|
Plagegeister aller Art und deren Bekämpfung: Adware in ChromeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
28.02.2017, 14:59 | #1 |
| Adware in Chrome Hallo liebe Leute, ich habe seit gestern unerwünschte Adware in Chrome (mein Hauptbrowser). Dies zeichnet sich dadurch aus, dass bestimmte Textbausteine in unerwünschte Links umgewandelt werden. Siehe hier: In diesem Fall sind Geldautomaten und Lederjacken die unerwünschten Links Hinzu kommt, dass sich relativ häufig Werbeseiten öffnen, wenn ich einen neuen Tab öffne und eine neue Seite aufrufe. Die Werbeseite wird dann im Ursprungsfenster geöffnet und die eigentliche Seite, die ich öffnen wollte, wird dann in einem neuen Tab geöffnet. Ich habe einen Zweitbrowser, Firefox, bei dem dieses Problem nicht auftritt. Komischerweise habe ich keine neuen Erweiterungen oder andere Sachen in den letzten Tagen installiert, deshalb kann ich mir nicht erklären, wie es zu diesem Problem gekommen ist. Als erste Instanz habe ich Malwarebytes Adwcleaner laufen lassen und alles entfernt, was dieses Programm gefunden hat, jedoch hat dies auch keine Abhilfe verschafft. Den Log kann ich gerne posten, falls es erwünscht ist. Ist dies ein bekanntes Problem, oder hat jemand eine Idee, wo der Ursprung dieses Problems sein könnte? Über Hilfe und Anregungen freue ich mich sehr und bedanke mich im Voraus schon mal ganz herzlich. LG Brettkopp Edit: Ich habe jetzt noch mal Malwarebytes Anti-Malware 2.2.1 durchlaufen lassen und 31 weitere potenziell gefährliche Dateien gefunden und entfernt. Leider hat sich das Problem dadurch noch nicht behoben |
28.02.2017, 17:53 | #2 |
/// TB-Ausbilder | Adware in ChromeMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Bitte die Logdatei von MBAM mit den Funden nachreichen. Zur ersten Analyse bitte FRST ausführen: Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Bitte poste mit deiner nächsten Antwort
|
28.02.2017, 20:45 | #3 |
| Adware in Chrome Hi Matthias, danke für deine Hilfe. Hier sind die gewünschten Logs.
__________________MBAM Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 28.02.2017 Suchlaufzeit: 14:20 Protokolldatei: MBAM.txt Administrator: Ja Version: 2.2.1.1043 Malware-Datenbank: v2017.02.28.06 Rootkit-Datenbank: v2017.02.27.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Username Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 347044 Abgelaufene Zeit: 21 Min., 7 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 5 Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\380b14beb7cb44d132a4a89ce089ea87, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\a8121016752761ffea4c707352975735, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Dateien: 28 PUP.Optional.Somoto, C:\Users\Username\AppData\Local\Temp\bitool.dll, In Quarantäne, [4313990f36722c0a6d6de591f70bd42c], PUP.Optional.OpenCandy, C:\Users\Username\AppData\Local\Temp\DTLite4481-0347.exe, In Quarantäne, [d680f6b21197ce68cd94e6437c888977], PUP.Optional.OpenCandy, C:\Users\Username\AppData\Local\Temp\DTLite4491-0356.exe, In Quarantäne, [76e0099f0f99fb3b80e143e6a55f6d93], Adware.DealPly.Generic, C:\Users\Username\AppData\Local\Temp\ns7402FA9C\2B476673_stp\setup.exe, In Quarantäne, [d1856246eabeef47513b5e8cc0409070], PUP.Optional.Babylon, C:\Users\Username\AppData\Local\Temp\is1070216317\128767833_stp\DeltaTB.exe, In Quarantäne, [a0b6c1e78a1e58de833b824629d88f71], PUP.Optional.WebConnect, C:\Users\Username\AppData\Local\Temp\is1070216317\128767945_stp\WebConnect.exe, In Quarantäne, [6de9baee9315a393dfc0dc218c77857b], PUP.Optional.SearchHijacker, C:\Users\Username\AppData\Local\Temp\is1201216051\4917F1FD_stp\June10_www.sweet-page.com.exe, In Quarantäne, [72e4bbed505893a3c9d1498228d93ec2], PUP.Optional.SearchHijacker, C:\Users\Username\AppData\Local\Temp\is1901864539\4917F1FD_stp\June10_www.sweet-page.com.exe, In Quarantäne, [f95d5e4aaff9fb3bb7e33c8f7e83d030], PUP.Optional.InstallCore, C:\Users\Username\AppData\Local\Temp\is961225091\MySearchDial.exe, In Quarantäne, [12445553adfb58de980fa5329968768a], PUP.Optional.BestToolBars, C:\Users\Username\AppData\Local\Temp\_ir_sf_temp_0\freecorder.ie.exe, In Quarantäne, [36203f69d9cf70c67f46d7f1738e7b85], PUP.Optional.DownloadSponsor, C:\Users\Username\Downloads\SpeedFan - CHIP-Installer.exe, In Quarantäne, [20366a3e7830d165d250e8c77789f20e], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\iufunzgtaoqzikud.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\dmr_72.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ivybfnlclegrktoc.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ivzcamuzgiahzddj.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\jnmqwxywrbkgzsjy.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\noyderfeqtfkxbjv.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\phffdkfzcxbstxax.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qmdovixnyaesxfsv.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qsfxqutuomyxoehz.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qxdbjwoztrhscchu.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\shjbrfccexjmjsku.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ycoteajccabonipd.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\yfjzdnbnsgyxzzpa.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\380b14beb7cb44d132a4a89ce089ea87\fdminst395.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\a8121016752761ffea4c707352975735\foobar2000_v1.3.7.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65], PUP.Optional.BundleInstaller, C:\Users\Username\AppData\Local\Temp\binsis142.xml, In Quarantäne, [4f0716923e6a51e59fccbd15946f42be], PUP.Optional.BundleInstaller, C:\Users\Username\AppData\Local\Temp\binsischeck654.xml, In Quarantäne, [afa744648b1d280eb0bce0f257ac60a0], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2017 01 durchgeführt von Username (Administrator) auf Username-PC (28-02-2017 19:48:05) Gestartet von C:\Users\Username\Downloads Geladene Profile: Username (Verfügbare Profile: Username) Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Windows\Runservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe () D:\Programme\CoreTemp\Core Temp.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited) C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe (Sophos Limited) C:\Program Files\Sophos\Sophos System Protection\ssp.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (CyberGhost S.R.L) C:\Program Files\CyberGhost 6\CyberGhost.Service.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (Disc Soft Ltd) D:\Programme\Daemon Tools Lite\DTLite.exe (Sync and Share NRW ) D:\Programme\sciebo\sciebo.exe (CyberGhost S.R.L.) C:\Program Files\CyberGhost 6\CyberGhost.exe (Dropbox, Inc.) C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (The OpenVPN Project) C:\Program Files\CyberGhost 6\Data\OpenVPN\openvpn.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (EJIE Technology) D:\Programme\clover\clover.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Don HO don.h@free.fr) D:\Programme\Notepad++\notepad++.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [8027016 2016-09-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43608 2000-01-01] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1480168 2017-02-02] (Sophos Limited) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [DAEMON Tools Lite] => D:\Programme\Daemon Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [Dropbox Update] => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-30] (Dropbox, Inc.) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [sciebo] => D:\Programme\sciebo\sciebo.exe [39619077 2016-10-06] (Sync and Share NRW ) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 6\CyberGhost.exe [1223728 2017-02-06] (CyberGhost S.R.L.) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: I - I:\setup.exe HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: {8a4cfe96-50ca-11e4-aed7-0025220fb9e5} - I:\setup.exe HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: {fa7931b5-1893-11e3-8ac7-0025220fb9e5} - I:\Install\Install.exe ShellIconOverlayIdentifiers: [ OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.) ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.) Startup: C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-02-27] ShortcutTarget: Dropbox.lnk -> C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited) Tcpip\Parameters: [DhcpNameServer] 185.156.172.178 185.93.180.131 83.143.245.42 Tcpip\..\Interfaces\{1864234F-DFB0-4F2E-8D6F-AE04B221BA35}: [NameServer] 185.156.172.178,185.93.180.131 Tcpip\..\Interfaces\{1864234F-DFB0-4F2E-8D6F-AE04B221BA35}: [DhcpNameServer] 185.156.172.178 185.93.180.131 83.143.245.42 Tcpip\..\Interfaces\{2521E38E-D27C-4323-9E3A-81AA7AEE3AD7}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{E1F97774-19F8-4258-812B-0606B2661549}: [NameServer] 185.156.172.178,185.93.180.131 Tcpip\..\Interfaces\{E1F97774-19F8-4258-812B-0606B2661549}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-27] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Programme\Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-27] (Oracle Corporation) BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> d:\programme\clover\TabHelper64.dll [2014-01-23] (EJIE Technology) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-27] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-27] (Oracle Corporation) Toolbar: HKLM - Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei Toolbar: HKLM-x32 - Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei Toolbar: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000 -> Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei FireFox: ======== FF DefaultProfile: lklm8bap.default FF ProfilePath: C:\Users\Username\AppData\Roaming\Mozilla\Firefox\Profiles\lklm8bap.default [2017-02-28] FF Homepage: Mozilla\Firefox\Profiles\lklm8bap.default -> hxxp://www.google.com FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Username\AppData\Roaming\Mozilla\Firefox\Profiles\lklm8bap.default\features\{1bae0e8a-aee3-4449-bec4-8c2f1265f06b}\disableSHA1rollout@mozilla.org.xpi [2017-02-26] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-14] () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-27] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-27] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> D:\PROGRA~1\Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.4 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Keine Datei] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [2014-04-10] (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-01-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3719417004-2107331891-2675601930-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-3719417004-2107331891-2675601930-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Username\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-01-23] (Unity Technologies ApS) StartMenuInternet: FIREFOX.EXE - D:\programme\Firefox\firefox.exe Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://search.disconnect.me/" CHR Session Restore: Default -> ist aktiviert. CHR Profile: C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default [2017-02-28] CHR Extension: (Simple Blocker) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\akfbkbiialncppkngofjpglbbobjoeoe [2016-08-22] CHR Extension: (Google Docs) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Google Drive) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22] CHR Extension: (YouTube) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-01] CHR Extension: (Google-Suche) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28] CHR Extension: (Google Docs Offline) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Inoreader - RSS, News and Social Reader) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhglljfmpijadbpkalkclnhlncncdono [2015-03-30] CHR Extension: (Disconnect Search) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmobfennjmjnkdbklhcnnfbhfibedgkk [2016-08-25] CHR Extension: (WEB.DE MailCheck) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2017-01-13] CHR Extension: (Disconnect) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-01-22] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19] CHR Extension: (Adult Blocker) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\onjjgbgnpbedmhbdoikhknhflbfkecjm [2017-02-25] CHR Extension: (Google Mail) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29] CHR Extension: (Chrome Media Router) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-28] CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1860616 2016-06-17] () R2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [76848 2017-02-06] (CyberGhost S.R.L) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [242960 2016-06-05] (EasyAntiCheat Ltd) R2 LicCtrlService; C:\Windows\runservice.exe [2560 2014-11-10] () [Datei ist nicht signiert] S3 Microsoft SharePoint Workspace Audit Service; D:\programme\Office\Office14\GROOVE.EXE [50942144 2013-12-18] (Microsoft Corporation) S3 Origin Client Service; D:\Spiele\Origin\OriginClientService.exe [2120712 2016-06-08] (Electronic Arts) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-10] () R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [229672 2016-10-25] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [200064 2016-10-25] (Sophos Limited) S2 SkypeUpdate; D:\programme\Skype\Updater\Updater.exe [315496 2014-12-11] (Skype Technologies) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [780424 2017-02-02] (Sophos Limited) R2 Sophos MCS Agent; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe [1379856 2016-12-01] (Sophos Limited) R2 Sophos MCS Client; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe [1805368 2016-12-01] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [360040 2016-09-13] (Sophos Limited) R2 SophosDataRecorderService; C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe [996240 2016-12-01] (Sophos Limited) R2 sophossps; C:\Program Files\Sophos\Sophos System Protection\ssp.exe [5366040 2016-12-01] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3644368 2016-09-13] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2121224 2016-09-13] (Sophos Limited) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-08-17] (Microsoft Corporation) S2 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 AsrVDrive; C:\Windows\System32\DRIVERS\AsrVDrive.sys [23048 2011-01-26] (ASRock Inc.) R3 DGUSBAP; C:\Windows\System32\DRIVERS\dgmbx2.sys [194864 2011-02-13] (Avid Technology, Inc.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-10] (Disc Soft Ltd) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49304 2014-12-29] (Visicom Media Inc.) R3 MBX2DFU; C:\Windows\System32\DRIVERS\dgmbx2fu.sys [32944 2011-02-13] (Avid Technology, Inc.) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (Visicom Media Inc.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 RT61; C:\Windows\System32\DRIVERS\rt61.sys [438784 2009-06-02] (Ralink Technology, Corp.) R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [201168 2016-09-13] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2016-09-13] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2016-09-13] (Sophos Limited) R0 Tpkd; C:\Windows\SysWow64\Drivers\Tpkd.sys [86528 2008-07-02] (PACE Anti-Piracy, Inc.) [Datei ist nicht signiert] R3 ALSysIO; \??\C:\Users\Username\AppData\Local\Temp\ALSysIO64.sys [X] <==== ACHTUNG S3 b06bdrv; \SystemRoot\system32\drivers\bxvbda.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S0 ignis; system32\DRIVERS\ignis.sys [X] U3 swmidi; kein ImagePath S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-28 19:48 - 2017-02-28 19:48 - 00032435 _____ C:\Users\Username\Downloads\FRST.txt 2017-02-28 19:47 - 2017-02-28 19:48 - 00000000 ____D C:\FRST 2017-02-28 19:47 - 2017-02-28 19:47 - 02423296 _____ (Farbar) C:\Users\Username\Downloads\FRST64.exe 2017-02-28 19:45 - 2017-02-28 19:46 - 00005913 _____ C:\Users\Username\Desktop\MBAM.txt 2017-02-28 15:56 - 2017-02-28 15:56 - 01496584 _____ C:\Users\Username\Downloads\Ad Aware Free Antivirus - CHIP-Installer.exe 2017-02-28 15:54 - 2017-02-28 15:54 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Username\Downloads\sh-remover.exe 2017-02-28 15:03 - 2017-02-28 15:03 - 00006525 _____ C:\Users\Username\Desktop\JRT.txt 2017-02-28 15:00 - 2017-02-28 15:00 - 01663040 _____ (Malwarebytes) C:\Users\Username\Downloads\JRT.exe 2017-02-28 14:19 - 2017-02-28 19:44 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-02-28 14:18 - 2017-02-28 14:18 - 00000731 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2017-02-28 14:18 - 2017-02-28 14:18 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-02-28 14:18 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2017-02-28 14:18 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-02-28 14:18 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-02-28 14:17 - 2017-02-28 14:18 - 22851472 _____ (Malwarebytes ) C:\Users\Username\Downloads\mbam-setup-2.2.1.1043.exe 2017-02-28 13:03 - 2017-02-28 13:43 - 00000000 ____D C:\AdwCleaner 2017-02-28 13:00 - 2017-02-28 13:01 - 04015056 _____ C:\Users\Username\Downloads\adwcleaner_6.043.exe 2017-02-27 21:00 - 2017-02-27 21:00 - 00000000 ____D C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-02-24 21:56 - 2017-02-24 21:56 - 00000000 ____D C:\Users\Username\Documents\BioshockHD 2017-02-24 21:56 - 2017-02-24 21:56 - 00000000 ____D C:\Users\Username\AppData\Roaming\BioshockHD 2017-02-17 21:33 - 2017-02-17 21:33 - 00000000 ____D C:\Users\Username\Documents\Avalanche Studios 2017-02-13 11:57 - 2016-10-25 21:15 - 00044304 _____ (Sophos Limited) C:\Windows\system32\SophosBootTasks.exe 2017-02-03 21:18 - 2017-02-03 21:18 - 00000000 ____D C:\Users\Username\AppData\LocalLow\U-Play online 2017-02-03 20:05 - 2017-02-03 20:05 - 00000000 ____D C:\Users\Public\Documents\Steam 2017-02-03 20:05 - 2017-02-03 20:05 - 00000000 ____D C:\Users\Username\Documents\U-Play online 2017-01-30 20:06 - 2017-01-30 20:06 - 00274896 _____ C:\Windows\Minidump\013017-39968-01.dmp ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-28 19:28 - 2014-01-16 20:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-02-28 18:55 - 2015-06-18 09:45 - 00001224 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000UA.job 2017-02-28 17:09 - 2016-12-02 23:41 - 00000000 ____D C:\Users\Username\AppData\LocalLow\Mozilla 2017-02-28 16:23 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-02-28 16:23 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-02-28 16:17 - 2013-09-08 16:33 - 00000000 ___RD C:\Users\Username\Dropbox 2017-02-28 16:15 - 2015-12-06 14:33 - 00000000 ____D C:\Users\Username\AppData\Local\sciebo 2017-02-28 16:15 - 2014-11-10 17:52 - 00000857 ___SH C:\Windows\SysWOW64\mmf.sys 2017-02-28 16:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-02-28 15:08 - 2016-12-05 14:44 - 00065536 _____ C:\Windows\system32\spu_storage.bin 2017-02-28 14:46 - 2015-12-06 14:34 - 00000000 ____D C:\Users\Username\sciebo 2017-02-28 14:44 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins 2017-02-27 21:00 - 2013-09-08 16:31 - 00000000 ____D C:\Users\Username\AppData\Roaming\Dropbox 2017-02-27 20:55 - 2015-06-18 09:45 - 00001172 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000Core.job 2017-02-26 00:03 - 2013-09-08 16:48 - 00000000 ____D C:\Users\Username\AppData\Roaming\vlc 2017-02-23 00:36 - 2016-12-02 21:09 - 00000000 ____D C:\Users\Username\AppData\Roaming\discord 2017-02-18 23:21 - 2014-02-13 01:47 - 00000000 ____D C:\Users\Username\Desktop\Musik smart 2017-02-14 16:28 - 2014-01-16 20:08 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-02-14 16:28 - 2014-01-16 20:08 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-02-14 16:28 - 2014-01-16 20:08 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-02-14 16:28 - 2014-01-16 20:08 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-02-14 16:28 - 2014-01-16 20:07 - 00000000 ____D C:\Windows\system32\Macromed 2017-02-13 11:57 - 2016-12-01 20:28 - 00000000 ____D C:\ProgramData\Sophos 2017-02-02 00:35 - 2013-09-08 15:21 - 00002187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-30 20:06 - 2014-05-14 22:20 - 762790477 _____ C:\Windows\MEMORY.DMP 2017-01-30 20:06 - 2014-05-14 22:20 - 00000000 ____D C:\Windows\Minidump ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2014-05-29 23:26 - 2013-09-21 11:42 - 0012005 _____ () C:\Users\Username\AppData\Roaming\alsoft.ini 2013-10-05 21:35 - 2017-01-26 18:56 - 0000016 _____ () C:\Users\Username\AppData\Roaming\msregsvv.dll 2006-12-11 18:13 - 2006-12-11 18:13 - 0097336 _____ (Un4seen Developments) C:\Users\Username\AppData\Local\bass.dll 2006-12-11 18:13 - 2006-12-11 18:13 - 0013872 _____ (Un4seen Developments) C:\Users\Username\AppData\Local\basscd.dll 2007-08-13 16:46 - 2007-08-13 16:46 - 0102912 _____ (Albert L Faber) C:\Users\Username\AppData\Local\CDRip.dll 2007-08-13 16:46 - 2007-08-13 16:46 - 0155136 _____ () C:\Users\Username\AppData\Local\lame_enc.dll 2007-01-18 20:09 - 2007-01-18 20:09 - 0623616 _____ (Ivan Bischof ©2003 - 2005) C:\Users\Username\AppData\Local\No23 Recorder.exe 2005-08-23 21:34 - 2005-08-23 21:34 - 0029184 _____ () C:\Users\Username\AppData\Local\no23xwrapper.dll 2006-10-26 00:06 - 2006-10-26 00:06 - 0015872 _____ () C:\Users\Username\AppData\Local\ogg.dll 2013-10-05 23:19 - 2016-05-08 13:24 - 0001475 _____ () C:\Users\Username\AppData\Local\RecConfig.xml 2006-10-26 00:06 - 2006-10-26 00:06 - 0143872 _____ () C:\Users\Username\AppData\Local\vorbis.dll 2006-10-26 00:06 - 2006-10-26 00:06 - 0064000 _____ () C:\Users\Username\AppData\Local\vorbisenc.dll 2006-10-26 00:06 - 2006-10-26 00:06 - 0019456 _____ () C:\Users\Username\AppData\Local\vorbisfile.dll 2016-09-20 21:21 - 2016-09-20 21:21 - 0026834 _____ () C:\ProgramData\agent.1474402891.bdinstall.bin 2016-12-01 09:30 - 2016-12-01 09:30 - 0028751 _____ () C:\ProgramData\agent.1480580983.bdinstall.bin 2013-10-05 21:35 - 2016-08-24 22:23 - 0000016 _____ () C:\ProgramData\autobk.inc Einige Dateien in TEMP: ==================== 2015-07-09 11:12 - 2015-07-09 11:13 - 250329200 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\amd-catalyst-15.7-without-dotnet45-win7-64bit.exe 2016-05-04 18:39 - 2016-05-04 18:39 - 1138176 _____ () C:\Users\Username\AppData\Local\Temp\AMDCleanupUtility.exe 2015-07-09 11:11 - 2014-12-05 13:43 - 6245888 _____ (Advanced Micro Devices, Inc.) C:\Users\Username\AppData\Local\Temp\AutoDetectUtilApp.exe 2016-05-04 18:39 - 2016-05-04 18:39 - 0232960 _____ () C:\Users\Username\AppData\Local\Temp\Cleanup.dll 2013-09-10 23:25 - 2013-09-10 23:25 - 0036864 _____ () C:\Users\Username\AppData\Local\Temp\CmdLineExt02.dll 2016-05-04 18:39 - 2016-05-04 18:39 - 0065536 _____ (Windows (R) Server 2003 DDK provider) C:\Users\Username\AppData\Local\Temp\ddu.exe 2016-05-04 18:39 - 2016-05-04 18:39 - 0414152 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\difxapi.dll 2015-12-11 10:23 - 2015-12-11 10:23 - 0071168 _____ () C:\Users\Username\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptqjwjq.dll 2013-02-11 14:08 - 2013-02-11 14:08 - 18722816 _____ () C:\Users\Username\AppData\Local\Temp\dsp_ipp.dll 2016-05-13 14:21 - 2016-11-30 20:50 - 0692072 _____ (Disc Soft Ltd.) C:\Users\Username\AppData\Local\Temp\DTLiteInstaller.exe 2015-12-17 01:55 - 2015-12-17 01:55 - 0000000 _____ () C:\Users\Username\AppData\Local\Temp\GURA208.exe 2014-12-14 12:55 - 2014-12-14 12:55 - 0079736 _____ (AppWork GmbH) C:\Users\Username\AppData\Local\Temp\JDSetup130630317136337890.exe 2014-04-15 21:50 - 2014-04-15 21:50 - 0921512 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe 2014-07-28 06:15 - 2014-07-28 06:15 - 0918440 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe 2017-01-18 02:56 - 2017-01-18 02:56 - 0739904 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u121-windows-au.exe 2015-06-12 23:21 - 2015-06-12 23:21 - 0563808 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u51-windows-au.exe 2015-09-27 09:50 - 2015-09-27 09:50 - 0585824 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u60-windows-au.exe 2016-04-20 01:56 - 2016-04-20 01:56 - 0739904 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u91-windows-au.exe 2016-05-04 18:39 - 2016-05-04 18:39 - 0516096 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcm80.dll 2016-05-04 18:39 - 2016-05-04 18:39 - 1061376 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcp80.dll 2016-05-04 18:39 - 2016-05-04 18:39 - 0796672 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcr80.dll 2014-06-04 17:42 - 2014-06-04 17:42 - 7643919 _____ () C:\Users\Username\AppData\Local\Temp\npp.6.6.3.Installer.exe 2014-06-27 12:20 - 2014-06-27 12:20 - 7674224 _____ () C:\Users\Username\AppData\Local\Temp\npp.6.6.7.Installer.exe 2010-03-17 11:28 - 2010-03-17 11:28 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00000.exe 2013-07-25 15:00 - 2013-07-25 15:00 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00001.exe 2013-07-25 15:00 - 2013-07-25 15:00 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00002.exe 2013-10-11 20:06 - 2013-10-11 20:06 - 0010752 _____ () C:\Users\Username\AppData\Local\Temp\PlaySound.dll 2016-04-29 15:17 - 2005-04-02 14:39 - 0207360 ____N () C:\Users\Username\AppData\Local\Temp\proccheck.exe 2017-02-24 21:49 - 2017-02-24 21:49 - 0040448 ____N () C:\Users\Username\AppData\Local\Temp\proxy_vole6036383075944681149.dll 2016-05-04 18:49 - 2016-05-04 18:49 - 12955000 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\radeon-crimson-16.3.2-minimalsetup.exe 2016-02-03 22:28 - 2016-02-03 22:29 - 61022664 _____ () C:\Users\Username\AppData\Local\Temp\raptrpatch.exe 2016-02-03 22:28 - 2016-02-03 22:28 - 0221632 _____ () C:\Users\Username\AppData\Local\Temp\raptr_stub.exe 2016-12-16 17:34 - 2016-12-16 17:34 - 0192512 _____ () C:\Users\Username\AppData\Local\Temp\sfamcc00001.dll 2015-02-10 18:56 - 2015-02-10 18:56 - 0105984 _____ () C:\Users\Username\AppData\Local\Temp\sfextra.dll 2015-04-13 23:14 - 2010-01-05 14:20 - 0088576 _____ (SkinSharp Inc.) C:\Users\Username\AppData\Local\Temp\Skin.dll 2016-04-29 14:33 - 2005-11-01 01:48 - 6711633 ____N () C:\Users\Username\AppData\Local\Temp\syncrosoftlicensecontrolsetup.exe 2015-08-05 22:02 - 2015-08-05 22:04 - 250446120 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\tmp43E0.exe 2016-02-03 22:00 - 2016-02-03 22:06 - 263289648 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\tmpEEB4.exe 2014-01-13 21:09 - 2015-04-18 08:06 - 0064358 _____ () C:\Users\Username\AppData\Local\Temp\Uninstall.exe 2013-11-28 01:10 - 2013-11-28 01:11 - 23679700 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.1-win64.exe 2014-01-18 16:07 - 2014-01-18 16:07 - 23884615 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.2-win64.exe 2014-03-24 20:14 - 2014-03-24 20:14 - 25055851 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.4-win64.exe 2014-08-17 14:04 - 2014-08-17 14:04 - 25611537 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.5-win64.exe 2012-11-02 10:08 - 2012-11-02 10:08 - 0118784 _____ () C:\Users\Username\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-02-22 18:39 ==================== Ende von FRST.txt ============================ |
28.02.2017, 20:46 | #4 |
| Adware in Chrome Addition: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 27-02-2017 01 durchgeführt von Username (28-02-2017 19:49:14) Gestartet von C:\Users\Username\Downloads Windows 7 Ultimate Service Pack 1 (X64) (2013-09-08 13:52:58) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3719417004-2107331891-2675601930-500 - Administrator - Disabled) Username (S-1-5-21-3719417004-2107331891-2675601930-1000 - Administrator - Enabled) => C:\Users\Username Gast (S-1-5-21-3719417004-2107331891-2675601930-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-3719417004-2107331891-2675601930-1002 - Limited - Enabled) SophosSAUUsername-PCaaa (S-1-5-21-3719417004-2107331891-2675601930-1007 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Sophos Home (Enabled - Up to date) {FFADE7EA-DC92-4602-D6B2-626CD3450A0F} AS: Sophos Home (Enabled - Up to date) {44CC060E-FAA8-498C-EC02-591EA8C240B2} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Age of Empires II: HD Edition (HKLM\...\Steam App 221380) (Version: - Skybox Labs) AirPlus G DWL-G510 (HKLM-x32\...\{8B128562-681D-4FFA-BEBF-A825985B2CB9}) (Version: 1.0.24 - D-Link) alien_crossfire (HKLM\...\{fa451eea-8a73-486b-9ea0-9628c2c2c3ad}.sdb) (Version: - ) alpha_centauri (HKLM\...\{fe81cd48-2ed2-4e7d-886c-b65767350095}.sdb) (Version: - ) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) Anki (HKLM-x32\...\Anki) (Version: - ) Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach) Avid Mbox 2 USB Drivers (x64) (HKLM\...\{F9242D4E-09E7-45C7-A53A-83375D0FAD42}) (Version: 9.0.2 - Avid Technology, Inc.) Barony (HKLM\...\Steam App 371970) (Version: - Turning Wheel LLC) Battle Brothers (HKLM\...\Steam App 365360) (Version: - Overhype Studios) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) Bejeweled 3 (HKLM\...\Steam App 78000) (Version: - PopCap Games, Inc.) BioShock Remastered (HKLM\...\Steam App 409710) (Version: - 2K Boston) Blackwell Convergence (HKLM-x32\...\Steam App 80350) (Version: - Wadjet Eye Games) Blackwell Deception (HKLM-x32\...\Steam App 80360) (Version: - Wadjet Eye Games) Blackwell Unbound (HKLM-x32\...\Steam App 80340) (Version: - Wadjet Eye Games) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.66.1075 - AB Team, d.o.o.) calibre 64bit (HKLM\...\{C50C44CA-48EE-4052-B629-6413080A0DDD}) (Version: 2.63.0 - Kovid Goyal) Card Hunter (HKLM-x32\...\Steam App 293260) (Version: - Blue Manchu) Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform) Clover 3.0 (HKLM-x32\...\Clover) (Version: 3.0 - EJIE Technology) Cook, Serve, Delicious! (HKLM\...\Steam App 247020) (Version: - Vertigo Gaming Inc.) Counter-Strike: Global Offensive - SDK (HKLM-x32\...\Steam App 745) (Version: - ) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Crusader Kings II (HKLM-x32\...\Steam App 203770) (Version: - Paradox Development Studio) CyberGhost 6 (HKLM\...\CyberGhost 6_is1) (Version: - CyberGhost S.R.L.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version: - FromSoftware) DayZ (HKLM\...\Steam App 221100) (Version: - Bohemia Interactive) Discord (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Divinity: Original Sin (HKLM-x32\...\Steam App 230230) (Version: - Larian Studios) Dota 2 (HKLM\...\Steam App 570) (Version: - Valve) Dr. Langeskov, The Tiger, and The Terribly Cursed Emerald: A Whirlwind Heist (HKLM-x32\...\Steam App 409160) (Version: - Crows Crows Crows) Dropbox (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Dropbox) (Version: 20.4.19 - Dropbox, Inc.) EAC eSports (HKLM\...\Steam App 282660) (Version: - EasyAntiCheat Ltd) Elevayta Extra Boy v4.91d VST (HKLM-x32\...\Elevayta Extra Boy v4.91d VST) (Version: - ) Endless Legend (HKLM-x32\...\Steam App 289130) (Version: - AMPLITUDE Studios) Endless Space (HKLM\...\Steam App 208140) (Version: - AMPLITUDE Studios) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Europa Universalis IV (HKLM-x32\...\Steam App 236850) (Version: - Paradox Development Studio) Exifer (HKLM-x32\...\Exifer_is1) (Version: - Friedemann Schmidt) F.E.A.R. (HKLM-x32\...\Steam App 21090) (Version: - Monolith Productions, Inc.) F1 2014 (HKLM\...\Steam App 226580) (Version: - Codemasters) Female Voice Pack (HKLM-x32\...\{D947A225-8C23-4E52-866E-CF3967476BFC}) (Version: 3.3.2 - Screaming Bee) FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts) Firewatch (HKLM-x32\...\Firewatch_is1) (Version: - ) Fistful of Frags (HKLM-x32\...\Steam App 265630) (Version: - Fistful of Frags Team) FlowStone FL 3.0 (HKLM-x32\...\FlowStone) (Version: - ) Fotogalerie (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free 3GP Video Converter version 5.0.30.1029 (HKLM-x32\...\Free 3GP Video Converter_is1) (Version: 5.0.30.1029 - DVDVideoSoft Ltd.) FTL: Faster Than Light (HKLM\...\Steam App 212680) (Version: - Subset Games) GameRanger (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\GameRanger) (Version: - GameRanger Technologies) Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios) Geeks3D FurMark 1.15.2.2 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) Gemini Rue (HKLM-x32\...\Steam App 80310) (Version: - Joshua Neurnberger) Gods Will Be Watching (HKLM\...\Steam App 274290) (Version: - Deconstructeam) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Guacamelee! Gold Edition (HKLM-x32\...\Steam App 214770) (Version: - DrinkBox Studios) Hard West (HKLM\...\Steam App 307670) (Version: - CreativeForge Games) Heroes of Might and Magic 3 Complete (HKLM-x32\...\Heroes of Might and Magic 3 Complete_is1) (Version: - GOG.com) Hitman: Absolution (HKLM\...\Steam App 203140) (Version: - IO Interactive) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - Dennaton Games) Insurgency (HKLM-x32\...\Steam App 222880) (Version: - New World Interactive) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Interlok driver setup x64 (HKLM\...\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.9.0 - PACE Anti-Piracy, Inc.) Invisible, Inc. (HKLM-x32\...\Steam App 243970) (Version: - Klei Entertainment) Java 8 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation) Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation) JdH's CiV MP Mod Manager (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\c03cf9dfba141d40) (Version: 1.0.7.10 - JdH's CiV MP Mod Manager) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.65.11 - JMicron Technology Corp.) Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) Life Is Strange™ (HKLM\...\Steam App 319630) (Version: - DONTNOD Entertainment) Logitech Gaming Software 8.50 (HKLM\...\Logitech Gaming Software) (Version: 8.50.281 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - Klei Entertainment) Master of Orion 1 and 2 (HKLM-x32\...\GOGPACKMASTEROFORION12_is1) (Version: 2.0.0.16 - GOG.com) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) MixMeister BPM Analyzer 1.0 (HKLM-x32\...\MixMeister BPM Analyzer_is1) (Version: - MixMeister Technology LLC) MorphVOX Pro (HKLM-x32\...\{2D7CF073-6583-464A-84D4-F86DE59DCA42}) (Version: 4.4.8 - Screaming Bee) Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Mozilla Firefox 50.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.0.2 (x86 de)) (Version: 50.0.2 - Mozilla) Mozilla Firefox 51.0.1 (x86 de) (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) M-Tron Pro (HKLM-x32\...\{EEE8DED0-8DCF-492A-865D-C20964420BE5}) (Version: 1.0.0.35 - GForce Software, Ltd.) Nero 2014 (HKLM-x32\...\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG) Next Car Game (HKLM-x32\...\Steam App 228380) (Version: - Bugbear) Next Car Game Sneak Peek 2.0 (HKLM-x32\...\Steam App 272860) (Version: - Bugbear) No23 Recorder (HKLM-x32\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.7 - Notepad++ Team) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.3.2.2730 - Electronic Arts, Inc.) PDF24 Creator 6.0.1 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.213.1 - Tracker Software Products Ltd) Personality Voices (HKLM-x32\...\{4B886E97-AF5B-46F0-9F48-6BE03149D972}) (Version: 1.0.1 - Screaming Bee) Pillars of Eternity (HKLM-x32\...\Steam App 291650) (Version: - Obsidian Entertainment) Pinball FX2 (HKLM-x32\...\Steam App 226980) (Version: - Zen Studios) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0009 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5919 - Realtek Semiconductor Corp.) Rise of the Tomb Raider (HKLM\...\Steam App 391220) (Version: - Crystal Dynamics) Risk of Rain (HKLM-x32\...\Steam App 248820) (Version: - ) Rocket League (HKLM\...\Steam App 252950) (Version: - Psyonix, Inc.) sciebo (HKLM-x32\...\sciebo) (Version: 2.2.4.840 - Sync and Share NRW ) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Shadow Tactics - Blades of the Shogun 1.0.8 (HKLM-x32\...\{BB762706-65FA-44C1-B2BB-EF29CA88D7CE}_is1) (Version: 1.0.8 - Daedalic Entertainment GmbH) Sid Meier's Alpha Centauri (HKLM-x32\...\GOGPACKSIDMEIERSALPHACENTAURI_is1) (Version: 2.0.2.23 - GOG.com) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sid Meier's Civilization V SDK (HKLM-x32\...\Steam App 16830) (Version: - Firaxis Games) Sid Meier's Civilization VI (HKLM\...\Steam App 289070) (Version: - Firaxis) Sins of a Solar Empire®: Rebellion (HKLM-x32\...\Steam App 204880) (Version: - Ironclad Games) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SONiVOX Sampla (HKLM-x32\...\SONiVOX Sampla_is1) (Version: - ) SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com) Sophos Anti-Virus (HKLM-x32\...\{7E0F4340-598F-462A-8073-AA93A297E74D}) (Version: 10.7.1.32 - Sophos Limited) Sophos AutoUpdate (HKLM-x32\...\{AFBCA1B9-496C-4AE6-98AE-3EA1CFF65C54}) (Version: 5.5.3.0 - Sophos Limited) Sophos Diagnostic Utility (HKLM-x32\...\{4627F5A1-E85A-4394-9DB3-875DF83AF6C2}) (Version: 1.14.0.123 - Sophos Limited) Sophos Home (HKLM-x32\...\{6D110061-38F8-4ED6-AAA8-914BBEB46898}) (Version: 1.1.1.3 - Sophos Limited) Sophos Management Communications System (HKLM-x32\...\{2C14E1A2-C4EB-466E-8374-81286D723D3A}) (Version: 4.3.0.107 - Sophos Limited) Sophos System Protection (HKLM\...\{934BEF80-B9D1-4A86-8B42-D8A6716A8D27}) (Version: 2.6.0.71 - Sophos Limited) Source SDK Base 2007 (HKLM-x32\...\Steam App 218) (Version: - Valve) Special Effects Voices (HKLM-x32\...\{913C4C4F-9E3E-41A6-A614-1BDC1352A225}) (Version: 1.0.2 - Screaming Bee) Spelunky (HKLM-x32\...\Steam App 239350) (Version: - ) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold HD (HKLM\...\Steam App 40950) (Version: - FireFly Studios) System Shock 2 (HKLM-x32\...\Steam App 238210) (Version: - Irrational Games) Tabletop Simulator (HKLM-x32\...\Steam App 286160) (Version: - Berserk Games) Tales of Maj'Eyal (HKLM\...\Steam App 259680) (Version: - DarkGod) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) TeamSpeak 3 Client (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) The Binding of Isaac: Rebirth (HKLM-x32\...\Steam App 250900) (Version: - Nicalis, Inc.) The Blackwell Legacy (HKLM-x32\...\Steam App 80330) (Version: - Wadjet Eye Games) The Culling (HKLM\...\Steam App 437220) (Version: - Xaviant) The Stanley Parable (HKLM\...\Steam App 221910) (Version: - Galactic Cafe) The Swapper (HKLM-x32\...\Steam App 231160) (Version: - Olli Harjola, Otto Hantula, Tom Jubert, Carlo Castellano) The Witcher 2: Assassins of Kings Enhanced Edition (HKLM-x32\...\Steam App 20920) (Version: - CD Projekt RED) Torchlight II (HKLM\...\Steam App 200710) (Version: - Runic Games) Trine (HKLM-x32\...\Steam App 35700) (Version: - Frozenbyte) Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte) UE4 Prerequisites (x64) (HKLM-x32\...\{b46d36bc-2438-471e-abe8-1fbbd51754ee}) (Version: 1.0.10.0 - Epic Games, Inc.) UE4 Prerequisites (x64) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden UninstallTpkdx64 (HKLM\...\Tpkdx64_is1) (Version: - ) Unity Web Player (HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\UnityWebPlayer) (Version: - Unity Technologies ApS) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) VPNAutoconnect (HKLM-x32\...\{8E557F21-99AE-440D-8058-CD8CB3302E13}) (Version: 1.15 - globalip) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.8.0 (HKLM\...\VulkanRT1.0.8.0) (Version: 1.0.8.0 - LunarG, Inc.) Wasteland 2 (HKLM-x32\...\Steam App 240760) (Version: - inXile Entertainment) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Worms Armageddon (HKLM-x32\...\Steam App 217200) (Version: - Team17 Digital Ltd.) XnView 2.04 (HKLM-x32\...\XnView_is1) (Version: 2.04 - Gougelet Pierre-e) You Must Build A Boat (HKLM-x32\...\Steam App 290890) (Version: - EightyEightGames) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0A7BCEBB-B0DF-4590-BBE8-7C968C346473} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-09-16] (Advanced Micro Devices, Inc.) Task: {0D275482-48F9-496B-A7B1-E43495EAC868} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-14] (Adobe Systems Incorporated) Task: {1551F9C7-A7BC-4F77-8F1F-D79A63812679} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-10-28] () Task: {5E884C40-D07B-4C7C-A68C-7FB5D5EB2DF4} - System32\Tasks\CCleanerSkipUAC => D:\programme\CCcleaner\CCleaner.exe [2014-09-26] (Piriform Ltd) Task: {734B2985-D233-426A-9B5B-3B4E2700AA71} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {9054DC4D-F6C3-4A85-AD4D-DBDC1085013B} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => D:\Programme\Bitdefender\Bitdefender\bdproductdata.exe Task: {AC412EFF-8115-4145-8D9B-3668B13A791A} - System32\Tasks\Core Temp Autostart Username => D:\Programme\CoreTemp\Core Temp.exe [2013-03-01] () Task: {B3261064-9569-4C15-8630-D53E6667DDE8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000UA => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-30] (Dropbox, Inc.) Task: {B593C3F8-7EA1-4DC3-80D6-1793A9F62ED5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Task: {B700000C-D51C-4FD6-80F8-4B409AE703A5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {CAA0595A-E3EB-44BB-8FC6-4BF6398BFB6D} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000Core => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-30] (Dropbox, Inc.) Task: {CFB3171C-0B3E-40F3-B284-5B10F30A226E} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000Core.job => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000UA.job => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2014-11-10 17:52 - 2014-11-10 17:52 - 00002560 _____ () C:\Windows\runservice.exe 2013-09-08 18:39 - 2013-10-10 23:34 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-02 13:10 - 2013-03-01 16:44 - 00763856 ____N () D:\Programme\CoreTemp\Core Temp.exe 2016-08-23 13:42 - 2016-08-23 13:42 - 00059904 _____ () d:\Programme\sciebo\shellext\OCUtil_x64.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll 2013-09-04 23:17 - 2013-09-04 23:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2014-11-10 17:52 - 2014-11-10 17:52 - 00048640 _____ () C:\Windows\mmfs.dll 2016-10-06 16:12 - 2016-10-06 16:12 - 03210602 _____ () D:\Programme\sciebo\libocsync.dll 2016-04-21 17:07 - 2016-04-21 17:07 - 00097326 _____ () D:\Programme\sciebo\libgcc_s_sjlj-1.dll 2016-04-21 17:07 - 2016-04-21 17:07 - 00922727 _____ () D:\Programme\sciebo\libstdc++-6.dll 2016-10-06 16:13 - 2016-10-06 16:13 - 18816506 _____ () D:\Programme\sciebo\libsciebosync.dll 2016-04-21 15:45 - 2016-04-21 15:45 - 00085548 _____ () D:\Programme\sciebo\zlib1.dll 2016-04-21 15:48 - 2016-04-21 15:48 - 02197765 _____ () D:\Programme\sciebo\icui18n53.dll 2016-04-21 15:48 - 2016-04-21 15:48 - 01308778 _____ () D:\Programme\sciebo\icuuc53.dll 2016-04-21 15:48 - 2016-04-21 15:48 - 21539975 _____ () D:\Programme\sciebo\icudata53.dll 2016-04-21 15:44 - 2016-04-21 15:44 - 00148117 _____ () D:\Programme\sciebo\libpcre16-0.dll 2016-04-21 15:47 - 2016-04-21 15:47 - 01366986 _____ () D:\Programme\sciebo\libGLESv2.dll 2016-04-21 15:49 - 2016-04-21 15:49 - 00209711 _____ () D:\Programme\sciebo\libpng16-16.dll 2016-05-09 21:13 - 2016-05-09 21:13 - 00048461 _____ () D:\Programme\sciebo\libqt5keychain.dll 2016-04-21 15:47 - 2016-04-21 15:47 - 00154982 _____ () D:\Programme\sciebo\libEGL.dll 2016-04-21 15:45 - 2016-04-21 15:45 - 00350662 _____ () D:\Programme\sciebo\libjpeg-8.dll 2016-04-21 15:46 - 2016-04-21 15:46 - 00689339 _____ () D:\Programme\sciebo\libsqlite3-0.dll 2016-04-21 16:10 - 2016-04-21 16:10 - 00247540 _____ () D:\Programme\sciebo\libwebp-4.dll 2016-04-21 15:51 - 2016-04-21 15:51 - 01169416 _____ () D:\Programme\sciebo\libxml2-2.dll 2016-04-21 17:48 - 2016-04-21 17:48 - 00231727 _____ () D:\Programme\sciebo\libxslt-1.dll 2017-02-27 21:00 - 2017-02-21 19:58 - 00802112 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll 2015-12-11 13:34 - 2017-01-25 22:03 - 00035792 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2015-12-11 13:34 - 2017-01-25 22:03 - 00100296 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2015-12-11 13:34 - 2017-01-25 22:03 - 00018888 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\select.pyd 2015-12-11 13:34 - 2017-02-21 20:01 - 00019776 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2015-12-11 13:34 - 2017-01-25 22:03 - 00694224 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00020824 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2015-12-11 13:34 - 2017-01-25 22:04 - 00123856 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 01682768 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00020816 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2017-02-27 21:00 - 2017-01-25 22:03 - 00145864 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2017-02-27 21:00 - 2017-01-25 22:04 - 00019408 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2017-02-27 21:00 - 2017-01-25 22:03 - 00116688 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2015-12-11 13:34 - 2017-01-25 22:06 - 00105928 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-08-05 19:59 - 2017-02-21 20:01 - 00022864 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00038712 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\fastpath.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00052544 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00024528 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32event.pyd 2017-02-27 21:00 - 2017-01-25 22:03 - 00392144 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2017-02-27 21:00 - 2017-01-25 22:06 - 00020936 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00116176 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32security.pyd 2015-12-11 13:34 - 2017-02-21 20:01 - 00381760 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00124880 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-08-05 19:59 - 2017-02-21 20:01 - 00026456 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00024016 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00175560 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32gui.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00030160 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00043472 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32process.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00048592 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32service.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00057808 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00024016 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32profile.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00246608 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00027488 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-08-05 19:59 - 2017-01-25 22:05 - 00241104 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\_jpegtran.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00022336 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00028616 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32ts.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 01826104 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2015-12-11 13:34 - 2017-01-25 22:04 - 00083912 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\sip.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 01972536 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 03928896 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00531264 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00053072 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd 2015-12-11 13:34 - 2017-02-21 20:01 - 00025432 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00133432 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00224064 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00207680 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2017-01-24 15:23 - 2017-02-21 20:01 - 00022864 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd 2017-01-24 15:23 - 2017-02-21 20:01 - 00022872 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-01-24 15:23 - 2017-02-21 20:01 - 00021848 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd 2017-01-24 15:23 - 2017-02-21 20:01 - 00022872 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00350152 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2016-02-12 16:45 - 2017-02-21 20:01 - 00023896 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00025936 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2017-02-27 21:00 - 2017-01-25 22:01 - 00036296 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\librsync.dll 2017-02-27 21:00 - 2017-02-21 20:01 - 00084288 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2017-02-27 21:00 - 2017-01-25 22:11 - 00017864 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\libEGL.dll 2017-02-27 21:00 - 2017-01-25 22:11 - 01631184 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2017-02-27 21:00 - 2017-02-21 20:01 - 00042816 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00171336 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00357688 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2015-12-11 13:34 - 2017-01-25 22:06 - 00060880 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\win32print.pyd 2016-08-05 19:59 - 2017-02-21 20:01 - 00026456 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-02-27 21:00 - 2017-02-21 20:01 - 00546104 _____ () C:\Users\Username\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2016-08-22 12:26 - 2017-02-06 14:41 - 00174448 _____ () C:\Program Files\CyberGhost 6\Data\OpenVPN\liblzo2-2.dll 2016-08-22 12:26 - 2017-02-06 14:41 - 00115168 _____ () C:\Program Files\CyberGhost 6\Data\OpenVPN\libpkcs11-helper-1.dll 2017-02-02 00:35 - 2017-02-01 10:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll 2017-02-02 00:35 - 2017-02-01 10:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll 2011-07-18 22:07 - 2011-07-18 22:07 - 00014336 _____ () D:\Programme\Notepad++\plugins\NppExport.dll 2014-01-07 00:42 - 2014-01-07 00:42 - 01611264 _____ () D:\Programme\Notepad++\plugins\NppFTP.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Microsoft:t4VWUkqjRfCpAHqv5 [2846] AlternateDataStreams: C:\ProgramData\Microsoft:ypVFsuVXcf93Qjoe85mPsKGG36p [3054] AlternateDataStreams: C:\Users\Username\Desktop\Unterrichten F.docx:com.dropbox.attributes [168] AlternateDataStreams: C:\Users\Username\AppData\Local\Temp:VOj4oxiqpp3vQZ2l75 [3108] AlternateDataStreams: C:\Users\Username\AppData\Local\Temporary Internet Files:L9bxCHOJiGzjyaabLVxk3SPAa [2960] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2016-12-01 19:26 - 00000002 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Username\AppData\Roaming\XnView\\xnview_wallpaper_20160804.bmp DNS Servers: 185.156.172.178 - 185.93.180.131 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == MSCONFIG\startupfolder: C:^Users^Username^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe => C:\Windows\pss\PowerReg Scheduler V3.exe.Startup MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: BCSSync => "D:\programme\Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: CCleaner Monitoring => "D:\Programme\CCcleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: GoogleChromeAutoLaunch_91D1BF9C9BE7D23B14826E2F84E42C40 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window MSCONFIG\startupreg: H2O => C:\Program Files (x86)\SyncroSoft\Pos\H2O\cledx.exe MSCONFIG\startupreg: IAAnotif => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe MSCONFIG\startupreg: PDFPrint => d:\programme\PDF24\pdf24.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: Skype => "D:\programme\skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{52AA3F4B-586B-4850-BD48-A681F143FC2D}] => (Allow) D:\Spiele\Steam\Steam.exe FirewallRules: [{D02F61FE-A143-4CC6-B99E-F2EBC387CDD0}] => (Allow) D:\Spiele\Steam\Steam.exe FirewallRules: [{2678156D-3B79-4843-8C0C-5A59BABBA951}] => (Allow) D:\Spiele\Origin\games\Battlefield 3\bf3.exe FirewallRules: [{40EC4A12-EFAF-45EC-9C28-E3B21177AA71}] => (Allow) D:\Spiele\Origin\games\Battlefield 3\bf3.exe FirewallRules: [{BA5F27DC-51D0-40C2-94CD-AF8DF3D59AE6}] => (Allow) D:\Spiele\Steam\SteamApps\common\SS2\Shock2.exe FirewallRules: [{CA23FA59-6121-4A07-9FDB-0C09FE90649D}] => (Allow) D:\Spiele\Steam\SteamApps\common\SS2\Shock2.exe FirewallRules: [{912A0816-DF89-4580-8C79-F57A1E8FD73A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{0754E905-A2D5-4A06-9C31-A37972743C4B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{800B9D66-81C7-4351-8A66-76BE87018EC3}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{EAA8204C-7169-414C-9191-241BC13A2350}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{E648A590-B6F2-4A72-968C-C2358F4A99BF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{98B832A7-902D-46C2-83C1-34D6E3C05EFA}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{974A6C4B-C900-4DB6-B84B-09FFD246527C}] => (Allow) D:\Spiele\Steam\SteamApps\common\Spelunky\Spelunky.exe FirewallRules: [{A485C35F-0D7E-4EDA-9ED9-E090832F3D4A}] => (Allow) D:\Spiele\Steam\SteamApps\common\Spelunky\Spelunky.exe FirewallRules: [{9FC8C580-FCBA-4B95-9332-FAD458281F97}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{9AB8AC03-D883-4E32-AF27-639F7C3F2F5E}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{E2EC5BB8-6696-40BD-B192-92E7EEEB6B83}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{023D34F9-5E7A-4A6C-9BA1-AE4359DB0F3F}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{ACC14E44-8C80-4C01-9887-3B0B997AE3AF}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{3A1A9ACF-9047-446E-816D-7004BBF938DF}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{A4C1ED4A-2838-4FAC-A877-411AE1F36391}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{9812B0B4-5CF2-4B16-AE23-2EF1EFEE642E}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{EB95AC16-0BD5-43B5-BDF9-83FCD32BD541}] => (Allow) D:\programme\skype\Phone\Skype.exe FirewallRules: [{7BEC1795-0C7C-47A1-B706-401D35FD76C3}] => (Allow) D:\Programme\Office\Office14\GROOVE.EXE FirewallRules: [{995C452F-48C0-4BA4-B06B-35C1EF9B4DD2}] => (Allow) D:\Programme\Office\Office14\GROOVE.EXE FirewallRules: [{23A66BC4-8BBB-424D-855F-820DA1907990}] => (Allow) D:\Programme\Office\Office14\ONENOTE.EXE FirewallRules: [{65D35A27-86A7-4F1E-8AF8-DEF0A30C51A5}] => (Allow) D:\Programme\Office\Office14\ONENOTE.EXE FirewallRules: [{47B0ED22-86D4-43F5-B744-641F99C9A3CB}] => (Allow) D:\Spiele\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{549A9706-7899-44BB-B78E-A4E7E0F904E5}] => (Allow) D:\Spiele\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{9D61099C-DCDE-41AC-9963-D5B2962A54C7}] => (Allow) D:\Programme\Nero 2014\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{733785D1-2F88-44DC-B432-52C6FE88C62D}] => (Allow) D:\Programme\Nero 2014\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{E0A55B62-1464-4713-8CE9-33B537E69801}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{6EB8C95D-9EDB-4B0D-9D51-08F73D1BD41D}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{735ECFB5-9FA9-44E6-A93D-535C56B18FB2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{D2C5DF4F-F4C3-4A09-A4A8-2A766E9AA7E9}] => (Allow) LPort=2869 FirewallRules: [{E6034620-7DFB-44D1-99E6-5863A7275F85}] => (Allow) LPort=1900 FirewallRules: [{94447915-68A3-41E8-A43E-D52B2F829427}] => (Allow) D:\Spiele\Steam\SteamApps\common\Pinball FX2\Pinball FX2.exe FirewallRules: [{8F6BA850-42E8-47EC-A939-8E790B3C0DC7}] => (Allow) D:\Spiele\Steam\SteamApps\common\Pinball FX2\Pinball FX2.exe FirewallRules: [{049A5CC8-7282-4495-B5DF-E5C2C7490037}] => (Allow) D:\Spiele\Stalker AMK\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{74D11C16-BEDE-498A-AA16-CF124E557FD2}] => (Allow) D:\Spiele\Stalker AMK\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe FirewallRules: [{F5C4E497-6581-4997-ADB0-F9136920B03E}] => (Allow) D:\Spiele\Stalker AMK\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{4F35C614-83BB-42FD-A046-785086FBCBC7}] => (Allow) D:\Spiele\Stalker AMK\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe FirewallRules: [{48F41630-F4C1-4A92-8C29-7F5F7AD6C1C1}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{36CBBC30-D2D2-45EA-8C8E-06C3A217CCBF}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{2D584BA7-C74A-4D32-BC7B-0A513B48FF79}] => (Allow) D:\Spiele\Steam\SteamApps\common\FEAR Ultimate Shooter Edition\FEAR.exe FirewallRules: [{F0C83617-29B0-4107-BD6D-5B1830A98258}] => (Allow) D:\Spiele\Steam\SteamApps\common\FEAR Ultimate Shooter Edition\FEAR.exe FirewallRules: [{3FC20CB4-3473-4235-8189-104F91CD54FD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gemini Rue\reslists\Gemini Rue.exe FirewallRules: [{3CCA7C68-19B5-4C1E-8BD3-FDA4DB0B3001}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gemini Rue\reslists\Gemini Rue.exe FirewallRules: [{CF0708ED-F820-4213-B27A-913FF7CE5EFB}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gemini Rue\reslists\winsetup.exe FirewallRules: [{D7B46C2C-3523-4094-928A-2EEFA4567DE3}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gemini Rue\reslists\winsetup.exe FirewallRules: [{CC4B0CC3-CE48-4A1D-9C83-8A1E92409BFC}] => (Allow) D:\Spiele\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [{4F43CA75-609A-4A0B-8258-44696C9E5E15}] => (Allow) D:\Spiele\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [{61CD0C50-E744-4FEC-B783-5576C0E20972}] => (Allow) D:\Spiele\Steam\SteamApps\common\TinyAndBig\tinyandbig.exe FirewallRules: [{33478706-7E16-458F-8C60-E5C82247527C}] => (Allow) D:\Spiele\Steam\SteamApps\common\TinyAndBig\tinyandbig.exe FirewallRules: [{6A8FFCE0-C224-4030-95D9-B51913241471}] => (Allow) D:\Spiele\Steam\SteamApps\common\The Swapper\TheSwapper.exe FirewallRules: [{8CB5E3E6-5BFC-41CC-8A71-D3DD8AFD07F9}] => (Allow) D:\Spiele\Steam\SteamApps\common\The Swapper\TheSwapper.exe FirewallRules: [{996BAE4B-B58C-482C-9695-9459204484B1}] => (Allow) D:\Spiele\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe FirewallRules: [{D1624BFC-0152-4607-B7EE-326B2D193A63}] => (Allow) D:\Spiele\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe FirewallRules: [{FBBBC158-122A-46C1-8B7B-72796CAB4F4F}] => (Allow) D:\Spiele\Steam\SteamApps\common\FLYN\Source\Flyn.exe FirewallRules: [{31D8525B-0B32-4531-AF4E-A7E50FFA7892}] => (Allow) D:\Spiele\Steam\SteamApps\common\FLYN\Source\Flyn.exe FirewallRules: [{D9B225D9-3F3D-4B72-A959-561774E190FA}] => (Allow) C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{78CCB979-DDF4-46D1-8AE8-B580222845E7}] => (Allow) C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{F2C89763-3408-43F8-AD53-57D12B382E0F}] => (Allow) D:\Spiele\Origin\games\FIFA 14\Game\fifa14.exe FirewallRules: [{88BBE39D-2EFE-4ABC-BB11-D86200375CAF}] => (Allow) D:\Spiele\Origin\games\FIFA 14\Game\fifa14.exe FirewallRules: [{42B48F74-5C8A-498D-8B0E-39BB204A89E7}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine\trine_launcher.exe FirewallRules: [{AFB2FB8A-A8BF-478E-B920-5983585C0060}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine\trine_launcher.exe FirewallRules: [{209770F3-19BD-411D-BC8B-3F285F4066EA}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine 2\trine2_launcher.exe FirewallRules: [{BA0A43EC-7849-4A57-843E-BCA46516E1CD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine 2\trine2_launcher.exe FirewallRules: [{D3592BCF-3CCF-4748-94CA-E0EA85DB58E9}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Deception\Deception.exe FirewallRules: [{A3CD48DD-C4CD-4371-8C35-DDA7F1BB67FE}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Deception\Deception.exe FirewallRules: [{2869977C-9A27-4A7E-B4BE-6EB32BA42726}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Convergence\Convergence.exe FirewallRules: [{C2B01DAA-CAB8-4531-8D99-555E59135265}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Convergence\Convergence.exe FirewallRules: [{8EDDDAE4-DE5F-4CE0-A1C9-174D181DB4AE}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Unbound\Unbound.exe FirewallRules: [{E182EF97-7EBB-4905-8E85-D94897CCFCD8}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Unbound\Unbound.exe FirewallRules: [{0CE0B1AB-CC02-488A-902C-AF64A38176EB}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Legacy\blackwell1.exe FirewallRules: [{17FC9060-924F-4787-817B-91B20FE649F3}] => (Allow) D:\Spiele\Steam\SteamApps\common\Blackwell Legacy\blackwell1.exe FirewallRules: [{5EB78E69-D53C-4EDB-B02D-3A2F434749C1}] => (Allow) D:\Spiele\Steam\SteamApps\common\Next Car Game Sneak Peek 2.0\Next Car Game Technology Sneak Peek.exe FirewallRules: [{FF1F99EC-C7AD-4C1D-A3FD-D4333849B8E2}] => (Allow) D:\Spiele\Steam\SteamApps\common\Next Car Game Sneak Peek 2.0\Next Car Game Technology Sneak Peek.exe FirewallRules: [{5F115DAA-33AB-4E41-A9D9-681B255DE8E3}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine\_enchanted_edition_\trine1_launcher.exe FirewallRules: [{778AF58D-EBD3-45D2-B1A2-16B0AAD40983}] => (Allow) D:\Spiele\Steam\SteamApps\common\Trine\_enchanted_edition_\trine1_launcher.exe FirewallRules: [{AD0687DD-B1E6-49FA-951B-E10C3937256C}] => (Allow) D:\Spiele\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe FirewallRules: [{563DC44D-355D-414B-BB1F-9D4CF6CB5698}] => (Allow) D:\Spiele\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe FirewallRules: [{6EC50E08-8590-4D74-B03A-D88B4459BB1A}] => (Allow) D:\Spiele\Steam\bin\steamwebhelper.exe FirewallRules: [{E258D326-6711-4C55-B020-41242AB55555}] => (Allow) D:\Spiele\Steam\bin\steamwebhelper.exe FirewallRules: [{AF743968-0991-4BB6-A66F-218494E53C67}] => (Allow) D:\Spiele\Steam\SteamApps\common\Hammerwatch\editor\HammerEditor.exe FirewallRules: [{B678452D-C4CE-46FC-96A3-0F7F4ABD7ADD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Hammerwatch\editor\HammerEditor.exe FirewallRules: [{CEDEF092-F38A-4E7B-AFA2-98192E6EC8E5}] => (Allow) D:\Spiele\Steam\SteamApps\common\Wasteland 2\Build\WL2.exe FirewallRules: [{A7D4F941-CB33-49A0-BFE0-83F8E18B4FD3}] => (Allow) D:\Spiele\Steam\SteamApps\common\Wasteland 2\Build\WL2.exe FirewallRules: [{B9F66A28-E30D-4DE9-B1F4-48F112FA42ED}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bugbear Entertainment\Wreckfest.exe FirewallRules: [{3EB35363-22CE-471F-A856-313083F0D23C}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bugbear Entertainment\Wreckfest.exe FirewallRules: [{79794646-D0B2-4594-93C2-3BDCB12035D4}] => (Allow) D:\Spiele\Steam\SteamApps\common\Risk of Rain\Risk of Rain.exe FirewallRules: [{C39194CE-76BA-442E-B307-A5318CC449B0}] => (Allow) D:\Spiele\Steam\SteamApps\common\Risk of Rain\Risk of Rain.exe FirewallRules: [{FFB88877-22B4-4EEB-B954-BB7D0B61A5E4}] => (Allow) D:\Spiele\Steam\SteamApps\common\insurgency2\insurgency.exe FirewallRules: [{31030F4C-9239-4052-B1F7-85127BC0ECCC}] => (Allow) D:\Spiele\Steam\SteamApps\common\insurgency2\insurgency.exe FirewallRules: [{633F39B6-0EA4-4E3B-A79E-532E753BF4CE}] => (Allow) D:\Spiele\Steam\SteamApps\common\Guacamelee\Guac.exe FirewallRules: [{3ACE565F-9499-4C04-8DCE-6DCBF988BA96}] => (Allow) D:\Spiele\Steam\SteamApps\common\Guacamelee\Guac.exe FirewallRules: [{DB572968-5623-4EB8-A646-B1F74BBD36ED}] => (Allow) D:\Spiele\Steam\SteamApps\common\TheCatLady\The Cat Lady.exe FirewallRules: [{3E52CA81-1829-4642-9401-5F74030501C9}] => (Allow) D:\Spiele\Steam\SteamApps\common\TheCatLady\The Cat Lady.exe FirewallRules: [{36D28811-2A96-4400-AF14-33D1631855A5}] => (Allow) D:\Spiele\Steam\SteamApps\common\Endless Legend\EndlessLegend.exe FirewallRules: [{56B6D1FC-79F8-4784-8E45-9C697055DAAF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Endless Legend\EndlessLegend.exe FirewallRules: [{E774D4B2-B72E-4EE4-ACFA-12CD8F7CCF11}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{98EDA751-B7D2-4044-82E9-31F0304F3B42}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sins of a Solar Empire Rebellion\Sins of a Solar Empire Rebellion.exe FirewallRules: [{28B18113-1D53-43A9-A7CD-C54944A57A30}] => (Allow) D:\Spiele\Steam\SteamApps\common\InvisibleInc\invisibleinc.exe FirewallRules: [{BB47BE09-D677-4136-825E-550264850E87}] => (Allow) D:\Spiele\Steam\SteamApps\common\InvisibleInc\invisibleinc.exe FirewallRules: [{46A2A12B-8250-4CD9-994C-BFB4E18E6763}] => (Allow) D:\Spiele\Steam\SteamApps\common\Worms Armageddon\WA.exe FirewallRules: [{0D81B859-C7FF-4CEC-AA33-D15F9646BDB2}] => (Allow) D:\Spiele\Steam\SteamApps\common\Worms Armageddon\WA.exe FirewallRules: [{4A8CE985-0FB3-4D92-B4ED-30844050D56C}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe FirewallRules: [{17688432-7095-4A8F-825E-615F133F8266}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe FirewallRules: [{3654FE8A-8F2B-4FE1-AA08-404C5FF1EDCA}] => (Allow) D:\Spiele\Steam\SteamApps\common\Inquisitor\Game\Inquisitor.exe FirewallRules: [{5BD05155-AFCF-4466-AC13-C57E0BE26140}] => (Allow) D:\Spiele\Steam\SteamApps\common\Inquisitor\Game\Inquisitor.exe FirewallRules: [{AA213B7D-0D4A-4801-9A12-DB188830E5E8}] => (Allow) D:\Spiele\Steam\SteamApps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{7F83A487-BE59-4711-919F-65D80651C96D}] => (Allow) D:\Spiele\Steam\SteamApps\common\Tabletop Simulator\Tabletop Simulator.exe FirewallRules: [{F86DBE7B-99EA-4B8F-913B-66351CF06B60}] => (Allow) D:\Spiele\Steam\SteamApps\common\Crusader Kings II\CK2game.exe FirewallRules: [{55CB568C-99C6-4C0B-BA28-0F78796DED91}] => (Allow) D:\Spiele\Steam\SteamApps\common\Crusader Kings II\CK2game.exe FirewallRules: [{A2B96135-9DFD-458D-9902-42D6B2E164FE}] => (Allow) D:\Spiele\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe FirewallRules: [{0E60C333-17FD-4FCA-8CDE-DC14063D9543}] => (Allow) D:\Spiele\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe FirewallRules: [{05CE4685-1DE7-4AF0-A0FC-4A8988EECA08}] => (Allow) D:\Spiele\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe FirewallRules: [{87A0421B-D8E8-4C70-8906-3729662DCDBC}] => (Allow) D:\Spiele\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe FirewallRules: [{29728993-72A3-47DD-9AE5-55E39E807E6D}] => (Allow) D:\Spiele\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{1738807C-499F-4621-A822-D0BDC10FAB79}] => (Allow) D:\Spiele\Steam\SteamApps\common\Europa Universalis IV\eu4.exe FirewallRules: [{53AD3B77-2559-4145-B944-4B6124600719}] => (Allow) D:\Spiele\Steam\SteamApps\common\Source SDK Base 2007\hl2.exe FirewallRules: [{714EAC88-2558-483E-9C5B-21B590A31074}] => (Allow) D:\Spiele\Steam\SteamApps\common\Source SDK Base 2007\hl2.exe FirewallRules: [{CA5C4D89-27B1-4DBC-8477-1DEE9576CDB8}] => (Allow) D:\Spiele\Steam\SteamApps\common\Fistful of Frags\sdk\hl2.exe FirewallRules: [{6D9E0E46-BD04-48F9-A734-5545F912937B}] => (Allow) D:\Spiele\Steam\SteamApps\common\Fistful of Frags\sdk\hl2.exe FirewallRules: [{359F8911-B94A-448B-963C-A5D42B79BABE}] => (Allow) D:\Spiele\Steam\SteamApps\common\YMBAB\YMBAB.exe FirewallRules: [{6E8C3D08-3670-45AC-9756-0804915B21CE}] => (Allow) D:\Spiele\Steam\SteamApps\common\YMBAB\YMBAB.exe FirewallRules: [{1040999C-F379-4C9E-AC7A-34511CC64499}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{9DC1A972-9917-429B-A352-46F137986EFB}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{2A57B301-124E-407A-A1B4-C57F0CE7D913}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bugbear Entertainment\Wreckfest_x64.exe FirewallRules: [{FA7A5830-D689-4CAF-A1B5-4D665C1F60A6}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bugbear Entertainment\Wreckfest_x64.exe FirewallRules: [{9B35F424-347C-4F72-8795-23EFFB7FF0E4}] => (Allow) D:\Spiele\Steam\SteamApps\common\CardHunter\CardHunter.exe FirewallRules: [{F52A36E0-6308-47A4-9B10-4D747F8D1266}] => (Allow) D:\Spiele\Steam\SteamApps\common\CardHunter\CardHunter.exe FirewallRules: [{F0B4635B-A8A8-43E4-A536-42174DB961E5}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe FirewallRules: [{D1E1A5E1-2B8D-4DEB-B3F8-8F3CA3C12E01}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe FirewallRules: [{F5FA53EF-65D5-45B2-A440-8D54D0FF5FF4}] => (Allow) d:\programme\Firefox\firefox.exe FirewallRules: [{435C63B4-582D-45B9-A4E7-9C700A7A34BF}] => (Allow) d:\programme\Firefox\firefox.exe FirewallRules: [{64D93D82-5EF0-47D8-A055-85326D85CDE5}] => (Allow) D:\Programme\IDevice\Software4u.IDeviceManager.exe FirewallRules: [{408B7E5C-2CA9-47CF-9AF5-4F93C9387688}] => (Allow) D:\Programme\IDevice\Software4u.IDeviceManager.exe FirewallRules: [{0F91D3F0-C76F-4814-ACDA-F8520AF5FC13}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{D8EE7C9F-A95F-463A-9BB9-796C5D65ACB8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{4F3FB429-1999-4B38-A41B-B6DF26C81AFD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{1177296F-904D-4FA8-AD2D-C502AD53E72B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{4A79A494-D605-462D-B66C-93EA9DFBFD09}] => (Allow) D:\programme\Firefox\firefox.exe FirewallRules: [{5B1E0197-A97A-4D1A-8769-9463D16E681C}] => (Allow) D:\programme\Firefox\firefox.exe FirewallRules: [{A6BB0D58-FE6D-44FC-B12A-AB17EF7012EF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Next Car Game Sneak Peek 2.0\PukkiFinal.exe FirewallRules: [{10B7A906-7F55-4333-9194-8B2AA73E44FD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Next Car Game Sneak Peek 2.0\PukkiFinal.exe FirewallRules: [{6BCA062C-2A56-45CF-8AA4-5BE34C010814}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{FD7BAA82-4596-4617-BC7C-DB757B7DB7E0}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{45D595CC-B63F-45CE-8DC1-30793F982FFD}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{C2110B36-4361-49A8-9164-A30809935956}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{58E3646C-DBAD-4977-A23B-664F8688A859}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dr Langeskov The Tiger and The Terribly Cursed Emerald A Whirlwind Heist\DrLangeskov.exe FirewallRules: [{0E801EF9-7406-41B9-B47F-AB9441A110A3}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dr Langeskov The Tiger and The Terribly Cursed Emerald A Whirlwind Heist\DrLangeskov.exe FirewallRules: [{F113B06D-EBCE-40AD-ABC9-24677FC54180}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{32CF48D6-EA1C-42D4-9CC4-E789AB6CE1FF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{125EFCE7-93FC-4084-8144-A0A731411B57}] => (Allow) D:\Spiele\Steam\SteamApps\common\TalesMajEyal\t-engine.exe FirewallRules: [{417BCBE9-C3A6-4E76-8BB7-18E69A13C073}] => (Allow) D:\Spiele\Steam\SteamApps\common\TalesMajEyal\t-engine.exe FirewallRules: [{10EB854D-6F40-40E1-8C36-FF8B708AB467}] => (Allow) D:\Spiele\Steam\SteamApps\common\TheCulling\TheCulling_Launcher.exe FirewallRules: [{2E344340-F754-48BD-B7AF-2754E2414C63}] => (Allow) D:\Spiele\Steam\SteamApps\common\TheCulling\TheCulling_Launcher.exe FirewallRules: [{7723952A-82F0-4279-A3F8-D421F1B2C587}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{8EB22243-6CEF-4680-AF1E-F50283F5948B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{86B0E625-CB2E-4C7A-B708-CF8024D91628}] => (Allow) D:\Spiele\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe FirewallRules: [{98932F56-4400-4E2F-8296-583A60E3ABCC}] => (Allow) D:\Spiele\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe FirewallRules: [{9D3C7818-1029-491B-9AF0-99A07A8E6CAC}] => (Allow) D:\Spiele\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe FirewallRules: [{1809A93E-6AF6-4128-B436-BDA88E911C1F}] => (Allow) D:\Spiele\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe FirewallRules: [{770D771D-F50F-4F80-B14B-3646D47751A2}] => (Allow) D:\Spiele\Steam\SteamApps\common\The Stanley Parable\stanley.exe FirewallRules: [{95F33A1E-7C59-4299-A16C-9F2BFF24D528}] => (Allow) D:\Spiele\Steam\SteamApps\common\The Stanley Parable\stanley.exe FirewallRules: [{A0378B41-8880-46B5-9E23-8EF56318E8A8}] => (Allow) D:\Spiele\Steam\SteamApps\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{E93519E5-3D7E-493C-A145-B8931057A639}] => (Allow) D:\Spiele\Steam\SteamApps\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{4B3626AA-BBA6-4764-AC19-E5CAE402BE27}] => (Allow) D:\Spiele\Steam\SteamApps\common\Stronghold\Stronghold.exe FirewallRules: [{B74E9527-FD59-4C64-A360-D3FB1C5426AD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Stronghold\Stronghold.exe FirewallRules: [TCP Query User{FD786838-9C5C-4EC4-9AF2-DB89D7BDDAC1}C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [UDP Query User{B4C98991-200B-4F28-8386-70F55B59866C}C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [{35436804-5A7E-4F97-B2FD-407010B4E04E}] => (Block) C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [{F716E894-2612-47C0-BB02-558FE611B995}] => (Block) C:\users\Username\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [TCP Query User{161BAD9B-FBA8-4BC5-9554-FD070AA883A1}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [UDP Query User{222650BC-92D4-4218-9A99-5FFF48DE8328}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [{50A9A58D-D28D-4704-B647-ADADCD280603}] => (Allow) D:\Spiele\Steam\SteamApps\common\GarrysMod\hl2.exe FirewallRules: [{5BE99164-F1B2-495F-B7F1-481326817BFE}] => (Allow) D:\Spiele\Steam\SteamApps\common\GarrysMod\hl2.exe FirewallRules: [{60D6BD18-C109-453F-ABAF-9C7C11CE41D9}] => (Allow) D:\Spiele\Steam\SteamApps\common\HardWest\HardWest.exe FirewallRules: [{34047DD0-7727-4609-8418-97E2B35EBA7B}] => (Allow) D:\Spiele\Steam\SteamApps\common\HardWest\HardWest.exe FirewallRules: [TCP Query User{12800B9C-C755-481D-9E60-96D96CD457C9}D:\spiele\steam\steamapps\common\theculling\victory\binaries\win64\victory.exe] => (Allow) D:\spiele\steam\steamapps\common\theculling\victory\binaries\win64\victory.exe FirewallRules: [UDP Query User{079A20AB-975A-47A9-8ABF-2F7C236FF5DC}D:\spiele\steam\steamapps\common\theculling\victory\binaries\win64\victory.exe] => (Allow) D:\spiele\steam\steamapps\common\theculling\victory\binaries\win64\victory.exe FirewallRules: [{8689A500-85F2-4A7C-A4EC-404C6F39A8DC}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gods Will Be Watching\gwbw.exe FirewallRules: [{C7DD094E-1F54-4E03-8A33-9936D4F01F9F}] => (Allow) D:\Spiele\Steam\SteamApps\common\Gods Will Be Watching\gwbw.exe FirewallRules: [{736ADF72-EBB1-4B02-BFF3-851378ED4087}] => (Allow) D:\Spiele\Steam\SteamApps\common\CookServeDelicious\CSDSteamBuild.exe FirewallRules: [{311AF86E-8DC1-4CE7-B5FC-D95C213BFD5D}] => (Allow) D:\Spiele\Steam\SteamApps\common\CookServeDelicious\CSDSteamBuild.exe FirewallRules: [{1E0B5C13-14E2-4CF2-ABE3-C57F3D019FFF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Hitman Absolution\HMA.exe FirewallRules: [{6E7B296B-CDFF-4568-B33D-58BBB0043D35}] => (Allow) D:\Spiele\Steam\SteamApps\common\Hitman Absolution\HMA.exe FirewallRules: [{B4A669EF-7177-4823-9159-C66F156E0076}] => (Allow) D:\Spiele\Steam\SteamApps\common\Battle Brothers\win32\BattleBrothers.exe FirewallRules: [{D943AEA4-8824-412A-9B3D-F710A7894B39}] => (Allow) D:\Spiele\Steam\SteamApps\common\Battle Brothers\win32\BattleBrothers.exe FirewallRules: [{ECC31D46-C3E2-4513-9F4B-AD0D7F1D2182}] => (Allow) D:\Spiele\Steam\SteamApps\common\F1 2014\F1_2014.exe FirewallRules: [{C5274060-45F4-4B1C-84A9-BADC563D9C1B}] => (Allow) D:\Spiele\Steam\SteamApps\common\F1 2014\F1_2014.exe FirewallRules: [{C9789318-C948-4EEF-925E-E8BB31FAF78E}] => (Allow) D:\Spiele\Steam\SteamApps\common\Age2HD\Launcher.exe FirewallRules: [{B627FF3B-A7FB-4012-9615-34FC7C7B972B}] => (Allow) D:\Spiele\Steam\SteamApps\common\Age2HD\Launcher.exe FirewallRules: [{C2690356-A3D1-430C-9C69-07A37941910F}] => (Allow) D:\Spiele\Steam\SteamApps\common\Endless Space\EndlessSpace.exe FirewallRules: [{22349C82-BE18-47C5-9DBA-088BE6FF29D7}] => (Allow) D:\Spiele\Steam\SteamApps\common\Endless Space\EndlessSpace.exe FirewallRules: [{65B906E4-BE0C-4B9A-8EEF-2F87021E44F4}] => (Allow) D:\Spiele\Steam\SteamApps\common\EasyAntiCheat\EasyAntiCheat.exe FirewallRules: [{70EA8D50-3CA0-4AE2-B77E-7D2064BB59C0}] => (Allow) D:\Spiele\Steam\SteamApps\common\EasyAntiCheat\EasyAntiCheat.exe FirewallRules: [{63DC68DB-787C-4E48-B95A-A1E6AB537034}] => (Allow) D:\Spiele\Origin\games\FIFA 14\Game\fifa14.exe FirewallRules: [{1AEFF97F-C253-4F99-AF6C-91032175E15C}] => (Allow) D:\Spiele\Origin\games\FIFA 14\Game\fifa14.exe FirewallRules: [{BA01D897-AD4F-4600-B8FB-F8EB7BD45A56}] => (Allow) D:\Spiele\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe FirewallRules: [{7DB44A66-8A89-4B83-B1BD-076469A47334}] => (Allow) D:\Spiele\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe FirewallRules: [{92BAE5D4-3685-4C6F-979C-5E9B66E664DC}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{ECBC5110-B55F-41D3-98EC-4F82469D48C5}] => (Allow) D:\Spiele\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{9176BD76-FF3A-458B-BB37-1976865FCA23}] => (Allow) D:\Spiele\Steam\SteamApps\common\Torchlight II\ModLauncher.exe FirewallRules: [{8437BDC4-E752-4161-B715-A8249B5F76CD}] => (Allow) D:\Spiele\Steam\SteamApps\common\Torchlight II\ModLauncher.exe FirewallRules: [{324D3407-8256-46F9-98C2-50A2A3B7AC21}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bejeweled 3\Bejeweled3.exe FirewallRules: [{1FF57B13-F3EF-4644-825E-0EE458A46B47}] => (Allow) D:\Spiele\Steam\SteamApps\common\Bejeweled 3\Bejeweled3.exe FirewallRules: [TCP Query User{823D0CDC-E78A-4CEA-85DD-15E7E72A733E}C:\users\Username\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\Username\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{3CEA50BC-9674-494B-9083-E189DE396E41}C:\users\Username\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\Username\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{3EC25F1E-E73E-4E52-BD25-3B03FA10F4B8}] => (Allow) D:\Spiele\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{4B63D3F2-BC07-44FB-94DC-D6F6E7991C4D}] => (Allow) D:\Spiele\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{3E447237-35D8-406A-9CE2-D13A90F25BB2}] => (Allow) D:\Spiele\Steam\SteamApps\common\EvolveGame\bin64_SteamRetail\Evolve.exe FirewallRules: [{28FD050A-9B13-434D-B84B-D9AE1B8A1D45}] => (Allow) D:\Spiele\Steam\SteamApps\common\EvolveGame\bin64_SteamRetail\Evolve.exe FirewallRules: [TCP Query User{22819786-7E16-4107-BE64-85DFED4D6424}C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe] => (Allow) C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe FirewallRules: [UDP Query User{6595A6C7-4177-4FB6-A3A0-C810DF68FB64}C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe] => (Allow) C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe FirewallRules: [TCP Query User{338CD5C8-F13C-49FB-A206-CB43AE561245}C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe] => (Allow) C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe FirewallRules: [UDP Query User{72703B4A-1CFE-4A03-951C-8468FA48C661}C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe] => (Allow) C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe FirewallRules: [{C766DDC3-51E6-4A9F-80DF-393CAD216656}] => (Block) C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe FirewallRules: [{3C7A033D-7C58-4D0C-82AE-733562C77515}] => (Block) C:\users\Username\appdata\local\temp\bduninstall\x64\pcsftool.exe FirewallRules: [{034A03BD-ABBC-46AF-8AE1-41F1C78F75AB}] => (Block) C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe FirewallRules: [{CF1F4BF6-F6A0-42EA-A3FE-B3F2840FFF5D}] => (Block) C:\users\Username\appdata\local\temp\bduninstall\x32\pcsftool.exe FirewallRules: [{D3665D4F-5B27-4A89-9D22-2D090086AE22}] => (Allow) D:\Spiele\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{59E94A4B-ED3B-4688-8AF6-102FE6D1840A}] => (Allow) D:\Spiele\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{A2449039-7184-4B56-ACD9-45DB9D234DAA}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{573F1795-8C6D-43EF-9EC6-87A4D1664AA0}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{2B8B60C7-50D7-4EC0-BF77-501D822F9B6B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{095F57D8-5E4B-4B70-855D-76E9A8BE9965}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2E45CE2A-323D-4A0A-866A-EA063033EA4E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{FB386D60-B54D-4CE6-ABB3-E052A95B9860}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{3D4FFDA9-751D-48B3-8274-F708F9555DF2}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{4952B2DB-8A87-4F96-9B7D-D3930B604E40}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{9C01AE39-D675-4DF1-A5B9-C7CFA292DA16}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{1D65750B-6A49-4BF4-B5C3-318250368C70}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5EEAD3FA-AA96-4CBF-81BE-C4A2ED1F3C10}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A8864E63-9950-4680-BC46-C73627F2301C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{8A992E91-7D7A-4658-9363-BE025BA3A5EF}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sins of a Solar Empire Rebellion\StardockLauncher.exe FirewallRules: [{3CB558C9-D70D-438F-BB3E-9ECD6C347947}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sins of a Solar Empire Rebellion\StardockLauncher.exe FirewallRules: [{F15ECC88-5A88-46CE-88CC-80A4FB32AA26}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{9FBB8C70-E385-466A-8E21-D54F4381E344}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{046688CC-0C9D-48CE-8587-ED27050DB4B9}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{E84154DE-0F18-476A-B3DF-48A88928D4A3}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5F386E58-4B96-4C0E-8B33-A9370580289D}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{B792E876-82C6-4E38-8ABB-1BDD2AA6DE27}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{DFE64EF8-FEB3-48AB-A294-658F7070E06E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C759A1A9-2A02-475E-A6BB-34868771129E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{BBAD7F0B-65B5-43A0-B73E-A2F30707FF36}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{AFA442A4-E25D-4BE7-BCD1-7F1F028886D7}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{F318CDEE-D7EB-4116-8C8C-13F86E86452A}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{1A87EFEE-3597-49AF-A331-AAB7A76E9096}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A1DBB060-0B1D-4592-8147-4C08CD7FC3AE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{66A28904-D214-4B1E-ABBC-3290D7579446}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{6EBC6F11-2394-47D1-8DF4-B0CFF9A7F971}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{777C72F3-AEFA-4508-A66B-61D04C37B1A8}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{99E0FFB3-78EC-4CE1-BD39-821BE861B89C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5EC1C93C-7426-4033-9B7C-DA3174FA693B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{514082F6-3B94-4793-AAD0-161ED5E6D9BE}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{EBF748A3-381D-4ECB-B383-197350B0EBBC}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{406E90AD-0138-43E1-90E9-7FAF637C52D4}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{13F582CD-28F4-474F-A549-EBAA6C12A111}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{6BC6EC10-8D6B-432A-89EC-D5389D1AA433}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{44DDD77E-C975-4AA1-AA2D-3E4DFD7FDEF5}] => (Allow) D:\Spiele\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{2D42BCF9-4934-499B-B83F-0D977AE1969B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{BB8D6FA4-F8E7-411B-9C47-717DA1A60F67}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{560EB1FD-E768-4BCB-ABF8-4D0791708627}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{8A0C55F9-09E2-4A4E-A87E-71A3657BA55A}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{DE66034D-A49A-4E47-93DD-084FA1365DF7}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{BDD80907-8AA6-438E-9B7F-5108AC55B80E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{EA7E6417-12CB-42A3-883E-FC1B283E589B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{63FD418F-0C9E-4D5B-8BFB-456669A61AEF}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{E9CE4073-2183-4F87-9E9D-262490C7A18F}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{FE3F5CB6-3342-4E82-8A0D-09929581C2C9}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{575F3E65-2597-4622-B80D-739E10B5DC48}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{7C04E598-A2F6-4795-AF9D-5F9692C2F4DB}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{F573F09B-7304-490A-B47F-C845BC91E1F6}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{9CF85754-2FE7-4E80-8203-DE571A462E0C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{D6D4BAFB-6533-4D4A-B9F1-3533BA59B2C4}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C35B5F08-85F2-4D87-A93B-5BED5B39D2AE}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A0FA4A3C-99A9-4B6F-B4EC-2FE02A1B7A3D}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2F6758C5-3779-456F-88D9-26D27B27E033}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{B59DB3BE-15BC-480B-B98B-6B1CE66B7F81}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe FirewallRules: [{8AA15C78-F927-4C05-80AF-20E0BDF974C2}] => (Allow) D:\Spiele\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe FirewallRules: [{F07BD73B-2AF8-4700-83CE-56F295423C2E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{06C37E22-BF26-4F96-8CA2-ED7BBD0B0AD8}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{6606812B-D029-4AD5-AB30-2F318F534113}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C15C400C-116D-40AC-A781-9558EBE72EE9}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C55CE211-13E1-4CE4-A1FD-9116DD2D4986}] => (Allow) D:\Spiele\Steam\SteamApps\common\Barony\barony.exe FirewallRules: [{37ED9DAE-F6DA-401C-985C-2DB4CD90D87B}] => (Allow) D:\Spiele\Steam\SteamApps\common\Barony\barony.exe FirewallRules: [{A9095FE1-DEFD-4B11-B98A-93251CBF018B}] => (Allow) D:\Spiele\Steam\SteamApps\common\Barony\editor.exe FirewallRules: [{50FCC761-1B0E-45E0-B4CE-733086E94342}] => (Allow) D:\Spiele\Steam\SteamApps\common\Barony\editor.exe FirewallRules: [{478B5531-5B73-4DD4-B5C5-1D0B5DDF86CE}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{0F41CC11-9D13-47D1-BB23-17ED322F0C1B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{E7BA3918-F3FB-4D56-B7CC-06C7D7AC72C8}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{490BF88F-5C84-4199-BE94-330115F870DF}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2B05FE9C-A9BD-402E-BB37-3B019F858846}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{F79EE336-2699-4358-B007-C486F47A4A18}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{423C8D3F-D7DB-4D14-8DF6-F6C260DC29D3}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C8D9A0D5-CFC4-4A51-B274-8241E8770941}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{9553D194-BE35-4D1B-BCAD-F1C66D2FB70E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{E328B263-A7B1-4A7A-BD67-A0E555801C0D}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{3D4E9794-E065-49D2-8E82-651576F31341}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{88B59F7E-996F-434E-9972-F24B6C46C6A1}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{B2CCFA18-485E-4779-BC97-CF830FB4A47C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A1B43CE4-6C36-4A12-A12D-6C34B11F9954}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{D210D5AE-D3A6-4CE9-A29B-DCCC50484E41}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5611E338-E0A4-4427-96FB-74C004B09BAA}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{ACD40E1E-7091-478B-95D4-071A0E000A4B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{4874A60B-E0E8-4970-AC15-E21975B1E39C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{AB70FDAC-62E3-4624-9EC9-FC7F62E45F22}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{0E346661-34D0-4C7D-A949-C2E533218B5E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{AE674E81-301F-4AAE-8DD7-625B655DAA53}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{9C271E1D-0087-41DE-912E-416488BFEB3A}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{01BFAC72-C570-4633-8296-A572553C24B5}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{C001F4B6-467A-4A4E-BCA6-AC08CD35796D}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{DD32A8D5-1ADB-4C0B-B73F-154BC8D44195}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2EB2345F-B98B-405A-90DD-B7D3E898B102}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2878D111-0634-4F6B-856F-FC6B5EF2C7D3}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{AE3C84E5-2A4C-48E5-9BB7-3B19449656D1}] => (Allow) D:\Spiele\Steam\SteamApps\common\insurgency2\insurgency_BE.exe FirewallRules: [{2942C888-8941-4DB2-87AB-5EB8A29E5978}] => (Allow) D:\Spiele\Steam\SteamApps\common\insurgency2\insurgency_BE.exe FirewallRules: [{A5573FFB-6C19-4B71-A361-280D6B31224A}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{49C0AD45-B0EC-4269-A835-8B030EC581E2}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{19BE1E9C-AC59-470C-BBCD-98BECA9E85A7}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{4D6C83A7-909E-4C0A-B3D5-357487D645C4}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{03118B24-2007-4293-8998-542E36444CA9}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{9A553C5B-1EBC-4DCB-A10E-66B88F94201B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2B76C6FE-E1DC-4397-BA0A-D6734B8751BC}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A5B23043-C746-438C-81B0-A085181C21BA}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{B190F402-3987-4C17-A378-DECC945D9B81}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A0E58455-BAFE-452B-BAEF-96BFF802A092}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5C33063E-3275-4C42-ABF4-46C4040D7EA1}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{86C1E415-B4BF-4F3C-BB38-11F3DD68A10B}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{6BFC7EC3-0BEB-48D6-B224-ED4514101962}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{E835EAFF-A9E5-4B08-8CFF-DD3E24B4C181}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{77635F33-8C8F-45FF-86E1-9A6C9D483F7E}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{5BA58341-FD0B-44AB-A342-24D56E407BCA}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{3B446B86-C0F6-4357-ACE3-414324583F86}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{DC765240-7E3C-4D8A-92B7-D4D54123F799}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{AFB4F74E-6BA2-4C91-AFB5-916FDA3EA952}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{35612C8D-5BB2-4181-9BE2-F08085BEF6F3}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{761E73D3-5682-4A2C-B122-46F873475C1C}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{ED5D5A99-167E-4554-975B-D8C9EAE78F81}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{D5714C85-8C15-492E-B50B-BCE8A19B62C1}] => (Allow) D:\Spiele\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{1574C306-2D8A-40F8-826A-B5A7FA10403C}] => (Allow) D:\Spiele\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{D4B6A2ED-AD9D-4D38-964E-0A1C8E2A998F}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe FirewallRules: [{321D3BD4-F475-403A-8974-54A37817B5B4}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe FirewallRules: [{D5DC5B0C-CA5A-4E46-B129-B6C2538A264C}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe FirewallRules: [{3E5F4512-E51D-4DE0-A0AC-46061184E911}] => (Allow) D:\Spiele\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe FirewallRules: [{AFE926DF-BC90-4112-9B81-83B1E258FE8D}] => (Allow) D:\Spiele\Steam\SteamApps\common\BioShock Remastered\Build\Final\BioshockHD.exe FirewallRules: [{557E186A-CCE3-4847-B90E-2FEE152B7DED}] => (Allow) D:\Spiele\Steam\SteamApps\common\BioShock Remastered\Build\Final\BioshockHD.exe FirewallRules: [{4537F972-1C53-4EC2-BFBF-3F528EA6F61D}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{A60CD73D-B8ED-48B6-A058-3B984F286F00}] => (Allow) D:\Spiele\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe ==================== Wiederherstellungspunkte ========================= 11-02-2017 00:00:02 Geplanter Prüfpunkt 18-02-2017 10:11:03 Geplanter Prüfpunkt 25-02-2017 20:46:25 Geplanter Prüfpunkt 28-02-2017 13:23:01 Removed SlimDrivers 28-02-2017 15:01:08 JRT Pre-Junkware Removal ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Realtek PCIe GBE Family Controller Description: Realtek PCIe GBE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: D-Link AirPlus G DWL-G510 Wireless PCI Adapter(rev.C) Description: D-Link AirPlus G DWL-G510 Wireless PCI Adapter(rev.C) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: D-Link Corporation Service: rt61x64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (02/28/2017 04:22:49 PM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: Ein HTTP-Status '503' wurde vom Client-Dienst 'Sophos Management Communications System' an den Server übermittelt. Unter Umständen bedeutet das, dass Handlungsbedarf vorhanden ist. Error: (02/28/2017 04:21:43 PM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: Ein HTTP-Status '503' wurde vom Client-Dienst 'Sophos Management Communications System' an den Server übermittelt. Unter Umständen bedeutet das, dass Handlungsbedarf vorhanden ist. Error: (02/28/2017 04:20:37 PM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: Ein HTTP-Status '503' wurde vom Client-Dienst 'Sophos Management Communications System' an den Server übermittelt. Unter Umständen bedeutet das, dass Handlungsbedarf vorhanden ist. Error: (02/28/2017 04:18:01 PM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: Ein HTTP-Status '503' wurde vom Client-Dienst 'Sophos Management Communications System' an den Server übermittelt. Unter Umständen bedeutet das, dass Handlungsbedarf vorhanden ist. Error: (02/28/2017 04:16:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (02/28/2017 04:16:43 PM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: Ein HTTP-Status '503' wurde vom Client-Dienst 'Sophos Management Communications System' an den Server übermittelt. Unter Umständen bedeutet das, dass Handlungsbedarf vorhanden ist. Error: (02/28/2017 03:11:29 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (02/28/2017 03:08:33 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: ATI EEU Service event error Error: (02/28/2017 03:06:58 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: ATI EEU Service event error Error: (02/28/2017 03:01:56 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: ATI EEU Service event error Systemfehler: ============= Error: (02/28/2017 04:15:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: ignis Error: (02/28/2017 04:15:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Apple Mobile Device Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (02/28/2017 04:15:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device Service erreicht. Error: (02/28/2017 04:15:26 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 28.02.2017 um 16:13:37 unerwartet heruntergefahren. Error: (02/28/2017 04:14:52 PM) (Source: Application Popup) (EventID: 56) (User: ) Description: Treiber PCI hat eine ungültige ID für das untergeordnete Gerät (03000000684CE00000) zurückgegeben. Error: (02/28/2017 03:11:26 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: ignis Error: (02/28/2017 03:10:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Apple Mobile Device Service" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (02/28/2017 03:10:41 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device Service erreicht. Error: (02/28/2017 03:09:31 PM) (Source: Application Popup) (EventID: 56) (User: ) Description: Treiber PCI hat eine ungültige ID für das untergeordnete Gerät (03000000684CE00000) zurückgegeben. Error: (02/28/2017 02:45:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: ignis ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Prozentuale Nutzung des RAM: 42% Installierter physikalischer RAM: 12286.15 MB Verfügbarer physikalischer RAM: 7121.77 MB Summe virtueller Speicher: 24570.48 MB Verfügbarer virtueller Speicher: 19579.61 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:241.76 GB) NTFS Drive d: () (Fixed) (Total:931.51 GB) (Free:240.6 GB) NTFS Drive f: (Work) (Fixed) (Total:2794.39 GB) (Free:1095.79 GB) NTFS Drive g: (SAMSUNG) (Fixed) (Total:1397.26 GB) (Free:94.13 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 217597F8) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 11E3F74A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 3 (Size: 1397.3 GB) (Disk ID: 742FD276) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
01.03.2017, 11:06 | #5 |
/// TB-Ausbilder | Adware in Chrome Servus, Du hast da mindestens eine illegale/gecrackte Software auf deinem Rechner: Microsoft Office Professional Plus 2010 Lesestoff: Illegale Software: Cracks, Keygens und Co Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter, wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems. |
05.03.2017, 09:55 | #6 |
/// TB-Ausbilder | Adware in Chrome Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu Adware in Chrome |
abhilfe, adware, andere, bestimmte, browser, entfernt, firefox, gestern, installiert, laufen, leute, log, malwarebytes, neue, neuen, posten, problem, programm, relativ, sache, sachen, tab, unerwünschte, werbeseite, öffnen |