0815julian | 05.01.2024 20:06 | Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 05.01.2024 01
durchgeführt von ichbi (05-01-2024 20:01:32)
Gestartet von C:\Users\ichbi\Downloads
Microsoft Windows 10 Pro for Workstations Version 22H2 19045.3803 (X64) (2021-05-16 15:07:12)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
Administrator (S-1-5-21-3203882355-2465378241-1904074028-500 - Administrator - Disabled)
B02C33EEFEF34FAEA538 (S-1-5-21-3203882355-2465378241-1904074028-1004 - Limited - Enabled)
DefaultAccount (S-1-5-21-3203882355-2465378241-1904074028-503 - Limited - Disabled)
Gast (S-1-5-21-3203882355-2465378241-1904074028-501 - Limited - Disabled)
haert (S-1-5-21-3203882355-2465378241-1904074028-1002 - Limited - Disabled)
ichbi (S-1-5-21-3203882355-2465378241-1904074028-1001 - Administrator - Enabled) => C:\Users\ichbi
WDAGUtilityAccount (S-1-5-21-3203882355-2465378241-1904074028-504 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov)
Adesso Cybertrack Driver version 1.00 (HKLM-x32\...\{BCAB7D40-5D74-4C2A-8B76-D13389AB63BC}_is1) (Version: 1.00 - )
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1031-1033-7760-BC15014EA700}) (Version: 23.008.20458 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601053}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Amazon Games (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\{4DD10B06-78A4-4E6F-AA39-25E9C38FA568}) (Version: 2.3.8425.2 - Amazon.com Services, Inc.)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.07.21.306 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.80 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 6.0.0.3 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Master SDK (HKLM\...\{DBD50508-5F75-416B-995D-C42433A00944}) (Version: 2.7.0.1725 - Advanced Micro Devices, Inc.)
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{7598e74a-915c-4911-918c-ca4b2c296122}) (Version: 2.07.21.306 - Advanced Micro Devices, Inc.) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.15_Beta2 - tippach engineering)
Audacity 3.0.0 (HKLM-x32\...\Audacity_is1) (Version: 3.0.0 - Audacity Team)
Audacity 3.1.2 (64 Bit) (HKLM\...\Audacity_is1) (Version: 3.1.2 - Audacity Team)
Avid Cloud Client Services (HKLM\...\{66E7D4F4-F044-428D-A734-59138A626A52}) (Version: 2.4.0.15 - Avid Technology, Inc.)
Avid Effects (HKLM\...\{19DE6A9D-DAF1-4CCD-8641-98AF7F7A3DC2}) (Version: 20.9.0.119 - Avid Technology, Inc.)
Blackmagic RAW Common Components (HKLM\...\{35D9A1FC-10E0-4825-B2D2-3B15EB9B2232}) (Version: 2.4.0.1 - Blackmagic Design)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CamScanner 1.1.3 (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\03fc796f-ccca-5cd2-9de8-e077585adf0b) (Version: 1.1.3 - intsig)
CCleaner (HKLM\...\CCleaner) (Version: 6.19 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.8.7128 - CDBurnerXP)
ChamSys MagicQ (HKLM-x32\...\MagicQ) (Version: 1.9.1.6 - ChamSys Limited)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cisco Webex Meetings (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\ActiveTouchMeetingClient) (Version: 42.1.3 - Cisco Webex LLC)
CPUID CPU-Z 1.96 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.96 - CPUID, Inc.)
CPUID HWMonitor 1.44 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.44 - CPUID, Inc.)
CurseForge 0.240.3-15191 (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\ca0e291c-abd4-5fc3-b6a0-3d4333eccbd7) (Version: 0.240.3-15191 - Overwolf)
darktable (HKLM\...\darktable) (Version: 3.8.0 - the darktable project)
DaVinci Resolve (HKLM\...\{0DE05B8E-6889-4616-8428-850274AB0700}) (Version: 17.4.60004 - Blackmagic Design)
DaVinci Resolve Control Panels (HKLM\...\{7667C543-084F-47F7-BC60-175FC25E9D6F}) (Version: 2.0.1.0 - Blackmagic Design)
DDFCreator 2.2.1 (HKLM-x32\...\DDFCreator_2.2.1) (Version: 2.2.1 - DMXControl Projects e.V.)
Discord (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\Discord) (Version: 1.0.9001 - Discord Inc.)
DisplayFusion 9.8 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 9.8.0.0 - Binary Fortress Software)
DMXControl 2.12.2 (HKLM-x32\...\DMXControl) (Version: 2.12.2 - PopSoft)
ENE_DRAM_RGB_AIO (HKLM\...\{1745D314-9077-46C9-8562-1C62BAE189B7}) (Version: 1.0.2.2 - Ene Tech.) Hidden
ENE_DRAM_RGB_AIO (HKLM-x32\...\{c0cc7253-fa06-46c2-9ceb-f8641408262f}) (Version: 1.0.2.2 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.8.13 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{54d3d2b5-db16-446d-b6dd-f4964b166b3b}) (Version: 1.0.8.13 - ENE TECHNOLOGY INC.) Hidden
ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_MousePad_HAL (HKLM-x32\...\{c2c794a4-7986-4c45-884d-d4ca43b88df9}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE_X-JMI_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.5.1 - ENE Tech) Hidden
ENE_X-JMI_HAL (HKLM-x32\...\{50ec3a07-291b-463e-be86-487eb8cbb71c}) (Version: 1.0.5.1 - ENE Tech) Hidden
Engine DJ (HKLM\...\{1D6DD610-418A-4FC3-91C2-CE1B88C14B20}) (Version: 3.3.0.70 - AIR Music Technology) Hidden
Engine DJ (HKLM-x32\...\{0c9736f4-2a1e-4177-844e-823e11a9cc30}) (Version: 3.3.0.70 - AIR Music Technology)
FACEIT Anti-Cheat (HKLM\...\{1419E44C-0EF4-4822-9194-9F1A4D43973D}_is1) (Version: 2.1 - FACEIT LTD)
FileZilla Client 3.54.1 (HKLM-x32\...\FileZilla Client) (Version: 3.54.1 - Tim Kosse)
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
Focusrite Audio Drivers 4.102.4.735 (HKLM\...\Focusrite Audio Drivers_is1) (Version: 4.102.4.735 - Focusrite Audio Engineering, Ltd.)
GIMP 2.10.24 (HKLM\...\GIMP-2_is1) (Version: 2.10.24 - The GIMP Team)
Git version 2.32.0 (HKLM\...\Git_is1) (Version: 2.32.0 - The Git Development Community)
GlobalProtect (HKLM\...\{8221047A-6727-47A0-AF10-C5F89CAA56A6}) (Version: 5.2.11 - Palo Alto Networks)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 118.0.5993.89 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 82.0.1.0 - Google LLC)
Grand Theft Auto V (HKLM-x32\...\{5EFC6C07-6B87-43FC-9524-F9E967241741}) (Version: 1.0.2545.0 - Rockstar Games)
grandMA3 onPC 1.6.3.7 (HKLM-x32\...\MA Lighting Technology GmbH grandMA3 onPC 1.6.3.7) (Version: - "MA Lighting Technology GmbH")
Inkscape (HKLM-x32\...\Inkscape) (Version: 1.1.2- - Inkscape)
ISO to USB (HKLM-x32\...\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1) (Version: - isotousb.com)
Java 8 Update 291 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180291F0}) (Version: 8.0.2910.10 - Oracle Corporation)
Java(TM) SE Development Kit 16.0.1 (64-bit) (HKLM\...\{75CDB88B-F917-5456-AB2D-5504DE7F43DE}) (Version: 16.0.1.0 - Oracle Corporation)
Lightshot-5.5.0.7 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.7 - Skillbrains)
Logitech Gaming Software 9.02 (HKLM\...\Logitech Gaming Software) (Version: 9.02.65 - Logitech Inc.)
Malwarebytes version 4.6.8.311 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.8.311 - Malwarebytes)
MATLAB R2021b (HKLM\...\Matlab R2021b) (Version: 9.11 - MathWorks)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 120.0.2210.91 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 120.0.2210.91 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - de-de (HKLM\...\ProPlus2019Volume - de-de) (Version: 16.0.10405.20015 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\Teams) (Version: 1.6.00.29964 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
MIDI-OX (HKLM-x32\...\{A6457851-5EA9-45B0-AF1D-D2A0A4781CFB}) (Version: 7.02.372 - MIDIOX Computing)
Minecraft Launcher (HKLM-x32\...\{733C3ACB-432D-4880-B0E1-660000D7974D}) (Version: 1.0.0.0 - Mojang)
MIXO 0.61.0 (HKLM\...\d55b2c77-de3d-571c-b37e-a566ff87822a) (Version: 0.61.0 - MIXO)
Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox 121.0 (x64 de)) (Version: 121.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 102.1.2 - Mozilla)
Mozilla Thunderbird (x64 de) (HKLM\...\Mozilla Thunderbird 115.5.2 (x64 de)) (Version: 115.5.2 - Mozilla)
MSI SDK (HKLM-x32\...\{EE7D557C-3AE7-4348-8DCA-3A89790D0002}}_is1) (Version: 2.2021.0428.01 - MSI)
MSYS2 64bit (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\{73df107e-2385-4feb-924e-ecf18a2366cb}) (Version: 20220603 - The MSYS2 Developers)
Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 2.6.2.547 - Native Instruments)
Native Instruments Native Access (HKLM-x32\...\Native Instruments Native Access) (Version: 1.14.1.156 - Native Instruments)
Native Instruments Traktor Pro 3 (HKLM-x32\...\Native Instruments Traktor Pro 3) (Version: 3.5.1.277 - Native Instruments)
Nextcloud (HKLM\...\{235C8899-32EF-44CF-9E58-3E182ABEFDC6}) (Version: 3.7.4.20230309 - Nextcloud GmbH)
Nicepage 5.2.4 (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\c9e6a573-2a17-5f23-a9b7-1d442c8e5de0) (Version: 5.2.4 - Artisteer Limited)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.4.8 - Notepad++ Team)
Nullsoft Install System (HKLM-x32\...\NSIS) (Version: 3.08 - Nullsoft and Contributors)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA Grafiktreiber 537.58 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 537.58 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 27.0.1 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10405.20015 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10405.20015 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.10405.20015 - Microsoft Corporation) Hidden
OpenIV (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\OpenIV) (Version: 4.1.1502 - .black/OpenIV Team)
Outlook (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\6b0f23e57a39ebfbf2814acb1a24293d) (Version: 1.0 - Outlook)
PACE License Support Win64 (HKLM\...\{5AC4321F-FCD1-4a37-BFCB-E1EB0047CDA4}) (Version: 5.4.1.3706 - PACE Anti-Piracy, Inc.) Hidden
PACE License Support Win64 (HKLM-x32\...\InstallShield_{5AC4321F-FCD1-4a37-BFCB-E1EB0047CDA4}) (Version: 5.4.1.3706 - PACE Anti-Piracy, Inc.)
PDF24 Creator 11.13.1 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: 11.13.1 - PDF24.org)
Phonic FireFly 808 & 808U Firewire Driver v6.11.0.0 (HKLM-x32\...\Phonic FireFly 808 & 808U Firewire Driver v6.11.0.0) (Version: 6.11.0.0 - Phonic)
PowerPoint (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\319814cb56b667dff88f54e08be8f51f) (Version: 1.0 - PowerPoint)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.)
PuTTY release 0.75 (64-bit) (HKLM\...\{06DB09EC-52D5-47FA-A0F3-D70ED6407481}) (Version: 0.75.0.0 - Simon Tatham)
Python 3.10.7 (64-bit) (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\{c62ef944-a7c9-4646-9fc7-d9e658defc1f}) (Version: 3.10.7150.0 - Python Software Foundation)
Python 3.10.7 Core Interpreter (64-bit) (HKLM\...\{D4C83865-A602-4834-8390-B094CAF22F71}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Development Libraries (64-bit) (HKLM\...\{C9D65557-5B19-4B9B-860E-4E5477F9B10A}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Documentation (64-bit) (HKLM\...\{51EC70CA-6E66-499A-B7F7-94912F3EA381}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Executables (64-bit) (HKLM\...\{CE8E4C24-9C7B-447B-B974-CD8236BE09B9}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 pip Bootstrap (64-bit) (HKLM\...\{30C9588C-5E1D-479E-988A-DA38CADFA384}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Standard Library (64-bit) (HKLM\...\{08D7A4E8-F704-409B-A676-457432DA3248}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Tcl/Tk Support (64-bit) (HKLM\...\{7BB23EC2-FD76-4BDB-813C-3EEFBB7FD3D9}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Test Suite (64-bit) (HKLM\...\{099B73AD-9E34-4ADF-B982-7E3A75610CA6}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python 3.10.7 Utility Scripts (64-bit) (HKLM\...\{E1A1200C-5CC4-404B-BF93-E33C463963CD}) (Version: 3.10.7150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{96BFBDD2-78C9-42B5-9893-FABA2BB527C4}) (Version: 3.10.7917.0 - Python Software Foundation)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9013.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.46.1231.2020 - Realtek)
Realtek USB Wireless LAN Driver (HKLM-x32\...\InstallShield_{DBCC4C27-F949-482b-B786-7B3B67587CD2}) (Version: Drv_3.00.0018 - REALTEK Semiconductor Corp.)
Realtek USB Wireless LAN Utility (HKLM-x32\...\{9C049509-055C-4CFF-A116-1D12312225EB}) (Version: UI_1.00.0287 - REALTEK Semiconductor Corp.)
rekordbox 5.8.7 64bit (HKLM\...\Pioneer rekordbox 5.8.7) (Version: 5.8.7.0006 - AlphaTheta)
rekordbox 6.6.5 64bit (HKLM\...\Pioneer rekordbox 6.6.5) (Version: 6.6.5.0041 - AlphaTheta)
REW 5.20.9 (HKLM\...\4549-9647-2313-4375) (Version: 5.20.9 - John Mulcahy)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.63.962 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.1.5.1 - Rockstar Games)
Sena 30K Updater 1.0.3 (HKLM\...\09cac4af-f108-5ae0-8a45-6335da525e88) (Version: 1.0.3 - Sena Technologies, Inc.)
Sena Bluetooth Device Manager 4.3.3 (HKLM-x32\...\Sena Bluetooth Device Manager) (Version: 4.3.3 - Copyright (C) 2012 ~ 2022 Sena Technologies Inc.)
Sidify Music Converter 2.5.0 (HKLM-x32\...\Sidify Music Converter) (Version: 2.5.0 - Sidify)
SiudiDriver Version 2.3 (HKLM\...\SiudiDriver_is1) (Version: 2.3 - LightingSoft AG)
SoundSwitch 2.5.0.416 (HKLM\...\{BD01C6BB-0A08-4D41-8FD3-CB5280B5AAB8}_is1) (Version: 2.5.0.416 - onesixone Ltd)
Spotify (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\Spotify) (Version: 1.2.26.1187.g36b715a1 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.5.6 - TeamSpeak Systems GmbH)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.41.9 - TeamViewer)
the t.racks FIR DSP 408 Processor Editor V1.1 (HKLM-x32\...\{4CC7B455-8C3D-4D79-AE0E-0CA76A27C448}_is1) (Version: - )
TR-8S Driver (HKLM\...\RolandRDID0198) (Version: - Roland Corporation)
TuneFab Spotify Music Converter 3.1.24 (HKLM\...\9ff685d9-8f1e-59e1-a273-b7c9e7cf0c17) (Version: 3.1.24 - TuneFab)
Two Point Hospital (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\AmazonGames/Two Point Hospital) (Version: - SEGA)
VdhCoApp 1.6.3 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.18 - VideoLAN)
WD_BLACK AN1500 (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.12.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK AN1500 (HKLM-x32\...\{9c94735f-73fd-4b0f-9ddb-8be7b3cc4681}) (Version: 1.0.12.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK D50 (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version: 1.0.9.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK D50 (HKLM-x32\...\{a1d1ba00-92b7-4a99-8ebd-65b25c0e9e44}) (Version: 1.0.9.0 - ENE TECHNOLOGY INC.) Hidden
Webex (HKLM\...\{611AD18D-000D-4ABB-84FD-CC503FDE8EC6}) (Version: 41.5.0.18911 - Cisco Systems, Inc)
Winamp (HKLM-x32\...\Winamp) (Version: 5.8 - Winamp SA)
Windows-Treiberpaket - Cambridge Silicon Radio Ltd. (CSRBC) USB (11/27/2020 2.5.5.9) (HKLM\...\6A50C99E75CE49370D2FB6BD3959E25A02A0751A) (Version: 11/27/2020 2.5.5.9 - Cambridge Silicon Radio Ltd.)
Xournal++ (HKLM\...\Xournal++) (Version: - The Xournal++ Team)
Zoom (HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\ZoomUMX) (Version: 5.16.2 (22807) - Zoom Video Communications, Inc.)
Packages:
=========
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2024-01-04] ()
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.61781.0_x64__8wekyb3d8bbwe [2023-07-12] (Microsoft Corporation)
DragonCenter -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.121.0_x64__kzh8wxbdkxb8p [2021-12-10] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task]
Excel -> C:\Program Files\WindowsApps\excel.office.com-72EAE3D_1.0.0.0_neutral__2vp2pd36ganw2 [2023-12-13] (excel.office.com)
Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-10-25] (Microsoft Corporation)
HEVC-Videoerweiterungen -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_2.0.61933.0_x64__8wekyb3d8bbwe [2023-08-13] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_150.1.1140.0_x64__v10z8vjag6ke6 [2023-11-14] (HP Inc.)
Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-10-16] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-05-17] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-05-17] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-10-16] (NVIDIA Corp.)
Python 3.10 -> C:\Program Files\WindowsApps\PythonSoftwareFoundation.Python.3.10_3.10.3056.0_x64__qbz5n2kfra8p0 [2023-04-06] (Python Software Foundation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.38.277.0_x64__dt26b99r8h8gj [2023-08-31] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.18.11210.0_x64__8wekyb3d8bbwe [2023-11-30] (Microsoft Studios) [MS Ad]
Word -> C:\Program Files\WindowsApps\word.office.com-51E922F2_1.0.0.1_neutral__jc2kecmnkxwqc [2023-09-01] (word.office.com)
Word -> C:\Program Files\WindowsApps\word.office.com-CECA1A7F_1.0.0.0_neutral__jc2kecmnkxwqc [2022-12-03] (word.office.com)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\ichbi\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.23270.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{1E62D59A-6EA4-476C-B707-4A32E88ED822}\InprocServer32 -> C:\Program Files\Nextcloud\CfApiShellExtensions.dll () [Datei ist nicht signiert]
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{32E26FD9-F435-4A20-A561-35D4B987CFDC}\InprocServer32 -> C:\Users\ichbi\AppData\Local\WebEx\WebEx64\Meetings\atucfobj.dll (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{3ebb2ee6-b94d-405e-aafd-3256b99908fc} -> [Nextcloud] => C:\Users\ichbi\Nextcloud [2023-01-24 17:55]
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{6FF9B5B6-389F-444A-9FDD-A286C36EA079}\InprocServer32 -> C:\Program Files\Nextcloud\CfApiShellExtensions.dll () [Datei ist nicht signiert]
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{993c1522-cb84-4df3-94f5-975ea4f69dbf}\InprocServer32 -> C:\Program Files\Mozilla Thunderbird\notificationserver.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\ichbi\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ NextcloudError] -> {E0342B74-7593-4C70-9D61-22F294AAFE05} => C:\Program Files\Nextcloud\NCOverlays.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ShellIconOverlayIdentifiers: [ NextcloudOK] -> {E1094E94-BE93-4EA2-9639-8475C68F3886} => C:\Program Files\Nextcloud\NCOverlays.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ShellIconOverlayIdentifiers: [ NextcloudOKShared] -> {E243AD85-F71B-496B-B17E-B8091CBE93D2} => C:\Program Files\Nextcloud\NCOverlays.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ShellIconOverlayIdentifiers: [ NextcloudSync] -> {E3D6DB20-1D83-4829-B5C9-941B31C0C35A} => C:\Program Files\Nextcloud\NCOverlays.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ShellIconOverlayIdentifiers: [ NextcloudWarning] -> {E4977F33-F93A-4A0A-9D3C-83DEA0EE8483} => C:\Program Files\Nextcloud\NCOverlays.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2021-03-22] (Notepad++ -> )
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => C:\Program Files (x86)\VMware\VMware Workstation\vmdkShellExt.dll [2020-06-05] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2020-06-05] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-01-05] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [NextcloudContextMenuHandler] -> {BC6988AB-ACE2-4B81-84DC-DC34F9B24401} => C:\Program Files\Nextcloud\NCContextMenu.dll [2023-03-09] (Nextcloud GmbH -> Nextcloud GmbH)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-12] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispsig.inf_amd64_2a8379cc1977656a\nvshext.dll [2023-10-05] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [Datei ist nicht signiert]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-01-05] (Malwarebytes Inc. -> Malwarebytes)
==================== Codecs (Nicht auf der Ausnahmeliste) ====================
==================== Verknüpfungen & WMI ========================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
ShortcutWithArgument: C:\Users\ichbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bjhmmnoficofgoiacjaajpkfndojknpb
ShortcutWithArgument: C:\Users\ichbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=opfacbhaojodjaojgocnibmklknchehf
==================== Geladene Module (Nicht auf der Ausnahmeliste) =============
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\Users\ichbi\Anwendungsdaten:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\ichbi\Downloads\adwcleaner.exe:MBAM.Zone.Identifier [141]
AlternateDataStreams: C:\Users\ichbi\Downloads\esetonlinescanner(1).exe:MBAM.Zone.Identifier [354]
AlternateDataStreams: C:\Users\ichbi\Downloads\esetonlinescanner.exe:MBAM.Zone.Identifier [354]
AlternateDataStreams: C:\Users\ichbi\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================
==================== Internet Explorer (Nicht auf der Ausnahmeliste) ==========
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2021-05-16] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [2021-05-17] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-05-17] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-05-16] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2023-09-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-09-16] (Microsoft Corporation -> Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
IE trusted site: HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\sharepoint.com -> hxxps://dtudk-files.sharepoint.com
==================== Hosts Inhalt: =========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2019-12-07 10:14 - 2019-12-07 10:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Andere Bereiche ===========================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\PuTTY\;C:\Program Files\Git\cmd;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\MATLAB\R2021b\bin;
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ichbi\Pictures\Saved Pictures\hd-wallpaper-3519309(1).jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
ist aktiviert.
Network Binding:
=============
VMware Network Adapter VMnet8: VMware Bridge Protocol -> vmware_bridge (disabled)
Ethernet 3: VMware Bridge Protocol -> vmware_bridge (enabled)
VMware Network Adapter VMnet1: VMware Bridge Protocol -> vmware_bridge (disabled)
Ethernet: VMware Bridge Protocol -> vmware_bridge (enabled)
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
HKLM\...\StartupApproved\StartupFolder: => "Avid Application Manager.lnk"
HKLM\...\StartupApproved\Run: => "PDF24"
HKLM\...\StartupApproved\Run: => "DigidesignMMERefresh"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "vmware-tray.exe"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\StartupFolder: => "rekordboxAgent.lnk"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "CiscoMeetingDaemon"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "CiscoSpark"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_4D67C3CB7D15609F738713BBF52A3A48"
HKU\S-1-5-21-3203882355-2465378241-1904074028-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{B0F7A8B0-742F-4122-B8A3-D088453E9334}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{95DE6847-2DF0-47EB-9BEF-F9141EB68D98}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{742BDAB2-59CB-429B-B8FA-D83336DCCAF2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{95C6F058-C7C8-4896-BCA1-F5644A1FA279}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8D3D2C69-7A73-41D0-BB40-95C0E3FDA997}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{92282828-0611-4788-8229-DC7CF8DDAC51}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{85FA02CE-5F40-4B74-A538-44D905B1A418}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1093ED26-AE6D-46B5-839D-CBA774FCED2B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{40704FC3-B77C-4CE5-A6D4-770F5ABA4CA4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B92DF34A-EB05-4A66-99FE-E19B5DEF377A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{295C6CE7-7412-44A8-AF57-DA679936E62D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5E159A1F-85F5-4409-AA79-0A29830D6DD6}] => (Allow) LPort=32682
FirewallRules: [{88A723FD-2EC9-4D34-AC2C-3A86B198C814}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{11FB3506-1E8D-43A0-BEF6-A43F2D29F8B5}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{70AE0C66-590A-48EF-84BE-05921365C3CD}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{36254BEA-AD6B-451A-A424-F371EC13CC99}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{CD23AB14-32A4-4521-9278-6D401FC80DCA}] => (Allow) D:\Programme\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe (EA Digital Illusions CE AB -> EA Digital Illusions CE AB)
FirewallRules: [{B8991E9B-DC6F-4F9F-BFD7-D7FAC98926E4}] => (Allow) D:\Programme\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe (EA Digital Illusions CE AB -> EA Digital Illusions CE AB)
FirewallRules: [{95FB7026-B5A9-4B10-8A0D-898A5831FFD0}] => (Allow) D:\Programme\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe (UBISOFT ENTERTAINMENT INC. -> Blue Mammoth Games)
FirewallRules: [{3B75BFED-2159-4024-9AED-1DC71A073F32}] => (Allow) D:\Programme\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe (UBISOFT ENTERTAINMENT INC. -> Blue Mammoth Games)
FirewallRules: [{BBE27F17-2D0B-4409-BC83-F8E479B8A169}] => (Allow) D:\Programme\Steam\steamapps\common\Business Tour\BusinessTour.exe () [Datei ist nicht signiert]
FirewallRules: [{F9EBFE0D-C363-4CC1-A6F3-3D4D9BAC5887}] => (Allow) D:\Programme\Steam\steamapps\common\Business Tour\BusinessTour.exe () [Datei ist nicht signiert]
FirewallRules: [{A051E65C-B58A-4EDE-A8CA-C9E480F100E5}] => (Allow) D:\Programme\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => Keine Datei
FirewallRules: [{E1360204-6D48-4C00-87E0-B87F8BF77119}] => (Allow) D:\Programme\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => Keine Datei
FirewallRules: [{46C7D13A-43B7-4230-B7F6-B5BC7B7C78B5}] => (Allow) D:\Programme\Steam\steamapps\common\Human Fall Flat\Human.exe () [Datei ist nicht signiert]
FirewallRules: [{8D98A846-E0A9-4744-9EAD-113AEB33D970}] => (Allow) D:\Programme\Steam\steamapps\common\Human Fall Flat\Human.exe () [Datei ist nicht signiert]
FirewallRules: [{9F7A774E-AB60-49E4-8341-B665C14398E9}] => (Allow) D:\Programme\Steam\steamapps\common\Poly Bridge\polybridge.exe () [Datei ist nicht signiert]
FirewallRules: [{3E14E871-4F66-4381-B1F8-2FD5CC1092BF}] => (Allow) D:\Programme\Steam\steamapps\common\Poly Bridge\polybridge.exe () [Datei ist nicht signiert]
FirewallRules: [{96DA8933-5D2C-407A-87D2-83D028E6DCD2}] => (Allow) D:\Programme\Steam\steamapps\common\Stigmat\Stigmat.exe () [Datei ist nicht signiert]
FirewallRules: [{47BD320C-76DE-406A-BB60-3EB8364E9382}] => (Allow) D:\Programme\Steam\steamapps\common\Stigmat\Stigmat.exe () [Datei ist nicht signiert]
FirewallRules: [{E12B3C2B-A8AB-4950-98A1-56E40548F74A}] => (Allow) D:\Programme\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe () [Datei ist nicht signiert]
FirewallRules: [{32925F97-E4F9-4A6E-B035-4D1E18D3A2BA}] => (Allow) D:\Programme\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe () [Datei ist nicht signiert]
FirewallRules: [{C47CA2D5-518A-4DA9-B868-728BE2B52B58}] => (Allow) D:\Programme\Steam\steamapps\common\TRIP\trip.exe () [Datei ist nicht signiert]
FirewallRules: [{F9CA3290-8088-4478-86E8-CA1290D633B0}] => (Allow) D:\Programme\Steam\steamapps\common\TRIP\trip.exe () [Datei ist nicht signiert]
FirewallRules: [{7765A5DF-3DE8-48A1-A81F-0CC79A7A2FC7}] => (Allow) D:\Programme\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe () [Datei ist nicht signiert]
FirewallRules: [{C4F65A04-192C-4DA8-92BC-CB67801F8EE7}] => (Allow) D:\Programme\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe () [Datei ist nicht signiert]
FirewallRules: [{F04FFBAC-BF43-401F-AEC8-A4379BC0405D}] => (Allow) D:\Programme\Steam\steamapps\common\Ben and Ed - Blood Party\BaEBloodParty.exe () [Datei ist nicht signiert]
FirewallRules: [{C2C23592-85B3-40BD-8927-38277119BA68}] => (Allow) D:\Programme\Steam\steamapps\common\Ben and Ed - Blood Party\BaEBloodParty.exe () [Datei ist nicht signiert]
FirewallRules: [{5A22AC9F-2EE1-44D7-9C85-96EF3DB8EC16}] => (Allow) D:\Programme\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe (Haemimont Games) [Datei ist nicht signiert]
FirewallRules: [{DEBFF066-D7ED-4E36-B435-8E8B59E0A1A0}] => (Allow) D:\Programme\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe (Haemimont Games) [Datei ist nicht signiert]
FirewallRules: [{ECF581ED-9FA1-4CAF-A7E7-6B658B28F639}] => (Allow) C:\Users\ichbi\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{EE9CDDA4-6010-4976-93E5-B2B9769023AB}] => (Allow) C:\Users\ichbi\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{8F481034-9422-4A5B-ABD1-1019C730B929}] => (Allow) C:\Users\ichbi\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{698DD5BB-309F-414F-AE93-13D2C56581B4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{85A3CDE6-2499-4504-99FA-AB9826CA249B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{05097074-1493-48EF-AD9B-F765D37B2747}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6093BB38-E05A-4612-9CDA-B6E1FFB0273F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E91EA20F-7E0C-4B61-8155-211B3A118E47}] => (Allow) C:\Program Files\Avid\Cloud Client Services\Hub.exe (Avid Technology, Inc. -> Avid Technology, Inc.)
FirewallRules: [{0FB5BFB4-D01A-4F67-B20E-4359CB2418F6}] => (Allow) C:\Program Files\Avid\Cloud Client Services\TransportClient.exe (Avid Technology, Inc. -> Avid Technology, Inc.)
FirewallRules: [{D5DD9903-A84C-4FCD-B224-62B32F915722}] => (Allow) C:\Program Files\Avid\Avid Link\jre\bin\java.exe => Keine Datei
FirewallRules: [{7F052D66-EB4D-465C-BF94-545F94D58325}] => (Allow) C:\Program Files\Avid\Avid Link\Avid Link.exe => Keine Datei
FirewallRules: [{31D62179-368A-4BF3-A351-9208DD232D3B}] => (Allow) C:\Program Files\Avid\Avid Link\AvidAppManHelper.exe => Keine Datei
FirewallRules: [{3631C4B7-5200-4A66-91A5-6596F9900D0C}] => (Allow) D:\Programme\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{830C12D3-1A9F-4FA9-A8F8-19950593A9C3}] => (Allow) D:\Programme\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [{6D46D3F3-8271-4E93-8D95-F7496560D969}] => (Allow) C:\Program Files\Avid\Pro Tools FirstProToolsFirst.exe => Keine Datei
FirewallRules: [TCP Query User{54638ADB-8D0A-48AE-A917-0E07EE5F39E2}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe => Keine Datei
FirewallRules: [UDP Query User{1A6138DB-AC6F-41F8-9A06-B5C6BF4EF915}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe => Keine Datei
FirewallRules: [TCP Query User{7FDBB71B-D166-4F69-AF85-D69671A36023}D:\programme\gta5\grand theft auto v\gta5.exe] => (Allow) D:\programme\gta5\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{E692F718-035B-47FA-8C50-A5864531A509}D:\programme\gta5\grand theft auto v\gta5.exe] => (Allow) D:\programme\gta5\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{15F0CB0C-C722-4BD6-9A45-38D08669016C}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe => Keine Datei
FirewallRules: [UDP Query User{3DAAA096-EE19-481D-A213-8297E9BDA2CF}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe => Keine Datei
FirewallRules: [{5C099345-F44F-40EE-ABEB-443138F2B070}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{415CFEAE-60E7-4709-AC47-DFBEF0B3D14B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{F5934923-D33E-491B-AF66-808660737E5A}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{6651349D-8367-4BC6-8ABC-C3A43A563E6A}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [TCP Query User{F3C5B21C-2E57-4956-B591-0ED06F620995}C:\users\ichbi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ichbi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{C280454A-A011-48F0-8C35-DCA9677431B4}C:\users\ichbi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ichbi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{AE50AEA7-4C6A-4570-B47D-F91C30A78436}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{60067F71-F890-46BF-B0D2-A6A3AAC4B148}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FE4432A8-A73F-4CE6-9D02-8688CB2A6948}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C2D9597D-3A0F-43E7-9B58-C8BE818F5DCF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8B93FA1B-D066-40E8-894A-2A9411C3496E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{871CF4E8-B398-47D9-87BB-38D0D120F899}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2518094A-AC98-41FA-B8C5-DBBD5B32561B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6BB64CEA-788C-4878-93FE-AE098E948A10}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.164.561.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [TCP Query User{0F5DCF46-9885-4C55-A693-CA0F99D92F2F}C:\users\ichbi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ichbi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{D6C02BC9-AA0B-4867-AAA7-8E77F2EE9DE9}C:\users\ichbi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ichbi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A19B1C4D-ABE2-44E0-886D-AA9C940265F4}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaUI.exe => Keine Datei
FirewallRules: [{7992D638-601B-4BB5-A224-0E10B0062D70}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaUI.exe => Keine Datei
FirewallRules: [TCP Query User{B8E8807C-D99A-45EA-BC8B-ADBB8BA083EE}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe
FirewallRules: [UDP Query User{D1FFB670-BAD0-4F2A-ACF0-8276EC743ED6}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe
FirewallRules: [{7271F8DD-576F-42A3-BC3A-FD5D9025B82D}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
FirewallRules: [{E1380A33-0EBC-4ED1-BC81-640A65AC32C1}] => (Allow) LPort=1542
FirewallRules: [{C49C792E-2A12-4334-9C12-BBFB31AA38B0}] => (Allow) LPort=1542
FirewallRules: [{22B6582F-CDC8-402C-84A2-DB276DAEBB3C}] => (Allow) LPort=53
FirewallRules: [{9132FED8-8A09-4AAB-B5E6-C3B2FB270F76}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{34FA8617-09E5-4846-B27F-82EC5FEDD9EE}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{A14FF5E4-CFF5-404F-B2C6-6EF34A600E61}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{CE224003-4E2C-4D4A-B202-A23D61F8F14B}] => (Allow) LPort=53
FirewallRules: [{C0FC1DEB-91BB-4A22-9AD7-82AB7BBC69AD}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{9AC907C3-7C29-4FEB-A74C-6186F1D4EF9B}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{22D20951-604C-4F91-BBEC-79940A34C168}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [{A332EBD2-6094-4307-8522-5598CC38432F}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek)
FirewallRules: [TCP Query User{2A0DE262-92D3-4167-AA7C-55741094346A}D:\programme\steam\steamapps\common\ben and ed - blood party\baebloodparty\binaries\win32\baebloodparty.exe] => (Allow) D:\programme\steam\steamapps\common\ben and ed - blood party\baebloodparty\binaries\win32\baebloodparty.exe (Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{35E1A64F-92EE-432B-A95B-37C8F7365CC8}D:\programme\steam\steamapps\common\ben and ed - blood party\baebloodparty\binaries\win32\baebloodparty.exe] => (Allow) D:\programme\steam\steamapps\common\ben and ed - blood party\baebloodparty\binaries\win32\baebloodparty.exe (Epic Games, Inc.) [Datei ist nicht signiert]
FirewallRules: [TCP Query User{298FF566-C6AD-4F2D-9213-44C20875F095}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [UDP Query User{CE128228-330B-4D40-9E09-CA0D1594E405}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [{421212DF-F44C-49B4-A014-3F27C1C03110}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{AB2F84C2-9F8D-4F35-928C-538512CED97D}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [TCP Query User{8202C236-541F-4A7E-9D31-F84EBF510D72}C:\program files\teamspeak 3 client\ts3client_win64.exe] => (Allow) C:\program files\teamspeak 3 client\ts3client_win64.exe (TeamSpeak Systems GmbH -> TeamSpeak Systems GmbH)
FirewallRules: [UDP Query User{4E04F0E0-4381-4BEF-8A84-7F6E91448868}C:\program files\teamspeak 3 client\ts3client_win64.exe] => (Allow) C:\program files\teamspeak 3 client\ts3client_win64.exe (TeamSpeak Systems GmbH -> TeamSpeak Systems GmbH)
FirewallRules: [{6EC8EBC8-C4AE-4060-BB8D-90EDC311F56C}] => (Allow) D:\Programme\Steam\steamapps\common\Farming Simulator 19\x64\FarmingSimulator2019Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{4A06503D-87BE-441D-81E8-A2B8FF1B8939}] => (Allow) D:\Programme\Steam\steamapps\common\Farming Simulator 19\x64\FarmingSimulator2019Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [TCP Query User{27E8C48E-80B0-45CF-9F7F-4ECC15338866}C:\program files\soundswitch\soundswitch.exe] => (Allow) C:\program files\soundswitch\soundswitch.exe (inMusic New Zealand Limited -> Onesixone)
FirewallRules: [UDP Query User{4C445716-4DC1-48E4-8192-C495FAC1C569}C:\program files\soundswitch\soundswitch.exe] => (Allow) C:\program files\soundswitch\soundswitch.exe (inMusic New Zealand Limited -> Onesixone)
FirewallRules: [TCP Query User{846B90C7-4163-4CD9-A42B-166F5EC89030}C:\program files (x86)\dmxcontrol\dmxcontrol.exe] => (Allow) C:\program files (x86)\dmxcontrol\dmxcontrol.exe (DMXControl Projects e. V. -> PopSoft) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{B1EFC2E0-2456-47F8-87D7-E0C1C25986B8}C:\program files (x86)\dmxcontrol\dmxcontrol.exe] => (Allow) C:\program files (x86)\dmxcontrol\dmxcontrol.exe (DMXControl Projects e. V. -> PopSoft) [Datei ist nicht signiert]
FirewallRules: [TCP Query User{D2044C2D-12F1-42E5-841B-18CE131ACECA}D:\programme\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\programme\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [UDP Query User{90D8489E-24F4-439F-9792-684443C0FE61}D:\programme\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\programme\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe (KRAFTON, Inc. -> KRAFTON, Inc.)
FirewallRules: [TCP Query User{47F86A28-8DAC-4F5B-A010-7CA8CDE7A63A}C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe () [Datei ist nicht signiert]
FirewallRules: [UDP Query User{6E915E32-18C0-4FAB-B502-543B26929A2C}C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe () [Datei ist nicht signiert]
FirewallRules: [TCP Query User{15FBCB82-2D1A-453B-91CD-469BA8C3283D}C:\program files (x86)\chamsys ltd\magicq pc\mqhd.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqhd.exe () [Datei ist nicht signiert]
FirewallRules: [UDP Query User{4779BFB5-8EE1-415A-8B99-07EDEB19D724}C:\program files (x86)\chamsys ltd\magicq pc\mqhd.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqhd.exe () [Datei ist nicht signiert]
FirewallRules: [TCP Query User{4D34AAE5-D22C-4494-BC1D-28F8ED4D4C7E}C:\program files (x86)\chamsys ltd\magicq pc\mqvis.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqvis.exe () [Datei ist nicht signiert]
FirewallRules: [UDP Query User{DF4D2E36-8D31-4740-9761-09CB42ACBED9}C:\program files (x86)\chamsys ltd\magicq pc\mqvis.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqvis.exe () [Datei ist nicht signiert]
FirewallRules: [{209964DC-45DA-4557-9581-5E8AD818AA13}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.6.3\bin\app_system.exe (MA Lighting Technology GmbH. -> MA Lighting Technology)
FirewallRules: [{F23FC923-CD12-40FA-B3D3-053788239B81}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.6.3\bin\app_gma3.exe (MA Lighting Technology GmbH. -> MA Lighting Technology)
FirewallRules: [{7F4C126F-5FC3-4450-A0A6-444D1CFFAB9E}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.6.3\bin\app_updater.exe (MA Lighting Technology GmbH. -> )
FirewallRules: [{5EB89E3E-499D-47EC-BDC0-CB66F4CE3FB0}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.6.3\bin\app_terminal.exe (MA Lighting Technology GmbH. -> )
FirewallRules: [{0B49B177-E589-46DE-8C5D-75831329ACEB}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{5DEEA7C4-8295-429C-9A94-165C81C0251E}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{2BF8500B-6703-4D2B-9309-3F6F9B4B62D3}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe (VMware, Inc. -> )
FirewallRules: [{0B16A5A2-33CB-4FA1-B71A-0BAD9FBDEA80}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe (VMware, Inc. -> )
FirewallRules: [{B82115B8-EEC8-4988-99EC-3AF102D91403}] => (Allow) D:\Programme\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{D62FEDEB-CBBC-4842-B4F9-64C5993CA2B7}] => (Allow) D:\Programme\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{06D7853D-258F-404A-A63D-8DFDABED638D}D:\programme\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\programme\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{3750B706-27CA-40B1-989D-4C45F9D2DC25}D:\programme\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\programme\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{196BF6AF-7522-4C90-91A5-ED7CB6B98880}C:\programdata\ichbi\wtools\app-1.2.1\wtools.exe] => (Allow) C:\programdata\ichbi\wtools\app-1.2.1\wtools.exe (LightingSoft AG -> Nicolaudie Group Inc.)
FirewallRules: [UDP Query User{6F3044D3-7F94-4ABB-81CA-3FD2286AB48D}C:\programdata\ichbi\wtools\app-1.2.1\wtools.exe] => (Allow) C:\programdata\ichbi\wtools\app-1.2.1\wtools.exe (LightingSoft AG -> Nicolaudie Group Inc.)
FirewallRules: [TCP Query User{CA5358B8-53B6-4BEF-B164-E1CCEE34F8B0}C:\users\ichbi\appdata\local\wtools\app-1.2.1\wtools.exe] => (Allow) C:\users\ichbi\appdata\local\wtools\app-1.2.1\wtools.exe => Keine Datei
FirewallRules: [UDP Query User{6CCEC559-DEC4-427E-B5A0-CFE2A65ACC1D}C:\users\ichbi\appdata\local\wtools\app-1.2.1\wtools.exe] => (Allow) C:\users\ichbi\appdata\local\wtools\app-1.2.1\wtools.exe => Keine Datei
FirewallRules: [TCP Query User{26B00AC8-815B-4050-AADE-BA25146CBDBD}C:\program files\matlab\r2021b\bin\win64\_temp_supportsoftwaredownloader_r2022a_win64\bin\win64\supportsoftwareinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\_temp_supportsoftwaredownloader_r2022a_win64\bin\win64\supportsoftwareinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [UDP Query User{F26EB670-3AAA-4804-AEF1-DD333F9C522E}C:\program files\matlab\r2021b\bin\win64\_temp_supportsoftwaredownloader_r2022a_win64\bin\win64\supportsoftwareinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\_temp_supportsoftwaredownloader_r2022a_win64\bin\win64\supportsoftwareinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [TCP Query User{07BC7897-6B76-465C-BFA2-9B260CE860AB}C:\program files\matlab\r2021b\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\matlab.exe (The MathWorks, Inc. -> The MathWorks Inc.)
FirewallRules: [UDP Query User{44334CEA-8AAF-4AA3-A8F3-365B8A758E02}C:\program files\matlab\r2021b\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\matlab.exe (The MathWorks, Inc. -> The MathWorks Inc.)
FirewallRules: [TCP Query User{E0BF3854-1654-44B3-AEC7-07ADE6070D9F}C:\program files (x86)\dmxcontrol\dmxcontrol.exe] => (Allow) C:\program files (x86)\dmxcontrol\dmxcontrol.exe (DMXControl Projects e. V. -> PopSoft) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{E74E8248-E22C-451F-90B9-A3DAFE5DA197}C:\program files (x86)\dmxcontrol\dmxcontrol.exe] => (Allow) C:\program files (x86)\dmxcontrol\dmxcontrol.exe (DMXControl Projects e. V. -> PopSoft) [Datei ist nicht signiert]
FirewallRules: [{36BDEFAA-AEB0-402E-A339-3CFFA93FEDEF}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{7D0798BF-12F9-43AB-9CE9-B6EF02CF4E24}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{A3485A3C-0C30-45AE-96EB-15CF8C877569}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{4D90C065-C1AF-41CC-A788-E97E93FC1A4F}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{913753A8-2331-4E42-84E5-FF36FFA0BBC9}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{3A7EFEBE-5992-4784-9F5D-FC0CA859C2B8}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{58F44218-D96A-4238-B960-20AF731D50DA}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => Keine Datei
FirewallRules: [{F972CA2B-5A8B-407F-B53C-D9DBDA10D812}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\fuscript.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{F970A519-8C2C-4A91-AE66-D210F8C04511}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C086083F-11C9-45BC-917D-E1D8AD5832E3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A8BD563C-2C87-4746-9003-A343A29FBCA8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{91C5865B-41FC-40BB-B8DB-C1C82AC39EEE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{8B55B662-EC8B-4982-A7D3-883B85DFDC70}C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [UDP Query User{17FF7001-D56A-467D-BC41-4E1C19B487F9}C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [TCP Query User{853B8257-A28E-49F4-88A0-4E5B74F14810}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{5AD9B704-B2EA-40EA-B727-BD99BD14C80D}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{66936BB7-2C76-44D6-AE2A-9E865AE2D9EF}C:\program files (x86)\minecraft launcher\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft launcher\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{9400B343-9976-466F-B1B8-356D185309BB}C:\program files (x86)\minecraft launcher\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft launcher\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [{41411A05-8AF8-477B-B3E4-B8E12BC61B08}] => (Allow) D:\Programme\Steam\steamapps\common\Poly Bridge 2\Poly Bridge 2.exe () [Datei ist nicht signiert]
FirewallRules: [{39797DF0-8291-498B-8209-9FC440C51412}] => (Allow) D:\Programme\Steam\steamapps\common\Poly Bridge 2\Poly Bridge 2.exe () [Datei ist nicht signiert]
FirewallRules: [TCP Query User{5192F18A-FE9A-42CE-B9FC-A652AA2D7254}C:\users\ichbi\appdata\local\wtools\app-1.3.1\wtools.exe] => (Allow) C:\users\ichbi\appdata\local\wtools\app-1.3.1\wtools.exe => Keine Datei
FirewallRules: [UDP Query User{6D696B6C-E016-4EE3-9788-E93AA2547048}C:\users\ichbi\appdata\local\wtools\app-1.3.1\wtools.exe] => (Allow) C:\users\ichbi\appdata\local\wtools\app-1.3.1\wtools.exe => Keine Datei
FirewallRules: [TCP Query User{82509882-027A-4AD5-85DC-85331334874B}C:\slmev\easyview.exe] => (Allow) C:\slmev\easyview.exe => Keine Datei
FirewallRules: [UDP Query User{8C0000D6-E413-4930-8F41-87C5BBCEFB9A}C:\slmev\easyview.exe] => (Allow) C:\slmev\easyview.exe => Keine Datei
FirewallRules: [{5C79924A-DA3E-4D30-861B-661736EFF82D}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\rekordbox.exe (AlphaTheta Corporation -> AlphaTheta Corporation)
FirewallRules: [{DB418B63-0756-4B42-9C7A-4B25EA3ADCA3}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\psvnfsd.exe (AlphaTheta Corporation -> AlphaTheta Corporation)
FirewallRules: [{6817FB9D-4BC6-4613-9B90-524F0C7366C5}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\psvlinksysmgr.exe (AlphaTheta Corporation -> AlphaTheta Corporation)
FirewallRules: [{E1C6B6A3-1517-476A-9DEC-8D59B018A5A7}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\edb_streamd.exe (AlphaTheta Corporation -> )
FirewallRules: [{7BCC20EF-F379-4E31-8C44-BE1951EF3F54}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\ls-unity-rekordbox-win-64bit.exe (AlphaTheta Corporation -> )
FirewallRules: [{8142F0FD-C6B8-41BE-9977-DDCD6F8332E4}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\rbHttpServer.exe (AlphaTheta Corporation -> )
FirewallRules: [{8DF0DBBC-2C79-49A5-A89E-57C5E846E9CE}] => (Allow) C:\Program Files\Pioneer\rekordbox 6.6.5\rekordboxAgent-win32-x64\rekordboxAgent.exe (AlphaTheta Corporation -> AlphaTheta Corporation)
FirewallRules: [{2C7F95BC-A010-4587-BCF5-CD5ECB472F57}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\rekordbox.exe (AlphaTheta Corporation -> AlphaTheta Corporation)
FirewallRules: [{435E3049-627F-42BF-9244-2993CD6EFF65}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\psvnfsd.exe (AlphaTheta Corporation -> Pioneer DJ Corporation.)
FirewallRules: [{EEF1B5BF-CF35-4786-9E50-60C0CC9ACF53}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\psvlinksysmgr.exe (AlphaTheta Corporation -> Pioneer DJ Corporation.)
FirewallRules: [{C6C52502-8B12-4742-A37A-06DEBCCAE348}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\edb_streamd.exe (AlphaTheta Corporation -> )
FirewallRules: [{DC6677E7-0905-41C8-9FBA-CEB5B44C27D7}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\ls-unity-rekordbox-win-64bit.exe (AlphaTheta Corporation -> )
FirewallRules: [{916D74EF-83EA-456A-A417-FB1992BE5708}] => (Allow) C:\Program Files\Pioneer\rekordbox 5.8.7\rbHttpServer.exe (AlphaTheta Corporation -> )
FirewallRules: [{E05669DB-864E-4260-94F9-337F38F5BEEA}] => (Allow) D:\Programme\Steam\steamapps\common\Galaxy Life\Galaxy Life.exe => Keine Datei
FirewallRules: [{B6148BC4-430A-4DF9-93BC-42598B9B5107}] => (Allow) D:\Programme\Steam\steamapps\common\Galaxy Life\Galaxy Life.exe => Keine Datei
FirewallRules: [{E569B051-DD70-41F3-862A-F6FD6A5CBCDF}] => (Allow) D:\Programme\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{E08D4857-5A29-4D0B-AEDE-1B51D9F1DCCE}] => (Allow) D:\Programme\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{2A09DE71-F547-4502-99EB-87FE0AFD931A}] => (Allow) D:\Programme\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{778F20A8-0A95-4DBE-BA4C-568700FF969F}] => (Allow) D:\Programme\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6D8CD427-FC49-449C-8429-591815B42E35}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{B60DD0A4-007C-4781-9A7C-B6726585CBDC}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{7FBD8017-7D39-4E6B-A496-D2EFFD97DC09}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{304A9476-9153-4778-8DFF-E1EBE19FF75B}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{C3B9F1F0-4281-4DFE-B658-4ADCD6D6E33A}C:\program files\engine dj\engine dj.exe] => (Allow) C:\program files\engine dj\engine dj.exe (inMusic Brands, Inc. -> AIR Music Technology)
FirewallRules: [UDP Query User{B29F8ED8-C00D-4C89-BB63-64F55E6A6E07}C:\program files\engine dj\engine dj.exe] => (Allow) C:\program files\engine dj\engine dj.exe (inMusic Brands, Inc. -> AIR Music Technology)
FirewallRules: [TCP Query User{0EC46D3C-0AFC-4662-A66A-56FE928526F5}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [UDP Query User{6F7825AD-6CDD-4214-86F5-81B8E6EEE1A1}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [TCP Query User{7A7B07CF-FA17-45D6-BDD5-A0506108A63F}C:\program files\engine dj\engine dj.exe] => (Allow) C:\program files\engine dj\engine dj.exe (inMusic Brands, Inc. -> AIR Music Technology)
FirewallRules: [UDP Query User{40585C1B-A4C7-41E9-A793-8B2B81406061}C:\program files\engine dj\engine dj.exe] => (Allow) C:\program files\engine dj\engine dj.exe (inMusic Brands, Inc. -> AIR Music Technology)
FirewallRules: [{9DAE8B49-9222-4050-BBB9-078BEDEF8F55}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{73B57914-2EB7-46F2-95A4-C49036D526BE}C:\users\ichbi\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\ichbi\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{CE1222EA-F448-4AD4-8EA0-4D95BA8E1216}C:\users\ichbi\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\ichbi\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{41555CD2-0F77-48EE-AEB8-EC8F0A3E8E72}C:\users\ichbi\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\ichbi\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{D809FF12-1E98-4748-9CD5-BB56B04A56AE}C:\users\ichbi\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\ichbi\curseforge\minecraft\install\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [TCP Query User{D35390B7-8F41-4D35-8369-222F5AA69FC6}C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [UDP Query User{9B3F6935-56B7-4014-A863-836D95D0E386}C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe] => (Allow) C:\program files\matlab\r2021b\bin\win64\addonproductinstaller.exe (The MathWorks, Inc. -> The MathWorks, Inc)
FirewallRules: [TCP Query User{B36BB949-8E06-4EFC-87E1-8891E3FB108D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{69BDE64E-AA0D-481B-9C50-34CFAD897D1E}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{00075C33-9180-4FDC-8F75-E29D436FDF85}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\120.0.2210.91\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Wiederherstellungspunkte =========================
17-12-2023 13:31:39 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660
04-01-2024 19:06:06 Geplanter Prüfpunkt
==================== Fehlerhafte Geräte im Gerätemanager ============
Name: PANGP Virtual Ethernet Adapter
Description: PANGP Virtual Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: PaloAltoNetworks
Service: PanGpd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Fehlereinträge in der Ereignisanzeige: ========================
Applikationsfehler:
==================
Error: (01/05/2024 07:23:15 PM) (Source: Firefox Default Browser Agent) (EventID: 2) (User: )
Description: Event-ID 2
Error: (01/05/2024 06:43:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ESETOnlineScanner.exe, Version: 10.23.31.0, Zeitstempel: 0x61e82da2
Name des fehlerhaften Moduls: WININET.dll, Version: 11.0.19041.3636, Zeitstempel: 0x5ccf5c78
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00313a68
ID des fehlerhaften Prozesses: 0x114c
Startzeit der fehlerhaften Anwendung: 0x01da3ffea06a0a4d
Pfad der fehlerhaften Anwendung: C:\Users\ichbi\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\WININET.dll
Berichtskennung: 2b71e4d5-ee66-4ef2-a8f4-55a08424b88f
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/05/2024 06:42:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ESETOnlineScanner.exe, Version: 10.23.31.0, Zeitstempel: 0x61e82da2
Name des fehlerhaften Moduls: WININET.dll, Version: 11.0.19041.3636, Zeitstempel: 0x5ccf5c78
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00313a68
ID des fehlerhaften Prozesses: 0x3f20
Startzeit der fehlerhaften Anwendung: 0x01da3ffe97635775
Pfad der fehlerhaften Anwendung: C:\Users\ichbi\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\WININET.dll
Berichtskennung: 2a2b3822-a536-482b-8251-1b2731c4223c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/05/2024 06:42:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ESETOnlineScanner.exe, Version: 10.23.31.0, Zeitstempel: 0x61e82da2
Name des fehlerhaften Moduls: WININET.dll, Version: 11.0.19041.3636, Zeitstempel: 0x5ccf5c78
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00313a68
ID des fehlerhaften Prozesses: 0x3084
Startzeit der fehlerhaften Anwendung: 0x01da3ffe8d53e41f
Pfad der fehlerhaften Anwendung: C:\Users\ichbi\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\WININET.dll
Berichtskennung: 3affffdd-2815-477a-9056-a528ed538e4a
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/05/2024 06:42:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ESETOnlineScanner.exe, Version: 10.23.31.0, Zeitstempel: 0x61e82da2
Name des fehlerhaften Moduls: WININET.dll, Version: 11.0.19041.3636, Zeitstempel: 0x5ccf5c78
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00313a68
ID des fehlerhaften Prozesses: 0x4364
Startzeit der fehlerhaften Anwendung: 0x01da3ffe86d66f6e
Pfad der fehlerhaften Anwendung: C:\Users\ichbi\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\WININET.dll
Berichtskennung: 1e77e458-40ab-414b-957f-84ca3f422af7
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/05/2024 06:39:32 PM) (Source: NIHardwareService) (EventID: 259) (User: )
Description: MIDIDevice: Unable to unlock BMIDI DLL/driver
Error: (01/04/2024 07:23:16 PM) (Source: Firefox Default Browser Agent) (EventID: 2) (User: )
Description: Event-ID 2
Error: (01/04/2024 06:52:48 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Die Speicheroptimierung konnte erneut optimieren auf DatenII (E:) nicht abschließen. Grund: Der angeforderte Vorgang wird von der Hardware des Volumes nicht unterstützt. (0x8900002A)
Systemfehler:
=============
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "VMware Workstation Server" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VMware Authorization Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "VMware USB Arbitration Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VMware DHCP Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "PDF24" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "PACE License Services" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 2000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/05/2024 06:41:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "PanGPS" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Windows Defender:
================
Date: 2024-01-04 17:10:27
Description:
Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {22D83DEA-FBB0-4151-940D-4476E65F55DF}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2023-12-23 22:45:01
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/Phish&threatid=2147678587&enterprise=0
Name: Trojan:HTML/Phish
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: containerfile:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar; file:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar->backup_domainmail_2109251227.tgz->(GZip)->info/Maildir/new/1538777135.M782738P8140V0000000000000902I0000000004120FB7.srv.web-alpha.de,S=2158; file:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar->backup_domainmail_2109251227.tgz->(GZip)->inhaber/Maildir/new/1538777136.M302278P8157V0000000000000902I0000000004120FB8.srv.web-alpha.de,S=2374; file:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar->backup_domainmail_2109251227.tgz->(GZip)->inhaber/Maildir/new/1538913208.M471140P25230V0000000000000902I0000000004120FBC.srv.web-alpha.de,S=2397
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Benutzer
Benutzer: JULIAN-PC-STUDI\ichbi
Prozessname: Unknown
Sicherheitsversion: AV: 1.403.693.0, AS: 1.403.693.0, NIS: 1.403.693.0
Modulversion: AM: 1.1.23110.2, NIS: 1.1.23110.2
Date: 2023-12-23 22:45:01
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Wacatac.H!ml&threatid=2147814524&enterprise=0
Name: Trojan:Script/Wacatac.H!ml
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: file:_C:\Users\ichbi\Downloads\Chapter-File-1.rar
Erkennungsursprung: Lokaler Computer
Erkennungstype: FastPath
Erkennungsquelle: Benutzer
Benutzer: JULIAN-PC-STUDI\ichbi
Prozessname: Unknown
Sicherheitsversion: AV: 1.403.693.0, AS: 1.403.693.0, NIS: 1.403.693.0
Modulversion: AM: 1.1.23110.2, NIS: 1.1.23110.2
Date: 2023-12-23 22:45:01
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Zusy.EC!MTB&threatid=2147842708&enterprise=0
Name: Trojan:Win32/Zusy.EC!MTB
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: containerfile:_C:\$Recycle.Bin\S-1-5-21-3203882355-2465378241-1904074028-1001\$R0F09Q3.zip; file:_C:\$Recycle.Bin\S-1-5-21-3203882355-2465378241-1904074028-1001\$R0F09Q3.zip->aclui.dll
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Benutzer
Benutzer: JULIAN-PC-STUDI\ichbi
Prozessname: Unknown
Sicherheitsversion: AV: 1.403.693.0, AS: 1.403.693.0, NIS: 1.403.693.0
Modulversion: AM: 1.1.23110.2, NIS: 1.1.23110.2
Date: 2023-12-23 22:45:01
Description:
Microsoft Defender Antivirus hat Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:HTML/CryptoExtortBTC&threatid=2147830595&enterprise=0
Name: Trojan:HTML/CryptoExtortBTC
Schweregrad: Schwerwiegend
Kategorie: Trojaner
Pfad: containerfile:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar; file:_E:\Backups\Equi-Trend.com\backup_equi-trend.com_2109251227.tar->backup_domainmail_2109251227.tgz->(GZip)->info/Maildir/new/1631216929.M296629P18582.mailsrv.web-beta.de,S=2876,W=2921
Erkennungsursprung: Lokaler Computer
Erkennungstype: Konkret
Erkennungsquelle: Benutzer
Benutzer: JULIAN-PC-STUDI\ichbi
Prozessname: Unknown
Sicherheitsversion: AV: 1.403.693.0, AS: 1.403.693.0, NIS: 1.403.693.0
Modulversion: AM: 1.1.23110.2, NIS: 1.1.23110.2
CodeIntegrity:
===============
Date: 2024-01-05 20:00:14
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
==================== Speicherinformationen ===========================
BIOS: American Megatrends International, LLC. H.F1 08/04/2021
Hauptplatine: Micro-Star International Co., Ltd. X570-A PRO (MS-7C37)
Prozessor: AMD Ryzen 9 3900X 12-Core Processor
Prozentuale Nutzung des RAM: 20%
Installierter physikalischer RAM: 32689.02 MB
Verfügbarer physikalischer RAM: 25857.91 MB
Summe virtueller Speicher: 37553.02 MB
Verfügbarer virtueller Speicher: 28314.89 MB
==================== Laufwerke ================================
Drive c: (Boot) (Fixed) (Total:476.38 GB) (Free:71.56 GB) (Model: SAMSUNG MZVL2512HCJQ-00B00) NTFS
Drive d: (Daten) (Fixed) (Total:953.87 GB) (Free:161.42 GB) (Model: SAMSUNG MZVL21T0HCLR-00B00) NTFS
Drive e: (DatenII) (Fixed) (Total:931.51 GB) (Free:645.51 GB) (Model: ST1000DM003-1ER162) NTFS
\\?\Volume{2ef37091-0000-0000-0000-100000000000}\ (System-reserviert) (Fixed) (Total:0.05 GB) (Free:0.02 GB) NTFS
\\?\Volume{2ef37091-0000-0000-0000-d01b77000000}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS
==================== MBR & Partitionstabelle ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: F38A4BF1)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 2EF37091)
Partition 1: (Active) - (Size=50 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=476.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=515 MB) - (Type=27)
==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 953.9 GB) (Disk ID: C78726A4)
Partition 1: (Not Active) - (Size=953.9 GB) - (Type=07 NTFS)
==================== Ende von Addition.txt ======================= |