloop Asia) Runtime VS2005 SP1 CRT 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 MFC 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 All 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 CRT 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 OpenMP 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2008 x64 CRT 1 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime_MSI_VS2005_SP1_CRT_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFC_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFCLOC_6195 (x32 Version: 1.00.0000 - Lattice Technology) Hidden Runtime_MSI_VS2005_SP1_x64_CRT_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFC_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFCLOC_6195 (Version: 1.00.0000 - Lattice Technology) Hidden Saints Row IV (HKLM\...\Steam App 206420) (Version: - Deep Silver Volition) Samsung Drucker-Diagnose (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7 - Samsung Electronics Co., Ltd.) Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 2.01.05 (11.02.2015) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.0.0.65 - Samsung Electronics Co., Ltd.) Samsung Printer Center (HKLM-x32\...\Samsung Printer Center) (Version: 1.0.0.21 - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (x32 Version: 1.03.05.19 - Samsung Electronics Co., Ltd.) Hidden Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 3.31.79:03 - Samsung Electronics Co., Ltd.) SanDisk SSD Dashboard (HKLM-x32\...\SanDisk SSD Dashboard) (Version: 1.4.3 - Western Digital Corporation or its affiliates) SanDisk SSD Dashboard Service (HKLM-x32\...\{760A9A9B-238A-4EC2-ABFD-88F340D676BC}) (Version: 1.0.2 - SanDisk Corporation) SetIP (HKLM-x32\...\SetIP) (Version: 1.05.08.00 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden SketchUp-Import 2016-2017 (HKLM-x32\...\{063925DB-9D8C-48E2-8F04-1B7038B6C783}) (Version: 2.2.0 - Autodesk) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) SNS Upload for Easy Document Creator (HKLM-x32\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd) Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.16.7.201605041511 - Sony Mobile Communications Inc.) Sound Blaster Cinema 2 (HKLM-x32\...\{B4F6F8CC-2C61-42CC-A4CC-76621F25BDC7}) (Version: 1.00.07 - Creative Technology Limited) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survarium (HKLM\...\Steam App 355840) (Version: - Vostok Games) TeamSpeak 3 Client (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Crew (Worldwide) (HKLM-x32\...\Uplay Install 413) (Version: - Ubisoft) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft) Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.8 - Samsung Electronics CO., LTD.) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{5D2260D6-DB16-41DC-915B-A39BF4F66362}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 23.0 - Ubisoft) Verfügbare Autodesk-Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WibuKey Setup (WibuKey Remove) (HKLM\...\{00060000-0000-1004-8002-0000C06B5161}) (Version: Version 6.30b of 2014-Oct-29 (Build 1471) (Setup) - WIBU-SYSTEMS AG) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.30 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) Wireless Password Recovery (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\WIFIPR) (Version: - Passcape) Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> E:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{32CDFF57-8CBA-4960-89B1-EC3FA58FB17A}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxTest.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtCp.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\Inventor.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxApprenticeServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\AcInetUI.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxInventorUtilities.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> E:\Program Files\Autodesk\AutoCAD 2017\de-DE\acadficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvResc.dll (Autodesk) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvTXTStack.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => Keine Datei ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02905C77-3498-4D2F-A56F-E3B47EA4C231} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG) Task: {05E915CC-B891-4A8E-AC29-7C952B785C22} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {0659C071-3026-4CA7-90E9-E65DEC87340D} - System32\Tasks\Opera scheduled Autoupdate 1451590946 => C:\Program Files (x86)\Opera\launcher.exe [2016-12-19] (Opera Software) Task: {0F516764-DEAF-400C-8691-DEE4AEC47730} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {24A13EA0-EBC9-427A-B8F0-D0D5D4F55AA7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} - \ThunderMaster -> Keine Datei <==== ACHTUNG Task: {325AD40C-6C77-4CA5-8EFC-C31A99DA86FB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {35651DCE-DF69-49D6-9E0D-6A040F15E01B} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) Task: {43C7A03F-A873-4A39-8510-7824CE650051} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation) Task: {45255647-EFA0-4FCC-8C71-796086CBF11E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {5CCB9225-F2A7-4EE5-8D55-110FA6DD613B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {638082EF-0C1B-4166-BC60-675738B3412F} - System32\Tasks\AdobeAAMUpdater-1.0-Alex-PC-Alex => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {6866B6C9-A5AD-4D44-A6F8-41F6280510D4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe [2017-01-18] (Adobe Systems Incorporated) Task: {6CA7FD92-E9A3-48DC-99D8-12238875FD2B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {726DEEC1-0C13-4293-BE34-834EDD3F5B7F} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI) Task: {80C2ECA6-96DD-4CBC-82F2-F64315C630DE} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-12-13] (NVIDIA Corporation) Task: {821636C8-9030-4062-80E1-563635D59776} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {9F897098-581F-457B-8254-8C2B94EC77BE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation) Task: {A3F6DB31-0FDA-48CA-A31D-A28855F66463} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {C7D487D6-F163-4179-B9BF-E64EB67DB5EA} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {CA7DAD2B-48E7-4F0B-BF32-A756013D4756} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-07-07] () Task: {D594DE41-D2B2-4D16-80F2-D58F777EBD9A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-18] (Adobe Systems Incorporated) Task: {E09DBBF5-33F2-41F7-8369-159B25B179B0} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {E1E08BC0-43A6-4589-A2DA-ED510EB3F1F1} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [2015-03-08] () Task: {E7FB3A92-28F8-448D-86BE-9077650866C1} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {EEAD75BF-FF30-4042-B12F-9574A609F54E} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-12-09] () Task: {FEBF9113-7489-4FC8-9DAC-E1372556C3CD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\MSIOSDx64_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe Task: C:\Windows\Tasks\MSIOSDx86_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe Task: C:\Windows\Tasks\MSISW_Host.job => C:\Windows\SysWOW64\muachost.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\Alex\Desktop\Programme\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-05-11 12:56 - 2007-08-14 18:03 - 00022016 _____ () C:\Windows\System32\sst1cl6.dll 2016-03-13 16:46 - 2015-03-12 03:43 - 00022528 _____ () C:\Windows\System32\us003lm.dll 2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-12-17 18:55 - 2016-12-17 18:55 - 01678560 _____ () C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll 2016-06-22 18:05 - 2016-06-14 15:35 - 00187392 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\D3D11FontDraw.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-09-08 12:39 - 2014-09-08 12:39 - 00464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2014-09-08 12:38 - 2014-09-08 12:38 - 00051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-01-02 20:48 - 2016-01-02 20:48 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2016-06-06 18:47 - 2016-05-01 08:38 - 00498488 ____N () C:\Windows\SysWOW64\spdsvc.exe 2016-06-06 18:43 - 2016-06-06 18:43 - 00143664 ____N () C:\Windows\SysWOW64\SecUPDUtilSvc.exe 2016-11-15 14:22 - 2016-12-11 19:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-01-18 19:24 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2016-03-13 16:46 - 2015-09-10 20:31 - 01676592 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\us003du.dll 2015-03-08 14:54 - 2015-03-08 14:54 - 03409632 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe 2016-06-22 18:05 - 2016-06-14 15:35 - 00163328 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\D3D11FontDraw.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2016-12-17 18:54 - 2016-12-17 18:54 - 01244376 _____ () C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\ClientTelemetry.dll 2015-12-31 19:33 - 2014-02-21 11:20 - 00074240 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2015-12-31 19:33 - 2014-02-21 11:17 - 00274944 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2016-03-25 12:02 - 2016-12-08 02:00 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-01-12 08:37 - 2016-12-08 02:01 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-03-25 12:02 - 2016-12-08 02:04 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-03-25 12:02 - 2016-12-08 02:00 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-03-25 12:02 - 2016-12-08 02:01 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 01682768 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00021328 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00052032 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-01-12 08:37 - 2016-12-08 02:00 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-01-12 08:37 - 2016-12-08 02:04 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00381760 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00026464 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-08-06 21:06 - 2016-12-08 02:02 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd 2017-01-12 08:37 - 2017-01-06 01:03 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00023384 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00019792 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-03-25 12:02 - 2017-01-06 01:04 - 00022360 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00024400 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-01-12 08:37 - 2016-12-08 01:57 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-01-12 08:37 - 2017-01-06 01:03 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-01-12 08:37 - 2017-01-06 01:04 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-03-25 12:02 - 2016-12-08 02:01 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 01972536 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00020296 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd 2017-01-12 08:37 - 2016-12-08 02:08 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2017-01-12 08:37 - 2016-12-08 02:08 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-01-12 08:37 - 2017-01-06 01:04 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-03-25 12:02 - 2016-12-08 02:04 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-08-06 21:06 - 2017-01-06 01:04 - 00024920 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-01-12 08:37 - 2017-01-06 01:04 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-06-06 18:50 - 2015-01-24 11:22 - 03029504 ____N () C:\Windows\system32\DlgSearchEngine.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2016-09-22 22:04 - 2016-09-22 22:04 - 05737472 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\EasyPrinterManagerV2\1c52e3141926a7b71183a774cf9e2e5d\EasyPrinterManagerV2.ni.exe 2016-09-23 10:03 - 2016-09-23 10:03 - 00854528 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceIOWrapper\cd08e2746ccf3e431000251c66aa95ad\DeviceIOWrapper.ni.dll 2015-03-08 14:52 - 2015-03-08 14:52 - 00494592 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\DeviceIOWrapper.dll 2015-01-05 13:12 - 2015-01-05 13:12 - 03650048 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\sf.dll 2015-01-05 13:12 - 2015-01-05 13:12 - 00300032 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\log4cplus.dll 2016-09-23 10:03 - 2016-09-23 10:03 - 00385536 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\NativeWrapper\c89bf4d352e3ed8d74c055bcc35879f7\NativeWrapper.ni.dll 2015-03-08 14:52 - 2015-03-08 14:52 - 00183808 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\NativeWrapper.dll 2015-02-19 10:59 - 2015-02-19 10:59 - 04286464 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\DevSearchDlg.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 68763736 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\opera.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 01893976 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\libglesv2.dll 2016-12-22 15:37 - 2016-12-22 15:37 - 00086616 _____ () C:\Program Files (x86)\Opera\42.0.2393.94\libegl.dll 2016-11-15 14:23 - 2016-12-12 15:36 - 00525760 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-11-15 14:23 - 2016-12-12 15:36 - 00254008 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-11-15 14:23 - 2016-12-12 15:36 - 02808888 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-11-15 14:23 - 2016-12-12 15:36 - 00384568 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-11-15 14:23 - 2016-12-12 15:36 - 00447424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node 2016-11-15 14:23 - 2016-12-12 15:36 - 00336832 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-11-15 14:23 - 2016-12-12 15:36 - 01003456 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node 2016-12-26 19:02 - 2016-12-12 15:36 - 00956472 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0816.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0817.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0818.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\FHBC_2016-01-12_TEAM-3B_Fasel_Gebäudeklimatik_3_alex.pptx:com.dropbox.attributes [183] AlternateDataStreams: C:\Users\Alex\Desktop\Fräsdateien:com.dropbox.attributes [168] AlternateDataStreams: C:\Users\Alex\Desktop\WLC_Team3B.xlsx:com.dropbox.attributes [168] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Software\Classes\.scr: DWGTrueViewScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2017-01-18 15:38 - 00001188 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\Services: AdAppMgrSvc => 2 MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: dbupdate => 2 MSCONFIG\Services: dbupdatem => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: MSI_LiveUpdate_Service => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: PSI_SVC_2_x64 => 2 MSCONFIG\Services: SanDisk SSD Dashboard Service => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: Sony PC Companion => 3 MSCONFIG\startupreg: ABNotify => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe -auto MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe MSCONFIG\startupreg: DAEMON Tools Lite Automount => "D:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: GammingApp => C:\Program Files (x86)\MSI\Gaming APP\SGamingApp.exe --min MSCONFIG\startupreg: Live Update => C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER MSCONFIG\startupreg: OneDrive => "C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: PDFPrint => "C:\Program Files (x86)\PDF24\pdf24.exe" MSCONFIG\startupreg: RemoteMedia => C:\Program Files (x86)\MSI\Command Center\RemoteMedia.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Spotify => "C:\Users\Alex\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Alex\AppData\Roaming\Spotify\SpotifyWebHelper.exe" MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: Steam => "D:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE MSCONFIG\startupreg: VLC Updater => C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 10 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{4750EED5-6919-45A0-AF08-359CC0076FE6}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D96219C-8301-44E5-953D-283283E7ECE8}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2594068C-343F-45A0-B63B-A62BF7BE6109}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{17446144-B74A-4606-B23A-1C189C8DC88A}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{FC13B60E-B2CD-4613-B4D5-1561FF5C0117}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{8605CED7-70B5-4EF4-A5B2-FE2E89F161D1}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [TCP Query User{EA9176A5-185D-416E-B6F9-75DCC8263276}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{B0C355E0-BADE-488A-8AAA-C0889BBAC615}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [{2D4A4BF4-5136-4465-A5B1-062152156216}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{609FC04D-F38E-4F2E-BD1A-A25D97854517}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{0D496196-3EF6-4E0E-B2AD-B658519A69F7}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9EBCAD6C-18A2-4069-82E8-3B7CA430486E}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{3815C750-D7D9-4D61-951F-DFA54724F5D9}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [UDP Query User{B290F1E3-1B27-40E2-9498-000F83BE3E39}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [TCP Query User{FE4D4A70-D0EC-4213-9CFB-CF908E994DCE}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [UDP Query User{8925978B-51D2-4366-96DA-91CCCA86FFCA}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [TCP Query User{61F753EC-EAAC-42A8-824C-BDD987602F82}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [UDP Query User{E4300497-5118-417A-A3D3-2EB1F7298E46}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [TCP Query User{70CDEF17-711F-456B-98CB-A53300F01430}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [UDP Query User{0FD8297F-CAE6-43A0-BC94-09B833AFBCC4}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [TCP Query User{1EC8A469-10A6-491B-90FF-87A554085014}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{D813B25E-13FC-42EF-9812-CEA6D36F4D9F}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{F7F60636-E730-48B7-BBA8-45191CD3581E}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{917CBFED-C3AD-47EA-BF60-32ADE1F9F846}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5599EFEF-A071-4979-8997-AF2FE258BBD6}] => C:\Windows\system32\hasplms.exe FirewallRules: [TCP Query User{01BB30AF-E5D8-4C9A-BFBE-5F605C6130A7}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [UDP Query User{F31E0C4C-4214-4EA7-9EF7-6127DC71DEC1}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [{9560061A-74CB-425A-B62A-09CABB55046C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [{2B6D10B2-1FE5-4F03-B775-102CAF1CBE0C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [TCP Query User{53A8BFA1-4603-4BB8-BC56-0BC38253F567}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{5A93F2D2-FA0D-495A-8A32-B5006D66BEF4}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{49D98C3B-2A5E-4338-ABE0-F924B6BDD358}] => C:\Program Files (x86)\Samsung\Samsung Printer Center\SamsungPrinterCenter.exe FirewallRules: [{671F46D4-0D24-45E1-B61C-E64153E30CD5}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{14AFAADC-8385-47D0-8098-F0B336385812}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{998C9E6E-A42A-4D65-9B13-EF1DD03CFE85}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe FirewallRules: [{9FD2B1E5-2012-4AEE-93BD-4E8F8180603C}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{6F266D86-6B83-410D-80D5-7CDCF27031BE}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe FirewallRules: [{238B1E07-AF59-40FE-94F1-B424B7242E94}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe FirewallRules: [{C300BE33-DBA4-4C93-B64D-613DDB869137}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{8E98299E-9580-43C8-975C-6192C78E9213}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{BEF0B44F-037E-476F-BFA6-8C2C706FCA5B}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{4454CFB3-19BE-405A-90B4-BC705A0CB1BA}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{57AA4318-1F74-4080-AA39-0AF55ED35C19}] => C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ScanCDLM.exe FirewallRules: [{EAC02C55-DB46-47D3-AE14-5FD27F82990F}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [{AF038FF8-ED4F-433F-9D43-497FDF85B06C}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [TCP Query User{05F95EF4-3FA5-4488-AA43-41AAA67F866B}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [UDP Query User{327CD24E-F107-416B-AA60-405B1F88B17C}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [{46E616EF-3721-4155-B683-CB0555788B21}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{4E173E3B-562E-46CF-89BC-B90CBC5E4579}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{DD361FB4-2DD0-4359-8613-498E04669C10}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{905E93C8-B3A8-4D6C-B4ED-CC16893C5A5D}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A60032BF-F733-4706-BE47-D0572603553F}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D41200A6-6C37-4320-A096-FB3B9B77D06A}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{D9AA500D-DED0-4C38-B29C-FBFFBB753BCF}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{D4F511F5-A3C0-4ACE-9887-29CCB2C1819A}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{6D017BB6-214A-4372-AC51-79A0E0838D38}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{3E3D7043-688B-42F1-BD19-EFEE531CD7EB}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{9D43C6AA-622A-4807-8D85-07C4D8DECC1E}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{DED23947-28C4-4CB0-A3DD-6AB991D002CA}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{7A84FB57-2C5F-4AF1-98D1-CBAA810C5371}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [{581081D7-DE6D-45D1-B024-D42D884F35D5}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{009C2982-F3A9-476A-A6DD-E9BBEFD008C2}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{7647EB15-3CF7-4C2D-BF74-C08E6C60CDAC}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{E67D201B-3D8F-415A-A46E-92FB5C4E6D60}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{9750BBA5-40A8-44F3-A4D9-5279F55675AF}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [{D851D20D-8592-4B90-90EC-C9601103100F}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [TCP Query User{44986407-2FDA-4D19-80D3-3E42B8633EC4}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [UDP Query User{85A8E48D-78B4-43AF-B77D-0A11F4CE797A}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [{6FA9110C-F5F5-43FD-8AAD-97C37F81F712}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{FDDAE222-742C-4755-9036-CC91ADF1A4DC}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{42A06F30-5633-4EC3-8516-22F6677C2947}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{D746E6BD-5966-46EA-B84D-3B9C3BC781C1}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{BB9E6EB6-A015-442E-841A-46B8D8981E0F}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{9FFCE39F-326C-4AA6-8A11-EA1980124981}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{7C92A080-F2E6-471E-B71D-A4BFAFCBA865}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{0BFCBF4F-4452-4086-96B1-8A2D033DECEA}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{7F63544E-5F0F-4CE5-BC77-13090B2B752D}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [{0BB49C5F-0009-48E6-BB0D-947907C8CB77}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [TCP Query User{75A0C3D7-376F-4E92-B796-39FB47CEA324}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{550AA2BC-F80A-4AD6-A9A7-A6E4E59C6263}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{9E8D188F-7A68-4CE1-AE50-776DAE4AC71B}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{97AB60CF-256B-4339-A041-C06A49483DAF}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{12A249D7-B9E5-417A-B4FF-0ED1519D3B57}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{D477E148-CA94-42B1-BDB5-4A107A21CF2C}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{5CFE4309-AE83-45A8-860D-A966B7A66F2E}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{383E1175-6B7C-4EAB-8592-581174AB387A}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{DC6CF8D7-022B-4BF1-A2D4-A01099710A8E}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{A8EDA4A9-1BB0-454F-851A-5C0A66C0935C}] => LPort=2869 FirewallRules: [{9076894C-96AF-4F79-9FC8-872941390765}] => LPort=1900 FirewallRules: [{982C83A7-E965-4A43-AC57-DED5418E1D86}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{34904A3E-2731-4BCA-99E7-0C522E19F596}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{79A4CA0B-FAAD-4F1D-B690-53DCB685F3B7}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{6A68F600-EE62-4D35-A8FD-19C7FC858DD0}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{7ED7E197-1394-431D-9A73-11AE6D10BEB9}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A9235B4D-7631-49AD-9E30-76937AC56F5E}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A350EF63-8725-4AB3-B6BD-33D13DA5F134}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_launcher.exe FirewallRules: [{BDC16B40-7773-4E47-A4A0-23BD74170D09}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{D8AD6045-708F-4629-A4D3-642C3BD4F61F}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{75E6E119-7E57-400A-B104-24F8D32EDD90}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{6D166702-17D2-4E22-B532-DD814E55C422}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{DA796ED4-9458-4BC1-95A0-AB6DD17FDCF5}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{176A26D4-1D56-44E4-9B84-4970448A6B21}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{56374166-7C69-44CF-9232-BAB7964BABCE}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{EDC2E8A6-CB4E-49CA-8B4F-F555651A914C}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{80B41A04-E617-42B5-AFCB-5CA576D9FDBA}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{1D989B94-B275-455F-B721-1C10E62BE0BF}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{991023BE-281F-40DD-A22A-5FF97099B5CB}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{B79C5C21-ACA7-43F6-9284-D0ABD0C7F86D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{BE7CB2A9-F20C-4BB0-87C0-644FD0CDA1D4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{D720B6B9-0A35-42D0-85A5-EE9270EA03BB}] => LPort=8318 FirewallRules: [{B99A897A-B2C5-456B-B3D8-E0B80DAB2FBE}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelDrw.exe FirewallRules: [{699A2E63-2033-4335-A20F-1686EBD94622}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\Designer.exe FirewallRules: [{CB3411CB-51BD-4951-A168-022BAAA9C7CD}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelPP.exe FirewallRules: [{A8ECF176-6083-4C6C-898B-638185759074}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{200F9EE4-2BF0-4ADF-BF03-BE4E5C8E16A2}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{6DF521B4-51CF-4AB3-B0AB-71091788AF8C}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{518CE409-F02B-4BA8-B0E3-16AD4BD4E7D7}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{F78314FA-4E04-4C00-B620-F4342A39F389}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{A9141310-E430-48A0-A42E-EC596D66B4E8}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{E8D911F0-75D3-49D6-811F-7773A97AF5E1}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{CB30BD9A-3C48-4EA5-8F44-A68289BC1E56}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{2E488689-B02A-48F2-9567-DA9848F1A6C5}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [{0A84CC58-F8C4-4E72-8EA1-3019C08D15AD}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [TCP Query User{EDDD8DC6-81D9-43F6-A646-74F92961A6B5}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [UDP Query User{A7DE668B-1E28-4EFE-ACBC-61ACB822FA99}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [{BE76A0A7-9704-4FEE-8174-3305863BAC38}] => C:\Program Files\Autodesk\Desktop Connect\forever\node.exe FirewallRules: [{2BF5D8B6-6403-4A42-8E4A-E21A7420760A}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{2C7B2DC1-7504-4C82-9DA7-D17A3DCDE685}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{DF6B2F65-8DAE-4D51-A95E-6743F086EC2A}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{26765CDE-DB0B-447C-893B-51F1C501186B}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{BE3EF81A-2CD1-45DD-A071-275030320227}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{7ECE005B-97E3-4C60-A29D-BD5D20BBEF43}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{A3D9E1E0-C8EA-4E2E-8FE3-DD48267D9E7C}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{12CAEE74-C739-431C-ABBF-82EA376E1535}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{6908C6EB-7521-4486-A71C-9A94CE4784F3}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{99122A42-4BB1-4FA9-8B82-DB47E74DE65F}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{0B6CE556-8917-4B14-BE1A-B94B057E5923}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{95D44447-AEB3-42E1-9812-FBA20C38F973}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{9705E715-8B84-4FB0-8761-6F399FEA9D5E}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{5E2D4D0F-96FA-4F7E-B60E-47B3927A85B2}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{A2BAFD1F-E6F8-42FA-9191-5E66E402272E}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{E8BA2090-632A-40E1-9E5B-2219C72336AD}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{4B563710-0FFB-4B58-8123-BF4948C0919B}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [TCP Query User{CB0D4FD0-D3EF-4926-9FD3-8DF624B8DBFF}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{07CB26DB-BCA3-4241-A49C-B409B6F95D5F}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{791ADF39-9F27-45E2-8361-5BDCF553233E}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{D13C0897-595A-403E-8BF6-4AB1772FC39D}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{994C4074-9B2E-421D-826C-EFDBEE9BFD18}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{B2C64793-5BD9-45A1-87CF-F19EB0938603}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{487A2954-09F0-495B-AA5E-BF44BC759183}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{63C63B5A-8D62-4FF6-AF78-5C7ED303AD27}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{E800328C-F65F-41A9-9F18-33ECB585C235}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Wiederherstellungspunkte ========================= 29-12-2016 00:33:06 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 29-12-2016 00:33:17 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 30-12-2016 03:01:50 DirectX wurde installiert 06-01-2017 19:41:51 Geplanter Prüfpunkt 09-01-2017 18:57:57 DirectX wurde installiert 18-01-2017 10:06:48 DVDVideoSoftRestorePoint 18-01-2017 11:05:03 Wiederherstellungsvorgang 18-01-2017 16:12:27 Malwarebytes Anti-Rootkit Restore Point ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/18/2017 07:46:07 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/18/2017 07:45:49 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/18/2017 07:34:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NetworkManager.exe, Version: 1.1.57.1125, Zeitstempel: 0x56aa8dfe Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.23569, Zeitstempel: 0x57f7c0b4 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000001a06d ID des fehlerhaften Prozesses: 0xba0 Startzeit der fehlerhaften Anwendung: 0x01d271b9852c4182 Pfad der fehlerhaften Anwendung: C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: cc0fbbc4-ddac-11e6-afb9-d8cb8a9bbec6 Error: (01/18/2017 07:34:51 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/18/2017 07:34:40 PM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.InvalidOperationException: Could not start IPC server bei Hirez.Patcher.HiPatchService.InternalStart() bei Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/18/2017 07:34:39 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: NetworkManager.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Net.Sockets.SocketException bei System.Net.Sockets.Socket..ctor(System.Net.Sockets.AddressFamily, System.Net.Sockets.SocketType, System.Net.Sockets.ProtocolType) bei System.Net.Sockets.TcpClient.initialize() bei System.Net.Sockets.TcpClient..ctor(System.Net.Sockets.AddressFamily) bei NetworkManager.ServerAPI.ServerPipe.ReadThread() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (01/18/2017 07:34:34 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/18/2017 07:34:33 PM) (Source: Schedule) (EventID: 0) (User: ) Description: Event-ID 0 Error: (01/18/2017 04:31:49 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2017-01-25T08:47:49Z. Error Code: 0x80070032. Error: (01/18/2017 04:21:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Systemfehler: ============= Error: (01/18/2017 07:45:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/18/2017 07:44:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/18/2017 07:44:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Disc Soft Ultra Bus Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/18/2017 07:44:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Malwarebytes Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Samsung UPD Utility Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Samsung Printer Dianostics Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/18/2017 07:44:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PnkBstrA" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. CodeIntegrity: =================================== Date: 2016-01-30 22:58:26.996 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.963 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.850 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.817 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.604 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.573 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.430 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.382 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.632 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-6300 Six-Core Processor Prozentuale Nutzung des RAM: 42% Installierter physikalischer RAM: 8156.29 MB Verfügbarer physikalischer RAM: 4654.95 MB Summe virtueller Speicher: 16310.77 MB Verfügbarer virtueller Speicher: 12087.07 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:223.37 GB) (Free:60.25 GB) NTFS Drive e: () (Fixed) (Total:277.17 GB) (Free:56.68 GB) NTFS Drive h: () (Fixed) (Total:277.17 GB) (Free:41.06 GB) NTFS Drive i: () (Fixed) (Total:100 GB) (Free:20.88 GB) NTFS Drive k: (Volume) (Fixed) (Total:277.08 GB) (Free:209.91 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6015DB08) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Active) - (Size=100 MB) - (Type=42) Partition 3: (Not Active) - (Size=100 GB) - (Type=42) Partition 4: (Not Active) - (Size=831.4 GB) - (Type=42) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 619C2244) Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=223.4 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
19.01.2017, 20:03 | #6 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera startESET Online Scanner
Hinweis: Dieser Scan kann schon einmal mehrere Stunden dauern... Hast du noch irgendwelche Probleme mit deinem Rechner?
__________________ --> Windows 7 3-4 Webseiten öffnen sich nach Opera start |
20.01.2017, 11:58 | #7 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Hallo Raphael, ESET Log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=e75a2966ce269c4c9064cd119a38da2f # end=init # utc_time=2017-01-19 07:26:34 # local_time=2017-01-19 08:26:34 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 32122 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=e75a2966ce269c4c9064cd119a38da2f # end=updated # utc_time=2017-01-19 07:28:42 # local_time=2017-01-19 08:28:42 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=e75a2966ce269c4c9064cd119a38da2f # engine=32122 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2017-01-19 10:32:00 # local_time=2017-01-19 11:32:00 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Antivirus' # compatibility_mode=1815 16777213 100 97 11333 35716055 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 8428757 236494970 0 0 # scanned=810885 # found=5 # cleaned=0 # scan_time=10997 sh=308999F438095DE8378E09606D629AC9118D8460 ft=1 fh=5ec7bc310a566309 vn="Variante von Win32/Packed.Themida verdächtige Datei" ac=I fn="C:\Users\Alex\Desktop\SBOT\****** - Kopie\SBotP_1.0.28d.exe" sh=86A3F18B6D6B7F10CACA9F5C3C4CBAC54339173D ft=1 fh=c62459d52f05468b vn="Variante von Win32/InstallCore.AHE eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\13107783104210041267.exe" sh=5B5EA2F5CEC496F99D245A68C884C09F5849E037 ft=1 fh=038fab3ea954bf64 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\DMR\dmr_72.exe" sh=4101270357B096EF454463D13581E3D123C60560 ft=1 fh=2a17fddd6cb742ea vn="Variante von Win32/InstallCore.ACL eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\in0DB19A7D\44134440_stp\RAM.dll" sh=308999F438095DE8378E09606D629AC9118D8460 ft=1 fh=5ec7bc310a566309 vn="Variante von Win32/Packed.Themida verdächtige Datei" ac=I fn="I:\Users\Alex\Desktop\SBOT\****** - Kopie\SBotP_1.0.28d.exe" In den 2 Funden habe ich Benutzernamen unkenntlich gemacht, bitte nicht wundern. Denke es ist ein Fehleralarm. Bis jetzt konnte ich keine anderweitige Probleme mit meinem Rechner feststellen. Prozessorauslastung im Idle bewegt sich zwischen 0-3% (Standard). Wenn ich am Rechner arbeite überwache ich öfters Prozesse und Dienste. Im alltäglichen Gebrauch kann ich keine Beeinträchtigungen merken oder erkennen. Alle Programme funktionieren wie sie sollen. Werbeseiten werden nicht mehr angezeigt, sprich: Alles wie bisher. Das einzige was mir aufgefallen ist, dass auf meinem Laptop, sobald Dropbox geöffnet wird, mein Antivirus anfängt zuarbeiten und meiner Meinung nach die Dropbox überprüft. Liegt womöglich daran das ich davor nicht darauf geachtet habe ob es auch sonst immer gemacht hat und es mir jetzt nur so vorkommt. Seit dem habe ich Dropbox und OneDrive nicht benutzt. Info: Dropbox war geöffnet als ich, wie im ersten Post beschrieben, die Probleme bekam. Jetzt weiß ich natürlich nicht ob es sein kann das was rein gekommen ist. Liebe Grüße BauBau Edit: habe doch ein Problem gehabt mit meinem Rechner. Als ich den angemacht habe startete automatisch eine Laufwerksprüfung (DOS-Fenster). Während der Prüfung erste/löschte es Dateien bzw. entfernte fehlerhafte Sektoren. Nach einem weiteren Neustart lief der endlich doch der Monitor blieb schwarz. Da mein Rechner Übertaktet ist (seit Okt, 2016), dachte ich das da im Bios etwas nicht passt. Da nichts anderes möglich war,startete ich Cmos-Reset (Batterie raus und rein), siehe da, er lief wieder. doch nach dem booten kam der Schreck... Das Problem ist jetzt das mein Rechner bzw. Festplatten auf einem Stand von 24.06.2016. Alle Programme, alle Dateien die erstellt wurden sind nicht mehr da. Das ist mir neu, dass beim Cmos-Reset Daten/Dateien weg sind. Bisher war es auch nicht der Fall dass nur eine Datei nach dem Reset fehlte.. Weißt du da was? Geändert von BauBau (20.01.2017 um 12:12 Uhr) |
21.01.2017, 14:41 | #8 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera start kann es sein, dass sich dein PC automatisch auf den Werkszustand zurück gesetzt hat weil du ihn mit dem Reset so verwirrt hast? Normal gehen dabei natürlich keine Daten verloren, bei einer Festplattenüberprüfung eigentlich auch nicht. Wenn du probieren willst Daten zu retten, PC nicht mehr benutzen und von einem USB Stick beispielsweise Recuva ausführen, gibt viele Anleitungen zu sowas im Internet. Aber ein komisches Problem. Das Malware Problem hat sich jetzt erledigt nehm ich mal an? Du kannst gerne in der Windows Sektion um weitere Hilfe fragen.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
23.01.2017, 19:00 | #9 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Guten Abend Raphael, das Problem hat sich ganz schnell wieder geklärt. Das Problem war dass der Cmos-Reset die Startreihenfolge auch zurück gesetzt hat. Habe es wieder umgestellt. Frage die noch bleibt ist in dem ESET Logfile waren noch 5 Einträge von denen 2 ich als sicher einstufe. Die 3 anderen weiß ich nicht was ich mit denen machen soll. Code:
ATTFilter sh=86A3F18B6D6B7F10CACA9F5C3C4CBAC54339173D ft=1 fh=c62459d52f05468b vn="Variante von Win32/InstallCore.AHE eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\13107783104210041267.exe" sh=5B5EA2F5CEC496F99D245A68C884C09F5849E037 ft=1 fh=038fab3ea954bf64 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\DMR\dmr_72.exe" sh=4101270357B096EF454463D13581E3D123C60560 ft=1 fh=2a17fddd6cb742ea vn="Variante von Win32/InstallCore.ACL eventuell unerwünschte Anwendung" ac=I fn="I:\Users\Alex\AppData\Local\Temp\in0DB19A7D\44134440_stp\RAM.dll" MfG BauBau Geändert von BauBau (23.01.2017 um 19:05 Uhr) |
23.01.2017, 19:20 | #10 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera start ah oke Schritt: 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Task: {2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} - \ThunderMaster -> Keine Datei <==== ACHTUNG HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Policies\Explorer: [] HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {2a7e694d-afe4-11e5-881f-806e6f6e6963} - F:\DVDSetup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} - R:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} - G:\startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} - M:\Startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {b7167805-aff4-11e5-89b3-d8cb8a9bbec6} - Q:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {dddedf48-3336-11e6-9221-d8cb8a9bbec6} - D:\setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {fd345007-2950-11e6-980e-d8cb8a9bbec6} - Y:\Setup.exe S3 ALSysIO; \??\C:\Users\Alex\AppData\Local\Temp\ALSysIO64.sys [X] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 BTCOM; system32\DRIVERS\btcomport.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 cpuz137; \??\C:\Users\Alex\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X] S3 cpuz138; \??\C:\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] S3 xspirit; \??\C:\Windows\xspirit.sys [X] Task: {CA7DAD2B-48E7-4F0B-BF32-A756013D4756} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-07-07] () C:\Windows\AutoKMS hosts: emptytemp: MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => Keine Datei Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
24.01.2017, 18:16 | #11 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera startCode:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 22-01-2017 durchgeführt von Alex (24-01-2017 18:10:30) Run:1 Gestartet von C:\Users\Alex\Desktop\Neuer Ordner (2) Geladene Profile: Alex (Verfügbare Profile: Alex) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** Task: {2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} - \ThunderMaster -> Keine Datei <==== ACHTUNG HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Policies\Explorer: [] HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {2a7e694d-afe4-11e5-881f-806e6f6e6963} - F:\DVDSetup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} - R:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} - G:\startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} - M:\Startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {b7167805-aff4-11e5-89b3-d8cb8a9bbec6} - Q:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {dddedf48-3336-11e6-9221-d8cb8a9bbec6} - D:\setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {fd345007-2950-11e6-980e-d8cb8a9bbec6} - Y:\Setup.exe S3 ALSysIO; \??\C:\Users\Alex\AppData\Local\Temp\ALSysIO64.sys [X] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 BTCOM; system32\DRIVERS\btcomport.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 cpuz137; \??\C:\Users\Alex\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X] S3 cpuz138; \??\C:\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] S3 xspirit; \??\C:\Windows\xspirit.sys [X] Task: {CA7DAD2B-48E7-4F0B-BF32-A756013D4756} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-07-07] () C:\Windows\AutoKMS hosts: emptytemp: MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => Keine Datei CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => Keine Datei ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} => Schlüssel erfolgreich entfernt HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E6C58C7-19CF-4156-B74A-9BEF63F0B56C} => Schlüssel erfolgreich entfernt HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ThunderMaster => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Wert erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a7e694d-afe4-11e5-881f-806e6f6e6963} => Schlüssel erfolgreich entfernt HKCR\CLSID\{2a7e694d-afe4-11e5-881f-806e6f6e6963} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7167805-aff4-11e5-89b3-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{b7167805-aff4-11e5-89b3-d8cb8a9bbec6} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dddedf48-3336-11e6-9221-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{dddedf48-3336-11e6-9221-d8cb8a9bbec6} => Schlüssel nicht gefunden. HKU\S-1-5-21-844601699-3614358154-429673199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd345007-2950-11e6-980e-d8cb8a9bbec6} => Schlüssel erfolgreich entfernt HKCR\CLSID\{fd345007-2950-11e6-980e-d8cb8a9bbec6} => Schlüssel nicht gefunden. ALSysIO => Dienst nicht gefunden. HKLM\System\CurrentControlSet\Services\BlueletAudio => Schlüssel erfolgreich entfernt BlueletAudio => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\BT => Schlüssel erfolgreich entfernt BT => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\BTCOM => Schlüssel erfolgreich entfernt BTCOM => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\Btcsrusb => Schlüssel erfolgreich entfernt Btcsrusb => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\cpuz137 => Schlüssel erfolgreich entfernt cpuz137 => Dienst erfolgreich entfernt cpuz138 => Dienst nicht gefunden. HKLM\System\CurrentControlSet\Services\dbx => Schlüssel erfolgreich entfernt dbx => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\IvtComBusSrv => Schlüssel erfolgreich entfernt IvtComBusSrv => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\MSICDSetup => Schlüssel erfolgreich entfernt MSICDSetup => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_C => Schlüssel erfolgreich entfernt NTIOLib_1_0_C => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\pccsmcfd => Schlüssel erfolgreich entfernt pccsmcfd => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\VGPU => Schlüssel erfolgreich entfernt VGPU => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\xhunter1 => Schlüssel erfolgreich entfernt xhunter1 => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\xspirit => Schlüssel erfolgreich entfernt xspirit => Dienst erfolgreich entfernt HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA7DAD2B-48E7-4F0B-BF32-A756013D4756} => Schlüssel nicht gefunden. C:\Windows\System32\Tasks\AutoKMS => erfolgreich verschoben HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS => Schlüssel erfolgreich entfernt C:\Windows\AutoKMS => erfolgreich verschoben Konnte nicht verschoben werden "C:\Windows\System32\Drivers\etc\hosts" => ist geplant bei Neustart verschoben zu werden. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdReg => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220} => Schlüssel erfolgreich entfernt HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1} => Schlüssel erfolgreich entfernt =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 87601566 B Java, Flash, Steam htmlcache => 83418182 B Windows/system/drivers => 352615934 B Edge => 0 B Chrome => 6695985 B Firefox => 18797441 B Opera => 388207526 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile32 => 33685 B LocalService => 0 B NetworkService => 0 B Alex => 363324808 B RecycleBin => 0 B EmptyTemp: => 1.2 GB temporäre Dateien entfernt. ================================ Ergebnis der geplanten Datei-Verschiebungen (Start-Modus: Normal) (Datum&Uhrzeit: 24-01-2017 18:12:06) "C:\Windows\System32\Drivers\etc\hosts" => Konnte nicht verschoben werden Konnte nicht wiederhergestellt werden Hosts. ==== Ende vom Fixlog 18:12:06 ==== |
24.01.2017, 20:17 | #12 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera start Fast geschafft: Schritt: 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter hosts: reboot: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Deaktiviere Avira vor dem Fix, da er sonst fehlschlagen wird! Schritt: 2 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
24.01.2017, 21:04 | #13 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017 durchgeführt von Alex (Administrator) auf ALEX-PC (24-01-2017 20:58:22) Gestartet von C:\Users\Alex\Desktop\Neuer Ordner (2) Geladene Profile: Alex (Verfügbare Profile: Alex) Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Opera) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe (MSI) C:\Windows\SysWOW64\muachost.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe (Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Palit Microsystems Ltd.) C:\Program Files (x86)\Thunder Master\THPanel.exe (iAnywhere Solutions) C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe (SafeNet Inc.) C:\Windows\System32\hasplms.exe (Hi-Rez Studios) H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe (MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () C:\Windows\System32\PnkBstrA.exe () C:\Windows\SysWOW64\spdsvc.exe () C:\Windows\SysWOW64\SecUPDUtilSvc.exe (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE () C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe () C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8801024 2016-04-22] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15112312 2016-02-09] (Logitech Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] () HKLM-x32\...\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-11-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] () HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1015808 2016-05-19] (MSI) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26142864 2017-01-18] (Dropbox, Inc.) HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MSI) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [THPanel] => C:\Program Files (x86)\Thunder Master\THPanel.exe [2197472 2015-07-22] (Palit Microsystems Ltd.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283112 2016-02-02] (Autodesk, Inc.) HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2016-02-07] (Autodesk, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.11.0.dll [2017-01-18] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Blue Manager Suite.lnk [2016-01-16] ShortcutTarget: Blue Manager Suite.lnk -> C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (iAnywhere Solutions) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-06-08] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\Parameters: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{40DBAA5B-6CDD-40E5-AF69-3B7168DAF5A1}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{6D01CE8B-7659-4887-9FF5-E8F77D6A492F}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [DhcpNameServer] 8.8.8.8 Internet Explorer: ================== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-844601699-3614358154-429673199-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default [2017-01-24] FF Homepage: Mozilla\Firefox\Profiles\qiF99tHm.default -> hxxps://www.google.de FF Session Restore: Mozilla\Firefox\Profiles\qiF99tHm.default -> ist aktiviert. FF Extension: (Avira Browser Safety) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\abs@avira.com.xpi [2016-11-27] FF Extension: (Firefox Hotfix) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-03] FF Extension: (MEGA) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox@mega.co.nz.xpi [2017-01-19] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-13] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-18] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @lattice3d.com/XVL Player -> C:\Program Files\Lattice\Player3_x86\npxvlplay.dll [2015-02-23] (Lattice Technology Co.,Ltd.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-01-24] CHR Extension: (Google Präsentationen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-14] CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-14] CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-14] CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-14] CHR Extension: (Adobe Acrobat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-12] CHR Extension: (Google Tabellen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-14] CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-12-14] CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-14] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-14] CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-14] CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-14] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-10-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk Inc.) S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-14] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-12] () S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [46400 2017-01-04] (Dropbox, Inc.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [392168 2016-08-31] (Digital Wave Ltd.) S3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1345368 2015-06-10] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [249104 2016-11-11] (EasyAntiCheat Ltd) R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.) R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.) R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-01] (SafeNet Inc.) U2 HiPatchService; H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-01-28] (Rivet Networks) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2016-02-09] (Logitech Inc.) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes) S4 mitsijm2017; E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe [967456 2015-08-04] (Autodesk, Inc.) S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MSI) S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2204768 2016-09-29] (MSI) S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4171360 2016-11-23] (MSI) R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2014816 2016-11-15] (MSI) R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2327648 2016-12-05] (MSI) S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-12-05] (MSI) S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [609888 2016-12-05] (MSI) R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2248144 2016-04-28] (Micro-Star INT'L CO., LTD.) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation) S4 Origin Client Service; C:\Users\Alex\Origin\OriginClientService.exe [2119688 2016-12-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Users\Alex\Origin\OriginWebHelperService.exe [2180624 2016-12-24] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-01-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-01-02] () S4 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc) R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-05-01] () R2 SamsungUPDUtilSvc; C:\Windows\SysWOW64\SecUPDUtilSvc.exe [143664 2016-06-06] () S4 SanDisk SSD Dashboard Service; C:\Program Files (x86)\SanDisk\SSD Dashboard\SanDiskSSDDashboardService.exe [373760 2016-06-24] (SanDisk) [Datei ist nicht signiert] S3 Survarium-Steam Update Service; H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-11-14] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-12-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-05-11] (Avira Operations GmbH & Co. KG) S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-01-24] (Rivet Networks, LLC.) S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT Corporation.) S3 btiaa2dp; C:\Windows\System32\drivers\btiaa2dp.sys [82944 2008-09-16] (iAnywhere Solutions) S3 BTiAPan; C:\Windows\System32\DRIVERS\btiapan.sys [37888 2008-09-16] (iAnywhere Solutions) S3 btiarcp; C:\Windows\System32\DRIVERS\btiarcp.sys [10880 2008-07-30] (iAnywhere Solutions) S3 btiaspp; C:\Windows\System32\DRIVERS\btiaspp.sys [92160 2008-09-16] (iAnywhere Solutions) S3 BTIAUSB; C:\Windows\System32\DRIVERS\btiausb.sys [31744 2008-11-14] (iAnywhere Solutions) S3 BTPROT; C:\Windows\System32\DRIVERS\btprot.sys [517632 2008-11-14] (iAnywhere Solutions) R0 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation) R0 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation) R0 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-31] (Disc Soft Ltd) S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-31] (Disc Soft Ltd) R0 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2016-03-15] (Disc Soft Ltd) R3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47160 2016-03-15] (Disc Soft Ltd) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc) R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-01] (SafeNet Inc.) R3 I2cHkBurn; C:\Windows\System32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.) S3 iAnywhere_btAudio; C:\Windows\System32\drivers\btiasco.sys [25088 2008-07-30] (iAnywhere Solutions) S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.) S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [125488 2015-03-18] (Qualcomm Atheros, Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2016-07-30] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Datei ist nicht signiert] R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [106760 2015-10-14] (WIBU-SYSTEMS AG) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-24 20:57 - 2017-01-24 20:57 - 00000000 ___HD C:\OneDriveTemp 2017-01-24 18:36 - 2017-01-24 18:36 - 00001169 _____ C:\Users\Public\Desktop\MSI Command Center.lnk 2017-01-24 18:29 - 2017-01-24 18:29 - 00263714 _____ C:\Users\Alex\Desktop\Preise_o2dslSML.pdf 2017-01-24 18:00 - 2017-01-24 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-01-21 11:53 - 2017-01-21 11:53 - 00000000 ____D C:\Users\Alex\Desktop\WAnd PC 2017-01-20 12:33 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-01-20 12:33 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-01-20 12:33 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-01-20 12:33 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-01-20 12:33 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-01-20 12:33 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-01-20 12:33 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-01-20 12:33 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-01-20 12:33 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-01-20 12:33 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-01-20 12:33 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-01-20 12:33 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-01-20 12:33 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-01-20 12:33 - 2016-11-21 19:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2017-01-20 12:33 - 2016-11-20 17:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2017-01-20 12:33 - 2016-11-20 15:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2017-01-20 12:33 - 2016-11-17 17:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2017-01-20 12:33 - 2016-11-15 00:27 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-01-20 12:33 - 2016-11-14 23:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-01-20 12:33 - 2016-11-12 20:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-01-20 12:33 - 2016-11-12 20:48 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-01-20 12:33 - 2016-11-12 20:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-01-20 12:33 - 2016-11-12 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-01-20 12:33 - 2016-11-12 20:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-01-20 12:33 - 2016-11-12 20:25 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-01-20 12:33 - 2016-11-12 20:25 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-01-20 12:33 - 2016-11-12 20:21 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-01-20 12:33 - 2016-11-12 20:15 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-01-20 12:33 - 2016-11-12 20:14 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-01-20 12:33 - 2016-11-12 20:09 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-01-20 12:33 - 2016-11-12 20:08 - 25759744 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-01-20 12:33 - 2016-11-12 20:08 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-01-20 12:33 - 2016-11-12 20:08 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-01-20 12:33 - 2016-11-12 20:07 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-01-20 12:33 - 2016-11-12 20:07 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-01-20 12:33 - 2016-11-12 19:56 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-01-20 12:33 - 2016-11-12 19:53 - 06049280 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-01-20 12:33 - 2016-11-12 19:52 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-01-20 12:33 - 2016-11-12 19:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-01-20 12:33 - 2016-11-12 19:41 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-01-20 12:33 - 2016-11-12 19:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-01-20 12:33 - 2016-11-12 19:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-01-20 12:33 - 2016-11-12 19:34 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-01-20 12:33 - 2016-11-12 19:31 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-01-20 12:33 - 2016-11-12 19:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-01-20 12:33 - 2016-11-12 19:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-01-20 12:33 - 2016-11-12 19:29 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-01-20 12:33 - 2016-11-12 19:29 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-01-20 12:33 - 2016-11-12 19:28 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-01-20 12:33 - 2016-11-12 19:27 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-01-20 12:33 - 2016-11-12 19:20 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-01-20 12:33 - 2016-11-12 19:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-01-20 12:33 - 2016-11-12 19:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-01-20 12:33 - 2016-11-12 19:17 - 20302848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-01-20 12:33 - 2016-11-12 19:15 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-01-20 12:33 - 2016-11-12 19:14 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-01-20 12:33 - 2016-11-12 19:14 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-01-20 12:33 - 2016-11-12 19:14 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-01-20 12:33 - 2016-11-12 19:14 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-01-20 12:33 - 2016-11-12 19:11 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-01-20 12:33 - 2016-11-12 19:10 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-01-20 12:33 - 2016-11-12 19:08 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-01-20 12:33 - 2016-11-12 19:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-01-20 12:33 - 2016-11-12 19:03 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-01-20 12:33 - 2016-11-12 18:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-01-20 12:33 - 2016-11-12 18:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-01-20 12:33 - 2016-11-12 18:52 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-01-20 12:33 - 2016-11-12 18:51 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-01-20 12:33 - 2016-11-12 18:49 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-01-20 12:33 - 2016-11-12 18:47 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-01-20 12:33 - 2016-11-12 18:41 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-01-20 12:33 - 2016-11-12 18:40 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-01-20 12:33 - 2016-11-12 18:38 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-01-20 12:33 - 2016-11-12 18:37 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-01-20 12:33 - 2016-11-12 18:36 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-01-20 12:33 - 2016-11-12 18:36 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-01-20 12:33 - 2016-11-12 18:35 - 02920960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-01-20 12:33 - 2016-11-12 18:21 - 13653504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-01-20 12:33 - 2016-11-12 18:20 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-01-20 12:33 - 2016-11-12 18:11 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-01-20 12:33 - 2016-11-12 18:05 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-01-20 12:33 - 2016-11-12 18:02 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-01-20 12:33 - 2016-11-12 18:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-01-20 12:33 - 2016-11-10 17:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2017-01-20 12:33 - 2016-11-10 17:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2017-01-20 12:33 - 2016-11-09 17:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2017-01-20 12:33 - 2016-11-09 17:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2017-01-20 12:33 - 2016-11-09 17:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2017-01-20 12:33 - 2016-11-09 17:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2017-01-20 12:33 - 2016-11-09 17:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2017-01-20 12:33 - 2016-11-09 17:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2017-01-20 12:33 - 2016-11-09 17:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-01-20 12:33 - 2016-11-09 17:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2017-01-20 12:33 - 2016-11-09 17:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2017-01-20 12:33 - 2016-11-09 17:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2017-01-20 12:33 - 2016-11-09 17:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2017-01-20 12:33 - 2016-11-09 17:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-01-20 12:33 - 2016-11-09 17:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2017-01-20 12:33 - 2016-11-09 16:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2017-01-20 12:33 - 2016-11-06 17:33 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-01-20 12:33 - 2016-11-06 17:16 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-01-20 12:33 - 2016-11-06 17:01 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-01-20 12:33 - 2016-10-27 16:33 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-01-20 12:33 - 2016-10-27 16:20 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-01-20 12:33 - 2016-10-11 16:40 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-01-20 12:33 - 2016-10-11 16:37 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-01-20 12:33 - 2016-10-11 16:37 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-01-20 12:33 - 2016-10-11 16:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-01-20 12:33 - 2016-10-11 16:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:24 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-01-20 12:33 - 2016-10-11 16:24 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-01-20 12:33 - 2016-10-11 16:21 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 16:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-01-20 12:33 - 2016-10-11 16:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-01-20 12:33 - 2016-10-11 16:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-01-20 12:33 - 2016-10-11 15:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-01-20 12:33 - 2016-10-11 15:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-01-20 12:33 - 2016-10-11 15:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2017-01-20 12:33 - 2016-10-11 15:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-01-20 12:33 - 2016-10-11 15:51 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-01-20 12:33 - 2016-10-11 15:51 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-01-20 12:33 - 2016-10-11 15:51 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-01-20 12:33 - 2016-10-11 15:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-01-20 12:33 - 2016-10-11 15:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 15:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 15:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 15:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-01-20 12:33 - 2016-10-11 14:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls 2017-01-20 12:33 - 2016-10-11 14:17 - 00419648 _____ C:\Windows\system32\locale.nls 2017-01-20 12:33 - 2016-10-08 14:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2017-01-20 12:33 - 2016-10-04 16:31 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-01-20 12:33 - 2016-10-04 16:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-01-20 12:33 - 2016-10-04 16:31 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-01-20 12:33 - 2016-10-04 16:31 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-01-20 12:33 - 2016-10-04 16:13 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-01-20 12:33 - 2016-10-04 16:13 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-01-20 12:33 - 2016-10-04 16:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-01-20 12:33 - 2016-10-04 16:13 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-01-20 10:58 - 2017-01-20 10:58 - 00003480 ____N C:\bootsqm.dat 2017-01-18 19:43 - 2017-01-18 19:45 - 00000000 ____D C:\AdwCleaner 2017-01-18 19:24 - 2017-01-18 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-01-18 19:24 - 2017-01-18 19:24 - 00000000 ____D C:\Program Files\Malwarebytes 2017-01-18 19:24 - 2016-12-14 12:55 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-01-18 19:14 - 2017-01-18 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2017-01-18 19:14 - 2017-01-18 19:14 - 00000000 ____D C:\Program Files\VS Revo Group 2017-01-18 17:23 - 2017-01-24 20:58 - 00000000 ____D C:\Users\Alex\Desktop\Neuer Ordner (2) 2017-01-18 16:48 - 2017-01-18 16:49 - 00000000 ____D C:\Users\Alex\Documents\Neuer Ordner (2) 2017-01-18 16:32 - 2017-01-24 20:58 - 00000000 ____D C:\FRST 2017-01-18 15:57 - 2017-01-18 16:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-01-18 15:55 - 2017-01-18 16:12 - 00000000 ____D C:\Users\Alex\Desktop\mbar 2017-01-18 15:48 - 2017-01-18 15:48 - 00000000 ____D C:\Users\Alex\Desktop\backups 2017-01-18 15:34 - 2017-01-18 15:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alex\Desktop\HijackThis_2.0.5.exe 2017-01-18 11:07 - 2017-01-18 19:34 - 00000318 ____H C:\Windows\Tasks\MSIOSDx86_Host.job 2017-01-18 11:07 - 2017-01-18 19:34 - 00000318 ____H C:\Windows\Tasks\MSIOSDx64_Host.job 2017-01-18 11:07 - 2017-01-18 19:34 - 00000252 ____H C:\Windows\Tasks\MSISW_Host.job 2017-01-18 10:54 - 2017-01-18 10:55 - 00000000 ____D C:\Windows\system32\SSL 2017-01-18 10:07 - 2017-01-18 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-01-18 10:06 - 2017-01-18 10:07 - 00000000 ____D C:\Users\Alex\AppData\Roaming\DVDVideoSoft 2017-01-18 10:04 - 2017-01-18 10:05 - 00000000 ____D C:\Users\Alex\Documents\psynetic-gifx 2017-01-18 10:04 - 2017-01-18 10:04 - 00000000 ____D C:\Users\Alex\AppData\Local\psynetic-imageconverter 2017-01-18 10:03 - 2017-01-18 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\psynetic 2017-01-13 12:28 - 2017-01-13 12:28 - 00000000 ____D C:\Users\Alex\Desktop\CINEBENCHR15.03 2017-01-12 22:36 - 2017-01-12 22:50 - 00000028 _____ C:\Users\Alex\Desktop\Neues Textdokument.txt 2017-01-12 20:14 - 2017-01-12 20:14 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-01-12 20:14 - 2017-01-12 20:14 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-01-12 20:14 - 2017-01-12 20:14 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-01-09 16:16 - 2017-01-09 16:22 - 04407342 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V4.0 inkl. Mittelabflußplan.xlsx 2017-01-08 20:53 - 2017-01-08 20:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-01-08 20:53 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-01-08 20:53 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-01-08 20:53 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe 2017-01-08 20:50 - 2016-12-12 03:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-01-08 20:50 - 2016-12-12 03:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-01-04 06:25 - 2017-01-04 06:25 - 00046400 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-01-04 00:21 - 2017-01-04 00:22 - 00000000 ____D C:\Program Files (x86)\OBS 2017-01-04 00:21 - 2017-01-04 00:21 - 00000935 _____ C:\Users\Alex\Desktop\Open Broadcaster Software.lnk 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Program Files\OBS 2017-01-03 12:12 - 2017-01-12 22:40 - 00000000 ____D C:\Users\Alex\Desktop\Gifs 2017-01-02 15:07 - 2017-01-02 15:07 - 00000000 ____D C:\Crash 2017-01-01 23:15 - 2017-01-02 15:06 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Daybreak Game Company 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\SCE 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\Daybreak Game Company 2016-12-26 19:26 - 2016-12-26 19:26 - 00000000 ____D C:\Users\Alex\AppData\Local\TechSmith 2016-12-26 19:02 - 2017-01-24 20:57 - 00002938 _____ C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-24 20:56 - 00005943 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2016-12-26 19:02 - 2016-12-26 19:02 - 00004236 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-12-26 19:02 - 2016-12-12 15:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2016-12-25 17:44 - 2016-12-25 17:44 - 00000000 ____D C:\Users\Alex\AppData\Local\4A Games ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-24 20:57 - 2016-12-20 12:07 - 00003018 _____ C:\Windows\System32\Tasks\MSIAfterburner 2017-01-24 20:57 - 2016-03-25 12:05 - 00000000 ___RD C:\Users\Alex\Dropbox 2017-01-24 20:57 - 2016-01-06 21:03 - 00000000 ___RD C:\Users\Alex\OneDrive 2017-01-24 20:57 - 2015-12-31 19:02 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-24 20:56 - 2016-05-21 18:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-24 20:56 - 2016-03-25 11:59 - 00001206 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-01-24 20:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-24 20:55 - 2008-05-09 16:08 - 00001891 _____ C:\Users\Alex\AppData\Local\bmarchive.bms 2017-01-24 20:52 - 2016-07-18 14:59 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype 2017-01-24 20:51 - 2016-03-25 11:59 - 00001210 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-01-24 18:40 - 2016-10-14 10:13 - 00719098 _____ C:\Windows\system32\perfh019.dat 2017-01-24 18:40 - 2016-10-14 10:13 - 00151344 _____ C:\Windows\system32\perfc019.dat 2017-01-24 18:40 - 2013-04-15 15:44 - 00702730 _____ C:\Windows\system32\perfh007.dat 2017-01-24 18:40 - 2013-04-15 15:44 - 00150314 _____ C:\Windows\system32\perfc007.dat 2017-01-24 18:40 - 2009-07-14 06:13 - 02498584 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-24 18:40 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-01-24 18:39 - 2016-07-18 16:25 - 00000384 ___RH C:\Windows\sosyambaess.lock 2017-01-24 18:36 - 2015-12-31 19:37 - 00000000 ____D C:\MSI 2017-01-24 18:36 - 2015-12-31 19:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI 2017-01-24 18:36 - 2015-12-31 19:35 - 00000000 ____D C:\Program Files (x86)\MSI 2017-01-24 18:35 - 2016-01-05 19:15 - 00000000 ____D C:\Users\Alex\Documents\Outlook-Dateien 2017-01-24 18:20 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-24 18:20 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-24 18:10 - 2016-11-23 12:46 - 00000000 ____D C:\Users\Public\Documents\AdobeGC 2017-01-24 18:10 - 2016-02-21 22:17 - 00000000 ____D C:\Users\Alex\AppData\Local\Adobe 2017-01-24 18:00 - 2016-02-20 15:08 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-01-24 17:59 - 2016-12-17 18:55 - 00003168 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2 2017-01-24 17:59 - 2016-01-06 21:03 - 00002172 _____ C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2017-01-21 12:32 - 2016-02-21 22:19 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-01-21 12:31 - 2015-12-31 19:02 - 05988983 ____H C:\Users\Alex\AppData\Local\IconCache.db.backup 2017-01-21 11:36 - 2016-03-07 20:07 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-01-21 11:32 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-21 00:31 - 2016-01-05 20:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client 2017-01-20 16:05 - 2009-07-14 05:45 - 00565072 _____ C:\Windows\system32\FNTCACHE.DAT 2017-01-20 12:50 - 2016-01-05 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2017-01-20 12:47 - 2009-07-14 03:34 - 00000750 _____ C:\Windows\win.ini 2017-01-20 12:45 - 2015-12-31 18:42 - 02453810 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-01-20 12:42 - 2016-06-24 03:07 - 00000000 ____D C:\Windows\system32\MRT 2017-01-20 12:39 - 2015-12-31 18:53 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-01-20 10:59 - 2016-02-18 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2017-01-19 22:48 - 2016-12-01 19:09 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mozilla 2017-01-19 22:24 - 2016-11-27 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-01-19 18:04 - 2015-12-31 20:42 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1451590946 2017-01-19 18:04 - 2015-12-31 20:41 - 00000000 ____D C:\Program Files (x86)\Opera 2017-01-19 17:59 - 2016-07-21 15:36 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-18 23:43 - 2009-07-14 06:08 - 00032592 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-01-18 19:34 - 2016-01-05 13:46 - 00000000 ____D C:\Users\Alex\AppData\Local\CrashDumps 2017-01-18 19:24 - 2016-07-21 15:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-01-18 16:24 - 2016-07-21 15:35 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-01-18 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2017-01-18 11:19 - 2016-12-14 15:41 - 00002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-18 10:46 - 2016-11-23 11:43 - 00000000 ____D C:\Users\Alex\Documents\Camtasia Studio 2017-01-18 10:07 - 2016-11-20 19:00 - 00000000 ____D C:\Users\Alex\.gimp-2.8 2017-01-18 09:56 - 2016-05-21 18:00 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-18 09:56 - 2016-02-21 22:19 - 00003936 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-01-18 09:56 - 2016-01-04 20:38 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-18 09:56 - 2016-01-04 20:38 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-13 12:29 - 2016-01-04 12:16 - 00000000 ____D C:\Users\Alex\AppData\Roaming\MAXON 2017-01-11 21:09 - 2016-03-07 20:07 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-01-10 16:14 - 2016-07-29 13:57 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS 2017-01-08 20:54 - 2016-11-15 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-01-08 20:54 - 2016-03-18 15:26 - 00000000 ____D C:\Temp 2017-01-08 20:54 - 2015-12-31 19:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-01-04 13:34 - 2016-01-04 14:47 - 00000000 ___RD C:\Users\Alex\Desktop\Games 2017-01-04 12:19 - 2015-12-31 16:47 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-01-01 23:09 - 2016-01-01 16:51 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Origin 2017-01-01 23:09 - 2016-01-01 16:46 - 00000000 ____D C:\ProgramData\Origin 2016-12-29 10:30 - 2016-01-04 14:50 - 00000000 ___RD C:\Users\Alex\Desktop\MSI 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\Program Files\Core Temp 2016-12-27 16:51 - 2016-11-14 17:01 - 00000000 ____D C:\Users\Alex\Documents\Survarium-Steam 2016-12-26 19:02 - 2016-11-15 14:23 - 00003832 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003820 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003644 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003584 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2015-12-31 19:03 - 00000000 ____D C:\Users\Alex\AppData\Local\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 19:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 18:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-25 17:46 - 2016-12-07 09:16 - 00000000 ____D C:\Users\Alex\Documents\4A Games ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 14:46 - 2016-02-06 14:54 - 0000104 _____ () C:\Users\Alex\AppData\Roaming\mBot.ini 2008-05-09 16:08 - 2017-01-24 20:55 - 0001891 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms 2008-05-09 16:08 - 2016-02-20 19:23 - 0000000 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms~RF1a66bd5.TMP 2016-12-21 07:52 - 2016-12-21 07:52 - 0018407 _____ () C:\Users\Alex\AppData\Local\recently-used.xbel 2015-12-31 18:57 - 2016-01-05 15:11 - 0007605 _____ () C:\Users\Alex\AppData\Local\resmon.resmoncfg 2016-05-13 21:20 - 2016-05-13 21:20 - 0000000 _____ () C:\Users\Alex\AppData\Local\{AF97A572-54D0-441A-A283-15CC4BC2A136} 2016-01-04 16:28 - 2016-01-04 16:28 - 0000016 _____ () C:\ProgramData\mntemp 2016-12-26 19:02 - 2017-01-24 20:57 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-24 20:56 - 0005943 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 Einige Dateien in TEMP: ==================== 2017-01-24 18:35 - 2016-12-05 13:38 - 24693376 _____ (MSI ) C:\Users\Alex\AppData\Local\Temp\Command Center.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-20 03:43 ==================== Ende von FRST.txt ============================ |
24.01.2017, 21:10 | #14 |
| Windows 7 3-4 Webseiten öffnen sich nach Opera start Addition Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 22-01-2017 durchgeführt von Alex (24-01-2017 20:58:46) Gestartet von C:\Users\Alex\Desktop\Neuer Ordner (2) Windows 7 Ultimate Service Pack 1 (X64) (2015-12-31 17:53:35) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-844601699-3614358154-429673199-500 - Administrator - Disabled) Alex (S-1-5-21-844601699-3614358154-429673199-1000 - Administrator - Enabled) => C:\Users\Alex Gast (S-1-5-21-844601699-3614358154-429673199-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-844601699-3614358154-429673199-1005 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) A360 Desktop (HKLM\...\{7758802D-9486-4883-9927-CCAC366A3BA4}) (Version: 7.2.3.1800 - Autodesk) ACA & MEP 2017 Object Enabler (Version: 7.9.45.0 - Autodesk) Hidden ACAD Private (Version: 21.0.52.0 - Autodesk) Hidden Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.1.335 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\{C1F3739C-D31D-4062-8788-29261C4A2A68}) (Version: 12.2.4.194 - Adobe Systems, Inc) Age of Mythology: Extended Edition (HKLM\...\Steam App 266840) (Version: - SkyBox Labs) AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.) Ansel (Version: 376.33 - NVIDIA Corporation) Hidden Aperture Tag: The Paint Gun Testing Initiative (HKLM\...\Steam App 280740) (Version: - Aperture Tag Team) AutoCAD 2017 - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 Language Pack - Deutsch (German) (Version: 21.0.52.0 - Autodesk) Hidden Autodesk Advanced Material Library Image Library 2017 (HKLM-x32\...\{8ED2ED41-4455-449D-993C-751C039089B9}) (Version: 15.11.3.0 - Autodesk) Autodesk AutoCAD 2017 - Deutsch (German) (HKLM\...\AutoCAD 2017 - Deutsch (German)) (Version: 21.0.52.0 - Autodesk) Autodesk AutoCAD Performance Feedback Tool 1.2.5 (HKLM-x32\...\{8600F844-9AA5-412E-B6F2-F9C6CBCFD268}) (Version: 1.2.5.0 - Autodesk) Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk) Autodesk Configurator 360 addin (HKLM-x32\...\{E3EE083F-6856-44AB-BC82-445E2FFB8C1A}) (Version: 21.0.11700 - Autodesk) Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.) Autodesk Design Review 2013 (x32 Version: 13.0.0.82 - Autodesk, Inc.) Hidden Autodesk Desktop Connect Service (HKLM\...\{FC772454-BB19-0000-0330-44B459520227}) (Version: 3.30.0 - Autodesk) Autodesk Desktop-App (HKLM-x32\...\Autodesk Desktop App) (Version: 6.2.0.174 - Autodesk) Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.52.0 - Autodesk) Autodesk Guided Tutorial Plugin (HKLM\...\{B3AFC608-D811-0003-0330-21FB25B48D6E}) (Version: 3.30.0 - Autodesk) Autodesk Inventor Content Center Libraries 2017 (Desktop Content) (HKLM\...\{B46DECD1-2164-4EF1-0000-22D71E81877C}) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German)) (Version: 14.0.57.0 - Autodesk) Autodesk Inventor Electrical Catalog Browser 2017 - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Electrical Catalog Browser 2017 Language Pack - Deutsch (German) (Version: 14.0.57.0 - Autodesk) Hidden Autodesk Inventor Professional 2017 - Deutsch (German) (HKLM\...\Autodesk Inventor Professional 2017) (Version: 21.0.14200.0000 - Autodesk) Autodesk Inventor Professional 2017 (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk Inventor Professional 2017 Language Pack - Deutsch (German) (Version: 21.0.14200.0000 - Autodesk) Hidden Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk) Autodesk Material Library 2017 (HKLM-x32\...\{8FB9F735-D64C-4991-8D91-4CDDAB1ABDEE}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Base Resolution Image Library 2017 (HKLM-x32\...\{3FBFBC43-9882-43FA-B979-2D53896747B3}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Low Resolution Image Library 2017 (HKLM-x32\...\{360AC116-6CD4-4E7D-8174-28D47B05E898}) (Version: 15.11.3.0 - Autodesk) Autodesk ReCap 360 (HKLM\...\Autodesk ReCap 360) (Version: 3.0.0.52 - Autodesk) Autodesk ReCap 360 (Version: 3.0.0.52 - Autodesk) Hidden Autodesk Revit Interoperability for Inventor 2017 (HKLM\...\Autodesk Revit Interoperability for Inventor 2017) (Version: 17.0.411.0 - Autodesk) Autodesk Revit Interoperability for Inventor 2017 (Version: 17.0.411.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) (HKLM\...\Autodesk Vault Basic 2017 (Client)) (Version: 22.0.48.0 - Autodesk) Autodesk Vault Basic 2017 (Client) (Version: 22.0.48.0 - Autodesk) Hidden Autodesk Vault Basic 2017 (Client) German Language Pack (Version: 22.0.48.0 - Autodesk) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG) Avira Browser Safety (HKLM-x32\...\{9E10EA90-5E97-43B7-A246-FC7B4F5E9493}) (Version: 1.4.5.509 - Avira Operations GmbH & Co KG) Avira Connect (HKLM-x32\...\{707e8edf-9482-4417-ae39-c9b5fe605e87}) (Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Avira Connect (x32 Version: 1.2.76.27124 - Avira Operations GmbH & Co. KG) Hidden Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - ) Blue Manager Suite (HKLM-x32\...\InstallShield_{28B0F39B-C0C6-4CC5-902B-9BF20111804C}) (Version: - ) Blue Manager Suite (Version: 3.3.0 - iAnywhere Solutions) Hidden Call of Duty Modern Warfare Remastered MULTi2 1.0 (HKLM-x32\...\Call of Duty Modern Warfare Remastered MULTi2 1.0) (Version: - ) Camtasia 9 (HKLM-x32\...\{b7d38e69-9571-4bb3-98c0-4ec2dfae7acf}) (Version: 9.0.0.1306 - TechSmith Corporation) Camtasia 9 (Version: 9.0.0.1306 - TechSmith Corporation) Hidden CDTS17_Setup_x64 (Version: 17.4 - Corel Corporation) Hidden Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Contagion (HKLM\...\Steam App 238430) (Version: - Monochrome, Inc) Corel Graphics - Windows Shell Extension (HKLM\...\_{9DA7C2FD-AD83-4E2E-B9F2-9996749318E0}) (Version: 17.4.0.887 - Corel Corporation) Corel Graphics - Windows Shell Extension (Version: 17.4.887 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.4.887 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Capture (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Common App (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Connect (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Custom Data (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - DE (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Designer (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Draw (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - EN (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Equation Editor (x32 Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Filters (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FontNav (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - FR (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM Content (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM T (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - IPM XVL (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - PHOTO-PAINT (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Photozoom Plugin (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Redist (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Setup Files (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VBA (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - VideoBrowser (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 - Writing Tools (x64) (Version: 17.4 - Corel Corporation) Hidden CorelDRAW Technical Suite X7 (64-Bit) (HKLM\...\_{A4B5A413-B7CF-415F-8994-595DB2EFE848}) (Version: 17.4.0.887 - Corel Corporation) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Crysis WARHEAD(R) (x32 Version: 1.0 - Crytek) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Ultra (HKLM\...\DAEMON Tools Ultra) (Version: 3.1.0.0368 - Disc Soft Ltd) Dropbox (HKLM-x32\...\Dropbox) (Version: 18.4.32 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden DWG TrueView 2017 - English (Version: 21.0.52.0 - Autodesk) Hidden Eco Materials Adviser for Autodesk Inventor 2017 (64-bit) (HKLM\...\{05D87862-35C9-4CB4-92EC-8A1FC97BFF6C}) (Version: 6.4.9.0 - Granta Design Limited) Elegant-Treiber Paket (HKLM-x32\...\Samsung Stylish UI Pack) (Version: 1.01.74.00 (09.02.2015) - Samsung Electronics Co., Ltd.) Euro Truck Simulator 2 Demo (HKLM\...\Steam App 231120) (Version: - SCS Software) FARO LS 1.1.505.0 (64bit) (HKLM-x32\...\{8834451B-6209-4E02-9EF4-4EF9E3C1F70F}) (Version: 5.5.0.44203 - FARO Scanner Production) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company) Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14 (HKLM-x32\...\Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 Final MULTi2 1.14) (Version: - ) Half-Life: A Place in the West (HKLM\...\Steam App 466270) (Version: - Michael Pelletier) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org) Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive) Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation) Inventor Connected Desktop for A360 (HKLM\...\{1FA52755-1FBC-0001-0330-7CEA1F3736D8}) (Version: 3.30.0 - Autodesk) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Killer Bandwidth Control Filter Driver (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer E220x Drivers (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Network Manager (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.57.1125 - Rivet Networks) Lattice3D Player / Lattice3D Player Pro (Ver. 9 oder höher) 64-bit Edition (HKLM-x32\...\{936575FE-E49B-4CE9-9934-0329727476C8}) (Version: 14.0c - Lattice Technology) Lattice3D Studio Corel Edition x64 (HKLM-x32\...\{A7161767-5AFE-4725-9DB0-AED7FB5FBA40}) (Version: 2.0 - Lattice Technology) Logitech Gaming Software 8.79 (HKLM\...\Logitech Gaming Software) (Version: 8.79.77 - Logitech Inc.) mb WorkSuite 2016 (HKLM\...\{1C1D8E70-B1C8-4ACE-ADAB-B37F271E71FC}) (Version: 20.16.010.0 - mb AEC Software GmbH) Metro 2033 Redux (HKLM\...\Steam App 286690) (Version: - 4A GAMES) Metro: Last Light Redux (HKLM\...\Steam App 287390) (Version: - 4A Games) Microsoft .NET Framework 4.6 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Hotfix Rollup (KB3154529) (HKLM\...\{5B71B4F6-A412-3C48-B332-0FA9B9958940}) (Version: 4.6.01081 - Microsoft Corporation) Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation) Middle-earth: Shadow of Mordor (HKLM\...\Steam App 241930) (Version: - Monolith Productions, Inc.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla) MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD) MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 1.0.1.17 - MSI) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Need for Speed™ (HKLM-x32\...\{F8643E83-A868-4EE8-A0B9-389386830453}) (Version: 1.3.0.0 - Electronic Arts) NVIDIA 3D Vision Treiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.33 - NVIDIA Corporation) NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation) NVIDIA Grafiktreiber 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Stable 42.0.2393.137 (HKLM-x32\...\Opera 42.0.2393.137) (Version: 42.0.2393.137 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.3.3.1921 - Electronic Arts, Inc.) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden Portal 2 (HKLM\...\Steam App 620) (Version: - Valve) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7634 - Realtek Semiconductor Corp.) RivaTuner Statistics Server 6.4.1 (HKLM-x32\...\RTSS) (Version: 6.4.1 - Unwinder) Rocketbirds: Hardboiled Chicken (HKLM\...\Steam App 215510) (Version: - Ratloop Asia) Runtime VS2005 SP1 CRT 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 MFC 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 All 6195 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 CRT 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2005 SP1 x64 OpenMP 762 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime VS2008 x64 CRT 1 (x32 Version: 0 - Lattice Technology Co.,Ltd.) Hidden Runtime_MSI_VS2005_SP1_CRT_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFC_6195 (x32 Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_MFCLOC_6195 (x32 Version: 1.00.0000 - Lattice Technology) Hidden Runtime_MSI_VS2005_SP1_x64_CRT_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFC_6195 (Version: 1.00.0000 - Your Company Name) Hidden Runtime_MSI_VS2005_SP1_x64_MFCLOC_6195 (Version: 1.00.0000 - Lattice Technology) Hidden Saints Row IV (HKLM\...\Steam App 206420) (Version: - Deep Silver Volition) Samsung Drucker-Diagnose (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7 - Samsung Electronics Co., Ltd.) Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 2.01.05 (11.02.2015) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.0.0.65 - Samsung Electronics Co., Ltd.) Samsung Printer Center (HKLM-x32\...\Samsung Printer Center) (Version: 1.0.0.21 - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (x32 Version: 1.03.05.19 - Samsung Electronics Co., Ltd.) Hidden Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 3.31.79:03 - Samsung Electronics Co., Ltd.) SanDisk SSD Dashboard (HKLM-x32\...\SanDisk SSD Dashboard) (Version: 1.4.3 - Western Digital Corporation or its affiliates) SanDisk SSD Dashboard Service (HKLM-x32\...\{760A9A9B-238A-4EC2-ABFD-88F340D676BC}) (Version: 1.0.2 - SanDisk Corporation) SetIP (HKLM-x32\...\SetIP) (Version: 1.05.08.00 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden SketchUp-Import 2016-2017 (HKLM-x32\...\{063925DB-9D8C-48E2-8F04-1B7038B6C783}) (Version: 2.2.0 - Autodesk) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) SNS Upload for Easy Document Creator (HKLM-x32\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd) Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.16.7.201605041511 - Sony Mobile Communications Inc.) Sound Blaster Cinema 2 (HKLM-x32\...\{B4F6F8CC-2C61-42CC-A4CC-76621F25BDC7}) (Version: 1.00.07 - Creative Technology Limited) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Survarium (HKLM\...\Steam App 355840) (Version: - Vostok Games) TeamSpeak 3 Client (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Crew (Worldwide) (HKLM-x32\...\Uplay Install 413) (Version: - Ubisoft) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft) Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.8 - Samsung Electronics CO., LTD.) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{5D2260D6-DB16-41DC-915B-A39BF4F66362}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3141468) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CB85A0CF-0448-43D8-8006-173A8C84A018}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3141468) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CB85A0CF-0448-43D8-8006-173A8C84A018}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3141468) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CB85A0CF-0448-43D8-8006-173A8C84A018}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 23.0 - Ubisoft) Verfügbare Autodesk-Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) <==== ACHTUNG Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WibuKey Setup (WibuKey Remove) (HKLM\...\{00060000-0000-1004-8002-0000C06B5161}) (Version: Version 6.30b of 2014-Oct-29 (Build 1471) (Setup) - WIBU-SYSTEMS AG) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.30 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) Wireless Password Recovery (HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\WIFIPR) (Version: - Passcape) Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> E:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Alex\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{32CDFF57-8CBA-4960-89B1-EC3FA58FB17A}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppDocView.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxTest.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtCp.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxAppCtrl.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\UCxTextBtn.Ocx (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\SolidObject.Dll () CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\Inventor.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxApprenticeServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DtBridge.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\AcInetUI.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\RxInventorUtilities.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> E:\Program Files\Autodesk\AutoCAD 2017\de-DE\acadficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\TestServer.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvResc.dll (Autodesk) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\ServiceModule.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\InvTXTStack.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-844601699-3614358154-429673199-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> E:\Program Files\Autodesk\Inventor 2017\Bin\DTInterop.dll (Autodesk, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02905C77-3498-4D2F-A56F-E3B47EA4C231} - System32\Tasks\Avira Browser Safety Updater Task => C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe [2015-03-11] (Avira Operations GmbH & Co. KG) Task: {05E915CC-B891-4A8E-AC29-7C952B785C22} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {07A4F0D1-5BEF-4664-858C-4497576F806D} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-12-09] () Task: {0F516764-DEAF-400C-8691-DEE4AEC47730} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {24A13EA0-EBC9-427A-B8F0-D0D5D4F55AA7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {325AD40C-6C77-4CA5-8EFC-C31A99DA86FB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {35651DCE-DF69-49D6-9E0D-6A040F15E01B} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) Task: {43C7A03F-A873-4A39-8510-7824CE650051} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation) Task: {45255647-EFA0-4FCC-8C71-796086CBF11E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {5CCB9225-F2A7-4EE5-8D55-110FA6DD613B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {638082EF-0C1B-4166-BC60-675738B3412F} - System32\Tasks\AdobeAAMUpdater-1.0-Alex-PC-Alex => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {6866B6C9-A5AD-4D44-A6F8-41F6280510D4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe [2017-01-18] (Adobe Systems Incorporated) Task: {6CA7FD92-E9A3-48DC-99D8-12238875FD2B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {726DEEC1-0C13-4293-BE34-834EDD3F5B7F} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI) Task: {80C2ECA6-96DD-4CBC-82F2-F64315C630DE} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-12-13] (NVIDIA Corporation) Task: {821636C8-9030-4062-80E1-563635D59776} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-31] (Google Inc.) Task: {9F897098-581F-457B-8254-8C2B94EC77BE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation) Task: {A3F6DB31-0FDA-48CA-A31D-A28855F66463} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation) Task: {AFD4C4E1-9934-4DFB-9236-06A7BA16FA2E} - System32\Tasks\Opera scheduled Autoupdate 1451590946 => C:\Program Files (x86)\Opera\launcher.exe [2017-01-16] (Opera Software) Task: {BB8BE35E-1BD1-49ED-96C3-A4810FDEF630} - \AutoKMS -> Keine Datei <==== ACHTUNG Task: {C7D487D6-F163-4179-B9BF-E64EB67DB5EA} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {D594DE41-D2B2-4D16-80F2-D58F777EBD9A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-18] (Adobe Systems Incorporated) Task: {E09DBBF5-33F2-41F7-8369-159B25B179B0} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-06-15] (Micro-Star INT'L CO., LTD.) Task: {E1E08BC0-43A6-4589-A2DA-ED510EB3F1F1} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [2015-03-08] () Task: {E7FB3A92-28F8-448D-86BE-9077650866C1} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-25] (Dropbox, Inc.) Task: {FEBF9113-7489-4FC8-9DAC-E1372556C3CD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\MSIOSDx64_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe Task: C:\Windows\Tasks\MSIOSDx86_Host.job => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe Task: C:\Windows\Tasks\MSISW_Host.job => C:\Windows\SysWOW64\muachost.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\Alex\Desktop\Programme\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-05-11 12:56 - 2007-08-14 18:03 - 00022016 _____ () C:\Windows\System32\sst1cl6.dll 2016-03-13 16:46 - 2015-03-12 03:43 - 00022528 _____ () C:\Windows\System32\us003lm.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-06-22 18:05 - 2016-06-14 15:35 - 00187392 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\D3D11FontDraw.dll 2016-03-13 16:46 - 2015-09-10 20:31 - 01676592 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\us003du.dll 2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 01:07 - 2015-03-07 01:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-02-09 20:34 - 2016-02-09 20:34 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-09-08 12:39 - 2014-09-08 12:39 - 00464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2014-09-08 12:38 - 2014-09-08 12:38 - 00051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-01-02 20:48 - 2016-01-02 20:48 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe 2016-06-06 18:47 - 2016-05-01 08:38 - 00498488 ____N () C:\Windows\SysWOW64\spdsvc.exe 2016-06-06 18:43 - 2016-06-06 18:43 - 00143664 ____N () C:\Windows\SysWOW64\SecUPDUtilSvc.exe 2016-11-15 14:22 - 2016-12-11 19:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-03-08 14:54 - 2015-03-08 14:54 - 01328352 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe 2015-03-08 14:54 - 2015-03-08 14:54 - 03409632 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe 2016-06-22 18:05 - 2016-06-14 15:35 - 00163328 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\D3D11FontDraw.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2017-01-18 10:07 - 2016-08-31 20:04 - 00048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2015-12-31 19:33 - 2014-02-21 11:20 - 00074240 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2015-12-31 19:33 - 2014-02-21 11:17 - 00274944 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2017-01-24 18:00 - 2017-01-18 19:39 - 00801600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll 2016-03-25 12:02 - 2016-12-21 09:44 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2016-03-25 12:02 - 2016-12-21 09:44 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-03-25 12:02 - 2016-12-21 09:44 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-03-25 12:02 - 2017-01-18 19:42 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-03-25 12:02 - 2016-12-21 09:44 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-03-25 12:02 - 2016-12-21 09:45 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 01682768 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2017-01-24 18:00 - 2016-12-21 09:44 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-01-24 18:00 - 2016-12-21 09:45 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2017-01-24 18:00 - 2016-12-21 09:44 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-03-25 12:02 - 2016-12-21 09:46 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-08-06 21:06 - 2017-01-18 19:42 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00052032 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-01-24 18:00 - 2016-12-21 09:44 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-01-24 18:00 - 2016-12-21 09:46 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-03-25 12:02 - 2016-12-21 09:47 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-03-25 12:02 - 2017-01-18 19:42 - 00381760 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-08-06 21:06 - 2017-01-18 19:42 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-03-25 12:02 - 2016-12-21 09:47 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-08-06 21:06 - 2016-12-21 09:45 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-03-25 12:02 - 2016-12-21 09:47 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-03-25 12:02 - 2017-01-18 19:42 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-03-25 12:02 - 2016-12-21 09:45 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 01972536 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd 2016-03-25 12:02 - 2016-12-21 09:47 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-03-25 12:02 - 2017-01-18 19:42 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-01-24 18:00 - 2016-12-21 09:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-01-24 18:00 - 2017-01-18 19:42 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-01-24 18:00 - 2016-12-21 09:50 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2017-01-24 18:00 - 2016-12-21 09:50 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-01-24 18:00 - 2017-01-18 19:42 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-03-25 12:02 - 2016-12-21 09:46 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-08-06 21:06 - 2017-01-18 19:42 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-01-24 18:00 - 2017-01-18 19:42 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-06-06 18:50 - 2015-01-24 11:22 - 03029504 ____N () C:\Windows\system32\DlgSearchEngine.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-15 14:23 - 2016-12-13 00:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2017-01-20 12:49 - 2017-01-20 12:49 - 05737472 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\EasyPrinterManagerV2\3ba286b1681ae5b915864a7d2a966bd8\EasyPrinterManagerV2.ni.exe 2017-01-20 12:49 - 2017-01-20 12:49 - 00854528 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceIOWrapper\06a86c893af81de047d60ce1ac4a3d9a\DeviceIOWrapper.ni.dll 2015-03-08 14:52 - 2015-03-08 14:52 - 00494592 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\DeviceIOWrapper.dll 2015-01-05 13:12 - 2015-01-05 13:12 - 03650048 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\sf.dll 2015-01-05 13:12 - 2015-01-05 13:12 - 00300032 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\log4cplus.dll 2017-01-20 12:49 - 2017-01-20 12:49 - 00385536 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\NativeWrapper\3cc56c08666522a8a124e596557c1111\NativeWrapper.ni.dll 2015-03-08 14:52 - 2015-03-08 14:52 - 00183808 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\NativeWrapper.dll 2015-02-19 10:59 - 2015-02-19 10:59 - 04286464 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\DevSearchDlg.dll 2017-01-19 18:04 - 2017-01-19 18:04 - 68769880 _____ () C:\Program Files (x86)\Opera\42.0.2393.137\opera.dll 2017-01-19 18:04 - 2017-01-19 18:04 - 01895000 _____ () C:\Program Files (x86)\Opera\42.0.2393.137\libglesv2.dll 2017-01-19 18:04 - 2017-01-19 18:04 - 00087128 _____ () C:\Program Files (x86)\Opera\42.0.2393.137\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0816.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0817.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\DSC_0818.JPG:com.dropbox.attributes [220] AlternateDataStreams: C:\Users\Alex\Desktop\FHBC_2016-01-12_TEAM-3B_Fasel_Gebäudeklimatik_3_alex.pptx:com.dropbox.attributes [183] AlternateDataStreams: C:\Users\Alex\Desktop\Fräsdateien:com.dropbox.attributes [168] AlternateDataStreams: C:\Users\Alex\Desktop\WLC_Team3B.xlsx:com.dropbox.attributes [168] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Software\Classes\.scr: DWGTrueViewScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2017-01-24 20:55 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\Services: AdAppMgrSvc => 2 MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: dbupdate => 2 MSCONFIG\Services: dbupdatem => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: mitsijm2017 => 2 MSCONFIG\Services: MSI_LiveUpdate_Service => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: PSI_SVC_2_x64 => 2 MSCONFIG\Services: SanDisk SSD Dashboard Service => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: Sony PC Companion => 3 MSCONFIG\startupreg: ABNotify => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe -auto MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe MSCONFIG\startupreg: DAEMON Tools Lite Automount => "D:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: GammingApp => C:\Program Files (x86)\MSI\Gaming APP\SGamingApp.exe --min MSCONFIG\startupreg: Live Update => C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER MSCONFIG\startupreg: OneDrive => "C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background MSCONFIG\startupreg: PDFPrint => "C:\Program Files (x86)\PDF24\pdf24.exe" MSCONFIG\startupreg: RemoteMedia => C:\Program Files (x86)\MSI\Command Center\RemoteMedia.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Spotify => "C:\Users\Alex\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Alex\AppData\Roaming\Spotify\SpotifyWebHelper.exe" MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: Steam => "D:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: VLC Updater => C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 10 ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{4750EED5-6919-45A0-AF08-359CC0076FE6}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D96219C-8301-44E5-953D-283283E7ECE8}] => D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2594068C-343F-45A0-B63B-A62BF7BE6109}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{17446144-B74A-4606-B23A-1C189C8DC88A}] => D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{FC13B60E-B2CD-4613-B4D5-1561FF5C0117}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{8605CED7-70B5-4EF4-A5B2-FE2E89F161D1}D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => D:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [TCP Query User{EA9176A5-185D-416E-B6F9-75DCC8263276}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{B0C355E0-BADE-488A-8AAA-C0889BBAC615}D:\games\steam\common\counter-strike global offensive\csgo.exe] => D:\games\steam\common\counter-strike global offensive\csgo.exe FirewallRules: [{2D4A4BF4-5136-4465-A5B1-062152156216}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{609FC04D-F38E-4F2E-BD1A-A25D97854517}] => C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{0D496196-3EF6-4E0E-B2AD-B658519A69F7}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9EBCAD6C-18A2-4069-82E8-3B7CA430486E}] => C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{3815C750-D7D9-4D61-951F-DFA54724F5D9}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [UDP Query User{B290F1E3-1B27-40E2-9498-000F83BE3E39}D:\program files (x86)\origin games\battlefield 4\bf4.exe] => D:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [TCP Query User{FE4D4A70-D0EC-4213-9CFB-CF908E994DCE}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [UDP Query User{8925978B-51D2-4366-96DA-91CCCA86FFCA}D:\program files\call of duty black ops iii\blackops3.exe] => D:\program files\call of duty black ops iii\blackops3.exe FirewallRules: [TCP Query User{61F753EC-EAAC-42A8-824C-BDD987602F82}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [UDP Query User{E4300497-5118-417A-A3D3-2EB1F7298E46}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [TCP Query User{70CDEF17-711F-456B-98CB-A53300F01430}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [UDP Query User{0FD8297F-CAE6-43A0-BC94-09B833AFBCC4}C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe] => C:\users\alex\desktop\mbot_vsro110_1.24\mbot_vsro110.exe FirewallRules: [TCP Query User{1EC8A469-10A6-491B-90FF-87A554085014}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{D813B25E-13FC-42EF-9812-CEA6D36F4D9F}C:\program files\logitech gaming software\lcore.exe] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{F7F60636-E730-48B7-BBA8-45191CD3581E}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{917CBFED-C3AD-47EA-BF60-32ADE1F9F846}] => C:\program files\logitech gaming software\lcore.exe FirewallRules: [{5599EFEF-A071-4979-8997-AF2FE258BBD6}] => C:\Windows\system32\hasplms.exe FirewallRules: [TCP Query User{01BB30AF-E5D8-4C9A-BFBE-5F605C6130A7}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [UDP Query User{F31E0C4C-4214-4EA7-9EF7-6127DC71DEC1}C:\windows\twain_32\samsung\clx3170\sscan2io.exe] => C:\windows\twain_32\samsung\clx3170\sscan2io.exe FirewallRules: [{9560061A-74CB-425A-B62A-09CABB55046C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [{2B6D10B2-1FE5-4F03-B775-102CAF1CBE0C}] => C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [TCP Query User{53A8BFA1-4603-4BB8-BC56-0BC38253F567}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{5A93F2D2-FA0D-495A-8A32-B5006D66BEF4}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{49D98C3B-2A5E-4338-ABE0-F924B6BDD358}] => C:\Program Files (x86)\Samsung\Samsung Printer Center\SamsungPrinterCenter.exe FirewallRules: [{671F46D4-0D24-45E1-B61C-E64153E30CD5}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{14AFAADC-8385-47D0-8098-F0B336385812}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{998C9E6E-A42A-4D65-9B13-EF1DD03CFE85}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe FirewallRules: [{9FD2B1E5-2012-4AEE-93BD-4E8F8180603C}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{6F266D86-6B83-410D-80D5-7CDCF27031BE}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe FirewallRules: [{238B1E07-AF59-40FE-94F1-B424B7242E94}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe FirewallRules: [{C300BE33-DBA4-4C93-B64D-613DDB869137}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{8E98299E-9580-43C8-975C-6192C78E9213}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{BEF0B44F-037E-476F-BFA6-8C2C706FCA5B}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{4454CFB3-19BE-405A-90B4-BC705A0CB1BA}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{57AA4318-1F74-4080-AA39-0AF55ED35C19}] => C:\Program Files (x86)\Samsung\Samsung Universal Scan Driver\ScanCDLM.exe FirewallRules: [{EAC02C55-DB46-47D3-AE14-5FD27F82990F}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [{AF038FF8-ED4F-433F-9D43-497FDF85B06C}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDCApp.exe FirewallRules: [TCP Query User{05F95EF4-3FA5-4488-AA43-41AAA67F866B}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [UDP Query User{327CD24E-F107-416B-AA60-405B1F88B17C}C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe] => C:\program files (x86)\samsung\easy printer manager\easyprintermanagerv2.exe FirewallRules: [{46E616EF-3721-4155-B683-CB0555788B21}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{4E173E3B-562E-46CF-89BC-B90CBC5E4579}] => D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{DD361FB4-2DD0-4359-8613-498E04669C10}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{905E93C8-B3A8-4D6C-B4ED-CC16893C5A5D}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A60032BF-F733-4706-BE47-D0572603553F}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D41200A6-6C37-4320-A096-FB3B9B77D06A}] => H:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{D9AA500D-DED0-4C38-B29C-FBFFBB753BCF}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{D4F511F5-A3C0-4ACE-9887-29CCB2C1819A}H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => H:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{6D017BB6-214A-4372-AC51-79A0E0838D38}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{3E3D7043-688B-42F1-BD19-EFEE531CD7EB}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{9D43C6AA-622A-4807-8D85-07C4D8DECC1E}] => H:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{DED23947-28C4-4CB0-A3DD-6AB991D002CA}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{7A84FB57-2C5F-4AF1-98D1-CBAA810C5371}C:\users\alex\appdata\roaming\spotify\spotify.exe] => C:\users\alex\appdata\roaming\spotify\spotify.exe FirewallRules: [{581081D7-DE6D-45D1-B024-D42D884F35D5}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{009C2982-F3A9-476A-A6DD-E9BBEFD008C2}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy's Splinter Cell\system\SplinterCell.exe FirewallRules: [{7647EB15-3CF7-4C2D-BF74-C08E6C60CDAC}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{E67D201B-3D8F-415A-A46E-92FB5C4E6D60}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{9750BBA5-40A8-44F3-A4D9-5279F55675AF}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [{D851D20D-8592-4B90-90EC-C9601103100F}] => E:\Games\Tom Clancy's Rainbow Six Siege\RainbowSixGame.exe FirewallRules: [TCP Query User{44986407-2FDA-4D19-80D3-3E42B8633EC4}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [UDP Query User{85A8E48D-78B4-43AF-B77D-0A11F4CE797A}H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe] => H:\program files (x86)\xcom 2\binaries\win64\xcom2.exe FirewallRules: [{6FA9110C-F5F5-43FD-8AAD-97C37F81F712}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{FDDAE222-742C-4755-9036-CC91ADF1A4DC}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe FirewallRules: [{42A06F30-5633-4EC3-8516-22F6677C2947}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{D746E6BD-5966-46EA-B84D-3B9C3BC781C1}] => C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe FirewallRules: [{BB9E6EB6-A015-442E-841A-46B8D8981E0F}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{9FFCE39F-326C-4AA6-8A11-EA1980124981}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AAGame.exe FirewallRules: [{7C92A080-F2E6-471E-B71D-A4BFAFCBA865}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{0BFCBF4F-4452-4086-96B1-8A2D033DECEA}] => H:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\AALauncher32.exe FirewallRules: [{7F63544E-5F0F-4CE5-BC77-13090B2B752D}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [{0BB49C5F-0009-48E6-BB0D-947907C8CB77}] => H:\Program Files (x86)\Steam\steamapps\common\SKILL\Binaries\Win32\sf2.exe FirewallRules: [TCP Query User{75A0C3D7-376F-4E92-B796-39FB47CEA324}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [UDP Query User{550AA2BC-F80A-4AD6-A9A7-A6E4E59C6263}C:\program files (x86)\msi\gaming app\gamingapp.exe] => C:\program files (x86)\msi\gaming app\gamingapp.exe FirewallRules: [{9E8D188F-7A68-4CE1-AE50-776DAE4AC71B}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{97AB60CF-256B-4339-A041-C06A49483DAF}] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Worldwide)\TheCrew.exe FirewallRules: [{12A249D7-B9E5-417A-B4FF-0ED1519D3B57}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{D477E148-CA94-42B1-BDB5-4A107A21CF2C}] => H:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2 Demo\bin\win_x86\eurotrucks2.exe FirewallRules: [{5CFE4309-AE83-45A8-860D-A966B7A66F2E}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{383E1175-6B7C-4EAB-8592-581174AB387A}] => H:\Program Files (x86)\Steam\steamapps\common\rocketbirds_hardboiled\Game.exe FirewallRules: [{DC6CF8D7-022B-4BF1-A2D4-A01099710A8E}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{A8EDA4A9-1BB0-454F-851A-5C0A66C0935C}] => LPort=2869 FirewallRules: [{9076894C-96AF-4F79-9FC8-872941390765}] => LPort=1900 FirewallRules: [{982C83A7-E965-4A43-AC57-DED5418E1D86}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{34904A3E-2731-4BCA-99E7-0C522E19F596}] => H:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe FirewallRules: [{79A4CA0B-FAAD-4F1D-B690-53DCB685F3B7}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{6A68F600-EE62-4D35-A8FD-19C7FC858DD0}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe FirewallRules: [{7ED7E197-1394-431D-9A73-11AE6D10BEB9}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A9235B4D-7631-49AD-9E30-76937AC56F5E}] => H:\Program Files (x86)\Steam\steamapps\common\TacticalIntervention\bin\tacint.exe FirewallRules: [{A350EF63-8725-4AB3-B6BD-33D13DA5F134}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_launcher.exe FirewallRules: [{BDC16B40-7773-4E47-A4A0-23BD74170D09}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{D8AD6045-708F-4629-A4D3-642C3BD4F61F}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{75E6E119-7E57-400A-B104-24F8D32EDD90}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{6D166702-17D2-4E22-B532-DD814E55C422}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\temp\survarium_updater.exe FirewallRules: [{DA796ED4-9458-4BC1-95A0-AB6DD17FDCF5}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{176A26D4-1D56-44E4-9B84-4970448A6B21}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium.exe FirewallRules: [{56374166-7C69-44CF-9232-BAB7964BABCE}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{EDC2E8A6-CB4E-49CA-8B4F-F555651A914C}] => H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium-2.exe FirewallRules: [{80B41A04-E617-42B5-AFCB-5CA576D9FDBA}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{1D989B94-B275-455F-B721-1C10E62BE0BF}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{991023BE-281F-40DD-A22A-5FF97099B5CB}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{B79C5C21-ACA7-43F6-9284-D0ABD0C7F86D}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{BE7CB2A9-F20C-4BB0-87C0-644FD0CDA1D4}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{D720B6B9-0A35-42D0-85A5-EE9270EA03BB}] => LPort=8318 FirewallRules: [{B99A897A-B2C5-456B-B3D8-E0B80DAB2FBE}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelDrw.exe FirewallRules: [{699A2E63-2033-4335-A20F-1686EBD94622}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\Designer.exe FirewallRules: [{CB3411CB-51BD-4951-A168-022BAAA9C7CD}] => e:\Program Files\Corel\CorelDRAW Technical Suite X7\Programs64\CorelPP.exe FirewallRules: [{A8ECF176-6083-4C6C-898B-638185759074}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{200F9EE4-2BF0-4ADF-BF03-BE4E5C8E16A2}] => H:\Program Files (x86)\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{6DF521B4-51CF-4AB3-B0AB-71091788AF8C}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{518CE409-F02B-4BA8-B0E3-16AD4BD4E7D7}] => H:\Program Files (x86)\Steam\steamapps\common\Metro Last Light Redux\metro.exe FirewallRules: [{F78314FA-4E04-4C00-B620-F4342A39F389}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{A9141310-E430-48A0-A42E-EC596D66B4E8}] => H:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe FirewallRules: [{E8D911F0-75D3-49D6-811F-7773A97AF5E1}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{CB30BD9A-3C48-4EA5-8F44-A68289BC1E56}] => H:\Program Files (x86)\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{2E488689-B02A-48F2-9567-DA9848F1A6C5}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [{0A84CC58-F8C4-4E72-8EA1-3019C08D15AD}] => H:\Program Files (x86)\Steam\steamapps\common\Metro 2033 Redux\metro.exe FirewallRules: [TCP Query User{EDDD8DC6-81D9-43F6-A646-74F92961A6B5}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [UDP Query User{A7DE668B-1E28-4EFE-ACBC-61ACB822FA99}E:\games\call of duty - infinite warfare\iw7_ship.exe] => E:\games\call of duty - infinite warfare\iw7_ship.exe FirewallRules: [{BE76A0A7-9704-4FEE-8174-3305863BAC38}] => C:\Program Files\Autodesk\Desktop Connect\forever\node.exe FirewallRules: [{2BF5D8B6-6403-4A42-8E4A-E21A7420760A}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{2C7B2DC1-7504-4C82-9DA7-D17A3DCDE685}] => H:\Program Files (x86)\Steam\steamapps\common\Warface\live\gflauncher.exe FirewallRules: [{DF6B2F65-8DAE-4D51-A95E-6743F086EC2A}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{26765CDE-DB0B-447C-893B-51F1C501186B}] => H:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{BE3EF81A-2CD1-45DD-A071-275030320227}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{7ECE005B-97E3-4C60-A29D-BD5D20BBEF43}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{A3D9E1E0-C8EA-4E2E-8FE3-DD48267D9E7C}H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => H:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{12CAEE74-C739-431C-ABBF-82EA376E1535}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{6908C6EB-7521-4486-A71C-9A94CE4784F3}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\Launcher.exe FirewallRules: [{99122A42-4BB1-4FA9-8B82-DB47E74DE65F}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{0B6CE556-8917-4B14-BE1A-B94B057E5923}] => H:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{95D44447-AEB3-42E1-9812-FBA20C38F973}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{9705E715-8B84-4FB0-8761-6F399FEA9D5E}] => H:\Program Files (x86)\Steam\steamapps\common\Aperture Tag\portal2.exe FirewallRules: [{5E2D4D0F-96FA-4F7E-B60E-47B3927A85B2}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{A2BAFD1F-E6F8-42FA-9191-5E66E402272E}] => H:\Program Files (x86)\Steam\steamapps\common\Contagion\contagion.exe FirewallRules: [{E8BA2090-632A-40E1-9E5B-2219C72336AD}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [{4B563710-0FFB-4B58-8123-BF4948C0919B}] => H:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency.exe FirewallRules: [TCP Query User{CB0D4FD0-D3EF-4926-9FD3-8DF624B8DBFF}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{07CB26DB-BCA3-4241-A49C-B409B6F95D5F}H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => H:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{791ADF39-9F27-45E2-8361-5BDCF553233E}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{D13C0897-595A-403E-8BF6-4AB1772FC39D}] => H:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe FirewallRules: [{994C4074-9B2E-421D-826C-EFDBEE9BFD18}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{B2C64793-5BD9-45A1-87CF-F19EB0938603}] => H:\Program Files (x86)\Steam\steamapps\common\Half-Life A Place in the West\apw.exe FirewallRules: [{487A2954-09F0-495B-AA5E-BF44BC759183}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{63C63B5A-8D62-4FF6-AF78-5C7ED303AD27}] => H:\Program Files (x86)\Steam\steamapps\common\Age of Mythology\aomx.exe FirewallRules: [{761F89A9-0C19-472D-8EBE-9E27787C30FE}] => C:\Program Files (x86)\Opera\42.0.2393.137\opera.exe FirewallRules: [{CACB245A-BA30-42BC-82F3-BC5CD478E03C}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Wiederherstellungspunkte ========================= 18-01-2017 10:06:48 DVDVideoSoftRestorePoint 18-01-2017 11:05:03 Wiederherstellungsvorgang 18-01-2017 16:12:27 Malwarebytes Anti-Rootkit Restore Point 20-01-2017 12:38:39 Windows Update ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/24/2017 08:57:10 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/24/2017 08:56:52 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/24/2017 06:12:24 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/24/2017 06:12:06 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/24/2017 06:00:50 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/24/2017 06:00:50 PM) (Source: DbxSvc) (EventID: 270) (User: ) Description: Filter Unload failed with: (-2145452013) Der angegebene Filter wurde nicht gefunden. Error: (01/24/2017 05:58:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (01/24/2017 05:58:44 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) Das System kann die angegebene Datei nicht finden. Error: (01/21/2017 11:18:24 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: DevExpress.XtraTreeList.v15.1, Version=15.1.7.0, Culture=neutral, PublicKeyToken=b88d1754d700e49a . Error code = 0x8007000b Error: (01/21/2017 11:18:23 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: DevExpress.XtraTreeList.v15.1, Version=15.1.7.0, Culture=neutral, PublicKeyToken=b88d1754d700e49a . Error code = 0x8007000b Systemfehler: ============= Error: (01/24/2017 08:56:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/24/2017 08:55:53 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/24/2017 06:59:51 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (01/24/2017 06:12:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/24/2017 05:58:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/21/2017 12:31:53 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/21/2017 09:37:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/20/2017 04:26:02 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: Der Server "{EA022610-0748-4C24-B229-6C507EBDFDBB}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (01/20/2017 04:23:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert Error: (01/20/2017 04:05:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: Zugriff verweigert CodeIntegrity: =================================== Date: 2016-01-30 22:58:26.996 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.963 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.850 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-30 22:58:26.817 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\AIDA32 - Enterprise System Information\aida32.sa6" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.604 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 19:23:23.573 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.430 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 17:51:15.382 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-04 01:57:25.632 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: AMD FX(tm)-6300 Six-Core Processor Prozentuale Nutzung des RAM: 42% Installierter physikalischer RAM: 8156.29 MB Verfügbarer physikalischer RAM: 4660.27 MB Summe virtueller Speicher: 16310.77 MB Verfügbarer virtueller Speicher: 12236.71 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:223.37 GB) (Free:55.91 GB) NTFS Drive e: () (Fixed) (Total:277.17 GB) (Free:56.68 GB) NTFS Drive h: () (Fixed) (Total:277.17 GB) (Free:39.26 GB) NTFS Drive i: () (Fixed) (Total:100 GB) (Free:20.34 GB) NTFS Drive k: (Volume) (Fixed) (Total:277.08 GB) (Free:209.91 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6015DB08) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Active) - (Size=100 MB) - (Type=42) Partition 3: (Not Active) - (Size=100 GB) - (Type=42) Partition 4: (Not Active) - (Size=831.4 GB) - (Type=42) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 619C2244) Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=223.4 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
26.01.2017, 04:00 | #15 |
/// Malwareteam | Windows 7 3-4 Webseiten öffnen sich nach Opera start Schritt: 1 Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Hinweis: Falls bei der Deinstallation zu Beginn ein Fehler auftritt oder du den aufgerufenen Uninstaller nicht bedienen kannst, breche dieses Setup einfach ab und fahre mit der Entfernung durch Revo wie oben beschrieben fort. Schritt: 2 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter sexy.rachel84 ShortcutWithArgument: C:\Users\Alex\Desktop\Programme\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic Task: {BB8BE35E-1BD1-49ED-96C3-A4810FDEF630} - \AutoKMS -> Keine Datei <==== ACHTUNG emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt: 3 Bitte starte wieder FRST, setze den Haken bei Addition und drücke auf Untersuchen. Poste bitte wieder die beiden Textdateien, die so entstehen.
__________________ Mfg, Rafael ~ I'm storm. I'm calm. I'm fire. I'm ice. I'm burningice. ~ Unterstütze uns mit einer Spende ......... Lob, Kritik oder Wünsche ......... .......... Folge uns auf Facebook .......... |
Themen zu Windows 7 3-4 Webseiten öffnen sich nach Opera start |
antivirus, avira, bho, desktop, flash player, google, helper, hijack, hkus\s-1-5-18, homepage, installation, internet, internet explorer, logfile, mozilla, nvcontainer, problem, prozesse, realtek, registry, senden, software, super, svchost.exe, trojaner, trojaner board, un_a.exe, usb, windows |