Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 11-10-2017
durchgeführt von Peter (14-10-2017 08:58:06)
Gestartet von D:\Users\Peter\Downloads
Windows 10 Pro Version 1703 170317-1834 (X64) (2017-05-17 08:22:52)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-2926960992-1055115158-727447495-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2926960992-1055115158-727447495-503 - Limited - Disabled)
Gast (S-1-5-21-2926960992-1055115158-727447495-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2926960992-1055115158-727447495-1002 - Limited - Enabled)
Peter (S-1-5-21-2926960992-1055115158-727447495-1000 - Administrator - Enabled) => C:\Users\Peter
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
64 Bit HP CIO Components Installer (HKLM\...\{55D55008-E5F6-47D6-B16F-B2A40D4D145F}) (Version: 6.2.1 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.159 - Adobe Systems Incorporated)
Amazon Music (HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\Amazon Amazon Music) (Version: 4.3.2.1367 - Amazon Services LLC)
ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOMEI Backupper Standard (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536CE9D}_is1) (Version: - AOMEI Technology Co., Ltd.)
Apple Application Support (32-Bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 11.2.2262 - AVAST Software)
AVM FRITZ!fax für FRITZ!Box (HKLM-x32\...\FRITZ! 2.0) (Version: - AVM Berlin)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Browser-Security (HKLM-x32\...\Browser-Security) (Version: 1.0.5.0 - ) <==== ACHTUNG
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
chip 1-click download service (HKLM-x32\...\{503CA94E-0834-4CEE-AD92-BA17AF4E809A}) (Version: 3.6.9.0 - Chip Digital GmbH)
CSR Harmony Wireless Software Stack (HKLM\...\{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}) (Version: 2.1.63.0 - CSR Plc.)
Desktopicon amazon.de (HKLM\...\DesktopIconAmazon) (Version: 1.0.1 - )
Dropbox (HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\Dropbox) (Version: 36.4.22 - Dropbox, Inc.)
Elevated Installer (HKLM-x32\...\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 18.1.22140 - Landesfinanzdirektion Thüringen)
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.6.124.715 - Foxit Software Inc.)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.2.5.930 - Foxit Software Inc.)
Free YouTube Download (HKLM-x32\...\Free YouTube Download_is1) (Version: 4.1.29.1027 - Digital Wave Ltd)
Free YouTube To MP3 Converter (HKLM-x32\...\Free YouTube To MP3 Converter_is1) (Version: 4.1.25.705 - Digital Wave Ltd)
Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\...\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin USB Drivers (HKLM\...\{DC7720F2-98BE-41C1-B0A8-E391362E86B8}) (Version: 2.3.1.1 - Garmin Ltd or its subsidiaries)
Gigaset QuickSync (HKLM\...\{192f673d-d310-4488-96da-4a4bfcd6ab2b}) (Version: 8.6.0875.1 - Gigaset Communications GmbH)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Hexenküche 5.0 (HKLM-x32\...\{9BE9E238-EEC8-430A-810E-664CF9A8DD03}) (Version: 5.0 - Software-Factory)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
IncrediMail (HKLM-x32\...\{C8842F80-0E07-4424-916D-9F6B6A9968E4}) (Version: 6.6.0.5288 - IncrediMail) Hidden
IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5288 - IncrediMail Ltd.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{35069AA3-F7B2-4759-96F0-9EE43AACB690}) (Version: 19.00.1621.3340 - Intel Corporation)
Java 8 Update 141 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180141F0}) (Version: 8.0.1410.15 - Oracle Corporation)
Kyocera Product Library (HKLM\...\Kyocera Product Library) (Version: 4.2.1909 - KYOCERA Document Solutions Inc.)
Lexmark Universal v2 Deinstallationsprogamm (HKLM\...\Lexmark Universal v2) (Version: - Lexmark International, Inc.)
Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA)
Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4963.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\OneDriveSetup.exe) (Version: 17.3.6998.0830 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{e6e75766-da0f-4ba2-9788-6ea593ce702d}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 56.0.1 (x64 de) (HKLM\...\Mozilla Firefox 56.0.1 (x64 de)) (Version: 56.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 56.0.1.6484 - Mozilla)
Mozilla Thunderbird 38.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.5.0 (x86 de)) (Version: 38.5.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4963.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4963.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0407-0000-0000000FF1CE}) (Version: 15.0.4963.1002 - Microsoft Corporation) Hidden
Passepartout-Rechner 2 Version 2.9.0.3 (HKLM-x32\...\{4F904A70-56F2-41B1-BC9B-7D55CB4C9FAD}_is1) (Version: 2.9.0.3 - Ulli Gabsch)
Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
PhotoSync (HKLM\...\{CECDB976-FC3E-49E1-8A47-DF447D8B4DBC}) (Version: 3.0.7 - touchbyte GmbH)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.140.248 - Google, Inc.)
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
SafeZone Stable 1.48.2066.101 (HKLM-x32\...\SafeZone 1.48.2066.101) (Version: 1.48.2066.101 - Avast Software) Hidden
SketchUp 2017 (HKLM\...\{5A8C61BD-0912-4B76-805E-4EDE5E13298C}) (Version: 17.1.174 - Trimble Navigation Limited)
TextMaker Viewer (HKLM-x32\...\TextMaker Viewer) (Version: - SoftMaker Software GmbH)
TomTom HOME (HKLM-x32\...\{B581E191-A2C1-4CE3-907E-9FE3C728750C}) (Version: 2.9.91 - Ihr Firmenname)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
TVgenial 5.50 (HKLM-x32\...\TVgenial) (Version: - )
Virtual WiFi Router version 3.0 (HKLM-x32\...\{F5F33265-5CAA-4F12-AA8F-7F8384BF2A57}_is1) (Version: 3.0 - Virtual WiFi Router, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
WhatsApp (HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\WhatsApp) (Version: 0.2.2732 - WhatsApp)
Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-Treiberpaket - Lexmark International Printer (05/03/2013 2.9.1.0) (HKLM\...\1E475DE70DA7DD9952D632639EB4729E88E705AC) (Version: 05/03/2013 2.9.1.0 - Lexmark International)
Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2926960992-1055115158-727447495-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-14] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-14] (AVAST Software)
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2015-08-31] (Foxit Software Inc.)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-14] (AVAST Software)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> Keine Datei
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Keine Datei
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-11-02] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-14] (AVAST Software)
ContextMenuHandlers1_S-1-5-21-2926960992-1055115158-727447495-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-2926960992-1055115158-727447495-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-2926960992-1055115158-727447495-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {083EBB74-96B9-4E44-B5DD-59149216CF36} - System32\Tasks\{532BA89F-CDAF-4371-BEC3-2B6746988EB4} => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Task: {0D331922-8FD7-4334-B99C-4C49304A4CE0} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {120C6F93-61ED-40ED-9E94-447DB83ECACB} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1398D37F-43B3-43CC-A367-68FEACF98E32} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {14D89C9C-EAAC-4D2E-8B72-CD51470E5173} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {16C04FF3-22AF-4837-A6DD-6A5AEFB28837} - System32\Tasks\{FD6B84DA-D2FB-4DFA-B473-81CED47F62ED} => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Task: {1FD09381-C915-41DF-B9D5-69F05F998A22} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {23B015AF-93E0-4824-839A-9EB81646896C} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {28F45B82-1F78-4E28-8E6D-00D0DAFF28A7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {29046124-EC6F-4B4A-B8C2-2F97EAFC1050} - System32\Tasks\{9F0CCA25-6AC1-4A5A-A40A-778D7CA99689} => C:\Windows\system32\pcalua.exe -a C:\Users\Peter\AppData\Local\Temp\Temp1_hexe5.zip\hexe5setup.exe <==== ACHTUNG
Task: {2A979D9B-B7B8-4B8D-AF85-71AA91C7446F} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2C5F4860-1CE2-44CF-B234-508FCFA6BBA7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2CE0C5B6-FADC-48C5-95CD-A2B9AA029DBF} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {32CECBBE-03A0-4588-AEEC-39E8D5AE03CC} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {43DC4DB6-2BC4-44E5-A080-602E91E29466} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {45304C37-520C-46AF-82AA-AAF84E653DCE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-11] (Adobe Systems Incorporated)
Task: {459ED182-8EB8-4096-A2FE-FDDDC56E85A6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {4891D40C-C8D6-47F1-BD6C-4CE40EA9A772} - System32\Tasks\{0DB46DD9-63D0-4539-8541-C15AD71F3EE9} => C:\Windows\system32\pcalua.exe -a D:\Users\Peter\Downloads\clear_flash.exe -d D:\Users\Peter\Downloads
Task: {4AB081A7-D88F-4C80-99E2-09ED4CDA5D38} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {54F11938-0824-4354-B3E5-68A88021FCBA} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56C6FCBB-35C9-4F78-B298-5FD82474F27F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {62D759C1-1A9C-4E74-8BD5-374F95DB5A4D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation)
Task: {6DEBADF5-E36A-4D85-B2FA-9316A17AA87B} - System32\Tasks\Sperrbildschirm deaktivieren => reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData /t REG_DWORD /v AllowLockScreen /d 0 /f
Task: {6F28D525-0699-4E85-AB2A-1EA900D6110A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-06-14] (AVAST Software)
Task: {70118257-A4CF-470A-963F-48471BE15900} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {704E3578-A832-4435-A76E-B6F21809B4B9} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-03-28] ()
Task: {7760C395-2576-492E-91AE-14F393A0877E} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {79455702-761A-41DA-A5C6-A645D93D6ECE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {81DD5037-786A-4FB6-9B10-FEB0B03B1FF4} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-11] (Microsoft Corporation)
Task: {90F772C7-55FE-43F6-B865-FA7BC50281FB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {977064DE-DC98-4867-A4B7-1B241509DA31} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {9A061D5B-8FA7-4115-80EA-3B9CD869A0C0} - System32\Tasks\{DE3265D1-982A-4558-966C-BA2D28E36764} => C:\Windows\system32\pcalua.exe -a D:\Users\Peter\Downloads\nw_22186_wdbackupexe.exe -d D:\Users\Peter\Downloads
Task: {9D989159-BC6C-472A-8682-300DC264C101} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {A21E4FBA-2289-4927-A11B-00DC7A314EDD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation)
Task: {A9C254AE-700E-42D0-A383-999E08879B30} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2926960992-1055115158-727447495-1000UA1d238f2cc775a38 => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {B30BB263-BD3F-49C1-9C28-3A763025A193} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {B8C8BD87-F208-461F-B5CF-5DB84FF17FD8} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG
Task: {B907D8D7-02D9-4548-BF4C-9242FEAAA572} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2926960992-1055115158-727447495-1000Core1d238f2cc729583 => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {BB284631-740C-416A-901E-5B168A9F3821} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CD22ACB3-31F3-4296-88DF-C672A4196AC5} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D167A38D-4C68-4207-8D25-308CAFDFB67F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {D4A0DD0E-C4CC-4233-B291-10FAA3AA0F58} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {DB57341D-FCEF-4D46-A1EA-63BC088EBDB0} - System32\Tasks\avastBCLRestartS-1-5-21-2926960992-1055115158-727447495-1000 => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Task: {DDB55E3F-FDC7-47A6-AA78-B6F2304E0030} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {E20EF8DE-7B30-4B73-951E-BA58F5256FE0} - System32\Tasks\SafeZone scheduled Autoupdate 1446590296 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software)
Task: {E5505448-7B21-4037-B83D-E1F2EEC0F7DA} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E5A74249-2B38-4CD6-A3B2-868E71AF6C2A} - System32\Tasks\Intel(R) Small Business Advantage\Notifier => C:\Program Files\Intel\Intel(R) Small Business Advantage\UI\SBA_Notifier.exe [2013-03-13] (Intel Corporation)
Task: {ED5ED8F9-B038-4C7D-935D-8FC717A3E933} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EF8ADCBE-9AF9-45B2-909A-23467FB9A847} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {EFA44714-8575-41BC-93F0-16A5A77461ED} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-07-12] (AVAST Software)
Task: {F1706E15-B721-490B-AF63-F12D749EB65C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {FBD06206-ABD3-4E81-ADAB-E5E5BD45DC19} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2926960992-1055115158-727447495-1000Core1d238f2cc729583.job => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2926960992-1055115158-727447495-1000UA1d238f2cc775a38.job => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe
==================== Verknüpfungen & WMI ========================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2016-06-14 19:08 - 2016-06-14 19:08 - 000137920 _____ () C:\Program Files\AVAST Software\Avast\x64\log.dll
2016-09-14 11:35 - 2006-02-23 11:35 - 000020480 _____ () C:\WINDOWS\System32\FritzColorPort64.dll
2016-09-14 11:35 - 2006-02-22 10:39 - 000020480 _____ () C:\WINDOWS\System32\FritzPort64.dll
2017-07-26 09:58 - 2017-07-26 09:58 - 000192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2016-07-05 15:23 - 2016-07-05 15:23 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-08-01 18:31 - 2013-08-01 18:31 - 000198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2013-08-01 18:31 - 2013-08-01 18:31 - 000054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-08-01 18:31 - 2013-08-01 18:31 - 000034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2014-02-03 20:49 - 2010-04-05 21:55 - 000116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2014-03-20 22:14 - 2017-01-17 04:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2017-03-18 22:58 - 2017-03-18 22:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-03-18 22:59 - 2017-03-20 06:43 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-08-23 10:28 - 2017-08-23 10:28 - 000074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-08-23 10:28 - 2017-08-23 10:28 - 000203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-08-23 10:28 - 2017-08-23 10:28 - 036162048 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-08-23 10:28 - 2017-08-23 10:28 - 002237952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\skypert.dll
2012-03-22 21:11 - 2012-03-22 21:11 - 000244944 _____ () C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe
2015-11-19 22:06 - 2016-06-16 22:05 - 005908968 _____ () C:\Users\Peter\AppData\Local\Amazon Music\Amazon Music Helper.exe
2016-12-06 16:09 - 2016-12-06 16:09 - 000061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000089968 _____ () C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe
2016-06-14 19:08 - 2016-06-14 19:08 - 000123344 _____ () c:\program files\avast software\avast\log.dll
2016-06-14 19:08 - 2016-06-14 19:08 - 000135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-10-13 15:51 - 2017-10-13 15:51 - 005880576 _____ () c:\program files\avast software\avast\defs\17101306\algo.dll
2016-06-14 19:08 - 2016-06-14 19:08 - 000309912 _____ () c:\program files\avast software\avast\browser_pass.dll
2017-02-14 09:42 - 2017-02-14 09:42 - 000326144 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll
2017-03-28 15:32 - 2017-03-28 15:32 - 000073216 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll
2016-08-21 10:58 - 2016-08-31 20:04 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
2016-08-21 10:58 - 2016-10-27 13:20 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
2016-08-21 10:58 - 2016-10-27 13:20 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
2016-08-21 10:58 - 2016-10-27 13:20 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000327536 _____ () C:\Program Files (x86)\AOMEI Backupper\Comn.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000937840 _____ () C:\Program Files (x86)\AOMEI Backupper\UiLogic.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000253800 _____ () C:\Program Files (x86)\AOMEI Backupper\diskmgr.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000135016 _____ () C:\Program Files (x86)\AOMEI Backupper\FuncLogic.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000040808 _____ () C:\Program Files (x86)\AOMEI Backupper\Encrypt.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000360304 _____ () C:\Program Files (x86)\AOMEI Backupper\ImgFile.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000495464 _____ () C:\Program Files (x86)\AOMEI Backupper\EnumFolder.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000081768 _____ () C:\Program Files (x86)\AOMEI Backupper\Compress.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000114536 _____ () C:\Program Files (x86)\AOMEI Backupper\BrLog.dll
2017-01-04 10:22 - 2015-05-20 23:32 - 002403504 _____ () C:\Program Files (x86)\AOMEI Backupper\QtCore4.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000089960 _____ () C:\Program Files (x86)\AOMEI Backupper\Ldm.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000073584 _____ () C:\Program Files (x86)\AOMEI Backupper\Device.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000298856 _____ () C:\Program Files (x86)\AOMEI Backupper\BrFat.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000978792 _____ () C:\Program Files (x86)\AOMEI Backupper\BrNtfs.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000294760 _____ () C:\Program Files (x86)\AOMEI Backupper\Clone.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000126824 _____ () C:\Program Files (x86)\AOMEI Backupper\Backup.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000167784 _____ () C:\Program Files (x86)\AOMEI Backupper\FlBackup.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000720752 _____ () C:\Program Files (x86)\AOMEI Backupper\Sync.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000114536 _____ () C:\Program Files (x86)\AOMEI Backupper\BrVol.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000266088 _____ () C:\Program Files (x86)\AOMEI Backupper\GptBcd.dll
2017-01-04 10:22 - 2016-12-23 17:53 - 000188264 _____ () C:\Program Files (x86)\AOMEI Backupper\DeviceMgr.dll
2013-11-23 21:25 - 2011-01-13 11:44 - 000232800 _____ () C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\PATCHW32.dll
2017-06-20 12:11 - 2017-06-20 12:11 - 000325824 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2015-05-01 19:17 - 2015-05-01 19:17 - 001754296 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\tmpod.dll
2017-09-23 20:46 - 2017-08-15 12:21 - 001041608 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\ADDINS\UmOutlookAddin.dll
2015-12-16 20:17 - 2015-12-16 20:17 - 040539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-10-05 11:47 - 2017-10-03 12:21 - 000771904 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll
2017-10-05 11:47 - 2017-10-03 12:21 - 001804608 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\dropbox_crashpad.dll
2015-12-11 20:12 - 2017-10-03 12:21 - 000100296 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000018888 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\select.pyd
2015-12-11 20:12 - 2017-10-03 12:22 - 000020800 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000035792 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000694224 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000021848 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000130512 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 001856848 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000145864 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000116688 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2015-12-11 20:12 - 2017-10-03 12:21 - 000105928 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32api.pyd
2016-08-05 21:24 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000062784 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000024528 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32event.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000040248 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\fastpath.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000020936 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000124880 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32file.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000116176 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32security.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000392656 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2015-12-11 20:12 - 2017-10-03 12:22 - 000392512 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2016-08-05 21:24 - 2017-10-03 12:22 - 000026456 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000024016 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000175560 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32gui.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000030160 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000043472 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32process.pyd
2017-09-22 07:54 - 2017-10-03 12:21 - 000026056 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32job.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000048592 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32service.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000057808 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000021824 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2017-09-08 20:57 - 2017-10-03 12:22 - 000023368 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winshell.compiled._winshell.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000022856 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\crashpad.compiled._Crashpad.pyd
2017-05-18 00:44 - 2017-10-03 12:22 - 000066392 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winenumhandles.compiled._WinEnumHandles.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 001796920 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000084424 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\sip.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 001956152 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 003859264 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000154440 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000521024 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000045888 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineCore.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000042304 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000131384 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000218944 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000204096 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2015-12-11 20:12 - 2017-10-03 12:22 - 000025432 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000060880 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32print.pyd
2017-02-28 09:48 - 2017-10-03 12:22 - 000054608 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000024016 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32profile.pyd
2017-01-24 01:55 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd
2016-04-14 13:35 - 2017-10-03 12:22 - 000069968 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\windisplaytoast.compiled._DisplayToast.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000028616 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\win32ts.pyd
2017-01-24 01:55 - 2017-10-03 12:22 - 000022360 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-01-24 01:55 - 2017-10-03 12:22 - 000021848 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd
2017-01-24 01:55 - 2017-10-03 12:22 - 000022360 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000027488 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2015-12-11 20:12 - 2017-10-03 12:21 - 000349128 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000101184 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWinExtras.pyd
2016-02-12 18:03 - 2017-10-03 12:22 - 000023896 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000025424 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000036296 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\librsync.dll
2017-10-05 11:47 - 2017-10-03 12:22 - 000032600 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\enterprise_data.compiled._enterprise_data.pyd
2017-10-05 11:47 - 2017-10-03 12:21 - 000293392 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\EnterpriseDataAdapter.dll
2017-10-05 11:47 - 2017-10-03 12:22 - 000181056 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2016-07-11 20:09 - 2017-10-03 12:22 - 000030536 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000024368 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\libEGL.DLL
2017-10-05 11:47 - 2017-10-03 12:22 - 001638200 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2016-08-05 21:24 - 2017-10-03 12:22 - 000026456 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000545080 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000359224 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2017-10-05 11:47 - 2017-10-03 12:22 - 000038208 _____ () C:\Users\Peter\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngine.pyd
2013-11-23 21:36 - 2013-05-17 01:05 - 001199576 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
IE trusted site: HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\garmin.com -> hxxps://my.garmin.com
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2017-03-23 00:24 - 000000039 _____ C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-2926960992-1055115158-727447495-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Peter^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: HotKeysCmds => "C:\Windows\system32\hkcmd.exe"
MSCONFIG\startupreg: IgfxTray => "C:\Windows\system32\igfxtray.exe"
MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
MSCONFIG\startupreg: IncrediMail => C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
MSCONFIG\startupreg: Persistence => "C:\Windows\system32\igfxpers.exe"
MSCONFIG\startupreg: RTHDVCPL => "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Super-Charger => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKU\S-1-5-21-2926960992-1055115158-727447495-1000\...\StartupApproved\Run: => "GarminExpressTrayApp"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{8CBEE309-7884-43B7-9187-C32014323857}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{E39EA5F7-D503-45A9-B516-B09B6879E55D}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{18AC6D5E-CB81-4438-A6AC-384DAFBC5E75}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{C385998B-BDEF-4C10-BBB0-10A8976A6AA7}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{7A1D85FE-22A3-40E4-A324-253AEC957674}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{35A2EA53-0148-474C-9950-028B8BA6B2A8}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{2BAD8DDC-C8B7-4013-AFEC-366955E9E25A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{538BD871-97F5-426C-87FB-2BD1E14A3670}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{C8CF3BAD-9C08-411C-B40B-9D291B21D26E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{06A33A53-5BEC-4E72-BEF5-B212505DF3D0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{BF164692-E917-4179-A22A-BC2761A79C78}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C8CD12DA-58FC-46CA-BE8B-8D6554392E36}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{76A68012-03DA-462E-A8C3-74C2890AC087}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{C9DE9B1F-9D3B-4D63-BA2E-6C310ABB9355}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{D41D6F57-E3ED-4DC9-8D6C-E0BB527AA6FF}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{2CECE47B-1F70-4F22-A436-7384446A050D}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{85BFA666-AC49-4119-9847-F024539B4B60}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{E1AC3D73-DB8B-44F6-9ADE-4F087FBF77B6}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{3A911DC3-F452-420A-9959-8CE611807258}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [UDP Query User{A6820E05-014A-42C0-9325-D1A9BA28DDDA}C:\users\peter\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\peter\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{1BFDC15D-5E1F-4041-B982-D8B04293266B}C:\users\peter\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\peter\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{A315FD63-A9E9-413A-9D2D-848848CB93E7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{D08D4CEC-76E1-4662-BC41-0B010E8F605A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{D92DBB30-03F7-4674-9076-2A204551C905}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{2E8D6CEF-36FA-406A-8659-8D9375E9A288}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{E342D332-10AD-4FAD-9E1B-DD58A36EFACA}] => (Allow) C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6C33D454-E513-4A5F-91EF-86C981220EAD}] => (Allow) C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{4F8D723E-D2A2-4A8C-8C49-2806E53E630F}] => (Allow) C:\Program Files (x86)\TV-Browser\tvbrowser_noDD.exe
FirewallRules: [{6FEE408A-08BE-4690-AAB5-02A3F647BDCE}] => (Allow) C:\Program Files (x86)\TV-Browser\tvbrowser_noDD.exe
FirewallRules: [{10D50A56-52DC-40C8-9ECC-E83E8DCFF213}] => (Allow) C:\Program Files (x86)\TV-Browser\tvbrowser.exe
FirewallRules: [{13962A41-D282-485C-9F3F-704672A2865A}] => (Allow) C:\Program Files (x86)\TV-Browser\tvbrowser.exe
FirewallRules: [{FB690228-5A26-4FE1-A104-6E587DE06C29}] => (Allow) C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe
FirewallRules: [{0A06D223-D0A3-4E23-8FCA-82C435BE6E73}] => (Allow) C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe
FirewallRules: [{2CD95023-BF5F-4AD9-A7E8-51619388D5A5}] => (Allow) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
FirewallRules: [{8451C290-172D-4F91-B345-3073E370236F}] => (Allow) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
FirewallRules: [{1583926A-3727-473E-9AA6-5267E29F7272}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{76677CF6-83FB-46C8-836A-7BE173B0AE4F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{682BDE92-8AC7-46CF-9E74-7B664419D440}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{75F6CB5D-B160-4D4B-9AA8-AC8863A66DBD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{38D9AE4D-06D1-4A20-998E-EEE8291DCAEE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DF6E5480-7C51-45F5-A073-824F3CB00015}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8C85A527-B0F5-4D02-8728-4F190D6CFFCA}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{ED4D1BEA-88AF-4CAF-AC92-EF812514B449}] => (Allow) C:\Program Files (x86)\Virtual WiFi Router\VirtualWiFiRouterLibrary.dll
FirewallRules: [{C849AC2A-DDAA-44A9-8879-F7AF95312042}] => (Allow) LPort=35722
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (10/14/2017 08:55:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 10.0.15063.0, Zeitstempel: 0x02799ef5
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.15063.608, Zeitstempel: 0x8274fd8b
Ausnahmecode: 0xc0000008
Fehleroffset: 0x00000000000a917a
ID des fehlerhaften Prozesses: 0xfc0
Startzeit der fehlerhaften Anwendung: 0x01d344b96990fd61
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\svchost.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: dfbf9241-68e9-4051-ac62-6aaa9ce5d92c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (10/13/2017 07:28:03 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Error: (10/13/2017 03:00:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PETERSPC)
Description: Bei der Aktivierung der App „Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (10/13/2017 03:00:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PETERSPC)
Description: Bei der Aktivierung der App „Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (10/13/2017 03:00:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PETERSPC)
Description: Bei der Aktivierung der App „Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2147023174. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (10/13/2017 03:00:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 10.0.15063.0, Zeitstempel: 0x02799ef5
Name des fehlerhaften Moduls: CNQ4809C.DLL, Version: 1.0.0.0, Zeitstempel: 0x51799004
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000119ec
ID des fehlerhaften Prozesses: 0xbdc
Startzeit der fehlerhaften Anwendung: 0x01d3442330063702
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\svchost.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\CNQ4809C.DLL
Berichtskennung: b77f07c4-3556-4573-a0fc-a8b7b4ccfd66
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (10/13/2017 12:49:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 10.0.15063.0, Zeitstempel: 0x02799ef5
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.15063.608, Zeitstempel: 0x8274fd8b
Ausnahmecode: 0xc0000008
Fehleroffset: 0x00000000000a917a
ID des fehlerhaften Prozesses: 0x10d4
Startzeit der fehlerhaften Anwendung: 0x01d34410f07a595f
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\svchost.exe
Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ntdll.dll
Berichtskennung: 6d38c78e-acf4-488a-9b27-26a34bbf3c24
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (10/13/2017 08:40:44 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files\avast software\avast\x64\CrtCheck.exe".
Die abhängige Assemblierung "Avast.VC140.CRT,processorArchitecture="amd64",publicKeyToken="fcc99ee6193ebbca",type="win32",version="14.0.23918.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/13/2017 08:40:41 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files\avast software\avast\CrtCheck.exe".
Die abhängige Assemblierung "Avast.VC140.CRT,processorArchitecture="x86",publicKeyToken="fcc99ee6193ebbca",type="win32",version="14.0.23918.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (10/13/2017 08:39:20 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Microsoft Office 15\root\office15\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL" in Zeile 1.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Systemfehler:
=============
Error: (10/14/2017 08:55:30 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Windows-Bilderfassung (WIA)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (10/14/2017 08:55:26 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "chip1click" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (10/14/2017 08:55:26 AM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "chip1click" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (10/14/2017 08:55:25 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "SysMain" wurde mit folgendem Fehler beendet:
Die Anforderung wird nicht unterstützt.
Error: (10/14/2017 08:55:25 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.
Error: (10/14/2017 08:55:24 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet:
Die Anforderung wird nicht unterstützt.
Error: (10/14/2017 08:55:21 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (10/13/2017 09:48:28 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst CSR Bluetooth Audio-Service konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (10/13/2017 09:47:49 PM) (Source: DCOM) (EventID: 10016) (User: PETERSPC)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "PetersPC\Peter" (SID: S-1-5-21-2926960992-1055115158-727447495-1000) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
und der APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (10/13/2017 09:47:49 PM) (Source: DCOM) (EventID: 10016) (User: PETERSPC)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "PetersPC\Peter" (SID: S-1-5-21-2926960992-1055115158-727447495-1000) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
und der APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
CodeIntegrity:
===================================
Date: 2017-10-12 19:05:35.369
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:35.352
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:35.326
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:35.280
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:35.270
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:35.262
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:34.579
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:05:34.490
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:02:28.063
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Date: 2017-10-12 19:02:28.049
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
Prozentuale Nutzung des RAM: 19%
Installierter physikalischer RAM: 16246 MB
Verfügbarer physikalischer RAM: 13124.14 MB
Summe virtueller Speicher: 16246 MB
Verfügbarer virtueller Speicher: 13072.64 MB
==================== Laufwerke ================================
Drive c: (Windows) (Fixed) (Total:111.25 GB) (Free:65.39 GB) NTFS
Drive d: (Daten) (Fixed) (Total:537.11 GB) (Free:443.66 GB) NTFS
Drive e: (Backup) (Fixed) (Total:394.28 GB) (Free:393.54 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: FB2037D3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== Ende von Addition.txt ============================ |