Yannick95 | 31.01.2016 20:30 | Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:27-01-2016
durchgeführt von Yannick (2016-01-29 17:13:19)
Gestartet von C:\Users\Yannick\Desktop
Windows 10 Home (X64) (2016-01-01 22:54:14)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-3391011429-186193620-3244763449-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-3391011429-186193620-3244763449-503 - Limited - Disabled)
Gast (S-1-5-21-3391011429-186193620-3244763449-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3391011429-186193620-3244763449-1005 - Limited - Enabled)
Yannick (S-1-5-21-3391011429-186193620-3244763449-1002 - Administrator - Enabled) => C:\Users\Yannick
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Panda Free Antivirus (Enabled - Up to date) {AAF74A68-8713-CDF1-004F-30003398BE9E}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Panda Free Antivirus (Enabled - Up to date) {1196AB8C-A129-C27F-3AFF-0B72481FF423}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Panda Firewall (Disabled) {92CCCB4D-CD7C-CCA9-2B10-9935CD4BF9E5}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Aftermath version 1.0 (HKLM-x32\...\{024D0ADC-6846-4B7A-B12F-D571DF826068}}_is1) (Version: 1.0 - Free Reign Entertainment)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios)
AION Free-to-Play (HKLM-x32\...\{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1) (Version: - Gameforge)
Amazon Music (HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Amazon Amazon Music) (Version: 4.0.0.1205 - Amazon Services LLC)
Andy OS (HKLM\...\Andy OS) (Version: 46.1.528.0 - Andy OS, Inc)
ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
ARK: Survival Evolved (HKLM-x32\...\Steam App 346110) (Version: - Studio Wildcard)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games)
BrowserProtect (HKLM-x32\...\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - ) <==== ACHTUNG
CCleaner (HKLM\...\CCleaner) (Version: 5.00 - Piriform)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - )
Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve)
Counter-Strike: Condition Zero (HKLM-x32\...\Steam App 80) (Version: - Valve)
Counter-Strike: Condition Zero Deleted Scenes (HKLM-x32\...\Steam App 100) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
Crossfire Europe (HKLM-x32\...\Crossfire Europe) (Version: 1.172 - SG Europe)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dead Space (HKLM-x32\...\{025A585C-0C66-413D-80D2-4C05CB699771}) (Version: 1.0.0.222 - Electronic Arts)
Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
Dropbox (HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Flixster (HKLM-x32\...\com.wb.DC2) (Version: 0.1.15 - Warner Bros. Entertainment Inc.)
Flixster (x32 Version: 0.1.15 - Warner Bros. Entertainment Inc.) Hidden
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalleri (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalleriet (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.50.1122 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1122 - DVDVideoSoft Ltd.)
Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Gameforge Live 2.0.7 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.7 - Gameforge)
Geeks3D FurMark 1.13.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
ICQ 8.0 (build 5996, für aktuellen Benutzer) (HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\ICQ) (Version: 8.0.5996.0 - Mail.Ru)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.20.1337 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
KeePass Password Safe 2.28 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.28 - Dominik Reichl)
League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.)
LoLSkinView (HKLM-x32\...\{875EAEE1-97A8-4A2A-9307-CF5EA171EA31}) (Version: 2.1.0.7 - MooreR Software)
LyricsMonkey-15 (HKLM-x32\...\LyricsMonkey-15) (Version: 1.28.153.5 - Showpass)
Mediathek (HKLM-x32\...\{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}) (Version: 1.4.0 - Medion)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.4 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.4 (x86 de)) (Version: 43.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.4.5848 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.8 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA Miracast Virtueller Ton 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 361.43 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4481.1005 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4481.1005 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4481.1005 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)
Panda Devices Agent (x32 Version: 1.03.06 - Panda Security) Hidden
Panda Devices Agent (x32 Version: 1.06.00 - Panda Security) Hidden
Panda Free Antivirus (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 16.01.00.0000 - Panda Security)
Panda Free Antivirus (Version: 8.20.00.0000 - Panda Security) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
QuickLaunch (HKLM-x32\...\{A802F1E3-34C8-4C84-9948-C1C4E37D0FA9}) (Version: 1.00.0019 - Lenovo Group Limited)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6710 - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Sennheiser 3D G4ME1 (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392DDDFB6}) (Version: 1.00.0001 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
Skype™ 7.4 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
SpeedSim (HKLM-x32\...\SpeedSim) (Version: 0.9.8.1b - )
Spotify (HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
SSD Tweaker version 3.5.2 (HKLM-x32\...\{83FA601A-241A-4956-8A21-F7D525C4422F}_is1) (Version: 3.5.2 - Elpamsoft.com)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
TERA (HKLM-x32\...\{A2S166A0-F031-4E27-A057-C69733219434}_is1) (Version: 19.04.02.03.hf3 - Gameforge Productions GmbH)
The Evil Within (HKLM-x32\...\Steam App 268050) (Version: - Tango Gameworks)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH)
USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - )
VMware Player (HKLM\...\{57AA4E8A-E2C9-4F1C-B3F1-762C36E34472}) (Version: 12.1.0 - VMware, Inc.)
VMware VIX (HKLM-x32\...\{F99FC179-EA67-4BBC-8955-BDDA0CB94B88}) (Version: 1.15.2.00000 - VMware, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Xerox WorkCentre 6015N_NI (HKLM-x32\...\InstallShield_{AF0A195E-2ECE-4B02-AC0E-B7B8B57F5E76}) (Version: 1.014.00 - Xerox)
Xerox WorkCentre 6015N_NI (x32 Version: 1.014.00 - Xerox) Hidden
Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Yannick\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Yannick\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Yannick\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Yannick\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3391011429-186193620-3244763449-500_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {00DE839A-D10B-4439-85D8-A2767DEF76E7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {0F454AC0-5760-4DD7-9394-ED7380B4A279} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {136E7DAF-358D-439D-9E20-A84118379607} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {142541F0-9211-49A0-835D-CBF9BFD0E11B} - \{5C06D2BE-375D-4C7D-8984-655483795A52} -> Keine Datei <==== ACHTUNG
Task: {3D380D3E-EFAB-45AD-BBF2-947A39883DB7} - \Software Updater -> Keine Datei <==== ACHTUNG
Task: {48B662FD-8217-4838-860F-1FAB3BFF5D6E} - \{D6D7D7CB-A8DB-4F05-831F-DDF3BA57513B} -> Keine Datei <==== ACHTUNG
Task: {4F1D20DA-D1BE-48D5-9F6C-A4B736361689} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {50D37279-C4D0-4FEB-A3D2-00EF46F30112} - \{19B60141-CCFA-4941-A5F7-28E699DD4F70} -> Keine Datei <==== ACHTUNG
Task: {566EC659-B42D-4B27-9B3D-89BDFFCEDDBE} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {613C6E22-37CA-4A43-B476-AB625DEE67C9} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {757A3FA9-3F9F-4BB5-9BAB-CC87DCDCD1F3} - \EPUpdater -> Keine Datei <==== ACHTUNG
Task: {759EA1CE-DB9C-4F8B-B8CF-FED7D0A5E2CA} - \{B83B40C0-D424-429B-B533-6413572AB56E} -> Keine Datei <==== ACHTUNG
Task: {77ECA296-2D02-4F76-96A5-CAAB5F109E39} - \User_Feed_Synchronization-{5F2F4A0A-634D-451C-A862-DD2863870B25} -> Keine Datei <==== ACHTUNG
Task: {85B5B092-F096-4535-9AF9-747BC7A0D9D8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-14] (Microsoft Corporation)
Task: {94134650-2B66-4C61-BEC8-4ADA052E265C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {A20B2CAE-96B0-4388-B8C9-A8AC43E1FEAA} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {A375DEBA-7ECB-4B21-99C2-CC50BD4A04B6} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG
Task: {B2B6FCDF-0514-4635-A8ED-DC1EE78AC2C2} - \Run LSI -> Keine Datei <==== ACHTUNG
Task: {B4E6230E-8727-4F96-971A-AC968409F575} - \Software Updater Ui -> Keine Datei <==== ACHTUNG
Task: {C7DD0E17-8D34-47F8-9568-E58097F9F917} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG
Task: {CE031ACD-13A2-443E-941E-626547AA2C00} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {E2C2836D-6033-4398-A83D-96F05B77527B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {EB918DC6-E5FC-46EE-995B-2DF7BEC7D033} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {F68A1E7B-54DD-4907-B4B7-7EC2B6D7FB9C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {F8A121BF-21AE-430D-AC4A-911BB64F7B4E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-19] (Adobe Systems Incorporated)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\{D6D7D7CB-A8DB-4F05-831F-DDF3BA57513B}.job => D:\Program Files (x86)\JobLauncher.exe
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2016-01-02 15:30 - 2015-07-15 03:04 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2016-01-01 23:32 - 2015-08-07 01:24 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-03-09 14:34 - 2012-03-09 14:34 - 00022528 _____ () C:\WINDOWS\System32\xrhk2alm.dll
2013-11-22 18:45 - 2012-03-15 14:48 - 15028224 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\xrhk2aRC.DLL
2016-01-02 15:29 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2013-10-12 02:15 - 2013-03-19 18:05 - 01558032 _____ () C:\ProgramData\gaupdt\service\0\gaupsvc.exe
2015-12-26 14:25 - 2015-12-09 02:52 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2012-01-03 10:04 - 2012-01-03 10:04 - 00095744 _____ () D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
2016-01-02 15:29 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-02 15:29 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-04-15 21:13 - 2015-04-15 21:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-02 15:28 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 11:59 - 2015-07-10 11:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2016-01-02 15:29 - 2015-11-25 05:20 - 06569472 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-02 15:29 - 2015-11-25 05:17 - 00471040 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-02 15:29 - 2015-11-25 05:17 - 01808384 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-02 15:29 - 2015-09-17 06:43 - 02274816 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 12:00 - 2015-07-10 17:45 - 00210432 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2014-11-13 10:38 - 2013-05-28 17:56 - 00151552 _____ () C:\Windows\System\3DG4me.exe
2014-09-18 08:23 - 2014-09-18 08:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-10-14 19:51 - 2014-10-14 19:51 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-09-18 08:23 - 2014-09-18 08:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-10-14 19:51 - 2014-10-14 19:51 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-11-22 23:36 - 2015-12-15 01:43 - 05890368 _____ () C:\Users\Yannick\AppData\Local\Amazon Music\Amazon Music Helper.exe
2016-01-10 20:23 - 2016-01-06 17:40 - 00974536 _____ () C:\Program Files\Andy\HandyAndy.exe
2014-11-22 01:03 - 2014-11-22 01:03 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2012-01-03 10:04 - 2012-01-03 10:04 - 00247296 _____ () D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe
2012-01-03 10:04 - 2012-01-03 10:04 - 00227840 _____ () D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe
2012-01-03 10:05 - 2012-01-03 10:05 - 04476928 _____ () D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe
2013-10-12 02:15 - 2013-02-22 09:08 - 00454656 _____ () C:\ProgramData\gaupdt\service\0\archive.dll
2013-10-12 02:15 - 2012-08-01 16:42 - 00156160 _____ () C:\ProgramData\gaupdt\service\0\libzmq.dll
2015-12-15 18:17 - 2015-12-15 18:17 - 00618544 _____ () D:\Program Files (x86)\SQLite3.dll
2015-12-26 14:25 - 2015-12-09 02:53 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2014-11-13 10:38 - 2012-06-06 10:56 - 00143360 _____ () C:\Windows\System\3DG4me.dll
2015-12-26 14:11 - 2015-11-10 20:55 - 00778752 _____ () D:\Program Files (x86)\Steam\SDL2.dll
2015-12-26 14:11 - 2015-07-03 17:12 - 04962816 _____ () D:\Program Files (x86)\Steam\v8.dll
2015-12-26 14:11 - 2015-12-14 21:01 - 02547280 _____ () D:\Program Files (x86)\Steam\video.dll
2015-12-26 14:11 - 2015-07-03 17:12 - 01187840 _____ () D:\Program Files (x86)\Steam\icuuc.dll
2015-12-26 14:11 - 2015-07-03 17:12 - 01556992 _____ () D:\Program Files (x86)\Steam\icui18n.dll
2015-12-26 14:11 - 2015-09-24 01:33 - 02549248 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll
2015-12-26 14:11 - 2015-09-24 01:33 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll
2015-12-26 14:11 - 2015-09-24 01:33 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll
2015-12-26 14:11 - 2015-09-24 01:33 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll
2015-12-26 14:11 - 2015-09-24 01:33 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll
2015-12-26 14:11 - 2015-12-14 21:01 - 00804432 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-12-26 14:11 - 2015-11-03 23:00 - 00201728 _____ () D:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-12-26 14:11 - 2015-11-17 01:31 - 47846176 _____ () D:\Program Files (x86)\Steam\bin\libcef.dll
2012-11-27 11:46 - 2012-11-16 03:32 - 01199648 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Yannick\Pictures\Neues Wallpaper\1.jpg
HKU\S-1-5-21-3391011429-186193620-3244763449-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\StartupApproved\Run: => "icq"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{2BC9AC5C-1D3E-4241-830D-F9837DF1265E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Age2HD\AoK HD.exe
FirewallRules: [{5C6DB745-A923-4B6B-B791-F0C6BBAE809B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9D4184BE-8D84-4D32-AC5B-FD344E9C2CBC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2CFE9A82-BD58-498D-94DC-42E2A0D97AEC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{3D0849A4-EF56-456C-B0C5-CF78884E1341}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{1F1CB72C-080B-49B5-B16A-29BE3896D5D1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{4995DD9F-4EA2-41C8-A87A-A1693951B582}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{102CB0B9-F5E8-4DA0-9496-5DDF2F7D5F0A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{3D34637F-93AD-41FB-872C-4F654747E3B2}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{A40D9534-6B52-4A1F-8928-D396F793BA42}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{DDF76FE6-81A4-47F0-8363-5B3CEDFD4C18}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9BBCFCF6-46C4-4A20-95D0-D452B85C9F07}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5847A416-0206-411B-B689-711712DF49C1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7BA13275-CE89-45B2-B7DE-51AB2C043A05}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{ACBDA20C-E0CD-4B0D-AA56-35BC0A53AC67}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{794053C4-62E4-4664-B810-6B1B7438C832}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [UDP Query User{C8E84F69-B513-46B8-B8A7-CF35AF9BC9AB}D:\program files\warcraft iii\war3.exe] => (Block) D:\program files\warcraft iii\war3.exe
FirewallRules: [TCP Query User{9D8C3C09-6A08-47C1-9D2A-B91963B18564}D:\program files\warcraft iii\war3.exe] => (Block) D:\program files\warcraft iii\war3.exe
FirewallRules: [UDP Query User{3709FC88-21F7-40B2-A89C-A2407A57CB53}D:\program files\warcraft 3 tft\war3.exe] => (Block) D:\program files\warcraft 3 tft\war3.exe
FirewallRules: [TCP Query User{3DCD431B-011C-4DAF-8BE2-67D8AD8AB774}D:\program files\warcraft 3 tft\war3.exe] => (Block) D:\program files\warcraft 3 tft\war3.exe
FirewallRules: [{6B0B9D69-0E2B-4D90-9ECB-A3584A61B5F0}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{4700A9BE-3E3F-4690-9C21-515D16F5F8AF}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{0A2BF57D-132E-4979-9EAB-CCA091201ED6}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGameServer.exe
FirewallRules: [{33F604F3-6734-419C-9DD5-93F061884E4D}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGameServer.exe
FirewallRules: [{6EBEAF27-C947-485F-B970-EC6828DC1DCE}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{1E8CB62D-E4D5-44A2-9A87-E65510B622B9}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{BC2CDB09-8BAB-4A6A-A18C-32ECC2755E7A}] => (Allow) D:\Program Files (x86)\GameforgeLive\gfl_client.exe
FirewallRules: [UDP Query User{B640B982-A0A0-48D6-9FAA-2482936CF144}C:\program files (x86)\moorer software\lolskinview\lolskinview.exe] => (Allow) C:\program files (x86)\moorer software\lolskinview\lolskinview.exe
FirewallRules: [TCP Query User{59850461-A5EB-42B8-82F2-E6FAD4B658F6}C:\program files (x86)\moorer software\lolskinview\lolskinview.exe] => (Allow) C:\program files (x86)\moorer software\lolskinview\lolskinview.exe
FirewallRules: [UDP Query User{D2E53298-B340-4EC4-99F2-2B3C8A90D3CD}D:\program files (x86)\aftermath\amlauncher.exe.new.exe] => (Allow) D:\program files (x86)\aftermath\amlauncher.exe.new.exe
FirewallRules: [TCP Query User{E4A9A9B1-1D4D-46B9-B137-B8081F100419}D:\program files (x86)\aftermath\amlauncher.exe.new.exe] => (Allow) D:\program files (x86)\aftermath\amlauncher.exe.new.exe
FirewallRules: [{58CBBE01-EEBA-46FF-905A-791361D4D4BB}] => (Allow) D:\Program Files (x86)\Aftermath\Aftermath.exe
FirewallRules: [UDP Query User{7331BE84-BF58-43C9-BC53-A3D041985FA9}D:\program files (x86)\aftermath\amlauncher.exe] => (Allow) D:\program files (x86)\aftermath\amlauncher.exe
FirewallRules: [TCP Query User{8AAE3135-FA78-4416-AE67-4C3C7B44BC8C}D:\program files (x86)\aftermath\amlauncher.exe] => (Allow) D:\program files (x86)\aftermath\amlauncher.exe
FirewallRules: [UDP Query User{F325CD6B-FACF-43F2-AABD-863FEF93F65E}D:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe] => (Allow) D:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{09A5585C-1B94-4A76-A5FC-0A27FA3BF6D4}D:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe] => (Allow) D:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{02E79A43-D84F-4575-A9CB-0AEC1D0A8845}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{B1D5C3F9-CAAE-4C20-B199-42EF50003FC1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EAD814CA-F48B-40B5-BF49-46F6542EE110}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4FB2AE6A-B611-4D3C-941D-2A9F49DE0E6D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{25F1767E-271B-4FAD-BA39-E56BE679889E}D:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe] => (Allow) D:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe
FirewallRules: [TCP Query User{0FAF8291-D655-4EFF-B1E0-4788D86ECC2A}D:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe] => (Allow) D:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe
FirewallRules: [{5992381E-6F71-476E-8423-FEED9F48C541}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe
FirewallRules: [{DBF98B37-9383-41CB-B313-C4237D1FB73E}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe
FirewallRules: [{C6AE51A1-F952-4330-8371-E715441DE7E4}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{DC3441D9-3A08-42EC-B8B0-77CA4F933ED5}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{BE0F52E9-FCA8-44E4-BD32-73420F57BA13}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{503A2FCB-DC9C-46F5-B22F-F7BFBEA958D0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{4032E0F1-B6D1-4794-936E-E23A89BDFCB2}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\TheEvilWithin\EvilWithin.exe
FirewallRules: [{62AABBF0-F9EE-4E28-9C95-4DC63E1483BF}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\TheEvilWithin\EvilWithin.exe
FirewallRules: [{9296BD5E-C49F-4038-8F40-ECC2824217E0}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{CF2F25FA-0DC8-4E1C-8D19-872FDA6C205C}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{EC22A999-21B5-463E-B404-B9A1D5DBF7F7}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{483AFEE9-E24E-4D20-9885-8DA34935E136}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CE74383C-7255-4406-8817-786C663FAE17}] => (Allow) D:\Program Files (x86)\Origin Games\Dead Space\Dead Space.exe
FirewallRules: [{BC587060-FA5C-4522-80D1-F89074271728}] => (Allow) D:\Program Files (x86)\Origin Games\Dead Space\Dead Space.exe
FirewallRules: [{CD1F6CAF-ABEB-4D81-85F6-D7BAE2D92F28}] => (Allow) D:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{96034A45-A7EF-4A4B-A98D-986E83E911C7}] => (Allow) D:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{EB0D2D02-D990-4B2E-A3FF-0C8A876B2BEB}] => (Allow) D:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{D0B3CCA4-797F-4AFB-8B67-D9D140A73189}] => (Allow) D:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{D9C5F331-8A93-4A1A-91CE-CB0CE41FF236}] => (Allow) D:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{1A937E19-5BB8-43DC-802C-DF8F739F72C7}] => (Allow) D:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{A1472765-9CCB-4238-843D-1735BFBC4E2A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{E4B2C475-9DD6-473B-94F5-515B3C51576B}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{D4A8286D-C4BB-4136-A4D8-16700CE36773}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{EB6103E7-4F29-47B4-BBA7-FE15D34A1795}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{A47D49AB-9096-4B95-A5D8-B473E2B10705}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{2FF7D7F1-F6A5-48BB-9CB2-63D71167DC43}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{3F065157-0262-4EE8-B2AE-ACF6A18E4E8A}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{5CD6AACA-9E38-42D6-A724-366947888050}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{9F1C6057-7646-437E-92D1-678547887E34}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{239C9805-C1D0-4B10-B9A4-D195105E4B9D}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [UDP Query User{F11C3ED4-3509-47F7-8698-C7983D4678C3}D:\program files (x86)\steam\steam.exe] => (Allow) D:\program files (x86)\steam\steam.exe
FirewallRules: [TCP Query User{9C443645-88CE-4604-92E6-79AD3CA85AC1}D:\program files (x86)\steam\steam.exe] => (Allow) D:\program files (x86)\steam\steam.exe
FirewallRules: [UDP Query User{7DFC864B-B773-4CD1-A3D4-7D1F84E02606}D:\program files (x86)\tera\tera-launcher.exe] => (Allow) D:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [TCP Query User{CFDD9031-DB8B-41D2-B5EE-6432669FA8DF}D:\program files (x86)\tera\tera-launcher.exe] => (Allow) D:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [{A717DB53-233B-40DD-8847-5EE18B6B07B0}] => (Allow) D:\Program Files (x86)\InitEngine.exe
FirewallRules: [{E24CB3E0-3022-4B64-93D3-9601CCC47BCD}] => (Allow) D:\Program Files (x86)\InitEngine.exe
FirewallRules: [{D135C8AD-9952-4003-8B40-1629EF5CE5C1}] => (Allow) D:\Program Files (x86)\AutoPatcher.exe
FirewallRules: [{AEF871AC-5791-4B9B-91F6-1416BD232AAF}] => (Allow) D:\Program Files (x86)\AutoPatcher.exe
FirewallRules: [{4924EE32-2FDB-479B-8A59-90E6343CCCB6}] => (Allow) D:\Program Files (x86)\Anno5.exe
FirewallRules: [{AD5AD1E6-A161-45A7-804B-25BFE21A8448}] => (Allow) D:\Program Files (x86)\Anno5.exe
FirewallRules: [{27E3B9C1-4C70-489F-9EE8-C46E26E9715A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{F7218085-98A7-483D-8F82-31BF21913E71}] => (Allow) LPort=2869
FirewallRules: [{48236E57-1BA0-420C-8D42-002FD75F0D3C}] => (Allow) LPort=1900
FirewallRules: [{75F702FC-3B3A-4205-B04C-257AC9A33510}] => (Allow) C:\Users\Yannick\AppData\Roaming\ICQM\icq.exe
FirewallRules: [{CE2C0457-8278-45CC-B5E9-77047B556563}] => (Allow) C:\Users\Yannick\AppData\Roaming\ICQM\icq.exe
FirewallRules: [TCP Query User{0BDD6573-05D3-4EC8-90D9-700980C0DB17}C:\users\yannick\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\yannick\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{DA860A6F-BF48-456F-BB74-9C2912EB9CAD}C:\users\yannick\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\yannick\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{21ECF702-5F8E-4E05-9721-65BBE0C11B8E}D:\program files (x86)\tera\tera-launcher.exe] => (Allow) D:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [UDP Query User{B4CF6EC6-05A3-4C74-B9E8-CDC017C75A6D}D:\program files (x86)\tera\tera-launcher.exe] => (Allow) D:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [{EC8014EB-9C84-43E9-8D17-FF1F7A683316}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{F2D69005-F893-4424-A56E-65EB92842F9F}] => (Allow) C:\Program Files (x86)\Tunngle\TnglCtrl.exe
FirewallRules: [{A7AA81D0-2819-4FF3-8070-D8CC1938C0D8}] => (Allow) C:\Program Files (x86)\Tunngle\TnglCtrl.exe
FirewallRules: [{86549713-A20C-47CF-A7C2-24DC70D6F5F4}] => (Allow) C:\Program Files (x86)\Tunngle\Tunngle.exe
FirewallRules: [{4B22B60D-F2E0-4360-9CBB-E9F120A01FDE}] => (Allow) C:\Program Files (x86)\Tunngle\Tunngle.exe
FirewallRules: [{92B88D33-05D1-426A-9B26-89E08487DA52}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{4F64DD16-7415-40B0-BF85-D3CF04009665}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{499D0DC2-D28F-4258-88D4-EE6C5C7769D4}C:\users\yannick\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\yannick\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E68E418B-615F-4BA5-B17C-D517B440FBC9}C:\users\yannick\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\yannick\appdata\roaming\spotify\spotify.exe
FirewallRules: [{798EEABB-33EF-41E8-A703-5F72154D1844}] => (Allow) LPort=2099
FirewallRules: [{B44923ED-F71B-43DD-942A-A10F936F3129}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{2210A644-7C16-4AEF-A57E-E734B3DDAEAE}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{40B87D24-ECB3-4A60-9676-738D02162AA7}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{4C706D4F-279B-4175-B894-668E6BDA17F9}] => (Allow) D:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{E07C79FB-2651-4C78-B295-6BB86CC50B1E}] => (Allow) C:\Users\Yannick\AppData\Local\Temp\Andy_46.2_x64\Setup.exe
FirewallRules: [{4F3FDFB2-A529-41B1-B75A-D24CD7FD7CCF}] => (Allow) C:\Users\Yannick\AppData\Local\Temp\Andy_46.2_x64\Setup.exe
FirewallRules: [{0E8A42F5-2EF7-4329-9631-9EC64852A5F3}] => (Allow) C:\Program Files\Andy\andy.exe
FirewallRules: [{C5073EA5-9DC9-43D9-80C2-6DE5C89CEB23}] => (Allow) C:\Program Files\Andy\andy.exe
FirewallRules: [{70F71DDF-0126-416E-8CC6-E74C8BD1E419}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
FirewallRules: [{6E7497A4-E197-4EEA-89D6-38A5B9B905FF}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
FirewallRules: [{7F8A5FA5-B7CB-41C1-A4A8-489774B2BDA8}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
FirewallRules: [{30B14B5F-D02E-4375-BB33-9663D883D555}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
FirewallRules: [{6EBE5D9F-481A-47C3-88C7-1B794F93FBE6}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
FirewallRules: [{BBC6B7DB-782D-4D93-A38D-A87F5860215B}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (01/29/2016 04:40:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Yannick-PC)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge“ ist folgender Fehler aufgetreten: -2144927149. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (01/29/2016 12:03:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Name des fehlerhaften Moduls: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003429d
ID des fehlerhaften Prozesses: 0x3860
Startzeit der fehlerhaften Anwendung: 0xLoLLauncher.exe0
Pfad der fehlerhaften Anwendung: LoLLauncher.exe1
Pfad des fehlerhaften Moduls: LoLLauncher.exe2
Berichtskennung: LoLLauncher.exe3
Vollständiger Name des fehlerhaften Pakets: LoLLauncher.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LoLLauncher.exe5
Error: (01/28/2016 10:11:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Name des fehlerhaften Moduls: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003429d
ID des fehlerhaften Prozesses: 0x8bc
Startzeit der fehlerhaften Anwendung: 0xLoLLauncher.exe0
Pfad der fehlerhaften Anwendung: LoLLauncher.exe1
Pfad des fehlerhaften Moduls: LoLLauncher.exe2
Berichtskennung: LoLLauncher.exe3
Vollständiger Name des fehlerhaften Pakets: LoLLauncher.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LoLLauncher.exe5
Error: (01/28/2016 10:09:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Name des fehlerhaften Moduls: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003429d
ID des fehlerhaften Prozesses: 0x1a08
Startzeit der fehlerhaften Anwendung: 0xLoLLauncher.exe0
Pfad der fehlerhaften Anwendung: LoLLauncher.exe1
Pfad des fehlerhaften Moduls: LoLLauncher.exe2
Berichtskennung: LoLLauncher.exe3
Vollständiger Name des fehlerhaften Pakets: LoLLauncher.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LoLLauncher.exe5
Error: (01/28/2016 10:08:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Name des fehlerhaften Moduls: LoLLauncher.exe, Version: 3.1.0.118, Zeitstempel: 0x56a6c5f8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003429d
ID des fehlerhaften Prozesses: 0x1610
Startzeit der fehlerhaften Anwendung: 0xLoLLauncher.exe0
Pfad der fehlerhaften Anwendung: LoLLauncher.exe1
Pfad des fehlerhaften Moduls: LoLLauncher.exe2
Berichtskennung: LoLLauncher.exe3
Vollständiger Name des fehlerhaften Pakets: LoLLauncher.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LoLLauncher.exe5
Error: (01/28/2016 09:42:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm SMCLpav.exe, Version 2.0.4.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1da0
Startzeit: 01d15a0c40c35fef
Beendigungszeit: 2
Anwendungspfad: C:\SMCLpav\SMCLpav.exe
Berichts-ID: a9240ce3-c5ff-11e5-bf16-eca86b299fcf
Vollständiger Name des fehlerhaften Pakets:
Auf das fehlerhafte Paket bezogene Anwendungs-ID:
Error: (01/28/2016 09:40:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: YANNICK-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (01/28/2016 09:40:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "NdkApi,type="win32",version="1.0.0.1"1".
Die abhängige Assemblierung "NdkApi,type="win32",version="1.0.0.1"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/28/2016 09:30:36 PM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (8316) Es konnte keine neue Protokolldatei erstellt werden, weil die Datenbank nicht auf das Protokolllaufwerk schreiben kann. Das Laufwerk ist möglicherweise schreibgeschützt, falsch konfiguriert, beschädigt oder hat zu wenig freien Speicherplatz. Fehler -1032.
Error: (01/28/2016 09:30:36 PM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (8316) Der Versuch, die Datei "C:\WINDOWS\system32\edbtmp.log" zu erstellen, ist mit Systemfehler 5 (0x00000005): "Zugriff verweigert " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Erstellen von Dateien.
Systemfehler:
=============
Error: (01/29/2016 04:50:00 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:49:59 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:49:59 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:58 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:53 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:46 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:40 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:30 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:24 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (01/29/2016 04:40:23 PM) (Source: DCOM) (EventID: 10016) (User: YANNICK-PC)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}Yannick-PCYannickS-1-5-21-3391011429-186193620-3244763449-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
CodeIntegrity:
===================================
Date: 2016-01-28 21:48:27.687
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-28 21:48:27.676
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-28 21:48:27.665
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-28 21:48:27.649
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-28 21:48:27.638
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-23 14:19:19.227
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-23 14:19:19.166
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-23 14:19:19.157
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-23 14:19:19.150
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-01-23 14:19:19.141
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 19%
Installierter physikalischer RAM: 16337.23 MB
Verfügbarer physikalischer RAM: 13091.93 MB
Summe virtueller Speicher: 17377.23 MB
Verfügbarer virtueller Speicher: 13382.92 MB
==================== Laufwerke ================================
Drive c: (Boot) (Fixed) (Total:57.13 GB) (Free:0.49 GB) NTFS
Drive d: (Data) (Fixed) (Total:1803.01 GB) (Free:1507.42 GB) NTFS
Drive f: (Recover) (Fixed) (Total:60 GB) (Free:43.43 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 59.6 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 2047D4ED)
Partition 1: (Not Active) - (Size=1803 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS)
==================== Ende von Addition.txt ============================ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
durchgeführt von Yannick (Administrator) auf YANNICK-PC (29-01-2016 17:12:51)
Gestartet von C:\Users\Yannick\Desktop
Geladene Profile: Yannick & Administrator (Verfügbare Profile: Yannick & Administrator)
Platform: Windows 10 Home (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\ProgramData\gaupdt\service\0\gaupsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Panda Security, S.L.) D:\Program Files (x86)\PSANHost.exe
(Panda Security, S.L.) D:\Program Files (x86)\PSUAService.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Windows\System\3DG4me.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Spotify Ltd) C:\Users\Yannick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
() C:\Users\Yannick\AppData\Local\Amazon Music\Amazon Music Helper.exe
(fabi.me) C:\Users\Yannick\Documents\SpeedAutoClicker\SpeedAutoClicker.exe
() C:\Program Files\Andy\HandyAndy.exe
(Valve Corporation) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Xerox) D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmw.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe
(Panda Security, S.L.) D:\Program Files (x86)\PSUAMain.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Windows\System\3DG4me.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmw.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe
() D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe
(Panda Security, S.L.) D:\Program Files (x86)\PSUAMain.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Panda Security, S.L.) D:\Program Files (x86)\PSUAMain.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
HKLM\...\Run: [3DG4me] => C:\WINDOWS\System\3DG4me.exe [151552 2013-05-28] ()
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => D:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKLM-x32\...\Run: [Launcher6015N] => D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2571264 2011-05-19] (Xerox)
HKLM-x32\...\Run: [6015N RUN] => D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [355840 2012-01-03] ()
HKLM-x32\...\Run: [StatusAutoRun6015N] => D:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [4476928 2012-01-03] ()
HKLM-x32\...\Run: [PSUAMain] => D:\Program Files (x86)\PSUAMain.exe [99064 2015-12-07] (Panda Security, S.L.)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [icq] => C:\Users\Yannick\AppData\Roaming\ICQM\icq.exe [26934632 2013-02-12] (ICQ)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [Spotify Web Helper] => C:\Users\Yannick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-25] (Spotify Ltd)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [Amazon Music] => C:\Users\Yannick\AppData\Local\Amazon Music\Amazon Music Helper.exe [5890368 2015-12-15] ()
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Run: [Speed AutoClicker] => C:\Users\Yannick\Documents\SpeedAutoClicker\SpeedAutoClicker.exe [179200 2015-04-01] (fabi.me)
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\RunOnce: [Uninstall C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2016-01-02] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2016-01-02] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2016-01-02] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => Keine Datei
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2016-01-02] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2016-01-02] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Yannick\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2016-01-02] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HandyAndy.lnk [2016-01-10]
ShortcutTarget: HandyAndy.lnk -> C:\Program Files\Andy\HandyAndy.exe ()
CHR HKU\S-1-5-21-3391011429-186193620-3244763449-1002\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\..\Interfaces\{103633a8-4a03-442a-81ed-15a3f1c3e540}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com?fr=hp-avast&type=avastbcl
HKU\S-1-5-21-3391011429-186193620-3244763449-1002\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=121562&tt=gc_&babsrc=HP_ss&mntrId=E665ECA86B299FCF
HKU\S-1-5-21-3391011429-186193620-3244763449-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com
HKU\S-1-5-21-3391011429-186193620-3244763449-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.enhanced-search.com/?q={searchTerms}&affID=121562&tt=gc_&babsrc=SP_ss_mib2&mntrId=E665ECA86B299FCF
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1391629333&from=amt&uid=C400-MTFDDAC064MAM_000000001239091D2392&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=kwd&qsrc=2869
SearchScopes: HKU\S-1-5-21-3391011429-186193620-3244763449-1002 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Kein Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> Keine Datei
BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2014-11-20] (DVDVideoSoft Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2014-11-22] (DVDVideoSoft Ltd.)
Toolbar: HKLM-x32 - Kein Name - {82E1477C-B154-48D3-9891-33D83C26BCD3} - Keine Datei
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - Keine Datei
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default
FF DefaultSearchUrl: hxxps://de.search.yahoo.com/yhs/search
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Homepage: about:home
FF Session Restore: -> ist aktiviert.
FF Keyword.URL: hxxps://de.search.yahoo.com/yhs/search
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-19] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-19] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-11-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-11-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-3391011429-186193620-3244763449-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei]
FF SearchPlugin: C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default\searchplugins\icq.xml [2013-02-12]
FF SearchPlugin: C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default\searchplugins\yahoo-avast.xml [2014-06-18]
FF Extension: 360 Web Shield - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default\Extensions\webshield@360safe.com [2014-08-30] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-19]
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [lightningnewtab@gmail.com] - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\uf0q2oem.default\extensions\lightningnewtab@gmail.com.xpi => nicht gefunden
FF HKU\S-1-5-21-3391011429-186193620-3244763449-1002\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff => nicht gefunden |