Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 15.11.2016, 12:43   #1
Klaus_Mittel
 
Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk - Standard

Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk



Hier das (jetzt hoffentlich lesbare) FRST-Logfile:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2016
durchgeführt von X (Administrator) auf X-PC (15-11-2016 12:44:36)
Gestartet von C:\Users\X\Downloads
Geladene Profile: X (Verfügbare Profile: X)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Dropbox, Inc.) C:\Users\X\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 2.0\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 2.0\program\soffice.bin
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe


==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-06-15] (NVIDIA Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\Run: [Dropbox Update] => C:\Users\X\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-19] (Dropbox, Inc.)
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\MountPoints2: {f6631e24-558c-11e6-b4ac-d8cb8a731465} - E:\LG_PC_Programs.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2016-03-12] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2016-06-04]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Users\X\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-11-10]
ShortcutTarget: Dropbox.lnk -> C:\Users\X\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\X\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk [2010-12-30]
ShortcutTarget: OpenOffice.org 2.0.lnk -> C:\Program Files (x86)\OpenOffice.org 2.0\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{094D41E0-F3C1-4A18-84B8-F8606D692EE3}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{1332CAA2-6C1E-42E5-80D3-405D8A72D810}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://safesearch.avira.com/#web/result?source=art&q=
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Kein Name -> {0347C33E-8762-4905-BF09-768834316C61} -> Keine Datei
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-03-25] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-25] (Oracle Corporation)
BHO-x32: Kein Name -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> Keine Datei
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default [2016-11-15]
FF user.js: detected! => C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\user.js [2011-03-16]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\8fwb6c52.default -> Search
FF Keyword.URL: Mozilla\Firefox\Profiles\8fwb6c52.default -> hxxp://www.slaago.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=1STLI09F&q=
FF NetworkProxy: Mozilla\Firefox\Profiles\8fwb6c52.default -> socks_remote_dns", true
FF NetworkProxy: Mozilla\Firefox\Profiles\8fwb6c52.default -> type", 0
FF Extension: (Avira Browser Safety) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\abs@avira.com [2016-11-14]
FF Extension: (Firebug) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\firebug@software.joehewitt.com.xpi [2016-10-11]
FF Extension: (FoxyProxy Standard) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\foxyproxy@eric.h.jung [2016-09-01]
FF Extension: (RefControl) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [2016-04-27]
FF Extension: (Live HTTP headers) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2016-04-27]
FF Extension: (Tamper Data) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2016-04-27]
FF Extension: (Web Developer) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2016-08-19]
FF Extension: (Adblock Plus) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28]
FF Extension: (DownThemAll!) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29]
FF Extension: (User Agent Switcher) - C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2016-04-27]
FF SearchPlugin: C:\Users\X\AppData\Roaming\Mozilla\Firefox\Profiles\8fwb6c52.default\searchplugins\google-search.xml [2011-03-16]
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-10-20] [ist nicht signiert]
FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2016-10-20] [ist nicht signiert]
FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-10-20] [ist nicht signiert]
FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2016-10-20] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-06-11] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-09-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-09-16] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3145422843-1996295090-1453084995-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\X\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-03-11] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\nppdf32.dll [2013-09-26] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npqtplugin.dll [2013-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npqtplugin2.dll [2013-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npqtplugin3.dll [2013-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npqtplugin4.dll [2013-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npqtplugin5.dll [2013-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npstrlnk.dll [2010-07-20] ( )

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
S3 GalaxyClientService; C:\Program Files\GalaxyClient\GalaxyClientService.exe [284224 2016-10-28] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6581824 2016-10-28] (GOG.com)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [Datei ist nicht signiert]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [Datei ist nicht signiert]
R2 HPSLPSVC; C:\Users\X\AppData\Local\Temp\7zS23FF\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [Datei ist nicht signiert]
S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe [146888 2016-03-19] (Mozilla Foundation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [Datei ist nicht signiert]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-06-15] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-06-15] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2130440 2016-09-12] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2195984 2016-09-12] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [Datei ist nicht signiert]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56552 2016-03-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-06-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-14 19:27 - 2016-11-14 19:27 - 00000000 ____D C:\Users\X\AppData\LocalLow\Prologue Games
2016-11-14 14:14 - 2016-11-14 14:16 - 69796004 _____ C:\Users\X\Downloads\WayOfTheWickedBook7TalesOfTalingardePFRPGPDF.zip
2016-11-14 14:12 - 2016-11-14 14:13 - 57222280 _____ C:\Users\X\Downloads\WayOfTheWickedBook6TheWagesOfSinPFRPGPDF.zip
2016-11-14 14:09 - 2016-11-14 14:10 - 42997798 _____ C:\Users\X\Downloads\WayOfTheWickedBook5TheDevilMyOnlyMasterPFRPGPDF.zip
2016-11-14 14:08 - 2016-11-14 14:08 - 48175625 _____ C:\Users\X\Downloads\WayOfTheWickedBook4OfDragonsAndPrincessesPFRPGPDF.zip
2016-11-14 14:06 - 2016-11-14 14:07 - 38282616 _____ C:\Users\X\Downloads\WayOfTheWickedBook3TearsOfTheBlessedPFRPGPDF.zip
2016-11-12 16:32 - 2016-11-12 16:32 - 00001235 _____ C:\mbam-log-2016-11-12 (16.32).txt
2016-11-12 15:45 - 2016-11-12 16:39 - 00074422 _____ C:\Users\X\Downloads\Addition.txt
2016-11-12 15:43 - 2016-11-15 12:44 - 00018536 _____ C:\Users\X\Downloads\FRST.txt
2016-11-12 15:43 - 2016-11-15 12:44 - 00000000 ____D C:\FRST
2016-11-12 15:43 - 2016-11-12 15:43 - 02411520 _____ (Farbar) C:\Users\X\Downloads\FRST64.exe
2016-11-11 18:42 - 2016-11-12 17:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-11-11 18:33 - 2016-11-12 16:59 - 00000000 ____D C:\Users\X\Desktop\mbar
2016-11-11 18:13 - 2016-11-11 18:14 - 16563352 _____ (Malwarebytes Corp.) C:\Users\X\Downloads\mbar-1.09.3.1001.exe
2016-11-10 19:40 - 2016-11-10 19:40 - 00000000 ____D C:\Users\X\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-11-10 18:00 - 2016-11-10 18:00 - 00007561 _____ C:\Users\X\.recently-used.xbel
2016-11-09 19:32 - 2016-11-09 19:32 - 00332768 _____ C:\Users\X\Downloads\Werewolf the Forsaken Merits.pdf
2016-11-09 16:26 - 2016-11-09 16:47 - 00012023 _____ C:\Users\X\Documents\Etikett 2.odt
2016-11-07 12:29 - 2016-11-07 12:29 - 00680619 _____ C:\Users\X\Documents\KfB Einladung X 15.11.16.pdf
2016-11-05 20:33 - 2016-11-05 20:33 - 00055177 _____ C:\Users\X\Downloads\Randommagicitems-3rd.pdf
2016-11-05 18:36 - 2016-11-05 18:40 - 00013982 _____ C:\Users\X\Documents\Etikett.odt
2016-11-01 11:48 - 2016-11-01 11:48 - 00061992 _____ C:\Users\X\Downloads\Konto_75106278-Auszug_2016_010.PDF
2016-11-01 11:47 - 2016-11-01 11:48 - 00059223 _____ C:\Users\X\Downloads\Konto_75106765-Auszug_2016_010.PDF
2016-11-01 11:47 - 2016-11-01 11:47 - 00064963 _____ C:\Users\X\Downloads\Konto_74102302-Auszug_2016_010.PDF
2016-11-01 11:42 - 2016-11-01 11:42 - 02228626 _____ C:\Users\X\Documents\Amtsgericht HX 2016.pdf
2016-10-31 12:17 - 2016-10-31 12:17 - 00105878 _____ C:\Users\X\Documents\Absage Expertum.pdf
2016-10-29 18:15 - 2016-10-29 18:15 - 00000222 _____ C:\Users\X\Desktop\The Age of Decadence.url
2016-10-28 17:27 - 2016-10-28 17:39 - 00008931 _____ C:\Users\X\Documents\Echogeld.ods
2016-10-26 11:52 - 2016-10-26 11:59 - 00012670 _____ C:\Users\X\Documents\Außergewöhnliche Belastungen Reissmann 2016.ods
2016-10-23 13:43 - 2016-11-04 13:31 - 00011529 _____ C:\Users\X\Documents\Bewerbungstagebuch X.ods
2016-10-21 18:43 - 2016-10-21 22:29 - 00276146 _____ C:\Users\X\Downloads\Biohazard.chum
2016-10-20 22:53 - 2016-10-21 15:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-10-20 16:06 - 2016-10-20 16:52 - 00016294 _____ C:\Users\X\Documents\Fahrten 2015 HX.ods
2016-10-20 10:18 - 2016-10-20 10:18 - 01138551 _____ C:\Users\X\Documents\X Anmeldung Martinsmarkt.pdf
2016-10-19 11:29 - 2016-10-19 11:44 - 00013543 _____ C:\Users\X\Documents\X Haus der Seelen.odt
2016-10-18 17:50 - 2016-10-18 17:50 - 00123297 _____ C:\Users\X\Documents\Biohazard SR 4.pdf
2016-10-18 17:07 - 2016-10-21 11:48 - 00272618 _____ C:\Users\X\Downloads\Entwurf 4.chum
2016-10-18 16:39 - 2016-10-18 17:07 - 00256890 _____ C:\Users\X\Downloads\Entwurf 3.chum
2016-10-18 11:31 - 2016-10-18 11:31 - 00089859 _____ C:\Users\X\Downloads\17379917_Kontoauszug_20161006.pdf
2016-10-18 11:30 - 2016-11-14 02:05 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-18 11:29 - 2016-11-12 16:33 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-10-18 11:29 - 2016-10-18 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-10-18 11:29 - 2016-10-18 11:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-10-18 11:29 - 2016-10-18 11:29 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-10-18 11:29 - 2016-03-18 15:04 - 22851472 _____ (Malwarebytes ) C:\Users\X\Downloads\mbam-setup-2.2.1.1043.exe
2016-10-18 11:29 - 2016-03-10 13:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-10-18 11:29 - 2016-03-10 13:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-10-18 10:46 - 2016-10-18 10:46 - 00118521 _____ C:\Users\X\Documents\Biohazard.pdf
2016-10-18 10:43 - 2016-10-18 10:43 - 00243082 _____ C:\Users\X\Downloads\Entwurf 2.chum
2016-10-16 14:39 - 2016-10-16 14:41 - 37021101 _____ C:\Users\X\Downloads\PathfinderAdventurePath56RaidersOfTheFeverSeaSkullShackles2Of6PFRPGPDF-SingleFile.zip
2016-10-16 14:37 - 2016-10-16 14:38 - 39657194 _____ C:\Users\X\Downloads\WayOfTheWickedBook2CallForthDarknessPFRPGPDF.zip

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-15 12:41 - 2009-07-14 18:58 - 00710030 _____ C:\Windows\system32\perfh007.dat
2016-11-15 12:41 - 2009-07-14 18:58 - 00154466 _____ C:\Windows\system32\perfc007.dat
2016-11-15 12:41 - 2009-07-14 06:13 - 01650140 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-15 12:41 - 2009-07-14 05:45 - 00015120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-15 12:41 - 2009-07-14 05:45 - 00015120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-15 12:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-11-15 12:37 - 2016-03-19 11:19 - 00001232 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000UA.job
2016-11-15 12:36 - 2013-12-12 13:11 - 00000000 ____D C:\ProgramData\Package Cache
2016-11-15 12:36 - 2012-10-09 11:55 - 00000000 ____D C:\Program Files (x86)\Avira
2016-11-15 12:36 - 2011-01-03 14:13 - 00000000 ____D C:\ProgramData\Avira
2016-11-15 12:35 - 2014-12-15 18:57 - 00000000 ___RD C:\Users\X\Dropbox
2016-11-15 12:34 - 2010-12-30 00:04 - 00000000 ____D C:\Users\X\AppData\Roaming\OpenOffice.org2
2016-11-15 12:34 - 2010-12-17 19:03 - 00000000 ____D C:\ProgramData\NVIDIA
2016-11-15 12:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-15 12:33 - 2012-10-09 12:01 - 00000000 ____D C:\Users\X\AppData\Roaming\Avira
2016-11-15 02:43 - 2010-12-18 18:12 - 00000000 ____D C:\Program Files (x86)\Steam
2016-11-14 14:20 - 2016-09-19 11:30 - 00000000 ____D C:\Users\X\Documents\Way Of The Wicked
2016-11-14 13:42 - 2015-02-23 11:29 - 00000000 ____D C:\Users\X\Documents\Echo
2016-11-10 22:34 - 2015-02-19 12:46 - 00000000 ____D C:\Users\X\AppData\Roaming\TS3Client
2016-11-10 19:40 - 2013-10-02 13:31 - 00000000 ____D C:\Users\X\AppData\Roaming\Dropbox
2016-11-10 18:02 - 2015-03-26 19:23 - 00000000 ____D C:\Users\X\AppData\LocalLow\Obsidian Entertainment
2016-11-10 18:00 - 2016-03-10 19:14 - 00000000 ____D C:\Users\X
2016-11-10 18:00 - 2010-12-20 23:09 - 00000000 ____D C:\Users\X\AppData\Roaming\gtk-2.0
2016-11-10 18:00 - 2010-12-20 23:07 - 00000000 ____D C:\Users\X\.gimp-2.6
2016-11-10 17:30 - 2012-05-12 23:01 - 00051211 _____ C:\Users\X\Desktop\schnelle notizen.txt
2016-11-10 11:37 - 2016-03-19 11:19 - 00001180 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000Core.job
2016-11-10 11:32 - 2016-03-19 11:19 - 00004206 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000UA
2016-11-10 11:32 - 2016-03-19 11:19 - 00003810 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000Core
2016-11-10 11:27 - 2016-03-12 23:01 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-10 11:27 - 2016-03-12 23:01 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-10 11:27 - 2016-03-12 23:01 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-11-10 11:27 - 2016-03-12 23:01 - 00000000 ____D C:\Windows\system32\Macromed
2016-11-10 11:27 - 2014-08-15 09:49 - 00000000 ____D C:\Users\X\AppData\Local\Adobe
2016-11-09 11:11 - 2016-03-11 18:30 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-08 17:25 - 2011-02-02 20:28 - 00000000 ____D C:\Users\X\AppData\Roaming\Skype
2016-11-08 02:49 - 2015-02-23 11:30 - 00000000 ____D C:\Users\X\Documents\wtf campaign
2016-11-05 22:58 - 2016-03-11 18:30 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-11-05 22:57 - 2016-07-22 14:00 - 00000000 ____D C:\Users\X\Documents\War of the Burning Sky
2016-11-03 22:31 - 2016-03-11 18:42 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-11-03 19:09 - 2016-03-11 19:05 - 00000000 ____D C:\Users\X\AppData\Local\CrashDumps
2016-11-01 22:18 - 2012-05-18 22:53 - 00000128 _____ C:\Users\X\Downloads\verkleinerer.set
2016-10-30 16:20 - 2011-04-21 18:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-10-30 16:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-10-28 13:57 - 2016-06-03 21:09 - 00000000 ____D C:\Program Files\GalaxyClient
2016-10-24 12:13 - 2016-08-15 19:14 - 00000000 ____D C:\Program Files\Cloud Imperium Games
2016-10-22 14:10 - 2016-04-13 22:27 - 00000000 ____D C:\Users\X\Documents\ShareX
2016-10-19 09:50 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\TAPI
2016-10-18 17:50 - 2016-10-15 18:37 - 00000000 ____D C:\Users\X\Downloads\Chummer4
2016-10-18 17:31 - 2016-10-15 12:20 - 00012374 _____ C:\Users\X\Documents\Fahrten X 2015.ods
2016-10-18 16:48 - 2016-10-15 21:01 - 00241254 _____ C:\Users\X\Documents\Entwurf 1.chum
2016-10-16 16:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-10-16 14:42 - 2016-09-19 11:30 - 00000000 ____D C:\Users\X\Documents\Skull and Shackles
2016-10-16 13:40 - 2009-07-14 05:45 - 00316272 _____ C:\Windows\system32\FNTCACHE.DAT
2016-10-16 13:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-10-16 13:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism
2016-10-16 01:28 - 2016-05-29 12:13 - 00000000 ____D C:\Windows\system32\MRT
2016-10-16 01:23 - 2016-05-29 12:13 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-10-16 01:22 - 2016-06-06 19:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-16 01:22 - 2012-05-15 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-16 01:22 - 2012-05-15 20:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-04-24 17:32 - 2013-04-24 18:25 - 0000096 _____ () C:\Users\X\AppData\Roaming\Camdata.ini
2013-04-24 17:32 - 2013-04-24 18:25 - 0000408 _____ () C:\Users\X\AppData\Roaming\CamLayout.ini
2013-04-24 17:32 - 2013-04-24 18:25 - 0000408 _____ () C:\Users\X\AppData\Roaming\CamShapes.ini
2013-04-24 17:32 - 2013-04-24 18:25 - 0004509 _____ () C:\Users\X\AppData\Roaming\CamStudio.cfg
2013-04-24 17:56 - 2013-04-24 17:56 - 0000098 _____ () C:\Users\X\AppData\Roaming\CamStudio.Producer.command
2013-04-24 18:04 - 2013-04-24 18:04 - 0000000 _____ () C:\Users\X\AppData\Roaming\CamStudio.Producer.Data.ini
2013-04-24 18:04 - 2013-04-24 18:04 - 0001207 _____ () C:\Users\X\AppData\Roaming\CamStudio.Producer.ini
2011-10-18 18:58 - 2011-10-18 19:39 - 0000002 _____ () C:\Users\X\AppData\Roaming\ceville_console_history.txt
2012-02-19 19:29 - 2012-02-19 19:30 - 0000222 _____ () C:\Users\X\AppData\Roaming\glide_wrapper.zbag.ini
2011-12-24 12:55 - 2011-12-24 12:55 - 0003584 _____ () C:\Users\X\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-19 19:57 - 2013-02-19 19:57 - 0000199 _____ () C:\ProgramData\2ea457cf9e11cd63eb1efd8d7ce4d13ee2b26134
2011-02-02 20:30 - 2011-02-02 20:30 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2010-12-18 15:28 - 2016-03-18 17:27 - 0009081 _____ () C:\ProgramData\hpzinstall.log

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\X\ntuser (1).dat
C:\Users\Nehrim\NehrimLauncher.exe


Einige Dateien in TEMP:
====================
C:\Users\X\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-11-04 00:45

==================== Ende von FRST.txt ============================
         

Geändert von Klaus_Mittel (15.11.2016 um 13:10 Uhr)

Alt 15.11.2016, 12:54   #2
Klaus_Mittel
 
Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk - Standard

Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk



Und hier der (jetzt hoffentlich auch lesbare) Addition.txt:


Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-11-2016
durchgeführt von X (15-11-2016 12:45:15)
Gestartet von C:\Users\X\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2016-03-10 18:14:28)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3145422843-1996295090-1453084995-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3145422843-1996295090-1453084995-1003 - Limited - Enabled)
X (S-1-5-21-3145422843-1996295090-1453084995-1000 - Administrator - Enabled) => C:\Users\X
Gast (S-1-5-21-3145422843-1996295090-1453084995-501 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov)
911 Operator (HKLM\...\Steam App 503560) (Version:  - Jutsu Games)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.182 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Ahnayro: The Dream World (HKLM\...\Steam App 449730) (Version:  - Alice & Smith)
AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.)
American McGee's Grimm - Season 2 (HKLM-x32\...\1207663013_is1) (Version: 2.2.0.7 - GOG.com)
American McGee's Grimm - Season 3 (HKLM-x32\...\1207663023_is1) (Version: 2.2.0.7 - GOG.com)
Ansel (Version: 372.90 - NVIDIA Corporation) Hidden
Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{981F324E-98F4-4784-B76F-04E92039F3F6}) (Version: 5.2.60328.3 - Microsoft Corporation)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman - The Telltale Series (HKLM\...\Steam App 498240) (Version:  - Telltale Games)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\{47A0EA10-D506-4473-AE99-5E07DD1062DE}) (Version: 2.77.1 - Blender Foundation)
BOSS (HKLM\...\BOSS) (Version: 2.3.2 - BOSS Development Team)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Darksiders II: Deathinitive Edition (HKLM\...\Steam App 388410) (Version:  - Gunfire Games)
DJ_AIO_03_F4200_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Dotfuscator and Analytics Community Edition 5.19.1 (x32 Version: 5.19.1.3091 - PreEmptive Solutions) Hidden
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Dragon Age™: Inquisition (HKLM-x32\...\{DC4C36DC-4E5B-4262-B0C7-157DF534B969}) (Version: 1.0.0.12 - Electronic Arts)
DRAGON BALL XENOVERSE (HKLM\...\Steam App 323470) (Version:  - DIMPS)
Dropbox (HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\Dropbox) (Version: 14.4.19 - Dropbox, Inc.)
F4200 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
GameSpy Comrade (HKLM-x32\...\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}) (Version: 1.5.0.156 - GameSpy)
Ghost Master (HKLM-x32\...\1207658687_is1) (Version: 2.1.0.4 - GOG.com)
Gothic 3 (HKLM-x32\...\1207658986_is1) (Version: 2.1.0.17 - GOG.com)
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Grabby Driver Installation (64 Bit) (HKLM-x32\...\{90CA4931-4A1F-4D30-A60B-C2BBFD53D30F}) (Version: 5.09.1202.00 - TERRATEC Electronic GmbH)
Gtk# for .Net 2.12.26 (HKLM-x32\...\{BC25B808-A11C-4C9F-9C0A-6682E47AAB83}) (Version: 2.12.26 - Xamarin, Inc.)
Headlander (HKLM\...\Steam App 340000) (Version:  - Double Fine Productions)
HP Deskjet F4200 All-In-One Driver Software 13.0 Rel. 3 (HKLM\...\{A00C9114-40E6-4C70-A619-7DF264B23485}) (Version: 13.0 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
King's Quest (HKLM\...\Steam App 345390) (Version:  - The Odd Gentlemen)
Knee Deep (HKLM\...\Steam App 371300) (Version:  - Prologue Games)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{30146B19-5822-4F46-BD61-6D1927DB75C6}) (Version: 7.0.2.6 - MAGIX Software GmbH)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX Software GmbH) Hidden
MAGIX Video easy TerraTec Edition (HKLM-x32\...\MX.{7FEE208C-09FB-4B37-B6EC-A589471C03DE}) (Version: 5.0.3.111 - MAGIX Software GmbH)
MAGIX Video easy TerraTec Edition (Version: 5.0.3.111 - MAGIX Software GmbH) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Marvel: Ultimate Alliance (HKLM\...\Steam App 433300) (Version:  - Zoë Mode)
Marvel: Ultimate Alliance 2 (HKLM\...\Steam App 433320) (Version:  - Zoë Mode)
Master Reboot (HKLM\...\Steam App 251850) (Version:  - Wales Interactive)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25123 - Microsoft Corporation)
Microsoft Office 2000 Premium (HKLM-x32\...\{00000407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2816 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual Studio 2015 Tools for Unity (HKLM-x32\...\{D68E6605-F852-4936-AB64-04B80E0C85AD}) (Version: 2.2.0.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 with Update 2 (HKLM-x32\...\{04fa3a35-1f49-4510-8051-819cdc1e6e01}) (Version: 14.0.25123.0 - Microsoft Corporation)
Mozilla Firefox 49.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 de)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.1 - Mozilla)
MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25123 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Neverwinter Nights Diamond Edition (HKLM-x32\...\1207658890_is1) (Version: 2.1.0.20 - GOG.com)
NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 372.90 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.90 - NVIDIA Corporation)
NVIDIA Grafiktreiber 372.90 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.90 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.15 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 9.11.6.18139 - Electronic Arts, Inc.)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation)
Party Hard (HKLM\...\Steam App 356570) (Version:  - Pinokl Games)
PCGen60600 (HKLM-x32\...\PCGen60600) (Version:  - )
PDF24 Creator 7.9.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Police Quest Collection (HKLM\...\Steam App 494740) (Version:  - Sierra)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
Quadrilateral Cowboy (HKLM\...\Steam App 240440) (Version:  - Blendo Games)
Ralink RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.31.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (x32 Version: 14.0.25126 - Microsoft Corporation) Hidden
Sam and Max - Season Two - Sam and Max Episode 201 - Ice Station Santa (HKLM-x32\...\Episode 201 - Ice Station Santa) (Version: 1.0.0.1 - Telltale Games)
Sam and Max - Season Two - Sam and Max Episode 202 - Moai Better Blues (HKLM-x32\...\Episode 202 - Moai Better Blues) (Version: 1.0.0.7 - Telltale Games)
Sam and Max - Season Two - Sam and Max Episode 203 - Night of the Raving Dead (HKLM-x32\...\Episode 203 - Night of the Raving Dead) (Version: 1.0.3.9 - Telltale Games)
Sam and Max - Season Two - Sam and Max Episode 204 - Chariots of the Dogs (HKLM-x32\...\Episode 204 - Chariots of the Dogs) (Version: 1.0.1.9 - Telltale Games)
Sam and Max - Season Two - Sam and Max Episode 205 - What's New, Beelzebub? (HKLM-x32\...\Episode 205 - What's New, Beelzebub?) (Version: 1.0.0.9 - Telltale Games)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.4.1 - NVIDIA Corporation) Hidden
Sid Meier's Alpha Centauri Planetary Pack (HKLM-x32\...\1207658936_is1) (Version: 2.1.0.24 - GOG.com)
Skype™ 7.28 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.28.101 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM\...\Steam App 365720) (Version:  - The SKSE Team)
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Soul Axiom (HKLM\...\Steam App 279900) (Version:  - Wales Interactive)
Space Pilgrim Episode I: Alpha Centauri (HKLM\...\Steam App 429470) (Version:  - Pilgrim Adventures)
Space Pilgrim Episode II: Epsilon Indi (HKLM\...\Steam App 431710) (Version:  - Pilgrim Adventures)
Space Pilgrim Episode III: Delta Pavonis (HKLM\...\Steam App 439250) (Version:  - Pilgrim Adventures)
Space Pilgrim Episode IV: Sol (HKLM\...\Steam App 446640) (Version:  - Pilgrim Adventures)
Space Quest Collection (HKLM\...\Steam App 10110) (Version:  - Sierra)
Star Citizen Launcher (HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\Star Citizen Launcher) (Version: 00.01.00.00 - Cloud Imperium Games)
Star Trek™ - 25th Anniversary (HKLM-x32\...\1427108887_is1) (Version: 2.0.0.5 - GOG.com)
Star Trek™ - Judgment Rites Limited Collector's Edition (HKLM-x32\...\1429089605_is1) (Version: 2.0.0.6 - GOG.com)
Team Explorer for Microsoft Visual Studio 2015 Update 2 (x32 Version: 14.95.25118 - Microsoft) Hidden
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
The Banner Saga 2 (HKLM\...\Steam App 281640) (Version:  - Stoic)
The Black Watchmen (HKLM\...\Steam App 349220) (Version:  - Alice & Smith)
The Deed: Dynasty (HKLM\...\Steam App 460960) (Version:  - Pilgrim Adventures)
The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Novelist (HKLM\...\Steam App 245150) (Version:  - Orthogonal Games)
the static speaks my name (HKLM\...\Steam App 387860) (Version:  - Jesse Barksdale)
TimeShift (HKLM\...\Steam App 10130) (Version:  - Saber Interactive)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TypeScript Power Tool (x32 Version: 1.8.9.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.30.0 - Microsoft Corporation) Hidden
Tyranny (HKLM\...\Steam App 362960) (Version:  - Obsidian Entertainment)
Unity (HKLM-x32\...\Unity) (Version: 5.3.4f1 - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\UnityWebPlayer) (Version: 5.3.4f1 - Unity Technologies ApS)
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 22.0 - Ubisoft)
Visual Studio 2015 Update 2 (KB3022398) (HKLM-x32\...\{78c1b501-a6eb-4f29-88c5-84189564827e}) (Version: 14.0.25123 - Microsoft Corporation)
VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN)
VS Update core components (x32 Version: 14.0.25123 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.3.0 (HKLM\...\VulkanRT1.0.3.0) (Version: 1.0.3.0 - LunarG, Inc.)
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows-Treiberpaket - TERRATEC  (USB28xxBGA) Media  (03/16/2010 5.09.1202.00) (HKLM\...\22B1739EAEA711117281C678C9005F17A0D9D420) (Version: 03/16/2010 5.09.1202.00 - TERRATEC )
Windows-Treiberpaket - TERRATEC (emAudio) Media  (03/16/2010 5.09.1202.00) (HKLM\...\0812DA72EAD4FBFA883430ED6EC04AC1F88DBBAD) (Version: 03/16/2010 5.09.1202.00 - TERRATEC)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\X\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02E1A326-8414-43CC-A21F-390B79ED8A3D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated)
Task: {28E49C93-ED3A-4829-B62E-B941A78E3317} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000Core => C:\Users\X\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-03-19] (Dropbox, Inc.)
Task: {3AB5A4B3-CDF6-45D5-99E9-BC7AEE0BD664} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000UA => C:\Users\X\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-03-19] (Dropbox, Inc.)
Task: {493CEFA2-6A19-4D80-AE74-A992FAFC9477} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {6F2AECF7-B118-4787-86CE-75BA5035D4FC} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-03-22] (Microsoft Corporation)
Task: {8BC02481-F4FC-410B-AEF1-E59F94992D41} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {DCE40910-7AEF-40EE-9F7C-3D15FCFA0A94} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000Core.job => C:\Users\X\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3145422843-1996295090-1453084995-1000UA.job => C:\Users\X\AppData\Local\Dropbox\Update\DropboxUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-11-18 22:21 - 2016-09-16 23:57 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2012-05-04 15:41 - 2012-05-04 15:41 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2016-03-11 18:43 - 2016-06-15 02:14 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-03-11 18:42 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2016-03-11 18:42 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2016-03-11 18:42 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2016-02-19 23:53 - 2016-10-10 17:29 - 00035792 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2016-11-10 19:40 - 2016-10-10 17:29 - 00145864 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2016-11-10 19:40 - 2016-10-10 17:29 - 00019408 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\faulthandler.pyd
2016-11-10 19:40 - 2016-10-10 17:29 - 00116688 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2016-02-19 23:53 - 2016-10-10 17:29 - 00100296 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2016-02-19 23:53 - 2016-10-10 17:29 - 00018888 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\select.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00019760 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2016-02-19 23:53 - 2016-10-10 17:29 - 00694224 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2016-11-10 19:40 - 2016-11-07 23:58 - 00020816 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2016-02-19 23:53 - 2016-10-10 17:30 - 00123856 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2016-11-10 19:40 - 2016-11-07 23:58 - 01682760 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2016-11-10 19:40 - 2016-11-07 23:58 - 00020808 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00105928 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32api.pyd
2016-08-05 19:42 - 2016-11-07 23:59 - 00021312 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00052024 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00038696 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\fastpath.pyd
2016-11-10 19:40 - 2016-10-10 17:29 - 00392144 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2016-11-10 19:40 - 2016-10-10 17:31 - 00020936 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00024528 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32event.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00116176 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32security.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00381752 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00124880 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32file.pyd
2016-08-05 19:42 - 2016-11-07 23:59 - 00025424 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00024016 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00175560 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32gui.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00030160 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00043472 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32process.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00048592 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32service.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00057808 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00024016 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32profile.pyd
2016-11-10 19:40 - 2016-11-07 23:58 - 00246592 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00026456 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-08-05 19:42 - 2016-10-10 17:30 - 00241104 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\_jpegtran.pyd
2016-11-10 19:40 - 2016-11-07 23:58 - 00020280 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00028616 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32ts.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00023376 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00020800 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00019776 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00020800 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00350152 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2016-02-19 23:53 - 2016-11-07 23:59 - 00022352 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00024392 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2016-11-10 19:40 - 2016-10-10 17:27 - 00036296 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\librsync.dll
2016-11-10 19:40 - 2016-11-07 23:59 - 00084280 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2016-11-10 19:40 - 2016-11-07 23:59 - 01826096 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2016-02-19 23:53 - 2016-10-10 17:29 - 00083912 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\sip.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00531248 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 03928880 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 01972528 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00133424 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00224056 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00207672 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2016-08-05 19:42 - 2016-11-07 23:59 - 00020288 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.user32._winffi_user32.pyd
2016-11-10 19:40 - 2016-10-10 17:33 - 00017864 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\libEGL.dll
2016-11-10 19:40 - 2016-10-10 17:34 - 01631184 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2016-11-10 19:40 - 2016-11-07 23:59 - 00042808 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00168760 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00357680 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2016-02-19 23:53 - 2016-10-10 17:31 - 00060880 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\win32print.pyd
2016-08-05 19:42 - 2016-11-07 23:59 - 00024904 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-11-10 19:40 - 2016-11-07 23:59 - 00546096 _____ () C:\Users\X\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2006-08-11 12:49 - 2006-08-11 12:49 - 00828416 _____ () C:\Program Files (x86)\OpenOffice.org 2.0\program\libxml2.dll
2016-03-11 18:42 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2016-03-11 18:42 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\Users\X\Documents\AQ2_mapswithnolabels_(8996914).zip:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\X\Documents\CAT27000_Shadowrun_5_(8719235).pdf:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\X\Documents\DD2_PS_WellofWorlds_(8244976).pdf:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\X\Documents\Shadowrun_4th_Ed_(6623749).pdf:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\X\Documents\ZGA-The_Investigation_Begins-PF-ONS_(7257351).pdf:com.dropbox.attributes [168]

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\...\123simsen.com -> www.123simsen.com

Da befinden sich 7631 mehr Seiten.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3145422843-1996295090-1453084995-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Hama Wireless LAN Utility.lnk => C:\Windows\pss\Hama Wireless LAN Utility.lnk.CommonStartup
MSCONFIG\startupreg: GalaxyClient => C:\Program Files\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
MSCONFIG\startupreg: PDFPrint => "C:\Program Files (x86)\PDF24\pdf24.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{A4E70973-2FDE-4BA8-A9AC-3EC673442ED1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4F8398F0-B9CB-4CE6-8BFB-2327AB8942E5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{42A1255C-EF33-4DC9-93C0-C847BFBE78A9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{35BB552A-A376-4548-9C3A-8A6F559002A6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{0783B1CB-7049-4B81-85C1-BB1AE425FB27}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{E83F02DF-C9C6-4E07-BDD3-1018E1A33A5E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{135F8AFC-37DB-4379-A659-C9039D3BC8EC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{061D2B15-0219-4DA1-B2FB-74C98D29262C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F01CC164-7B39-4A6C-BD3C-92DEAF173710}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9D34AC37-6467-449C-9546-B6429A49B4EB}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{4B7C3D49-6B37-4B3B-BCBD-0537627EB863}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{0ABF3259-5A8B-4094-804D-E5CF7A07A75D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Always Sometimes Monsters\Game.exe
FirewallRules: [{C1451494-137A-49CE-83D1-4311DB67CCE1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Always Sometimes Monsters\Game.exe
FirewallRules: [{76D49E2C-B917-4D7D-8B41-9102950083A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\HardWest\HardWest.exe
FirewallRules: [{A89CA368-F948-45D0-B0D1-5220DE106CBC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\HardWest\HardWest.exe
FirewallRules: [{B4F11BA5-1EC5-46CF-BB79-32E18CE4DAAD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Hong Kong\SRHK.exe
FirewallRules: [{542B6B91-2E1B-4378-A505-10BAC209162E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Hong Kong\SRHK.exe
FirewallRules: [{18E88F4C-980E-4DBE-80D3-78F613E8DE82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Magic Circle\TheMagicCircle.exe
FirewallRules: [{22B75698-FF3A-40B3-88B1-84A7DB4A01BC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Magic Circle\TheMagicCircle.exe
FirewallRules: [TCP Query User{43A61847-AF50-450E-83FA-CC829121BB43}C:\program files (x86)\steam\steamapps\common\torment tides of numenera\win\tidesofnumenera.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\torment tides of numenera\win\tidesofnumenera.exe
FirewallRules: [UDP Query User{98B76BB3-EAEE-463B-A2C3-3FC75DEB8555}C:\program files (x86)\steam\steamapps\common\torment tides of numenera\win\tidesofnumenera.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\torment tides of numenera\win\tidesofnumenera.exe
FirewallRules: [{EDB701CC-ABA0-4517-BCE2-6E9BCC1152D3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{4C293D2D-7A0E-44B8-9704-71B71D36FDFD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{D4C9E7A6-9919-49CA-BC98-A30711BA71CA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{6ECCABD8-45DC-4E6B-A595-3A86B34C0BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{C1E70677-8D7F-4115-B765-40C58A37BD11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{4E124A2A-AA43-42E7-B4B3-947D562A5EE7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{7A247F53-645B-4542-8BF5-4D48EC78DDBE}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{B55A2BC9-6F29-4167-AAC0-9CCC59864591}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{067FEB93-A5F9-4D61-91C1-E0DCEA31AB29}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{D6798387-ACE4-4F9C-8881-83444CBC79AA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{0AA66CA3-71FD-461E-8090-63C436D57F74}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{9A5B78C6-95B8-4905-B746-40F7C589C893}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{BBC78B21-ACDD-4AF0-9939-F13D1403620B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{210F8E3C-AEA2-48CE-A85C-8C7BAD6ABD36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{6D4E4359-DEDA-4BFA-944E-460B0D304764}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{13374435-5559-407F-9D5C-A6FDDAA40E31}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{B3923CFD-CC57-40B5-A06C-D6216AAEA854}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{C80B3E70-5303-4421-8EBA-69AED33C1E7C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Besiege\Besiege.exe
FirewallRules: [{4AD2F1F0-0ED4-4A7C-BD52-F2FC9BD12BE1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Besiege\Besiege.exe
FirewallRules: [{10D28DC4-BD16-4D02-BA02-8CD8AD4CC754}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{57FDE4D9-5600-4E5A-8135-080158D9B659}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{68264353-604F-48C6-8B65-EDACD972B8FB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\the static speaks my name\thestatic_win.exe
FirewallRules: [{5FACCA97-4B4E-4269-A3E3-B3672B8FC1C1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\the static speaks my name\thestatic_win.exe
FirewallRules: [TCP Query User{C6D69720-22CD-4783-8CE0-E74B42B7F663}C:\program files (x86)\steam\steamapps\common\shadowrun returns\shadowrun.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\shadowrun returns\shadowrun.exe
FirewallRules: [UDP Query User{1381E8CB-CEF3-49EB-A67D-703FC1ED0184}C:\program files (x86)\steam\steamapps\common\shadowrun returns\shadowrun.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\shadowrun returns\shadowrun.exe
FirewallRules: [TCP Query User{7C4DC2D1-A7F6-4C34-A3D5-CF210EA18ED9}C:\program files (x86)\steam\steamapps\common\shadowrun dragonfall director's cut\dragonfall.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\shadowrun dragonfall director's cut\dragonfall.exe
FirewallRules: [UDP Query User{791AE151-4071-4C2F-9BEE-889ACBE9A4D8}C:\program files (x86)\steam\steamapps\common\shadowrun dragonfall director's cut\dragonfall.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\shadowrun dragonfall director's cut\dragonfall.exe
FirewallRules: [{727E9964-AA36-456E-A4BF-C7E649A04902}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Decadence\AoD64.exe
FirewallRules: [{A8043BC8-21E3-4CB5-AD6C-6986A65BA99D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Decadence\AoD64.exe
FirewallRules: [{CDB56EB7-A196-441B-97A7-CC3E230C57C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Eisenwald\Eisenwald.exe
FirewallRules: [{CA042E88-D34D-4D57-9225-EF0DEE49550A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Eisenwald\Eisenwald.exe
FirewallRules: [{6389D0C3-2263-4FB8-9A42-3001AB0EFBC2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\HeroesRiseHeroFall\HeroesRiseHeroFall.exe
FirewallRules: [{B5798906-176F-4FB5-98D4-B2793226ED4A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\HeroesRiseHeroFall\HeroesRiseHeroFall.exe
FirewallRules: [{FBC22BAE-5E4D-43CF-8CCE-096C301D983E}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{6D9049CE-5615-4D64-86BA-F3E6ABCFC85D}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio Tools for Unity\2015\UnityVS.OpenFile.exe
FirewallRules: [{0EECAADD-20AB-4B2F-9FF1-E031023FB0F8}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{DD9B2ECD-DC57-4C26-9602-B2C8F75B40A5}] => (Allow) C:\PROGRA~1\Unity\Editor\Unity.exe
FirewallRules: [TCP Query User{D8A0C47E-43AB-4A92-8121-B10BACBB16E6}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{B90EFB0B-97F9-4746-AC5E-193CFF202F8F}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{90909E0D-830E-4F4E-844B-A8C4DA934195}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Deed\Game.exe
FirewallRules: [{23AF37CB-02FB-46C5-84CF-A24856EDEDD5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Deed\Game.exe
FirewallRules: [{FA6965F6-4345-4B73-A5A8-67BB514D90BF}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{13A7D245-E77B-4214-97DB-04E8A0F2E13E}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{D7B270D4-6197-41AE-A02A-E6D94C1DE9D4}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{8784B872-9B22-4780-8586-40BC4A9CE22A}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [TCP Query User{559B2184-616D-4F6D-92FB-51986EDAF5B9}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{189A7BE9-C52E-40F2-A0B1-612441061087}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{4EED539A-1053-4708-BF5F-0B500BB870B9}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age Inquisition\DragonAgeInquisition.exe
FirewallRules: [{EF41F434-5B3F-4476-9B4B-B77407E01E26}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age Inquisition\DragonAgeInquisition.exe
FirewallRules: [{39A93A03-7C8C-4CB0-8949-839F0EE4F688}] => (Allow) C:\Users\X\AppData\Local\Temp\7zS23FF\hppiw.exe
FirewallRules: [{19D44352-265F-4DDF-968A-7560AEC69CB0}] => (Allow) C:\Users\X\AppData\Local\Temp\7zS23FF\hppiw.exe
FirewallRules: [{E1478AFB-9D53-4E54-8092-7690CEE9AD57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SatelliteReign\SatelliteReignWindows.exe
FirewallRules: [{AAB3F032-CCF6-4964-B5F4-619E1F1C4DEB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SatelliteReign\SatelliteReignWindows.exe
FirewallRules: [{84E229D8-E76C-4214-89E2-028F7374EB03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{F53F44B3-8A94-411B-B08E-EB7A7D7737A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{726EEEB4-9559-4FA7-BD0B-864BA9161EEF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Broken Age\BrokenAge.exe
FirewallRules: [{4C7FF55C-E891-46D2-943F-9B1EA0C7AF1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Broken Age\BrokenAge.exe
FirewallRules: [{B3CE13D6-8653-4AA6-8F14-6109E21D2133}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brothers - A Tale of Two Sons\Binaries\Win32\Brothers.exe
FirewallRules: [{E45FB30D-8129-4189-ABF0-9581E5C11811}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brothers - A Tale of Two Sons\Binaries\Win32\Brothers.exe
FirewallRules: [{BF68FC6E-2976-4A9E-8D15-EF76422CB839}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brothers - A Tale of Two Sons\Binaries\Win32\BrothersLauncher.exe
FirewallRules: [{EB7ED9B4-0515-44E7-83B9-425FF606EC75}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brothers - A Tale of Two Sons\Binaries\Win32\BrothersLauncher.exe
FirewallRules: [{DA05032B-2525-48D0-BB20-D77F360B6D7A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{52989DAD-DD96-4BFB-AFB3-F6EF083203AF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{C1B469F9-56A9-404A-B36D-D34C6B9DF230}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheCave\Cave.exe
FirewallRules: [{5A975FE3-52A5-4AC5-AE98-4A79AF3DE468}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheCave\Cave.exe
FirewallRules: [{70E14885-3829-4965-9696-2C71280402B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Consuming Shadow\consumingshadow.exe
FirewallRules: [{1C66A6D7-EF10-4422-92D4-D1EEDCF30662}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Consuming Shadow\consumingshadow.exe
FirewallRules: [{3AA7FB90-2B10-435F-B971-CB3F2765A8C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\costume quest\Cq.exe
FirewallRules: [{6775EB37-E066-4F1D-A9B0-DE4A39F1CA64}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\costume quest\Cq.exe
FirewallRules: [{C2ED132B-B42E-4060-92A9-42A69CC650E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CostumeQuest2\CostumeQuest2.exe
FirewallRules: [{C6A4A305-8BB9-4D17-8C02-62F8199E8E99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CostumeQuest2\CostumeQuest2.exe
FirewallRules: [{5BAB58BE-9EC8-40CE-9E0C-C703E278EF6F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CostumeQuest2\CostumeQuest2_DX9.exe
FirewallRules: [{3ECC7FE7-4A9B-4463-ACB0-5C4237E70920}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CostumeQuest2\CostumeQuest2_DX9.exe
FirewallRules: [{2FA23132-2715-4242-983A-891A31BCA589}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cry of Fear\CoFLaunchApp.exe
FirewallRules: [{AE147611-9453-4E8F-820A-289DA909A42E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cry of Fear\CoFLaunchApp.exe
FirewallRules: [{C672D9D8-4D95-4F3F-B48A-3CD7D5161B60}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{4068B55C-2908-4841-A320-ACA5AFC326D8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
FirewallRules: [{2FB2C769-9D8B-4975-AADF-7E38B1D9061C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{077E2B8E-0B5F-4F92-A6F5-D1F03095255B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{9FA6B1F8-EB5E-4595-B5E8-A4E858BCD16B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dragon age ultimate edition\DAOriginsLauncher.exe
FirewallRules: [{3BA8D674-C14D-4978-977A-9A45CA1587B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dragon age ultimate edition\DAOriginsLauncher.exe
FirewallRules: [{140FF0A9-3A12-4C16-AB03-D6116ADA793F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{480B3DBA-307B-4316-8165-02A64092EDEE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{35002D44-52FD-4285-8E19-C0261DFD71DD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dex\Dex.exe
FirewallRules: [{37AA7366-C1D7-4661-A125-A26567AB1476}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dex\Dex.exe
FirewallRules: [{4960FE2A-51BD-461E-8E60-E3362A0BB3A9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dex\GamepadConfigTool.exe
FirewallRules: [{DA962B5B-F13B-4BAB-8433-E33E3B740CD3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dex\GamepadConfigTool.exe
FirewallRules: [{F498DFBA-191E-43DF-A790-3AECA3D36CC8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Wasteland 2 Director's Cut\Build\WL2.exe
FirewallRules: [{C50F1D33-31D2-4368-9AD3-D862D29419CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Wasteland 2 Director's Cut\Build\WL2.exe
FirewallRules: [{20CFCDD2-553E-442B-8647-0ED45C553B4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Soul Axiom\SoulAxiom.exe
FirewallRules: [{56308751-6B48-408A-BA68-AF1D9F53D455}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Soul Axiom\SoulAxiom.exe
FirewallRules: [{9D5B4CA7-8C26-4E2D-8A73-2B2DF2341B76}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MasterReboot\Binaries\Win32\MasterReboot.exe
FirewallRules: [{08472699-8749-4BC7-9978-5FE92E20A75C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MasterReboot\Binaries\Win32\MasterReboot.exe
FirewallRules: [{147227FD-89E9-42D8-9BD6-C38670C285BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LongLiveTheQueen\LongLiveTheQueen.exe
FirewallRules: [{3AEEBDE3-D4F1-42E2-89A4-E5B8F5B59B3A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LongLiveTheQueen\LongLiveTheQueen.exe
FirewallRules: [{F854A822-C6A1-429C-90B6-7BE3285C0591}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{2042F614-7F8A-42BB-96DA-59B75F80B2A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{8B2DFC9B-8A4E-44D5-A1B1-0C7EC348484C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{9EB8EF54-CBD3-4BCB-B90E-C4E5EA42F73C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{D621663B-5647-4F1E-9FE8-B846E4B06A44}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{D2043EEC-A278-4B89-B352-BD48E6B9DB7B}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [UDP Query User{9242B4E8-FD47-424E-A427-FCCA1A2B3D9A}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [{08B09B3A-1277-42DC-870D-E7685E8C3CD1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Secret Of Magia\EQLauncher.exe
FirewallRules: [{214A1ECB-C9A8-43C6-8471-45BDD5C1DE4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Secret Of Magia\EQLauncher.exe
FirewallRules: [{832FD3B3-6B06-4F1B-8B1F-0DFBE4305803}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DB Xenoverse\DBXV.exe
FirewallRules: [{21A78A78-B47C-467F-9B7D-5319E7BD90A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DB Xenoverse\DBXV.exe
FirewallRules: [{78227B80-786A-4EBE-B553-218C8D268CF3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Contradiction\Windows\nw.exe
FirewallRules: [{DB0BD4EC-DED6-4E67-921F-7AC3D6EE4DE5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Contradiction\Windows\nw.exe
FirewallRules: [{43DD6AB0-EA9F-4A2E-A7CC-3E46CC035163}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Decadence\AoD.exe
FirewallRules: [{C4FDE679-97F4-452E-955F-17C9DBC29454}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Decadence\AoD.exe
FirewallRules: [{596BA756-BAF4-4411-BEA3-5368CE79DB1A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Deed Dynasty\Game.exe
FirewallRules: [{73086BC1-D110-42B9-8919-EA430241A827}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Deed Dynasty\Game.exe
FirewallRules: [{E8794874-9F2E-4D20-9E07-5FD11108A23B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode One Alpha Centauri\Game.exe
FirewallRules: [{6DFDF235-3DA9-4241-B1DB-BBFDEDE888BB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode One Alpha Centauri\Game.exe
FirewallRules: [{179830CB-654A-470D-B9C7-47DEF003BDE4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode Two\Game.exe
FirewallRules: [{566F1199-707F-4541-A2DE-3688D25BF0C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode Two\Game.exe
FirewallRules: [{22F8B3A0-D82D-44C8-96F5-996D0B8F302B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode III Delta Pavonis\Game.exe
FirewallRules: [{A06F9093-52B6-4541-8194-342FB975A42E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode III Delta Pavonis\Game.exe
FirewallRules: [{1AD5649C-D38C-4C5B-927B-FFF93D19125C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode IV Sol\Game.exe
FirewallRules: [{5074AAF6-EE7F-4D4F-AEF7-058D76F16A95}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Pilgrim Episode IV Sol\Game.exe
FirewallRules: [TCP Query User{0829C57F-F7C2-4661-A078-AC581CE54C32}C:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe
FirewallRules: [UDP Query User{64E5E6D9-61C3-4525-84F8-85D45A25C472}C:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe
FirewallRules: [{C535F910-CFD2-4FEF-81BF-FAB8DC2AC326}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman The Telltale Series\Batman_win8.exe
FirewallRules: [{D57839B0-0A9A-4EBD-AFB6-D59AC9312873}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman The Telltale Series\Batman_win8.exe
FirewallRules: [{19128602-021A-41D0-976B-7184315FF81E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman The Telltale Series\Batman_win7.exe
FirewallRules: [{082711C9-61B6-4541-A467-99D92C6EC8CD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Batman The Telltale Series\Batman_win7.exe
FirewallRules: [{E3F248DD-DE31-49F9-BFE4-298EEA923145}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Inquisitor\Game\Inquisitor.exe
FirewallRules: [{6FAB7E6C-ADFA-47D6-B2A8-B1ECE3134E45}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Inquisitor\Game\Inquisitor.exe
FirewallRules: [{9961D509-47F3-4D56-8C2A-D74B603144B3}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{8E22674A-E010-42B5-8E87-F8AD9B457607}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [TCP Query User{FA218370-928B-40A4-AD23-27A930B3F3FC}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe
FirewallRules: [UDP Query User{05B97A19-001B-4374-96A5-C7CFDBF7857F}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe
FirewallRules: [{E0B4B686-C73E-4A94-AF55-C0662ABDC5C9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs2\win32\The Banner Saga 2.exe
FirewallRules: [{7014183D-9E04-4D55-8FA0-95C3DFDA823A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs2\win32\The Banner Saga 2.exe
FirewallRules: [{CB51B168-C4AB-4F94-B02E-9C3C81771273}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Party Hard\PartyHardGame.exe
FirewallRules: [{4DBC3E84-9489-4D55-9625-DDF84CFAA987}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Party Hard\PartyHardGame.exe
FirewallRules: [{D397A13D-FCA8-4464-906F-302E82544BED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Novelist\The Novelist.exe
FirewallRules: [{4F4854ED-1C58-4128-9BF8-72319A964DA9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Novelist\The Novelist.exe
FirewallRules: [{160173CE-7941-4FD9-A8A4-DFEA3B8A15A5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{C202AE04-467D-4F2C-B950-0AC21ADD70D0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{A591DF0F-EEFD-4795-B5D2-7DDD5A9D2B2D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TimeShift\bin\TimeShift.Exe
FirewallRules: [{38ED49C5-8B2C-4244-8125-83B778D08C2C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TimeShift\bin\TimeShift.Exe
FirewallRules: [{55894420-D580-437C-8D0E-9BC05D0D7137}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Quest Collection\2016_SpaceQuestCollection\SierraLauncher.exe
FirewallRules: [{D3B13504-A832-42D1-9489-68D72A9AC5FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Quest Collection\2016_SpaceQuestCollection\SierraLauncher.exe
FirewallRules: [{D4B5B657-62DA-4B94-8337-64DD606ADA04}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Quest Collection\SierraLauncher.exe
FirewallRules: [{4AC50393-D9F1-4224-AEDB-9FEF5D81FE67}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Space Quest Collection\SierraLauncher.exe
FirewallRules: [{05C6BEDE-9BD1-4425-B952-1BD6801A6D1C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\911 Operator\911.exe
FirewallRules: [{48FD9FCE-12F4-44C5-AEA1-75B82565E862}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\911 Operator\911.exe
FirewallRules: [{C6A66A53-9AA1-4BCC-953F-B0AAC1337E40}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Police Quest Collection\SierraLauncher.exe
FirewallRules: [{67D0CED7-2909-4E8B-8FBB-B2A646A4620D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Police Quest Collection\SierraLauncher.exe
FirewallRules: [{3D13FC7D-C4E9-4E19-87AB-CB59D39EC5A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\quadrilateralcowboy\qc.exe
FirewallRules: [{E5004409-E1C4-43EC-BBD6-C82F631CCBF1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\quadrilateralcowboy\qc.exe
FirewallRules: [{0B32A373-4037-4E9D-BD06-3CAC17A0D97E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Headlander\Headlander.exe
FirewallRules: [{B24029D8-575D-4E49-BEB5-5ABEC4A2D0EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Headlander\Headlander.exe
FirewallRules: [{25467C13-8D35-4F48-ACF9-925EB91340D1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Marvel - Ultimate Alliance\Marvel.exe
FirewallRules: [{CE7CF8F6-1948-4C3B-89F3-040F89A795F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Marvel - Ultimate Alliance\Marvel.exe
FirewallRules: [{3F50FAAB-7587-4485-A095-4DBC70CB62E0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Marvel - Ultimate Alliance 2\Alliance.exe
FirewallRules: [{58FD53BE-CE98-4AC6-BD86-14C03268AD8E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Marvel - Ultimate Alliance 2\Alliance.exe
FirewallRules: [{C661932F-2E22-4227-8687-8F0A330C625F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Heroes Rise The Hero Project\HeroesRiseTheHeroProject.exe
FirewallRules: [{20846FD6-A9CA-47A7-B3BF-2FAF10620980}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Heroes Rise The Hero Project\HeroesRiseTheHeroProject.exe
FirewallRules: [{A431F3CD-1518-449C-8D4F-86A15C85AEA2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Quest\Binaries\Win\KingsQuest.exe
FirewallRules: [{3231FE71-4487-4BF6-90C7-1FFCD913749A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Quest\Binaries\Win\KingsQuest.exe
FirewallRules: [{C6CCBB46-62F4-46A2-80A0-89D98D857BE4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders II Deathinitive Edition\Darksiders2.exe
FirewallRules: [{080FC556-9339-480C-9757-B6CD1BD4F886}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders II Deathinitive Edition\Darksiders2.exe
FirewallRules: [{2A7B882C-EA04-429F-8262-525FB37CBC32}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Black Watchmen\tbw.exe
FirewallRules: [{F7658F9F-7E25-421F-8CEE-5639741BCC1D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Black Watchmen\tbw.exe
FirewallRules: [{CE26B43C-7E67-4048-9348-33841EA018FA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Ahnayro\ahnayro.exe
FirewallRules: [{02E87EC2-93FB-4853-9F38-F1C2157DC634}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Ahnayro\ahnayro.exe
FirewallRules: [{427E6622-B7C6-469E-A7B6-63E458709CDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tyranny\Tyranny.exe
FirewallRules: [{35FA2CFC-F65B-474B-BE13-50D65E76F41B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tyranny\Tyranny.exe
FirewallRules: [{E49D7ED4-441F-4ED0-819F-D3993B84FBE8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knee Deep\Knee Deep.exe
FirewallRules: [{7CBCF85F-5EDC-4133-A0DC-A58FED02BD1E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knee Deep\Knee Deep.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Wiederherstellungspunkte =========================


==================== Fehlerhafte Geräte im Gerätemanager =============

Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/12/2016 05:00:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm mbar.exe, Version 1.9.3.1001 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 524

Startzeit: 01d23cfa15efcba4

Endzeit: 2418

Anwendungspfad: C:\Users\X\Desktop\mbar\mbar.exe

Berichts-ID: 246bfe22-a8f1-11e6-a1fb-d8cb8a731465

Error: (11/11/2016 11:46:23 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 7.1.2084.9592, Zeitstempel: 0x57605ac0
Name des fehlerhaften Moduls: MessageBus.dll, Version: 0.0.0.0, Zeitstempel: 0x5760534f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000010f73
ID des fehlerhaften Prozesses: 0xe64
Startzeit der fehlerhaften Anwendung: 0x01d23c08cc2eac75
Pfad der fehlerhaften Anwendung: C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
Pfad des fehlerhaften Moduls: C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
Berichtskennung: 15e82eb6-a7fc-11e6-8f95-24050f78a73a

Error: (11/03/2016 07:09:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Darksiders2.exe, Version: 0.0.0.0, Zeitstempel: 0x56414237
Name des fehlerhaften Moduls: Darksiders2.exe, Version: 0.0.0.0, Zeitstempel: 0x56414237
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000058742d
ID des fehlerhaften Prozesses: 0x1828
Startzeit der fehlerhaften Anwendung: 0x01d235faa56b74ec
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Steam\steamapps\common\Darksiders II Deathinitive Edition\Darksiders2.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Steam\steamapps\common\Darksiders II Deathinitive Edition\Darksiders2.exe
Berichtskennung: b607d569-a1f0-11e6-a362-d8cb8a731465

Error: (11/02/2016 09:09:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 15.20.20039.7108, Zeitstempel: 0x57eee485
Name des fehlerhaften Moduls: AcroRd32.dll, Version: 15.20.20039.7108, Zeitstempel: 0x57eee462
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0028992b
ID des fehlerhaften Prozesses: 0x1084
Startzeit der fehlerhaften Anwendung: 0x01d235332c58f1a5
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll
Berichtskennung: 3c43c7ff-a138-11e6-a4f5-d8cb8a731465

Error: (10/28/2016 07:01:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GrimmGame.exe, Version: 0.0.0.0, Zeitstempel: 0x48561d63
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x8b068b57
ID des fehlerhaften Prozesses: 0x19c8
Startzeit der fehlerhaften Anwendung: 0x01d231420e1ea3db
Pfad der fehlerhaften Anwendung: C:\Program Files\GalaxyClient\Games\American McGees Grimm - Season 1\1-1 BoyFear\Binaries\GrimmGame.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 800a914b-9d38-11e6-948b-d8cb8a731465

Error: (10/27/2016 09:50:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 15.20.20039.7108, Zeitstempel: 0x57eee485
Name des fehlerhaften Moduls: AcroRd32.dll, Version: 15.20.20039.7108, Zeitstempel: 0x57eee462
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0028992b
ID des fehlerhaften Prozesses: 0x81c
Startzeit der fehlerhaften Anwendung: 0x01d23061cfd3008d
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll
Berichtskennung: ff7aabbb-9c86-11e6-97ff-d8cb8a731465

Error: (10/18/2016 11:47:56 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\X\Downloads\SoftonicDownloader_fuer_mpeg-streamclip.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.

Error: (10/16/2016 08:13:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: steamwebhelper.exe, Version: 3.65.13.80, Zeitstempel: 0x57fed9f2
Name des fehlerhaften Moduls: steamwebhelper.exe, Version: 3.65.13.80, Zeitstempel: 0x57fed9f2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00037b59
ID des fehlerhaften Prozesses: 0x1700
Startzeit der fehlerhaften Anwendung: 0x01d227afc1e102a8
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe
Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe
Berichtskennung: 9a20e304-93d4-11e6-a1b3-d8cb8a731465

Error: (10/06/2016 07:42:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: setup.exe_unknown, Version: 0.0.0.0, Zeitstempel: 0x57d87fc5
Name des fehlerhaften Moduls: NVI2.DLL, Version: 2.1002.224.1962, Zeitstempel: 0x57d880dc
Ausnahmecode: 0x40000015
Fehleroffset: 0x00278476
ID des fehlerhaften Prozesses: 0x1a54
Startzeit der fehlerhaften Anwendung: 0x01d2200144599214
Pfad der fehlerhaften Anwendung: C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\setup.exe
Pfad des fehlerhaften Moduls: C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{0C482131-D588-4F13-B169-4C29AA0CAE47}\NVI2.DLL
Berichtskennung: abecad92-8bf4-11e6-8116-d8cb8a731465

Error: (10/03/2016 06:56:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Marvel.exe, Version: 1.0.0.1, Zeitstempel: 0x57b584fc
Name des fehlerhaften Moduls: XAudio2_7.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4c0643cc
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000007fef1a12891
ID des fehlerhaften Prozesses: 0xd3c
Startzeit der fehlerhaften Anwendung: 0x01d21d9ba44a857a
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Steam\steamapps\common\Marvel - Ultimate Alliance\Marvel.exe
Pfad des fehlerhaften Moduls: XAudio2_7.dll
Berichtskennung: ba1e08d1-8992-11e6-8026-d8cb8a731465


Systemfehler:
=============
Error: (11/15/2016 12:34:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (11/15/2016 12:34:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht.

Error: (11/15/2016 12:14:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (11/15/2016 12:14:27 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht.

Error: (11/14/2016 05:31:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (11/14/2016 05:31:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht.

Error: (11/14/2016 01:11:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (11/14/2016 01:11:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht.

Error: (11/13/2016 06:31:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Origin Web Helper Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (11/13/2016 06:31:25 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Origin Web Helper Service erreicht.


==================== Speicherinformationen =========================== 

Prozessor: AMD FX(tm)-6300 Six-Core Processor 
Prozentuale Nutzung des RAM: 34%
Installierter physikalischer RAM: 8140.05 MB
Verfügbarer physikalischer RAM: 5321.74 MB
Summe virtueller Speicher: 16278.29 MB
Verfügbarer virtueller Speicher: 13657.66 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:153.77 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 78BCB546)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         
__________________


Geändert von Klaus_Mittel (15.11.2016 um 13:11 Uhr)

Antwort

Themen zu Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk
.dll, administrator, antivirus, avira, defender, desktop, explorer, firefox, helper, home, hängen, mozilla, nvidia, prozesse, realtek, registry, scan, secur, services.exe, software, spam, system, temp, windows, winlogon.exe




Ähnliche Themen: Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk


  1. mailer Daemon als fishing e-mail
    Überwachung, Datenschutz und Spam - 15.10.2016 (1)
  2. Mail Delivery System <mailer-daemon@kundenserver.de> mailrücklauf auf nicht gesendete mail
    Überwachung, Datenschutz und Spam - 26.03.2015 (4)
  3. Unzählige Emails mit dem Betreff "Mail Delivery System <MAILER-DAEMON@XXX.info>" erhalten
    Plagegeister aller Art und deren Bekämpfung - 21.03.2015 (15)
  4. Mysteriöse Mailer-Daemon-mail
    Überwachung, Datenschutz und Spam - 13.07.2014 (15)
  5. Mail account gesperrt: Mailer daemon - undeliverable mail massenhaft
    Log-Analyse und Auswertung - 29.04.2014 (10)
  6. Mailer Daemon Mails von GMX-Konto - Spam oder sendet Outlook selbstständig Mails?
    Plagegeister aller Art und deren Bekämpfung - 12.12.2013 (8)
  7. Windows 7: Mailer-Daemon Mails von gmx ohne Ende
    Log-Analyse und Auswertung - 29.10.2013 (3)
  8. Flut von Mailer Daemon @ GMX Mails!
    Log-Analyse und Auswertung - 28.10.2013 (6)
  9. E-Mail Account gehackt? mailer-daemon@gmx.de
    Plagegeister aller Art und deren Bekämpfung - 24.07.2013 (17)
  10. Gmx Konto Mail Flut MAILER-DAEMON@mail.gmx.com
    Log-Analyse und Auswertung - 19.03.2013 (2)
  11. e-Mail Flut mit mailer-daemon Meldungen
    Plagegeister aller Art und deren Bekämpfung - 21.12.2012 (24)
  12. Mailer-Daemon - erhalte für EINGEGANGENE Mails Mailer-Daemon-Nachrichten
    Plagegeister aller Art und deren Bekämpfung - 09.12.2012 (3)
  13. hunderte Mails von MAILER-DAEMON@mailout-de.gmx.net in zwei tagen im Posteingang
    Plagegeister aller Art und deren Bekämpfung - 06.11.2012 (1)
  14. GMX Account erhält Mailer Daemon Mails von Arcor - Spam-Weiterleitung?
    Überwachung, Datenschutz und Spam - 17.07.2012 (0)
  15. mailer-daemon@mail.gmx.de
    Überwachung, Datenschutz und Spam - 14.04.2011 (26)
  16. viele MAILER-DAEMON@mail.gmx.net emails im postfach bei thunderbird
    Plagegeister aller Art und deren Bekämpfung - 04.01.2011 (8)
  17. Plötzlich hunderte MAILER-DAEMON@mail.gmx.net emails
    Plagegeister aller Art und deren Bekämpfung - 19.10.2010 (1)

Zum Thema Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk - Hier das (jetzt hoffentlich lesbare) FRST-Logfile: Code: Alles auswählen Aufklappen ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2016 durchgeführt von X (Administrator) auf X-PC (15-11-2016 12:44:36) Gestartet - Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk...
Archiv
Du betrachtest: Erhalte Emails von mailer-daemon@mail.corp.ru und versende Mails an litemill@yahoo.co.uk auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.