![]() |
|
Log-Analyse und Auswertung: Wie werde ich "win32.downloader.gen" los?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Wie werde ich "win32.downloader.gen" los? Hi, SpyBot Search&Destroy hat auf meinem PC "win32.downloader.gen" gefunden. Avira und TDSSKiller hatten nichts gefunden. Würde mich freuen wenn mir jemand hilft, das wieder loszuwerden! Scan mit FRST ergab Folgendes: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017 durchgeführt von horton (Administrator) auf HORTON-PC (02-02-2017 12:42:35) Gestartet von C:\Users\horton\Desktop Geladene Profile: horton (Verfügbare Profile: horton & Ameise & der Erfinder) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 8 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Windows\System32\atwtusb.exe () C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe () C:\Windows\System32\atwtusb.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Windows\System32\WTMKM.exe (Safer Networking Limited) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe () C:\Users\horton\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (JME) C:\Program Files (x86)\jmesoft\hotkey.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (Lenovo) C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe (Lenovo) C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe (CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe () C:\Program Files (x86)\Lenovo\Lenovo EBook&QuickNotes\TMCMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\USB Vibration\7906\USB Gamepad.exe (Adobe Sytems Incorporated) C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Chip Digital GmbH) C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11057768 2010-07-06] (Realtek Semiconductor) HKLM\...\Run: [] => [X] HKLM\...\Run: [MacroKeyManager] => C:\Windows\system32\WTMKM.exe [6446312 2010-06-14] () HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [jmekey] => C:\Program Files (x86)\jmesoft\hotkey.exe [225280 2009-08-25] (JME) HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-16] (CyberLink Corp.) HKLM-x32\...\Run: [Lenovo Eye Distance System] => C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [264704 2010-07-08] (Lenovo) HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] => C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe [281088 2010-07-16] (Lenovo) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [TMCMonitor] => C:\Program Files (x86)\Lenovo\Lenovo EBook&QuickNotes\TMCMonitor.exe [53248 2009-11-09] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [917576 2016-12-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [USB Gamepad] => C:\Windows\USB Vibration\7906\USB Gamepad.exe [796784 2008-12-10] () HKLM-x32\...\Run: [Adobe Version Cue CS2] => c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064 2005-04-06] (Adobe Sytems Incorporated) HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2144088 2009-01-26] (Safer Networking Limited) HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\horton\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_192_Plugin.exe -update plugin HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [WLStart] => C:\Program Files (x86)\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation) HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2016-05-16] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2010-09-20] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) GroupPolicy\User: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{A6F2330F-3790-4172-B4B7-CE7317B8C6F6}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{DCDE01C2-B4BA-4B7A-BBDC-8B4FD2A8AAE7}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ URLSearchHook: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 SearchScopes: HKU\S-1-5-21-3064065677-2226785740-1792966077-1000 -> DefaultScope {271EF175-8711-4D5F-A69D-5130D0D13442} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=DE&q={searchTerms}&gu=5461d95f1c7a4557892446976248e913&tu=11Jiy00Ez1D13P0&sku=&tstsId=&ver=&&r=323 SearchScopes: HKU\S-1-5-21-3064065677-2226785740-1792966077-1000 -> {271EF175-8711-4D5F-A69D-5130D0D13442} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=DE&q={searchTerms}&gu=5461d95f1c7a4557892446976248e913&tu=11Jiy00Ez1D13P0&sku=&tstsId=&ver=&&r=323 BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-08] (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-11-01] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-08] (Oracle Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2014-04-22] (DVDVideoSoft Ltd.) BHO-x32: DVDVideoSoftTB DE Toolbar -> {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -> C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll [2011-05-09] (Conduit Ltd.) BHO-x32: Zonealarm Helper Object -> {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} -> C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.29.17\bh\zonealarm.dll => Keine Datei BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited) BHO-x32: Kein Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> Keine Datei BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14] (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-31] (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-11-01] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-31] (Oracle Corporation) BHO-x32: Windows Live Toolbar Helper -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06] (Microsoft Corporation) BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2014-04-30] (DVDVideoSoft Ltd.) Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06] (Microsoft Corporation) Toolbar: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll [2011-05-09] (Conduit Ltd.) Toolbar: HKLM-x32 - ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.29.17\zonealarmTlbr.dll Keine Datei Toolbar: HKU\S-1-5-21-3064065677-2226785740-1792966077-1000 -> Kein Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Keine Datei Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: fzwgi5ur.default FF ProfilePath: C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default [2017-02-02] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\fzwgi5ur.default -> DuckDuckGo FF Extension: (YouTube mp3) - C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default\Extensions\info@youtube-mp3.org.xpi [2016-04-27] FF Extension: (Save as PDF) - C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default\Extensions\save-as-pdf-ff@pdfcrowd.com.xpi [2016-04-28] FF Extension: (UnMHT) - C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default\Extensions\{f759ca51-3a91-4dd1-ae78-9db5eee9ebf0}.xpi [2016-11-28] FF Extension: (Diagnostics) - C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default\features\{f11a5f6e-61bd-4e13-8a98-44f23f361f4e}\diagnostics@mozilla.org.xpi [2017-02-02] FF Extension: (Send HSTS Priming Requests) - C:\Users\horton\AppData\Roaming\Mozilla\Firefox\Profiles\fzwgi5ur.default\features\{f11a5f6e-61bd-4e13-8a98-44f23f361f4e}\hsts-priming@mozilla.org.xpi [2017-02-02] FF HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: (Download videos and MP3s from YouTube) - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-07-18] [ist nicht signiert] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-23] () FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-08] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-08] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-23] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-10-31] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-31] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 -> C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll [2011-08-03] (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll [2012-08-02] (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3064065677-2226785740-1792966077-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\horton\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-04-23] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3064065677-2226785740-1792966077-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\horton\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=MCF6129E0-50C5-47DB-9195-25BD87B7A4AE&SearchSource=55&CUI=&UM=6&UP=SP484366AB-7A74-4877-98A7-BE92B29E4CCA&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=MCF6129E0-50C5-47DB-9195-25BD87B7A4AE&SearchSource=55&CUI=&UM=6&UP=SP484366AB-7A74-4877-98A7-BE92B29E4CCA&SSPV=" CHR DefaultSearchURL: Default -> hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=MCF6129E0-50C5-47DB-9195-25BD87B7A4AE&SearchSource=58&CUI=&UM=6&UP=SP484366AB-7A74-4877-98A7-BE92B29E4CCA&q={searchTerms}&SSPV= CHR DefaultSearchKeyword: Default -> trovi.search CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\gcswf32.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\ppGoogleNaClPluginChrome.dll => Keine Datei CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\pdf.dll => Keine Datei CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => Keine Datei CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll => Keine Datei CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll => Keine Datei CHR Profile: C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default [2017-02-02] CHR Extension: (YouTube) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-02] CHR Extension: (Google-Suche) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02] CHR Extension: (Avira Browserschutz) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-27] CHR Extension: (Amazon-Icon) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2014-03-13] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29] CHR Extension: (Google Mail) - C:\Users\horton\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29] CHR HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-07-18] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\horton\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2014-01-15] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2016-05-16] (Adobe Systems) [Datei ist nicht signiert] R2 Adobe Version Cue CS2; c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\VersionCueCS2.exe [163840 2005-04-06] (Adobe Systems Incorporated) [Datei ist nicht signiert] S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1089592 2016-12-15] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [476736 2016-12-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [476736 2016-12-15] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG) S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [Datei ist nicht signiert] R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [915232 2010-07-15] (Broadcom Corporation.) R2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2016-10-27] (Chip Digital GmbH) [Datei ist nicht signiert] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042032 2016-12-13] (Microsoft Corporation) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [391656 2016-07-22] (Digital Wave Ltd.) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert] S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R2 WTService; C:\Windows\System32\atwtusb.exe [907496 2010-06-14] () [Datei ist nicht signiert] S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X] S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 AFS; C:\Windows\SysWow64\Drivers\AFS.sys [77004 2016-08-31] (Oak Technology Inc.) [Datei ist nicht signiert] R3 ATIAVPCI; C:\Windows\System32\DRIVERS\atinavrr.sys [1557760 2010-03-26] (ATI Technologies Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG) S2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-06-02] (Avira Operations GmbH & Co. KG) S3 h647906; C:\Windows\System32\drivers\h647906.sys [62576 2008-12-01] (Your Corporation) S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [41096 2008-12-01] (Your Corporation) R0 johci; C:\Windows\System32\DRIVERS\johci.sys [23152 2010-01-15] (JMicron ) R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [7680 2009-03-08] (Windows (R) Codename Longhorn DDK provider) R3 NW1950; C:\Windows\System32\DRIVERS\NW1950.sys [26176 2010-08-06] () R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [7552 2009-08-26] (Windows (R) Win 7 DDK provider) R3 VMC412; C:\Windows\System32\Drivers\VMC412.sys [237568 2010-07-17] (Vimicro Corporation) R0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.) R0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-22] (Nicomsoft Ltd.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-02 12:42 - 2017-02-02 12:43 - 00030068 _____ C:\Users\horton\Desktop\FRST.txt 2017-02-02 12:42 - 2017-02-02 12:42 - 00000000 ____D C:\FRST 2017-02-02 12:22 - 2017-02-02 12:33 - 02420736 _____ (Farbar) C:\Users\horton\Desktop\FRST64.exe 2017-02-02 12:00 - 2017-02-02 12:08 - 00414016 _____ C:\TDSSKiller.3.1.0.12_02.02.2017_12.00.46_log.txt 2017-02-02 11:55 - 2017-02-02 11:57 - 00414150 _____ C:\TDSSKiller.3.1.0.12_02.02.2017_11.55.10_log.txt 2017-02-02 11:54 - 2017-02-02 11:54 - 00000000 ____D C:\Program Files (x86)\Chip Digital GmbH 2017-02-02 11:18 - 2017-02-02 11:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-02-02 08:47 - 2017-02-02 08:47 - 00000000 ____D C:\Program Files (x86)\TeaTimer (Spybot - Search & Destroy) 2017-02-02 08:47 - 2017-02-02 08:47 - 00000000 ____D C:\Program Files (x86)\File Scanner Library (Spybot - Search & Destroy) 2017-02-02 07:24 - 2017-02-02 07:24 - 00010473 _____ C:\Users\horton\Desktop\TJP e.V.*-*Bundesfreiwilligendienst.htm 2017-02-02 07:24 - 2017-02-02 07:24 - 00000000 ____D C:\Users\horton\Desktop\TJP e.V.*-*Bundesfreiwilligendienst-Dateien 2017-01-31 10:24 - 2017-01-31 10:24 - 00000000 ____D C:\Windows\pss 2017-01-26 14:31 - 2017-02-01 17:36 - 00000000 ____D C:\Users\horton\Desktop\umgang ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-02 12:39 - 2012-10-04 19:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-02-02 12:14 - 2016-12-03 11:42 - 00000000 ____D C:\Users\horton\AppData\LocalLow\Mozilla 2017-02-02 11:54 - 2012-11-20 21:55 - 00000000 ____D C:\Users\horton\AppData\Local\Downloaded Installations 2017-02-02 11:38 - 2009-07-14 05:45 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-02-02 11:38 - 2009-07-14 05:45 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-02-02 11:28 - 2009-07-14 03:34 - 00000742 _____ C:\Windows\win.ini 2017-02-02 11:27 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-02-02 11:20 - 2013-10-17 13:42 - 00007638 _____ C:\Users\horton\AppData\Local\Resmon.ResmonCfg 2017-02-02 11:18 - 2014-08-17 21:45 - 00000000 ____D C:\ProgramData\Package Cache 2017-02-02 10:59 - 2012-11-14 14:55 - 00000000 ____D C:\Program Files (x86)\Conduit 2017-02-02 08:39 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2017-02-02 08:04 - 2013-12-18 20:34 - 00000000 ____D C:\ProgramData\SecTaskMan 2017-02-01 14:13 - 2013-05-06 14:07 - 00000000 ____D C:\Users\horton\Desktop\WORK2DO 2017-02-01 14:11 - 2015-01-30 20:08 - 00000000 ____D C:\Users\horton\Desktop\Desktop aufräumen! 2017-02-01 10:57 - 2016-11-30 23:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-02-01 10:57 - 2016-01-21 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-01-31 10:13 - 2016-05-04 13:14 - 00000000 ____D C:\Users\horton\Desktop\SoSe2016 2017-01-31 10:11 - 2016-05-04 09:08 - 00000000 ____D C:\Users\horton\Desktop\Beppo 2017-01-31 10:07 - 2014-07-15 18:50 - 00000000 ____D C:\Users\horton\Desktop\uni 2017-01-31 09:28 - 2012-02-23 11:59 - 00000000 ____D C:\Users\horton\AppData\Roaming\vlc 2017-01-25 17:32 - 2016-11-18 16:02 - 00000000 ____D C:\Users\Ameise\AppData\LocalLow\Mozilla 2017-01-23 16:14 - 2015-11-29 18:58 - 00004090 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1448819900 2017-01-23 15:39 - 2012-10-04 19:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-23 15:39 - 2012-06-08 10:22 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-23 15:39 - 2012-03-18 04:26 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-23 15:39 - 2011-06-30 13:45 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-23 15:39 - 2010-09-20 13:39 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-23 15:05 - 2016-03-10 20:21 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-01-23 15:04 - 2016-01-21 09:58 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-01-18 16:33 - 2016-01-21 11:08 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-01-18 16:31 - 2016-01-21 11:05 - 00000000 ____D C:\Program Files\Microsoft Office 15 ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2013-05-22 12:03 - 2013-05-22 12:03 - 0000050 _____ () C:\Users\horton\AppData\Roaming\AcroIEHelpe.txt 2013-05-22 11:27 - 2013-05-22 11:27 - 0552126 _____ () C:\Users\horton\AppData\Roaming\dict.txt 2013-05-22 11:27 - 2013-05-22 11:27 - 0001466 _____ () C:\Users\horton\AppData\Roaming\jserv.txt 2013-05-22 11:58 - 2013-05-22 11:58 - 0000505 _____ () C:\Users\horton\AppData\Roaming\rost.dat 2013-05-22 11:27 - 2013-05-22 11:27 - 0000260 _____ () C:\Users\horton\AppData\Roaming\srvblck5.tmp 2016-05-12 07:12 - 2016-05-12 07:12 - 0002112 _____ () C:\Users\horton\AppData\Local\recently-used.xbel 2013-10-17 13:42 - 2017-02-02 11:20 - 0007638 _____ () C:\Users\horton\AppData\Local\Resmon.ResmonCfg 2011-11-10 10:40 - 2012-03-06 11:07 - 0000125 ___SH () C:\ProgramData\.zreglib 2010-09-20 13:39 - 2010-09-20 13:39 - 1914000 _____ (Adobe Systems Incorporated) C:\ProgramData\flashax10.exe 2016-07-21 18:00 - 2016-08-03 12:31 - 0000848 ___SH () C:\ProgramData\KGyGaAvL.sys Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\ProgramData\flashax10.exe Einige Dateien in TEMP: ==================== 2015-05-30 09:31 - 2015-05-30 09:31 - 0000000 ____D () C:\Users\Ameise\AppData\Local\Temp\avgnt.exe 2016-09-13 14:12 - 2016-09-13 14:12 - 0000000 ____D () C:\Users\der Erfinder\AppData\Local\Temp\avgnt.exe 2016-08-10 15:20 - 2016-07-04 01:08 - 0049544 _____ (HP Inc.) C:\Users\horton\AppData\Local\Temp\ACLMInstaller.exe 2013-12-02 12:11 - 2014-08-17 21:45 - 0000000 ____D () C:\Users\horton\AppData\Local\Temp\avgnt.exe 2016-07-21 17:29 - 2016-07-21 17:35 - 0008480 _____ (Corel Corporation) C:\Users\horton\AppData\Local\Temp\DRPCUNLR.dll 2012-09-20 02:15 - 2012-09-20 02:15 - 50352408 _____ (Microsoft Corporation) C:\Users\horton\AppData\Local\Temp\NetFramework45.exe 2016-07-10 07:14 - 2016-07-10 07:14 - 7424678 _____ () C:\Users\horton\AppData\Local\Temp\tmpA44A.tmp.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-11-20 01:49 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 29-01-2017 durchgeführt von horton (02-02-2017 12:43:49) Gestartet von C:\Users\horton\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2011-06-18 20:21:03) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3064065677-2226785740-1792966077-500 - Administrator - Disabled) Ameise (S-1-5-21-3064065677-2226785740-1792966077-1001 - Limited - Enabled) => C:\Users\Ameise der Erfinder (S-1-5-21-3064065677-2226785740-1792966077-1002 - Limited - Enabled) => C:\Users\der Erfinder Gast (S-1-5-21-3064065677-2226785740-1792966077-501 - Limited - Disabled) horton (S-1-5-21-3064065677-2226785740-1792966077-1000 - Administrator - Enabled) => C:\Users\horton ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: AntiVir Desktop (Enabled - Up to date) {090F9C29-64CE-6C6F-379C-5901B49A85B7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AntiVir Desktop (Enabled - Up to date) {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 1x1-Trainer 4 (HKLM-x32\...\1x1-Trainer) (Version: 4 - Hans-Jürgen Stoffels, Köln.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated) Adobe Creative Suite 2 (HKLM-x32\...\{0134A1A1-C283-4A47-91A1-92F19F960372}) (Version: - ) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.) Amazon Kindle (HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Amazon Kindle) (Version: - Amazon) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ArcSoft PhotoStudio Paint (HKLM-x32\...\{EC252D0D-C690-4CE7-BA07-23F4E00505BE}) (Version: 1.0.1.25 - ArcSoft) ATI Catalyst Install Manager (HKLM\...\{D6D18877-4A64-CE9E-1980-C1F414AC7F27}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.24.146 - Avira Operations GmbH & Co. KG) Avira Connect (HKLM-x32\...\{845380e2-f0b5-4584-bc40-cc54345b3c06}) (Version: 1.2.77.41287 - Avira Operations GmbH & Co. KG) Avira Connect (x32 Version: 1.2.77.41287 - Avira Operations GmbH & Co. KG) Hidden BCL easyConverter 3.0 Licensing Module (BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Loader SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Module (Loader, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 Module (RTF, BCL License) (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 RTF SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden BCL easyConverter 3.0 SDK Module (x32 Version: 3.0.18 - BCL Technologies) Hidden Bluetooth Notice (HKLM-x32\...\{4CC5AE2D-492D-4A21-9E99-1F46A7D4158B}) (Version: 2.0.00.07050 - Lenovo) Botanicula (HKLM-x32\...\Botanicula) (Version: 1.0 - Amanita Design, s.r.o.) ccc-core-static (x32 Version: 2010.0302.2233.40412 - Ihr Firmenname) Hidden chip 1-click download service (HKLM-x32\...\{503CA94E-0834-4CEE-AD92-BA17AF4E809A}) (Version: 3.6.9.0 - Chip Digital GmbH) Corel PDF Fusion - Creator (Version: 4.0.0 - Corel Corporation) Hidden Corel PDF Fusion - ICA (x32 Version: 1.12 - Corel Corporation) Hidden Corel PDF Fusion - Program (x32 Version: 1.14.0000 - Corel Corporation) Hidden Corel PDF Fusion - Setup (x32 Version: 1.12 - Corel Corporation) Hidden Corel PDF Fusion (HKLM-x32\...\_{5D62567F-38BA-4713-B87E-CF06C465E33B}) (Version: 1.14 - Corel Corporation) Corel Shell Extension - 64Bit (Version: 14.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Content (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Draw (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Extra Content (HKLM-x32\...\_{806422F8-8E0A-494A-A369-0F34F1B89160}) (Version: - Corel Corporation) CorelDRAW Essentials 4 - Extra Content (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Filters (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - ICA (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - IPM - No VBA (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang BR (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang DE (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang EN (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang ES (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang FR (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang IT (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Lang NL (x32 Version: 4.0 - Uw bedrijfsnaam) Hidden CorelDRAW Essentials 4 - PHOTO-PAINT (x32 Version: 4.0 - Corel Corporation) Hidden CorelDRAW Essentials 4 - Windows Shell Extension (HKLM-x32\...\_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}) (Version: - Corel Corporation) CorelDRAW Essentials 4 - Windows Shell Extension (x32 Version: 1.1 - Corel Corporation) Hidden CorelDRAW Essentials 4 (HKLM-x32\...\_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}) (Version: - Corel Corporation) CorelDRAW Essentials 4 (x32 Version: 4.0 - Corel Corporation) Hidden Curling (HKLM-x32\...\{369AAC15-34EF-4A1E-9090-29BEE38956F4}) (Version: 1.16.063010 - NTTC) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2716 - CyberLink Corp.) Dialang V1 Beta (HKLM-x32\...\{97DF4674-AB43-11D5-91C9-005004F84FA1}) (Version: - ) DriverInstall (x32 Version: 1.00.0000 - Genaitech) Hidden DVD Decrypter (Remove Only) (HKLM-x32\...\DVD Decrypter) (Version: - ) DVDVideoSoftTB DE Toolbar (HKLM-x32\...\DVDVideoSoftTB_DE Toolbar) (Version: 6.9.0.16 - DVDVideoSoftTB DE) EGR-ShellExtension (HKLM-x32\...\EGR-ShellExtension) (Version: 1.1.0.100 - EasternGraphics) Firework (HKLM-x32\...\{736DB9B0-D2BA-41DC-AACD-384A599B7D24}) (Version: 1.14.063010 - NTTC) Free Notes & Office Ink (HKLM-x32\...\{556F2137-B772-43BB-9A45-E0275234DD16}) (Version: - ) Funny Cube (HKLM-x32\...\{791708C1-0D84-4D05-88DC-A29EE9808270}) (Version: 1.17.063010 - NTTC) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Happy Hit (HKLM-x32\...\{A8BE86A1-7E0E-4814-80E5-6F4073B744F7}) (Version: 1.33.063010 - NTTC) HP Foto und Bildbearbeitung 1.0 - HP PSC - HP OfficeJet (HKLM-x32\...\PSC 2000 Series) (Version: - ) Idea Touch 3.0 (HKLM-x32\...\{70D6A420-AAC3-4213-9EF7-CDD6C16CCF2D}) (Version: 3.00.010.0816 - Lenovo) InterVideo WinDVD 8 (HKLM-x32\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0.20.197 - InterVideo Inc.) InterVideo WinDVD 8 (x32 Version: 8.0.20.197 - InterVideo Inc.) Hidden Janosch Tigerschule (HKLM-x32\...\{DB7DEBC2-8031-4186-A5C2-DAD6C823853C}) (Version: 1.00.0000 - Terzio Verlag) Janoschs neue Tigerschule (HKLM-x32\...\Janoschs neue Tigerschule) (Version: - ) Java 7 Update 67 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417067FF}) (Version: 7.0.670 - Oracle) Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle) Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JMicron 1394 Filter Driver (HKLM-x32\...\{13C96625-28E4-4c58-ADE0-CDAFC64752EB}) (Version: 1.00.09.00 - JMicron Technology Corp.) JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.44.1 - JMicron Technology Corp.) Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden LEGO Digital Designer (HKLM-x32\...\New LEGO Digital Designer) (Version: - LEGO A/S) Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.2600 - Broadcom Corporation) Lenovo Dynamic Brightness System (HKLM-x32\...\{D9ED6D06-6002-495E-A7BC-46E6AE386996}) (Version: 4.0.00.19161 - Lenovo) Lenovo EBook&QuickNotes (HKLM-x32\...\InstallShield_{63EA246F-3C4F-4809-B0DE-3738F99B34DD}) (Version: 1.0.3.9 - ArcSoft) Lenovo EBook&QuickNotes (x32 Version: 1.0.3.9 - ArcSoft) Hidden Lenovo Eye Distance System (HKLM-x32\...\{5183D7AB-D09B-411F-A74E-BBAEA61C6505}) (Version: 4.0.00.19080 - Lenovo) Lenovo Fun Zone (HKLM-x32\...\motiongame) (Version: 0.7.8.51 - Tose(Shanghai) Ltd.) Lenovo Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3720 - CyberLink Corp.) Lenovo Power2Go (x32 Version: 6.0.3720 - CyberLink Corp.) Hidden Lenovo Rescue System (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 3.0.1409 - CyberLink Corp.) Lenovo Rescue System (Version: 3.0.1409 - CyberLink Corp.) Hidden Lenovo Treiber- und Anwendungsinstallation (HKLM-x32\...\{45970CD1-D599-47D4-938F-3E9800D54ED1}) (Version: 5.10.1809 - Lenovo) Lenovo USB2.0 UVC Camera (HKLM-x32\...\{70D2C5B8-EB22-45B1-9EAA-5E8C1C408A3B}) (Version: 1.00.0000 - Vimicro Corporation) Lenovo VeriTouch 2.0 (HKLM-x32\...\InstallShield_{6A7F7465-284F-4299-8663-CDB496CEFA7D}) (Version: 2.0.1.9 - ArcSoft) Lenovo VeriTouch2.0 (x32 Version: 2.0.1.9 - ArcSoft) Hidden Lenovo_Wireless_Driver (HKLM-x32\...\{28ABE740-47F3-441B-9437-852F6A64EFF8}) (Version: 1.02.01 - Lenovo) LenovoModifyWindowStyle (HKLM-x32\...\{EBC41B09-E56D-421C-B3D0-84AC1103541B}) (Version: 1.00.0408 - Lenovo) LIMBO (HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\Limbo) (Version: - ) Link Up (HKLM-x32\...\{3DEDB107-2FCB-4544-844D-EC2878A9F22C}) (Version: 1.17.063010 - NTTC) LVT (HKLM-x32\...\{D3063097-EC84-4D21-84A4-9D852E974355}) (Version: 4.1.2.0423 - Lenovo) LXH-JME8002B Hotkey Driver (HKLM-x32\...\{29EA755D-404B-4310-872C-EB1B8513F9D6}) (Version: 5.0.0825 - Lenovo) Machinarium (HKLM-x32\...\Machinarium) (Version: - Daedalic Entertainment) MacroKey Manager (HKLM-x32\...\InstallShield_{66A4349A-AA55-43E5-A781-62867A701A90}) (Version: - ) MacroKey Manager (Version: 1.00.0000 - Ihr Firmenname) Hidden Mat5070Win7x64Drv (HKLM-x32\...\InstallShield_{884D18CB-F012-4F9D-9498-25D1E004DB87}) (Version: 6.14.10.396 - Geniatech) Mat5070Win7x64Drv (x32 Version: 6.14.10.396 - Geniatech) Hidden Media Go (HKLM-x32\...\{7A6C3344-5CF9-4B83-959C-6576C5B27D09}) (Version: 2.3.255 - Sony) Media Go Video Playback Engine 1.96.115.08260 (HKLM-x32\...\{065DBB54-6E55-A609-2E1E-F0617E827D53}) (Version: 1.96.115.08260 - Sony) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 15.0.4893.1002 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Proofing Tools 2013 - Español (HKLM\...\{90150000-001F-0C0A-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Research AutoCollage Touch 2009 (HKLM-x32\...\{1F8DA253-3C27-4B01-A63A-BA3533120833}) (Version: 2.00.2009 - Microsoft Research) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 51.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) MuseScore 1.2 MuseScore score typesetter (HKLM-x32\...\MuseScore) (Version: 1.2.0 - Werner Schweer and Others) Music Star (HKLM-x32\...\{E4FB9C8E-E965-4885-A4F8-8D2991AD4A36}) (Version: 1.35.063010 - NTTC) Music Star (x32 Version: 1.35.063010 - NTTC) Hidden NextWindow Drivers (HKLM\...\{0D765C2F-D317-4C25-9582-F669974FADA4}) (Version: 1.4.144 - NextWindow) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4893.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation) Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA) Opera Stable 37.0.2178.32 (HKLM-x32\...\Opera 37.0.2178.32) (Version: 37.0.2178.32 - Opera Software) pCon.planner 6.7 (HKLM-x32\...\pCon.planner 6.7) (Version: 6.7.0.102 - EasternGraphics) pCon.planner 6.7 (x32 Version: 6.7.0.102 - EasternGraphics) Hidden PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version: - ) PlayStation(R)Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.07.00849 - Sony Computer Entertainment Inc.) PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.12.6.14870 - Sony Computer Entertainment Inc.) PowerCinema (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 7.0.4308 - CyberLink Corp.) PowerCinema (x32 Version: 7.0.4308 - CyberLink Corp.) Hidden QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Readiris 7.5 (HKLM-x32\...\{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}) (Version: - ) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6151 - Realtek Semiconductor Corp.) Scrabble3D (HKLM-x32\...\{FF7B2746-9028-4784-B4E7-CC8CA67CF98D}) (Version: 3.1.4 - Heiko Tietze) Security Task Manager 1.8g (HKLM-x32\...\Security Task Manager) (Version: 1.8g - Neuber Software) Suite Specific (x32 Version: 2.0.0 - Adobe Systems, Incorporated) Hidden ThemeWallpaper (HKLM-x32\...\{F29CBF73-C211-4616-898A-379A2679F990}) (Version: 1.2.0.100706 - Lenovo) Tiny and Big - Grandpa's Leftovers (remove only) (HKLM-x32\...\Tiny and Big - Grandpas Leftovers) (Version: - ) tipptapp (HKLM-x32\...\tipptapp) (Version: 1.1 - UNKNOWN) tipptapp (x32 Version: 1.1 - UNKNOWN) Hidden Unity Web Player (HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\...\UnityWebPlayer) (Version: - Unity Technologies ApS) USB Network Joystick (HKLM-x32\...\{2A558A06-A44E-400D-95AD-D9FAA89AFD36}) (Version: V3.70a - ) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430) (HKLM\...\DE7217D2A8B057F15EC6E52329FDAB84231521E8) (Version: 04/08/2010 6.3.5.430 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom) Windows Live Anmelde-Assistent (HKLM-x32\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinRAR 4.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {04C5F25C-AAFA-492D-81D3-F2A3C7F99DC7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {06FE0C75-095D-4538-9652-1459AD205388} - System32\Tasks\{68C54E11-A282-461B-95D6-06C9D1E2DA94} => pcalua.exe -a C:\Users\horton\Desktop\dialang.exe -d C:\Users\horton\Desktop Task: {0B2FB6FB-5A3B-4553-91CA-5D4A0F147735} - System32\Tasks\{D6E62EA7-E2F5-4CA8-BF54-4E460763B5E2} => pcalua.exe -a D:\setup.exe -d D:\ Task: {184B24B0-6EEB-4954-99E5-36D978467C30} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation) Task: {1CF293F8-1AEA-4197-946C-92687175403F} - System32\Tasks\{736C63F3-D2A7-419C-8F26-4F75DB5FA8EE} => pcalua.exe -a C:\Users\horton\Desktop\cs2\CS2_RetNon_Ger_3.exe -d C:\Users\horton\Desktop\cs2 Task: {3B09AC67-7BFE-49D7-AD47-3AD780BF497F} - System32\Tasks\Opera scheduled Autoupdate 1448819900 => C:\Users\Ameise\AppData\Local\Programs\Opera\launcher.exe [2017-01-16] (Opera Software) Task: {3B289925-D629-4DFE-AE42-D9D95D4B4410} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {3EAB639C-2FC8-4064-98DD-4C85415019E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-23] (Adobe Systems Incorporated) Task: {448A37AB-EE09-4022-B1B2-E40C21C38283} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-11-01] (Microsoft Corporation) Task: {54200FB5-0D44-4CAA-98C9-708949FA1F09} - System32\Tasks\Opera scheduled Autoupdate 1418639019 => C:\Program Files (x86)\Opera\launcher.exe [2016-04-28] (Opera Software) Task: {65219F8A-790B-47DF-A54B-CEE1F484C54D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {661D22D4-FB9D-4D29-8177-BBA903971A83} - System32\Tasks\{9A441C31-2AC8-449A-98AD-3A8894ED1EB5} => pcalua.exe -a C:\Users\horton\Desktop\Beppo\cs2\CS_2.0_GR_Extras_1.exe -d C:\Users\horton\Desktop\Beppo\cs2 Task: {7BCEE2BE-4536-465C-9685-42B1C8CB5079} - System32\Tasks\{9F891BA6-C1FD-4436-8635-17892C96B09F} => pcalua.exe -a C:\Users\horton\Desktop\cs2\CS_2.0_GR_Extras_1.exe -d C:\Users\horton\Desktop\cs2 Task: {A6155A92-7CDC-49EE-BF19-BC640597705A} - System32\Tasks\{11BC33C9-6703-4868-A206-CC3820EC52EF} => pcalua.exe -a C:\Users\horton\Desktop\cs2\CS2_RetNon_Ger_2.exe -d C:\Users\horton\Desktop\cs2 Task: {AA7AF7A0-6DFC-429F-9B01-3F6FE6409F23} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation) Task: {C85FD0DE-8A35-454D-A55E-9C4A0DF07642} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.) Task: {CE94750F-6DB9-4D3E-8104-F4408AB635C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.) Task: {F7FB24F9-0C03-4DF3-9AD9-48BF1D996598} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-01-21 11:05 - 2016-05-24 08:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2010-06-14 13:27 - 2010-06-14 13:27 - 00907496 _____ () C:\Windows\System32\atwtusb.exe 2005-04-06 15:53 - 2005-04-06 15:53 - 03502080 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe 2010-06-14 13:27 - 2010-06-14 13:27 - 00907496 _____ () C:\Windows\system32\atwtusb.exe 2010-07-15 14:37 - 2010-07-15 14:37 - 00173344 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll 2012-02-09 14:01 - 2012-01-09 19:44 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2010-06-14 15:50 - 2010-06-14 15:50 - 06446312 _____ () C:\Windows\System32\WTMKM.exe 2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\horton\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe 2009-11-09 15:38 - 2009-11-09 15:38 - 00053248 _____ () C:\Program Files (x86)\Lenovo\Lenovo EBook&QuickNotes\TMCMonitor.exe 2015-12-25 01:18 - 2008-12-10 11:10 - 00796784 _____ () C:\Windows\USB Vibration\7906\USB Gamepad.exe 2010-04-23 14:29 - 2010-04-23 14:29 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-09-20 13:27 - 2010-09-20 13:27 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2005-04-06 15:52 - 2005-04-06 15:52 - 00028791 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\hpi.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00057453 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\verify.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00102515 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\java.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00053364 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\zip.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00057455 _____ () C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\net.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00032880 _____ () C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\jre\bin\nio.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 00434255 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\ps-rw-vc-v8_58.dll 2005-04-06 15:53 - 2005-04-06 15:53 - 01019904 _____ () c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\ps-vc-v8_58.dll 2014-07-18 11:12 - 2016-07-22 07:26 - 00114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2016-08-08 15:12 - 2016-07-22 07:24 - 00108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2016-08-08 15:12 - 2016-07-22 07:24 - 00024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2016-08-08 15:12 - 2016-07-22 07:24 - 00048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2010-09-20 13:31 - 2009-08-21 07:35 - 00032768 _____ () C:\Program Files (x86)\jmesoft\Keyhook.dll 2010-09-20 13:31 - 2009-08-21 08:27 - 00028672 _____ () C:\Program Files (x86)\jmesoft\hidhook.dll 2010-09-20 13:38 - 2010-07-08 13:52 - 00210432 _____ () C:\Program Files\Lenovo\Lenovo Eye Distance System\KeyStoneAdapter.dll 2010-09-20 13:38 - 2010-07-08 13:52 - 00211456 _____ () C:\Program Files\Lenovo\Lenovo Eye Distance System\VideoPlayer.dll 2010-09-20 13:39 - 2010-07-16 14:55 - 00210432 _____ () C:\Program Files\Lenovo\Lenovo Brightness System\KeyStoneAdapter.dll 2010-09-20 13:39 - 2010-07-16 14:55 - 00182272 _____ () C:\Program Files\Lenovo\Lenovo Brightness System\DDCHelperWraper.dll 2009-12-04 15:59 - 2009-12-04 15:59 - 00619816 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll 2009-12-04 16:04 - 2009-12-04 16:04 - 00013096 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3064065677-2226785740-1792966077-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\horton\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) mpsdrv => Firewall Dienst läuft nicht. MpsSvc => Firewall Dienst läuft nicht. bfe => Firewall Dienst läuft nicht. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^hp psc 2000 Series.lnk => C:\Windows\pss\hp psc 2000 Series.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^officejet 6100.lnk => C:\Windows\pss\officejet 6100.lnk.CommonStartup MSCONFIG\startupreg: Adobe Version Cue CS2 => "c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Share-to-Web Namespace Daemon => C:\Program Files (x86)\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{A4FB27FC-023D-4129-B1DE-FDF2B09061D5}] => C:\Program Files (x86)\Lenovo\PowerCinema\PowerCinema.exe FirewallRules: [{8A3B9C82-477B-497B-875D-47FB8BA0C12E}] => C:\Program Files (x86)\Lenovo\PowerCinema\PCMService.exe FirewallRules: [{9C02D370-9C54-4245-8D97-C3EF1807BD7B}] => C:\Program Files (x86)\Lenovo\PowerCinema\Kernel\DMP\CLBrowserEngine.exe FirewallRules: [{C31DDC86-21AB-47E0-888F-8DEF4FD5BE47}] => C:\Program Files (x86)\Lenovo\PowerCinema\Kernel\DMS\CLMSService.exe FirewallRules: [{C8468554-4EA9-4C9F-8262-671D36E9E99F}] => C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe FirewallRules: [{0516DDB6-8361-4C3B-91AD-478A20CF035E}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{034FFB5D-CBD4-4AC3-AE1F-6F182A2C1083}] => svchost.exe FirewallRules: [{6CA96BF6-9B90-44A9-AFD3-29CC3CB428E6}] => C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{BD3F27AF-F479-44D9-81F7-343CA3100C7D}] => C:\Program Files (x86)\Opera\opera.exe FirewallRules: [{590DF1F9-59A1-408A-A742-150E8DE4BC62}] => C:\Program Files (x86)\Opera\opera.exe FirewallRules: [TCP Query User{97B50266-2462-4C09-817D-46088F510B3D}C:\users\horton\appdata\local\temp\cprogram files (x86)opera\operaupgrader.exe] => C:\users\horton\appdata\local\temp\cprogram files (x86)opera\operaupgrader.exe FirewallRules: [UDP Query User{4D447EA7-4625-409F-B49C-29DA7B9C90C7}C:\users\horton\appdata\local\temp\cprogram files (x86)opera\operaupgrader.exe] => C:\users\horton\appdata\local\temp\cprogram files (x86)opera\operaupgrader.exe ==================== Wiederherstellungspunkte ========================= 20-11-2016 01:55:47 Geplanter Prüfpunkt 22-11-2016 14:10:20 Windows Update 02-02-2017 08:36:22 Removed BlueStacks Notification Center 02-02-2017 08:38:17 Removed BlueStacks Notification Center Überprüfen Sie den "winmgmt" Dienst oder reparieren Sie den WMI. ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Realtek PCIe GBE Family Controller #2 Description: Realtek PCIe GBE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (02/02/2017 08:11:43 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (02/02/2017 08:00:01 AM) (Source: RasClient) (EventID: 20227) (User: ) Description: CoID={5089AFC7-E689-4661-9467-5683F945F9F1}: Der Benutzer "horton-PC\horton" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 0. Error: (02/02/2017 07:07:26 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (02/01/2017 02:37:52 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (02/01/2017 10:59:25 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/30/2017 08:13:04 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/28/2017 11:50:58 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/26/2017 08:56:10 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/25/2017 04:24:45 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (01/24/2017 02:59:02 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Systemfehler: ============= Error: (02/02/2017 11:54:34 AM) (Source: Service Control Manager) (EventID: 7016) (User: ) Description: Der Dienst "chip 1-click download service" hat einen ungültigen aktuellen Status gemeldet: 0 Error: (02/02/2017 11:54:34 AM) (Source: Service Control Manager) (EventID: 7016) (User: ) Description: Der Dienst "chip 1-click download service" hat einen ungültigen aktuellen Status gemeldet: 0 Error: (02/02/2017 11:30:27 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Heimnetzgruppen-Listener" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147023143 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar.. Error: (02/02/2017 11:30:24 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: Dienst "WMPNetworkSvc" konnte nicht ordnungsgemäß gestartet werden, da ein Fehler "0x80004005" in "CoCreateInstance(CLSID_UPnPDeviceFinder)" aufgetreten ist. Überprüfen Sie, ob der Dienst "UPnPHost" ausgeführt wird und ob die Windows-Komponente "UPnPHost" richtig installiert ist. Error: (02/02/2017 11:29:56 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Avira Email-Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: Unzulässige Funktion. . Error: (02/02/2017 11:29:56 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "avnetflt" wurde aufgrund folgenden Fehlers nicht gestartet: In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar. Error: (02/02/2017 11:29:56 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: AFS Error: (02/02/2017 11:29:56 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Avira Email-Schutz" wurde nicht richtig gestartet. Error: (02/02/2017 11:27:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "ZoneAlarm Privacy Service" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/02/2017 11:27:27 AM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Der Dienst "SBSD Security Center Service" ist von folgendem Dienst abhängig: wscsvc. Dieser Dienst ist eventuell nicht installiert. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i3 CPU 550 @ 3.20GHz Prozentuale Nutzung des RAM: 60% Installierter physikalischer RAM: 4023.12 MB Verfügbarer physikalischer RAM: 1571.37 MB Summe virtueller Speicher: 8044.42 MB Verfügbarer virtueller Speicher: 4969.82 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:906.34 GB) (Free:656.73 GB) NTFS Drive d: (TippTapp) (CDROM) (Total:0.17 GB) (Free:0 GB) CDFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8D385642) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=906.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=25.1 GB) - (Type=12) ==================== Ende von Addition.txt ============================ |
Themen zu Wie werde ich "win32.downloader.gen" los? |
adobe, antivir, antivirus, computer, cpu, defender, firefox, flash player, home, homepage, mozilla, mp3, object, office 365, prozesse, realtek, registry, rundll, safer networking, security, services.exe, software, svchost.exe, system, temp, udp, windows |