ikarus2557 | 10.09.2019 08:42 | Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-09-2019
Ran by MSI_USER (10-09-2019 14:21:46)
Running from C:\Users\MSI_USER\Desktop
Windows 10 Pro Version 1803 17134.950 (X64) (2019-01-13 12:03:18)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-465342472-1690862640-1647311925-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-465342472-1690862640-1647311925-503 - Limited - Disabled)
Guest (S-1-5-21-465342472-1690862640-1647311925-501 - Limited - Disabled)
MSI_USER (S-1-5-21-465342472-1690862640-1647311925-1001 - Administrator - Enabled) => C:\Users\MSI_USER
WDAGUtilityAccount (S-1-5-21-465342472-1690862640-1647311925-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {88AE6B46-DC3C-455A-A21B-085F285A3546}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Avira Antivirus (Enabled - Up to date) {33CF8AA2-FA06-4AD4-98AB-332D53DD7FFB}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
727 Captain (727-100) Base Pack [FSX/SE] 2.70 FSX (HKLM-x32\...\p721_fsx) (Version: 2.70 - © 1999-2016 Captain Sim)
727 Captain (727-200) Expansion Model [FSX/SE/P3D] 2.70 FSX (HKLM-x32\...\p722_fsx) (Version: 2.70 - © 1999-2016 Captain Sim)
737 Captain (737-100 Exterior Model) 0.2 (HKLM-x32\...\x730) (Version: 0.2.00 - ฉ 1999-2011 Captain Sim)
777 Captain (777-200 Exterior Model) 0.1 (HKLM-x32\...\x770) (Version: 0.1.00 - ฉ 1999-2011 Captain Sim)
Accu-Feel (HKLM-x32\...\Accu-Feel) (Version: - )
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20040 - Adobe Systems Incorporated)
Aerosoft Mega Airport Munich v 1.00 for FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Aerosoft Mega Airport Munich v 1.00 for FSX) (Version: - )
Aerosoft's - Aerosoft Launcher (HKLM-x32\...\{EE11CFFC-898C-4875-8A63-8B732A9AD43B}) (Version: 1.2.0.3 - Aerosoft)
aerosoft's - Lukla X - Mount Everest (HKLM-x32\...\{EF32F291-8B08-43EF-8BAA-58B9F8C9540F}) (Version: 1.00 - aerosoft)
Aerosoft's - Madeira X Evolution - FSX (HKLM-x32\...\Madeira X Evolution - FSX) (Version: 1.05a - Aerosoft)
Aerosoft's - Mega Airport Zurich 2012 - FSX (HKLM-x32\...\{463A571A-B793-459B-BEA8-028DC323AAB0}) (Version: 1.01 - Aerosoft)
aerosoft's - Menorca X for FSX (HKLM-x32\...\{5BD1BBB6-DC09-420F-B459-DD61DD351541}) (Version: 1.00 - aerosoft)
Aerosoft's - MonacoX (HKLM-x32\...\{B56D25A0-1316-4255-AB45-1147C9D01C5E}) (Version: 1.02 - Aerosoft)
aerosoft's - Nice Cote dAzur X (HKLM-x32\...\{90447E05-DE8E-470D-8D3E-C871D2AE74AF}) (Version: 1.10 - aerosoft)
AIMP (HKLM-x32\...\AIMP) (Version: v4.51.2084, 01.12.2018 - AIMP DevTeam)
Airbus A320 Family Mega Pack FSX & P3D (HKLM\...\{B3433E82-1261-4523-9D4E-BEC8CA678D50}) (Version: 1 - Project Airbus & its collaborators, François Doré, repack by Luis Quintero)
Aircraft Factory F4u Corsair (HKLM-x32\...\Aircraft Factory F4u Corsair) (Version: - )
ALABEO Pitts S-2S (HKLM-x32\...\ALABEO Pitts S-2S) (Version: 1.00.00.00 - ALABEO)
Alphasim EFA Typhoon FSX & P3D (HKLM\...\{35F708C4-5C11-46C5-B4A1-EFA97EC214DE}) (Version: 1 - Alphasim/Virtavia)
Antonov An-2 0.9.7 (HKLM-x32\...\{7cd9d678-9999-4f1e-8ae0-24f71faad1a0}_is1) (Version: 0.9.7 - SibWings)
Apple Application Support (32-Bit) (HKLM-x32\...\{308F2F8C-9D33-4B22-8A6C-D9C13DBEF8C6}) (Version: 7.0.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{0CB84A7D-9697-4526-A819-60FB050E8F05}) (Version: 7.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BD6778C5-6FA5-492A-ADD6-E706339C2A7B}) (Version: 11.0.2.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
AVG (HKLM\...\{136B57DF-DA9E-4361-A165-09AB4422BCD1}) (Version: 1.231.3 - AVG Technologies) Hidden
AVG Driver Updater (HKLM-x32\...\{BAAB946F-7E00-41F4-BEC7-B8CCF758E012}) (Version: 2.3.0 - AVG Netherlands B.V) Hidden
AVG Driver Updater (HKLM-x32\...\AVG Driver Updater) (Version: 2.3.0 - AVG Netherlands B.V)
AVG PC TuneUp (HKLM-x32\...\{52B6D655-9038-4290-B710-0E568F806155}) (Version: 16.80.3 - AVG Technologies) Hidden
AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: 16.80.3.38236 - AVG Technologies)
AVG Secure VPN (HKLM\...\{078F51FA-D92F-419A-9E69-08BC59265F7E}_is1) (Version: 1.1.588.1 - AVG)
Avira (HKLM-x32\...\{1db45392-716a-490d-9b3e-2d96adbb5ab0}) (Version: 1.2.136.25116 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{CC898F82-66EF-4083-947F-5C69703DDBAF}) (Version: 1.2.136.25116 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.1908.1579 - Avira Operations GmbH & Co. KG)
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.28.3.20557 - Avira Operations GmbH & Co. KG)
Avira Privacy Pal (HKLM-x32\...\{F2BC8305-DFBE-4C02-A906-9BBD8EE299A3}_is1) (Version: 1.8.0.1831 - Avira Operations GmbH & Co. KG)
Avira Safe Shopping (HKLM-x32\...\{099DC083-FEAC-45B0-9B0E-B858193D07F8}) (Version: 1.1.42.3954 - Avira Operations GmbH & Co. KG)
Avira Software Updater (HKLM-x32\...\{9A748448-7435-49AD-B175-087292C52A2E}) (Version: 2.0.6.17105 - Avira Operations GmbH & Co. KG)
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 4.16.0.7822 - Avira Operations GmbH & Co. KG)
B1900D HD SERIES FSX/P3D (HKLM-x32\...\B1900D HD SERIES FSX/P3D) (Version: 1.00.00.00 - Carenado)
BAE Red Arrows Hawk T1 (HKLM-x32\...\BAE Red Arrows Hawk T1) (Version: - )
Basler BT-67 Base Pack V2 FSX SP2 & P3D (HKLM\...\{EB6BE03D-1D14-4137-AAE8-6DEEBDB8575D}) (Version: 1 - Manfred Jahn, Daniel Fuernkaess, Alexander M. Metzger, Hansjoerg Naegele)
Boeing 737 Classic Multi Livery Pack (HKLM\...\{C85841E6-BA63-4C03-BFE6-C0688AD52771}) (Version: 1 - Eagle Rotorcraft Simulation, George A.Arana, Alejandro Rojas Lucena, package by Rikoooo)
Boeing 777-200ER Ultimate Pack (HKLM\...\{5849CFC1-98B4-4B0A-98F7-86322E790294}) (Version: 1 - Project OpenSky, update by Hanzalah Ravat)
Boeing B737-823 Advanced VC FSX & P3D (HKLM\...\{330F6375-B0DB-4CDD-B1EB-B83C43810D11}) (Version: 1 - Project OpenSky, Alejandro Rojas Lucenda, FSRepaintsGER, Adam Murphy)
Boeing P8-A Poseidon (HKLM\...\{0D1B836B-D6BC-4C8B-9B06-CE966304893D}) (Version: 1 - Model by TDS, enhanced by Alejandro Rojas Lucena, packaged by Chris Evans)
Bombardier CRJ-200 Full Pack (HKLM\...\{24BEBC74-49DD-429C-B85A-6E95DB3E093F}) (Version: 3 - Rikoooo)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
C90B King Air HD SERIES FSX (HKLM-x32\...\C90B King Air HD SERIES FSX) (Version: 1.00.00.00 - Carenado)
Captain Sim 707 All-in-One (HKLM-x32\...\{0906F438-9315-477C-9DBB-4A3050699810}) (Version: 1.00 - SilverWingz)
Carenado Baron 58 FSX (HKLM-x32\...\Carenado Baron 58 FSX) (Version: 1.00.00.00 - Carenado)
Carenado C340 II FSX (HKLM-x32\...\Carenado C340 II FSX) (Version: 1.00.00.00 - Carenado)
Carenado F33A Bonanza (HKLM-x32\...\Carenado F33A Bonanza) (Version: 1.00.00.00 - Carenado)
Carenado PA28-181 ARCHER II FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Carenado PA28-181 ARCHER II FSX) (Version: - )
Carenado Piper Cherokee FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Carenado Piper Cherokee FSX) (Version: - )
Carenado V35B Bonanza for FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Carenado V35B Bonanza for FSX) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.53 - Piriform)
CE2400X FSX/P3D/STEAM (HKLM-x32\...\CE2400X FSX/P3D/STEAM) (Version: 1.0 - Carenado)
Cessna Citation Excel XLS+ (HKLM\...\{66DB8AF6-8736-40AB-BC09-7168A951B8B7}) (Version: 1 - Aryus Works, Alex Sandro Guedes Silva, Jeffrey S. Bryner, Christoffer Petersen, Bigmike)
CH Control Manager Software (HKLM-x32\...\CHControlManager_is1) (Version: - )
CLS Piper Arrow (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\CLS Piper Arrow) (Version: - )
CPUID CPU-Z 1.78 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION
Curtiss C46 Commando (HKLM-x32\...\{8FA2A715-0B8D-4A8C-979F-C4886053A6FB}) (Version: 1.00.000 - Just Flight)
DeHavilland DHC-7 Spantax (HKLM\...\{F9A46DAE-9088-4652-AA37-C11876E086FB}) (Version: 1 - By Milton Shupe, Mike Kelly, George Arana and Sim-Outhouse. FSX native conversion by Eagle Rotorcraft Simulations. Textures by Enrique Medal. Assembled for FSX/P3D v3 & 4 by Chris Evans)
DH104 Dove and Devon (HKLM-x32\...\{CE279BBA-E76C-4A0A-B9A0-45DBBF3BF045}) (Version: 1.00.000 - Just Flight)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 419.35 - NVIDIA Corporation) Hidden
Douglas A-20 Havoc (HKLM\...\{20CB9B16-10C0-4A1C-9297-B64878854036}) (Version: 1 - Rikoooo)
DX10 Scenery Fixer (HKLM-x32\...\{BEC93831-5B06-4A2B-911E-DCC135AFCA08}) (Version: 3.0.92.1 - Stevefx)
EMB500 Phenom 100 FSX/P3D (HKLM-x32\...\EMB500 Phenom 100 FSX/P3D) (Version: ${PRODUCT_VERSION} - Carenado)
EMB505 Phenom 300 v1.3 (HKLM-x32\...\EMB505 Phenom 300 v1.3with Navigraph Pack 1.1FSX) (Version: with Navigraph Pack 1.1 - Carenado)
Embraer EMB-120 Mega Pack (HKLM\...\{3517A4A7-53F2-4597-8420-D07F6A5FF79D}) (Version: 1 - Rikoooo)
F-8 Vought Crusader v2 (HKLM\...\{B88A5BAF-08DB-4704-A587-8B04DCDBA672}) (Version: 2 - Alphasim/Virtavia. Henk Schuitemaker)
F9F Panther (HKLM-x32\...\F9F Panther) (Version: - )
Fiji Photoreal Package Western FSX & P3D (HKLM\...\{DC17D3A5-1F2A-47F2-8FDD-6F5550C6030E}) (Version: 1 - Tiberius Kowalski)
Flight1 Citation Mustang (HKLM-x32\...\f1mustang_FSX) (Version: 1.01 - Flight One Software)
FlyLogic's - Altenrhein X (HKLM-x32\...\{E5326C48-869C-43C0-A78E-B531CCFF066B}) (Version: 1.00 - FlyLogic)
FMW 1 (HKLM\...\{4CC5FB14-3F4D-4FA8-B921-00A9B40145C4}) (Version: 1.227.45 - AVG Technologies) Hidden
Fraps (HKLM-x32\...\Fraps) (Version: - )
FSD Pilatus Porter Amphibian V2 for FS X (HKLM-x32\...\FSD Pilatus Porter Amphibian V 2 for FS X) (Version: - )
FSD Pilatus Porter Landplane V2 for FS X (HKLM-x32\...\FSD Pilatus Porter Landplane V 2 for FS X) (Version: - )
FSD Pilatus Porter Skiplane V2 for FS X (HKLM-x32\...\FSD Pilatus Porter Skiplane V 2 for FS X) (Version: - )
FSDG-Paro (HKLM-x32\...\FSDG-Paro) (Version: - )
FSDreamTeam Geneva version 2.0.2 (HKLM-x32\...\FSDreamTeam Geneva_is1) (Version: 2.0.2 - VIRTUALI Sagl)
FSDreamTeam Hawaiian Airports Volume 1 version 2.0.2 (HKLM-x32\...\FSDreamTeam Hawaiian Airports Volume 1_is1) (Version: 2.0.2 - VIRTUALI Sagl)
FSDreamTeam Hawaiian Airports Volume 2 version 2.0.2 (HKLM-x32\...\FSDreamTeam Hawaiian Airports Volume 2_is1) (Version: 2.0.2 - VIRTUALI Sagl)
FSDreamTeam Honolulu International version 2.0.2 (HKLM-x32\...\FSDreamTeam Honolulu International_is1) (Version: 2.0.2 - VIRTUALI Sagl)
FSDreamTeam ZurichX version 2.8.2 (HKLM-x32\...\FSDreamTeam ZurichX_is1) (Version: 2.8.2 - VIRTUALI Sagl)
FSJ - Hawaii Extra Contents Version 1.0 (HKLM-x32\...\{23EFA1FF-9364-4268-96F3-CA84C034312F}_is1) (Version: 1.0 - Flight Sim Jewels)
FSJ - Hawaii Photoreal Vol. 1 - Niihau, Kauai & Oahu Version 0.99 (HKLM-x32\...\{4D088B72-89C9-4678-AA5C-24C968E7406D}_is1) (Version: 0.99 - Flight Sim Jewels)
FSJ - Hawaii Photoreal Vol. 2 - Molokai, Lanai, Maui & Kahoolawe v.0.99 Version 0.99 (HKLM-x32\...\{6E8752DD-FE4E-4204-A08E-D50AFA0617CE}_is1) (Version: 0.99 - Flight Sim Jewels)
FSJ - Hawaii Photoreal Vol. 3 - The Big Island Version 0.97 (HKLM-x32\...\{3BB43A17-8A9E-4BA0-8213-BD33B9163FDE}_is1) (Version: 0.97 - Flight Sim Jewels)
FSJ - Hawaiian Airports by George Keogh Version 1.0 (HKLM-x32\...\{C327E80A-E3CA-4091-AEC0-00D1C312E2AB}_is1) (Version: 1.0 - Flight Sim Jewels)
FSX & P3D - Hawaii Photoreal Vol. 1 - Oahu v.0.97 Plus Version 0.97 (HKLM-x32\...\{B32B2669-7B1D-4200-9395-4DF2D70461B5}_is1) (Version: 0.97 - AveMetal Entertainment, Inc.)
FSX & P3D - Hawaii Photoreal Vol. 2 - Molokai v.0.99 Plus Version 0.99 (HKLM-x32\...\{4463C090-92E1-4EC1-B715-17C9A59FB76B}_is1) (Version: 0.99 - AveMetal Entertainment, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 76.0.3809.132 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
H25B_H850XP FSX/P3D (HKLM-x32\...\H25B_H850XP FSX/P3D) (Version: ${PRODUCT_VERSION} - Carenado)
High Definition Environment v2.1 (HKLM\...\{E46C2BF4-6090-4C42-9D26-21A6B3C143AF}) (Version: 1 - Original author Pablo Diaz, FSX update by Danny Glover and Erik BENDER (Rikoooo))
Ilyushin Il-18 FSX & P3D (HKLM\...\{988FEEF6-2B16-4516-AEC5-C306DEA5D90E}) (Version: 1 - Edgar Giunar)
Image Resizer for Windows (64 bit) (HKLM\...\{617CA6E9-D5FB-4017-8130-82E68C56C34D}) (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Intel(R) Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
ItalySim-LICA 2016 (HKLM-x32\...\ISD-LICA2016-18199E96-4C34-473F-9530-E949D9209CE6_is1) (Version: 1.0.0.0 - SimMarket)
iTunes (HKLM\...\{9E84991B-6078-4311-A714-0A1360C3706C}) (Version: 12.9.0.167 - Apple Inc.)
JetStream Designs LFML X 2013 (HKLM-x32\...\FSX_JETSTREAM_DESIGN_LFML_X_2013_is1) (Version: 1.0.0.0 - SimMarket)
JetStream Designs Palermo LICJ (HKLM-x32\...\JETSTREAMDESIGN-PALERMOLICJ-08588E01-7F3A-401B-A~17A2AB48_is1) (Version: 1.0.0.0 - SimMarket)
Just Flight - DC-8 Jetliner Series 10 to 40 (HKLM-x32\...\{14410905-9476-45D9-AC33-3DEDC9BDD257}) (Version: 1.00.0000 - Just Flight)
Just Flight - MilViz F-15E Strike Eagle (HKLM-x32\...\{AFCBCDA6-98C4-4D33-BA8F-3168A1860608}) (Version: 1.00.000 - Just Flight)
Just Flight Constellation Professional (HKLM-x32\...\{070B2AFF-E7F2-4085-83CD-5ED64A4C9CE5}) (Version: 1.00.000 - )
Just Flight MD-81/82 Jetliner (HKLM-x32\...\{6AA6251B-B7C8-40FC-8FB9-DCB9D81BE4C7}) (Version: 1.00.000 - )
Killer Bandwidth Control Filter Driver (HKLM\...\{24BA7D32-B740-47A3-BE0E-2F4863A05D13}) (Version: 1.1.56.1120 - Rivet Networks) Hidden
Killer E220x Drivers (HKLM\...\{921ABFC0-9681-487D-9379-89C1712EFEBF}) (Version: 1.1.56.1120 - Rivet Networks) Hidden
Killer Network Manager (HKLM\...\{E21E50A4-4A55-4A7E-B1AA-16F8F9E255C8}) (Version: 1.1.56.1120 - Rivet Networks) Hidden
Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.56.1120 - Rivet Networks)
L-1011 Captain (1011-1 Exterior Model) 0.1 (HKLM-x32\...\l111) (Version: 0.1.00 - ฉ 1999-2013 Captain Sim)
LFKB Bastia Poretta v1.1 (HKLM-x32\...\RFSCENERYBUILDING_LFKB_is1) (Version: 1.1.0.0 - SimMarket)
LFLB - Chamb้ry Aix les Bains FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\LFLB - Chamb้ry Aix les Bains FSX) (Version: - )
LFMD Cannes FSX version 1.01 (HKLM-x32\...\{75CBE292-551C-4CBD-89D4-D57733A4B14E}_is1) (Version: 1.01 - LMT SIMULATION)
LICC_Catania-Fontanarossa (HKLM-x32\...\RFS_LICC_CATANIA_FONTANAROSSA_is1) (Version: 1.1.0.0 - SimMarket)
LLH1 (HKLM-x32\...\LLH1) (Version: - )
LLH9 (HKLM-x32\...\LLH9) (Version: - )
Macrium Reflect Free Edition (HKLM\...\{84BD4249-F4BB-43EE-BE16-D08A27E54439}) (Version: 6.3.1849 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.3 - Paramount Software (UK) Ltd.)
Mailsoft's - Birrfeld X (HKLM-x32\...\{F3F3CA83-5D04-4F6F-9234-0E3557CEADBD}) (Version: 1.00 - Mailsoft)
Malwarebytes Version 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
MeatWater FO Altitude Callouts v1.0 (HKLM-x32\...\MeatWater FO Altitude Callouts v1.0) (Version: - )
Mega Route Rio São Paulo and Natal City Pack5 (HKLM-x32\...\FSX_MegaRiodeJaneiroX2012_is1) (Version: 1.0.0.0 - SimMarket)
MegaSceneryEarth Florida 001 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 001 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 002 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 002 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 003 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 003 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 004 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 004 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 005 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 005 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 006 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 006 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 007 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 007 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 008 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 008 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 009 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 009 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 010 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 010 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 011 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 011 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 012 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 012 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 013 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 013 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 014 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 014 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 015 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 015 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 016 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 016 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 017 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 017 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 018 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 018 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 019 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 019 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 020 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 020 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 021 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 021 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 022 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 022 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 023 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 023 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 024 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 024 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida 025 2.0 (HKLM-x32\...\MegaSceneryEarth Florida 025 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Florida Charts 2.0 (HKLM-x32\...\MegaSceneryEarth Florida Charts 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 001 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 001 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 002 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 002 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 003 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 003 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 004 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 004 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 005 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 005 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 006 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 006 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 007 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 007 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 008 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 008 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 009 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 009 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 010 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 010 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 011 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 011 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Seattle Ultra Res 012 2.0 (HKLM-x32\...\MegaSceneryEarth Seattle Ultra Res 012 2.0) (Version: 2.0 - MegaSceneryEarth)
MegaSceneryEarth Washington Charts 2.0 (HKLM-x32\...\MegaSceneryEarth Washington Charts 2.0) (Version: 2.0 - MegaSceneryEarth)
Microsoft Flight Simulator SimConnect Client v10.0.61259.0 (HKLM-x32\...\{D61CA184-3F6D-4A50-B2CC-7A18447D6A8D}) (Version: 10.0.61259.0 - Microsoft Corporation)
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft OneDrive (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\OneDriveSetup.exe) (Version: 19.152.0801.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mirage IIIC (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Mirage IIIC) (Version: - )
MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.8 - MSI)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.021 - MSI)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Northrop Grumman E-11A Sentinel (HKLM\...\{4A5F6C64-A6EF-4CF4-81AF-B61CA6124FBF}) (Version: 2 - Rikoooo)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.13 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 419.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 419.35 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.17.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.17.0.126 - NVIDIA Corporation)
NVIDIA Grafiktreiber 419.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 419.35 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.38.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.13 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.1.4 (HKLM-x32\...\{5E9128B1-0AB8-40F5-9F71-69089C490855}) (Version: 4.14.9788 - Apache Software Foundation)
Opera Stable 63.0.3368.71 (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\Opera 63.0.3368.71) (Version: 63.0.3368.71 - Opera Software)
P-3C Orion V3.31 (HKLM\...\{CE6DA500-D22D-4DDF-BE50-4ECFB65FE06E}) (Version: 2 - Team FS KBT)
PA32R SARATOGA SP FSX (HKLM-x32\...\PA32R SARATOGA SP FSX) (Version: 1.00.00.00 - Carenado)
PA34 200T SENECA II FSX (HKLM-x32\...\PA34 200T SENECA II FSX) (Version: 1.00.00.00 - Carenado)
PC-6 Patrouille Suisse Repaint FSX (HKLM-x32\...\{ECE6D6DA-42E3-4D54-A196-356A101E6BD2}) (Version: 1.0.0.0 - Design fuer Flugsimulation)
Phuket International Airport for FSX (HKLM-x32\...\PhuketIntFSX_is1) (Version: 1.0.0.0 - SimMarket)
QualityWings Ultimate 146 Collection FSX (HKLM-x32\...\QualityWings Ultimate 146 Collection FSX) (Version: - )
RAZBAM LTV A-7 E & D Corsair II Volume I (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\RAZBAM LTV A-7 E & D Corsair II Volume I) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
REX File Transfer Manager (HKLM-x32\...\{B60F3334-ED72-4F7B-945E-22FF8E401E8A}) (Version: 1.10.2016.1111 - REX Game Studios, LLC.)
SAAB 91 Safir X 3.0.2 (HKLM-x32\...\{971F7265-110A-4A7E-A159-3DB0A3CE4C63}_is1) (Version: 3.0.2 - SibWings lab)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samui International Airport for FSX (HKLM-x32\...\SamuiInternationalAirport_is1) (Version: - SimMarket)
SBD Dauntless FSX (HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\SBD Dauntless FSX) (Version: - )
SBGL v1.1.2 for FSX (HKLM\...\{B88C0221-3BC4-4256-B241-AC1627541B93}) (Version: 1.1.2 - BluePrint Simulations)
SimObject Display Engine (HKLM-x32\...\{CF01DDCE-487C-40D1-A798-BE842515661D}) (Version: 1.5.3 - 12bPilot)
Skydesigners - LFTZ Saint-Tropez La Mole Airport (HKLM-x32\...\FSX_SKYDESIGNERS_LFTZ_SAINT_TROPEZ_LA_MOLE_is1) (Version: 1.0.0.0 - SimMarket)
SOD Dragoneye HK v2 (HKLM-x32\...\SOD_DRAGONEYE_HK_V2_is1) (Version: 1.0.0.0 - SimMarket)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.75813 - TeamViewer)
True Iot Pocket WiFi Play 1 (HKLM-x32\...\{AEFF9E60-3E93-41EE-9895-311F7D1C5FFD}) (Version: 1.0.0.2 - )
UKMIL Buccaneer S2 PACKAGE FSX & P3D (HKLM\...\{A1BA46E2-9D56-4DDC-93E7-EBAE79BF4214}) (Version: 1 - UKMIL)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
UpdateYeti (HKLM-x32\...\UpdateYeti_is1) (Version: 2.45 - Abelssoft)
Vickers Viking for FSX (HKLM-x32\...\{74DEA96E-53A5-4616-A267-71A714A10840}) (Version: 1.00.0000 - Jens B. Kristensen)
VIIN-FSX 2.0 (HKLM-x32\...\{7BB15D3A-377E-4D84-8527-531805A82C91}_is1) (Version: - Philippe PENOT)
VIRTUALI Addon ManagerX FSX (HKLM-x32\...\VIRTUALI Addon ManagerX FSX_is1) (Version: 3.1.0.1 - VIRTUALI Sagl)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.6 - VideoLAN)
Web Companion (HKLM-x32\...\{9d1481c3-8582-4d6b-a9c9-593402236470}) (Version: 4.8.2078.3950 - Lavasoft)
WinPcap for Avira 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Domotz, Inc)
WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
World of Tanks (HKLM-x32\...\World of Tanks) (Version: - )
World Of Warships (HKLM-x32\...\World Of Warships) (Version: - )
Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.4.2012.5 - URSoft, Inc.)
Packages:
=========
Mail und Kalender -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11901.20184.0_x64__8wekyb3d8bbwe [2019-09-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation) [MS Ad]
Microsoft Begleiter für Telefon -> C:\Program Files\WindowsApps\Microsoft.WindowsPhone_10.1802.311.0_x64__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation)
Microsoft News – Nachrichten -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.12124.0_x64__8wekyb3d8bbwe [2019-09-10] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Studios) [MS Ad]
Microsoft-Telefon -> C:\Program Files\WindowsApps\Microsoft.CommsPhone_3.43.20002.1000_x64__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation)
MSN Finanzen -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.31.11905.0_x64__8wekyb3d8bbwe [2019-09-10] (Microsoft Corporation) [MS Ad]
MSN Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.31.11905.0_x64__8wekyb3d8bbwe [2019-09-10] (Microsoft Corporation) [MS Ad]
MSN Wetter -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.31.11905.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Corporation) [MS Ad]
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll [2019-03-01] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers1: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2019-01-10] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Image Resizer] -> {51B4D7E5-7568-4234-B4BB-47FB3C016A69} => C:\Program Files\Image Resizer for Windows\ShellExtensions.dll [2013-02-23] (Brice Lambson) [File not signed]
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2019-09-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {ef263503-8f0e-3e6a-ae2e-fe0b4b441d52} => C:/Program Files (x86)/Avira/System Speedup/Avira.SystemSpeedup.UI.ShellExtension.DLL [2019-01-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-10-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-10-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll [2019-03-01] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers4: [AVG Disk Space Explorer Shell Extension] -> {4838CD50-7E5D-4811-9B17-C47A85539F28} => C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll [2019-01-10] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2019-01-10] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {3d52b24d-33bb-3895-99ea-a0156f24a3f9} => C:/Program Files (x86)/Avira/System Speedup/Avira.SystemSpeedup.UI.ShellExtension.DLL [2019-01-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-03-01] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {cefaf456-bc17-3f4b-b7d9-75070925911b} => C:/Program Files (x86)/Avira/System Speedup/Avira.SystemSpeedup.UI.ShellExtension.DLL [2019-01-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2019-09-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-10-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-10-01] (win.rar GmbH -> Alexander Roshal)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Pilatus PC-7 V2.0 FSX\www.rikoooo.com.lnk -> hxxp://www.rikoooo.com
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\North American F-86 EF Sabre FSX\www.rikoooo.com.lnk -> hxxp://www.rikoooo.com
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\North American F-86 EF Sabre FSX\www.sectionf8.com.lnk -> hxxp://www.sectionf8.com
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Lockheed L-1049H Super Constellation FSX\calclassic.proboards55.com.lnk -> hxxp://calclassic.proboards55.com
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Lockheed L-1049H Super Constellation FSX\www.calclassic.com.lnk -> hxxp://www.calclassic.com
Shortcut: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Lockheed L-1049H Super Constellation FSX\www.rikoooo.com.lnk -> hxxp://www.rikoooo.com
ShortcutWithArgument: C:\Users\MSI_USER\Documents\DESKTOP\ARCHIV 1\Shared WiFi 3.lnk -> C:\Program Files (x86)\Hostless Modem\Shared WiFi 3\LaunchWebUI.exe () -> hxxp://m.home
ShortcutWithArgument: C:\Users\MSI_USER\Desktop\PROGRAMM Verknüpfungen\True Iot Pocket WiFi Play 1.lnk -> C:\Program Files (x86)\True Iot Pocket WiFi Play 1\True Iot Pocket WiFi Play 1\LaunchWebUI.exe () -> hxxp://192.168.0.1
ShortcutWithArgument: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World Of Warships\World Of Warships.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://cpm.wargaming.net/l4k6lc56/?pub_id=100
ShortcutWithArgument: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks\World of Tanks.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://cpm.wargaming.net/3ebs472f/?pub_id=100
ShortcutWithArgument: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\World of Tanks.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://cpm.wargaming.net/3ebs472f/?pub_id=100
ShortcutWithArgument: C:\Users\MSI_USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\World Of Warships.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://cpm.wargaming.net/l4k6lc56/?pub_id=100
==================== Loaded Modules (Whitelisted) ==============
2019-01-14 21:21 - 2017-05-22 18:12 - 001172992 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\_libastro.pyd
2019-01-14 21:21 - 2016-06-13 12:01 - 000032768 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\alut.dll
2019-01-14 21:21 - 2017-05-22 18:12 - 000014336 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\winsound.pyd
2019-01-14 21:21 - 2017-05-29 19:45 - 001054208 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_controls_.pyd
2019-01-14 21:21 - 2017-05-29 19:46 - 001152512 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_core_.pyd
2019-01-14 21:21 - 2017-05-29 19:46 - 000780288 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_gdi_.pyd
2019-01-14 21:21 - 2017-05-29 19:46 - 000725504 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_misc_.pyd
2019-01-14 21:21 - 2017-05-29 19:46 - 000805888 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_windows_.pyd
2019-01-14 21:21 - 2017-05-29 19:45 - 000153600 _____ () [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\_xrc.pyd
2017-12-03 15:16 - 2017-12-03 15:11 - 048920064 _____ () [File not signed] C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2016-08-04 11:33 - 2005-07-18 13:43 - 000160256 _____ () [File not signed] C:\Program Files (x86)\MSI\Live Update\unrar.dll
2017-02-23 22:46 - 2016-08-19 08:39 - 000019968 _____ () [File not signed] E:\FSX NEW\d3dx10_34.dll
2017-02-23 22:46 - 2016-08-19 08:39 - 000562688 _____ () [File not signed] E:\FSX NEW\dx10fixerlib.DLL
2017-02-23 22:46 - 2016-08-19 08:38 - 000007168 _____ () [File not signed] E:\FSX NEW\dx10SharedLib.dll
2006-04-30 04:20 - 2019-03-11 20:32 - 000040960 _____ () [File not signed] E:\FSX NEW\GaugeSound.DLL
2019-03-22 13:50 - 2010-06-04 11:51 - 000023552 _____ () [File not signed] E:\FSX NEW\MD80.dll
2017-02-03 17:06 - 2012-09-13 09:22 - 000603648 _____ () [File not signed] E:\FSX NEW\Modules\A2A_Feel.dll
2017-02-03 17:06 - 2012-08-14 09:16 - 000190976 _____ () [File not signed] E:\FSX NEW\Modules\AccuFeelMenu.dll
2011-08-29 09:14 - 2010-10-27 14:08 - 000352256 _____ () [File not signed] E:\FSX NEW\ORBX\FTX_NA\FTX_AA_1WA6\Scenery\ObjectFlow_1WA6.dll
2015-09-05 15:05 - 2015-09-05 15:05 - 000255760 _____ (Beepa Pty Ltd -> Beepa P/L) [File not signed] C:\Fraps\FRAPS32.DLL
2015-09-05 15:11 - 2015-09-05 15:11 - 000102160 _____ (Beepa Pty Ltd -> Beepa P/L) [File not signed] C:\Fraps\fraps64.dat
2015-09-05 15:05 - 2015-09-05 15:05 - 000215824 _____ (Beepa Pty Ltd -> Beepa P/L) [File not signed] C:\Fraps\fraps64.dll
2013-02-23 11:47 - 2013-02-23 11:47 - 000166400 _____ (Brice Lambson) [File not signed] C:\Program Files\Image Resizer for Windows\ShellExtensions.dll
2004-11-11 07:30 - 2004-11-11 07:30 - 000885248 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee0.GAU
2004-11-11 07:31 - 2004-11-11 07:31 - 000717824 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee1.GAU
2004-11-11 07:31 - 2004-11-11 07:31 - 001022464 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee2.GAU
2004-11-11 07:31 - 2004-11-11 07:31 - 000595968 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee3.GAU
2004-11-11 07:31 - 2004-11-11 07:31 - 001054720 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee4.GAU
2004-11-11 07:32 - 2004-11-11 07:32 - 001164800 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\Cherokee5.GAU
2004-11-11 07:32 - 2004-11-11 07:32 - 000764416 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\CherokeeM.GAU
2004-11-11 07:32 - 2004-11-11 07:32 - 001452544 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\CherokeeVFR.GAU
2004-11-11 07:32 - 2004-11-11 07:32 - 000666112 _____ (Carenado Team) [File not signed] E:\FSX NEW\SimObjects\Airplanes\Carenado Cherokee\panel\RadioCherokeeF.GAU
2015-06-23 16:00 - 2015-06-23 16:00 - 000562688 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\ISDI2.dll
2015-06-23 16:00 - 2015-06-23 16:00 - 000285696 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\PsiData.dll
2006-04-30 04:22 - 2006-04-28 01:20 - 000015872 _____ (MeatWater) [File not signed] E:\FSX NEW\GAUGES\hs748_altcall.GAU
2019-01-13 18:58 - 2019-01-13 18:58 - 000037888 _____ (Microsoft Corp.) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.flightsimulator.simconnect_67c7c14424d61b5b_10.0.60905.0_none_dd92b94d8a196297\SimConnect.dll
2019-01-13 18:58 - 2019-01-13 18:58 - 000045568 _____ (Microsoft Corp.) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.flightsimulator.simconnect_67c7c14424d61b5b_10.0.61259.0_none_55f5ecdc14f60568\SimConnect.dll
2007-09-26 16:08 - 2016-08-09 15:26 - 000262720 _____ (Microsoft Corporation -> Microsoft Corp.) [File not signed] E:\FSX NEW\ai_player.dll
2019-01-13 18:58 - 2019-01-13 18:58 - 001233920 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d\MSXML4.DLL
2019-03-01 18:38 - 2019-03-01 18:38 - 001101824 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\MFC80.DLL
2019-03-01 18:38 - 2019-03-01 18:38 - 000065536 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c72205943d3\MFC80DEU.DLL
2019-01-14 21:21 - 2014-05-23 23:21 - 000110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\OpenAL32.dll
2019-01-14 21:21 - 2017-05-22 17:15 - 002826752 _____ (Python Software Foundation) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\python27.dll
2019-01-11 13:59 - 2019-01-11 13:59 - 002095104 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\AVG\Secure VPN\libcrypto-1_1.dll
2019-01-14 21:21 - 2017-05-29 19:13 - 000161792 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxbase30u_net_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:13 - 002119680 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxbase30u_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:13 - 000138752 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxbase30u_xml_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:12 - 001296384 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxmsw30u_adv_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:12 - 004821504 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxmsw30u_core_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:12 - 000600576 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxmsw30u_html_vc_custom.dll
2019-01-14 21:21 - 2017-05-29 19:13 - 000685568 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Addon Manager\couatl\wx\wxmsw30u_xrc_vc_custom.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:00934A10 [119]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-01-17 07:08 - 2017-11-26 22:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-465342472-1690862640-1647311925-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MSI_USER\Desktop\Screenshot (718).png
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
HKLM\...\StartupApproved\StartupFolder: => "Killer Network Manager.lnk"
HKLM\...\StartupApproved\StartupFolder: => "AVG Secure VPN.lnk"
HKLM\...\StartupApproved\Run: => "MouseDriver"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "AvgUi"
HKLM\...\StartupApproved\Run: => ""
HKLM\...\StartupApproved\Run32: => "Live Update"
HKLM\...\StartupApproved\Run32: => "Fast Boot"
HKLM\...\StartupApproved\Run32: => "USB Security"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKLM\...\StartupApproved\Run32: => "adm_tray.exe"
HKLM\...\StartupApproved\Run32: => ""
HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_566FF74826DC815D3E0370C0C29D28A3"
HKU\S-1-5-21-465342472-1690862640-1647311925-1001\...\StartupApproved\Run: => ""
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{CAB9E442-65BC-4D26-8321-F64D3DE1A0D3}] => (Allow) C:\Windows\KMS-R@1n.exe () [File not signed]
FirewallRules: [{44F68DD6-4711-407C-B159-4E93E368FB6A}] => (Allow) C:\Windows\KMS-R@1n.exe () [File not signed]
FirewallRules: [{9057A54A-205D-4A2F-BEC2-5E831CEAA8A8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5E30314C-6F6A-4E69-A6B2-9E107EE62A59}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5983E1B5-3E16-48D8-A231-BF17AEB2ECD6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{CE46208A-95D0-450B-A93E-F52D0F1B6BD9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [UDP Query User{DFC29034-E9F3-45B6-8F27-9E2A7955E4C4}C:\users\msi_user\appdata\local\microsoft\onedrive\onedrive.exe] => (Allow) C:\users\msi_user\appdata\local\microsoft\onedrive\onedrive.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{829D104F-3C9B-4B6B-ADFA-06C026871431}C:\users\msi_user\appdata\local\microsoft\onedrive\onedrive.exe] => (Allow) C:\users\msi_user\appdata\local\microsoft\onedrive\onedrive.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{694024F0-FC8F-4EFF-97AC-4118E714BC82}] => (Allow) C:\Users\MSI_USER\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) [File not signed]
FirewallRules: [{0DB6C35C-3BCB-4070-A309-EFBA91EDFA41}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{4DB5F2DC-1688-41EC-9CA2-2C5257F5B36A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A5B5CF15-232A-4360-86FF-B612C302ACBD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{5DF56E8C-6A83-4F27-A434-2054E29B809B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{1E8A2B2B-CF82-4D4F-BDA7-BE836C3472C5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8B54F2F5-9799-473C-9BB3-90EF6121299B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A38878EB-4321-41F8-A73A-A96D103DE4C4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{EB2FE336-FA97-441B-BF9B-6067BCDC7ECE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9FF215F6-D147-45E6-AB6B-B7C9F4347513}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{64512AB7-358E-425D-8BCF-D9C42FD5143A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{39E29475-840C-4BF4-A4E0-A829B63F8B11}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{DABE951A-3DC7-459F-97ED-242EBEEE1921}] => (Allow) C:\Program Files (x86)\AVG\Secure VPN\VpnUpdate.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{321B4731-9F33-45C4-9570-492F76EDC55F}] => (Allow) C:\Program Files (x86)\AVG\Secure VPN\VpnUpdate.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{D0600634-EC89-4EA2-83DD-7050B581442A}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{44049211-AF23-45BE-AF75-B57891FE767C}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{B36547AA-23EB-4519-B675-5E46358D89A7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{835D8980-3FD3-4964-8F5D-38FFB6B4F720}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{58807947-972A-40FB-B5FA-3C769A23188D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D486A7DF-14E8-4D6D-A099-21F4E181F692}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{9208FAA9-0163-4B5E-A61C-EAE4EFA5FACE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{472BF734-D17E-4DBD-A31E-0E05779F2885}] => (Block) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
FirewallRules: [{B44B79B2-A305-4AB1-B68F-C141D019314A}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
FirewallRules: [{81AFB9DB-C338-48FC-AF01-CE82DD2DF04B}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
FirewallRules: [{279529C3-6E4D-491C-BF8D-DC597FFA2402}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:117.85 GB) (Free:28.77 GB) (24%)
==================== Faulty Device Manager Devices =============
Name: AVG TAP Adapter v3
Description: AVG TAP Adapter v3
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: avgTap
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/10/2019 01:30:04 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkQuarantineRetry
Error: (09/10/2019 01:30:04 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (09/10/2019 12:56:17 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
Error: (09/09/2019 08:53:40 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkQuarantineRetry
Error: (09/09/2019 08:53:29 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (09/09/2019 08:41:17 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004F074
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (09/09/2019 08:15:42 PM) (Source: AviraOptimizerHost) (EventID: 0) (User: )
Description: Event-ID 0
Error: (09/09/2019 08:11:37 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: Die erweiterbare Leistungsindikator-DLL rdyboost kann nicht geladen werden. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Windows-Fehlercode.
System errors:
=============
Error: (09/10/2019 12:34:56 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-TUSRUQC)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "DESKTOP-TUSRUQC\MSI_USER" (SID: S-1-5-21-465342472-1690862640-1647311925-1001) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (09/10/2019 12:32:30 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-TUSRUQC)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "DESKTOP-TUSRUQC\MSI_USER" (SID: S-1-5-21-465342472-1690862640-1647311925-1001) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
und der APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
im Anwendungscontainer "Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy" (SID: S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (09/09/2019 09:04:47 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Der Server "{995C996E-D918-4A8C-A302-45719A6F4EA7}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (09/09/2019 09:04:47 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Der Server "{995C996E-D918-4A8C-A302-45719A6F4EA7}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (09/09/2019 09:04:44 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-TUSRUQC)
Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (09/09/2019 08:36:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-TUSRUQC)
Description: Der Server "Microsoft.MicrosoftEdge_42.17134.1.0_neutral__8wekyb3d8bbwe!ContentProcess#{00091402-0079-0000-F698-100000000000}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (09/09/2019 08:35:32 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-TUSRUQC)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "DESKTOP-TUSRUQC\MSI_USER" (SID: S-1-5-21-465342472-1690862640-1647311925-1001) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
und der APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
im Anwendungscontainer "Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy" (SID: S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (09/09/2019 08:25:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-TUSRUQC)
Description: Durch die Berechtigungseinstellungen für "application-specific" wird dem Benutzer "DESKTOP-TUSRUQC\MSI_USER" (SID: S-1-5-21-465342472-1690862640-1647311925-1001) unter der Adresse "LocalHost (Using LRPC)" keine Berechtigung vom Typ "Local Activation" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Unavailable" (SID: Unavailable) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Windows Defender:
===================================
Date: 2019-01-27 13:15:31.461
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {13F6B8AA-11C5-45C4-959A-AC3367661EBB}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT AUTHORITY\SYSTEM
Date: 2019-01-26 18:53:47.974
Description:
Von Windows Defender Antivirus wurde Schadsoftware oder andere potenziell unerwünschte Software erkannt.
Weitere Informationen:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0
Name: HackTool:Win32/AutoKMS
ID: 2147685180
Schweregrad: High
Kategorie: Tool
Pfad: file:_C:\Users\MSI_USER\AppData\Roaming\KMSpico-setup.exe
Erkennungsursprung: Lokaler Computer
Erkennungstyp: Konkret
Erkennungsquelle: Echtzeitschutz
Benutzer: DESKTOP-TUSRUQC\MSI_USER
Prozessname: C:\Users\MSI_USER\Desktop\Neuer Ordner (3)\Setup.exe
Signaturversion: AV: 1.285.182.0, AS: 1.285.182.0, NIS: 1.285.182.0
Modulversion: AM: 1.1.15600.4, NIS: 1.1.15600.4
Date: 2019-01-15 15:51:55.668
Description:
Die Windows Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet.
Überprüfungs-ID: {60002256-9742-4588-8395-DB2278DA0332}
Überprüfungstyp: Antimalware
Überprüfungsparameter: Schnellüberprüfung
Benutzer: NT AUTHORITY\SYSTEM
Date: 2019-01-28 19:54:46.618
Description:
Fehler von Windows Defender Antivirus beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.285.247.0
Updatequelle: Microsoft Update-Server
Signaturtyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
Vorherige Modulversion: 1.1.15600.4
Fehlercode: 0x8024402c
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2019-01-28 19:34:45.073
Description:
Fehler von Windows Defender Antivirus beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.285.247.0
Updatequelle: Microsoft Update-Server
Signaturtyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
Vorherige Modulversion: 1.1.15600.4
Fehlercode: 0x8024402c
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2019-01-28 15:11:39.195
Description:
Fehler von Windows Defender Antivirus beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.285.247.0
Updatequelle: Microsoft Update-Server
Signaturtyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
Vorherige Modulversion: 1.1.15600.4
Fehlercode: 0x8024402c
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2019-01-28 11:04:14.395
Description:
Fehler von Windows Defender Antivirus beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.285.247.0
Updatequelle: Microsoft Update-Server
Signaturtyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
Vorherige Modulversion: 1.1.15600.4
Fehlercode: 0x8024402c
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2019-01-23 20:41:22.376
Description:
Fehler von Windows Defender Antivirus beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.283.3486.0
Updatequelle: Microsoft Update-Server
Signaturtyp: AntiVirus
Updatetyp: Voll
Benutzer: NT AUTHORITY\SYSTEM
Aktuelle Modulversion:
Vorherige Modulversion: 1.1.15500.2
Fehlercode: 0x8024402c
Fehlerbeschreibung: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
CodeIntegrity:
===================================
Date: 2019-09-10 12:39:34.474
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Users\MSI_USER\AppData\Local\Programs\Opera\63.0.3368.71\opera.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
Date: 2019-09-09 20:26:18.718
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Users\MSI_USER\AppData\Local\Programs\Opera\63.0.3368.71\opera.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
Date: 2019-09-09 19:20:51.026
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Users\MSI_USER\AppData\Local\Programs\Opera\63.0.3368.71\opera.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
Date: 2019-04-08 07:20:01.722
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\avirasecuritycenteragent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\libcurl.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2019-04-07 07:08:37.165
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\avirasecuritycenteragent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\libcurl.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2019-04-04 21:51:39.416
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\avirasecuritycenteragent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Avira\Antivirus\libcurl.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. V10.7 05/18/2015
Motherboard: MSI Z87-G43 GAMING (MS-7816)
Processor: Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz
Percentage of memory in use: 71%
Total physical RAM: 8135.94 MB
Available physical RAM: 2359.16 MB
Total Virtual: 11351.42 MB
Available Virtual: 2007.78 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:117.85 GB) (Free:28.77 GB) NTFS
Drive d: (Local Disk) (Fixed) (Total:931.51 GB) (Free:405.07 GB) NTFS
Drive e: (Local Disk) (Fixed) (Total:1863.01 GB) (Free:331.92 GB) NTFS
\\?\Volume{bd9540bb-66ec-4f88-be07-ad4807346eef}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{e0ef77ee-3d2a-4b7a-b517-03092a471ed4}\ () (Fixed) (Total:0.83 GB) (Free:0.34 GB) NTFS
\\?\Volume{22f94353-c4e4-485b-b85e-d1a572b21212}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: FADE989E)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 1ED78F3D)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 1ED78F3E)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================ |