Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 10-04-2021
durchgeführt von K1992 (Administrator) auf DANIEL (10-04-2021 18:25:53)
Gestartet von C:\Users\gnxks\Downloads
Geladene Profile: K1992
Platform: Windows 10 Pro Version 20H2 19042.867 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Chrome
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
() [Datei ist nicht signiert] C:\Program Files (x86)\Kinoni\EpocCam\KinoniSvc.exe
() [Datei ist nicht signiert] C:\Program Files\Antares Audio Technologies\Antares Central Services.exe
() [Datei ist nicht signiert] C:\Program Files\OpenVPN Connect\agent_ovpnconnect_1612970385045.exe
() [Datei ist nicht signiert] C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe
() [Datei ist nicht signiert] C:\Users\gnxks\AppData\Local\Programs\Chatterino\chatterino.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Binary Fortress Software Ltd -> Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.CpuIdRemote64.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.DisplayAdapter.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE.exe
(Discord Inc. -> Discord Inc.) C:\Users\gnxks\AppData\Local\DiscordCanary\app-1.0.28\DiscordCanary.exe <6>
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <6>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <24>
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_7c484f80872e1cd8\jhi_service.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_1e5aa28740c131d2\RstMwService.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\LogiCapture\bin\Service\LogiFacecamService.exe
(MAGIX Software GmbH -> MAGIX) C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe
(MAGIX Software GmbH -> simplitec GmbH) C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\NisSrv.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(PLARIUM GLOBAL LTD. -> ) C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\6.2.0-0.0.0\TrayPP.exe
(PLARIUM GLOBAL LTD. -> Plarium) C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\6.2.0-0.0.0\PlariumPlay.exe <4>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung DeX\SamsungDeX.exe
(Signify Netherlands B.V. -> Signify Netherlands B.V.) C:\Program Files\Hue Sync\HueSync.exe
(Skutta, Kristjan -> ) D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\bin\ui32.exe <4>
(Skutta, Kristjan -> ) D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper64.exe
(Spotify AB) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.156.595.0_x86__zpdnekdrzrea0\Spotify.exe <5>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TEFINCOM S.A. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(Tonalio GmbH -> sandboxie-plus.com) D:\HACKS\Sandbox\SbieSvc.exe
(Tonec Inc. -> Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9228800 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [CORSAIR iCUE Software] => C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE Launcher.exe [410152 2020-08-13] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [779448 2021-03-12] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-02-05] (Adobe Inc. -> )
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [5484392 2021-03-03] (Tonec Inc. -> Tonec Inc.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [680720 2021-03-12] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [917200 2020-11-17] (Nota,Inc. -> Nota Inc.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [9011648 2019-12-23] (Binary Fortress Software Ltd -> Binary Fortress Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [PreMiD] => "C:\Users\gnxks\AppData\Roaming\PreMiD\PreMiD.exe" --hidden
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5536424 2021-03-06] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50041472 2021-03-12] (Google LLC -> )
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [PlariumPlay] => C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\PlariumPlay --args -run-with-os
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33169992 2021-03-18] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [WallpaperEngine] => D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper64.exe [3531880 2021-02-16] (Skutta, Kristjan -> )
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [HueSync] => C:\Program Files\Hue Sync\HueSync.exe [17515400 2020-12-16] (Signify Netherlands B.V. -> Signify Netherlands B.V.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe [1151744 2020-08-24] (MAGIX Software GmbH -> MAGIX)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Opera Browser Assistant] => C:\Users\gnxks\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3154456 2020-11-25] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Chatterino] => C:\Users\gnxks\AppData\Local\Programs\Chatterino\chatterino.exe [4754944 2020-11-17] () [Datei ist nicht signiert]
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Samsung DeX] => C:\Program Files (x86)\Samsung\Samsung DeX\SamsungDeX.exe [10398376 2021-01-28] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [DiscordCanary] => C:\Users\gnxks\AppData\Local\DiscordCanary\Update.exe [1512040 2021-02-25] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Discord] => C:\Users\gnxks\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Opera GX Browser Assistant] => C:\Users\gnxks\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Proxifier] => C:\Program Files (x86)\Proxifier\Proxifier.exe [6660016 2021-03-03] (Initeks, OOO -> Initex)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [GoogleChromeAutoLaunch_61793B35B632BA2286F49DD9D1C0CA79] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [SandboxieControl] => "D:\HACKS\Sandbox\SbieCtrl.exe"
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [274176 2021-01-18] (TEFINCOM S.A. -> TEFINCOM S.A.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\RunOnce: [Application Restart #6] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 --flag-switches-begin --disable-quic --enable-smooth-scrolling --enable-features=AutofillShowTypePrediction (Der Dateneintrag hat 229 mehr Zeichen).
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\RunOnce: [Application Restart #4] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 --flag-switches-begin --disable-quic --enable-smooth-scrolling --enable-features=AutofillShowTypePrediction (Der Dateneintrag hat 244 mehr Zeichen).
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Policies\Explorer: [NoInstrumentation] 1
HKLM\...\Providers\Internet Print Provider: inetpp.dll
HKLM\...\Providers\LanMan Print Services: win32spl.dll
HKLM\...\Print\Monitors\Appmon: AppMon.dll
HKLM\...\Print\Monitors\HP C211 Status Monitor: hpinkstsC211LM.dll
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Deskjet 2540 series): HPDiscoPMC211.dll
HKLM\...\Print\Monitors\Local Port: localspl.dll
HKLM\...\Print\Monitors\Microsoft Shared Fax Monitor: FXSMON.DLL
HKLM\...\Print\Monitors\PDF-XChange Standard Port Monitor: C:\WINDOWS\system32\pxcpm.dll [2147584 2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
HKLM\...\Print\Monitors\Standard TCP/IP Port: tcpmon.dll
HKLM\...\Print\Monitors\USB Monitor: usbmon.dll
HKLM\...\Print\Monitors\WSD Port: APMon.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8237E44A-0054-442C-B6B6-EA0509993955}] -> C:\Program Files (x86)\Google\Chrome Beta\Application\90.0.4430.61\Installer\chrmstp.exe [2021-04-07] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\89.0.4389.114\Installer\chrmstp.exe [2021-04-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\89.1.22.71\Installer\chrmstp.exe [2021-04-01] (Brave Software, Inc. -> Brave Software, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{E5931AF4-2A8F-48A5-AFC8-3E048AC137B9}] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\...\Winlogon\GPExtensions: [{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}] -> C:\Windows\SysWOW64\wlgpclnt.dll [2020-09-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{169EBF44-942F-4C43-87CE-13C93996EBBE}] -> C:\Windows\SysWOW64\AppManagementConfiguration.dll [2021-01-15] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{16be69fa-4209-4250-88cb-716cf41954e0}] -> auditcse.dll
HKLM\Software\...\Winlogon\GPExtensions: [{25537BA6-77A8-11D2-9B6C-0000F8080861}] -> C:\Windows\SysWOW64\fdeploy.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{2BFCC077-22D2-48DE-BDE1-2F618D9B476D}] -> C:\Windows\SysWOW64\AppManagementConfiguration.dll [2021-01-15] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{426031c0-0b47-4852-b0ca-ac3d37bfcb39}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{4d968b55-cac2-4ff5-983f-0a54603781a3}] -> WorkFoldersGPExt.dll
HKLM\Software\...\Winlogon\GPExtensions: [{7909AD9E-09EE-4247-BAB9-7029D5F0A278}] -> C:\Windows\SysWOW64\dmenrollengine.dll [2021-03-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2020-09-02] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{9650FDBC-053A-4715-AD14-FC2DC65E8330}] -> hvsigpext.dll
HKLM\Software\...\Winlogon\GPExtensions: [{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}] -> C:\Windows\SysWOW64\dot3gpclnt.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{BA649533-0AAC-4E04-B9BC-4DBAE0325B12}] -> pwlauncher.dll
HKLM\Software\...\Winlogon\GPExtensions: [{C34B2751-1CF4-44F5-9262-C3FC39666591}] -> pwlauncher.dll
HKLM\Software\...\Winlogon\GPExtensions: [{c6dc5466-785a-11d2-84d0-00c04fb169f7}] -> C:\Windows\SysWOW64\appmgmts.dll [2020-10-16] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{F312195E-3D9D-447A-A3F5-08DFFA24735E}] -> dggpext.dll
HKLM\Software\...\Winlogon\GPExtensions: [{f3ccc681-b74c-4060-9f26-cd84525dca2a}] -> auditcse.dll
HKLM\Software\...\Winlogon\GPExtensions: [{FB2CA36D-0B40-4307-821B-A13B252DE56C}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{FC491EF1-C4AA-4CE1-B329-414B101DB823}] -> dggpext.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2021-01-01]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update UWP App.lnk [2019-03-23]
ShortcutAndArgument: Update UWP App.lnk -> C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe => -WindowStyle Hidden -NoLogo -NonInteractive -InputFormat None -NoProfile -ExecutionPolicy Bypass -Command "& 'C:\Program Files (x86)\LastPass\AppxUpgrade.ps1' -PackagePath 'C:\Program Files (x86)\LastPass\lpwinmetro.appxbundle' -PackageName 'LastPass.LastPass
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iCUE.lnk [2019-09-21]
ShortcutTarget: iCUE.lnk -> C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\log.txt [2021-04-06] ()
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wallpaper32.exe [2019-09-28] (Kristjan Skutta -> )
GroupPolicy: Beschränkung ? <==== ACHTUNG
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0106E90F-57D0-4E44-9A82-CF3F0C2F26A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-19] (Google Inc -> Google Inc.)
Task: {02398F6D-5B3C-4669-9DE0-43AB0C8A08C7} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6896800 2020-11-17] (Nota,Inc. -> Nota Inc.)
Task: {08C931ED-7BAC-431E-A77C-439CDB2E130A} - System32\Tasks\sartorial ecologically marshallingsartorial ecologically marshalling => C:\Users\gnxks\AppData\Local\Boaster.exe
Task: {0A50E67E-8040-45E3-AC54-26E610654AA7} - System32\Tasks\presets rozenpresets rozen => C:\Program Files (x86)\Kefauver\Unruffled.exe
Task: {19094E1F-D621-48E8-ACA2-A486360F85D2} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1E03D216-BD54-4C68-927F-54D824B16858} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2216A62B-D7AF-4652-8B7D-05635CAF3017} - System32\Tasks\ZhangWoZheC12-TaskPlan => C:\Program Files\ZELOTES MOUSE (C-12)\ZELOTES(C-12).exe
Task: {27A02945-C013-4D94-8191-5AD75C8BCF26} - System32\Tasks\danto-zeroeddanto-zeroed => C:\Program Files (x86)\lees\Unruffled.exe
Task: {2CAEB079-F779-4A1A-9FD7-0B7643FB9A84} - System32\Tasks\Opera GX scheduled Autoupdate 1591363623 => C:\Users\gnxks\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-03-31] (Opera Software AS -> Opera Software)
Task: {37D1A31E-BFCA-42E3-ADE0-65B01034BD45} - System32\Tasks\Opera scheduled assistant Autoupdate 1576864332 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gnxks\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {38402431-47D9-4590-89D6-686671F7FEBF} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
Task: {3DBAC250-A56C-4EBE-88D5-AFE69FA1C7C9} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248760 2021-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {40BCE62A-1ACE-44DD-AAA8-4795E96B3702} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3660232 2020-02-17] (Easeware Technology Limited -> Easeware)
Task: {428623A4-A7A0-48DF-8F86-68C944D9F1AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4AE9343A-A1F0-4DA3-8083-E96B14D0BDAE} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F344803-33ED-46BD-8933-4B2663543E27} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-03-18] (Piriform Software Ltd -> Piriform)
Task: {52324BF7-F973-4E45-8604-7DF6D563B931} - System32\Tasks\Microsoft\VisualStudio\Updates\UpdateConfiguration_S-1-5-21-2402965086-3410531683-3514658406-1005 => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXConfigurationUpdater.exe [23472 2020-05-19] (Microsoft Corporation -> Microsoft)
Task: {5B4D47E4-D1F5-475D-876C-EC5813566865} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {5C284F6B-D398-4C9A-B043-5FB20CE5B91D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
Task: {5EEC591D-D363-4FE0-8FB6-C0563E8A9D14} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248760 2021-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {60D5D834-8D0B-415C-B30F-12014E0DACE4} - System32\Tasks\MAGIX PC Check & Tuning 2020 (Autopilot.exe) => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe [1754696 2019-07-22] (MAGIX Software GmbH -> simplitec GmbH)
Task: {66A8D936-D160-43F9-A20D-83D3E347F114} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302128 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6755313D-6338-43F6-AD6D-5D79B0536776} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {69B5C771-2F2E-4225-BB02-DC28318FDC17} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6F55A292-61C8-4F1C-8DA9-936600248CE9} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646896 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7B916094-9CDF-4857-9623-FEFF824E655F} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {7C4E1769-E525-4768-9D3C-8F674932CF74} - System32\Tasks\Opera scheduled Autoupdate 1540659554 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software)
Task: {7CE58D19-6B1F-4FBF-A40E-276517EC24EA} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [744968 2019-03-01] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {80D1BB67-A738-45CE-A889-710C86FE5E3A} - System32\Tasks\Opera scheduled Autoupdate 1537686832 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software)
Task: {81B5E6E8-B450-4366-B016-06FB495BF222} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [5745672 2014-03-06] (Hewlett Packard -> Hewlett-Packard Co.)
Task: {84AE3A01-F928-463E-B33B-284496BE7A03} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {8526A9C4-6A2D-4528-BA84-AEF463449F52} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27616328 2021-03-18] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {8C2D8998-1E79-4D2A-AE4D-E04ED149AEEB} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXAutoUpdate.exe [208752 2020-05-19] (Microsoft Corporation -> )
Task: {8CB81A13-AB89-4E2E-88A2-7EE3F4C8775E} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2402965086-3410531683-3514658406-500 => C:\Users\gnxks\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {8F648B96-83FF-41AF-9E94-A8690FADE1FD} - System32\Tasks\MAGIX PC Check & Tuning 2020 => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\PCCT.exe [2449992 2019-07-22] (MAGIX Software GmbH -> MAGIX Software GmbH)
Task: {933F6584-43EE-4E0A-945D-589B9E6761FC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
Task: {95D81D41-D3D0-4323-A285-1260C5E16148} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {97E29870-6A75-4BA3-8F0C-4E43491260C8} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-01-11] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {9BD5D49C-453B-48F6-A3AA-5EC0F6232A38} - System32\Tasks\venial_weisvenial_weis => C:\Program Files (x86)\Kefauver\Boaster.exe
Task: {AB05B368-13F7-468A-9B30-E553C06B5449} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => C:\Windows\SysWOW64\BthUdTask.exe [38400 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {AF0FE55C-49DD-4602-9014-8AC6221A5FFD} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1615903302 => C:\Users\gnxks\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-03-31] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gnxks\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {B5ECE740-A749-4791-8882-0AB3C81D997B} - System32\Tasks\G2MUploadTask-S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupload.exe [31320 2021-04-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {B74A4D2C-C51D-4B33-A18D-8249CFBB83B2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-19] (Google Inc -> Google Inc.)
Task: {BCB9FC0A-7D14-4A49-998F-7C9AA99E455F} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\IntelPTTEKRecertification.exe [919832 2021-02-15] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {BD1F2D7F-0821-41DC-A5AF-837856604DB0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE95F1D6-892B-440F-8422-77430AA6FDF4} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0111449-62A3-43BF-BA7B-FDFDCFEAE198} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0A9D2BB-52F6-46C2-9C24-ECF56C62F604} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-01-11] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {D1D2A371-BB0A-46BA-863D-8A25DA5FD429} - System32\Tasks\Microsoft\Windows\Secondary Authentication Factor\BackgroundTaskDeployment => C:\WINDOWS\System32\DeviceCredentialDeployment.exe [82432 2021-01-15] (Microsoft Windows -> Microsoft Corporation)
Task: {D3E7E47B-4965-4277-9644-A2557D3C085A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [677344 2021-01-30] (Mozilla Corporation -> Mozilla Foundation)
Task: {DA2AD96D-464F-48F6-B60C-1D440F197720} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E305393D-CD51-49FD-AA36-8FA1B93C8DB2} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
Task: {E83092EA-1A06-4BE8-AEA9-9783419F235C} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {E8B748A7-9672-4ABC-886E-1F96474D204F} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6896800 2020-11-17] (Nota,Inc. -> Nota Inc.)
Task: {EC0DEAD1-F4B1-4D1D-8A6C-7C2D05F37F91} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141168 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EEA2F8C6-5154-42D2-9625-4ECA984044AD} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141168 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EF107803-57EA-4382-BCA3-BAE26A64E473} - System32\Tasks\Microsoft\VisualStudio\Updates\UpdateConfiguration_S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXConfigurationUpdater.exe [23472 2020-05-19] (Microsoft Corporation -> Microsoft)
Task: {F67786C0-C38E-45EE-B85F-7CD6996D0D96} - System32\Tasks\LastPassUpdater => C:\Program Files (x86)\LastPass\Updater\Updater.exe [2865552 2019-03-21] (LogMeIn, Inc. -> )
Task: {FA449228-C584-4E77-B501-4AA156008246} - System32\Tasks\G2MUpdateTask-S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupdate.exe [31320 2021-04-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2402965086-3410531683-3514658406-1004.job => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2402965086-3410531683-3514658406-1004.job => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupload.exe
Task: C:\WINDOWS\Tasks\MAGIX PC Check & Tuning 2020 (Autopilot.exe).job => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\DANIEL\K1992-MAGIX PC Check & Tuning 2020 (Autopilot.exe
Task: C:\WINDOWS\Tasks\MAGIX PC Check & Tuning 2020.job => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\PCCT.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Winsock: Catalog9 15 C:\WINDOWS\SysWOW64\vsocklib.dll [44128 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\vsocklib.dll [44128 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9-x64 15 C:\Windows\system32\vsocklib.dll [48224 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9-x64 16 C:\Windows\system32\vsocklib.dll [48224 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{86af3e41-a25f-4a31-a897-a8329e43f830}: [DhcpNameServer] 192.168.2.1
Edge:
=======
Edge Extension: (Kein Name) -> EdgeExtension_TonecIncIDMIntegrationModule_e7b5mm5d3r6v2 => C:\Program Files\WindowsApps\TonecInc.IDMIntegrationModule_6.30.6.0_neutral__e7b5mm5d3r6v2 [2019-04-09]
Edge Extension: (Kein Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.29.0.0_neutral__qq0fmhteeht3j [2019-06-08]
Edge Profile: C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default [2021-04-10]
Edge Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2021-04-09]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-04-09]
Edge Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec [2021-04-09]
Edge Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2021-04-09]
Edge HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2021-03-05]
Edge HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2021-03-05]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: l2px8do5.default
FF DefaultProfile: gbfvkn07.default-1566082662414
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\ParseHub\parsehub\Profiles\l2px8do5.default [2019-03-31]
FF Extension: (ParseHub) - C:\Users\gnxks\AppData\Roaming\ParseHub\parsehub\Profiles\l2px8do5.default\Extensions\parsehub2@parsehub.com.xpi [2019-03-31] [] [ist nicht signiert]
FF Extension: (Kein Name) - Z:\Websites\browser\extensions\install@parsehub.com.xpi [nicht gefunden]
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781 [2021-02-21]
FF Extension: (MySessions) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\balyaev@gmail.com.xpi [2020-11-04]
FF Extension: (Browsec VPN - Free VPN for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\browsec@browsec.com.xpi [2021-01-30]
FF Extension: (cliget) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\cliget@zaidabdulla.com.xpi [2021-01-30]
FF Extension: (Tampermonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\firefox@tampermonkey.net.xpi [2020-11-04]
FF Extension: (FoxyProxy Standard) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\foxyproxy@eric.h.jung.xpi [2020-11-04]
FF Extension: (Tab Reloader (page auto refresh)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid0-bnmfwWw2w2w4e4edvcdDbnMhdVg@jetpack.xpi [2020-11-04]
FF Extension: (Turbo Download Manager (3rd edition)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid0-dsq67mf5kjjhiiju2dfb6kk8dfw@jetpack.xpi [2021-01-30]
FF Extension: (Hola Free VPN Proxy Unblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi [2021-01-30]
FF Extension: (To Google Translate) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2020-11-11]
FF Extension: (download-helper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-i6dUGvCrz2WZu8@jetpack.xpi [2021-01-30]
FF Extension: (Privacy Badger) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2021-01-30]
FF Extension: (Dark Background and Light Text) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2020-11-04]
FF Extension: (Double-click Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2021-01-30]
FF Extension: (ScrollAnywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\juraj.masiar@gmail.com_ScrollAnywhere.xpi [2021-01-30]
FF Extension: (Link Analyzer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\link-analyzer@damufo.xpi [2020-11-04]
FF Extension: (NordVPN #1 VPN Extension: Get VPN for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\nordvpnproxy@nordvpn.com.xpi [2021-01-30]
FF Extension: (Open Multiple URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\openmultipleurls@ustat.de.xpi [2020-11-04]
FF Extension: (PageExpand) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\PageExpand@hakuhin.jp.xpi [2020-11-04]
FF Extension: (HTTP Directory Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\rushikesh988-4@gmail.com.xpi [2020-11-04]
FF Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\support@lastpass.com.xpi [2020-11-04]
FF Extension: (Wildfire) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\support@wildfire.ai.xpi [2020-11-04]
FF Extension: (tumblr Downloader Professional) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\tumblrS@link64.xpi [2020-11-04]
FF Extension: (User-Agent Switcher) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2021-01-30]
FF Extension: (minerBlock) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\xd4rker@gmail.com.xpi [2020-11-04]
FF Extension: (Imagus) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{00000f2a-7cde-4f20-83ed-434fcb420d71}.xpi [2020-11-04] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download with JDownloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{03e07985-30b0-4ae0-8b3e-0c7519b9bdf6}.xpi [2021-01-30]
FF Extension: (Popupblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{05ce2135-ced2-4272-97b0-c00c00a93355}.xpi [2020-11-04]
FF Extension: (PH Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{0adb7d9f-4f8a-43db-890a-5421cd153986}.xpi [2020-11-07]
FF Extension: (Dark Mode) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{174b2d58-b983-4501-ab4b-07e71203cb43}.xpi [2021-01-30]
FF Extension: (UI.Vision RPA) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{190d04a6-e387-4f5b-9751-e0d222cf8275}.xpi [2021-01-30]
FF Extension: (M3U Playlist Converter) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{2755cbda-50f7-4cfe-a497-8585df5be40f}.xpi [2020-11-04]
FF Extension: (A powerful reverse image search tool, with support for various search engines, such as Google, Bing, Yandex, Baidu and TinEye.) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2021-01-30]
FF Extension: (Link Extractor) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{32234610-80fa-4bc1-9cef-183abea3f3b2}.xpi [2020-11-04]
FF Extension: (Download All Images) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2020-11-04]
FF Extension: (AddToAny: Share Anywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{35d49e56-0142-4a7b-82a8-6ace7d28ff92}.xpi [2020-11-04]
FF Extension: (4chan Image Expander & Saver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{3859d492-cbb8-4ce1-a1c2-d9394ea829df}.xpi [2020-11-04] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download Images From Tabs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{45ee564a-8d3a-4efa-92cc-8ff5db92bf93}.xpi [2020-11-04]
FF Extension: (Web Scraper - Free Web Scraping) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{4d22c3b5-8248-4431-ad99-90b1443de5ee}.xpi [2020-11-04]
FF Extension: (Bulk Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi [2020-11-04]
FF Extension: (SingleFile) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{531906d3-e22f-4a6c-a102-8057b88a1a63}.xpi [2021-01-30]
FF Extension: (Don't touch my tabs! (rel=noopener)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{6b938c0c-fc53-4f27-805f-619778631082}.xpi [2020-11-04]
FF Extension: (Open in VLC™ media player) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{6b954d17-d17c-4a19-8fe6-ee8052a562d6}.xpi [2020-11-04]
FF Extension: (NoScript) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-01-30]
FF Extension: (iMacros for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi [2020-11-04]
FF Extension: (Kein Name) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{8b344d1d-265c-4d48-8418-0b522359bad2}.xpi [2020-11-08]
FF Extension: (List open tab URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{92e1f589-b2de-4ad6-bcd5-95ab0699a4fb}.xpi [2020-11-04]
FF Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2021-01-30]
FF Extension: (Reddit Minimizer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{9b76f004-d8fb-46f5-9ce9-47c5412b47ec}.xpi [2020-11-04]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2021-01-30]
FF Extension: (Selenium IDE) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{a6fd85ed-e919-4a43-a5af-8da18bda539f}.xpi [2020-11-04]
FF Extension: (Private Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2020-11-04]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2021-01-30]
FF Extension: (Video DownloadHelper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-01-30]
FF Extension: (Popup blocker for FF: Poper Blocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{bee8b1f2-823a-424c-959c-f8f76c8b2306}.xpi [2020-11-17]
FF Extension: (Bulk URL Opener) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{c5b32a48-5514-4a46-81f2-075ebf3cbc29}.xpi [2021-01-30]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-01-30]
FF Extension: (NZBDonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{dd77cf0b-b93f-4e9f-8006-b642c02219db}.xpi [2020-11-04]
FF Extension: (DownThemAll!) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2020-11-04]
FF Extension: (iDM Integration Extension) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{ed9a84e6-a04e-4d97-ad7e-b7414f2912eb}.xpi [2020-11-04]
FF Extension: (All Video Downloader Pro) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{eef4a074-e2c8-428c-bbe0-63da072bb563}.xpi [2020-11-04]
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414 [2020-11-13]
FF NetworkProxy: Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414 -> backup.ftp", ""
FF Extension: (Facebook Videos and Photoalbums Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\@fud.xpi [2019-08-18]
FF Extension: (MySessions) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\balyaev@gmail.com.xpi [2020-01-20]
FF Extension: (Browsec VPN - Free and Unlimited VPN) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\browsec@browsec.com.xpi [2020-01-04]
FF Extension: (cliget) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\cliget@zaidabdulla.com.xpi [2019-08-18]
FF Extension: (Tampermonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\firefox@tampermonkey.net.xpi [2019-12-19]
FF Extension: (FoxyProxy Standard) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\foxyproxy@eric.h.jung.xpi [2020-01-04]
FF Extension: (Tab Reloader (page auto refresh)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid0-bnmfwWw2w2w4e4edvcdDbnMhdVg@jetpack.xpi [2020-01-05]
FF Extension: (To Google Translate) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2020-01-19]
FF Extension: (download-helper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-i6dUGvCrz2WZu8@jetpack.xpi [2019-10-05]
FF Extension: (Privacy Badger) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2020-01-14]
FF Extension: (Dark Background and Light Text) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2020-01-04]
FF Extension: (Premiumize.me) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-sirVJT0BXhkuJg@jetpack.xpi [2020-01-04]
FF Extension: (Double-click Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2020-01-01]
FF Extension: (ScrollAnywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\juraj.masiar@gmail.com_ScrollAnywhere.xpi [2020-01-05]
FF Extension: (Link Analyzer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\link-analyzer@damufo.xpi [2019-08-18]
FF Extension: (NordVPN – #1 VPN Proxy Extension for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\nordvpnproxy@nordvpn.com.xpi [2020-01-20]
FF Extension: (Open Multiple URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\openmultipleurls@ustat.de.xpi [2019-12-10]
FF Extension: (PageExpand) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\PageExpand@hakuhin.jp.xpi [2019-11-20]
FF Extension: (Reddit Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\RedditVideoDownloader@sas41.ext.xpi [2019-11-05]
FF Extension: (HTTP Directory Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\rushikesh988-4@gmail.com.xpi [2020-01-19]
FF Extension: (Wildfire) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\support@wildfire.ai.xpi [2020-01-05]
FF Extension: (User-Agent Switcher) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2020-01-14]
FF Extension: (minerBlock) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\xd4rker@gmail.com.xpi [2019-08-18]
FF Extension: (Imagus) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{00000f2a-7cde-4f20-83ed-434fcb420d71}.xpi [2019-08-18] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download with JDownloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{03e07985-30b0-4ae0-8b3e-0c7519b9bdf6}.xpi [2019-12-27]
FF Extension: (Popupblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{05ce2135-ced2-4272-97b0-c00c00a93355}.xpi [2019-08-18]
FF Extension: (Dark Mode) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{174b2d58-b983-4501-ab4b-07e71203cb43}.xpi [2019-11-05]
FF Extension: (UI.Vision RPA) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{190d04a6-e387-4f5b-9751-e0d222cf8275}.xpi [2020-01-05]
FF Extension: (M3U Playlist Converter) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{2755cbda-50f7-4cfe-a497-8585df5be40f}.xpi [2019-12-08]
FF Extension: (A powerful reverse image search tool, with support for various search engines, such as Google, Bing, Yandex, Baidu and TinEye.) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2020-01-05]
FF Extension: (Link Extractor) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{32234610-80fa-4bc1-9cef-183abea3f3b2}.xpi [2019-08-18]
FF Extension: (Download all Images) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2020-01-05]
FF Extension: (AddToAny: Share Anywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{35d49e56-0142-4a7b-82a8-6ace7d28ff92}.xpi [2019-08-18]
FF Extension: (4chan Image Expander & Saver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{3859d492-cbb8-4ce1-a1c2-d9394ea829df}.xpi [2019-08-18] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download Images From Tabs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{45ee564a-8d3a-4efa-92cc-8ff5db92bf93}.xpi [2020-01-06]
FF Extension: (AntiCaptcha automatic captcha solver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{487609b5-5ca6-4c62-8523-11f3e1db851c}.xpi [2020-01-06] [UpdateUrl:hxxps://antcpt.com/downloads/firefox/update_manifest.json]
FF Extension: (Bulk Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi [2019-08-18]
FF Extension: (SingleFile) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{531906d3-e22f-4a6c-a102-8057b88a1a63}.xpi [2020-01-22]
FF Extension: (Don't touch my tabs! (rel=noopener)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{6b938c0c-fc53-4f27-805f-619778631082}.xpi [2020-01-05]
FF Extension: (Open in VLC™ media player) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{6b954d17-d17c-4a19-8fe6-ee8052a562d6}.xpi [2019-11-05]
FF Extension: (iMacros for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi [2020-01-05]
FF Extension: (Kein Name) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{8b344d1d-265c-4d48-8418-0b522359bad2}.xpi [2020-01-14]
FF Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2020-01-19]
FF Extension: (Reddit Minimizer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{9b76f004-d8fb-46f5-9ce9-47c5412b47ec}.xpi [2019-08-18]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2019-11-06]
FF Extension: (Selenium IDE) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{a6fd85ed-e919-4a43-a5af-8da18bda539f}.xpi [2020-01-05]
FF Extension: (Private Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2019-08-18]
FF Extension: (Video DownloadHelper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2019-08-18]
FF Extension: (Bulk URL Opener) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{c5b32a48-5514-4a46-81f2-075ebf3cbc29}.xpi [2020-01-06]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-11-05]
FF Extension: (NZBDonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{dd77cf0b-b93f-4e9f-8006-b642c02219db}.xpi [2019-11-24]
FF Extension: (DownThemAll!) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2020-01-04]
FF Extension: (All Video Downloader Pro) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{eef4a074-e2c8-428c-bbe0-63da072bb563}.xpi [2019-11-05]
FF HKLM\...\Firefox\Extensions: [support@lastpass.com] - C:\Program Files (x86)\LastPass\support@lastpass.com.xpi
FF Extension: (LastPass: Free Password Manager) - C:\Program Files (x86)\LastPass\support@lastpass.com.xpi [2019-03-21]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2021-03-05]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\gnxks\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\gnxks\AppData\Roaming\IDM\idmmzcc5 [2019-04-08] [] [ist nicht signiert]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] []
FF Plugin: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-06-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-06-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2021-03-12] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google Inc -> Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\Neuer Ordner\bin\dtplugin\npDeployJava1.dll [2020-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\Neuer Ordner\bin\plugin2\npjp2.dll [2020-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [Keine Datei]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2021-03-12] (Adobe Inc. -> Adobe Systems)
FF Plugin HKU\S-1-5-21-2402965086-3410531683-3514658406-1004: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\gnxks\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-2402965086-3410531683-3514658406-1004: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\gnxks\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [Keine Datei]
StartMenuInternet: Firefox-94437107B3C58B50 - Z:\Websites\parsehub.exe |