und addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020
Ran by ***** (01-04-2020 10:37:59)
Running from D:\!temp
Windows 10 Pro Version 1909 18363.752 (X64) (2019-09-15 18:11:03)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2325083572-1221612603-3422617723-500 - Administrator - Disabled)
* (S-1-5-21-2325083572-1221612603-3422617723-1001 - Administrator - Enabled) => C:\Users\c
***** (S-1-5-21-2325083572-1221612603-3422617723-1000 - Administrator - Enabled) => C:\Users\chris
DefaultAccount (S-1-5-21-2325083572-1221612603-3422617723-503 - Limited - Disabled)
Guest (S-1-5-21-2325083572-1221612603-3422617723-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2325083572-1221612603-3422617723-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (HKLM\...\{13DA9C7C-EBFB-40D0-94A1-55B42883DF21}) (Version: 21.2.1 - HP Inc.) Hidden
A Ruler for Windows (HKLM\...\{DCF4C336-18DB-449B-9238-821B7F28B614}_is1) (Version: 3.3.3 - Latour)
ADInstruments Cardiac Output 1.3 (HKLM-x32\...\{8CFC9019-C386-495B-8257-7DA98D2F1064}) (Version: 1.3.0400 - ADInstruments)
ADInstruments ECG Analysis 2.4 (HKLM-x32\...\{C5A6366C-1016-4478-8A1A-D05076746570}) (Version: 2.4.0400 - ADInstruments)
ADInstruments LabChart 8.1.9 (HKLM-x32\...\{C49799FB-A9EE-4856-85BC-051C80B39E97}) (Version: 8.1.9400 - ADInstruments)
ADInstruments Peak Analysis 1.5.1 (HKLM-x32\...\{34EBE20B-8716-4616-8235-F10C858246F5}) (Version: 1.5.1400 - ADInstruments)
ADInstruments PV Loop 2.4 (HKLM-x32\...\{14378098-4AF0-4BD2-8F93-3503C9AAC113}) (Version: 2.4.0400 - ADInstruments)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 31.0.0.96 - Adobe Systems Incorporated)
Adobe Connect (HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\...\Adobe Connect App) (Version: 2018.7.10.32 - Adobe Systems Inc.)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.344 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0407-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3B000145}) (Version: 1.7.45.1 - Alcor Micro Corp.) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.45.1 - Alcor Micro Corp.)
Apple Application Support (32-Bit) (HKLM-x32\...\{308F2F8C-9D33-4B22-8A6C-D9C13DBEF8C6}) (Version: 7.0.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{0CB84A7D-9697-4526-A819-60FB050E8F05}) (Version: 7.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{77F8C879-88CD-4145-945A-541C35285285}) (Version: 12.0.0.1039 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Attribute Changer 7.10e (HKLM-x32\...\{27263813-8BDE-4CD2-84D3-02536743428A}_is1) (Version: 7.10e - Romain Petges)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.55 - Piriform)
Connect2 (HKLM-x32\...\Connect2_is1) (Version: 4.1.1.3444 - Lenovo)
Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 5.49 - NCH Software)
Desktop Restore version 1.6.4 (HKLM\...\{DBD4F07A-7607-4A4F-A46C-6AA399E06E38}_is1) (Version: 1.6.4 - Jamie O'Connell)
Documentation Manager (HKLM\...\{885E5716-698F-47E6-9ABD-87260B6C80F7}) (Version: 21.80.2.1 - Intel Corporation) Hidden
Dolby Audio X2 Windows API SDK (HKLM\...\{F290F786-5F69-48D4-B20B-D21C7DE56EF0}) (Version: 0.8.8.88 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{D0D32569-4680-490A-905C-5117CEAAB3EF}) (Version: 0.8.8.76 - Dolby Laboratories, Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 93.4.273 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden
EndNote X7 (HKLM-x32\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.8.0.11583 - Thomson Reuters)
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 8.00 - NCH Software)
Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
FinePointe Client (64) (HKLM\...\{4C1EA41E-47B3-4FF0-94A1-ED5EAD16F37D}) (Version: 2.2.08 - Buxco Research Systems)
FinePointe version 2.4.6 (HKLM\...\{25B8ADD2-04FD-4E83-8594-6D0AE0ACCA6F}_is1) (Version: 2.4.6 - Data Sciences International)
FortiClient (HKLM\...\{E869338F-FD3D-4A12-9C1A-5583D1AE23FC}) (Version: 6.0.3.0155 - Fortinet Technologies Inc)
G Suite Migration For Microsoft Outlook® 4.2.7.0 (HKLM\...\{FB570A8C-2DA2-465F-B5A6-61FF190D60D5}) (Version: 4.2.7.0 - Google, Inc.)
G Suite Sync™ for Microsoft Outlook® 4.2.40.0 (HKLM\...\{6358D58F-4158-424A-956F-3413BBD9FA45}) (Version: 4.2.40.0 - Google, Inc.)
G*Power 3.1.9.2 (HKLM-x32\...\{F9C59D86-6F65-4EDB-89A2-FBA1F78762D2}) (Version: 3.1.92 - Franz Faul, Uni Kiel, Germany)
GDR 2269 for SQL Server 2014 (KB3045324) (64-bit) (HKLM\...\KB3045324) (Version: 12.0.2269.0 - Microsoft Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GoTo Opener (HKLM-x32\...\{0FC4261B-F502-48B3-B1CF-60021C8F7D22}) (Version: 1.0.481 - LogMeIn, Inc.)
GoToMeeting 10.9.0.17052 (HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\...\GoToMeeting) (Version: 10.9.0.17052 - LogMeIn, Inc.)
GraphPad Prism 6 (HKLM-x32\...\{606443B0-9831-11DC-5F90-015CFB7A6952}) (Version: 6.01 - GraphPad Software)
HandBrake 1.1.0 (HKLM-x32\...\HandBrake) (Version: 1.1.0 - )
IBM SPSS Statistics 24 (HKLM\...\{4762AE15-E5A3-43BF-8822-1CFC70FB147A}) (Version: 24.0.0.0 - IBM Corp)
ImageJ 1.48v (HKLM\...\ImageJ_is1) (Version: - NIH)
Intel(R) Chipset Device Software (HKLM-x32\...\{b23c55fa-5271-4d64-ba8f-6718be55b9a7}) (Version: 10.1.1.33 - Intel(R) Corporation) Hidden
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 20.2 - Intel)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.2.42 - Intel Corporation)
Intel(R) WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel(R) WiDi Software Asset Manager (HKLM-x32\...\{C7D64C31-3F1E-4205-87A5-B61AAE55E64B}) (Version: 3.4.1942 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000080-0210-1031-84C8-B8D95FA3C8C3}) (Version: 21.80.0.3 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{55fdbad7-83d5-40e8-83cb-a53fbd378e01}) (Version: 21.30.2 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{B294CE94-FE0F-4427-910C-180AF9FCFED1}) (Version: 1.0.1.620 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{45fc2606-7c3b-4963-966b-b6e0eae08246}) (Version: 21.80.2.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{9E84991B-6078-4311-A714-0A1360C3706C}) (Version: 12.9.0.167 - Apple Inc.)
Java 8 Update 241 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
Lenovo Active Protection System (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.82.00.20 - Lenovo)
Lenovo Mouse Suite (HKLM\...\MouseSuite98) (Version: 6.78 - Lenovo)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.12.14 - Lenovo) Hidden
Lenovo Service Bridge (HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.0.4 - Lenovo)
Lenovo System Update (HKLM-x32\...\TVSU_is1) (Version: 5.07.0093 - Lenovo)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
Lexmark MX410 Series Deinstallationsprogamm (HKLM\...\Lexmark MX410 Series) (Version: - Lexmark International, Inc.)
Lexmark Virtual Solution Center Plugin (HKLM-x32\...\Lexmark Virtual Solution Center Plugin 1.5.0) (Version: 1.5.0 - Lexmark)
Metric Collection SDK (HKLM-x32\...\{DDAA788F-52E6-44EA-ADB8-92837B11BF26}) (Version: 1.1.0005.00 - Lenovo Group Limited) Hidden
Micro Focus iPrint Client v06.06.00 (HKLM\...\Novell iPrint Client) (Version: - Micro Focus, Inc.)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 16.0.12527.20278 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.12527.20278 - Microsoft Corporation)
Microsoft Report Viewer 2014 Runtime (HKLM-x32\...\{327E9C0D-1687-414F-923E-F5979E549548}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation)
Microsoft SQL Server 2014 Policies (HKLM-x32\...\{1C30FE7E-8A8C-4492-89D6-10CB20C3B0EB}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Setup (English) (HKLM\...\{37C44B5C-E839-4A9D-9E20-A93E1B2FD35A}) (Version: 12.0.2269.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL Compiler Service (HKLM\...\{537203CB-708E-43A3-BA16-3D5C14A587BB}) (Version: 12.0.2269.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{8C06D6DB-A391-4686-B050-99CC522A7843}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: - )
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (HKLM-x32\...\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}) (Version: 14.11.25325.0 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Windows Media Video 9 VCM (HKLM-x32\...\WMV9_VCM) (Version: - )
Mozilla Firefox 74.0 (x64 de) (HKLM\...\Mozilla Firefox 74.0 (x64 de)) (Version: 74.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.6.1 - Mozilla)
Mozilla Thunderbird 60.6.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 60.6.1 (x86 en-US)) (Version: 60.6.1 - Mozilla)
Mozilla Thunderbird 60.9.1 (x86 en-US) (HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\...\Mozilla Thunderbird 60.9.1 (x86 en-US)) (Version: 60.9.1 - Mozilla)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.5.9 - Notepad++ Team)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden
Opera Stable 67.0.3575.115 (HKLM-x32\...\Opera 67.0.3575.115) (Version: 67.0.3575.115 - Opera Software)
Pelles C for Windows (HKLM-x32\...\PellesC) (Version: 8.00 - Pelle Orinius)
PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Prolific Technology INC)
Power Packet Utility (HKLM-x32\...\{808021CD-292E-4D1B-B927-C0D977AEAC79}) (Version: 6.1.0009 - Qualcomm Atheros)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8777.1 - Realtek Semiconductor Corp.) Hidden
ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - Thomson Reuters)
Scratch 2 Offline Editor (HKLM-x32\...\{6E988774-5309-E02E-7EA8-F19CB65C2063}) (Version: 255 - Massachusetts Institute of Technology) Hidden
Scratch 2 Offline Editor (HKLM-x32\...\edu.media.mit.Scratch2Editor) (Version: 461 - Massachusetts Institute of Technology)
SQL Server 2014 Client Tools (HKLM\...\{2BA1811B-44C0-4C50-8C5A-CE68AB25ED71}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Client Tools (HKLM\...\{B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Common Files (HKLM\...\{BD1CD96B-FE4B-4EAE-83D4-6EF55AB5779C}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Common Files (HKLM\...\{F7012F84-80F5-4C25-852E-B1BA03276FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM\...\{17531BCD-C627-46A2-9F1E-7CC920E0E94A}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM\...\{5082A9F3-AEE5-4639-9BA7-C19661BA7331}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM\...\{ACC530B8-B6B4-40D6-B59B-152468CF47D0}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM\...\{D1B847A9-B06B-4264-9EF0-78E6E1571E65}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Management Studio (HKLM\...\{75A54138-3B98-4705-92E4-F619825B121F}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server 2014 Management Studio (HKLM\...\{839EF29A-3055-43DC-ADCE-8E84893798D5}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2014 (HKLM-x32\...\{3204DE95-97D2-4261-A286-98A262E171D4}) (Version: 12.0.2000.8 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (HKLM\...\{6476DB81-F263-4C04-8574-AAD31136C304}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
SRM Install CDRom 6.42.18 (HKLM-x32\...\{6B3C0CE2-AB22-4800-9413-5DDB652E95FA}) (Version: 6.42.18 - SRM)
Stata 15 (HKLM-x32\...\{EF43617A-2570-4999-9F4C-DC3937E43B84}) (Version: 15.0 - StataCorp LLC)
Synaptics WBF Fingerprint Reader Drivers (HKLM\...\{078EF6CA-4270-446C-A876-F50F6A42CC78}) (Version: 5.0.62.30 - Synaptics Incroporated)
ThinkPad Compact Keyboard with TrackPoint driver (HKLM-x32\...\{CF48A022-4ACC-465A-9441-4069BDCCDCAE}) (Version: 1.5.1.0 - Lenovo)
ThinkPad Pro Dock, Ultra Dock,Workstaion Dock Firmware Utility version 2.33.000 (HKLM-x32\...\TeslaUpdater_is1) (Version: 2.33.000 - )
Thinkpad USB Ethernet Adapter Driver (HKLM-x32\...\{D8102684-7BA1-4948-88B9-535F84E6E588}) (Version: 7.14.1114.2014 - Lenovo)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0 - Ghisler Software GmbH)
TP-Link PLC Utility (HKLM-x32\...\{A79B7C66-DC26-417A-8BB5-B48721B45623}) (Version: 2.2.2758.8 - TP-Link) Hidden
TP-Link PLC Utility (HKLM-x32\...\InstallShield_{A79B7C66-DC26-417A-8BB5-B48721B45623}) (Version: 2.2.2758.8 - TP-Link)
Transcend SSD Scope version 3.3.0 (HKLM-x32\...\{AD8E7B8B-EAD8-4B9F-882E-7970ABFACE34}_is1) (Version: 3.3.0 - Transcend Information, Inc.)
True Image 2013 (HKLM-x32\...\{75BC2136-B6A1-4F3B-8A69-55E39C647B1F}) (Version: 16.0.6514 - Acronis) Hidden
True Image 2013 (HKLM-x32\...\{75BC2136-B6A1-4F3B-8A69-55E39C647B1F}Visible) (Version: 16.0.6514 - Acronis)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Vevo LAB x64 3.1.1 (HKLM\...\VSI Vevo LAB Application) (Version: 3.1.1 - FUJIFILM VisualSonics, Inc.)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 7.24 - NCH Software)
Virtual CD v10 (HKLM-x32\...\{10C51313-A308-4B40-90E3-B368D5882660}) (Version: 10.00.0 - H+H Software GmbH)
Virtual Disk Driver (HKLM-x32\...\{6B6137AE-281D-419E-9F40-FFD1B42A740D}) (Version: 1.1.2141 - Acronis)
Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.1 - VideoLAN)
Vulkan Run Time Libraries 1.0.42.0 (HKLM\...\VulkanRT1.0.42.0) (Version: 1.0.42.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Desktop App 1.5.0.87 (HKLM-x32\...\{2f9f5d2c-2da0-417e-bbff-8787105a70f2}) (Version: 1.5.0.87 - Western Digital Technologies, Inc.) Hidden
WD Desktop App 1.5.0.87 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 1.5.0.87 - Western Digital Technologies, Inc.) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.0.268 - Western Digital Technologies, Inc.)
WD Drive Agent (HKLM-x32\...\{10BD0B99-6C39-4246-85DA-E4AA34B7707E}) (Version: 1.1.0.18 - Western Digital Technologies, Inc.) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.58 - Nullsoft, Inc)
Windows Driver Package - Buxco Research Systems (WinUSB) Buxco Drivers (09/18/2013 1.1.3.0) (HKLM\...\40EAA6E3A23532C46401E62B7E9BEDBDA7D291CA) (Version: 09/18/2013 1.1.3.0 - Buxco Research Systems)
Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (07/12/2013 2.08.30) (HKLM\...\22CCD58B53472BE3FCAFF05631111C4062959A43) (Version: 07/12/2013 2.08.30 - FTDI)
Windows Driver Package - FTDI CDM Driver Package - VCP Driver (07/12/2013 2.08.30) (HKLM\...\BD00013670D26C16E19F284BF8E15DAF813497C7) (Version: 07/12/2013 2.08.30 - FTDI)
Windows-Treiberpaket - Intel (e1dexpress) Net (06/18/2015 12.13.17.4) (HKLM\...\FE55442046680D03C120002D4B87A4BF7D0EEB04) (Version: 06/18/2015 12.13.17.4 - Intel)
Windows-Treiberpaket - Intel Corporation (iaStorA) HDC (07/22/2015 14.5.2.1088) (HKLM\...\03D7382F4D343B67528506692B8E766E0C24EB23) (Version: 07/22/2015 14.5.2.1088 - Intel Corporation)
Windows-Treiberpaket - Lenovo 1.67.10.20 (08/06/2015 1.67.10.20) (HKLM\...\6FC04F7E6E5B13D46033821EF4DBEC1883D331B9) (Version: 08/06/2015 1.67.10.20 - Lenovo)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR (HKLM-x32\...\WinRAR) (Version: - )
Packages:
=========
Audiobooks from Audible -> C:\Program Files\WindowsApps\AudibleInc.AudibleforWindowsPhone_10.5.56.0_x64__xns73kv1ymhp2 [2020-03-17] (Audible Inc)
KYOCERA Print Center -> C:\Program Files\WindowsApps\A97ECD55.KYOCERAPrintCenter_2.4.11127.0_x64__kqmhh0ktdt7dg [2019-12-06] (KYOCERA Document Solutions Inc)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2003.10.0_x64__k1h2ywk1493x8 [2020-03-25] (LENOVO INC.)
Lexmark Printer Home -> C:\Program Files\WindowsApps\58539F3C.LexmarkPrinterHome_3.0.73.0_neutral__xyj5e99tmxdva [2016-08-15] (Lexmark International, Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2020-01-17] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-01-17] (Microsoft Corporation)
Pulse Secure -> C:\Program Files\WindowsApps\951D7986.PulseSecureVPN_5.2.8.0_x64__qzpvqh70t9a4p [2016-08-15] (Pulse Secure LLC)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0 [2020-03-30] (Spotify AB) [Startup Task]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
WindowsDVDPlayer -> C:\Program Files\WindowsApps\Microsoft.WindowsDVDPlayer_3.6.13291.0_x64__8wekyb3d8bbwe [2016-07-16] (Microsoft Corporation)
XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.3.0_x86__xpfg3f7e9an52 [2020-03-18] (New Work SE)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2325083572-1221612603-3422617723-1000_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> "C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2325083572-1221612603-3422617723-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => D:\datenIII\documents\Dropbox [2016-08-19 15:46]
SSODL: WDFSMountNotificator-wdfsconnect2017 - {810C7C0F-99E6-464C-AD4E-234A8940E2AE} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {810C7C0F-99E6-464C-AD4E-234A8940E2AE} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {810C7C0F-99E6-464C-AD4E-234A8940E2AE} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {810C7C0F-99E6-464C-AD4E-234A8940E2AE} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-03-27] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-03-27] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-03-27] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => d:\Programme\Notepad++\NppShell_06.dll [2018-03-19] (Notepad++ -> )
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2013-03-27] (Acronis International GmbH -> Acronis)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {2f14ea59-b6ad-32d6-b690-1cde278ea7d7} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext64.dll [2006-12-11] () [File not signed]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext.dll [2007-01-17] () [File not signed]
ContextMenuHandlers2: [ACShell] -> {D3F9A525-8824-497A-BE36-B23E22F141FC} => d:\Programme\Attribute Changer\acshell.dll [2013-07-18] (Romain Petges) [File not signed]
ContextMenuHandlers2: [Virtual CD v10] -> {A45CC9E4-123E-4F9F-9581-F3D41942B7E9} => -> No File
ContextMenuHandlers3: [ACShell] -> {D3F9A525-8824-497A-BE36-B23E22F141FC} => d:\Programme\Attribute Changer\acshell.dll [2013-07-18] (Romain Petges) [File not signed]
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {2f14ea59-b6ad-32d6-b690-1cde278ea7d7} => C:\Program Files\WD Desktop App\kda.DLL [2018-04-04] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext64.dll [2006-12-11] () [File not signed]
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext.dll [2007-01-17] () [File not signed]
ContextMenuHandlers5: [DeskMenu] -> {7E74422F-2393-11D4-98E0-444553540000} => d:\Programme\Desktop Restore\dkticnsr.dll [2014-07-14] (Jamie O'Connell) [File not signed]
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_4645af5c659ae51a\igfxDTCM.dll [2018-03-27] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [ADIPak] -> {212CA368-CAAC-4F6E-8970-4B7EF9E70E41} => C:\Program Files (x86)\Common Files\ADInstruments\ADILauncher64.dll [2014-05-02] (ADInstruments -> ADInstruments)
ContextMenuHandlers6: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2013-03-27] (Acronis International GmbH -> Acronis)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext64.dll [2006-12-11] () [File not signed]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\programme\WinRAR\rarext.dll [2007-01-17] () [File not signed]
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [176416 2012-01-18] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [307488 2012-01-18] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [VIDC.WMV3] => C:\Windows\SysWOW64\wmv9vcm.dll [1415680 2003-06-23] (Microsoft Corporation) [File not signed]
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
ShortcutWithArgument: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pelles C for Windows\Pelles C Command Prompt (64-bit).lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k Bin\povars64.bat
ShortcutWithArgument: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pelles C for Windows\Pelles C Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k Bin\povars32.bat
==================== Loaded Modules (Whitelisted) =============
2016-09-29 08:12 - 2012-09-04 10:54 - 000103936 _____ () [File not signed] C:\Program Files (x86)\Lenovo\ThinkPad Compact Keyboard with TrackPoint driver\maincpl\fsHid.dll
2020-03-05 22:06 - 2019-05-28 15:06 - 001021440 _____ () [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\LenovoWiFiSecurityPlugin\x86\x86\e_sqlite3.dll
2018-03-16 08:54 - 2017-02-23 09:46 - 000445952 _____ (Aladdin Knowledge Systems Ltd.) [File not signed] d:\Programme\DSI\FinePointe\hasp_net_windows_x64.dll
2018-03-16 08:54 - 2017-02-23 09:46 - 000787968 _____ (Aladdin Knowledge Systems Ltd.) [File not signed] d:\Programme\DSI\FinePointe\hasp_windows_x64_47018.dll
2016-09-29 08:12 - 2012-12-21 14:40 - 000090112 _____ (chicony) [File not signed] C:\Program Files (x86)\Lenovo\ThinkPad Compact Keyboard with TrackPoint driver\fsHid.dll
2016-09-29 08:12 - 2012-12-28 10:28 - 000048128 _____ (CHICONY) [File not signed] C:\Program Files (x86)\Lenovo\ThinkPad Compact Keyboard with TrackPoint driver\maincpl\TRAYICONDLL.dll
2016-09-29 08:12 - 2013-03-04 19:03 - 000098304 _____ (chicony) [File not signed] C:\Program Files (x86)\LENOVO\ThinkPad Compact Keyboard with TrackPoint driver\set\fsHidRaw.dll
2016-07-20 21:19 - 2014-07-14 10:10 - 000390144 _____ (Jamie O'Connell) [File not signed] d:\Programme\Desktop Restore\dkticnsr.dll
2017-01-09 09:46 - 2017-01-09 09:46 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2017-01-09 09:46 - 2017-01-09 09:46 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2018-02-03 20:00 - 2017-09-27 18:30 - 000489984 _____ (Newtonsoft) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\Newtonsoft.Json.dll
2019-11-27 08:57 - 2019-10-27 06:36 - 001261568 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll
2016-09-08 08:07 - 2013-07-18 10:30 - 000072192 _____ (Romain Petges) [File not signed] d:\Programme\Attribute Changer\acshell.dll
2018-02-03 20:00 - 2018-01-26 18:08 - 000088064 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppCollect.dll
2018-02-03 20:00 - 2018-01-26 18:08 - 000200192 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppCommon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2020-03-14 16:19 - 000000857 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 vscplugin.lexmark.com
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;D:\programme\ffmpeg\bin;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Lenovo;C:\SWTOOLS\ReadyApps;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files\Google\Google Apps Sync\;C:\Program Files\Google\Google Apps Migration\;D:\Programme\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;D:\Programme\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Novell\iPrint;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\;C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files\IBM\SPSS\Statistics\24\JRE\bin;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\Control Panel\Desktop\\Wallpaper -> D:\!temp\trol_jump_5.jpg
HKU\S-1-5-80-4227916734-4135089799-3650001050-1485020763-2650598600\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.188.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
Network Binding:
=============
Ethernet 5: FortiClient NDIS 6.3 Packet Filter Driver -> ft_fortifilter (enabled)
Ethernet 4: FortiClient NDIS 6.3 Packet Filter Driver -> ft_fortifilter (enabled)
Ethernet: FortiClient NDIS 6.3 Packet Filter Driver -> ft_fortifilter (enabled)
Wireless Network Connection: FortiClient NDIS 6.3 Packet Filter Driver -> ft_fortifilter (enabled)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\Services: FA_Scheduler => 2
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "Daemon for Mouse Suite"
HKLM\...\StartupApproved\Run: => "iPrint Tray"
HKLM\...\StartupApproved\Run: => "iPrint Event Monitor"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "WinampAgent"
HKLM\...\StartupApproved\Run32: => "VC10Player"
HKLM\...\StartupApproved\Run32: => "WDAppManager"
HKLM\...\StartupApproved\Run32: => "WDDiscovery"
HKLM\...\StartupApproved\Run32: => "WDDriveAgent"
HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant"
HKU\S-1-5-21-2325083572-1221612603-3422617723-1000\...\StartupApproved\Run: => "Lync"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{F37BA70B-83B1-4BB5-8000-19E4C62DD84E}] => (Allow) D:\programme\Fortinet\FortiClient\fortifws.exe (Fortinet Technologies (Canada) Inc. -> Fortinet Inc.)
FirewallRules: [{04714CFC-08F6-409C-8A1B-8491F810ACAB}] => (Allow) D:\programme\Fortinet\FortiClient\fortiesnac.exe (Fortinet Technologies (Canada) Inc. -> Fortinet Inc.)
FirewallRules: [{9D7B03E8-F123-4472-AE07-3C12425CB3B9}] => (Allow) D:\programme\Fortinet\FortiClient\ipsec.exe (Fortinet Technologies (Canada) Inc. -> Fortinet Inc.)
FirewallRules: [{A5802A1E-30BE-461D-88F3-F897C65FBBCE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{136C0176-A76A-449A-B29C-AB4779EB6BE6}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{468FD53C-025C-4721-827B-3A6A61E21A00}D:\system\hardware\tplink\powerline scan.exe] => (Allow) D:\system\hardware\tplink\powerline scan.exe (TP-LINK TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [TCP Query User{376B5500-BD37-4644-9B2C-726A96ABA4A7}D:\system\hardware\tplink\powerline scan.exe] => (Allow) D:\system\hardware\tplink\powerline scan.exe (TP-LINK TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [UDP Query User{DD4F646A-3482-4422-8E5B-A068C45BCBF7}C:\program files\ibm\spss\statistics\24\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\24\stats.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [TCP Query User{419C655D-3060-45DB-B612-35E9EEC8D2EA}C:\program files\ibm\spss\statistics\24\stats.exe] => (Allow) C:\program files\ibm\spss\statistics\24\stats.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{EE353644-72F6-40A8-A153-D9F57E8EDC8D}] => (Allow) D:\Programme\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BC7989BA-4983-4F60-9186-91F7BE743BE7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{25E1E462-B381-4A13-A102-6BDBB3F7BE06}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{103A9377-B388-452E-9902-ECD0D904A88E}D:\system\hardware\tplink\powerline scan.exe] => (Allow) D:\system\hardware\tplink\powerline scan.exe (TP-LINK TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [TCP Query User{AD3EB0B5-3E21-4C33-8628-E0EEB3EAF69B}D:\system\hardware\tplink\powerline scan.exe] => (Allow) D:\system\hardware\tplink\powerline scan.exe (TP-LINK TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [{EB1DB316-3C11-409D-A239-BF0F34670506}] => (Block) D:\programme\tp-link\tp-link plc utility\tpplc.exe (TP-Link TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [{4D886198-219E-4A66-820F-BF8B9819FE93}] => (Block) D:\programme\tp-link\tp-link plc utility\tpplc.exe (TP-Link TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [UDP Query User{2F124538-69B3-4984-A3B7-0F96B60FE7CC}D:\programme\tp-link\tp-link plc utility\tpplc.exe] => (Allow) D:\programme\tp-link\tp-link plc utility\tpplc.exe (TP-Link TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [TCP Query User{2F12EE1A-69FA-4942-986D-A0AF63EE2C7E}D:\programme\tp-link\tp-link plc utility\tpplc.exe] => (Allow) D:\programme\tp-link\tp-link plc utility\tpplc.exe (TP-Link TECHNOLOGIES CO., LTD.) [File not signed]
FirewallRules: [UDP Query User{962E3CFC-B618-4BE6-8609-9888DCC1B5DA}D:\programme\imagej\imagej.exe] => (Allow) D:\programme\imagej\imagej.exe () [File not signed]
FirewallRules: [TCP Query User{04178929-97D5-4C87-ABF1-905A9EA94CCF}D:\programme\imagej\imagej.exe] => (Allow) D:\programme\imagej\imagej.exe () [File not signed]
FirewallRules: [UDP Query User{DD57A970-5A28-4103-AD06-F528FAC9B37A}D:\programme\imagej\imagej.exe] => (Allow) D:\programme\imagej\imagej.exe () [File not signed]
FirewallRules: [TCP Query User{76D1180F-0A25-4A92-A750-62361CC0927B}D:\programme\imagej\imagej.exe] => (Allow) D:\programme\imagej\imagej.exe () [File not signed]
FirewallRules: [{4042B64B-A8AD-4DE1-B0A1-D9FD3B400222}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D2125790-2E2D-453F-AC44-79C0AD4C2D79}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{CD6803F4-E99D-4628-9568-AA4021A37D4D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FE29B05B-9676-45FD-BB89-195B8E30ED56}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E8CC4457-AD3A-4AA0-B623-29720BF09F13}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiAppOld.exe (Intel(R) Wireless Display -> Intel Corporation)
FirewallRules: [{A858E496-7D47-4C99-B079-01269F41AA89}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\SmartAgentTest.exe (Intel(R) Wireless Display -> )
FirewallRules: [{4C16F236-0301-4BE0-A2DA-D355967CD34C}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel(R) Wireless Display -> Intel)
FirewallRules: [{4B95BEE0-8D46-4AAE-9C6C-6AEB0256278B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{FA1C4084-3CCC-4E22-B3EA-7E2F9D216360}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4AD3424F-B4F3-4349-B6F5-27D89460D73F}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{A3C8A22D-C04F-4DDF-83D3-18413A409337}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{B900326B-D80F-4395-82D7-1BF456401C20}] => (Allow) C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe (Lenovo -> Lenovo)
FirewallRules: [{0247148A-E9C9-4D6B-AB67-AC275089D823}] => (Allow) C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe (Lenovo -> Lenovo)
FirewallRules: [{86DC71F8-E300-432C-A1EA-E2728C251FD4}] => (Allow) C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe (Lenovo -> Lenovo)
FirewallRules: [{87E1A3DD-1457-4DA6-954B-E0F3AC6B545F}] => (Allow) LPort=17320
FirewallRules: [{AF93DC51-F7F5-4A1A-BAE2-1D52BE096997}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{40E95C7C-CAE0-463B-BDCC-B6A2E4BE803F}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{1DA5E04C-8A78-4BF8-8389-63E9F9178018}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{B17DD6F3-DA8D-4C86-89DB-EAB48A15B81C}D:\programme\finepointe client (64)\finepointereview.exe] => (Allow) D:\programme\finepointe client (64)\finepointereview.exe (Buxco Research Systems) [File not signed]
FirewallRules: [UDP Query User{B971D352-C5B7-4DCF-9DBA-15980E694636}D:\programme\finepointe client (64)\finepointereview.exe] => (Allow) D:\programme\finepointe client (64)\finepointereview.exe (Buxco Research Systems) [File not signed]
FirewallRules: [{88462638-0A32-493E-8F7B-766E6B49989C}] => (Allow) C:\WINDOWS\system32\hasplms.exe (SafeNet, Inc. -> SafeNet Inc.)
FirewallRules: [TCP Query User{C3E711DA-9625-4339-98A6-554755FB44CC}D:\programme\dsi\finepointe\finepointereview.exe] => (Allow) D:\programme\dsi\finepointe\finepointereview.exe (Data Sciences International Inc. -> Data Sciences International)
FirewallRules: [UDP Query User{E9405F6C-446B-47FB-A191-91234CCC2471}D:\programme\dsi\finepointe\finepointereview.exe] => (Allow) D:\programme\dsi\finepointe\finepointereview.exe (Data Sciences International Inc. -> Data Sciences International)
FirewallRules: [{C19AACB9-F48E-47C2-AE1C-3FC87DFA394C}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\WinWrapIDE.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{5E930E06-A49C-43E9-A7BB-11924204E288}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\stats.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{4635200F-CE31-47AD-8CBE-5C068623E0D1}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\WinWrapIDE.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{D3B14943-F126-4C37-83CC-EFA88A35A3C2}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\stats.exe (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{A4C9B99E-048A-4264-9D86-D527FEFF49E7}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\stats.com (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{5A48B9F4-9E90-4921-8268-F64FA9AEEAAC}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\24\stats.com (IBM -> IBM Corp.) [File not signed]
FirewallRules: [{AEBF4E71-06F3-4F7F-B840-FC4DF2D3B75D}] => (Allow) D:\programme\FinePointe Client (64)\FinePointeStation.exe (Buxco Research Systems) [File not signed]
FirewallRules: [{DB3768C7-2CB3-4B49-A0B1-E30D0082F0D0}] => (Allow) D:\programme\FinePointe Client (64)\FinePointeStation.exe (Buxco Research Systems) [File not signed]
FirewallRules: [{53D0EB5A-486F-4DCF-ABB5-7C36A43717F7}] => (Allow) D:\programme\FinePointe Client (64)\FinePointeStation.exe (Buxco Research Systems) [File not signed]
FirewallRules: [{893F25DB-55E4-468B-A78A-9E965072A854}] => (Allow) D:\programme\FinePointe Client (64)\FinePointeStation.exe (Buxco Research Systems) [File not signed]
FirewallRules: [{7167ABC9-C7AA-465E-83CE-8E9379F75850}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{35ACFC89-26F3-4D62-84ED-34FA74970389}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4C6A9F6-754F-4B31-9650-1AFB606E0493}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6E6E1B79-A190-40D6-A7BC-33B96EE0EFF7}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CCA3A55E-FA02-4712-B58B-ADB6A14303BB}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.FINEPOINTE\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{74AD2EC4-C73E-420A-9284-7B58D92860A8}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.FINEPOINTE\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F538BFC6-C617-4810-9D12-914850E336B3}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.FINEPOINTE\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{72C412D8-88A8-479B-9373-7289870198C6}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.FINEPOINTE\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{996048FF-88D4-406E-BBA8-57BC67FF6B34}] => (Allow) LPort=777
FirewallRules: [TCP Query User{2A7E921C-FCDC-4035-81D7-034C741909B6}D:\programme\videolan\vlc\vlc.exe] => (Allow) D:\programme\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{98B8B4DC-C8D8-4959-B591-F27A17BC1A7B}D:\programme\videolan\vlc\vlc.exe] => (Allow) D:\programme\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{84950C51-F644-4E8D-A468-8DF560FDFB15}] => (Block) D:\programme\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{9BEDA028-452B-41E2-88AB-825320FB1874}] => (Block) D:\programme\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{ACAD2906-46C3-408C-846C-D6D881D32458}] => (Allow) D:\programme\lexmark_mx410\Lexmark\Status Center\lmsmc.exe (Lexmark International, Inc. -> )
FirewallRules: [{C6527421-D657-4AEB-947B-67C92C19B27E}] => (Allow) D:\programme\lexmark_mx410\Lexmark\Status Center\lmsmc.exe (Lexmark International, Inc. -> )
FirewallRules: [{7EEE7A8A-26F1-477E-B920-6F257930D4E2}] => (Allow) C:\Program Files (x86)\Lexmark MX410 Series\LMAD0lscn.exe (Lexmark International, Inc. -> )
FirewallRules: [{250C9554-3D9D-449A-A73B-90D1240B7285}] => (Allow) C:\Program Files (x86)\Lexmark MX410 Series\LMAD0lscn.exe (Lexmark International, Inc. -> )
FirewallRules: [{F81E8DF7-366C-4146-BA39-29BDE061AFE3}] => (Allow) C:\Program Files (x86)\Lexmark MX410 Series\LMabscw.dll () [File not signed]
FirewallRules: [{CE0AC596-B08E-4F14-BD91-E7B60B0A2C11}] => (Allow) C:\Program Files (x86)\Lexmark MX410 Series\LMabscw.dll () [File not signed]
FirewallRules: [{9F4469EF-9790-4719-B4B6-067496F9A020}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwds.ds () [File not signed]
FirewallRules: [{6B92541A-DC5D-457A-AF02-D088EDA1C62C}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwds.ds () [File not signed]
FirewallRules: [{3A5901F5-0C52-42B4-96F4-F724D3A83049}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwpro.dll () [File not signed]
FirewallRules: [{6DAE7E82-B5D6-4799-B0E3-D7EDEFDD3EDB}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwpro.dll () [File not signed]
FirewallRules: [{7438EF73-8FA7-45EF-BB8A-332A5C58A047}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwui.dll () [File not signed]
FirewallRules: [{1B7019B1-BF53-480E-9093-4944B9457171}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabtwui.dll () [File not signed]
FirewallRules: [{C815F66D-AD45-402E-9EB9-15CC0BC2B897}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabdrs.dll (Microsoft Windows Hardware Compatibility Publisher -> )
FirewallRules: [{58AD8982-8B2C-4851-AF73-69D417247852}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\LMabdrs.dll (Microsoft Windows Hardware Compatibility Publisher -> )
FirewallRules: [{28D983DF-8D0F-4346-97A3-19B0FC1C56D1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D6B8ED6C-A12C-42E2-BDC7-DDBA3956E55B}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> )
FirewallRules: [{BD868873-C2F8-44C5-B858-A56519B262B2}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe (Lenovo -> )
FirewallRules: [{5C3CE221-6C27-42EF-A335-F084DB7E35A3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{62F703C1-6D20-43DA-A5F7-6A940922C560}] => (Allow) d:\Programme\Opera\67.0.3575.97\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{581AD690-69B9-4941-BE05-EB14371CD5FF}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{0D4359B5-ECFB-4056-A739-777254791E33}] => (Allow) D:\programme\Fortinet\FortiClient\FortiProxy.exe No File
FirewallRules: [{86E47269-275B-4CA4-8D13-9A0E7A710F4F}] => (Allow) D:\programme\Fortinet\FortiClient\FortiWad.exe No File
FirewallRules: [{96053EF9-93AB-4964-BC5E-A58086EE6E88}] => (Allow) d:\Programme\Opera\67.0.3575.115\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{ED5F6904-0623-4743-AC65-5882A5372C0E}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A94A6A9A-85AF-44B5-AE23-7185913CBFCF}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2ED23248-28BC-4914-939F-4AEA4F5D9739}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7D0F0BCF-394E-4236-8720-9765215FA2F1}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{20C3CB15-B71E-47E1-BDAD-9FAFA855CFAD}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B665B352-0DB4-4AD7-B174-8610BCBF29BC}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D9F74293-DCFB-4A1B-AA71-8AC25C183243}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{933BFAE6-2AB6-4348-9669-CB46F552224D}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
==================== Restore Points =========================
17-03-2020 07:51:39 Windows Update
25-03-2020 09:25:09 Scheduled Checkpoint
30-03-2020 23:56:06 Windows Update
==================== Faulty Device Manager Devices ============
Name: Fortinet SSL VPN Virtual Ethernet Adapter
Description: Fortinet SSL VPN Virtual Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Fortinet Inc.
Service: ftsvnic
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (04/01/2020 09:54:09 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (7684,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/01/2020 09:45:20 AM) (Source: Outlook) (EventID: 69) (User: )
Description: Sicherheitswarnung beim Laden von "gsync.dll". Diese MAPI-Anbieter-DLL könnte schädlich für Ihr System sein. Sie sollten nur DLLs von vertrauenswürdigen Anbietern laden, die bei "MapiSvc.Inf" registriert sind. Diese Anbieter-DLL wird in einem zukünftigen Outlook-Clientupdate blockiert, und ihre Funktionen stehen dann nicht mehr zur Verfügung. Weitere Informationen zum Registrieren von Anbieter-DLLs finden Sie unter "https://go.microsoft.com/fwlink/?linkid=2009861&clcid=0x409".
Error: (03/31/2020 04:43:25 PM) (Source: MSSQL$FINEPOINTE) (EventID: 17187) (User: )
Description: SQL Server is not ready to accept new client connections. Wait a few minutes before trying again. If you have access to the error log, look for the informational message that indicates that SQL Server is ready before trying to connect again. [CLIENT: 127.0.0.1]
Error: (03/31/2020 04:43:23 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0
Error: (03/31/2020 04:43:23 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0
Error: (03/31/2020 04:43:23 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0
Error: (03/31/2020 04:43:23 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0
Error: (03/31/2020 04:43:23 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0
System errors:
=============
Error: (03/31/2020 04:43:17 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:42:05 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:38:50 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:28:05 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:25:58 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:24:19 PM) (Source: DCOM) (EventID: 10000) (User: HT460P)
Description: Unable to start a DCOM Server: {7160A13D-73DA-4CEA-95B9-37356478588A}. The error:
"2147942403"
Happened while starting this command:
C:\WINDOWS\system32\igfxext.exe -Embedding
Error: (03/31/2020 04:23:56 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Error: (03/31/2020 04:12:45 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY)
Description: The password notification DLL iPrntWinCredMan failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at hxxp://go.microsoft.com/fwlink/?LinkId=245898.
Windows Defender:
===================================
Date: 2020-03-30 22:39:25.537
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {89FE6B6B-F0EE-4505-A64E-F713EC255151}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Vollständige Überprüfung
Benutzer: HT460P\chris
Date: 2020-03-30 13:14:08.258
Description:
Windows Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Esulat.A!rfn&threatid=2147745898&enterprise=0
Name: Trojan:Win32/Esulat.A!rfn
ID: 2147745898
Schweregrad: Severe
Kategorie: Trojan
Pfad: file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\ab4aaa273abe454b7597e63beeb0b52f; file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\c3038579f979d53b68de98dd377cffc0
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: HT460P\chris
Prozessname: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Sicherheitsversion: AV: 1.313.406.0, AS: 1.313.406.0, NIS: 1.313.406.0
Modulversion: AM: 1.1.16900.4, NIS: 1.1.16900.4
Date: 2020-03-30 13:14:08.214
Description:
Windows Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Esulat.A!rfn&threatid=2147745898&enterprise=0
Name: Trojan:Win32/Esulat.A!rfn
ID: 2147745898
Schweregrad: Severe
Kategorie: Trojan
Pfad: file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\ab4aaa273abe454b7597e63beeb0b52f
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: HT460P\chris
Prozessname: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Sicherheitsversion: AV: 1.313.406.0, AS: 1.313.406.0, NIS: 1.313.406.0
Modulversion: AM: 1.1.16900.4, NIS: 1.1.16900.4
Date: 2020-03-25 15:07:35.934
Description:
Windows Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Esulat.A!rfn&threatid=2147745898&enterprise=0
Name: Trojan:Win32/Esulat.A!rfn
ID: 2147745898
Schweregrad: Severe
Kategorie: Trojan
Pfad: file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\4c5474f53d5984c2c21ed5ab03e27088; file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\7a43258cd9f6a9e9afc672b1096664c1
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: HT460P\chris
Prozessname: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Sicherheitsversion: AV: 1.311.1877.0, AS: 1.311.1877.0, NIS: 1.311.1877.0
Modulversion: AM: 1.1.16900.4, NIS: 1.1.16900.4
Date: 2020-03-25 15:07:18.186
Description:
Windows Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Esulat.A!rfn&threatid=2147745898&enterprise=0
Name: Trojan:Win32/Esulat.A!rfn
ID: 2147745898
Schweregrad: Severe
Kategorie: Trojan
Pfad: file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\4c5474f53d5984c2c21ed5ab03e27088; file:_D:\datenIII\documents\Dropbox\.dropbox.cache\new_files\7a43258cd9f6a9e9afc672b1096664c1
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: HT460P\chris
Prozessname: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Sicherheitsversion: AV: 1.311.1877.0, AS: 1.311.1877.0, NIS: 1.311.1877.0
Modulversion: AM: 1.1.16900.4, NIS: 1.1.16900.4
Date: 2020-03-17 06:57:40.247
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.311.1368.0
Update Source: Microsoft Update-Server
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.16800.2
Fehlercode: 0x80240016
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
CodeIntegrity:
===================================
Date: 2020-03-17 09:42:06.747
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-17 09:42:06.652
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-17 09:40:20.113
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-17 09:40:20.020
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-14 15:55:34.781
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-14 15:55:34.693
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-14 15:53:51.993
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2020-03-14 15:53:51.905
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO R07ET91W (2.31 ) 12/11/2019
Motherboard: LENOVO 20FW000DGE
Processor: Intel(R) Core(TM) i5-6440HQ CPU @ 2.60GHz
Percentage of memory in use: 34%
Total physical RAM: 20332.11 MB
Available physical RAM: 13278.95 MB
Total Virtual: 44268.11 MB
Available Virtual: 35253.58 MB
==================== Drives ================================
Drive c: (Windows7_OS) (Fixed) (Total:237.62 GB) (Free:71.75 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (driveD) (Fixed) (Total:476.94 GB) (Free:116.87 GB) NTFS
\\?\Volume{9853cd39-962d-4e4d-a590-fa96645c24e9}\ () (Fixed) (Total:0.63 GB) (Free:0.08 GB) NTFS
\\?\Volume{c0f38a25-f2bb-4c73-9540-a69bba229426}\ (SYSTEM_DRV) (Fixed) (Total:0.1 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: B4EB12C8)
Partition 1: (Not Active) - (Size=476.9 GB) - (Type=07 NTFS)
==========================================================
Disk: 1 (Size: 238.5 GB) (Disk ID: C0D8AD00)
Partition: GPT.
==================== End of Addition.txt ======================= |