Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 05-04-2021
durchgeführt von K1992 (Administrator) auf DANIEL (10-04-2021 11:43:01)
Gestartet von C:\Users\gnxks\Downloads
Geladene Profile: K1992
Platform: Windows 10 Pro Version 20H2 19042.867 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Chrome
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
() [Datei ist nicht signiert] C:\Program Files (x86)\Kinoni\EpocCam\KinoniSvc.exe
() [Datei ist nicht signiert] C:\Program Files\Antares Audio Technologies\Antares Central Services.exe
() [Datei ist nicht signiert] C:\Program Files\OpenVPN Connect\agent_ovpnconnect_1612970385045.exe
() [Datei ist nicht signiert] C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe
() [Datei ist nicht signiert] C:\Users\gnxks\AppData\Local\Programs\Chatterino\chatterino.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Binary Fortress Software Ltd -> Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.CpuIdRemote64.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.DisplayAdapter.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE.exe
(Discord Inc. -> Discord Inc.) C:\Users\gnxks\AppData\Local\DiscordCanary\app-1.0.28\DiscordCanary.exe <6>
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <5>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <41>
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_7c484f80872e1cd8\jhi_service.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_1e5aa28740c131d2\RstMwService.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\LogiCapture\bin\Service\LogiFacecamService.exe
(MAGIX Software GmbH -> MAGIX) C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe
(MAGIX Software GmbH -> simplitec GmbH) C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2101.10.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12101.1001.14.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20122.11121.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\NisSrv.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(PLARIUM GLOBAL LTD. -> ) C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\6.2.0-0.0.0\TrayPP.exe
(PLARIUM GLOBAL LTD. -> Plarium) C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\6.2.0-0.0.0\PlariumPlay.exe <4>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung DeX\SamsungDeX.exe
(Signify Netherlands B.V. -> Signify Netherlands B.V.) C:\Program Files\Hue Sync\HueSync.exe
(Skutta, Kristjan -> ) D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe <4>
(Skutta, Kristjan -> ) D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper64.exe
(Spotify AB) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.156.595.0_x86__zpdnekdrzrea0\Spotify.exe <5>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TEFINCOM S.A. -> TEFINCOM S.A.) C:\Program Files\NordVPN\NordVPN.exe
(TEFINCOM S.A. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(Tonalio GmbH -> sandboxie-plus.com) D:\HACKS\Sandbox\SbieSvc.exe
(Tonec Inc. -> Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9228800 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [CORSAIR iCUE Software] => C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE Launcher.exe [410152 2020-08-13] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [779448 2021-03-12] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-02-05] (Adobe Inc. -> )
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [5484392 2021-03-03] (Tonec Inc. -> Tonec Inc.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [680720 2021-03-12] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [917200 2020-11-17] (Nota,Inc. -> Nota Inc.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [9011648 2019-12-23] (Binary Fortress Software Ltd -> Binary Fortress Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [PreMiD] => "C:\Users\gnxks\AppData\Roaming\PreMiD\PreMiD.exe" --hidden
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5536424 2021-03-06] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50041472 2021-03-12] (Google LLC -> )
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [PlariumPlay] => C:\Users\gnxks\AppData\Local\Plarium\PlariumPlay\PlariumPlay --args -run-with-os
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33169992 2021-03-18] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [WallpaperEngine] => D:\GAMES\Steam BACKUP\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper64.exe [3531880 2021-02-16] (Skutta, Kristjan -> )
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [HueSync] => C:\Program Files\Hue Sync\HueSync.exe [17515400 2020-12-16] (Signify Netherlands B.V. -> Signify Netherlands B.V.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe [1151744 2020-08-24] (MAGIX Software GmbH -> MAGIX)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Opera Browser Assistant] => C:\Users\gnxks\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3154456 2020-11-25] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Chatterino] => C:\Users\gnxks\AppData\Local\Programs\Chatterino\chatterino.exe [4754944 2020-11-17] () [Datei ist nicht signiert]
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Samsung DeX] => C:\Program Files (x86)\Samsung\Samsung DeX\SamsungDeX.exe [10398376 2021-01-28] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [DiscordCanary] => C:\Users\gnxks\AppData\Local\DiscordCanary\Update.exe [1512040 2021-02-25] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Discord] => C:\Users\gnxks\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Opera GX Browser Assistant] => C:\Users\gnxks\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [Proxifier] => C:\Program Files (x86)\Proxifier\Proxifier.exe [6660016 2021-03-03] (Initeks, OOO -> Initex)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [GoogleChromeAutoLaunch_61793B35B632BA2286F49DD9D1C0CA79] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [SandboxieControl] => "D:\HACKS\Sandbox\SbieCtrl.exe"
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [274176 2021-01-18] (TEFINCOM S.A. -> TEFINCOM S.A.)
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\RunOnce: [Application Restart #6] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 --flag-switches-begin --disable-quic --enable-smooth-scrolling --enable-features=AutofillShowTypePrediction (Der Dateneintrag hat 229 mehr Zeichen).
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\RunOnce: [Application Restart #4] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 --flag-switches-begin --disable-quic --enable-smooth-scrolling --enable-features=AutofillShowTypePrediction (Der Dateneintrag hat 244 mehr Zeichen).
HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Policies\Explorer: [NoInstrumentation] 1
HKLM\...\Providers\Internet Print Provider: inetpp.dll
HKLM\...\Providers\LanMan Print Services: win32spl.dll
HKLM\...\Print\Monitors\Appmon: AppMon.dll
HKLM\...\Print\Monitors\HP C211 Status Monitor: hpinkstsC211LM.dll
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Deskjet 2540 series): HPDiscoPMC211.dll
HKLM\...\Print\Monitors\Local Port: localspl.dll
HKLM\...\Print\Monitors\Microsoft Shared Fax Monitor: FXSMON.DLL
HKLM\...\Print\Monitors\PDF-XChange Standard Port Monitor: C:\WINDOWS\system32\pxcpm.dll [2147584 2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
HKLM\...\Print\Monitors\Standard TCP/IP Port: tcpmon.dll
HKLM\...\Print\Monitors\USB Monitor: usbmon.dll
HKLM\...\Print\Monitors\WSD Port: APMon.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8237E44A-0054-442C-B6B6-EA0509993955}] -> C:\Program Files (x86)\Google\Chrome Beta\Application\90.0.4430.61\Installer\chrmstp.exe [2021-04-07] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\89.0.4389.114\Installer\chrmstp.exe [2021-04-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\89.1.22.71\Installer\chrmstp.exe [2021-04-01] (Brave Software, Inc. -> Brave Software, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{E5931AF4-2A8F-48A5-AFC8-3E048AC137B9}] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\...\Winlogon\GPExtensions: [{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}] -> C:\Windows\SysWOW64\wlgpclnt.dll [2020-09-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{169EBF44-942F-4C43-87CE-13C93996EBBE}] -> C:\Windows\SysWOW64\AppManagementConfiguration.dll [2021-01-15] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{16be69fa-4209-4250-88cb-716cf41954e0}] -> auditcse.dll
HKLM\Software\...\Winlogon\GPExtensions: [{25537BA6-77A8-11D2-9B6C-0000F8080861}] -> C:\Windows\SysWOW64\fdeploy.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{2BFCC077-22D2-48DE-BDE1-2F618D9B476D}] -> C:\Windows\SysWOW64\AppManagementConfiguration.dll [2021-01-15] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{426031c0-0b47-4852-b0ca-ac3d37bfcb39}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{4d968b55-cac2-4ff5-983f-0a54603781a3}] -> WorkFoldersGPExt.dll
HKLM\Software\...\Winlogon\GPExtensions: [{7909AD9E-09EE-4247-BAB9-7029D5F0A278}] -> C:\Windows\SysWOW64\dmenrollengine.dll [2021-03-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2020-09-02] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{9650FDBC-053A-4715-AD14-FC2DC65E8330}] -> hvsigpext.dll
HKLM\Software\...\Winlogon\GPExtensions: [{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}] -> C:\Windows\SysWOW64\dot3gpclnt.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{BA649533-0AAC-4E04-B9BC-4DBAE0325B12}] -> pwlauncher.dll
HKLM\Software\...\Winlogon\GPExtensions: [{C34B2751-1CF4-44F5-9262-C3FC39666591}] -> pwlauncher.dll
HKLM\Software\...\Winlogon\GPExtensions: [{c6dc5466-785a-11d2-84d0-00c04fb169f7}] -> C:\Windows\SysWOW64\appmgmts.dll [2020-10-16] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{F312195E-3D9D-447A-A3F5-08DFFA24735E}] -> dggpext.dll
HKLM\Software\...\Winlogon\GPExtensions: [{f3ccc681-b74c-4060-9f26-cd84525dca2a}] -> auditcse.dll
HKLM\Software\...\Winlogon\GPExtensions: [{FB2CA36D-0B40-4307-821B-A13B252DE56C}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}] -> C:\Windows\SysWOW64\gptext.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Winlogon\GPExtensions: [{FC491EF1-C4AA-4CE1-B329-414B101DB823}] -> dggpext.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2019-03-30]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2021-01-01]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update UWP App.lnk [2019-03-23]
ShortcutAndArgument: Update UWP App.lnk -> C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe => -WindowStyle Hidden -NoLogo -NonInteractive -InputFormat None -NoProfile -ExecutionPolicy Bypass -Command "& 'C:\Program Files (x86)\LastPass\AppxUpgrade.ps1' -PackagePath 'C:\Program Files (x86)\LastPass\lpwinmetro.appxbundle' -PackageName 'LastPass.LastPass
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iCUE.lnk [2019-09-21]
ShortcutTarget: iCUE.lnk -> C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE.exe (Corsair Memory, Inc. -> Corsair Memory, Inc.)
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\log.txt [2021-04-06] ()
Startup: C:\Users\gnxks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wallpaper32.exe [2019-09-28] (Kristjan Skutta -> )
GroupPolicy: Beschränkung ? <==== ACHTUNG
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0106E90F-57D0-4E44-9A82-CF3F0C2F26A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-19] (Google Inc -> Google Inc.)
Task: {02398F6D-5B3C-4669-9DE0-43AB0C8A08C7} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6896800 2020-11-17] (Nota,Inc. -> Nota Inc.)
Task: {08C931ED-7BAC-431E-A77C-439CDB2E130A} - System32\Tasks\sartorial ecologically marshallingsartorial ecologically marshalling => C:\Users\gnxks\AppData\Local\Boaster.exe
Task: {0A50E67E-8040-45E3-AC54-26E610654AA7} - System32\Tasks\presets rozenpresets rozen => C:\Program Files (x86)\Kefauver\Unruffled.exe
Task: {19094E1F-D621-48E8-ACA2-A486360F85D2} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1E03D216-BD54-4C68-927F-54D824B16858} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2216A62B-D7AF-4652-8B7D-05635CAF3017} - System32\Tasks\ZhangWoZheC12-TaskPlan => C:\Program Files\ZELOTES MOUSE (C-12)\ZELOTES(C-12).exe
Task: {27A02945-C013-4D94-8191-5AD75C8BCF26} - System32\Tasks\danto-zeroeddanto-zeroed => C:\Program Files (x86)\lees\Unruffled.exe
Task: {27AA4274-5B95-45F6-B1DE-5CA16C19E9CF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5255104 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {2CAEB079-F779-4A1A-9FD7-0B7643FB9A84} - System32\Tasks\Opera GX scheduled Autoupdate 1591363623 => C:\Users\gnxks\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-03-31] (Opera Software AS -> Opera Software)
Task: {2E963AE7-2CCA-4EA8-901E-B2606F25269C} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248760 2021-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {37D1A31E-BFCA-42E3-ADE0-65B01034BD45} - System32\Tasks\Opera scheduled assistant Autoupdate 1576864332 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gnxks\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {38402431-47D9-4590-89D6-686671F7FEBF} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
Task: {40BCE62A-1ACE-44DD-AAA8-4795E96B3702} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3660232 2020-02-17] (Easeware Technology Limited -> Easeware)
Task: {428623A4-A7A0-48DF-8F86-68C944D9F1AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {462577E0-4952-48FC-80FF-CAEF19F8FA20} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5255104 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {4AE9343A-A1F0-4DA3-8083-E96B14D0BDAE} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F344803-33ED-46BD-8933-4B2663543E27} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-03-18] (Piriform Software Ltd -> Piriform)
Task: {52324BF7-F973-4E45-8604-7DF6D563B931} - System32\Tasks\Microsoft\VisualStudio\Updates\UpdateConfiguration_S-1-5-21-2402965086-3410531683-3514658406-1005 => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXConfigurationUpdater.exe [23472 2020-05-19] (Microsoft Corporation -> Microsoft)
Task: {5B4D47E4-D1F5-475D-876C-EC5813566865} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {5C284F6B-D398-4C9A-B043-5FB20CE5B91D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
Task: {600034CF-BB59-4F46-A8BE-873378E78242} - System32\Tasks\Avast Cleanup Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [1659000 2019-07-25] (AVAST Software s.r.o. -> AVAST Software)
Task: {60D5D834-8D0B-415C-B30F-12014E0DACE4} - System32\Tasks\MAGIX PC Check & Tuning 2020 (Autopilot.exe) => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe [1754696 2019-07-22] (MAGIX Software GmbH -> simplitec GmbH)
Task: {66A8D936-D160-43F9-A20D-83D3E347F114} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302128 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6755313D-6338-43F6-AD6D-5D79B0536776} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {69B5C771-2F2E-4225-BB02-DC28318FDC17} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6F55A292-61C8-4F1C-8DA9-936600248CE9} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646896 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7B916094-9CDF-4857-9623-FEFF824E655F} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {7C4E1769-E525-4768-9D3C-8F674932CF74} - System32\Tasks\Opera scheduled Autoupdate 1540659554 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software)
Task: {7CE58D19-6B1F-4FBF-A40E-276517EC24EA} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [744968 2019-03-01] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {80D1BB67-A738-45CE-A889-710C86FE5E3A} - System32\Tasks\Opera scheduled Autoupdate 1537686832 => C:\Users\gnxks\AppData\Local\Programs\Opera\launcher.exe [1886872 2021-04-01] (Opera Software AS -> Opera Software)
Task: {81B5E6E8-B450-4366-B016-06FB495BF222} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [5745672 2014-03-06] (Hewlett Packard -> Hewlett-Packard Co.)
Task: {84AE3A01-F928-463E-B33B-284496BE7A03} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {8526A9C4-6A2D-4528-BA84-AEF463449F52} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27616328 2021-03-18] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {8C2D8998-1E79-4D2A-AE4D-E04ED149AEEB} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXAutoUpdate.exe [208752 2020-05-19] (Microsoft Corporation -> )
Task: {8CB81A13-AB89-4E2E-88A2-7EE3F4C8775E} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2402965086-3410531683-3514658406-500 => C:\Users\gnxks\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {8F648B96-83FF-41AF-9E94-A8690FADE1FD} - System32\Tasks\MAGIX PC Check & Tuning 2020 => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\PCCT.exe [2449992 2019-07-22] (MAGIX Software GmbH -> MAGIX Software GmbH)
Task: {9148909C-5457-4907-8E73-253736790577} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248760 2021-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {933F6584-43EE-4E0A-945D-589B9E6761FC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
Task: {95D81D41-D3D0-4323-A285-1260C5E16148} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {97E29870-6A75-4BA3-8F0C-4E43491260C8} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-01-11] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {9BD5D49C-453B-48F6-A3AA-5EC0F6232A38} - System32\Tasks\venial_weisvenial_weis => C:\Program Files (x86)\Kefauver\Boaster.exe
Task: {AB05B368-13F7-468A-9B30-E553C06B5449} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => C:\Windows\SysWOW64\BthUdTask.exe [38400 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {AF0FE55C-49DD-4602-9014-8AC6221A5FFD} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1615903302 => C:\Users\gnxks\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-03-31] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gnxks\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {B5ECE740-A749-4791-8882-0AB3C81D997B} - System32\Tasks\G2MUploadTask-S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupload.exe [31320 2021-04-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {B74A4D2C-C51D-4B33-A18D-8249CFBB83B2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-09-19] (Google Inc -> Google Inc.)
Task: {BCB9FC0A-7D14-4A49-998F-7C9AA99E455F} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_a93205b6238060e4\lib\IntelPTTEKRecertification.exe [919832 2021-02-15] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {BD1F2D7F-0821-41DC-A5AF-837856604DB0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MpCmdRun.exe [566368 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE95F1D6-892B-440F-8422-77430AA6FDF4} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0111449-62A3-43BF-BA7B-FDFDCFEAE198} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1127664 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0A9D2BB-52F6-46C2-9C24-ECF56C62F604} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2021-01-11] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {D1D2A371-BB0A-46BA-863D-8A25DA5FD429} - System32\Tasks\Microsoft\Windows\Secondary Authentication Factor\BackgroundTaskDeployment => C:\WINDOWS\System32\DeviceCredentialDeployment.exe [82432 2021-01-15] (Microsoft Windows -> Microsoft Corporation)
Task: {D3E7E47B-4965-4277-9644-A2557D3C085A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [677344 2021-01-30] (Mozilla Corporation -> Mozilla Foundation)
Task: {DA2AD96D-464F-48F6-B60C-1D440F197720} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906480 2021-01-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DF366096-582A-41E1-A14D-A09AB544CB88} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141168 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {E305393D-CD51-49FD-AA36-8FA1B93C8DB2} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
Task: {E83092EA-1A06-4BE8-AEA9-9783419F235C} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {E8B748A7-9672-4ABC-886E-1F96474D204F} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6896800 2020-11-17] (Nota,Inc. -> Nota Inc.)
Task: {E9F781DA-475F-4C0E-A50E-BC2039326B97} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141168 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EF107803-57EA-4382-BCA3-BAE26A64E473} - System32\Tasks\Microsoft\VisualStudio\Updates\UpdateConfiguration_S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\VSIXConfigurationUpdater.exe [23472 2020-05-19] (Microsoft Corporation -> Microsoft)
Task: {F67786C0-C38E-45EE-B85F-7CD6996D0D96} - System32\Tasks\LastPassUpdater => C:\Program Files (x86)\LastPass\Updater\Updater.exe [2865552 2019-03-21] (LogMeIn, Inc. -> )
Task: {FA449228-C584-4E77-B501-4AA156008246} - System32\Tasks\G2MUpdateTask-S-1-5-21-2402965086-3410531683-3514658406-1004 => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupdate.exe [31320 2021-04-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2402965086-3410531683-3514658406-1004.job => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2402965086-3410531683-3514658406-1004.job => C:\Users\gnxks\AppData\Local\GoToMeeting\19598\g2mupload.exe
Task: C:\WINDOWS\Tasks\MAGIX PC Check & Tuning 2020 (Autopilot.exe).job => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\Autopilot.exe C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\DANIEL\K1992-MAGIX PC Check & Tuning 2020 (Autopilot.exe
Task: C:\WINDOWS\Tasks\MAGIX PC Check & Tuning 2020.job => C:\Program Files (x86)\MAGIX\MAGIX PC Check & Tuning 2020\PCCT.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Winsock: Catalog9 15 C:\WINDOWS\SysWOW64\vsocklib.dll [44128 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\vsocklib.dll [44128 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9-x64 15 C:\Windows\system32\vsocklib.dll [48224 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Winsock: Catalog9-x64 16 C:\Windows\system32\vsocklib.dll [48224 2020-08-11] (VMware, Inc. -> VMware, Inc.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\..\Interfaces\{5d7c2cd5-9a75-1ac5-6245-118f1c411193}: [NameServer] 103.86.96.100,103.86.99.100
Tcpip\..\Interfaces\{86af3e41-a25f-4a31-a897-a8329e43f830}: [DhcpNameServer] 192.168.2.1
Edge:
=======
Edge Extension: (Kein Name) -> EdgeExtension_TonecIncIDMIntegrationModule_e7b5mm5d3r6v2 => C:\Program Files\WindowsApps\TonecInc.IDMIntegrationModule_6.30.6.0_neutral__e7b5mm5d3r6v2 [2019-04-09]
Edge Extension: (Kein Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.29.0.0_neutral__qq0fmhteeht3j [2019-06-08]
Edge Profile: C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default [2021-04-10]
Edge Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2021-04-09]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-04-09]
Edge Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec [2021-04-09]
Edge Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2021-04-09]
Edge HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2021-03-05]
Edge HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2021-03-05]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: l2px8do5.default
FF DefaultProfile: gbfvkn07.default-1566082662414
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\ParseHub\parsehub\Profiles\l2px8do5.default [2019-03-31]
FF Extension: (ParseHub) - C:\Users\gnxks\AppData\Roaming\ParseHub\parsehub\Profiles\l2px8do5.default\Extensions\parsehub2@parsehub.com.xpi [2019-03-31] [] [ist nicht signiert]
FF Extension: (Kein Name) - Z:\Websites\browser\extensions\install@parsehub.com.xpi [nicht gefunden]
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781 [2021-02-21]
FF Extension: (MySessions) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\balyaev@gmail.com.xpi [2020-11-04]
FF Extension: (Browsec VPN - Free VPN for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\browsec@browsec.com.xpi [2021-01-30]
FF Extension: (cliget) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\cliget@zaidabdulla.com.xpi [2021-01-30]
FF Extension: (Tampermonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\firefox@tampermonkey.net.xpi [2020-11-04]
FF Extension: (FoxyProxy Standard) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\foxyproxy@eric.h.jung.xpi [2020-11-04]
FF Extension: (Tab Reloader (page auto refresh)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid0-bnmfwWw2w2w4e4edvcdDbnMhdVg@jetpack.xpi [2020-11-04]
FF Extension: (Turbo Download Manager (3rd edition)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid0-dsq67mf5kjjhiiju2dfb6kk8dfw@jetpack.xpi [2021-01-30]
FF Extension: (Hola Free VPN Proxy Unblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi [2021-01-30]
FF Extension: (To Google Translate) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2020-11-11]
FF Extension: (download-helper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-i6dUGvCrz2WZu8@jetpack.xpi [2021-01-30]
FF Extension: (Privacy Badger) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2021-01-30]
FF Extension: (Dark Background and Light Text) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2020-11-04]
FF Extension: (Double-click Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2021-01-30]
FF Extension: (ScrollAnywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\juraj.masiar@gmail.com_ScrollAnywhere.xpi [2021-01-30]
FF Extension: (Link Analyzer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\link-analyzer@damufo.xpi [2020-11-04]
FF Extension: (NordVPN #1 VPN Extension: Get VPN for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\nordvpnproxy@nordvpn.com.xpi [2021-01-30]
FF Extension: (Open Multiple URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\openmultipleurls@ustat.de.xpi [2020-11-04]
FF Extension: (PageExpand) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\PageExpand@hakuhin.jp.xpi [2020-11-04]
FF Extension: (HTTP Directory Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\rushikesh988-4@gmail.com.xpi [2020-11-04]
FF Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\support@lastpass.com.xpi [2020-11-04]
FF Extension: (Wildfire) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\support@wildfire.ai.xpi [2020-11-04]
FF Extension: (tumblr Downloader Professional) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\tumblrS@link64.xpi [2020-11-04]
FF Extension: (User-Agent Switcher) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2021-01-30]
FF Extension: (minerBlock) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\xd4rker@gmail.com.xpi [2020-11-04]
FF Extension: (Imagus) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{00000f2a-7cde-4f20-83ed-434fcb420d71}.xpi [2020-11-04] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download with JDownloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{03e07985-30b0-4ae0-8b3e-0c7519b9bdf6}.xpi [2021-01-30]
FF Extension: (Popupblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{05ce2135-ced2-4272-97b0-c00c00a93355}.xpi [2020-11-04]
FF Extension: (PH Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{0adb7d9f-4f8a-43db-890a-5421cd153986}.xpi [2020-11-07]
FF Extension: (Dark Mode) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{174b2d58-b983-4501-ab4b-07e71203cb43}.xpi [2021-01-30]
FF Extension: (UI.Vision RPA) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{190d04a6-e387-4f5b-9751-e0d222cf8275}.xpi [2021-01-30]
FF Extension: (M3U Playlist Converter) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{2755cbda-50f7-4cfe-a497-8585df5be40f}.xpi [2020-11-04]
FF Extension: (A powerful reverse image search tool, with support for various search engines, such as Google, Bing, Yandex, Baidu and TinEye.) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2021-01-30]
FF Extension: (Link Extractor) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{32234610-80fa-4bc1-9cef-183abea3f3b2}.xpi [2020-11-04]
FF Extension: (Download All Images) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2020-11-04]
FF Extension: (AddToAny: Share Anywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{35d49e56-0142-4a7b-82a8-6ace7d28ff92}.xpi [2020-11-04]
FF Extension: (4chan Image Expander & Saver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{3859d492-cbb8-4ce1-a1c2-d9394ea829df}.xpi [2020-11-04] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download Images From Tabs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{45ee564a-8d3a-4efa-92cc-8ff5db92bf93}.xpi [2020-11-04]
FF Extension: (Web Scraper - Free Web Scraping) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{4d22c3b5-8248-4431-ad99-90b1443de5ee}.xpi [2020-11-04]
FF Extension: (Bulk Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi [2020-11-04]
FF Extension: (SingleFile) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{531906d3-e22f-4a6c-a102-8057b88a1a63}.xpi [2021-01-30]
FF Extension: (Don't touch my tabs! (rel=noopener)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{6b938c0c-fc53-4f27-805f-619778631082}.xpi [2020-11-04]
FF Extension: (Open in VLC™ media player) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{6b954d17-d17c-4a19-8fe6-ee8052a562d6}.xpi [2020-11-04]
FF Extension: (NoScript) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-01-30]
FF Extension: (iMacros for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi [2020-11-04]
FF Extension: (Kein Name) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{8b344d1d-265c-4d48-8418-0b522359bad2}.xpi [2020-11-08]
FF Extension: (List open tab URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{92e1f589-b2de-4ad6-bcd5-95ab0699a4fb}.xpi [2020-11-04]
FF Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2021-01-30]
FF Extension: (Reddit Minimizer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{9b76f004-d8fb-46f5-9ce9-47c5412b47ec}.xpi [2020-11-04]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2021-01-30]
FF Extension: (Selenium IDE) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{a6fd85ed-e919-4a43-a5af-8da18bda539f}.xpi [2020-11-04]
FF Extension: (Private Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2020-11-04]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2021-01-30]
FF Extension: (Video DownloadHelper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-01-30]
FF Extension: (Popup blocker for FF: Poper Blocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{bee8b1f2-823a-424c-959c-f8f76c8b2306}.xpi [2020-11-17]
FF Extension: (Bulk URL Opener) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{c5b32a48-5514-4a46-81f2-075ebf3cbc29}.xpi [2021-01-30]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-01-30]
FF Extension: (NZBDonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{dd77cf0b-b93f-4e9f-8006-b642c02219db}.xpi [2020-11-04]
FF Extension: (DownThemAll!) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2020-11-04]
FF Extension: (iDM Integration Extension) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{ed9a84e6-a04e-4d97-ad7e-b7414f2912eb}.xpi [2020-11-04]
FF Extension: (All Video Downloader Pro) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\h1292jlu.bit-1604517672781\Extensions\{eef4a074-e2c8-428c-bbe0-63da072bb563}.xpi [2020-11-04]
FF ProfilePath: C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414 [2020-11-13]
FF NetworkProxy: Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414 -> backup.ftp", ""
FF Extension: (Facebook Videos and Photoalbums Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\@fud.xpi [2019-08-18]
FF Extension: (MySessions) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\balyaev@gmail.com.xpi [2020-01-20]
FF Extension: (Browsec VPN - Free and Unlimited VPN) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\browsec@browsec.com.xpi [2020-01-04]
FF Extension: (cliget) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\cliget@zaidabdulla.com.xpi [2019-08-18]
FF Extension: (Tampermonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\firefox@tampermonkey.net.xpi [2019-12-19]
FF Extension: (FoxyProxy Standard) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\foxyproxy@eric.h.jung.xpi [2020-01-04]
FF Extension: (Tab Reloader (page auto refresh)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid0-bnmfwWw2w2w4e4edvcdDbnMhdVg@jetpack.xpi [2020-01-05]
FF Extension: (To Google Translate) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2020-01-19]
FF Extension: (download-helper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-i6dUGvCrz2WZu8@jetpack.xpi [2019-10-05]
FF Extension: (Privacy Badger) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2020-01-14]
FF Extension: (Dark Background and Light Text) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-QoFqdK4qzUfGWQ@jetpack.xpi [2020-01-04]
FF Extension: (Premiumize.me) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-sirVJT0BXhkuJg@jetpack.xpi [2020-01-04]
FF Extension: (Double-click Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2020-01-01]
FF Extension: (ScrollAnywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\juraj.masiar@gmail.com_ScrollAnywhere.xpi [2020-01-05]
FF Extension: (Link Analyzer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\link-analyzer@damufo.xpi [2019-08-18]
FF Extension: (NordVPN – #1 VPN Proxy Extension for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\nordvpnproxy@nordvpn.com.xpi [2020-01-20]
FF Extension: (Open Multiple URLs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\openmultipleurls@ustat.de.xpi [2019-12-10]
FF Extension: (PageExpand) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\PageExpand@hakuhin.jp.xpi [2019-11-20]
FF Extension: (Reddit Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\RedditVideoDownloader@sas41.ext.xpi [2019-11-05]
FF Extension: (HTTP Directory Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\rushikesh988-4@gmail.com.xpi [2020-01-19]
FF Extension: (Wildfire) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\support@wildfire.ai.xpi [2020-01-05]
FF Extension: (User-Agent Switcher) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2020-01-14]
FF Extension: (minerBlock) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\xd4rker@gmail.com.xpi [2019-08-18]
FF Extension: (Imagus) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{00000f2a-7cde-4f20-83ed-434fcb420d71}.xpi [2019-08-18] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download with JDownloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{03e07985-30b0-4ae0-8b3e-0c7519b9bdf6}.xpi [2019-12-27]
FF Extension: (Popupblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{05ce2135-ced2-4272-97b0-c00c00a93355}.xpi [2019-08-18]
FF Extension: (Dark Mode) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{174b2d58-b983-4501-ab4b-07e71203cb43}.xpi [2019-11-05]
FF Extension: (UI.Vision RPA) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{190d04a6-e387-4f5b-9751-e0d222cf8275}.xpi [2020-01-05]
FF Extension: (M3U Playlist Converter) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{2755cbda-50f7-4cfe-a497-8585df5be40f}.xpi [2019-12-08]
FF Extension: (A powerful reverse image search tool, with support for various search engines, such as Google, Bing, Yandex, Baidu and TinEye.) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{2e5ff8c8-32fe-46d0-9fc8-6b8986621f3c}.xpi [2020-01-05]
FF Extension: (Link Extractor) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{32234610-80fa-4bc1-9cef-183abea3f3b2}.xpi [2019-08-18]
FF Extension: (Download all Images) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2020-01-05]
FF Extension: (AddToAny: Share Anywhere) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{35d49e56-0142-4a7b-82a8-6ace7d28ff92}.xpi [2019-08-18]
FF Extension: (4chan Image Expander & Saver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{3859d492-cbb8-4ce1-a1c2-d9394ea829df}.xpi [2019-08-18] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Download Images From Tabs) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{45ee564a-8d3a-4efa-92cc-8ff5db92bf93}.xpi [2020-01-06]
FF Extension: (AntiCaptcha automatic captcha solver) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{487609b5-5ca6-4c62-8523-11f3e1db851c}.xpi [2020-01-06] [UpdateUrl:hxxps://antcpt.com/downloads/firefox/update_manifest.json]
FF Extension: (Bulk Image Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi [2019-08-18]
FF Extension: (SingleFile) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{531906d3-e22f-4a6c-a102-8057b88a1a63}.xpi [2020-01-22]
FF Extension: (Don't touch my tabs! (rel=noopener)) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{6b938c0c-fc53-4f27-805f-619778631082}.xpi [2020-01-05]
FF Extension: (Open in VLC™ media player) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{6b954d17-d17c-4a19-8fe6-ee8052a562d6}.xpi [2019-11-05]
FF Extension: (iMacros for Firefox) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi [2020-01-05]
FF Extension: (Kein Name) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{8b344d1d-265c-4d48-8418-0b522359bad2}.xpi [2020-01-14]
FF Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2020-01-19]
FF Extension: (Reddit Minimizer) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{9b76f004-d8fb-46f5-9ce9-47c5412b47ec}.xpi [2019-08-18]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2019-11-06]
FF Extension: (Selenium IDE) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{a6fd85ed-e919-4a43-a5af-8da18bda539f}.xpi [2020-01-05]
FF Extension: (Private Video Downloader) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2019-08-18]
FF Extension: (Video DownloadHelper) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2019-08-18]
FF Extension: (Bulk URL Opener) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{c5b32a48-5514-4a46-81f2-075ebf3cbc29}.xpi [2020-01-06]
FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-11-05]
FF Extension: (NZBDonkey) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{dd77cf0b-b93f-4e9f-8006-b642c02219db}.xpi [2019-11-24]
FF Extension: (DownThemAll!) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2020-01-04]
FF Extension: (All Video Downloader Pro) - C:\Users\gnxks\AppData\Roaming\Mozilla\Firefox\Profiles\gbfvkn07.default-1566082662414\Extensions\{eef4a074-e2c8-428c-bbe0-63da072bb563}.xpi [2019-11-05]
FF HKLM\...\Firefox\Extensions: [support@lastpass.com] - C:\Program Files (x86)\LastPass\support@lastpass.com.xpi
FF Extension: (LastPass: Free Password Manager) - C:\Program Files (x86)\LastPass\support@lastpass.com.xpi [2019-03-21]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2021-03-05]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\gnxks\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\gnxks\AppData\Roaming\IDM\idmmzcc5 [2019-04-08] [] [ist nicht signiert]
FF HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] []
FF Plugin: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-06-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-06-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2021-03-12] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google Inc -> Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\Neuer Ordner\bin\dtplugin\npDeployJava1.dll [2020-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\Neuer Ordner\bin\plugin2\npjp2.dll [2020-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [Keine Datei]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2020-01-06] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2021-03-12] (Adobe Inc. -> Adobe Systems)
FF Plugin HKU\S-1-5-21-2402965086-3410531683-3514658406-1004: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\gnxks\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-2402965086-3410531683-3514658406-1004: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\gnxks\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [Keine Datei]
StartMenuInternet: Firefox-94437107B3C58B50 - Z:\Websites\parsehub.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default [2021-04-10]
CHR StartupUrls: Default -> "hxxps://www.youtube.com/","hxxps://www.amazon.de/"
CHR DefaultSearchURL: Default -> hxxps://www.instagram.com/static/images/ico/xxhdpi_launcher.png/99cf3909d459.png
CHR Extension: (Google Übersetzer) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2021-02-20]
CHR Extension: (Präsentationen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-02-20]
CHR Extension: (Just Black) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2021-02-21]
CHR Extension: (BetterTTV) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2021-03-15]
CHR Extension: (Docs) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-02-20]
CHR Extension: (Google Drive) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-20]
CHR Extension: (Web Developer) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2021-02-20]
CHR Extension: (Turn Off the Lights) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2021-04-01]
CHR Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhchdcejhohfmigjafbampogmaanbfkg [2021-02-20]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2021-02-20]
CHR Extension: (YouTube) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-02-20]
CHR Extension: (Twitter Media Downloader) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\cblpjenafgeohmnjknfhpdbdljfkndig [2021-03-27]
CHR Extension: (uBlock Origin) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-03-21]
CHR Extension: (Tampermonkey) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2021-04-09]
CHR Extension: (User-Agent Switcher for Chrome) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg [2021-02-20]
CHR Extension: (Auto Link Bypasser) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\doiagnjlaingkmdjlbfalakpnphfmnoh [2021-03-21]
CHR Extension: (XPath Generator) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\dphfifdfpfabhbkghlmnkkdghbmocfeb [2021-02-20]
CHR Extension: (Video Downloader professional) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2021-02-20]
CHR Extension: (Tabellen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-02-20]
CHR Extension: (Postman) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhbjgbiflinjbdggehcddcbncdddomop [2021-02-20]
CHR Extension: (Streamheroes) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\fibcoefnefcolkjjkjeamcokohnjbagp [2021-02-20]
CHR Extension: (NordVPN — #1 VPN Chrome Extension: Get a VPN) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa [2021-03-27]
CHR Extension: (NordPass® Password Manager & Digital Vault) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\fooolghllnmhmmndgjiamiiodkpenpbb [2021-04-08]
CHR Extension: (Authy) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb [2021-02-20]
CHR Extension: (UI.Vision RPA) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbalfbdmfieckjlnblleoemohcganoc [2021-04-05]
CHR Extension: (HTTPS Everywhere) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2021-02-20]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2021-02-20]
CHR Extension: (Google Docs Offline) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-13]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-04-09]
CHR Extension: (Picture-in-Picture Extension (by Google)) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgfoiooedgoejojocmhlaklaeopbecg [2021-02-20]
CHR Extension: (AirDroid) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgndiocipalkpejnpafdbdlfdjihomd [2021-02-20]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-03-29]
CHR Extension: (Web Scraper - Free Web Scraping) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnhgnonknehpejjnehehllkliplmbmhn [2021-02-20]
CHR Extension: (Image and Video Downloader) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\khnadcdfjbjgojiilfdebbpiepokangj [2021-02-20]
CHR Extension: (Twitter Image Downloader) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljfafhkjifmbnflpbpeoepeponlkodel [2021-02-20]
CHR Extension: (Instagram) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\maonlnecdeecdljpahhnnlmhbmalehlm [2021-02-20]
CHR Extension: (Downloader for OnlyFans.com) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdkjblcbbgncmdipibnbgfoehgdjpaob [2021-02-21]
CHR Extension: (Web Sniffer) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfgffclcpdbgghfgkmooklaendohaef [2021-02-20]
CHR Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2021-03-10]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-20]
CHR Extension: (WebRTC Network Limiter) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\npeicpdbkakmehahjeeohfdhnlpdklia [2021-02-20]
CHR Extension: (vidIQ Vision for YouTube) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2021-04-04]
CHR Extension: (Google Mail) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-02-20]
CHR Extension: (Chrome Media Router) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-03]
CHR Extension: (RSS Feed Reader) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2021-03-14]
CHR Profile: C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-03-15]
CHR Extension: (Präsentationen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-02-24]
CHR Extension: (Docs) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2021-02-24]
CHR Extension: (Google Drive) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-02-24]
CHR Extension: (YouTube) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-02-24]
CHR Extension: (Avira Password Manager) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-03-15]
CHR Extension: (Avira Safe Shopping) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2021-02-24]
CHR Extension: (Tabellen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-02-24]
CHR Extension: (Google Docs Offline) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-15]
CHR Extension: (Avast Online Security) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-02-24]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-03-15]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-03-15]
CHR Extension: (Anwendungs-Launcher für Drive (von Google)) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-02-24]
CHR Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2021-03-15]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-24]
CHR Extension: (Google Mail) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-02-24]
CHR Extension: (Chrome Media Router) - C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-15]
CHR Profile: C:\Users\gnxks\AppData\Local\Google\Chrome\User Data\System Profile [2021-02-24]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2021-03-05]
CHR HKU\S-1-5-21-2402965086-3410531683-3514658406-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2021-03-05]
StartMenuInternet: Google Chrome Beta - C:\Program Files (x86)\Google\Chrome Beta\Application\chrome.exe
Opera:
=======
OPR Profile: C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable [2021-04-06]
OPR DefaultSearchURL: Opera Stable -> hxxp://shadow2531.com/opera/extensions/gmail_compose_support.html
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (WebRTC Control) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\abbdelbgkogfgjkjflgmhebbfjahgalo [2019-11-02]
OPR Extension: (Screensync Screenshot App Turbo Version) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\amehcfbcblckknomikfmijhhbfkalfcj [2020-04-30]
OPR Extension: (Bulk URL Opener) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\aohlmdjhlikgookdbgebjikjmijipnkf [2019-04-02]
OPR Extension: (Free VPN Proxy) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\ddmpfhchafhgfdflhiilhdeaocinlocb [2021-03-19]
OPR Extension: (Browsec VPN - Free VPN for Opera) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\dknfpcdpbkjijldegonllfnnfhabjpde [2021-03-10]
OPR Extension: (Rich Hints Agent) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-03-10]
OPR Extension: (Page Screenshot) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\henfjlgncdjjhkpjhkjdhiimecnigjlm [2020-04-30]
OPR Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2021-04-01]
OPR Extension: (Droplr - Screenshots, Anmerkungen und Screencasts) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\jehccjfmbojnohjjnpnbinkpikndopeo [2020-04-30]
OPR Extension: (WebRTC Leak Prevent) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\jjabaljgaabcnmcoalhaldkmcfbojkkb [2019-04-01]
OPR Extension: ( Copy URLs ) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\kgmdofgghbeipjnddielphhhecgnppab [2019-04-02]
OPR Extension: (User-Agent Switcher and Manager) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\mdhadkjmpbhfdmmoogneplmcpoelfggp [2020-01-14]
OPR Extension: (Amazon Assistant für Opera) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\mmmbddcnnndpbdflpccgcknaaabgldak [2021-03-29]
OPR Extension: (EasyShot: one click full page screenshots) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\npkdeckocgecnojkdbpdjnelfmnmndeb [2020-04-30]
OPR Extension: (SimpleProxy) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\oalcjjbilaklgpajmkkkbdblbamkckai [2019-03-24]
OPR Extension: (Gmail Compose) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\oplkbppbdibcplkemfiadblmhopffnfm [2020-05-17]
OPR Extension: (Nehmen Sie Screenshot der Webseite - FireShot) - C:\Users\gnxks\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbjmgmedeliohhbaefhlplndokcbmjio [2020-04-30]
StartMenuInternet: (HKU\S-1-5-21-2402965086-3410531683-3514658406-1004) Opera GXStable - "C:\Users\gnxks\AppData\Local\Programs\Opera GX\Launcher.exe"
StartMenuInternet: (HKU\S-1-5-21-2402965086-3410531683-3514658406-1004) OperaStable - "C:\Users\gnxks\AppData\Local\Programs\Opera\Launcher.exe"
Brave:
=======
BRA DefaultProfile: Default
BRA Profile: C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2021-03-27]
BRA DefaultSearchKeyword: Default -> :g
BRA Extension: (Avira Password Manager) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-03-27]
BRA Extension: (User-Agent Switcher for Chrome) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg [2020-02-08]
BRA Extension: (NordVPN — #1 VPN Chrome Extension: Get a VPN) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa [2021-03-27]
BRA Extension: (LastPass: Free Password Manager) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-03-27]
BRA Extension: (Malwarebytes Browser Guard) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-03-20]
BRA Extension: (Application Launcher For Drive (by Google)) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-03-20]
BRA Extension: (IDM Integration Module) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2021-03-20]
BRA Extension: (WebRTC Network Limiter) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\npeicpdbkakmehahjeeohfdhnlpdklia [2020-02-08]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2021-03-20]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2021-03-27]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2020-09-13]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2020-09-02]
BRA Extension: (Brave NTP sponsored images) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\obbokncgfcbepeipkhpdepjjoncelefj [2021-03-27]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\gnxks\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2021-03-27]
StartMenuInternet: Brave - C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [842424 2021-03-12] (Adobe Inc. -> Adobe Inc.)
R2 agent_ovpnconnect; C:\Program Files\OpenVPN Connect\agent_ovpnconnect_1612970385045.exe [2445824 2021-02-10] () [Datei ist nicht signiert]
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3780296 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Antares Central Services; C:\Program Files\Antares Audio Technologies\Antares Central Services.exe [5499904 2020-11-10] () [Datei ist nicht signiert]
S4 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.28\atkexComSvc.exe [419264 2018-12-28] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8615864 2020-05-31] (BattlEye Innovations e.K. -> )
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
S4 CleanupPSvc; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [10287216 2019-07-25] (AVAST Software s.r.o. -> AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8788368 2021-03-29] (Microsoft Corporation -> Microsoft Corporation)
S3 CLink4Service; C:\Program Files (x86)\CorsairLink4\CorsairLink4.Service.exe [34344 2018-12-28] (Corsair Memory, Inc. -> Corsair Components, Inc.)
R2 CmWebAdmin.exe; C:\Program Files\CodeMeter\Runtime\bin\CmWebAdmin.exe [11976128 2020-12-21] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [605096 2020-07-17] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe [421928 2020-08-13] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe [56872 2020-08-13] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [5546960 2019-12-23] (Binary Fortress Software Ltd -> Binary Fortress Software)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2019-08-30] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S4 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [859304 2017-02-08] (Tim Kosse -> FileZilla Project)
S4 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [163840 2013-02-13] (Brio) [Datei ist nicht signiert]
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [410864 2021-01-25] (NVIDIA Corporation -> NVIDIA)
S4 GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [22184 2015-07-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
S3 GoogleChromeBetaElevationService; C:\Program Files (x86)\Google\Chrome Beta\Application\90.0.4430.61\elevation_service.exe [1498216 2021-04-07] (Google LLC -> Google LLC)
S4 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [138912 2019-03-15] (eVenture Limited -> eVenture Limited)
S4 iaStorAfsService; C:\windows\IAStorAfsService\iaStorAfsService.exe [2406576 2017-03-28] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2017-01-06] (Microsoft Corporation -> Microsoft Corporation)
R2 KinoniSvc; C:\Program Files (x86)\Kinoni\EpocCam\KinoniSvc.exe [748544 2020-04-18] () [Datei ist nicht signiert]
R2 LogiFacecamService; C:\Program Files\Logitech\LogiCapture\bin\Service\LogiFacecamService.exe [499336 2020-05-18] (Logitech Inc -> Logitech)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-02-21] (Malwarebytes Inc -> Malwarebytes)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [275200 2021-01-18] (TEFINCOM S.A. -> TEFINCOM S.A.)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2298688 2019-03-12] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3171144 2019-03-12] (Electronic Arts, Inc. -> Electronic Arts)
R2 ovpnhelper_service; C:\Program Files\OpenVPN Connect\ovpnhelper_service.exe [2280448 2021-02-10] () [Datei ist nicht signiert]
S3 Rockstar Service; M:\Games\GTA LAUNCHER\Launcher\RockstarService.exe [1676696 2021-03-16] (Rockstar Games, Inc. -> Rockstar Games)
R2 SbieSvc; D:\HACKS\Sandbox\SbieSvc.exe [332264 2021-03-05] (Tonalio GmbH -> sandboxie-plus.com)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5352528 2021-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [183816 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12757520 2020-12-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 TwitchService; C:\Program Files\Common Files\Twitch\TwitchService.exe [334208 2020-06-15] (Twitch Interactive, Inc. -> )
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [746944 2021-01-07] (Oracle Corporation -> Oracle Corporation)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\NisSrv.exe [2483616 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2102.4-0\MsMpEng.exe [128376 2021-03-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2018-04-05] (ASUSTeK Computer Inc. -> )
R1 Asusgio2; C:\WINDOWS\system32\drivers\AsIO2.sys [33504 2019-01-01] (ASUSTeK Computer Inc. -> )
S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [53904 2018-09-05] (AVAST Software s.r.o. -> The OpenVPN Project)
R1 BadlionAnticheat; C:\WINDOWS\system32\drivers\BadlionAnticheat.sys [2479648 2020-05-24] (Microsoft Windows Hardware Compatibility Publisher -> <Turtle Entertainment>)
S3 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv.sys [303712 2018-10-03] (Bluestack Systems, Inc. -> Bluestack System Inc.)
R3 BthAvrcp; C:\WINDOWS\System32\drivers\BthAvrcp.sys [29184 2009-08-13] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 CorsairGamingAudioService; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudioamd64.sys [103664 2018-08-06] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Components, Inc.)
R2 CorsairLLAccess3B84E98236B28D4E075D5737DF9F567A1FB76E8A; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys [21752 2020-07-03] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45984 2020-07-07] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21920 2020-07-07] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 cpuz149; C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys [44320 2021-04-10] (CPUID S.A.R.L.U. -> CPUID)
R3 csr_a2dp; C:\WINDOWS\system32\drivers\bthav.sys [78848 2009-12-21] (Microsoft Windows Hardware Compatibility Publisher -> CSR, plc)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [161288 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 GLCKIO2; C:\WINDOWS\system32\drivers\GLCKIO2.sys [19392 2018-04-23] (ASUSTeK Computer Inc. -> )
R3 iVCam; C:\WINDOWS\system32\DRIVERS\iVCam.sys [1089512 2020-04-04] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft)
R3 JmUsbCcgp; C:\WINDOWS\system32\DRIVERS\jmccgp.sys [17136 2009-07-29] (JMicron Technology Corp. -> JMicron Technology Corp.)
R3 kinonivd; C:\WINDOWS\System32\drivers\kinonivd.sys [283840 2020-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 KINONI_Wave; C:\WINDOWS\system32\drivers\kinonivad.sys [31424 2020-04-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 ksapi64; C:\WINDOWS\system32\drivers\ksapi64.sys [89776 2019-04-05] (Beijing Kingsoft Security software Co.,Ltd -> Kingsoft Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220616 2021-04-09] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-10-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-04-09] (Malwarebytes Inc -> Malwarebytes)
R3 MpKslb32d3d50; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8234890-A82E-4B20-8C68-704052FBF740}\MpKslDrv.sys [97528 2021-04-10] (Microsoft Windows -> Microsoft Corporation)
S3 MSIO; C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys [25616 2018-02-12] (MICSYS Technology Co., Ltd. -> )
R2 NDivert; C:\WINDOWS\System32\drivers\NDivert.sys [105184 2021-02-22] (TEFINCOM S.A. -> )
R3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [37824 2019-11-24] (SoftEther Corporation -> SoftEther Corporation)
R3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [39360 2021-03-29] (TEFINCOM S.A. -> WireGuard LLC)
R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [38608 2020-12-14] (TEFINCOM S.A. -> TEFINCOM S.A.)
S3 phantomtap; C:\WINDOWS\System32\drivers\phantomtap.sys [45056 2019-11-04] (Avira Operations GmbH & Co. KG -> The OpenVPN Project)
R3 pmkbdfltr; C:\WINDOWS\System32\drivers\pmkbdfltr.sys [18832 2009-06-18] (PenMount Test Certification -> PenMount)
R2 ProxifierDrv; C:\WINDOWS\system32\DRIVERS\ProxifierDrv.sys [58104 2020-09-24] (Initeks, OOO -> Initex)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
S3 RtsUpx; C:\windows\system32\drivers\RtsUpx.sys [30328 2018-09-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 SbieDrv; D:\HACKS\Sandbox\SbieDrv.sys [192504 2021-03-05] (Tonalio GmbH -> sandboxie-plus.com)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
R0 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [133944 2020-06-05] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd)
R3 Serial; C:\WINDOWS\system32\DRIVERS\wdfserial.sys [89976 2018-04-26] (LG Electronics Inc. -> LG Electronics Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [168968 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [45064 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
R3 tap_ovpnconnect; C:\WINDOWS\System32\drivers\tap_ovpnconnect.sys [40128 2021-02-10] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2019-09-16] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [239872 2021-01-07] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [249776 2021-01-07] (Oracle Corporation -> Oracle Corporation)
S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [174968 2021-01-07] (Oracle Corporation -> Oracle Corporation)
R0 veracrypt; C:\WINDOWS\System32\drivers\veracrypt.sys [829320 2019-04-08] (IDRIX -> IDRIX)
R2 VMnetBridge; C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys [67072 2021-03-25] (VMware, Inc. -> VMware, Inc.)
R3 VOICEMOD_Driver; C:\WINDOWS\system32\drivers\vmdrv.sys [48136 2021-01-13] (Voicemod Sociedad Limitada -> Windows (R) Win 7 DDK provider)
R0 vsock; C:\WINDOWS\System32\DRIVERS\vsock.sys [105912 2020-08-11] (VMware, Inc. -> VMware, Inc.)
S3 WacHidRouterPro; C:\WINDOWS\System32\drivers\wachidrouter.sys [127512 2020-09-18] (WDKTestCert dant,132134237881206156 -> Wacom Technology, Corp.)
R3 wacomrouterfilter; C:\WINDOWS\System32\drivers\wacomrouterfilter.sys [28680 2020-09-18] (WDKTestCert dant,132134237881206156 -> Wacom Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-03-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [420072 2021-03-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [72952 2021-03-16] (Microsoft Windows -> Microsoft Corporation)
R3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [38176 2020-09-13] (WireGuard LLC -> WireGuard LLC)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) |