![]() |
Hotspot shield malware und chrome.exe Siehe mein vor einigen Tagen gerade abgeschlossenes Thema. 2 Dinge sind passiert: ich habe Hotel wieder installiert und dann entfernt. Malwarebytes ist im Hintergrund weiter gelaufen und hat irgendwann ein pop up geöffnet, das Chrome.exe ein Trojaner ist. Daraufhin habe ich einen scan mit Malwarebytes durchgeführt. Dabei wurde keine Schadsoftware gefunden. Ich habe dann der Reihe nach Frst, Malwarebytes, Adwcleaner und roguekiller laufen lassen. Dabei wurde nur Hotspot Shield malware gefunden, keine Meldung bezüglich chrome Im folgenden die Log-Dateien: Code: Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11-07-2022 Code: Malwarebytes |
Fortsetzung (Addition u. rogue) Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 11-07-2022 durchgeführt von wrt (14-07-2022 16:21:41) Gestartet von C:\Users\wrt\Downloads Microsoft Windows 10 Pro Version 21H2 19044.1766 (X64) (2021-03-09 10:24:05) Start-Modus: Normal ========================================================== ==================== Konten: ============================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) Administrator (S-1-5-21-779246859-3990032973-3551585165-500 - Administrator - Enabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-779246859-3990032973-3551585165-503 - Limited - Disabled) drrei (S-1-5-21-779246859-3990032973-3551585165-1004 - Limited - Disabled) Gast (S-1-5-21-779246859-3990032973-3551585165-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-779246859-3990032973-3551585165-504 - Limited - Disabled) wrt (S-1-5-21-779246859-3990032973-3551585165-1001 - Administrator - Enabled) => C:\Users\wrt ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 4K Video Downloader 4.4 (HKLM-x32\...\{D04F9BA2-CF6F-41AD-8BD1-313ABD28FAF2}) (Version: 4.4.4.2275 - Open Media LLC) ABBYY FineReader 11 (HKLM-x32\...\{F11000FE-0010-0000-0000-074957833700}) (Version: 11.11.194 - ABBYY Production LLC) Acronis True Image (HKLM-x32\...\{E8C3CECC-4A39-489A-AE2A-28160E194BD9}) (Version: 22.7.15560 - Acronis) Hidden Acronis True Image (HKLM-x32\...\{E8C3CECC-4A39-489A-AE2A-28160E194BD9}Visible) (Version: 22.7.15560 - Acronis) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 22.001.20142 - Adobe Systems Incorporated) Adobe Audition 3.0 (HKLM-x32\...\Adobe Audition 3.0) (Version: 3.0 - Adobe Systems Incorporated) Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-001824458876}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden Amazon Kindle (HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\Amazon Kindle) (Version: 1.37.0.65274 - Amazon) AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.13.27.501 - Advanced Micro Devices, Inc.) AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden AMD I2C Driver (HKLM-x32\...\{B31D92D9-2914-46B0-9738-F668A563DE73}) (Version: 1.2.0.117 - Advanced Micro Devices, Inc.) Hidden AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.82 - Advanced Micro Devices, Inc.) Hidden AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.13.0.0 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 6.0.0.9 - Advanced Micro Devices, Inc.) Hidden AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 21.3.1 - Advanced Micro Devices, Inc.) AMD_Chipset_Drivers (HKLM-x32\...\{40c19864-e557-4855-95ee-075689dfcf8e}) (Version: 2.13.27.501 - Advanced Micro Devices, Inc.) Hidden ANT Drivers Installer x64 (HKLM\...\{1BC0225E-AF99-4434-92CC-615111CE698F}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden ApowerMirror Version 1.4.1.9 (HKLM-x32\...\{a9482532-9c34-478c-80c3-85bdccbb981f}_is1) (Version: 1.4.1.9 - APOWERSOFT LIMITED) Apple Software Update (HKLM-x32\...\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}) (Version: 2.1.1.116 - Apple Inc.) AquaSoft DiaShow 7 Ultimate (HKLM-x32\...\{2FAA2415-618E-4EC0-8253-3CDA076C84D6}) (Version: 7.8.01 - AquaSoft) Hidden AquaSoft DiaShow 7 Ultimate (HKLM-x32\...\AquaSoft DiaShow 7 Ultimate) (Version: 7.8.01 - AquaSoft) Audacity 3.0.2 (HKLM-x32\...\Audacity_is1) (Version: 3.0.2 - Audacity Team) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bonjour-Druckdienste (HKLM\...\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.) BrainWave Generator (HKLM-x32\...\BrainWave Generator) (Version: - ) Branding64 (HKLM\...\{856DA29A-EA4A-468B-BBC2-B5F60DD75BFE}) (Version: 1.00.0002 - Advanced Micro Devices, Inc.) Hidden calibre (HKLM-x32\...\{85703FD4-26A1-436A-85DA-A2612DE45C60}) (Version: 5.43.0 - Kovid Goyal) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.) Canon G3010 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_G3010_series) (Version: 1.01 - Canon Inc.) Canon G3010 series On-Screen-Handbuch (HKLM-x32\...\Canon G3010 series On-Screen-Handbuch) (Version: 1.2.0 - Canon Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.5.3 - Canon Inc.) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.) Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.05.1.51 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.) Canon Kurzwahlprogramm (HKLM-x32\...\Speed Dial Utility) (Version: - ) Canon MP Navigator EX 4.1 (HKLM-x32\...\MP Navigator EX 4.1) (Version: - ) Canon MX420 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX420_series) (Version: - Canon Inc.) Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.4 - Canon Inc.) Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.) Canon Wi-Fi Connection Assistant (HKLM-x32\...\Wi-Fi Connection Assistant) (Version: 1.20.0 - Canon Inc.) CherryTree Version 0.39.4 (HKLM-x32\...\{DBA7384C-E1C6-44B5-A3B4-C94F2F0B8C0C}_is1) (Version: 0.39.4 - Giuseppe Penone) Chessmaster Grandmaster Edition (HKLM-x32\...\InstallShield_{27614800-84A9-484E-9CCB-43ED2F1205F5}) (Version: 1.00.0000 - Ubisoft) CPUID CPU-Z 1.89 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.89 - CPUID, Inc.) CUEcards 2000 (HKLM-x32\...\CUEcards 2000) (Version: - Marcus Humann Software-Technik) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden DocFetcher (HKLM-x32\...\DocFetcher) (Version: 1.1.25 - ) DocFetcher Pro Demo (HKLM\...\DocFetcher Pro Demo) (Version: 1.15 - ) Dr. Hardware 2019 19.0.1 (HKLM-x32\...\Dr. Hardware 2019_is1) (Version: - Peter A. Gebhard) Dr. Robert Anthony's Intention Activator (HKLM-x32\...\{1C35ABA7-6507-4CB9-91E7-6311B105A526}) (Version: 2.00 - ) Dragon NaturallySpeaking 13 (HKLM-x32\...\{33EA20FB-5389-4938-BA59-2BCD9BB68F41}) (Version: 13.00.000 - Nuance Communications Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 152.4.4880 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.583.1 - Dropbox, Inc.) Hidden eBook Converter Bundle 3.22.10306.440 (HKLM-x32\...\{74173236-3507-49A7-A0FC-1BDABF0A9338}_is1) (Version: 3.22.10306.440 - eBook Converter Team) Effective File Search 6.8.1 (HKLM-x32\...\Effective File Search) (Version: 6.8.1 - SOW) Elevated Installer (HKLM-x32\...\{C3D3E0B3-6B8D-4AF4-B49A-3583E512ECE8}) (Version: 7.5.0.0 - Garmin Ltd or its subsidiaries) Hidden Enchanter X 2.0 (HKLM-x32\...\Enchanter_X_2.0) (Version: - ) EncoreBasic (HKLM-x32\...\{4C0C787B-EF87-4A5F-B4CC-A022BC97A2FC}) (Version: 2.4 - Ihr Firmenname) Epubor Ultimate (HKLM-x32\...\Epubor Ultimate) (Version: 3.0.14.402 - Epubor Inc.) Everything 1.4.1.1005 (x86) (HKLM-x32\...\Everything) (Version: 1.4.1.1005 - voidtools) Everything 1.4.1.935 (x64) (HKLM\...\Everything) (Version: 1.4.1.935 - David Carpenter) EZCast (HKLM-x32\...\{74CECDD9-4B8E-4AE3-9571-8070A17F3C34}) (Version: 2.8.0.145 - Actions-Micro) FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version: - ) FinePrint (HKLM\...\FinePrint) (Version: 10.40 - FinePrint Software, LLC) Fotogalerie (HKLM-x32\...\{41BF4A3B-D60A-4E92-883F-C88C8C157261}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Foxit Phantom (HKLM-x32\...\Foxit Phantom) (Version: 2.0.0.0424 - Foxit Software Company) Free Download Manager (HKLM\...\{43781dff-e0df-49ce-a6d2-47da96a485e7}}_is1) (Version: 5.1.38.7312 - FreeDownloadManager.ORG) Free Download Manager 3.9.7 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) fx-ES PLUS Emulator Subscription for fx-991ES PLUS C 2nd edition (HKLM-x32\...\{12CC30ED-A07C-46D4-8075-C5660DE67856}) (Version: 5.00.0000 - CASIO COMPUTER CO., LTD.) Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{034F279C-D74E-42F2-8CEC-216E91969B29}) (Version: 7.5.0.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (HKLM-x32\...\{afe06296-a3d5-48cf-88a2-77629aeb124b}) (Version: 7.5.0.0 - Garmin Ltd or its subsidiaries) Gnaural ver. 1.0.20080808 (HKLM-x32\...\Gnaural_is1) (Version: - Bret Logan) Gnaural2 ver. 0.1.20080229 (HKLM-x32\...\Gnaural2_is1) (Version: - Bret Logan) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 103.0.5060.114 - Google LLC) Google Earth Pro (HKLM\...\{DE181B35-ACEF-4DB0-86D9-731D5767ABB1}) (Version: 7.3.4.8642 - Google) I-Doser Premium (HKLM-x32\...\I-Doser) (Version: 5.1 - I-Doser.com) ifap praxisCENTER® (HKLM-x32\...\{0B59E9CB-DA5B-4CDE-88E8-3F7C269DE130}_is1) (Version: 3.34.0.122 - ifap GmbH) Inkscape 0.92.3 (HKLM-x32\...\Inkscape) (Version: 0.92.3 - Inkscape Project) IrfanView 4.50 (64-bit) (HKLM\...\IrfanView64) (Version: 4.50 - Irfan Skiljan) Java 8 Update 333 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180333F0}) (Version: 8.0.3330.2 - Oracle Corporation) KeePass Password Safe 2.38 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.38 - Dominik Reichl) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) LibreOffice 7.3 Help Pack (German) (HKLM\...\{D3A8CE42-862A-491E-B149-AC475F815D60}) (Version: 7.3.2.2 - The Document Foundation) LibreOffice 7.3.2.2 (HKLM\...\{001D6695-F9B8-4CBD-AA92-FE8A58638060}) (Version: 7.3.2.2 - The Document Foundation) MadAppLauncher version 1.10.0.0 (HKLM-x32\...\{73F59F3E-E753-4D3D-B123-B497B74A549A}_is1) (Version: 1.10.0.0 - Roberto Concepcion) Malwarebytes version 4.5.10.200 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.10.200 - Malwarebytes) MaxLauncher version 1.20.1.0 (HKLM\...\{D887E7A5-7906-4A0B-9E16-791BD8F2FD2F}_is1) (Version: 1.20.1.0 - Roberto Concepcion) MD Medicus vOffice (HKLM-x32\...\vOffice 2.3.0) (Version: 2.3.0 - MD Medicus) Med7 (HKLM-x32\...\{36427C11-0CC8-4AF9-A5F8-DC9FD5BE3D97}) (Version: 8.40.0004 - Bitron GmbH) Microsoft 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.15330.20230 - Microsoft Corporation) Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.15330.20230 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 103.0.1264.49 - Microsoft Corporation) Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 103.0.1264.49 - Microsoft Corporation) Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.131.0619.0001 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29913 (HKLM-x32\...\{855e31d2-9031-46e1-b06d-c9d7777deefb}) (Version: 14.28.29913.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29913 (HKLM-x32\...\{03d1453c-7d5c-479c-afea-8482f406e036}) (Version: 14.28.29913.0 - Microsoft Corporation) Microsoft Visual C++ 2019 X64 Additional Runtime - 14.28.29913 (HKLM\...\{620A7633-7A09-42A8-8580-076A4483C4B0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.28.29913 (HKLM\...\{EECDD137-13DA-46ED-ADA0-BDF7F8BE65B8}) (Version: 14.28.29913 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29913 (HKLM-x32\...\{572DCD10-CF2E-43D1-8151-8BD9AC9086D0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29913 (HKLM-x32\...\{6236EBBD-F50F-40B3-B819-8DB0C608308C}) (Version: 14.28.29913 - Microsoft Corporation) Hidden MindMaster (HKLM-x32\...\{D5A2C78C-5D8F-40D2-A130-7696D4F22953}) (Version: 2.2.9 - MindMaster) Mini Manifestor 4-2 (HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\Mini Manifestor 4-2) (Version: - ) Movie Maker (HKLM-x32\...\{70C91B91-61E8-4D06-86D6-A9DCC291983A}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 68.12.0.7577 - Mozilla) Mozilla Thunderbird 68.12.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 68.12.1 (x86 de)) (Version: 68.12.1 - Mozilla) MSVCRT (HKLM-x32\...\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}) (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (HKLM-x32\...\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}) (Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (HKLM\...\{E9FA781F-3E80-4399-825A-AD3E11C28C77}) (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.9 - F.J. Wechselberger) Nero ControlCenter (HKLM-x32\...\{ABC88553-8770-4B97-B43E-5A90647A5B63}) (Version: 11.4.3033 - Nero AG) Hidden Nero Core Components (HKLM-x32\...\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}) (Version: 11.8.1063 - Nero AG) Hidden Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 21.0.3001 - Nero AG) Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 21.0.1014 - Nero AG) Hidden Nero WaveEditor (HKLM-x32\...\{C2B4762F-2F35-4CB0-A413-1B3C0C1D9ACE}) (Version: 21.0.1002 - Nero AG) Hidden Nero WaveEditor (HKLM-x32\...\{D261A45C-CC66-419A-8D50-1FB933468DCB}) (Version: 21.0.00100 - Nero AG) Neuro-Programmer 3.3.1 (HKLM-x32\...\Neuro-Programmer 3_is1) (Version: - Transparent Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15330.20230 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15330.20230 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.15128.20178 - Microsoft Corporation) Hidden Onis 2.3 Free Edition (HKLM-x32\...\{185514C4-3F4C-499A-A9DD-5E280450BE8D}) (Version: 2.3.0 - Digitalcore) Opera Stable 88.0.4412.74 (HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\Opera 88.0.4412.74) (Version: 88.0.4412.74 - Opera Software) OSCAR (HKLM\...\{FC6F08E6-69BF-4469-ADE3-78199288D305}_is1) (Version: 1.4.0-Win64-e35d47b3 - The OSCAR Team) Photo Common (HKLM-x32\...\{87DABDEA-47A4-4182-AA7C-2C90DAAE3117}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photo Gallery (HKLM-x32\...\{07AAB66E-4718-422D-9218-4AFB3C922A71}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7917 - Realtek Semiconductor Corp.) Remote Desktop assistant (HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\4ffdbc81071cec8e) (Version: 1.0.0.103 - Remote Desktop assistant) Rife Generator 3.4 (HKLM-x32\...\{9D334442-BC5A-4654-952E-518C74B4852C}_is1) (Version: - Timo Esser) Samsung AllShare (HKLM-x32\...\{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Hidden Samsung AllShare (HKLM-x32\...\InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Skype Version 8.81 (HKLM-x32\...\Skype_is1) (Version: 8.81 - Skype Technologies S.A.) SpO2 Assistant V3.0.5 (HKLM-x32\...\SpO2 Assistant V3.0.5_is1) (Version: - ) Stellarium 0.13.0 (HKLM-x32\...\Stellarium_is1) (Version: 0.13.0 - Stellarium team) synedra View Personal (HKLM-x32\...\synedraViewPersonal) (Version: - ) TAP-Windows 9.24.2 (HKLM\...\TAP-Windows) (Version: 9.24.2 - OpenVPN Technologies, Inc.) ThaiTrainer111-V4 (HKLM-x32\...\ThaiTrainer111-V4_is1) (Version: - © 1998-2008 by WANTANA Software) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 10.50 beta 8 - Ghisler Software GmbH) TreePad X Enterprise 384 Gb (single-user) 7.12 (HKLM-x32\...\TreePadXEnterprise_384Gb) (Version: - ) TreeSize Free V4.4.2 (HKLM-x32\...\TreeSize Free_is1) (Version: 4.4.2 - JAM Software) TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation) Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.9.0 - Tweaking.com) Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation) UpdateAssistant (HKLM\...\{567756E0-361F-4E88-AF74-8B0E4628E5BC}) (Version: 1.12.0.0 - Microsoft Corporation) Hidden VLC media player (HKLM\...\VLC media player) (Version: 3.0.3 - VideoLAN) vOffice (HKLM-x32\...\{D21BBB39-EA60-4ADB-84A6-5C0F72CDA1CE}) (Version: 2.3.0 - MD Medicus) Hidden Windows Live Communications Platform (HKLM-x32\...\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\{66233218-CA57-4AB2-BA43-A97AA4635960}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Installer (HKLM-x32\...\{659CB81C-B54E-4DF1-B618-F35777393A54}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Photo Common (HKLM-x32\...\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live PIMT Platform (HKLM-x32\...\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE (HKLM-x32\...\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (HKLM-x32\...\{D1893000-EA77-493C-8DDD-E262436E959B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform (HKLM-x32\...\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (HKLM-x32\...\{FC071B45-4A5F-408F-92F8-4D9D693E866F}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer (HKLM-x32\...\{04BE4035-3C8E-4B48-BFB8-1655849C0C8B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer (HKLM-x32\...\{714E162E-CD4F-4F1B-8302-7F5179409C25}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer (HKLM-x32\...\{955E4722-1480-4198-A144-65FA5F4446DA}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer Resources (HKLM-x32\...\{A951D5DA-4759-4C3B-9C36-C6BF30082A2F}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - ) Windows-PC-Integritätsprüfung (HKLM\...\{AD47C6B2-6C72-4F0E-B66F-7685C28ACDFD}) (Version: 3.3.2110.22002 - Microsoft Corporation) Windows-PC-Integritätsprüfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation) Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows-Treiberpaket - Silicon Laboratories (silabenm) Ports (03/19/2014 6.7.0.0) (HKLM\...\B97004A400E30DCF940971EFA7A0C13C6B0A4B66) (Version: 03/19/2014 6.7.0.0 - Silicon Laboratories) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Windows-Treiberpaket - STMicroelectronics (usbser) Ports (08/02/2013 1.4.0) (HKLM\...\04B4996F06620A7ECFBFE8F9BCC458F9761E39F7) (Version: 08/02/2013 1.4.0 - STMicroelectronics) XMedia Recode 64bit Version 3.5.5.8 (HKLM\...\{D31E6E69-4C6A-42CC-926F-CC7B186864EB}_is1) (Version: 3.5.5.8 - XMedia Recode 64bit) Zoom (HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\ZoomUMX) (Version: 5.4.1 (58698.1027) - Zoom Video Communications, Inc.) Packages: ========= Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2022-04-15] (Canon Inc.) Clockmaker: Match Three in Row -> C:\Program Files\WindowsApps\SamfinacoLimited.ClockmakerMatchThreeinRow_66.0.2.0_x86__aj0b1qrpyg0w6 [2022-07-07] (Samfinaco Limited) Hypnosis Wheel -> C:\Program Files\WindowsApps\43852Rob.Kachmar.HypnosisWheel_1.0.0.1_neutral__a29k398mwv6a8 [2022-04-15] (Rob.Kachmar) Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x64__8wekyb3d8bbwe [2022-04-15] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x86__8wekyb3d8bbwe [2022-04-15] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2022-04-15] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2022-04-15] (Microsoft Corporation) [MS Ad] Microsoft Remote Desktop -> C:\Program Files\WindowsApps\Microsoft.RemoteDesktop_10.2.1817.0_x64__8wekyb3d8bbwe [2022-04-15] (Microsoft Corporation) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.13.7040.0_x64__8wekyb3d8bbwe [2022-07-08] (Microsoft Studios) [MS Ad] Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.74.51921.0_x64__8wekyb3d8bbwe [2022-07-13] (Microsoft Corporation) [Startup Task] Movie Maker & Video Editor : Slideshow Maker -> C:\Program Files\WindowsApps\3631PhotoVideoZone.MovieMakerVideoEditorSlideshowM_1.1.13.0_x64__vfc75da8vjzxg [2022-04-15] (Photo Video Zone) [MS Ad] Pinball Deluxe Reloaded 3D -> C:\Program Files\WindowsApps\18880GatesKingsGroupHoldi.PinballDeluxeReloaded3D_6.6.6.0_x64__mgran42w2k48p [2022-04-15] (Gates Kings Group Holdings) PowerPom - Pomodoro Timer -> C:\Program Files\WindowsApps\25994ProdDev.PowerPom-PomodoroTimer_1.1.6.0_x64__w3j63e9zf5dsr [2022-06-01] (Productive Team) RECOIL -> C:\Program Files\WindowsApps\9998PiotrFusik.RECOIL_6.2.0.0_x64__5dbjqw3zx3tpw [2022-07-14] (Piotr Fusik) Scatter Slots -> C:\Program Files\WindowsApps\Fishsticksserviceslimited.ScatterSlots_4.27.0.0_x64__bcx82fedc2d04 [2022-07-03] (Murka Games Limited) Sudoku - Pro -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.Sudoku-Pro_3.1.19.0_x64__kx24dqmazqk8j [2022-07-04] (Random Salad Games LLC) Super Craft Mario Run -> C:\Program Files\WindowsApps\62585RoyalKingGamesStudio.SuperCraftMarioRun_10.5.2.0_x86__b66x5gv52tdk6 [2022-04-15] (Royal King Games Studio) [MS Ad] VLC -> C:\Program Files\WindowsApps\VideoLAN.VLC_3.2.1.0_x64__paz6r1rewnh0a [2022-06-01] (VideoLAN) Wi-Fi Transfer -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.Wi-FiTransfer_2.0.26.0_x64__3c1yjt4zspk6g [2022-06-01] (Samsung Electronics Co. Ltd.) Word Finder Scrabble -> C:\Program Files\WindowsApps\15985Yasindewid.WordFinderScrabble_4.1.2.0_x64__39dp1177718dj [2022-04-15] (Yasin dewid) Wordplay: Exercise your brain -> C:\Program Files\WindowsApps\828B5831.WordplayExerciseyourbrain_1.12.1400.0_x64__ytsefhwckbdv6 [2022-04-15] (G5 Entertainment AB) Words Scrabble & Friends -> C:\Program Files\WindowsApps\54753DragonKingsGamesFree.WordsScrabbleFriends_13.2.0.0_x64__nj2hqgcefq0de [2022-04-15] (Dragon Kings Games Free Inc.) [MS Ad] ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-779246859-3990032973-3551585165-1001_Classes\CLSID\{A2B78634-DD87-2E5F-D25B-10D9E13A0B1F}\InprocServer32 -> C:\WINDOWS\system32\ole32.dll (Microsoft Windows -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-779246859-3990032973-3551585165-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\wrt\Dropbox [2020-01-29 19:54] ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-12-22] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-12-22] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-12-22] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-12-22] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [FineReader11ContextMenu] -> {79E48320-C6B5-49F1-992B-571D53586885} => C:\Program Files (x86)\ABBYY FineReader 11\FRIntegration.x64.dll [2013-06-28] (ABBYY PRODUCTION LLC -> ABBYY Production LLC) ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-31] (F.J. Wechselberger) [Datei ist nicht signiert] ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => C:\Program Files (x86)\VMware\VMware Workstation\vmdkShellExt.dll [2022-02-18] (VMware, Inc. -> VMware, Inc.) ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2022-02-18] (VMware, Inc. -> VMware, Inc.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-07-01] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.131.0619.0001\FileSyncShell64.dll [2022-07-14] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll [2021-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll [2022-01-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers6: [FineReader11ContextMenu] -> {79E48320-C6B5-49F1-992B-571D53586885} => C:\Program Files (x86)\ABBYY FineReader 11\FRIntegration.x64.dll [2013-06-28] (ABBYY PRODUCTION LLC -> ABBYY Production LLC) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-07-01] (Malwarebytes Inc. -> Malwarebytes) ==================== Codecs (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Drivers32: [msacm.pspgru] => C:\Windows\SysWOW64\pspgru.acm [401920 2010-03-22] (Philips Austria GmbH - Speech Processing) [Datei ist nicht signiert] ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\wrt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Google Drive.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=aghbiahbpaijignceidepookljebhfak ShortcutWithArgument: C:\Users\wrt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Drive.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=aghbiahbpaijignceidepookljebhfak ShortcutWithArgument: C:\Users\wrt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\6ba478f6faf86bd4\ZenMate VPN - Top Internet Security & Unblock.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=fdcgdnkidjaadafnichfpabhfomcebme ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============= 2017-12-22 06:45 - 2017-12-22 06:45 - 000277538 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\LIBMAGIC.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 012242432 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\avcodec-57.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 001825792 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\avfilter-6.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 002158592 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\avformat-57.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 000485376 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\avutil-55.dll 2020-03-10 11:20 - 2017-04-13 11:46 - 069740544 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\libcef.dll 2020-03-09 18:53 - 2018-05-15 06:32 - 000015360 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\libegl.dll 2020-03-09 18:53 - 2018-05-15 06:32 - 002521088 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\libglesv2.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 000138752 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\swresample-2.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 000662016 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\swscale-4.dll 2020-03-09 18:52 - 2019-01-30 21:58 - 000048640 _____ () [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\winunivappfeatures.dll 2018-12-26 11:37 - 2012-06-14 17:18 - 000359936 _____ (CANON INC.) [Datei ist nicht signiert] C:\WINDOWS\System32\CNMN6PPM.DLL 2020-03-09 18:52 - 2019-01-30 21:59 - 000436224 _____ (FreeDownloadManager.org) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\common.dll 2020-03-09 18:52 - 2019-01-30 21:59 - 000110080 _____ (FreeDownloadManager.org) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\mediahelper.dll 2020-03-09 18:52 - 2019-01-30 21:59 - 000676864 _____ (FreeDownloadManager.org) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\wba.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 001712640 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\LIBEAY32.dll 2020-03-10 11:20 - 2017-04-13 11:42 - 000351744 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\SSLEAY32.dll 2020-03-10 11:20 - 2018-05-15 06:39 - 000049152 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\bearer\qgenericbearer.dll 2020-03-10 11:20 - 2018-05-15 06:38 - 000032768 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qgif.dll 2020-03-10 11:20 - 2018-05-15 06:48 - 000041984 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qicns.dll 2020-03-10 11:20 - 2018-05-15 06:38 - 000033280 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qico.dll 2020-03-10 11:20 - 2018-05-15 06:39 - 000331264 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qjpeg.dll 2020-03-10 11:20 - 2018-05-15 06:48 - 000025600 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qtga.dll 2020-03-10 11:20 - 2018-05-15 06:48 - 000371712 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qtiff.dll 2020-03-10 11:20 - 2018-05-15 06:48 - 000024064 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qwbmp.dll 2020-03-10 11:20 - 2018-05-15 06:48 - 000478720 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\imageformats\qwebp.dll 2020-03-10 11:20 - 2018-05-15 06:40 - 001439744 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\platforms\qwindows.dll 2020-03-10 11:20 - 2019-01-30 22:01 - 005938176 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\Qt5Core.dll 2020-03-10 11:20 - 2018-05-15 06:35 - 006345216 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\Qt5Gui.dll 2020-03-10 11:20 - 2018-05-15 06:35 - 001256960 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\Qt5Network.dll 2020-03-10 11:20 - 2018-05-15 06:33 - 000207360 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\Qt5Sql.dll 2020-03-10 11:20 - 2018-05-15 06:38 - 005515264 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\Qt5Widgets.dll 2020-03-10 11:20 - 2018-05-15 06:39 - 001121280 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\sqldrivers\qsqlite.dll 2020-03-10 11:20 - 2018-05-15 06:39 - 000136192 _____ (The Qt Company Ltd.) [Datei ist nicht signiert] C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\styles\qwindowsvistastyle.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [510] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ================= ==================== Internet Explorer (Nicht auf der Ausnahmeliste) ========== BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.) BHO: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\x64\dgnriaie_x64.dll [2014-11-04] (Nuance Communications, Inc. -> Nuance Communications, Inc.) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.) BHO-x32: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\dgnriaie.dll [2014-11-04] (Nuance Communications, Inc. -> Nuance Communications, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_333\bin\ssv.dll [2022-06-07] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2018-11-14] (FreeDownloadManager.ORG) [Datei ist nicht signiert] BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_333\bin\jp2ssv.dll [2022-06-07] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.) Toolbar: HKU\S-1-5-21-779246859-3990032973-3551585165-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts Inhalt: ========================= (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2015-07-10 18:04 - 2022-07-05 07:19 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost 2019-05-05 21:06 - 2021-10-23 23:42 - 000000436 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics ==================== Andere Bereiche =========================== (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\VMware\VMware Workstation\bin\;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\Win dowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files (x86)\Common Files\Acronis\VirtualFile\;C:\Program Files (x86)\Common Files\Acronis\VirtualFile64\;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Calibre2\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\synedra\ViewPersonal HKU\S-1-5-21-779246859-3990032973-3551585165-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\wrt\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\irfanview_wallpaper.png HKU\S-1-5-21-779246859-3990032973-3551585165-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) ist aktiviert. Network Binding: ============= VMware Network Adapter VMnet8: VMware Bridge Protocol -> vmware_bridge (disabled) LAN-Verbindung: VMware Bridge Protocol -> vmware_bridge (enabled) Ethernet: VMware Bridge Protocol -> vmware_bridge (enabled) WLAN: VMware Bridge Protocol -> vmware_bridge (enabled) VMware Network Adapter VMnet1: VMware Bridge Protocol -> vmware_bridge (disabled) ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) HKLM\...\StartupApproved\StartupFolder: => "MaxLauncher.lnk" HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service" HKLM\...\StartupApproved\Run32: => "KeePass 2 PreLoad" HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe" HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor" HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX" HKLM\...\StartupApproved\Run32: => "ISUSPM" HKLM\...\StartupApproved\Run32: => "DNS7reminder" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX2" HKLM\...\StartupApproved\Run32: => "AllShareAgent" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "MadAppLauncher.lnk" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "ZenMate.bat" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "MindMasterV2.exe" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "IntentionActivator.exe - Verknüpfung.lnk" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\StartupFolder: => "Dragon NaturallySpeaking.lnk" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\Run: => "ISUSPM" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\Run: => "Skype for Desktop" HKU\S-1-5-21-779246859-3990032973-3551585165-1001\...\StartupApproved\Run: => "GarminExpress" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{4B454696-C4A8-426A-AE41-FFBB52CA5B7F}] => (Allow) LPort=51001 FirewallRules: [TCP Query User{BE634D55-0B89-49EE-8105-AB14088D0979}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [UDP Query User{679AD103-ED3E-4FA5-B96A-17BDC770EA45}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{BD6BDF2A-5A62-49D0-8629-155EC78034A7}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{4EF86B53-E7D7-47F6-8EF6-7D0B8EF1D524}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{B4F94747-CD34-4F0C-A863-ABF7A4689A07}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{1A65D6B3-A20E-4965-B455-01F6278BE010}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{346C51B0-7890-4688-91D5-A3097A8AC329}C:\program files (x86)\acronis\trueimagehome\trueimage.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\trueimage.exe (Acronis International GmbH -> ) FirewallRules: [UDP Query User{70BEE53B-0D88-4B8E-AE9C-FEF021FF8545}C:\program files (x86)\acronis\trueimagehome\trueimage.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\trueimage.exe (Acronis International GmbH -> ) FirewallRules: [{1587EF67-D3D7-474E-8009-A42327BC3DAF}] => (Block) C:\program files (x86)\acronis\trueimagehome\trueimage.exe (Acronis International GmbH -> ) FirewallRules: [{E2C5380C-242D-4332-A864-D22EB490921D}] => (Block) C:\program files (x86)\acronis\trueimagehome\trueimage.exe (Acronis International GmbH -> ) FirewallRules: [{8978EF4D-A8FE-49D2-A7CD-8C3E8D82A33F}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.49\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{37C8354A-8414-407E-893F-206937510AA8}C:\program files (x86)\acronis\trueimagehome\ga_service.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\ga_service.exe (Acronis International GmbH -> ) FirewallRules: [UDP Query User{672940D8-3184-47ED-97DE-EF6653B35B6F}C:\program files (x86)\acronis\trueimagehome\ga_service.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\ga_service.exe (Acronis International GmbH -> ) FirewallRules: [{02AD545C-5C8B-4614-9EC4-F25858C9F7D8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{0C1FA531-2B05-49FF-AB51-632A32F4CE36}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{6A71C120-B1E6-4778-9740-670CD033FC07}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{BAC7DEBB-E468-4F09-BEE8-B8B12BAD4F50}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) ==================== Wiederherstellungspunkte ========================= 13-07-2022 17:49:13 Geplanter Prüfpunkt ==================== Fehlerhafte Geräte im Gerätemanager ============ ==================== Fehlereinträge in der Ereignisanzeige: ======================== Applikationsfehler: ================== Error: (07/14/2022 01:50:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NeroInfo.exe, Version: 21.0.3.1, Zeitstempel: 0x5fb1dbf9 Name des fehlerhaften Moduls: NeroInfo.exe, Version: 21.0.3.1, Zeitstempel: 0x5fb1dbf9 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00031fe3 ID des fehlerhaften Prozesses: 0x4794 Startzeit der fehlerhaften Anwendung: 0x01d8974dfb9cfee9 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe Berichtskennung: 1036b467-8848-4c00-9f2e-90196b49a49f Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/14/2022 01:49:51 PM) (Source: SamsungAllShareV2.0) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt. bei AllShareDmsUtil.Configuration.ConfigurationManager.GetSharingFolderList() bei AllShareDmsUtil.Manager.AllShareDmsManager.LoadSharingFolderList() bei AllShareDmsUtil.Manager.AllShareDmsManager.InitContentsDirectoryManager() bei AllShareDmsUtil.Manager.AllShareDmsManager.Initialize() bei AllShareDmsUtil.Manager.AllShareDmsManager..ctor() bei AllShareDmsUtil.Manager.AllShareDmsManager.get_Instance() bei AllShareDMS.AllShareDMS.DoStart() bei AllShareDMS.AllShareDMS.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (07/14/2022 01:49:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: NeroInfo.exe, Version: 21.0.3.1, Zeitstempel: 0x5fb1dbf9 Name des fehlerhaften Moduls: NeroInfo.exe, Version: 21.0.3.1, Zeitstempel: 0x5fb1dbf9 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00031fe3 ID des fehlerhaften Prozesses: 0x3720 Startzeit der fehlerhaften Anwendung: 0x01d8974da723b193 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe Berichtskennung: 21a4efda-6c96-474d-9f31-73b96f668b20 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/14/2022 01:30:09 PM) (Source: DNS logging) (EventID: 0) (User: ) Description: Event-ID 0 Error: (07/14/2022 01:30:08 PM) (Source: DNS logging) (EventID: 0) (User: ) Description: Event-ID 0 Error: (07/14/2022 01:30:08 PM) (Source: DNS logging) (EventID: 0) (User: ) Description: Event-ID 0 Error: (07/14/2022 01:30:08 PM) (Source: DNS logging) (EventID: 0) (User: ) Description: Event-ID 0 Error: (07/14/2022 01:30:08 PM) (Source: DNS logging) (EventID: 0) (User: ) Description: Event-ID 0 Systemfehler: ============= Error: (07/14/2022 04:19:52 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:48 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:45 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:41 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:37 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:33 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:29 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/14/2022 04:19:25 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Windows Defender: ================ Date: 2022-07-13 10:46:24 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {0140696D-02E4-4AEC-B9E1-1EF60BF0B189} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2022-07-01 06:34:27 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {F31327EA-7973-46EE-80BA-29EE323B8D42} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2022-06-30 06:39:21 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {CB7CADA5-D73C-4CBF-A77D-4B092E4B4436} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2022-06-29 07:04:38 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {19B1A66A-C64A-4261-ABDC-9268C2582C23} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2022-06-27 15:47:43 Description: C:\Windows\System32\RuntimeBroker.exe wurde durch den überwachten Ordnerzugriff daran gehindert, %userprofile%\Favorites zu ändern. Erkennungszeit: 2022-06-27T08:47:43.633Z Benutzer: RYZEN\wrt Pfad: %userprofile%\Favorites Prozessname: C:\Windows\System32\RuntimeBroker.exe Sicherheitsversion: 1.369.304.0 Modulversion: 1.1.19300.2 Produktversion: 4.18.2205.7 Event[0]: Date: 2022-07-09 12:20:17 Description: Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten. Neue Version der Sicherheitsinformationen: %Vorherige Version der Sicherheitsinformationen: 1.369.539.0 Update Source: Microsoft Center zum Schutz vor Schadsoftware Sicherheitstyp: AntiSpyware Updatetyp: Voll Benutzer: NT-AUTORITÄT\Netzwerkdienst Aktuelle Modulversion: %Vorherige Modulversion: 1.1.19300.2 Fehlercode: 0x80072ee7 Fehlerbeschreibung: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Date: 2022-07-09 12:20:17 Description: Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten. Neue Version der Sicherheitsinformationen: %Vorherige Version der Sicherheitsinformationen: 1.369.539.0 Update Source: Microsoft Center zum Schutz vor Schadsoftware Sicherheitstyp: AntiVirus Updatetyp: Voll Benutzer: NT-AUTORITÄT\Netzwerkdienst Aktuelle Modulversion: %Vorherige Modulversion: 1.1.19300.2 Fehlercode: 0x80072ee7 Fehlerbeschreibung: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. Date: 2022-07-09 12:19:49 Description: Bei Microsoft Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten. Neue Version der Sicherheitsinformationen: %Vorherige Version der Sicherheitsinformationen: 1.369.539.0 Update Source: Microsoft Update-Server Sicherheitstyp: AntiVirus Updatetyp: Voll Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %Vorherige Modulversion: 1.1.19300.2 Fehlercode: 0x8007045b Fehlerbeschreibung: Der Computer wird heruntergefahren. CodeIntegrity: =============== Date: 2022-07-14 16:13:42 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. ==================== Speicherinformationen =========================== BIOS: American Megatrends Inc. R01-A3 10/25/2017 Hauptplatine: Acer Aspire GX-281 Prozessor: AMD Ryzen 7 1700 Eight-Core Processor Prozentuale Nutzung des RAM: 36% Installierter physikalischer RAM: 16314.88 MB Verfügbarer physikalischer RAM: 10312.23 MB Summe virtueller Speicher: 18746.88 MB Verfügbarer virtueller Speicher: 10915.53 MB ==================== Laufwerke ================================ Drive c: (treesize) (Fixed) (Total:317.12 GB) (Free:95.6 GB) (Model: WDC WD10EZEX-21WN4A0) NTFS Drive d: (Volume) (Fixed) (Total:612.86 GB) (Free:50.66 GB) (Model: WDC WD10EZEX-21WN4A0) NTFS Drive f: (Seagate Backup Plus Drive) (Fixed) (Total:3726.02 GB) (Free:1059.5 GB) (Model: Seagate Backup+ Desk SCSI Disk Device) NTFS Drive g: () (Fixed) (Total:0 GB) (Free:0 GB) (Model: WD My Passport 25E1 USB Device) Drive h: (Backup Plus) (Fixed) (Total:3725.75 GB) (Free:1616.08 GB) (Model: Seagate BUP Portable SCSI Disk Device) exFAT Drive i: (System-reserviert) (Fixed) (Total:0.49 GB) (Free:0.39 GB) (Model: WDC WD10EZEX-21WN4A0) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive j: (USB HD rot) (Fixed) (Total:1862.86 GB) (Free:409.76 GB) (Model: WD My Passport 25E2 USB Device) NTFS Drive m: () (Fixed) (Total:0 GB) (Free:0 GB) (Model: WDC WD10EZEX-21WN4A0) Drive n: () (Fixed) (Total:0 GB) (Free:0 GB) (Model: WDC WD10EZEX-21WN4A0) \\?\Volume{2b434e5a-ef35-469b-96f5-adc30ba7be98}\ (EFI) (Fixed) (Total:0.19 GB) (Free:0.19 GB) FAT32 ==================== MBR & Partitionstabelle ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 90C151F2) Partition 1: (Not Active) - (Size=600 MB) - (Type=42) Partition 2: (Active) - (Size=500 MB) - (Type=42) Partition 3: (Not Active) - (Size=317.1 GB) - (Type=42) Partition 4: (Not Active) - (Size=613.3 GB) - (Type=42) ========================================================== Disk: 1 (Size: 1863 GB) (Disk ID: 16F2A91F) Partition: GPT. ========================================================== Disk: 2 (Protective MBR) (Size: 3726 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 3 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: C865BF2D) Partition: GPT. Attempted reading MBR returned 0 bytes. Could not read MBR for disk 4. ==================== Ende von Addition.txt ======================= Code: Program : RogueKiller Anti-Malware |
2.Fortsetzung RogueKiller Anti-Malware_debug.log Code: 2022/07/03 15:53:58:CRITICAL [SDKConfig] Unable to unserialize existing config (or empty), searching backup... |
debug log Teil 2 von 3 Code: 2022/07/03 15:59:33:INFO [CloudScanner::PreProcess] Processing detection (\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task)... |
Teil 3 Code: 2022/07/03 16:20:55:INFO [QuarantineEngine::PushFile] Adding file to quarantine (C:\Program Files (x86)\Hotspot Shield\bin\lang\gui-eng.dll / Adw.HotspotShield) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 18:49 Uhr. |
Copyright ©2000-2025, Trojaner-Board