Windows 10: Bedrohung PUP.Optional.HomePageHelper gefunden
"Addition" - Teil 2
Code:
ATTFilter
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:DocumentSummaryInformation [0]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:OzngklrtOwudrp0bAayojd1qWh [0]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:SebiesnrMkudrfcoIaamtykdDa [0]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:SummaryInformation [0]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:Updt_DocumentSummaryInformation [331]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:Updt_OzngklrtOwudrp0bAayojd1qWh [65]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:Updt_SebiesnrMkudrfcoIaamtykdDa [59]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:Updt_SummaryInformation [755]
AlternateDataStreams: C:\Users\Ich\Desktop\Borgia (812) (Historiendrama CZD 2011) [ZDF].ts:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Ich\Desktop\Erklärung zu den Tabellen (Hauptsächlich Übersicht Kommunionkinder).odt:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Jugru-Kategorien für die Stundenorganisation.pdf:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Raumplan.ods:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Raumübersicht - Wo ist was - unverschlüsselt.odt:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Raumübersicht - Wo ist was.odt:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.26.07.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.26.17.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.26.39.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.27.00.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.27.33.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.27.40.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.28.16.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.28.25.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.28.34.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.29.03.png:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Ich\Desktop\Screenshot 2016-01-11 23.29.25.png:com.dropbox.attributes [168]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\Software\Classes\.scr: AutoCADScriptFile =>
==================== Internet Explorer (Nicht auf der Ausnahmeliste) ==========
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM -> DefaultScope {7309C6E0-0811-4345-BCCB-F1562932F896} URL =
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001 -> DefaultScope {E469C974-E6C4-11E4-826D-ACB57D77D7C7} URL =
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001 -> {C161E8B4-DA5D-4A49-8062-82B7AAD38884} URL =
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507 -> DefaultScope {E469C974-E6C4-11E4-826D-ACB57D77D7C7} URL =
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507 -> {C161E8B4-DA5D-4A49-8062-82B7AAD38884} URL =
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466 -> DefaultScope {E469C974-E6C4-11E4-826D-ACB57D77D7C7} URL =
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466 -> {C161E8B4-DA5D-4A49-8062-82B7AAD38884} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\ssv.dll [2019-07-28] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-28] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Kein Name - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - Keine Datei
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2018-03-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-27] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts Inhalt: =========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 14:25 - 2016-08-29 09:49 - 000000834 _____ C:\WINDOWS\system32\drivers\etc\hosts
2019-03-22 19:54 - 2020-09-30 17:32 - 000000438 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
==================== Andere Bereiche ===========================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Acer\abFiles\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093012931\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094736401\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013194\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094736698\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\Control Panel\Desktop\\Wallpaper -> c:\users\ich\appdata\roaming\microsoft\windows photo viewer\hintergrundbild der windows-fotoanzeige.jpg
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\Control Panel\Desktop\\Wallpaper -> c:\users\ich\appdata\roaming\microsoft\windows photo viewer\hintergrundbild der windows-fotoanzeige.jpg
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\Control Panel\Desktop\\Wallpaper -> c:\users\ich\appdata\roaming\microsoft\windows photo viewer\hintergrundbild der windows-fotoanzeige.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\...\StartupApproved\StartupFolder: => "RC.lnk"
HKLM\...\StartupApproved\StartupFolder: => "LRZ Sync+Share.lnk"
HKLM\...\StartupApproved\Run: => "GlobalProtect"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX"
HKLM\...\StartupApproved\Run32: => "BrHelp"
HKLM\...\StartupApproved\Run32: => "ArcSoft Connection Service"
HKLM\...\StartupApproved\Run32: => "EPGServiceTool"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "PCSpeedUp"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "SlimCleaner Plus"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "ProgLauncher"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Desktop Dimmer"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "PCSpeedUp"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "SlimCleaner Plus"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "ProgLauncher"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Desktop Dimmer"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020093013507\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "PCSpeedUp"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "SlimCleaner Plus"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "ProgLauncher"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Desktop Dimmer"
HKU\S-1-5-21-3486276509-1338222940-3729840800-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11112020094737466\...\StartupApproved\Run: => "Steam"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{F0D86BDF-1AE1-4B1E-908B-72832F7B82B7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EEF511BF-FFE0-4A39-8B69-FAB4E190828E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04BB9F58-7812-47DB-8AED-C5DE144FCFA1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D30EC799-61CE-4FD1-880D-DC33070AEF1C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{77B52717-4DC0-4FED-B576-6F418AA4794A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{DB5083F5-FF19-4585-8859-FB0E7D917467}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{84D17501-6C66-4E97-BAFD-A9693A51FD78}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{1BCB5F35-1E9C-4D33-96FC-C32B89D60C23}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{040ADC04-2CC3-4C47-9A4C-0F41E71E614B}] => (Block) C:\users\ich\downloads\utox_win64.exe () [Datei ist nicht signiert]
FirewallRules: [{FBD968C4-4113-4624-90E3-E2E47F780BEA}] => (Block) C:\users\ich\downloads\utox_win64.exe () [Datei ist nicht signiert]
FirewallRules: [UDP Query User{ACD76694-A97B-4136-9C4D-2EA017F62376}C:\users\ich\downloads\utox_win64.exe] => (Allow) C:\users\ich\downloads\utox_win64.exe () [Datei ist nicht signiert]
FirewallRules: [TCP Query User{AE7E1DBB-223A-48FF-BCB5-3F4C593A506E}C:\users\ich\downloads\utox_win64.exe] => (Allow) C:\users\ich\downloads\utox_win64.exe () [Datei ist nicht signiert]
FirewallRules: [{E7CBF7BA-47D1-4DC5-B0D1-0A2D6243D5AF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{D6EB6D06-8221-419C-9994-9305D08D9AE8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{22444BB3-6218-4550-A9C4-00F04299887D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{1B33C570-1C7A-48EB-A3C2-1BD5A0E28AFB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{FE7BE911-D733-4433-BEEB-38D9A4C00254}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.) [Datei ist nicht signiert]
FirewallRules: [{AD0E6736-B806-4247-94AA-A9E96637FBEC}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.) [Datei ist nicht signiert]
FirewallRules: [{8DFF0A3C-0B21-402F-AA03-BB0F3E8D3306}] => (Allow) LPort=54925
FirewallRules: [UDP Query User{214AAA33-CE48-4649-A410-6552A867D58C}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{8D470ECB-6F00-4847-8045-6D5CB4E1B4BC}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{17D73307-7DCE-400B-93D6-E807D48E034E}C:\totalcmd\totalcmd.exe] => (Allow) C:\totalcmd\totalcmd.exe (C. Ghisler & Co. -> C. Ghisler & Co.)
FirewallRules: [TCP Query User{5D2BD86D-C7CC-4508-8BD1-E64EAC734470}C:\totalcmd\totalcmd.exe] => (Allow) C:\totalcmd\totalcmd.exe (C. Ghisler & Co. -> C. Ghisler & Co.)
FirewallRules: [{BFBA1044-9902-499C-84BD-3496A2668302}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [{7FC6D7C6-498A-4EB7-B8A1-877259CFB796}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [{0D2BFBE4-1000-4258-A4A3-8063413D9EF7}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{F6F1D1E7-932A-4459-A5F5-92B9C97AD636}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{756096C6-3FAD-4829-BE31-AAA3A28BC4DA}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{DEA0A588-3780-44B9-B04D-9F6F9D371BC4}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{4BD45058-C7C9-49DF-A649-54132A675FCD}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{B063093B-10F3-4222-AA26-B58E9783959F}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{9DDB8229-0722-4129-BC26-1DEFAAAAB472}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{7971D4E5-0441-4527-A300-512A5CD3F157}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{289D32AD-F62F-4D48-80FE-81DCAC606AD1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{AEC729E4-188B-491F-A9A8-A81294377E9D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{883FCF6A-0D90-478B-951C-2013B6C80798}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{E323FFB9-9B3E-4C4D-B0AB-744FDD6C9AA5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{3458DD54-E0FF-4F06-BB29-EF4CB149B028}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{DB3BE63B-6FCD-4057-A6AF-2596A11BA895}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{96D89B5C-58D3-4755-AD8B-91EEA9E706C8}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{A4F8DA0F-6AE5-451E-AA84-E0EED01AC04D}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{4BB4B980-4B2D-45A2-AF75-6A91021BA3B7}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{549E3BB0-DE9A-4F7D-B47E-282EB7EEEF71}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{068FAEF0-419C-42F8-9935-E7A12CE7DD2B}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{CEDB11DA-08F7-4AB2-B54D-09BBBC28445C}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{F5D0EC4F-CEA6-489B-95B9-C40F7EA8DC3A}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{0D30746A-E370-4711-8244-CA86B3587F35}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe => Keine Datei
FirewallRules: [{9FE83C09-8406-4FBD-B28E-F048F168B0EF}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe => Keine Datei
FirewallRules: [{EF9403B5-3E44-4128-BD24-D232F916D630}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe => Keine Datei
FirewallRules: [{0F0C9990-B4B0-4239-B84F-BC41DB7AC079}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe => Keine Datei
FirewallRules: [{B948601A-2AF8-442B-A96A-D3908764CAF0}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{756CAC19-960B-4145-823E-DD24E8C5A406}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{37C2B513-D390-4C33-AA90-FDDB69D98AAE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{D3CD576E-2B74-4D32-85C0-A31CB3CCAEA1}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology)
FirewallRules: [{FFEDAF99-E7F5-45D7-9C06-6B2D0AAB8307}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology)
FirewallRules: [{8F405E09-1B3D-4AFC-B9B4-F8EA47A6F4DD}] => (Allow) C:\Users\Ich\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{727B61D4-CAA8-4800-A6E7-22670C29850C}] => (Allow) C:\Users\Ich\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{BFFBF7F4-57A3-4228-B561-988C6E7CF0E1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{BDC5FB65-D35C-464B-8EAD-DEE7B047DFE7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{20D7250C-8103-4039-B6BA-E20B185B215F}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{EB276167-82BC-4470-8661-62AE13AF3891}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2FD2C087-9136-4EE9-A931-CDA265C9ABEB}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{99CB30BA-89AE-455E-BD15-5A58F1DB85F7}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{02CE6A9C-4613-4973-B279-80A151025E98}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe => Keine Datei
FirewallRules: [{1B17A834-602C-4A88-AC2B-7D3781666E53}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe => Keine Datei
FirewallRules: [{4A7D7D45-8D09-4765-B527-1532CCD0F5B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{67C1A378-16B4-4269-BA10-167853EF16AC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{0E47F56C-F587-484A-9D3C-5F2BAA5A094D}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe (CyberLink -> CyberLink Corp.) [Datei ist nicht signiert]
FirewallRules: [{25A1E190-2493-4E33-A594-6FCCA76964D6}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Live\CLHomeMediaServer.exe (CyberLink -> CyberLink) [Datei ist nicht signiert]
FirewallRules: [{02234822-9C6B-4674-8639-E348FBCA724D}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe (CyberLink -> CyberLink) [Datei ist nicht signiert]
FirewallRules: [{5A46CC24-C069-4A83-9A18-8955EFEF16B8}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe (CyberLink -> CyberLink) [Datei ist nicht signiert]
FirewallRules: [{071240E0-9271-4630-B3CF-933B3EC6A4C0}] => (Allow) LPort=50248
FirewallRules: [{F0F8BBB8-79A0-4A08-B69B-3260DBFFB8D1}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{388632DB-CE41-43F5-9A0A-3CFCC74647D2}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{BD8EBE60-7E97-4BDE-AD80-3C9E10E37AB6}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [{8204678C-FB98-4574-B0E9-8CB8A8DC7E75}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [{F33A418A-6FFA-4D29-BA22-EF55A7930F29}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{F2931EEE-90BC-4949-9CBD-85B2ACFD64CD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{1EEFD807-67D8-47DE-A230-A0F30C09930B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [{E07039DB-97AF-4ABC-A598-56E1A61E0141}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe (Acer Incorporated -> acer)
FirewallRules: [TCP Query User{35243A4B-3BA5-41A3-8579-156A8279623E}C:\users\ich\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\ich\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{C35B50D7-CB8A-4435-B388-F13CE5CF4B71}C:\users\ich\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\ich\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{A5B172A1-210D-4C41-82AD-CE558329F729}] => (Allow) C:\Windows\system32\hasplms.exe (SafeNet, Inc. -> SafeNet Inc.)
FirewallRules: [TCP Query User{EC42EED3-BE59-4623-882B-B48D68E68A37}C:\program files\firebird-2.5.2.26540-0_x64\bin\fb_inet_server.exe] => (Allow) C:\program files\firebird-2.5.2.26540-0_x64\bin\fb_inet_server.exe (Firebird Project) [Datei ist nicht signiert]
FirewallRules: [UDP Query User{3FA029A8-B95B-4EFE-81C4-F33B17C64051}C:\program files\firebird-2.5.2.26540-0_x64\bin\fb_inet_server.exe] => (Allow) C:\program files\firebird-2.5.2.26540-0_x64\bin\fb_inet_server.exe (Firebird Project) [Datei ist nicht signiert]
FirewallRules: [TCP Query User{9AF7EFC6-FA76-45E2-9A34-E6FA54143606}C:\users\ich\downloads\utox_win64(1).exe] => (Allow) C:\users\ich\downloads\utox_win64(1).exe () [Datei ist nicht signiert]
FirewallRules: [UDP Query User{340FFA58-89AB-4D29-A61D-2A739D1D7092}C:\users\ich\downloads\utox_win64(1).exe] => (Allow) C:\users\ich\downloads\utox_win64(1).exe () [Datei ist nicht signiert]
FirewallRules: [TCP Query User{89999A97-905C-4B12-8BBE-D53CE0429DE5}C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe] => (Allow) C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{F34533F6-C63E-402F-BDF1-E34005BCA8D7}C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe] => (Allow) C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [TCP Query User{2D1A9992-66E5-4836-B65C-574B2DAEEE66}C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe] => (Block) C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [UDP Query User{1C2AADD1-7E71-4206-A30C-BB79DDC75EA1}C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe] => (Block) C:\program files (x86)\leibniz-rechenzentrum\lrz_sync_share\jre\launch4j-tmp\lrz_sync_share.exe (Oracle America, Inc. -> Oracle Corporation)
FirewallRules: [{65933529-C2E8-48B2-801A-233F06F2C774}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe (Beijing Duodian Online Science and Technology Co.,Ltd -> Duodian Technology Co. Ltd.)
FirewallRules: [{AC7126EF-76F4-4E30-A726-57E26074812C}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)
FirewallRules: [{B28F6F00-7CAF-4ACF-99CB-983863E1E2EE}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{59EB7201-949D-41F3-8898-76A556A5DE99}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{4BC00654-9B50-4A98-A227-D507F7F9846A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5AA6C36A-41C2-44F7-BEC3-BC44AC6E033C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{D94385B3-F823-4AA4-88E2-CFDCA6C16542}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{4AE314A4-4448-4875-A8A4-4521F377510F}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{8AFFDA36-8FE0-401F-A91A-5C37D76C2404}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{238E09A9-443C-45F9-9282-BC27F57586AD}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{FC860D9C-746A-40B8-B6D9-C12B4FBC7E99}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{37842C8B-FDEA-4D6C-A399-8DD6FE1F923B}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => Keine Datei
FirewallRules: [{472672B9-386C-4680-B63A-5A6A8C3C3E7B}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\OxygenPanelDaemon.exe => Keine Datei
FirewallRules: [{9684EF10-1BA2-4835-A87C-3F217B857493}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{81C671CA-9189-4602-A4CD-3F81F9706418}] => (Allow) C:\ProgramData\Blackmagic Design\DaVinci Resolve\Support\QtDecoder\QTDecoder.exe => Keine Datei
FirewallRules: [TCP Query User{98D1DA36-EA2D-4C7E-9805-FA576FCFF832}C:\program files\blackmagic design\davinci resolve\dpdecoder.exe] => (Block) C:\program files\blackmagic design\davinci resolve\dpdecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [UDP Query User{9376BEBB-6F83-4DA7-A432-2B3EA1DFC945}C:\program files\blackmagic design\davinci resolve\dpdecoder.exe] => (Block) C:\program files\blackmagic design\davinci resolve\dpdecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [TCP Query User{5390A765-D46A-4EFA-A22C-C065EA0EC1A2}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Block) C:\program files\blackmagic design\davinci resolve\resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [UDP Query User{E2917ED9-8E4E-44A0-8CB6-A6230348EEB6}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Block) C:\program files\blackmagic design\davinci resolve\resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [TCP Query User{BF4A39FB-A51D-4A8C-9A1A-32EEA4D70EEF}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Block) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [UDP Query User{50E6A890-5D79-49B5-8BCC-82CC4FF8BFCB}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Block) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{5DD74ADB-F8EC-4573-808A-485DBDD629F8}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{2D9CEFFB-24C9-44B3-AB40-6E66C8DDC87D}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{75360EE9-543A-4151-A122-BB20107C935B}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{ADB13423-DA54-4AC6-BB47-BFA2E801C07E}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{61AE63F1-B7E8-46E9-9A8A-277D41CE480E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9B69517E-CF9E-407F-B99B-B79462C60E57}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A82FF775-FAED-4519-B38A-5845CEB8DD5B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6CB761A2-70C0-4230-BD85-BE44CC9697B4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AE8E1DA1-EFC8-401D-8B73-4C675CD87775}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Wiederherstellungspunkte =========================
02-10-2020 17:37:58 Windows Update
14-10-2020 17:52:54 Windows Update
23-10-2020 10:01:55 Windows Update
==================== Fehlerhafte Geräte im Gerätemanager ============
==================== Fehlereinträge in der Ereignisanzeige: ========================
Applikationsfehler:
==================
Error: (11/11/2020 10:57:39 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (117476,R,98) TILEREPOSITORYS-1-5-18: Fehler -1023 (0xfffffc01) beim Öffnen von Protokolldatei C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (11/11/2020 10:15:57 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (111984,R,98) TILEREPOSITORYS-1-5-18: Fehler -1023 (0xfffffc01) beim Öffnen von Protokolldatei C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (11/11/2020 01:51:38 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7202547
Error: (11/11/2020 01:51:38 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7202547
Error: (11/11/2020 01:51:38 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/10/2020 11:51:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1672
Error: (11/10/2020 11:51:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1672
Error: (11/10/2020 11:51:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Systemfehler:
=============
Error: (11/11/2020 09:50:32 AM) (Source: DCOM) (EventID: 10010) (User: PPF-PC)
Description: Der Server "Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (11/11/2020 09:49:53 AM) (Source: DCOM) (EventID: 10010) (User: PPF-PC)
Description: Der Server "Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (11/10/2020 06:26:50 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Error: (11/10/2020 06:26:50 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Error: (11/10/2020 06:26:50 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Error: (11/10/2020 05:31:24 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Error: (11/10/2020 05:31:24 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Error: (11/10/2020 05:31:24 PM) (Source: MTConfig) (EventID: 1) (User: )
Description: Fehler beim Konfigurieren des Eingabemodus eines Mehrfingereingabegeräts.
Windows Defender:
===================================
Date: 2020-11-04 10:33:47.842
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {E117B586-B32D-4ECE-96E5-13AA26221D2C}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2020-10-22 20:53:47.132
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {06B48618-63D3-4B57-ABD7-8BD92BFB776C}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2020-10-22 20:23:24.542
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {E5213CBA-F813-476B-9233-D4BC0832F610}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2020-10-17 11:43:46.903
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {B7F22232-617B-4439-B085-5A60A62197DD}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2020-10-17 11:37:28.369
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {8A50B3E1-C5B2-4B45-AD0A-FDDAF5D8FFBD}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT-AUTORITÄT\SYSTEM
Date: 2020-10-29 08:23:30.852
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.325.1512.0
Update Source: Microsoft Center zum Schutz vor Schadsoftware
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\Netzwerkdienst
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.17500.4
Fehlercode: 0x80070102
Fehlerbeschreibung: Der Wartevorgang wurde abgebrochen.
Date: 2020-10-29 08:17:30.471
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.325.1512.0
Update Source: Microsoft Update-Server
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.17500.4
Fehlercode: 0x80240016
Fehlerbeschreibung: Unerwartetes Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates oder zur Problembehandlung finden Sie unter "Hilfe und Support".
Date: 2020-10-28 16:30:25.863
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.325.1512.0
Update Source: Microsoft Update-Server
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.17500.4
Fehlercode: 0x80240016
Fehlerbeschreibung: Unerwartetes Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates oder zur Problembehandlung finden Sie unter "Hilfe und Support".
Date: 2020-09-20 19:15:56.974
Description:
Bei Windows Defender Antivirus ist ein Fehler beim Aktualisieren der Sicherheitsinformationen aufgetreten.
Neue Version der Sicherheitsinformationen:
%Vorherige Version der Sicherheitsinformationen: 1.323.1563.0
Update Source: Microsoft Update-Server
Sicherheitstyp: AntiVirus
Updatetyp: Voll
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion:
%Vorherige Modulversion: 1.1.17400.5
Fehlercode: 0x80070102
Fehlerbeschreibung: Der Wartevorgang wurde abgebrochen.
CodeIntegrity:
===================================
Date: 2020-11-11 11:16:40.053
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 11:15:41.151
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 11:15:40.263
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 11:13:35.624
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 10:31:52.075
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 10:27:56.419
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 10:20:57.579
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2020-11-11 10:20:57.451
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
BIOS: Insyde Corp. V1.21 11/17/2014
Hauptplatine: Acer EA50_HB
Prozessor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 89%
Installierter physikalischer RAM: 8115.27 MB
Verfügbarer physikalischer RAM: 860.13 MB
Summe virtueller Speicher: 16819.27 MB
Verfügbarer virtueller Speicher: 3619.85 MB
==================== Laufwerke ================================
Drive c: (Acer) (Fixed) (Total:448.67 GB) (Free:19.29 GB) NTFS
\\?\Volume{2ca47058-2748-4dff-a303-a243eefbc32f}\ (Recovery) (Fixed) (Total:0.59 GB) (Free:0.3 GB) NTFS
\\?\Volume{789cd1bb-fd77-49f5-8cc6-6cb1b1b9bb73}\ (Push Button Reset) (Fixed) (Total:16.09 GB) (Free:1.84 GB) NTFS
\\?\Volume{1108ae31-9f99-40d5-b963-daa961953ccf}\ (ESP) (Fixed) (Total:0.29 GB) (Free:0.24 GB) FAT32
==================== MBR & Partitionstabelle ====================
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 8695E95C)
Partition: GPT.
==================== Ende von Addition.txt =======================
---ENDE der Auszüge---
Zu dem Windows Update: Es sind Updates verfügbar (stehen zum download bereit)...aber er zeigt keine Aufforderung oder Warnung an, eines durchzuführen. Müsste schon passen.
Zum Thema Windows 10: Bedrohung PUP.Optional.HomePageHelper gefunden - "Addition" - Teil 2
Code:
Alles auswählen Aufklappen ATTFilter
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS - Windows 10: Bedrohung PUP.Optional.HomePageHelper gefunden...