Grace777 | 25.08.2017 15:23 | Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017
durchgeführt von Günter (Administrator) auf BUSINESS-PC (25-08-2017 15:09:42)
Gestartet von C:\Users\Günter\Downloads
Geladene Profile: Günter (Verfügbare Profile: Günter)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\22.10.0.85\nis.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\22.10.0.85\nis.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Dropbox, Inc.) C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dropbox, Inc.) C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dropbox, Inc.) C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\OSDManager.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Lexware\Update Manager\LxUpdateManager.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\dthtml.exe
(Portrait Displays Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\HookManager.exe
() C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpCtrl.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
() C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\BCMWLTRY.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Users\Günter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
(Microsoft Corporation) C:\Users\Günter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2013-07-15] (Hewlett-Packard )
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [10613760 2013-07-15] (Broadcom Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-07-15] (IDT, Inc.)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [PivotSoftware] => C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [110192 2010-05-13] ()
HKLM-x32\...\Run: [DT HPO] => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe [120400 2012-08-16] (Portrait Displays, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-02] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [210432 2016-07-05] (Geek Software GmbH)
HKLM-x32\...\Run: [LexwareInfoService] => C:\Program Files (x86)\Lexware\Update Manager\LxUpdateManager.exe [357344 2016-09-01] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [Haufe.Loge.AutostartLauncher.exe] => C:\Program Files (x86)\Common Files\Lexware\Dll\Haufe.Loge.AutostartLauncher.exe [18912 2017-06-28] (Haufe-Lexware GmbH & Co. KG)
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Run: [Amazon Music] => C:\Users\Günter\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Run: [Dropbox Update] => C:\Users\Günter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-07] (Dropbox, Inc.)
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50509440 2015-11-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\MountPoints2: {80312b1e-5194-11e3-8250-446d57854b7b} - "F:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\MountPoints2: {e5d420b0-3305-11e3-be90-446d57854b7b} - "F:\HTC_Sync_Manager_PC.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-07-15]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Günter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2013-07-30]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Keine Datei)
Startup: C:\Users\Günter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-08-23]
ShortcutTarget: Dropbox.lnk -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Günter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - .lnk [2017-03-31]
ShortcutTarget: Tintenwarnungen überwachen - .lnk -> C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Günter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk [2017-08-02]
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{DB719CAE-9AFB-4B88-A652-FD2C67110969}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK13/4
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.norton.com/?prt=ns&chn=oem&geo=de&ver=22.9.3.13&locale=de_de&guid=a9d6e3b0-0cac-4f79-aaa4-0beed7b39ed6&doi=2017-05-24&o=APN11915
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK13/4
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {1527D929-F718-4EF6-84EB-AF24E9C2D673} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {1527D929-F718-4EF6-84EB-AF24E9C2D673} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-1829671353-3276857950-888964810-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1829671353-3276857950-888964810-1001 -> {1527D929-F718-4EF6-84EB-AF24E9C2D673} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1829671353-3276857950-888964810-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NS&chn=oem&geo=DE&ver=22&locale=de_DE&gct=kwd&qsrc=2869
SearchScopes: HKU\S-1-5-21-1829671353-3276857950-888964810-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKU\S-1-5-21-1829671353-3276857950-888964810-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-08-23] (Microsoft Corporation)
BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Internet Security\Engine\22.10.0.85\coIEPlg.dll [2017-07-14] (Symantec Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-08-23] (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Internet Security\Engine32\22.10.0.85\coIEPlg.dll [2017-07-14] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL => Keine Datei
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\22.10.0.85\coIEPlg.dll [2017-07-14] (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine32\22.10.0.85\coIEPlg.dll [2017-07-14] (Symantec Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-08-23] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-08-23] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-08-23] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-08-23] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Günter\AppData\Roaming\Mozilla\Firefox\Profiles\ywlqu8da.default [2017-08-25]
FF Homepage: Mozilla\Firefox\Profiles\ywlqu8da.default -> www.google.de
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.9.1.12\coFFAddon
FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.9.1.12\coFFAddon [2017-08-05]
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.9.1.12\coFFAddon
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-08] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-08] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-15] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-15] (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-08-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Internet Security\Engine\22.10.0.85\Exts\Chrome.crx [2017-07-27]
CHR HKLM\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <kein Path/update_url>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Internet Security\Engine\22.10.0.85\Exts\Chrome.crx [2017-07-27]
CHR HKLM-x32\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <kein Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2013-07-15] (Andrea Electronics Corporation) [Datei ist nicht signiert]
S2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4424392 2017-08-12] (Microsoft Corporation)
S2 CLKMSVC10_38F51D56; c:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241776 2013-01-28] (CyberLink)
R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [136784 2012-08-16] (Portrait Displays, Inc.)
S3 ElfoService; C:\Program Files (x86)\ElsterFormular Update Service\elfoService.exe [1283336 2017-05-17] ()
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321896 2017-07-06] (HP Inc.)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-10] (Nero AG)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129336 2013-07-15] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-07-15] (Intel Corporation)
R2 Lexware_Update_Service; C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe [64992 2016-08-23] (Haufe-Lexware GmbH & Co. KG)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 NIS; C:\Program Files\Norton Internet Security\Engine\22.10.0.85\NIS.exe [326144 2017-07-15] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [Datei ist nicht signiert]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2013-07-15] (IDT, Inc.) [Datei ist nicht signiert]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [6036480 2013-07-15] (Broadcom Corporation) [Datei ist nicht signiert]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AVerIT13x; C:\WINDOWS\System32\Drivers\AVerIT13x_x64.sys [197504 2013-05-24] (AVerMedia TECHNOLOGIES, Inc.)
R3 bcbtums; C:\WINDOWS\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [6957744 2013-07-15] (Broadcom Corporation)
R1 BHDrvx64; C:\Program Files\Norton Internet Security\NortonData\22.9.1.12\Definitions\BASHDefs\20170821.001\BHDrvx64.sys [1862816 2017-06-28] (Symantec Corporation)
R3 btwpanfl; C:\WINDOWS\system32\drivers\btwpanfl.sys [44912 2013-07-15] (Broadcom Corporation.)
R1 ccSet_NIS; C:\WINDOWS\system32\drivers\NISx64\160A000.055\ccSetx64.sys [187520 2017-07-14] (Symantec Corporation)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 CpqDfw; C:\WINDOWS\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508032 2017-06-29] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158336 2017-06-29] (Symantec Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-08-21] ()
R1 IDSVia64; C:\Program Files\Norton Internet Security\NortonData\22.9.1.12\Definitions\IPSDefs\20170823.001\IDSvia64.sys [1056920 2017-08-01] (Symantec Corporation)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [192960 2017-08-23] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [101824 2017-08-25] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-08-25] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [253888 2017-08-25] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [94144 2017-08-25] (Malwarebytes)
R1 SRTSP; C:\WINDOWS\System32\Drivers\NISx64\160A000.055\SRTSP64.SYS [810136 2017-07-14] (Symantec Corporation)
R1 SRTSPX; C:\WINDOWS\system32\drivers\NISx64\160A000.055\SRTSPX64.SYS [49304 2017-07-14] (Symantec Corporation)
R0 SymEFASI; C:\WINDOWS\System32\drivers\NISx64\160A000.055\SYMEFASI64.SYS [1868416 2017-07-14] (Symantec Corporation)
S0 SymELAM; C:\WINDOWS\System32\drivers\NISx64\160A000.055\SymELAM.sys [24608 2017-05-11] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-07-27] (Symantec Corporation)
S1 SymIM; C:\WINDOWS\system32\DRIVERS\SymIMv.sys [43680 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\WINDOWS\system32\drivers\NISx64\160A000.055\Ironx64.SYS [301288 2017-07-14] (Symantec Corporation)
R1 SymNetS; C:\WINDOWS\System32\Drivers\NISx64\160A000.055\SYMNETS.SYS [566912 2017-07-14] (Symantec Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-08-25 15:09 - 2017-08-25 15:10 - 000026896 _____ C:\Users\Günter\Downloads\FRST.txt
2017-08-25 15:09 - 2017-08-25 15:09 - 000000000 ____D C:\FRST
2017-08-25 15:08 - 2017-08-25 15:08 - 002395648 _____ (Farbar) C:\Users\Günter\Downloads\FRST64.exe
2017-08-24 18:25 - 2017-08-24 18:25 - 000613792 _____ C:\Users\Günter\Documents\Kindergeldantrag_Nadine 240817.pdf
2017-08-24 17:54 - 2017-08-24 17:55 - 002910819 _____ C:\Users\Günter\Documents\Scan0087.pdf
2017-08-24 17:48 - 2017-08-24 17:48 - 003630288 _____ C:\Users\Günter\Documents\Erklärung der Mutter BAB_523D021411 Schanz.pdf
2017-08-24 17:41 - 2017-08-24 17:41 - 000454517 _____ C:\Users\Günter\Documents\Angaben zur Miete BAB_523D021411 Schanz.pdf
2017-08-24 17:36 - 2017-08-24 17:36 - 002371997 _____ C:\Users\Günter\Documents\Bescheinigung der Ausbildungsstätte BAB_523D021411 Schanz.pdf
2017-08-24 17:34 - 2017-08-24 17:34 - 001778102 _____ C:\Users\Günter\Documents\Scan0086.pdf
2017-08-24 17:17 - 2017-08-24 17:18 - 002190582 _____ C:\Users\Günter\Documents\Antrag auf Weiterbewilligung BAB_ 523D021411 Schanz.pdf
2017-08-24 16:22 - 2017-08-24 18:12 - 000000000 ____D C:\Users\Günter\AppData\Local\FSDART
2017-08-24 16:22 - 2017-08-24 16:28 - 000000000 ____D C:\ProgramData\F-Secure
2017-08-24 16:22 - 2017-08-24 16:22 - 000000000 ____D C:\Users\Günter\AppData\Local\F-Secure
2017-08-24 16:21 - 2017-08-24 16:21 - 000524248 _____ (F-Secure Corporation) C:\Users\Günter\Downloads\F-SecureOnlineScanner.exe
2017-08-24 16:17 - 2017-08-24 16:17 - 000040814 _____ C:\ProgramData\1503584225.10928.bin
2017-08-24 16:17 - 2017-08-24 16:17 - 000002058 _____ C:\ProgramData\1503584225.9600.bin
2017-08-24 16:17 - 2017-08-24 16:17 - 000000189 _____ C:\ProgramData\1503584225.3388.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000039399 _____ C:\ProgramData\1503584041.3816.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000002062 _____ C:\ProgramData\1503584041.8312.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000000189 _____ C:\ProgramData\1503584041.3088.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000000000 ____D C:\Users\Günter\AppData\Roaming\QuickScan
2017-08-23 21:20 - 2017-08-23 21:20 - 000000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2017-08-23 20:31 - 2017-08-23 20:31 - 000000000 ____D C:\Users\Günter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-08-23 18:50 - 2017-08-25 14:50 - 000101824 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-08-23 18:50 - 2017-08-25 14:50 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-08-23 18:50 - 2017-08-25 14:50 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-08-23 18:50 - 2017-08-23 18:50 - 000192960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-08-23 18:49 - 2017-08-25 14:49 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-08-23 18:49 - 2017-08-23 18:49 - 000001883 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-08-23 18:49 - 2017-08-23 18:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-23 18:49 - 2017-08-23 18:49 - 000000000 ____D C:\Program Files\Malwarebytes
2017-08-23 18:49 - 2017-08-21 07:20 - 000077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-08-23 18:36 - 2017-08-25 14:48 - 000000000 ____D C:\AdwCleaner
2017-08-23 18:35 - 2017-08-23 18:48 - 065942208 _____ (Malwarebytes ) C:\Users\Günter\Downloads\mb3-setup-consumer-3.2.2.2018.exe
2017-08-23 18:34 - 2017-08-23 18:35 - 008185288 _____ (Malwarebytes) C:\Users\Günter\Downloads\adwcleaner_7.0.1.0.exe
2017-08-23 14:08 - 2017-08-23 18:27 - 000000000 ____D C:\Users\Günter\AppData\Roaming\Nico Mak Computing
2017-08-23 10:12 - 2017-08-23 10:12 - 001058704 _____ C:\Users\Günter\Documents\Pläne_ Drinda Halle 5.pdf
2017-08-23 10:06 - 2017-08-23 10:06 - 000453457 _____ C:\Users\Günter\Documents\Scan0085.pdf
2017-08-23 10:05 - 2017-08-23 10:05 - 000601620 _____ C:\Users\Günter\Documents\Scan0084.pdf
2017-08-22 17:51 - 2017-08-22 17:51 - 000430162 _____ C:\Users\Günter\Documents\Anerkennung Vaterschaft_Tommy.pdf
2017-08-18 10:19 - 2017-08-18 10:19 - 000350573 _____ C:\Users\Günter\Documents\Fertigungsauftrag 4005-33-17.pdf
2017-08-15 10:27 - 2017-08-15 10:27 - 000601507 _____ C:\Users\Günter\Documents\Skizze Verteiler HV Springer Stein_Adelmann.pdf
2017-08-14 16:07 - 2017-08-14 16:07 - 000593541 _____ C:\Users\Günter\Documents\Untersuchung Aortenaneurysma 2014.pdf
2017-08-10 11:27 - 2017-08-10 11:27 - 000472380 _____ C:\Users\Günter\Documents\Whatsapp Gebetsliste.pdf
2017-08-08 21:45 - 2017-08-02 05:17 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-08-08 21:45 - 2017-07-21 15:40 - 000518144 _____ C:\WINDOWS\SysWOW64\msjetoledb40.dll
2017-08-08 21:45 - 2017-07-21 15:40 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjtes40.dll
2017-08-08 21:45 - 2017-07-15 12:10 - 000536688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-08-08 21:45 - 2017-07-15 12:10 - 000140016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-08-08 21:45 - 2017-07-15 12:06 - 000449840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-08-08 21:45 - 2017-07-15 12:06 - 000136832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-08-08 21:45 - 2017-07-14 22:08 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2017-08-08 21:45 - 2017-07-14 20:44 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2017-08-08 21:45 - 2017-07-14 08:49 - 025733632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-08-08 21:45 - 2017-07-14 08:44 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-08-08 21:45 - 2017-07-14 08:19 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-08-08 21:45 - 2017-07-14 07:35 - 005981184 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-08-08 21:45 - 2017-07-14 07:26 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2017-08-08 21:45 - 2017-07-14 07:10 - 000806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-08-08 21:45 - 2017-07-14 06:40 - 015254016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-08-08 21:45 - 2017-07-14 06:23 - 003240960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-08-08 21:45 - 2017-07-14 06:07 - 001545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-08-08 21:45 - 2017-07-14 05:58 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-08-08 21:45 - 2017-07-14 04:54 - 020270080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-08-08 21:45 - 2017-07-14 04:48 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-08-08 21:45 - 2017-07-14 04:38 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-08-08 21:45 - 2017-07-14 04:17 - 004546048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-08-08 21:45 - 2017-07-14 04:17 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2017-08-08 21:45 - 2017-07-14 04:12 - 000693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-08-08 21:45 - 2017-07-14 04:09 - 013663744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-08-08 21:45 - 2017-07-14 03:53 - 002767872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-08-08 21:45 - 2017-07-14 03:50 - 001314816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-08-08 21:45 - 2017-07-14 03:48 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-08-08 21:45 - 2017-07-08 22:14 - 000376672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-08-08 21:45 - 2017-07-08 21:12 - 004169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-08-08 21:45 - 2017-07-08 19:45 - 007078912 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll
2017-08-08 21:45 - 2017-07-08 19:05 - 003631616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-08-08 21:45 - 2017-07-08 18:39 - 005274624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll
2017-08-08 21:45 - 2017-07-08 18:37 - 007797248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-08-08 21:45 - 2017-07-08 18:23 - 002749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-08-08 21:45 - 2017-07-08 17:59 - 005270016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-08-08 21:45 - 2017-07-08 05:46 - 000377688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgrx.sys
2017-08-08 21:45 - 2017-07-08 05:16 - 007440728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-08-08 21:45 - 2017-07-08 05:16 - 001674520 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-08-08 21:45 - 2017-07-08 05:16 - 001534072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-08-08 21:45 - 2017-07-08 05:16 - 001499920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-08-08 21:45 - 2017-07-08 05:16 - 001370328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-08-08 21:45 - 2017-07-08 05:16 - 000086360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2017-08-08 21:45 - 2017-07-01 15:47 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswdat10.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000641536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrepl40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-08-08 21:45 - 2017-07-01 15:47 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjter40.dll
2017-08-08 21:45 - 2017-06-24 18:46 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2017-08-08 21:45 - 2017-06-24 18:16 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
2017-08-08 21:45 - 2017-06-15 16:17 - 002551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-08-08 21:45 - 2017-06-15 16:16 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-08-08 21:45 - 2017-06-13 19:51 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-08-08 21:45 - 2017-06-13 19:23 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-08-08 21:45 - 2017-06-13 19:19 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
2017-08-08 21:45 - 2017-06-13 19:16 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2017-08-08 21:45 - 2017-06-13 19:11 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2017-08-08 21:45 - 2017-06-13 19:07 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2017-08-08 21:45 - 2017-06-13 16:17 - 000656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-08-08 21:45 - 2017-06-13 16:16 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2017-08-08 21:45 - 2017-06-13 11:47 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-08-08 21:45 - 2017-06-13 11:09 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-08-08 21:45 - 2017-06-13 10:22 - 001436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-08-08 21:45 - 2017-06-13 10:16 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2017-08-08 21:45 - 2017-06-13 10:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2017-08-08 21:45 - 2017-06-13 10:07 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2017-08-08 21:45 - 2017-06-13 10:03 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2017-08-08 21:45 - 2017-06-13 09:54 - 000374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2017-08-08 21:45 - 2017-06-13 09:50 - 001547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2017-08-08 21:45 - 2017-06-12 02:14 - 000276320 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2017-08-08 21:45 - 2017-06-11 22:13 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2017-08-08 21:45 - 2017-06-11 22:11 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2017-08-08 21:45 - 2017-06-11 22:02 - 002778112 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-08-08 21:45 - 2017-06-11 22:02 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2017-08-08 21:45 - 2017-06-11 21:52 - 002463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-08-08 21:45 - 2017-06-09 15:47 - 000448629 _____ C:\WINDOWS\system32\ApnDatabase.xml
2017-08-08 21:45 - 2017-06-08 19:01 - 001737600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-08-08 21:45 - 2017-06-08 19:01 - 001502000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-08-08 21:45 - 2017-06-08 03:48 - 002457936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-08-08 21:45 - 2017-06-07 06:25 - 000428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2017-08-08 21:45 - 2017-06-06 20:38 - 000607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2017-08-08 21:45 - 2017-06-06 19:44 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2017-08-08 21:45 - 2017-05-27 18:42 - 001115136 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2017-08-08 21:45 - 2017-05-27 18:38 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll
2017-08-07 12:46 - 2017-08-07 12:46 - 001359630 _____ C:\Users\Günter\Documents\Gerinnungswerte 2017_Mama.pdf
2017-08-05 09:49 - 2017-08-05 09:49 - 000000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security
2017-08-05 09:43 - 2017-08-05 09:43 - 000003224 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
2017-07-31 16:56 - 2017-07-31 16:56 - 000172746 _____ C:\Users\Günter\Documents\Surrender all- give you everything-C.pdf
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-08-25 14:53 - 2016-11-18 14:48 - 000000000 ____D C:\Users\Günter\AppData\LocalLow\Mozilla
2017-08-25 14:51 - 2013-11-14 14:15 - 000000000 ___DO C:\Users\Günter\SkyDrive
2017-08-25 14:50 - 2013-11-20 10:45 - 000000000 ____D C:\Users\Günter\AppData\Local\HTC MediaHub
2017-08-25 14:49 - 2013-08-22 16:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-08-25 14:48 - 2013-08-22 15:25 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2017-08-25 14:46 - 2014-01-29 21:23 - 000003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CD7599BD-DEBE-4CC9-94E3-02CD59F354AF}
2017-08-24 21:26 - 2013-05-08 16:25 - 000000000 ____D C:\ProgramData\Lexware
2017-08-24 18:49 - 2015-06-20 11:23 - 000001252 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001UA.job
2017-08-24 18:24 - 2013-04-30 09:49 - 000003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1829671353-3276857950-888964810-1001
2017-08-24 18:13 - 2013-08-22 15:25 - 000262144 ___SH C:\WINDOWS\system32\config\ELAM
2017-08-24 16:50 - 2013-09-30 06:14 - 001983678 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-08-24 16:50 - 2013-09-30 05:56 - 000842224 _____ C:\WINDOWS\system32\perfh007.dat
2017-08-24 16:50 - 2013-09-30 05:56 - 000191896 _____ C:\WINDOWS\system32\perfc007.dat
2017-08-24 16:50 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\Inf
2017-08-23 20:31 - 2014-08-19 18:11 - 000000000 ____D C:\Users\Günter\AppData\Roaming\Dropbox
2017-08-23 19:21 - 2014-04-27 19:41 - 000000000 ____D C:\Users\Günter\AppData\Local\NPE
2017-08-23 19:05 - 2016-11-18 14:31 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-08-23 18:49 - 2013-05-04 15:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-08-23 15:12 - 2012-12-30 08:17 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-08-23 15:04 - 2013-08-22 17:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-08-23 14:10 - 2017-07-19 06:45 - 000000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForGünter.job
2017-08-23 10:49 - 2015-06-20 11:23 - 000001200 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001Core.job
2017-08-23 10:25 - 2017-07-19 06:46 - 000003176 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForGünter
2017-08-23 10:16 - 2013-10-30 23:10 - 000000000 ____D C:\Users\Günter\AppData\Local\CrashDumps
2017-08-22 16:31 - 2013-10-30 15:13 - 000000000 ____D C:\Users\Günter\Mama
2017-08-21 18:09 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-08-15 10:33 - 2015-11-09 21:42 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-10 13:54 - 2013-05-10 15:38 - 000000000 ____D C:\ProgramData\elsterformular
2017-08-10 12:55 - 2013-08-22 17:36 - 000000000 ___HD C:\Program Files\WindowsApps
2017-08-10 11:47 - 2015-05-18 13:06 - 000004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-08-09 12:11 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\rescache
2017-08-08 22:56 - 2013-08-22 16:44 - 000636664 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-08 22:51 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-08-08 22:51 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-08-08 22:38 - 2012-07-26 09:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-08-08 22:37 - 2013-08-15 07:53 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-08-08 22:34 - 2013-05-03 14:56 - 140394280 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-08-08 15:52 - 2014-08-19 19:05 - 000000000 ___RD C:\Users\Günter\Dropbox
2017-08-08 13:23 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-08-08 13:23 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-08-08 13:23 - 2013-05-04 11:09 - 000004342 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-08-05 18:47 - 2013-05-14 00:57 - 000000000 ____D C:\Users\Günter\Gott
2017-08-05 18:44 - 2013-05-14 01:03 - 000000000 ____D C:\Users\Günter\Ingrid
2017-08-05 10:13 - 2015-06-15 12:03 - 000000000 ____D C:\Program Files\Common Files\AV
2017-08-05 09:44 - 2017-04-19 14:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\NISx64
2017-08-05 09:43 - 2017-04-19 14:55 - 000002384 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk
2017-08-05 09:43 - 2017-04-19 14:52 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2017-07-29 02:03 - 2017-07-21 12:10 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-07-29 02:03 - 2017-07-21 12:10 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-27 12:37 - 2017-04-19 14:55 - 000102568 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2017-07-27 12:37 - 2017-04-19 14:55 - 000008309 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2017-07-26 05:38 - 2017-02-01 13:06 - 000053248 ___SH C:\Users\Günter\Desktop\Thumbs.db
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-08-25 14:36 - 2014-12-20 15:36 - 000000232 _____ () C:\Users\Günter\AppData\Roaming\WB.CFG
2014-11-28 16:39 - 2014-11-28 16:39 - 000004608 _____ () C:\Users\Günter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-02 11:36 - 2014-12-17 14:36 - 000000010 _____ () C:\Users\Günter\AppData\Local\DSI.DAT
2017-08-24 16:14 - 2017-08-24 16:14 - 000000189 _____ () C:\ProgramData\1503584041.3088.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000039399 _____ () C:\ProgramData\1503584041.3816.bin
2017-08-24 16:14 - 2017-08-24 16:14 - 000002062 _____ () C:\ProgramData\1503584041.8312.bin
2017-08-24 16:17 - 2017-08-24 16:17 - 000040814 _____ () C:\ProgramData\1503584225.10928.bin
2017-08-24 16:17 - 2017-08-24 16:17 - 000000189 _____ () C:\ProgramData\1503584225.3388.bin
2017-08-24 16:17 - 2017-08-24 16:17 - 000002058 _____ () C:\ProgramData\1503584225.9600.bin
2013-12-19 13:08 - 2013-12-19 13:08 - 000000057 _____ () C:\ProgramData\Ament.ini
2013-05-04 17:11 - 2013-12-19 13:02 - 000016064 _____ () C:\ProgramData\hpzinstall.log
2013-04-30 09:41 - 2013-04-30 09:41 - 000000141 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
Einige Dateien in TEMP:
====================
2014-06-18 16:57 - 2013-06-04 10:30 - 000050432 ____R () C:\Users\Günter\AppData\Local\Temp\Extract.exe
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-08-25 15:06
==================== Ende von FRST.txt ============================ Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 20-08-2017
durchgeführt von Günter (25-08-2017 15:10:51)
Gestartet von C:\Users\Günter\Downloads
Windows 8.1 (Update) (X64) (2013-11-13 14:30:48)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1829671353-3276857950-888964810-500 - Administrator - Disabled)
Gast (S-1-5-21-1829671353-3276857950-888964810-501 - Limited - Disabled)
Günter (S-1-5-21-1829671353-3276857950-888964810-1001 - Administrator - Enabled) => C:\Users\Günter
HomeGroupUser$ (S-1-5-21-1829671353-3276857950-888964810-1009 - Limited - Enabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security (Enabled - Up to date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117}
FW: Norton Internet Security (Enabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.012.20095 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Amazon Kindle) (Version: 1.20.1.47037 - Amazon)
Amazon Music (HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Amazon Amazon Music) (Version: 3.2.0.591 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\...\{DC7C952E-3B17-9BBE-CED0-152DB6B0BAA2}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
AVerMedia TV Player (HKLM-x32\...\{DCF2CF72-8523-4487-9D55-31A6D53AEC57}) (Version: 1.8.1.13080201 - AVerMedia Technologies, Inc.) Hidden
AVerMedia TV Player (HKLM-x32\...\InstallShield_{DCF2CF72-8523-4487-9D55-31A6D53AEC57}) (Version: 1.8.1.13080201 - AVerMedia Technologies, Inc.)
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
bpd_scan (HKLM-x32\...\{3D73DC7A-2D1D-45CF-8A67-24873925C716}) (Version: 3.00.0000 - Hewlett-Packard) Hidden
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 6.30.66.1 - Broadcom Corporation)
Broadcom Bluetooth Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.6300 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\{4CDA59B9-7AD3-4283-9F5C-BC469FF975B6}) (Version: 6.30.66.1 - Broadcom Corporation)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6321 - CDBurnerXP)
Connected Music powered by Universal Music Group version 1.0 (HKLM-x32\...\{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1) (Version: 1.0 - Snowite)
Content Manager (HKLM-x32\...\Content Manager) (Version: 3.18.5.639191 - NNG Llc.)
Corel Graphics - Windows Shell Extension (HKLM\...\_{2CDF0D0A-C58C-4136-9978-F029B2723B0D}) (Version: 16.4.0.1280 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM\...\{2CDF0D0A-C58C-4136-9978-F029B2723B0D}) (Version: 16.4.1280 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (HKLM\...\{80F776E8-B47B-4F23-835F-4464EA3E8BC6}) (Version: 16.4.1280 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - BR (x64) (HKLM\...\{8EF2B1E1-4D7A-43FA-92C5-61DB6F0524C4}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (HKLM\...\{1967EF95-E00B-4669-8B1C-A589BE8BF24F}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (HKLM\...\{35869A6C-BA31-4F23-B52D-BC1B1E41EC1B}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (HKLM\...\{96AAAB95-AEBE-437A-B7CA-37C7BE13FFE9}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (HKLM\...\{7386B5FA-8715-481D-821F-7785110506DF}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - DE (x64) (HKLM\...\{CDFFDDCC-B74E-4AEE-A97F-12E31BAFF3FF}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (HKLM\...\{27AE72A4-B217-4CDC-B82B-3311E9D7460E}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - EN (x64) (HKLM\...\{BB65D262-3EBC-4F10-89D9-67A320E94EAA}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - ES (x64) (HKLM\...\{839546C9-2E4E-4A42-B0D4-22E05E92E7AA}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (HKLM\...\{E699230D-4B5E-411E-9F45-FF50789B18DD}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (HKLM\...\{3933C06C-8239-432B-87FC-F2BDC5B49A10}) (Version: 16.2 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FR (x64) (HKLM\...\{A1CDB206-B8F1-41F0-9DAA-C7FC8664C737}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{B6DF7031-2843-44FD-9CAB-DECAB4257456}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{FB8CF321-07A3-464C-B1D5-35CE28E474C3}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM T3 (HKLM\...\{80411B38-DEF6-4E32-BE6B-796015325109}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IT (x64) (HKLM\...\{B6FB1FF8-B79B-44E5-97BE-6E1E37F281AC}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - NL (x64) (HKLM\...\{5123BE03-F8AF-4D20-A6A7-65CB35FF514E}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (HKLM\...\{D7C2687D-924E-4485-B367-C7D95CBF8DDD}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Photozoom Plugin (x64) (HKLM\...\{695E54E9-5B06-4FFD-8481-B09E5761B5D5}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (HKLM\...\{6099F026-0A98-4D40-9B3D-ED2123A8CBD0}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (HKLM\...\{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (HKLM\...\{10762393-1B90-4AC2-AF1A-4C0C04AE303F}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (HKLM\...\{7B79AE44-9B76-4815-84E5-ACAC3F0F0278}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (HKLM\...\{1E3A578C-0A7D-4820-990F-B7545C0B2303}) (Version: 16.6 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (HKLM\...\{DDE82E3D-20C4-48E1-AE1D-B1F10E42CA44}) (Version: 16.7 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (64-Bit) (HKLM\...\_{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.4.1.1281 - Corel Corporation)
CorelDRAW Graphics Suite X6 (x64) (HKLM\...\{CBC1BFA3-E641-4FCA-8EFA-77E2B7D7E552}) (Version: 16.7 - Corel Corporation) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3109 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.1.1902 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.8.5511 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
dakota.ag (HKLM-x32\...\{7DCCF6BD-1A33-4511-AF9E-F7E577B566F4}) (Version: 6.0 - ITSG GmbH) Hidden
dakota.ag (HKLM-x32\...\dakota.ag) (Version: 6.0 - ITSG GmbH)
Dropbox (HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\Dropbox) (Version: 33.4.23 - Dropbox, Inc.)
ElsterFormular (HKLM-x32\...\{FAC6CEDE-32AC-4EDE-AF6F-D09399BBBFD2}) (Version: 18.4.0 - Thüringer Landesfinanzdirektion)
Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}.KB947789) (Version: 1 - Microsoft Corporation)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP Connected Remote (HKLM-x32\...\{F243A34B-AB7F-4065-B770-B85B767C247C}) (Version: 1.0.1206 - Hewlett-Packard)
HP My Display (HKLM-x32\...\{1F4DDC90-5923-4E49-A4C7-F3CCC954DCA0}) (Version: 1.12.004 - Portrait Displays, Inc.)
HP Officejet Pro 8600 - Grundlegende Software für das Gerät (HKLM\...\{D2D05FDB-4EDA-462D-8DB6-E0B9AD4FA25F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet Pro 8600 Hilfe (HKLM-x32\...\{FDE820DD-CC88-4395-AD5C-801365B8F316}) (Version: 28.0.0 - Hewlett Packard)
HP Quick Start (HKLM-x32\...\{BB27C290-AB30-4D9E-A5D1-88745AAE42E9}) (Version: 1.0.4660.30220 - Hewlett-Packard)
HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.4.19.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 12.00.0000 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\...\{B1AD4FFB-DD17-43EC-8C30-B9E71EAD9132}) (Version: 12.7.27.15 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.10.0.001 - HTC Corporation)
HTC Sync Manager (HKLM-x32\...\{368E4EF8-E840-40EE-A224-50B8D1DC2B12}) (Version: 2.4.11.0 - HTC)
HydraVision (HKLM-x32\...\{866A5B13-0B3E-9402-9D1D-62E33DC1F21D}) (Version: 4.2.236.0 - Advanced Micro Devices, Inc.) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6435.0 - IDT)
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC)
Lexware EasyArchive 2017 (HKLM-x32\...\{C0C53938-408C-4CFB-BE8E-C95AC7E1BAA8}) (Version: 1.00.00.0007 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware Elster (HKLM-x32\...\{A8877DD0-6474-4AA3-8998-64F83844622E}) (Version: 17.03.00.0307 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware Elster 2017 (HKLM-x32\...\{c2bd713f-8377-4bac-8e60-fcf27567e0fe}) (Version: 17.3.0.208 - Haufe-Lexware GmbH & Co.KG)
Lexware financial office 2017 (HKLM-x32\...\{41AA3D63-FD67-41FA-B8D6-C66427EB6F54}) (Version: 21.51.00.0363 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware financial office plus 2017 (HKLM-x32\...\{c08ee6de-3502-40c8-84e5-257a2babb64c}) (Version: 21.51.0.261 - Haufe-Lexware GmbH & Co.KG)
Lexware Formular-Update 2014 (HKLM-x32\...\Lexware Formular-Update 2014_is1) (Version: 14.00 - Haufe-Lexware GmbH & Co. KG)
Lexware Info Service (HKLM-x32\...\{73681446-EE9F-47DF-9185-4BB6B985F743}) (Version: 17.00.00.0028 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware Installations Dienst (HKLM-x32\...\{3E7D13DE-D424-4AF6-A2DD-2E28506844E7}) (Version: 5.03.00.0048 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware lohn+gehalt Diagnose (HKLM-x32\...\{63EA36B6-341B-4AE9-BBBC-2F24E2DDC96C}) (Version: 4.00.00.0082 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware online banking (HKLM-x32\...\{2A594C9D-3011-4628-A524-1D5B7181C0A9}) (Version: 24.01.00.0124 - Haufe-Lexware GmbH & Co.KG)
Lexware PDF-Export 5 (HKLM-x32\...\{D6604FDD-E71F-40CA-9764-98649EC969DD}) (Version: 5.50.01.0011 - Haufe-Lexware GmbH & Co.KG) Hidden
Licensing Service (03000201) (HKLM-x32\...\{9F9C5C18-9665-41EC-A660-5A3BA213CA1D}) (Version: 03.00.02.15 - Protexis Inc.) Hidden
Malwarebytes Version 3.2.2.2018 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2018 - Malwarebytes)
Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.8326.2076 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (HKLM-x32\...\{76DAEC83-AF7B-333C-8A53-83D7C7D39199}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 54.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 de)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
Naviextras Toolbox Prerequesities (HKLM-x32\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 22.10.0.85 - Symantec Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0407-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
PDF24 Creator 7.9.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Pivot Pro Plugin (HKLM-x32\...\{0217E1D1-BCEF-4A61-AF6D-F7740F65A066}) (Version: 9.50.110 - Portrait Displays, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28137 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5530 - CyberLink Corp.) Hidden
SDK (HKLM-x32\...\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}) (Version: 2.28.007 - Portrait Displays, Inc.) Hidden
Skype™ 7.15 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.15.102 - Skype Technologies S.A.)
Studie zur Verbesserung von HP Officejet Pro 8600 Produkten (HKLM\...\{B9824225-2055-4700-BCD4-64B25EC88264}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
sv.net (HKLM-x32\...\sv.net) (Version: 17.0 - ITSG GmbH)
TomTom MyDrive Connect 4.1.2.2862 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.2.2862 - TomTom)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WOLF Energiesparen + Datanorm (HKLM-x32\...\WOLF Datanorm (Minimalversion)_is1) (Version: - Wolf GmbH)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Günter\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1829671353-3276857950-888964810-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-07-10] (Cyberlink)
ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\NavShExt.dll [2017-07-15] (Symantec Corporation)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-07-10] (Cyberlink)
ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\NavShExt.dll [2017-07-15] (Symantec Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2012-08-21] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [PortraitDisplaysContextMenu] -> {8602BDD8-9780-4717-B89A-7F89AF75B2AB} => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\shellmenu64.dll [2010-05-13] (Portrait Displays, Inc.)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\buShell.dll [2017-07-14] (Symantec Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\NavShExt.dll [2017-07-15] (Symantec Corporation)
ContextMenuHandlers1_S-1-5-21-1829671353-3276857950-888964810-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-1829671353-3276857950-888964810-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-1829671353-3276857950-888964810-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Günter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-08-22] (Dropbox, Inc.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {116F652B-CC1C-4BE6-BD3E-F63787A0EEDA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {2350A495-6DA4-4F43-9BE8-7154EE8712E8} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-08] (Adobe Systems Incorporated)
Task: {39B7E973-7C5C-462D-8C1D-20BA068E586B} - System32\Tasks\HP AR Program Upload - 7d9e40fcb29044a5b2f7ed2833c3bebdf21f6cd2c71441dc95886d9a86b1b467 => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {423C85E6-6D75-425E-85EB-B372E75B171E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {55CE6AC0-05B4-40A0-AFD2-DD27FBF54E07} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Analyzer => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\SymErr.exe [2017-07-14] (Symantec Corporation)
Task: {55F4269F-53E3-4748-9822-13900D308411} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-08-14] (HP Inc.)
Task: {56C614AE-372C-4367-8197-34C998EEE587} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\WSCStub.exe [2017-07-15] (Symantec Corporation)
Task: {69C5BD21-5631-431A-95D9-C8BDA316AA58} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001UA => C:\Users\Günter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {6C36D764-5207-40AB-814A-4EBA43A19469} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {727C28B9-3480-4836-9314-BFC04E27FEFC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-08-23] ()
Task: {809CBFE0-C406-4D74-953A-9DA689166110} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-1829671353-3276857950-888964810-1001
Task: {83322215-737D-405B-964D-E68499BC6FD8} - System32\Tasks\HP AR Program Upload - c38cb29e0b7540de86461cdd4628883bc77644b433164df0bd9b07e071228ab0 => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {83EACF79-5428-482E-8989-6299A62E895D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {8A151225-2B20-4B29-BDD0-424C532AAC35} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-08-08] (Microsoft Corporation)
Task: {8C31E661-4000-4BDD-A801-0684236220FE} - System32\Tasks\HP AR Program Upload - 91c78c4685f546b7979e592ab3b0f7c219d3cd8cff6d4757b3c60204214085f7 => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {8EB8B43D-67B8-4FBB-824D-011B838EE065} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Processor => C:\Program Files\Norton Internet Security\Engine\22.10.0.85\SymErr.exe [2017-07-14] (Symantec Corporation)
Task: {914040FF-2192-47DB-8780-1E250C7ED6C9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {A99993D6-D849-4693-A769-D32076AC3F2F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-08-12] (Microsoft Corporation)
Task: {AF47A272-5B68-4E22-AD02-46FC22FF70B2} - System32\Tasks\HP AR Program Upload - 4b187a92b7b945b78659c800a69c68cd74fcb340a75f4d8e86dba24dfcd503ea => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {B1AAD25E-53B2-45E5-B8E9-2D35331238DC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {B2CEE281-B3E7-4B13-ACBC-FA9E1226B6DF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-08-23] ()
Task: {BE6E464A-1A6E-4429-B58E-8E88E2BCEF27} - System32\Tasks\HPCeeScheduleForGünter => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {BF2AC407-C36F-4823-8F70-C32384FDDE27} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-08-12] (Microsoft Corporation)
Task: {BF6A46FB-09FA-4A1B-9519-7972739A592D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-08-14] (HP Inc.)
Task: {C25BA188-642D-4784-9EDF-650C3FFF7AB7} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2017-07-15] (Symantec Corporation)
Task: {D435C2D9-ED0A-4D81-B919-90E6A6669ACD} - System32\Tasks\HP AR Program Upload - 3fa6208a3b6840309b3c20316354e7aef6f31f647f35421881e6ab485fa86537 => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {DC8B1688-7E3C-47E8-9356-B3520C58BEE7} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001Core => C:\Users\Günter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {E6632DFB-595E-4751-A6E3-BFE67C1DF2E1} - System32\Tasks\HP AR Program Upload - 4980e50e6fed45f1987c3a2ded465c48466ea7f1f73c442caa1c0116e33143c6 => C:\Program Files\HP\HP Officejet Pro 8600\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {E91870AE-D7ED-4286-9CEA-A5182251587F} - System32\Tasks\HPCustParticipation HP Officejet Pro 8600 => C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {EBF7CD02-8472-496D-AF8A-92536977C5CF} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {F07547AE-72B5-4150-A9F7-6DDF0C649A51} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {F32CD3CB-6D7D-4E33-A503-430D52F4FE7A} - System32\Tasks\{8BF290A2-9639-4414-B6B9-C6C62F353939} => C:\windows\system32\pcalua.exe -a "C:\Program Files (x86)\HP\Digital Imaging\{49C2B7C1-A4E7-4770-8E30-255795AD4712}\setup\hpzscr40.exe" -c -datfile hpwscr22.dat -onestop -forcereboot
Task: {FC33FAA9-7498-4235-B8B2-CF7B318F16D4} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-08-23] (Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001Core.job => C:\Users\Günter\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1829671353-3276857950-888964810-1001UA.job => C:\Users\Günter\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForGünter.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Verknüpfungen & WMI ========================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2013-03-22 12:27 - 2013-03-22 12:27 - 000049368 _____ () c:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
2012-12-07 19:27 - 2012-12-07 19:27 - 000167424 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2017-08-23 18:49 - 2017-08-21 07:20 - 002264520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2012-12-30 08:20 - 2012-08-16 19:12 - 000268880 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dthook.dll
2013-11-14 22:32 - 2013-11-14 22:32 - 000821600 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
2012-12-30 08:21 - 2010-05-13 18:34 - 000674928 _____ () C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
2012-12-30 08:21 - 2012-08-16 19:12 - 000161360 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
2012-12-30 08:21 - 2012-08-16 19:12 - 000194640 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
2013-11-14 22:30 - 2013-11-14 22:30 - 000031080 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll
2013-11-14 22:31 - 2013-11-14 22:31 - 000607376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll
2013-11-14 22:31 - 2013-11-14 22:31 - 000044392 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll
2013-11-14 22:31 - 2013-11-14 22:31 - 000036216 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
2013-11-14 22:31 - 2013-11-14 22:31 - 000080248 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll
2013-11-14 22:33 - 2013-11-14 22:33 - 000129376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\zlib1.dll
2013-11-14 22:34 - 2013-11-14 22:34 - 000223592 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll
2017-08-23 20:30 - 2017-08-22 18:55 - 000757568 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll
2017-08-23 20:30 - 2017-08-22 18:55 - 001787200 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\dropbox_crashpad.dll
2017-08-23 20:30 - 2017-08-22 18:53 - 000100296 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000018888 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\select.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000020800 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000035792 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2017-08-23 20:30 - 2017-08-22 18:56 - 000021848 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000125904 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000694224 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2017-08-23 20:30 - 2017-08-22 18:56 - 001862992 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2017-08-23 20:30 - 2017-08-22 18:56 - 000022864 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000145864 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2017-08-23 20:30 - 2017-08-22 18:55 - 000116688 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2017-08-23 20:30 - 2017-08-22 18:53 - 000105928 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32api.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000022864 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000062784 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000040248 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\fastpath.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000024528 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32event.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000020936 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000124880 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32file.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000116176 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32security.pyd
2017-08-23 20:30 - 2017-08-22 18:55 - 000392656 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2017-08-23 20:30 - 2017-08-22 18:57 - 000392512 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000026456 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000024016 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000175560 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32gui.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000030160 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000043472 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32process.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000048592 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32service.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000057808 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2017-08-23 20:30 - 2017-08-22 18:56 - 000022336 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000082264 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winenumhandles.compiled._WinEnumHandles.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000025432 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 003928896 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000083912 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\sip.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 001826104 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 001972024 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000028616 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32ts.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000024016 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32profile.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000171336 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000042816 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000531264 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000133432 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000224064 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000207680 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000060880 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\win32print.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000054608 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000022864 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000022872 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000021848 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000022872 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd
2017-08-23 20:30 - 2017-08-22 18:56 - 000027488 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-08-23 20:30 - 2017-08-22 18:53 - 000349128 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000103232 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtWinExtras.pyd
2017-08-23 20:30 - 2017-08-22 18:58 - 000023896 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000025936 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2017-08-23 20:30 - 2017-08-22 18:55 - 000036296 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\librsync.dll
2017-08-23 20:30 - 2017-08-22 18:56 - 000181056 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2017-08-23 20:30 - 2017-08-22 18:57 - 000030536 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000024368 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\libEGL.dll
2017-08-23 20:30 - 2017-08-22 18:57 - 001637688 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2017-08-23 20:30 - 2017-08-22 18:57 - 000026456 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000023368 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\wincrashpad.compiled._Crashpad.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000546104 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2017-08-23 20:30 - 2017-08-22 18:57 - 000357688 _____ () C:\Users\Günter\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2012-12-30 08:24 - 2012-06-08 05:34 - 000627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 13:34 - 2012-06-08 13:34 - 000016400 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2012-12-30 08:21 - 2012-01-17 18:21 - 000068104 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\PEGAACPIDLL.dll
2012-12-30 08:21 - 2011-02-15 13:59 - 000015624 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\ACPIDll.dll
2016-08-25 17:45 - 2016-08-25 17:45 - 000174560 _____ () C:\Program Files (x86)\Lexware\Update Manager\Haufe.Core.Diagnostics.Logging.Targets.Etw.dll
2016-08-25 17:45 - 2016-08-25 17:45 - 000041440 _____ () C:\Program Files (x86)\Lexware\Update Manager\Haufe.Core.Diagnostics.Etw.dll
2012-12-30 08:20 - 2012-08-16 18:53 - 000180224 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\PresetsCOM.dll
2013-07-15 11:48 - 2013-07-15 11:48 - 001199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 15:25 - 2013-08-22 15:25 - 000000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Günter\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\hp_svinoya_norway_sunset.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
HKLM\...\StartupApproved\StartupFolder: => "Bluetooth.lnk"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "BeatsOSDApp"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk"
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\StartupApproved\Run: => "MyDriveConnect.exe"
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\StartupApproved\Run: => "Amazon Music"
HKU\S-1-5-21-1829671353-3276857950-888964810-1001\...\StartupApproved\Run: => "Skype"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{263A109C-29EA-462F-A56E-115FC7FCE05E}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{104048D4-4EC7-4765-8ABB-096C8FE2F58A}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{E0C62721-8A82-4823-A525-CB83915686FF}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{2AA8AEFC-4EF5-4BE8-B409-D096EE507B2D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{5A588215-B20C-4880-910A-3D8D60979DF6}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{F48995DF-602D-48C9-9F82-6736F8C0B163}] => (Allow) C:\Users\Günter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{B60E108C-752A-40E5-BDAC-7A347E20413C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\{49C2B7C1-A4E7-4770-8E30-255795AD4712}\setup\hpznui40.exe
FirewallRules: [{4712B7A3-D126-455C-B4CC-D36CC7EFE2A8}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{A8F83780-65AB-41A5-905C-9F4E6F2FBB67}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{C13E9766-7437-4078-B75F-9C6DB3B7C646}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{4C5EEEBE-FC89-42A0-96E2-378DEB763666}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{216FECD9-B5DA-4F36-AD9D-017001416833}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{A0410B55-5B33-4008-BAC3-8B1C0E1EBB24}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{F0BC71EF-44F6-47B4-AD52-5C5C2CC32DBD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{4FA0DB73-BC3A-4453-88D5-248C5B14EC12}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{1F0D1C60-E2EA-478A-A196-F214BB70AC6F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{7756DA8F-C97D-4C0B-80D2-C9372540B5D2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{5CF17A91-AA19-4D16-98F3-9255A041CB6F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{E6A73E4F-1BA3-49D0-A8F8-1C790A209D59}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{AEC0AB6C-1935-4974-AF1C-6F1CA1C940CC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{100E13C6-53BB-490D-9DFA-D383F5F7B341}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{92829AC8-A403-4760-8F2A-E1DF6B646C22}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{4400D6A6-4613-47D0-8B8F-D4C6F0DB4F2E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{EB502B45-214C-4287-8651-C1CBA242B4F3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{C4BFB9A5-AEAE-4569-B0C4-15B860B619AD}] => (Allow) LPort=1900
FirewallRules: [{CF5619AC-0F03-4292-ABDD-69068E9A5171}] => (Allow) LPort=2869
FirewallRules: [{C7FF4D7A-0951-4AD1-9013-674C61EA6D87}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BBBF4208-073D-436D-903E-22B61877BDC3}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{46F6F234-C8A4-4C85-9146-9F07BA0B608C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{583385C0-DCF5-4119-B61D-5261F8368348}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{463B6628-23CD-48C7-A1CA-6E806E21004A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0365077C-42D5-47FB-B27C-811BBDE6F88C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B64BC49B-CEDC-4BA4-B44B-C77533C454A5}] => (Allow) C:\Program Files (x86)\HTC\HTC Sync Manager\HTCSyncManager.exe
FirewallRules: [{C6932342-27C5-4816-9D39-D66127E8DB3D}] => (Allow) C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
FirewallRules: [{50E0D49C-1E9E-48E9-AD23-5420CD945C31}] => (Allow) C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
FirewallRules: [{3A6281B4-F0FD-481C-AEA3-5ECE610EBEC6}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\FaxApplications.exe
FirewallRules: [{AE82FF80-AAE3-43F3-B44B-8180FF16AE40}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\DigitalWizards.exe
FirewallRules: [{DCE3FDD2-B98E-485A-A96E-9E4B09AAAD58}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\SendAFax.exe
FirewallRules: [{DF29B015-0151-4FAF-8171-A256318FC6E8}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\DeviceSetup.exe
FirewallRules: [{DD6E9E6F-7A61-4E06-B322-610FEC0E5E78}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
FirewallRules: [{BD32652D-8CA7-4AB2-A30D-063FA2B4FCDD}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{0CA585C7-7494-4FEA-9C3B-93CC046543A5}] => (Allow) C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{84BDD1DE-2EB3-4AC4-94A1-AE2EEBC039E8}] => (Allow) C:\Users\Günter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{9B8CA255-FEAC-4DF6-BCCF-A157B13C2148}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{44B82284-36DC-4AA0-9043-3086E134B36A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{1EEC38EF-DD3E-4793-AA85-43EE8E8D8AC7}C:\users\günter\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\günter\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{14514D4A-22A5-48C8-92B7-3B09B48767ED}C:\users\günter\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\günter\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{817AB1C5-761E-4C27-9357-8974C1725CE8}] => (Allow) LPort=52000
FirewallRules: [{58B7199F-4CEA-4281-9EE5-D851D54D7454}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E66FD9E3-72E4-4822-9C9C-C8ADC6EDCB33}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6369EFEB-631D-4F6C-ABB5-79E6AC67375B}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [TCP Query User{E0B16434-9EE4-4FDD-89C4-38F3011A8A18}C:\program files (x86)\hewlett-packard\hp support solutions\modules\hpdevicedetection3.exe] => (Block) C:\program files (x86)\hewlett-packard\hp support solutions\modules\hpdevicedetection3.exe
FirewallRules: [UDP Query User{7744A3E4-2FD4-458F-97BB-822B47D1C9F6}C:\program files (x86)\hewlett-packard\hp support solutions\modules\hpdevicedetection3.exe] => (Block) C:\program files (x86)\hewlett-packard\hp support solutions\modules\hpdevicedetection3.exe
FirewallRules: [{494BE862-09D6-4E05-A988-C7E8BE5B937C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{42A0CE8F-5B76-4994-9027-67E49E5B47B7}] => (Allow) LPort=53000
==================== Wiederherstellungspunkte =========================
08-08-2017 22:32:33 Windows Update
16-08-2017 10:31:00 Geplanter Prüfpunkt
23-08-2017 21:09:51 Geplanter Prüfpunkt
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (08/24/2017 09:20:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x2460
Startzeit der fehlerhaften Anwendung: 0x01d31d0d29f9dcff
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 59ea0a45-8901-11e7-bf23-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 09:12:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x1c58
Startzeit der fehlerhaften Anwendung: 0x01d31d0ca2ed624a
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 33a6d7b7-8900-11e7-bf23-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 09:09:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x2570
Startzeit der fehlerhaften Anwendung: 0x01d31d0bf4040374
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: b4f2b318-88ff-11e7-bf23-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 09:05:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x23b0
Startzeit der fehlerhaften Anwendung: 0x01d31d0b8fbfd9af
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 2ebcbc50-88ff-11e7-bf23-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 09:02:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x1940
Startzeit der fehlerhaften Anwendung: 0x01d31cf61e69eff7
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: c235b1f7-88fe-11e7-bf23-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 06:17:52 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Error: (08/24/2017 06:09:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x2a18
Startzeit der fehlerhaften Anwendung: 0x01d31ce260a12b48
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 90bc9286-88e6-11e7-bf22-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/24/2017 06:08:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 16.0.8326.2076, Zeitstempel: 0x598eaf6c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.18725, Zeitstempel: 0x593806da
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000e61f4
ID des fehlerhaften Prozesses: 0x2b5c
Startzeit der fehlerhaften Anwendung: 0x01d31ce7f9a04c4d
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: 7a2d3209-88e6-11e7-bf22-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/23/2017 07:32:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x14d8
Startzeit der fehlerhaften Anwendung: 0x01d31c34141f14e7
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 1178be18-8829-11e7-bf22-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/23/2017 07:19:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 54.0.1.6388, Zeitstempel: 0x5953d1f8
Name des fehlerhaften Moduls: KERNEL32.DLL, Version: 6.3.9600.17415, Zeitstempel: 0x545049be
Ausnahmecode: 0x80000003
Fehleroffset: 0x00018b81
ID des fehlerhaften Prozesses: 0x17f8
Startzeit der fehlerhaften Anwendung: 0x01d31c337b048bb6
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\KERNEL32.DLL
Berichtskennung: 386a1ca4-8827-11e7-bf22-446d57854b7b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (08/25/2017 02:52:12 PM) (Source: Schannel) (EventID: 4102) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (08/25/2017 02:48:30 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" ist vom Dienst "Windows Search" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
Der Dienst wurde nicht gestartet.
Error: (08/25/2017 02:48:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\WINDOWS\System32\bcmihvsrv64.dll
Error: (08/25/2017 02:48:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\WINDOWS\System32\bcmihvsrv64.dll
Error: (08/25/2017 02:48:19 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\WINDOWS\System32\bcmihvsrv64.dll
Error: (08/25/2017 02:48:05 PM) (Source: Schannel) (EventID: 4102) (User: NT-AUTORITÄT)
Description: Schwerwiegender Fehler beim Zugriff auf den privaten Schlüssel der Anmeldeinformationen Server für SSL. Der vom kryptografischen Modul zurückgegebene Fehlercode lautet 0x8009030d. Der interne Fehlerstatus ist 10001.
Error: (08/25/2017 02:48:00 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (08/25/2017 02:48:00 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (08/25/2017 02:47:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "HTCMonitorService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (08/25/2017 02:47:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5-3330S CPU @ 2.70GHz
Prozentuale Nutzung des RAM: 46%
Installierter physikalischer RAM: 6080.82 MB
Verfügbarer physikalischer RAM: 3254.59 MB
Summe virtueller Speicher: 6480.82 MB
Verfügbarer virtueller Speicher: 3332.74 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:1819.36 GB) (Free:1689.19 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Recovery Image) (Fixed) (Total:11.84 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: F05B29F6)
Partition: GPT.
==================== Ende von Addition.txt ============================ |