|
Alles rund um Windows: Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufenWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
15.11.2021, 20:58 | #1 |
| Problem: Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Seit ca. 4 Wochen beklagt sich meine Frau, das "das Internet" so langsam geworden sei. Insb email programme (gmx) funktionieren praktisch gar nicht mehr. Als ich gestern dann doch auf ihr drängen hin einer meiner PCs abgeschalten haben, funktionierte alles von email bis netflix problem los. Darauf aufmerksam geworden, dass wohl dieser Rechner das Problem verursacht sah ich mir sein verhalten kritischer an. Tatsächlich, hier dauert der Aufbau von Verbindungen zu urls sehr lange, man kann in der Statuszeile zuschauen wie die verschiedenen Dieste angefragt werden, manchmal bricht auch die Verbindung ab, man muss neu laden, dann geht es wieder.... Im taskmanager werden die Ressourcen tw. auf 90% ausgelastet. Das erklärt wohl das laute Lüfter Geräusch.. Also ich habe mir was eingefangen. avast, avg und eset (jeweils die Gratisversion) installiert und alles durchsuchen lassen. Nichts. Die Log-files finde ich auch nicht bei den Onlineversionen die ich verwende. (sorry) Wenn ich den PC hoch fahre gibt es ca. 10 Minuten lang kein Problem, dann fängt wieder die Verbindung "langsam" zu werden an, und das oben beschriebene Verhalten setzt ein.... Danke für die Hilfe! Stephan |
15.11.2021, 21:16 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Anleitung / HilfePosten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
15.11.2021, 22:23 | #3 |
| Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Details FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2021 Ran by wohn (administrator) on DESKTOP-1GFHPO6 (HP HP EliteDesk 800 G4 DM 35W) (15-11-2021 20:37:04) Running from C:\Users\wohn\Downloads Loaded Profiles: wohn Platform: Microsoft Windows 10 Enterprise Version 21H1 19043.1348 (X64) Language: English (United States) Default browser: "C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe" --single-argument %1 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avast Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1189.1\AvastBrowserCrashHandler.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1189.1\AvastBrowserCrashHandler64.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4> (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4> (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe (AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\1.8.1188.1\AVGBrowserCrashHandler.exe (AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\1.8.1188.1\AVGBrowserCrashHandler64.exe (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\SysWOW64\UIUSrv.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_540f2c3a00626c78\igfxCUIService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_540f2c3a00626c78\igfxEM.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_c20bc7fe4fb9b481\OneApp.IGCC.WinService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6c531da99dfd5830\IntelCpHDCPSvc.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_6c531da99dfd5830\IntelCpHeciSvc.exe (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10> (NETGROUP -> ) C:\Users\wohn\AppData\Local\NetboxBrowser\netboxwallet.exe (NETGROUP -> The Netbox.Browser Authors) C:\Users\wohn\AppData\Local\NetboxBrowser\Application\netboxbrowser.exe <5> (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (Synaptics Incorporated -> Conexant Systems LLC.) C:\Windows\CxSvc\CxAudioSvc.exe (Synaptics Incorporated -> Conexant Systems LLC.) C:\Windows\CxSvc\CxUtilSvc.exe (Synaptics Incorporated -> Conexant Systems, Inc.) C:\Windows\System32\CxUIUSvc64.exe (Synaptics Incorporated -> Conexant) C:\Windows\System32\MicTray64.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [134936 2021-11-14] (Avast Software s.r.o. -> AVAST Software) HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [168376 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [288184 2021-11-10] (Intel Corporation -> Intel) HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Run: [NetboxBrowserAutoLaunch_80A637F412F952D50BEA0E3D72BBB461] => C:\Users\wohn\AppData\Local\NetboxBrowser\Application\netboxbrowser.exe [1991256 2021-10-29] (NETGROUP -> The Netbox.Browser Authors) HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Run: [Medal] => C:\Users\wohn\AppData\Local\Medal\update.exe [1833048 2021-02-17] (Ferox Games B.V. -> GitHub) HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Run: [Opera Browser Assistant] => C:\Users\wohn\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4105424 2021-10-14] (Opera Software AS -> Opera Software) HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Run: [AVGBrowserAutoLaunch_7C93A3F67FD77EE1EF50CA52DFFB2432] => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [2498752 2021-11-01] (AVG Technologies USA, LLC -> AVG Technologies) HKLM\...\Windows x64\Print Processors\HPCP1020PP: C:\Windows\System32\spool\prtprocs\x64\HPCP1020PP.DLL [73712 2016-01-06] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.) HKLM\...\Print\Monitors\HP CP1020 LM: C:\WINDOWS\system32\HPCP1020LM.DLL [137712 2016-01-06] (Microsoft Windows Hardware Compatibility Publisher -> ) HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\95.0.12827.71\Installer\chrmstp.exe [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\95.0.4638.69\Installer\chrmstp.exe [2021-11-02] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\95.0.12827.70\Installer\chrmstp.exe [2021-11-14] (Avast Software s.r.o. -> AVAST Software) HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2AA8E37B-EB91-4919-BBDB-973B3AAA443A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-05-27] (Google Inc -> Google LLC) Task: {34813988-B549-4AF3-867E-975C2A59BD3C} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" Task: {40AF50C0-3A03-40C7-A972-8ED5D44FB3B4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-05-27] (Google Inc -> Google LLC) Task: {4BE1658C-3C95-42D8-9F16-1A5AB5A60BE2} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_321_pepper.exe -check pepperplugin (No File) Task: {4DDD9FD2-B6F3-45CF-9740-E691190CCBE5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1778456 2021-11-14] (Avast Software s.r.o. -> Avast Software) Task: {511B2664-A3EE-40BD-86EC-5FE4F5F1575C} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3075936 2021-09-13] (Intel Corporation -> Intel Corporation) Task: {63D639EB-8EED-439F-B73E-51FFCBCD7C77} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193872 2021-11-14] (Avast Software s.r.o. -> AVAST Software) Task: {650F1A21-B049-4D76-AAC6-C8FCB5D1934F} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201656 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) Task: {6E5EA1FC-4929-4432-8BAA-848B9626CD67} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3075936 2021-09-13] (Intel Corporation -> Intel Corporation) Task: {6F39488A-0B3B-42A3-ADBF-BE4027338242} - System32\Tasks\Opera scheduled assistant Autoupdate 1576825458 => C:\Users\wohn\AppData\Local\Programs\Opera\launcher.exe [46227664 2021-10-20] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\wohn\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {805E411F-F5FA-4AB5-AE1D-446E97653229} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2495608 2021-11-01] (Avast Software s.r.o. -> AVAST Software) Task: {86FC8684-3E9F-4F36-BF0F-3CBB7B218F52} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5008312 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) Task: {8FA45C87-C93A-40A1-8DA5-8AAD4C186586} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [682936 2021-11-14] (Mozilla Corporation -> Mozilla Foundation) Task: {AF00122A-A6E3-429C-BEF9-563E9FA47955} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1815352 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) Task: {B2770F3E-A750-4689-B56A-B2E5A5932A3C} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\wohn\Downloads\ESETOnlineScanner_DEU.exe SCHED (No File) Task: {C5E48CB6-00F9-4BAC-A6AF-9474029F9536} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4974872 2021-11-14] (Avast Software s.r.o. -> AVAST Software) Task: {DAEE7EFB-4019-4306-80AE-B41CA478EE53} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File) Task: {DE720103-34D1-4844-BF51-D782162E89DB} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2495608 2021-11-01] (Avast Software s.r.o. -> AVAST Software) Task: {DF5C26D5-6CFF-4B57-9AFD-C13D9E0B9B01} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {E65BD07E-54CA-4F04-AB6A-48CED6245C9A} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [2498752 2021-11-01] (AVG Technologies USA, LLC -> AVG Technologies) Task: {EA86B791-27E8-49EB-9252-1ED682D4C97F} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [2498752 2021-11-01] (AVG Technologies USA, LLC -> AVG Technologies) Task: {EACB064E-5831-44C2-A7DF-926E9A7ECAFD} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193872 2021-11-14] (Avast Software s.r.o. -> AVAST Software) Task: {EC7E403A-5E48-4B45-977B-7DAAD63A0239} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201656 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) Task: {F53C6D48-BAEF-46F7-B1FF-314844845B8D} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\wohn\Downloads\ESETOnlineScanner_DEU.exe LOGON (No File) Task: {FCF64DE5-1F53-4340-ADD0-884D1CA2256E} - System32\Tasks\Opera scheduled Autoupdate 1558984892 => C:\Users\wohn\AppData\Local\Programs\Opera\launcher.exe [46227664 2021-10-20] (Opera Software AS -> Opera Software) Task: {FD5B8C94-A972-44BA-83F5-63ED721C6CFD} - System32\Tasks\Intel\Intel® Management and Security Status => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [860648 2019-04-03] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60 (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{f5af7d18-894e-4336-98f4-15beb6af9440}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge DefaultProfile: Default Edge Profile: C:\Users\wohn\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-15] FireFox: ======== FF DefaultProfile: cecf4tg6.default FF ProfilePath: C:\Users\wohn\AppData\Roaming\Mozilla\Firefox\Profiles\cecf4tg6.default [2019-05-27] FF ProfilePath: C:\Users\wohn\AppData\Roaming\Mozilla\Firefox\Profiles\r15kmoao.default-release [2021-11-15] FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1189.1\npAvastBrowserUpdate3.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1189.1\npAvastBrowserUpdate3.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1188.1\npAvgBrowserUpdate3.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1188.1\npAvgBrowserUpdate3.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default [2021-11-15] CHR Notifications: Default -> hxxps://check-out-this.site; hxxps://hideout.co; hxxps://tny.so; hxxps://uplibra.io CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxps://www.waff.at/" CHR Session Restore: Default -> is enabled. CHR Extension: (Präsentationen) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-05-27] CHR Extension: (Docs) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-05-27] CHR Extension: (Lucidchart Diagrams) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apboafhkiegglekeafbckfjldecefkhn [2020-05-24] CHR Extension: (Google Drive) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-20] CHR Extension: (Fotor Photo Editor) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbckhhmjfnmedpakkaaflpnmkamdppf [2019-07-17] CHR Extension: (YouTube) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-05-27] CHR Extension: (Best Draw.io Diagram Tool) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\cchkdgeljiellkglonkiciahfdhnpcen [2019-11-13] CHR Extension: (Calculator) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\decmldkknaaemlafplkkdmmmelbdnlja [2019-07-17] CHR Extension: (Clipchamp – Video-Editor) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\delkpojpfkkfgmknffmblbhmlamkjioi [2021-05-12] CHR Extension: (Polarr Photo Editor) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\djonnbgfieijldcieafgjcnhmpcfpmgg [2019-12-02] CHR Extension: (Kostenlose Filme, free movies) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaegjaoflfhniefnpbojpfmlagpabbl [2019-07-17] CHR Extension: (Tabellen) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-05-27] CHR Extension: (EBook Offline Reader) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkidldjfpemdgkehdhkoehplkbkcadfa [2019-07-17] CHR Extension: (IBA Opt-out (by Google)) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2019-07-17] CHR Extension: (Office Editor) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2021-08-06] CHR Extension: (Google Docs Offline) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-10-14] CHR Extension: (ShareSurface) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\hchbohooppdogpfbjejghgilkjdifgbb [2019-07-17] CHR Extension: (Zoom) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2021-09-20] CHR Extension: (Talk Connect) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\jodhknddnkalmefanjhlcaiackbcjfib [2021-09-06] CHR Extension: (Document and Image Converter Toolbox) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpjkaekegnficmcdgicgdbnpnjiaeldi [2019-07-17] CHR Extension: (IPP / CUPS printing for Chrome & Chromebooks) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkhfeoafdgbaecajkdbioenncjopbpmk [2019-07-17] CHR Extension: (PowerPoint Online) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdafamggmaaaginooondinjgkgcbpnhp [2019-07-17] CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2021-10-21] CHR Extension: (Screencastify Video Editor) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnkmedmlejehdecjaadjnhmjgklkpfgo [2019-07-17] CHR Extension: (Sticky Notes) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbjdhgkkhefpifbifjiflpaajchdkhpg [2019-07-17] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Google Mail) - C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-27] CHR Profile: C:\Users\wohn\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-05-16] CHR Profile: C:\Users\wohn\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-16] Opera: ======= OPR Profile: C:\Users\wohn\AppData\Roaming\Opera Software\Opera Stable [2021-11-15] OPR Notifications: Opera Stable -> hxxps://cryptowat.ch; hxxps://freebitco.in; hxxps://uplibra.io OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} OPR Extension: (Rich Hints Agent) - C:\Users\wohn\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-11-11] OPR Extension: (Amazon Assistant Promotion) - C:\Users\wohn\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-08-14] OPR Extension: (Install Chrome Extensions) - C:\Users\wohn\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2019-12-16] OPR Extension: (Bookmark All Tabs) - C:\Users\wohn\AppData\Roaming\Opera Software\Opera Stable\Extensions\kkebajkjjlghneokjfloegmblkleahji [2020-05-24] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8376400 2021-11-14] (Avast Software s.r.o. -> AVAST Software) S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193872 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [680728 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [427800 2021-11-14] (Avast Software s.r.o. -> AVAST Software) S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193872 2021-11-14] (Avast Software s.r.o. -> AVAST Software) S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\95.0.12827.70\elevation_service.exe [1713640 2021-11-01] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2021-11-14] (Avast Software s.r.o. -> AVAST Software) S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201656 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [713656 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [460728 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [8413296 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201656 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies) S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\95.0.12827.71\elevation_service.exe [1713672 2021-11-01] (AVG Technologies USA, LLC -> AVG Technologies) R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R2 CxAudioSvc; C:\WINDOWS\CxSvc\CxAudioSvc.exe [85528 2021-07-13] (Synaptics Incorporated -> Conexant Systems LLC.) R2 CxUIUSvc; C:\WINDOWS\System32\CxUIUSvc64.exe [123256 2021-07-13] (Synaptics Incorporated -> Conexant Systems, Inc.) R2 CxUtilSvc; C:\Windows\CxSvc\CxUtilSvc.exe [173880 2020-07-27] (Synaptics Incorporated -> Conexant Systems LLC.) R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [39352 2021-11-10] (Intel Corporation -> Intel) R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [177592 2021-11-10] (Intel Corporation -> Intel) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803952 2019-08-02] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 mracsvc; C:\WINDOWS\System32\mracsvc.exe [18534552 2019-10-08] (Mail.Ru LLC -> LLC Mail.Ru) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6103464 2021-11-10] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [35704 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [222112 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [367656 2021-11-15] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [250392 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [99344 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [21936 2021-11-14] (Microsoft Windows Early Launch Anti-Malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [41344 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [184648 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [538976 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [107848 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [82904 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852216 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [557648 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [214384 2021-11-14] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [317696 2021-11-14] (Avast Software s.r.o. -> AVAST Software) S0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [35872 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [222264 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [367728 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [250456 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [99432 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [21960 2021-11-15] (Microsoft Windows Early Launch Anti-Malware Publisher -> AVG Technologies CZ, s.r.o.) S3 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [41504 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [184800 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [539144 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [107976 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [83040 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [852352 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [557784 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [214496 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [317840 2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed] S3 mracdrv; C:\WINDOWS\System32\drivers\mracdrv.sys [17770920 2019-10-08] (Mail.Ru LLC -> LLC Mail.Ru) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48520 2021-11-02] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [435424 2021-11-02] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-02] (Microsoft Windows -> Microsoft Corporation) U3 avgbdisk; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-15 19:24 - 2021-11-15 19:25 - 000056642 _____ C:\Users\wohn\Downloads\Addition.txt 2021-11-15 19:23 - 2021-11-15 20:37 - 000031193 _____ C:\Users\wohn\Downloads\FRST.txt 2021-11-15 19:23 - 2021-11-15 20:37 - 000000000 ____D C:\FRST 2021-11-15 18:59 - 2021-11-15 18:59 - 002311680 _____ (Farbar) C:\Users\wohn\Downloads\FRST64.exe 2021-11-15 18:43 - 2021-11-15 18:44 - 000000000 ____D C:\ProgramData\PC Cleaner 2021-11-15 18:40 - 2021-11-15 18:40 - 013543496 _____ C:\Users\wohn\Downloads\bitdefender_online.exe 2021-11-15 18:36 - 2021-11-15 18:36 - 000003826 _____ C:\WINDOWS\system32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) 2021-11-15 18:36 - 2021-11-15 18:36 - 000003242 _____ C:\WINDOWS\system32\Tasks\AVG Secure Browser Heartbeat Task (Logon) 2021-11-15 18:36 - 2021-11-15 18:36 - 000002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk 2021-11-15 18:36 - 2021-11-15 18:36 - 000002412 _____ C:\Users\Public\Desktop\AVG Secure Browser.lnk 2021-11-15 18:34 - 2021-11-15 18:34 - 000003626 _____ C:\WINDOWS\system32\Tasks\AVGUpdateTaskMachineUA 2021-11-15 18:34 - 2021-11-15 18:34 - 000003502 _____ C:\WINDOWS\system32\Tasks\AVGUpdateTaskMachineCore 2021-11-15 18:34 - 2021-11-15 18:34 - 000000000 ____D C:\Program Files (x86)\AVG 2021-11-15 18:33 - 2021-11-15 18:36 - 000000000 ____D C:\Users\wohn\AppData\Local\AVG 2021-11-15 18:30 - 2021-11-15 18:30 - 000002071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG AntiVirus FREE.lnk 2021-11-15 18:30 - 2021-11-15 18:30 - 000002059 _____ C:\Users\Public\Desktop\AVG AntiVirus FREE.lnk 2021-11-15 18:30 - 2021-11-15 18:30 - 000000000 ____D C:\Users\wohn\AppData\Roaming\AVG 2021-11-15 18:27 - 2021-11-15 18:27 - 000852352 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000557784 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000539144 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetHub.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000367728 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000336824 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe 2021-11-15 18:27 - 2021-11-15 18:27 - 000317840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000316736 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys.163699724339002 2021-11-15 18:27 - 2021-11-15 18:27 - 000250456 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000222264 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000214496 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000184800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000107976 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000099432 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000083040 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000041504 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000035872 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArDisk.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000021960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgElam.sys 2021-11-15 18:27 - 2021-11-15 18:27 - 000003992 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update 2021-11-15 18:27 - 2021-11-15 18:27 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG 2021-11-15 18:27 - 2021-11-15 18:27 - 000000000 ____D C:\Program Files\Common Files\AVG 2021-11-15 18:25 - 2021-11-15 18:25 - 000000000 ____D C:\Program Files\AVG 2021-11-15 18:24 - 2021-11-15 18:27 - 000000000 ____D C:\ProgramData\AVG 2021-11-15 18:24 - 2021-11-15 18:24 - 000224072 _____ (AVG Technologies CZ, s.r.o.) C:\Users\wohn\Downloads\avg_antivirus_free_setup.exe 2021-11-15 18:22 - 2021-11-15 18:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-11-15 06:46 - 2021-11-15 06:46 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000005-000000.txt 2021-11-15 06:46 - 2021-11-15 06:46 - 000000000 ___HD C:\$WinREAgent 2021-11-14 10:11 - 2021-11-15 17:39 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk 2021-11-14 10:11 - 2021-11-15 17:39 - 000002463 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk 2021-11-14 10:11 - 2021-11-14 10:11 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) 2021-11-14 10:11 - 2021-11-14 10:11 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon) 2021-11-14 10:07 - 2021-11-14 10:07 - 000003668 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineUA 2021-11-14 10:07 - 2021-11-14 10:07 - 000003544 _____ C:\WINDOWS\system32\Tasks\AvastUpdateTaskMachineCore 2021-11-14 10:07 - 2021-11-14 10:07 - 000000000 ____D C:\Program Files (x86)\AVAST Software 2021-11-14 10:02 - 2021-11-15 18:37 - 000000000 ____D C:\Users\wohn\AppData\Local\Avast Software 2021-11-14 10:01 - 2021-11-14 10:01 - 000002160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2021-11-14 10:01 - 2021-11-14 10:01 - 000002148 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2021-11-14 10:01 - 2021-11-14 10:01 - 000000000 ____D C:\Users\wohn\AppData\Roaming\Avast Software 2021-11-14 09:57 - 2021-11-15 13:57 - 000367656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000852216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000557648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000538976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000340248 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2021-11-14 09:57 - 2021-11-14 09:57 - 000317696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000250392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000222112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000214384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000184648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000107848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000099344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000082904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000041344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000035704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000021936 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys 2021-11-14 09:57 - 2021-11-14 09:57 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2021-11-14 09:57 - 2021-11-14 09:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2021-11-14 09:57 - 2021-11-14 09:57 - 000000000 ____D C:\Program Files\Common Files\Avast Software 2021-11-14 09:54 - 2021-11-15 17:39 - 000000000 ____D C:\ProgramData\Avast Software 2021-11-14 09:54 - 2021-11-14 09:54 - 000000000 ____D C:\Program Files\Avast Software 2021-11-14 09:53 - 2021-11-14 09:53 - 000234280 _____ (AVAST Software) C:\Users\wohn\Downloads\avast_free_antivirus_setup_online(2).exe 2021-11-14 09:53 - 2021-11-14 09:53 - 000234280 _____ (AVAST Software) C:\Users\wohn\Downloads\avast_free_antivirus_setup_online(1).exe 2021-11-14 09:52 - 2021-11-14 09:53 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-11-14 09:51 - 2021-11-14 09:51 - 000234280 _____ (AVAST Software) C:\Users\wohn\Downloads\avast_free_antivirus_setup_online.exe 2021-11-14 08:49 - 2021-11-15 18:51 - 000001271 _____ C:\Users\wohn\Desktop\ESET Online Scanner.lnk 2021-11-14 08:48 - 2021-11-14 08:48 - 013311448 _____ (ESET) C:\Users\wohn\Downloads\esetonlinescanner.exe 2021-11-11 22:53 - 2021-11-11 22:53 - 000001510 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk 2021-11-10 22:41 - 2021-11-10 22:41 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000004-000000.txt 2021-11-10 17:36 - 2021-11-10 17:36 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe 2021-11-10 17:36 - 2021-11-10 17:36 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-11-10 17:36 - 2021-11-10 17:36 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2021-11-10 17:36 - 2021-11-10 17:36 - 000011363 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-11-09 17:14 - 2021-11-09 17:14 - 000942408 _____ (Intel Corporation) C:\WINDOWS\system32\libmfxhw64.dll 2021-11-09 17:14 - 2021-11-09 17:14 - 000703208 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\libmfxhw32.dll 2021-11-09 17:14 - 2021-11-09 17:14 - 000497512 _____ (Intel) C:\WINDOWS\system32\libvpl.dll 2021-11-09 17:14 - 2021-11-09 17:14 - 000431336 _____ (Intel) C:\WINDOWS\SysWOW64\libvpl.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 027888040 _____ (Intel Corporation) C:\WINDOWS\system32\mfxplugin64_hw.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 020630440 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\mfxplugin32_hw.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 001861760 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2021-11-09 17:13 - 2021-11-09 17:13 - 001861760 _____ C:\WINDOWS\system32\vulkaninfo.exe 2021-11-09 17:13 - 2021-11-09 17:13 - 001441424 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2021-11-09 17:13 - 2021-11-09 17:13 - 001441424 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2021-11-09 17:13 - 2021-11-09 17:13 - 001107056 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 001107056 _____ C:\WINDOWS\system32\vulkan-1.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000960624 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000960624 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000499096 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000450456 _____ C:\WINDOWS\system32\ze_tracing_layer.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000369560 _____ C:\WINDOWS\system32\ze_loader.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000361896 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000140176 _____ C:\WINDOWS\system32\ze_validation_layer.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000039032 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll 2021-11-09 17:13 - 2021-11-09 17:13 - 000036400 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll 2021-11-09 17:12 - 2021-11-09 17:12 - 000304208 _____ C:\WINDOWS\system32\ControlLib.dll ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-15 20:30 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-11-15 20:28 - 2019-05-27 20:07 - 000000000 ____D C:\Program Files (x86)\Google 2021-11-15 20:16 - 2021-04-12 06:15 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-11-15 19:05 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-11-15 19:05 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-11-15 18:52 - 2019-05-27 20:22 - 000000000 ____D C:\ProgramData\Mozilla 2021-11-15 18:51 - 2020-01-08 16:42 - 000001377 _____ C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk 2021-11-15 18:51 - 2019-05-27 20:22 - 000000000 ____D C:\Users\wohn\AppData\LocalLow\Mozilla 2021-11-15 18:50 - 2019-07-19 18:11 - 000000000 ____D C:\Users\wohn\AppData\Roaming\NetboxWallet 2021-11-15 18:50 - 2019-07-17 22:11 - 000000000 __SHD C:\Users\wohn\IntelGraphicsProfiles 2021-11-15 18:48 - 2019-07-19 18:34 - 000000000 ____D C:\Users\wohn\AppData\Local\D3DSCache 2021-11-15 18:27 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2021-11-15 18:22 - 2019-05-27 20:22 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-11-15 18:22 - 2019-05-27 20:22 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-11-15 17:43 - 2021-04-12 16:54 - 000840662 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-11-15 17:43 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2021-11-15 17:39 - 2021-04-12 06:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-11-15 17:39 - 2021-04-12 06:15 - 000008192 ___SH C:\DumpStack.log.tmp 2021-11-15 17:39 - 2020-09-05 21:48 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-11-15 17:39 - 2020-09-05 21:48 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-11-15 17:39 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2021-11-15 17:39 - 2019-06-15 13:24 - 000000000 ____D C:\Intel 2021-11-15 17:39 - 2019-05-27 20:16 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-11-15 17:39 - 2019-05-27 20:16 - 000002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2021-11-15 07:02 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-11-14 22:47 - 2019-07-22 22:36 - 000000000 ____D C:\Users\wohn\AppData\Roaming\Telegram Desktop 2021-11-14 18:19 - 2019-05-27 19:47 - 000000000 ____D C:\ProgramData\Package Cache 2021-11-14 10:20 - 2019-08-24 17:50 - 000006581 _____ C:\WINDOWS\system32\InstallUtil.InstallLog 2021-11-14 10:20 - 2019-05-27 19:40 - 000000000 ____D C:\WINDOWS\CxSvc 2021-11-14 08:25 - 2020-05-25 19:14 - 000000000 ____D C:\Users\wohn\AppData\Roaming\RNRC 2021-11-14 08:25 - 2019-07-20 07:20 - 000000000 ____D C:\Users\wohn\AppData\Roaming\NetCoin 2021-11-11 22:53 - 2019-05-27 19:48 - 000000000 ____D C:\Program Files (x86)\Intel 2021-11-11 19:53 - 2019-07-20 07:20 - 000000000 ____D C:\ProgramData\boost_interprocess 2021-11-10 22:42 - 2021-04-12 06:15 - 000257920 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-11-10 22:41 - 2019-12-07 10:54 - 000000000 ___SD C:\WINDOWS\system32\AppV 2021-11-10 22:41 - 2019-12-07 10:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-11-10 22:41 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-11-10 22:41 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing 2021-11-09 18:12 - 2019-06-15 12:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-11-09 18:10 - 2019-06-15 12:50 - 141529560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-11-09 06:41 - 2019-07-19 18:10 - 000000000 ____D C:\Users\wohn\AppData\Local\NetboxBrowser 2021-11-08 10:43 - 2019-07-19 18:11 - 000002439 _____ C:\Users\wohn\Desktop\Netbox.lnk 2021-11-07 09:14 - 2021-04-12 06:19 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1698593899-983368009-612206484-1001 2021-11-07 09:14 - 2021-04-11 03:03 - 000002376 _____ C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-11-07 08:39 - 2020-09-03 15:10 - 000000000 ____D C:\Users\wohn\AppData\Roaming\Signal 2021-11-02 23:09 - 2019-07-17 21:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-10-26 16:43 - 2021-04-12 06:19 - 000004198 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1558984892 2021-10-26 16:43 - 2019-11-07 08:18 - 000001402 _____ C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2021-10-22 02:55 - 2019-05-27 18:08 - 000000000 ____D C:\Users\wohn\AppData\Local\Packages ==================== Files in the root of some directories ======== 2019-06-15 12:03 - 2020-02-21 13:47 - 000007605 _____ () C:\Users\wohn\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== --- --- --- --- --- --- [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2021 Ran by wohn (15-11-2021 20:37:57) Running from C:\Users\wohn\Downloads Microsoft Windows 10 Enterprise Version 21H1 19043.1348 (X64) (2021-04-12 05:19:27) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-1698593899-983368009-612206484-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1698593899-983368009-612206484-503 - Limited - Disabled) defaultuser0 (S-1-5-21-1698593899-983368009-612206484-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-1698593899-983368009-612206484-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1698593899-983368009-612206484-504 - Limited - Disabled) wohn (S-1-5-21-1698593899-983368009-612206484-1001 - Administrator - Enabled) => C:\Users\wohn ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG Antivirus (Disabled - Out of date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411} AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe) Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 21.9.2494 - Avast Software) Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 95.0.12827.70 - AVAST Software) Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1189.1 - AVAST Software) Hidden AVG AntiVirus FREE (HKLM\...\AVG Antivirus) (Version: 21.9.3209 - AVG Technologies) AVG Secure Browser (HKLM-x32\...\AVG Secure Browser) (Version: 95.0.12827.71 - AVG Technologies) AVG Update Helper (HKLM-x32\...\{EDB7AEE7-E932-4836-AE50-D3B0B7766CB5}) (Version: 1.8.1188.1 - AVG Technologies) Hidden Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.281.2 - Conexant) Electrum (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Electrum) (Version: 4.0.7 - Electrum Technologies GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 95.0.4638.69 - Google LLC) Intel Driver && Support Assistant (HKLM-x32\...\{D4A904AA-E027-424A-B21C-A9FE1B791169}) (Version: 21.6.39.7 - Intel) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{eb0d4a41-3065-42b0-a868-c60d42d3ea98}) (Version: 10.1.17695.8086 - Intel(R) Corporation) Hidden Intel(R) Computing Improvement Program (HKLM\...\{88B98508-2D8F-46F1-90AD-557BE40C7067}) (Version: 2.4.07642 - Intel Corporation) Intel(R) Graphics Driver Software (HKLM-x32\...\{9454a0e6-0762-48ec-b153-2a75b252d1fb}) (Version: 3.11.1.0 - Intel) Hidden Intel(R) Graphics Driver Software (HKLM-x32\...\{b4e016a7-e963-49d7-9b66-4d635026af31}) (Version: 3.11.1.0 - Intel) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1914.12.0.1255 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.52.230.1 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{c6de84fd-ece7-4c2a-9f06-8cabe7ab79a0}) (Version: 1.52.230.1 - Intel Corporation) Hidden Intel® Driver & Support Assistant (HKLM-x32\...\{8e97d87d-065f-48c1-bd2b-f7bff04dcfc1}) (Version: 21.6.39.7 - Intel) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 95.0.1020.53 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\OneDriveSetup.exe) (Version: 21.205.1003.0005 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\...\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox 94.0.1 (x64 de)) (Version: 94.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 67.0 - Mozilla) Netbox (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\NetboxBrowser) (Version: 92.0.4515.135 - The Netbox Authors) Opera Stable 80.0.4170.63 (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\Opera 80.0.4170.63) (Version: 80.0.4170.63 - Opera Software) Signal 1.35.1 (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\7d96caee-06e6-597c-9f2f-c7bb2e0948b4) (Version: 1.35.1 - Open Whisper Systems) Telegram Desktop version 3.2.2 (HKU\S-1-5-21-1698593899-983368009-612206484-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 3.2.2 - Telegram FZ-LLC) Packages: ========= Audio Controls -> C:\Program Files\WindowsApps\22094SynapticsIncorporate.AudioControls_1.3.99.0_x64__qt57b6kdvhcfw [2021-08-28] (Synaptics Hong Kong Limited, Taiwan Branch (H.K.)) BreeZip -> C:\Program Files\WindowsApps\3138AweZip.AweZip_1.4.8.0_x86__ffd303wmbhcjt [2021-08-28] (BreeZip) [MS Ad] Intel® Grafik-Kontrollraum -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt [2021-07-22] (INTEL CORP) [Startup Task] Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2021-04-12] (INTEL CORP) Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-11-12] (Microsoft Corporation) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-04-12] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-04-12] (Microsoft Corporation) [MS Ad] Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.56.43053.0_x64__8wekyb3d8bbwe [2021-11-03] (Microsoft Corporation) [Startup Task] Office Lens -> C:\Program Files\WindowsApps\Microsoft.OfficeLens_16.0.32001.0_x86__8wekyb3d8bbwe [2020-10-02] (Microsoft Corporation) Xbox 360 SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2019-08-25] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1698593899-983368009-612206484-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive - Personal] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6} ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-11-14] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-11-15] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Calculator.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=decmldkknaaemlafplkkdmmmelbdnlja ShortcutWithArgument: C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\EBook Offline Reader.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=fkidldjfpemdgkehdhkoehplkbkcadfa ShortcutWithArgument: C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Polarr Photo Editor.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=djonnbgfieijldcieafgjcnhmpcfpmgg ShortcutWithArgument: C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Sticky Notes.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nbjdhgkkhefpifbifjiflpaajchdkhpg ShortcutWithArgument: C:\Users\wohn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Zoom.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hmbjbjdpkobdjplfobhljndfdfdipjhg ==================== Loaded Modules (Whitelisted) ============= 2021-04-13 12:36 - 2021-04-13 12:36 - 005745664 _____ () [File not signed] C:\Program Files (x86)\Intel\Driver and Support Assistant\irmfuu_module.dll 2021-07-23 10:36 - 2021-07-23 10:36 - 001638912 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\SQLite.Interop.dll 2021-05-21 14:04 - 2021-05-21 14:04 - 000130048 _____ (Sam Grogan) [File not signed] [File is in use] C:\Program Files (x86)\Intel\Driver and Support Assistant\NotifyIconWin32.dll 2021-07-23 10:36 - 2021-07-23 10:36 - 002122240 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC SearchScopes: HKU\S-1-5-21-1698593899-983368009-612206484-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 SearchScopes: HKU\S-1-5-21-1698593899-983368009-612206484-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 12:47 - 2016-07-16 12:45 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1698593899-983368009-612206484-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-1698593899-983368009-612206484-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{F9BA8CA6-6ABB-477A-8D9F-12FD05E1A87A}C:\users\wohn\appdata\local\programs\opera\74.0.3911.218\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.218\opera.exe => No File FirewallRules: [TCP Query User{C5CBE55B-88CD-45EA-93DF-ACF4EB70E614}C:\users\wohn\appdata\local\programs\opera\74.0.3911.218\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.218\opera.exe => No File FirewallRules: [UDP Query User{C29B5AD0-F83C-4B12-A6F7-7E10780BA217}C:\users\wohn\appdata\local\programs\opera\74.0.3911.203\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.203\opera.exe => No File FirewallRules: [TCP Query User{35F069A1-4108-4F7A-B567-A6CBF8ED25D0}C:\users\wohn\appdata\local\programs\opera\74.0.3911.203\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.203\opera.exe => No File FirewallRules: [UDP Query User{4E68C69C-C0B2-4F28-A328-CAD59D17C4DE}C:\users\wohn\appdata\local\programs\opera\74.0.3911.160\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.160\opera.exe => No File FirewallRules: [TCP Query User{CB0E9C4D-FE91-4A1F-8470-F97A1E6C1E4B}C:\users\wohn\appdata\local\programs\opera\74.0.3911.160\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.160\opera.exe => No File FirewallRules: [UDP Query User{695E09AB-87E6-4D8E-AB0C-35EBA8D69F6B}C:\users\wohn\appdata\local\programs\opera\74.0.3911.107\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.107\opera.exe => No File FirewallRules: [TCP Query User{AD63AA44-C0DB-412F-9EBA-33D9D204CC04}C:\users\wohn\appdata\local\programs\opera\74.0.3911.107\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\74.0.3911.107\opera.exe => No File FirewallRules: [UDP Query User{78A482D8-57C4-4D4C-B8F1-47874CF2CFED}C:\users\wohn\appdata\local\programs\opera\73.0.3856.344\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.344\opera.exe => No File FirewallRules: [TCP Query User{AA14B0C1-797D-4E1D-9344-D990C5FB8891}C:\users\wohn\appdata\local\programs\opera\73.0.3856.344\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.344\opera.exe => No File FirewallRules: [UDP Query User{C400413F-51AF-473D-99A6-84C0148909EA}C:\users\wohn\appdata\local\programs\opera\73.0.3856.329\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.329\opera.exe => No File FirewallRules: [TCP Query User{AE86E050-2DD4-4219-BB30-561D8D737905}C:\users\wohn\appdata\local\programs\opera\73.0.3856.329\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.329\opera.exe => No File FirewallRules: [UDP Query User{6A326E86-314B-4D93-88E0-249D5CA59A50}C:\users\wohn\appdata\local\programs\opera\73.0.3856.284\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.284\opera.exe => No File FirewallRules: [TCP Query User{1E09E198-37C1-49C3-8285-7F49852277C1}C:\users\wohn\appdata\local\programs\opera\73.0.3856.284\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\73.0.3856.284\opera.exe => No File FirewallRules: [UDP Query User{559FD9EB-C05C-47B6-875E-F63283713735}C:\users\wohn\appdata\local\programs\opera\72.0.3815.400\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.400\opera.exe => No File FirewallRules: [TCP Query User{7C4AB1A6-A204-471B-BE28-6B0BF9CDF8C7}C:\users\wohn\appdata\local\programs\opera\72.0.3815.400\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.400\opera.exe => No File FirewallRules: [UDP Query User{34130385-A09A-4B01-A976-0AA5BB10CEDF}C:\users\wohn\appdata\local\programs\opera\72.0.3815.320\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.320\opera.exe => No File FirewallRules: [TCP Query User{08B80132-5F3B-401E-BE03-1B85305794F6}C:\users\wohn\appdata\local\programs\opera\72.0.3815.320\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.320\opera.exe => No File FirewallRules: [UDP Query User{B8E1D131-294D-4AD4-A875-421E09DD8D1D}C:\users\wohn\appdata\local\programs\opera\72.0.3815.186\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.186\opera.exe => No File FirewallRules: [TCP Query User{8BC002C5-3E59-444A-97E6-9888FA1B6092}C:\users\wohn\appdata\local\programs\opera\72.0.3815.186\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\72.0.3815.186\opera.exe => No File FirewallRules: [UDP Query User{3F37B839-D68E-4321-9027-E21BAE3020D4}C:\users\wohn\appdata\local\programs\opera\71.0.3770.284\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.284\opera.exe => No File FirewallRules: [TCP Query User{8AF57DA1-FF86-4538-9AE9-99D9C98F6BF9}C:\users\wohn\appdata\local\programs\opera\71.0.3770.284\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.284\opera.exe => No File FirewallRules: [UDP Query User{0D26ADDC-563B-4AE1-9A18-8CB22447A781}C:\users\wohn\appdata\local\programs\opera\71.0.3770.271\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.271\opera.exe => No File FirewallRules: [TCP Query User{747B012A-4DC0-4872-9B1E-959B8AF67850}C:\users\wohn\appdata\local\programs\opera\71.0.3770.271\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.271\opera.exe => No File FirewallRules: [UDP Query User{6FC4B789-9BBA-4814-9AA9-1A20E38CBB09}C:\users\wohn\appdata\local\programs\opera\71.0.3770.228\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.228\opera.exe => No File FirewallRules: [TCP Query User{E991A218-A07B-4835-98AA-A9249950A51F}C:\users\wohn\appdata\local\programs\opera\71.0.3770.228\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.228\opera.exe => No File FirewallRules: [UDP Query User{295DF23C-74BA-4E2C-82D6-6146D0786DE8}C:\users\wohn\appdata\local\programs\opera\71.0.3770.198\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.198\opera.exe => No File FirewallRules: [TCP Query User{828F4765-256C-42E7-AAC5-8A047CDB3D76}C:\users\wohn\appdata\local\programs\opera\71.0.3770.198\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\71.0.3770.198\opera.exe => No File FirewallRules: [UDP Query User{C5A1143A-B724-4B6A-A05B-1E763E67EE1E}C:\users\wohn\appdata\local\programs\opera\70.0.3728.189\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.189\opera.exe => No File FirewallRules: [TCP Query User{6782E350-CB60-42E9-82A7-F972BF9C3DE1}C:\users\wohn\appdata\local\programs\opera\70.0.3728.189\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.189\opera.exe => No File FirewallRules: [UDP Query User{EB263424-798F-4D20-ACB6-56FF9337815F}C:\users\wohn\appdata\local\programs\opera\70.0.3728.178\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.178\opera.exe => No File FirewallRules: [TCP Query User{4DEF3AE7-3C9A-484F-A750-EB81F434CA3E}C:\users\wohn\appdata\local\programs\opera\70.0.3728.178\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.178\opera.exe => No File FirewallRules: [UDP Query User{F1442B75-C18B-4593-B8B1-06D18DB70CCE}C:\users\wohn\appdata\local\programs\opera\70.0.3728.154\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.154\opera.exe => No File FirewallRules: [TCP Query User{B24AED48-C2AC-43B8-8FAE-25BC004AC7F6}C:\users\wohn\appdata\local\programs\opera\70.0.3728.154\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.154\opera.exe => No File FirewallRules: [UDP Query User{F516C963-A24B-482E-92D0-F8EDB631E3A0}C:\users\wohn\appdata\local\programs\opera\70.0.3728.106\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.106\opera.exe => No File FirewallRules: [TCP Query User{B82007DA-E83F-4842-8EC3-3DC6FFDE1C68}C:\users\wohn\appdata\local\programs\opera\70.0.3728.106\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\70.0.3728.106\opera.exe => No File FirewallRules: [UDP Query User{F5F83620-EDBC-4CAD-A7EA-A3CEEC9A2B7B}C:\users\wohn\downloads\rnrc-v1.0.1-win-qt\rnrc-qt.exe] => (Allow) C:\users\wohn\downloads\rnrc-v1.0.1-win-qt\rnrc-qt.exe () [File not signed] FirewallRules: [TCP Query User{7FC45E72-735C-4AAB-AF94-11F571282B92}C:\users\wohn\downloads\rnrc-v1.0.1-win-qt\rnrc-qt.exe] => (Allow) C:\users\wohn\downloads\rnrc-v1.0.1-win-qt\rnrc-qt.exe () [File not signed] FirewallRules: [UDP Query User{D119DF03-148B-45DA-932A-9EDCDD97C134}C:\users\wohn\appdata\local\programs\opera\69.0.3686.95\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\69.0.3686.95\opera.exe => No File FirewallRules: [TCP Query User{434FE5AA-EF44-45D1-BF10-B028494B683A}C:\users\wohn\appdata\local\programs\opera\69.0.3686.95\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\69.0.3686.95\opera.exe => No File FirewallRules: [UDP Query User{89D71B1B-6732-45B7-9DCB-A4325B82CF74}C:\users\wohn\appdata\local\programs\opera\69.0.3686.77\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\69.0.3686.77\opera.exe => No File FirewallRules: [TCP Query User{BF44459D-514F-4F30-A502-CFF7647E3AEB}C:\users\wohn\appdata\local\programs\opera\69.0.3686.77\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\69.0.3686.77\opera.exe => No File FirewallRules: [UDP Query User{583A015A-752F-4CC7-B778-32F06F68266A}C:\users\wohn\appdata\local\programs\opera\68.0.3618.173\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.173\opera.exe => No File FirewallRules: [TCP Query User{79D7E858-53ED-40AD-8D0D-2F64564EDC25}C:\users\wohn\appdata\local\programs\opera\68.0.3618.173\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.173\opera.exe => No File FirewallRules: [UDP Query User{7639B46E-3B27-4840-BED6-8A5FC5A5518C}C:\users\wohn\appdata\local\programs\opera\68.0.3618.165\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.165\opera.exe => No File FirewallRules: [TCP Query User{2D5BE232-1F91-46E9-A153-6C7B9FB95F9E}C:\users\wohn\appdata\local\programs\opera\68.0.3618.165\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.165\opera.exe => No File FirewallRules: [UDP Query User{F38335A9-0D74-434E-B4DF-2E59C14C9858}C:\_stephan\rnrc-v1.0.1-win-qt\rnrc-qt.exe] => (Allow) C:\_stephan\rnrc-v1.0.1-win-qt\rnrc-qt.exe () [File not signed] FirewallRules: [TCP Query User{8BB707E0-2F35-4F32-8AB1-7826A30079F0}C:\_stephan\rnrc-v1.0.1-win-qt\rnrc-qt.exe] => (Allow) C:\_stephan\rnrc-v1.0.1-win-qt\rnrc-qt.exe () [File not signed] FirewallRules: [UDP Query User{90697D09-0EFA-4E8C-895E-0A3AA6FACA56}C:\users\wohn\appdata\local\programs\opera\68.0.3618.125\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.125\opera.exe => No File FirewallRules: [TCP Query User{1DE49EBD-2585-44A5-B595-FA3270FDF604}C:\users\wohn\appdata\local\programs\opera\68.0.3618.125\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.125\opera.exe => No File FirewallRules: [UDP Query User{8DB47E4D-F36F-46A6-A304-B552EA7F77E9}C:\users\wohn\appdata\local\programs\opera\68.0.3618.104\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.104\opera.exe => No File FirewallRules: [TCP Query User{827C2F46-A148-4FA0-86B0-DD0DA36C4500}C:\users\wohn\appdata\local\programs\opera\68.0.3618.104\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.104\opera.exe => No File FirewallRules: [UDP Query User{A9EFEAF6-F14B-4DE1-A9C8-0D48EB6D9D38}C:\users\wohn\appdata\local\programs\opera\68.0.3618.63\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.63\opera.exe => No File FirewallRules: [TCP Query User{D120DECD-7B3A-4DA0-8A35-6D81A6FF5E02}C:\users\wohn\appdata\local\programs\opera\68.0.3618.63\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\68.0.3618.63\opera.exe => No File FirewallRules: [UDP Query User{B99BF364-5A3E-443F-91C7-62E90383AB43}C:\users\wohn\desktop\fibercoin-qt.exe] => (Allow) C:\users\wohn\desktop\fibercoin-qt.exe () [File not signed] FirewallRules: [TCP Query User{04CB7A64-D6F8-424C-A330-9B9049BA1564}C:\users\wohn\desktop\fibercoin-qt.exe] => (Allow) C:\users\wohn\desktop\fibercoin-qt.exe () [File not signed] FirewallRules: [UDP Query User{D23B006B-7CA6-4AF5-A8DF-80D32AE0CD4A}C:\users\wohn\downloads\fibercoin-v2.0.0.0-win64\fibercoin-qt.exe] => (Allow) C:\users\wohn\downloads\fibercoin-v2.0.0.0-win64\fibercoin-qt.exe () [File not signed] FirewallRules: [TCP Query User{4B1C8784-7618-487D-8A8B-9FDFAE96CB3B}C:\users\wohn\downloads\fibercoin-v2.0.0.0-win64\fibercoin-qt.exe] => (Allow) C:\users\wohn\downloads\fibercoin-v2.0.0.0-win64\fibercoin-qt.exe () [File not signed] FirewallRules: [UDP Query User{BA1AB6F0-D3BC-4DA9-9B30-F593E532C97B}C:\users\wohn\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File FirewallRules: [TCP Query User{A7625393-4427-4CBC-9A46-EFB682C3D113}C:\users\wohn\appdata\local\programs\opera\67.0.3575.137\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.137\opera.exe => No File FirewallRules: [UDP Query User{A89B1662-C8E5-4FF9-A594-62ED9251B8D1}C:\users\wohn\appdata\local\programs\opera\67.0.3575.115\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.115\opera.exe => No File FirewallRules: [TCP Query User{DF86B779-C9F9-4EDF-ABB3-B1EC5842F825}C:\users\wohn\appdata\local\programs\opera\67.0.3575.115\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.115\opera.exe => No File FirewallRules: [UDP Query User{998A4CAE-137C-4755-9F8A-889844052585}C:\users\wohn\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File FirewallRules: [TCP Query User{448AAE22-E2F1-43D1-993C-978747FAC354}C:\users\wohn\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File FirewallRules: [UDP Query User{8D835535-9FB4-40A9-B4C0-E0F398BF3A45}C:\users\wohn\appdata\local\programs\opera\67.0.3575.79\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.79\opera.exe => No File FirewallRules: [TCP Query User{4F47D12D-C632-4469-8AE4-654951DB22EB}C:\users\wohn\appdata\local\programs\opera\67.0.3575.79\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.79\opera.exe => No File FirewallRules: [UDP Query User{D8145691-AB54-41CA-B133-010F19AC06CA}C:\users\wohn\appdata\local\programs\opera\67.0.3575.53\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.53\opera.exe => No File FirewallRules: [TCP Query User{B0826E15-D78B-423B-8B37-A9EF89F928DF}C:\users\wohn\appdata\local\programs\opera\67.0.3575.53\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\67.0.3575.53\opera.exe => No File FirewallRules: [UDP Query User{AA32128F-ECD9-4207-9BC3-FD3F50E5FBD2}C:\users\wohn\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.115\opera.exe => No File FirewallRules: [TCP Query User{41E45E2E-5877-4D4E-B7BF-EBC5B4CE479A}C:\users\wohn\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.115\opera.exe => No File FirewallRules: [UDP Query User{51F853B5-F96A-4FB1-A486-D86FE907033F}C:\users\wohn\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.103\opera.exe => No File FirewallRules: [TCP Query User{20777FC0-CD2B-44A8-A933-C9FC77E7A934}C:\users\wohn\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.103\opera.exe => No File FirewallRules: [UDP Query User{F3F028FF-6DC6-4018-BF63-8F5A3CAD7606}C:\users\wohn\appdata\local\programs\opera\66.0.3515.72\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.72\opera.exe => No File FirewallRules: [TCP Query User{DC11BB48-C0A2-49C0-A10A-D32289516ED6}C:\users\wohn\appdata\local\programs\opera\66.0.3515.72\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.72\opera.exe => No File FirewallRules: [UDP Query User{FA7449F7-1340-4D2C-AE49-C4CA9390D4C3}C:\users\wohn\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.44\opera.exe => No File FirewallRules: [TCP Query User{BA9BC2BE-87A7-4FC2-BF86-C8BF88417992}C:\users\wohn\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\66.0.3515.44\opera.exe => No File FirewallRules: [UDP Query User{B097B57B-C525-4E48-B5F6-C160D10AF532}C:\users\wohn\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File FirewallRules: [TCP Query User{44120AD7-DE8D-4879-BDE4-361B7FBD881F}C:\users\wohn\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.78\opera.exe => No File FirewallRules: [UDP Query User{C5650CE6-2E6C-45D5-A933-C7DE638BA855}C:\users\wohn\appdata\local\programs\opera\65.0.3467.72\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.72\opera.exe => No File FirewallRules: [TCP Query User{ECE7FCFE-7D75-4970-90CB-8C7E0405CA7E}C:\users\wohn\appdata\local\programs\opera\65.0.3467.72\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.72\opera.exe => No File FirewallRules: [UDP Query User{8E844D26-4DE8-4C4F-B4D0-B97F34948C2A}C:\users\wohn\appdata\local\programs\opera\65.0.3467.62\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.62\opera.exe => No File FirewallRules: [TCP Query User{421D2C37-70BF-4E56-B322-E5A64D9F4921}C:\users\wohn\appdata\local\programs\opera\65.0.3467.62\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.62\opera.exe => No File FirewallRules: [UDP Query User{FE25026D-0A85-4E2D-87B8-B333909F970A}C:\users\wohn\appdata\local\programs\opera\65.0.3467.48\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.48\opera.exe => No File FirewallRules: [TCP Query User{CBEFE2C0-C10B-4305-8193-39520160AFCF}C:\users\wohn\appdata\local\programs\opera\65.0.3467.48\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\65.0.3467.48\opera.exe => No File FirewallRules: [UDP Query User{60477030-59A6-4307-A8DC-55714F14A54B}C:\_stephan\deuro-win10-x64\digitaleuro-qt.exe] => (Allow) C:\_stephan\deuro-win10-x64\digitaleuro-qt.exe () [File not signed] FirewallRules: [TCP Query User{D1D88085-BD4C-46C0-9563-7E19A700739F}C:\_stephan\deuro-win10-x64\digitaleuro-qt.exe] => (Allow) C:\_stephan\deuro-win10-x64\digitaleuro-qt.exe () [File not signed] FirewallRules: [UDP Query User{6B522010-7962-4658-A783-36D7071F3FA3}C:\_stephan\fibercoin\fibrecoin.exe] => (Allow) C:\_stephan\fibercoin\fibrecoin.exe () [File not signed] FirewallRules: [TCP Query User{FDC3178D-9701-4B09-9205-5C58753806D4}C:\_stephan\fibercoin\fibrecoin.exe] => (Allow) C:\_stephan\fibercoin\fibrecoin.exe () [File not signed] FirewallRules: [UDP Query User{B2C22202-4D6F-4B3E-9754-BA23B66CC198}C:\users\wohn\downloads\deuro-win10-x64\digitaleuro-qt.exe] => (Allow) C:\users\wohn\downloads\deuro-win10-x64\digitaleuro-qt.exe => No File FirewallRules: [TCP Query User{F71F6219-8289-4A1A-8199-9B7F395122E3}C:\users\wohn\downloads\deuro-win10-x64\digitaleuro-qt.exe] => (Allow) C:\users\wohn\downloads\deuro-win10-x64\digitaleuro-qt.exe => No File FirewallRules: [UDP Query User{0D508F21-02F7-4D3B-BF36-A2997F392773}C:\users\wohn\downloads\fibrecoin.exe] => (Allow) C:\users\wohn\downloads\fibrecoin.exe => No File FirewallRules: [TCP Query User{7C81A10E-905A-4DC1-91C4-E8AA1124DED6}C:\users\wohn\downloads\fibrecoin.exe] => (Allow) C:\users\wohn\downloads\fibrecoin.exe => No File FirewallRules: [UDP Query User{72645BCA-D417-4200-9282-DA9A755CE4C7}C:\users\wohn\downloads\windows.aevo-qt.exe] => (Allow) C:\users\wohn\downloads\windows.aevo-qt.exe () [File not signed] FirewallRules: [TCP Query User{B7AA558A-DF17-4E83-B869-02DB0502F26B}C:\users\wohn\downloads\windows.aevo-qt.exe] => (Allow) C:\users\wohn\downloads\windows.aevo-qt.exe () [File not signed] FirewallRules: [UDP Query User{CE3545EA-2B13-4364-9A7D-6A7E0E30086B}C:\program files\secondlifeviewer\slvoice.exe] => (Allow) C:\program files\secondlifeviewer\slvoice.exe => No File FirewallRules: [TCP Query User{DA775077-C140-4A72-9A09-303CB983BCAE}C:\program files\secondlifeviewer\slvoice.exe] => (Allow) C:\program files\secondlifeviewer\slvoice.exe => No File FirewallRules: [UDP Query User{E5B6C405-E1E1-4695-8F0D-0AFCE8ABD922}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe => No File FirewallRules: [TCP Query User{2D20A275-364F-48DD-96BB-446B4907ECD1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe => No File FirewallRules: [UDP Query User{1B29AD44-5042-4C43-B357-8743FB481D74}C:\users\wohn\appdata\local\warthunder\win64\aces.exe] => (Block) C:\users\wohn\appdata\local\warthunder\win64\aces.exe => No File FirewallRules: [TCP Query User{68D1D90F-867F-4916-B0E7-B293D80E0EBC}C:\users\wohn\appdata\local\warthunder\win64\aces.exe] => (Block) C:\users\wohn\appdata\local\warthunder\win64\aces.exe => No File FirewallRules: [UDP Query User{4B3C41C0-E4DE-4231-878F-01ECD137D074}C:\users\wohn\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\wohn\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [TCP Query User{2A146C1C-D52F-4DD3-86EB-EAF35E5A7ABB}C:\users\wohn\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\wohn\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [UDP Query User{CDAC6ACA-CAC8-4E6F-9D0D-AD39A4A0018B}C:\users\wohn\appdata\local\warthunder\launcher.exe] => (Allow) C:\users\wohn\appdata\local\warthunder\launcher.exe => No File FirewallRules: [TCP Query User{ACC23C51-D070-415C-ACF0-26F8F5D71817}C:\users\wohn\appdata\local\warthunder\launcher.exe] => (Allow) C:\users\wohn\appdata\local\warthunder\launcher.exe => No File FirewallRules: [UDP Query User{992F8F16-C43B-4ADB-8060-9D0623C5A819}C:\users\wohn\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\wohn\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [TCP Query User{18569FA0-3B0A-4029-87C3-760EA2EA22B9}C:\users\wohn\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\wohn\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [UDP Query User{D3CDB946-2969-42D6-B73A-99E2B83EBA8D}C:\_stephan\aevo\windows.aevo-qt.exe] => (Allow) C:\_stephan\aevo\windows.aevo-qt.exe () [File not signed] FirewallRules: [TCP Query User{03F93BC2-D4BE-43C2-B9CF-65612B15089B}C:\_stephan\aevo\windows.aevo-qt.exe] => (Allow) C:\_stephan\aevo\windows.aevo-qt.exe () [File not signed] FirewallRules: [UDP Query User{0B5D3808-FC95-434A-A52C-CEE3A4C08F66}C:\program files (x86)\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe] => (Allow) C:\program files (x86)\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe () [File not signed] FirewallRules: [TCP Query User{F9EBA588-DE94-4136-AE4E-A0A1AF9EEB69}C:\program files (x86)\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe] => (Allow) C:\program files (x86)\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe () [File not signed] FirewallRules: [UDP Query User{078CB309-673A-4CF2-96E0-B8579BCE3E9C}C:\users\wohn\downloads\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe] => (Allow) C:\users\wohn\downloads\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe => No File FirewallRules: [TCP Query User{A7864B9B-2D96-4C0C-875F-B2029A6BD48B}C:\users\wohn\downloads\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe] => (Allow) C:\users\wohn\downloads\netcoin-3.0.0-x64\netcoin-3.0.0-x64.exe => No File FirewallRules: [{BD17A483-28A6-4E11-A0C1-551D8BC68984}] => (Allow) C:\Users\wohn\AppData\Local\NetboxBrowser\netboxwallet.exe (NETGROUP -> ) FirewallRules: [{506FD89E-87A1-4297-B773-5419F561E70D}] => (Allow) C:\Users\wohn\AppData\Local\NetboxBrowser\netboxwallet.exe (NETGROUP -> ) FirewallRules: [{19081F0D-CC06-4062-BB3F-E74F25D47DCF}] => (Allow) C:\Users\wohn\AppData\Local\NetboxBrowser\netboxwallet.exe (NETGROUP -> ) FirewallRules: [{068644AB-C143-4EB9-83C3-A4A79067A517}] => (Allow) C:\Users\wohn\AppData\Local\NetboxBrowser\netboxwallet.exe (NETGROUP -> ) FirewallRules: [{B3E5A341-D659-48C7-8EC4-85243E7A8DA6}] => (Allow) C:\Users\wohn\AppData\Local\NetboxBrowser\Application\netboxbrowser.exe (NETGROUP -> The Netbox.Browser Authors) FirewallRules: [{C7C33987-1549-411E-B57D-3C5D2D069CED}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{C11C097A-B0AD-4646-999A-328FB9131B82}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{15F06C60-AB68-4209-9A85-E89AF4B5A326}C:\users\wohn\appdata\local\programs\opera\75.0.3969.149\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.149\opera.exe => No File FirewallRules: [UDP Query User{C409B7C5-8045-4E37-82BF-5410969865BC}C:\users\wohn\appdata\local\programs\opera\75.0.3969.149\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.149\opera.exe => No File FirewallRules: [TCP Query User{AC0CF128-EFA9-4DCB-9D89-26EDE8E617C2}C:\users\wohn\appdata\local\programs\opera\75.0.3969.171\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.171\opera.exe => No File FirewallRules: [UDP Query User{9E46468B-D3A0-4E67-A46A-EE204B0573EB}C:\users\wohn\appdata\local\programs\opera\75.0.3969.171\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.171\opera.exe => No File FirewallRules: [TCP Query User{803543C9-A5CA-490B-8898-702B07C0623D}C:\users\wohn\appdata\local\programs\opera\75.0.3969.218\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.218\opera.exe => No File FirewallRules: [UDP Query User{86127679-74B1-4DF4-AC13-72D6C80D6ACA}C:\users\wohn\appdata\local\programs\opera\75.0.3969.218\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.218\opera.exe => No File FirewallRules: [TCP Query User{D239897A-001A-4DF9-8528-282EC72130E4}C:\users\wohn\appdata\local\programs\opera\75.0.3969.243\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.243\opera.exe => No File FirewallRules: [UDP Query User{4C06F081-A16B-42E0-B8A5-D74147117FE9}C:\users\wohn\appdata\local\programs\opera\75.0.3969.243\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\75.0.3969.243\opera.exe => No File FirewallRules: [TCP Query User{8FD52B17-08CD-4CB3-A080-17421ADF03AE}C:\users\wohn\appdata\local\programs\opera\76.0.4017.107\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.107\opera.exe => No File FirewallRules: [UDP Query User{56CD0FC7-EDE6-4273-BDC6-3ACFB747F11D}C:\users\wohn\appdata\local\programs\opera\76.0.4017.107\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.107\opera.exe => No File FirewallRules: [TCP Query User{9295A25B-B0E9-4628-BD5A-1F4C71CF3F42}C:\users\wohn\appdata\local\programs\opera\76.0.4017.123\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.123\opera.exe => No File FirewallRules: [UDP Query User{0D3C72C5-3A3E-400E-8425-2ECE36DA62F4}C:\users\wohn\appdata\local\programs\opera\76.0.4017.123\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.123\opera.exe => No File FirewallRules: [TCP Query User{7C899268-D611-41BF-A7CD-34FDD5587D05}C:\users\wohn\appdata\local\programs\opera\76.0.4017.154\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.154\opera.exe => No File FirewallRules: [UDP Query User{E0EF3A91-15C6-4D74-BB32-ECE3FA7B3765}C:\users\wohn\appdata\local\programs\opera\76.0.4017.154\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.154\opera.exe => No File FirewallRules: [TCP Query User{E6875AC0-7E62-43A9-A460-0D5A900BE243}C:\users\wohn\appdata\local\programs\opera\76.0.4017.177\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.177\opera.exe => No File FirewallRules: [UDP Query User{0CBDAF81-76F6-4B0A-91DE-065A7586B719}C:\users\wohn\appdata\local\programs\opera\76.0.4017.177\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\76.0.4017.177\opera.exe => No File FirewallRules: [TCP Query User{F98F0692-88E1-463C-AA6E-2B6BE2A0DE5E}C:\users\wohn\appdata\local\programs\opera\77.0.4054.90\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.90\opera.exe => No File FirewallRules: [UDP Query User{F99E68FD-72F8-4D4E-9C01-F0B3DDB47B70}C:\users\wohn\appdata\local\programs\opera\77.0.4054.90\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.90\opera.exe => No File FirewallRules: [TCP Query User{E1237100-15CD-4665-83D1-E5BF8D5B0023}C:\users\wohn\appdata\local\programs\opera\77.0.4054.172\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.172\opera.exe => No File FirewallRules: [UDP Query User{7A6CBEDE-B70B-45BD-9888-9375495F0615}C:\users\wohn\appdata\local\programs\opera\77.0.4054.172\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.172\opera.exe => No File FirewallRules: [TCP Query User{D7169D67-CC5E-41DD-B6D7-3D4D50566160}C:\users\wohn\appdata\local\programs\opera\77.0.4054.203\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.203\opera.exe => No File FirewallRules: [UDP Query User{837A80F1-C930-40E4-8B6B-F30B0F968084}C:\users\wohn\appdata\local\programs\opera\77.0.4054.203\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.203\opera.exe => No File FirewallRules: [TCP Query User{89FDAF03-D256-477A-A879-E9BE7A14E5E8}C:\users\wohn\appdata\local\programs\opera\77.0.4054.277\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.277\opera.exe => No File FirewallRules: [UDP Query User{E47FF9D0-4A8C-4004-A507-F4DAFC1E89D2}C:\users\wohn\appdata\local\programs\opera\77.0.4054.277\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\77.0.4054.277\opera.exe => No File FirewallRules: [{0DC86891-9F15-4CBF-8C5F-A4BC9A112828}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{83BAA105-2F50-4E2F-9C8E-5A7999776A61}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{FB32FFD3-DB88-4CDB-9A70-91ED85FA7574}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{5989B7C1-199A-4447-BBFD-8F18541B80E7}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [TCP Query User{C69652EA-EAD9-4F45-A213-AD0596BBC701}C:\users\wohn\appdata\local\programs\opera\78.0.4093.147\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.147\opera.exe => No File FirewallRules: [UDP Query User{7492D97B-A7CB-4C64-ABC0-48C8943FDBC0}C:\users\wohn\appdata\local\programs\opera\78.0.4093.147\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.147\opera.exe => No File FirewallRules: [TCP Query User{74BCFCF9-2F06-4EC6-A8D0-03BC6CE792C2}C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe => No File FirewallRules: [UDP Query User{338766C6-8E93-4FB7-B372-4C136FD4992B}C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe => No File FirewallRules: [TCP Query User{C92E42FC-C6A1-441F-BD82-1E0560EFA791}C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe => No File FirewallRules: [UDP Query User{81B72C40-C570-4EC3-9DCC-F79E839C11E9}C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\78.0.4093.169\opera.exe => No File FirewallRules: [TCP Query User{32B54DE3-0F8E-4B57-8D54-1AA1BE3CBFEF}C:\users\wohn\appdata\local\programs\opera\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [UDP Query User{A82F020E-0515-41C7-9194-EE3A03C03E4F}C:\users\wohn\appdata\local\programs\opera\opera.exe] => (Allow) C:\users\wohn\appdata\local\programs\opera\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{6DB6A038-3F37-4A1E-BD73-9E9C18D22FC7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{C3D290BC-8A4B-4CD3-82FE-D00D3277F069}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{7228BEA4-9F89-470B-A7F8-992F8341C104}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{72A71770-51EC-4CCB-BE14-C70E92871F78}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{8C773349-8A7F-4DE3-9FAF-44075DA7E8A4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{63796D62-9EE9-4CD1-BDA7-21C846E81828}] => (Block) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software) FirewallRules: [{4A639CFA-525C-47EF-B6C4-47C22165D025}] => (Block) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software) FirewallRules: [{239DCED0-BFE9-4EF8-996E-8B343BB66C83}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software) FirewallRules: [{2A054278-E519-4D41-AA88-858364D885D5}] => (Block) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) FirewallRules: [{E19BFAD9-2C80-4EB9-86ED-4E230DE435CD}] => (Block) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) FirewallRules: [{37C05CDE-E02D-4E4B-BC7B-2C4AAC0572DC}] => (Allow) C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe (AVG Technologies USA, LLC -> AVG Technologies) ==================== Restore Points ========================= 10-11-2021 16:55:23 Windows Modules Installer 11-11-2021 22:53:00 Intel® Driver & Support Assistant 15-11-2021 07:02:36 Windows Modules Installer ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (11/15/2021 08:31:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 08:21:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 08:11:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 08:01:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 07:51:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 07:41:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 07:31:19 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (11/15/2021 07:21:18 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-1GFHPO6) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. System errors: ============= Error: (11/15/2021 06:52:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (11/15/2021 06:52:25 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\wohn\AppData\Local\Temp\ehdrv.sys Error: (11/15/2021 06:52:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (11/15/2021 06:52:24 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\wohn\AppData\Local\Temp\ehdrv.sys Error: (11/15/2021 06:52:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (11/15/2021 06:52:24 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\wohn\AppData\Local\Temp\ehdrv.sys Error: (11/15/2021 06:52:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (11/15/2021 06:52:24 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\wohn\AppData\Local\Temp\ehdrv.sys Windows Defender: ================ Date: 2021-11-14 01:41:33 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-11-12 23:53:24 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-11-12 07:54:10 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-11-09 23:58:08 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-11-08 23:42:45 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan CodeIntegrity: =============== Date: 2021-11-15 19:04:24 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2021-11-15 17:50:06 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. ==================== Memory info =========================== BIOS: HP Q21 Ver. 02.06.03 02/15/2019 Motherboard: HP 83E2 Processor: Intel(R) Core(TM) i7-8700T CPU @ 2.40GHz Percentage of memory in use: 50% Total physical RAM: 16163.29 MB Available physical RAM: 7981.2 MB Total Virtual: 21795.29 MB Available Virtual: 12743.11 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:237.12 GB) (Free:151.51 GB) NTFS \\?\Volume{0a98fbbe-2422-4e09-baa7-8d2779f01f29}\ () (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS \\?\Volume{d9a214b8-c1a9-4696-bbfd-18c50e4883c5}\ () (Fixed) (Total:0.8 GB) (Free:0.38 GB) NTFS \\?\Volume{44f42bb9-7e6e-48b7-b234-558e9ce002b3}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ==================== End of Addition.txt ======================= |
15.11.2021, 22:26 | #4 |
| Lösung: Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen doppel post, sorry gelöscht Geändert von Razzorfish (15.11.2021 um 22:28 Uhr) Grund: doppelt gepostet |
15.11.2021, 22:28 | #5 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Wie Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Hier ist schon mal der erste Aufhänger: Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2021, 22:39 | #6 |
| Wo Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Lösung! Habe sie (gestern, vorgestern?) über den Windows updateservice installiert... laut update history wurde 21H1 am 15.11.21 installiert. Soll ich einen screenshot von der update history posten? (Die Version ist seit einiger Zeit nicht "active" (kleines graues Feld/Overlay rechts unten)) beantwortet das die Frage? vorher war Version 20H2. Das sind alte Rechner aus einer Firma, die ausgeschieden wurden.. (das ist jetzt wohl die Antwort auf deine Frage.) |
15.11.2021, 22:45 | #7 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufenZitat:
Und wer ist auf die grandiose Idee gekommen, gleich zwei schachsinnige Virenscanner wie Avast und AVG draufzuklatschen? Ich versteh es echt nicht mehr, seit Jahren redet man sich den Mund fusselig wie unsinnig und kontraproduktiv diese Software ist - und noch NIE hatte man dazu geraten gleich zwei oder noch mehr dieser Programme zu installieren. Das mit dem Enterprise-Windows ist eigentlich schon grund genug für eine saubere Neuinstallation von einem "normalen" Windows 10 HOME oder PRO.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2021, 22:52 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen Ich verschiebe jetzt nach Windows, das ganze hat nämlich nichts mit Schädlingen zu tun (auch wenn du wohl dir gerne Schädlinge wünscht, weil nur das die Ursache sein darf)
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2021, 23:02 | #9 |
| Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen scheinbar ist meine erst Antwort verschwunden. ist direkt vom windows updater. die rechner sind altbestand der ausgeschieden wurde.. (Windos wird als "Deaktiviert" angezeigt, rechts unten in einem grauen overlay.) Beantwortet das die Frage? |
15.11.2021, 23:06 | #10 |
| Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen [gelöst] Alte Rechner? Ja ne ist klar. Intel i7 8. Generation, 16 GAB RAM. Alles andere als alt. Wer gibt denn sowas ab? |
15.11.2021, 23:08 | #11 |
| Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen [gelöst] posting ist wieder da |
15.11.2021, 23:13 | #12 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen [gelöst]Zitat:
BIOS-Datum von 2019, keine drei Jahre alt. Sowas verschrottet/verscherbelt man doch nicht und wenn dann nur, wenn man vorher die HDD/SSD dadrin nullt oder ausbaut - das noch installierte Windows als Enterprise-Edition könnte auch gut ein Lizenzverstoß sein.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2021, 23:24 | #13 |
| Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen [gelöst] Der kann nicht vom LKW gefallen sein. Dann wäre das Gerät doch kaputt Irgendwie eine Räuberpistole das ganze. |
15.11.2021, 23:34 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen [gelöst] Ist eh wurscht jetzt. Das ist kein Schädlingproblem, sondern kaputtes Windows. Dann zusätzlich noch mit Avast und AVG zugemüllt…da lohnt sich nichts mehr saubere Neuinstallation ist das beste was man hier machen kann.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Irgendetwas frist up-/downloadspeed und bringt die PC-Kühlung zum laut laufen |
aufbau, avg, email, eset, funktionieren, gen, gmx, installiert, internet, laden, langsam, lüfter, neu, pcs, problem, programme, rechner, ressourcen, setzt, taskmanager, url-umleitung, verbindungen, verhalten, verschiedene, verursacht, virus, woche |