![]() |
|
Plagegeister aller Art und deren Bekämpfung: Misleading:Win32/Lodi Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() Misleading:Win32/Lodi Virus? Hallo Freunde, nachdem ich viele Jahre meine Ruhe hatte und lange keine Probleme mit Viren hat es mich wohl wieder einmal erwischt... ich bekomme alle 5 Minuten die Nachricht von Windows, dass eine Potenzielle Bedrohung auf meinem Rechner gefunden wurde. Misleading:Win32/Lodi Hier ist einmal ein frisches FRST und die Addition.txt Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:28-07-2015 durchgeführt von Azad (Administrator) auf DESKTOP-VOMS6S7 (13-10-2020 18:03:58) Gestartet von C:\Users\Azad\Downloads Geladene Profile: Azad (Verfügbare Profile: Azad) Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) konnte nicht auf den Prozess zugreifen -> Registry (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe konnte nicht auf den Prozess zugreifen -> Memory Compression (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Chip Digital GmbH) C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe (Electronic Arts) D:\Origin\OriginWebHelperService.exe (Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe (Microsoft Corporation) C:\Windows\System32\SgrmBroker.exe (Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.7-0\MsMpEng.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.7-0\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Microsoft Corporation) C:\Windows\System32\sihost.exe (Microsoft Corporation) C:\Windows\System32\taskhostw.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20092.108.0_x64__8wekyb3d8bbwe\YourPhone.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthSystray.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Microsoft Corporation) C:\Windows\System32\CompPkgSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Apple Inc.) C:\ProgramData\iMobieDNA\AppleDriver\AppleMobileDeviceProcess.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12109.3.52015.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2009.23741.0_x64__8wekyb3d8bbwe\Cortana.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_11.4.12.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe (Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_11.4.12.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_11.4.12.0_x86__nzyj5cx40ttqa\iCloud\iCloudDrive.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_11.4.12.0_x86__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_11.4.12.0_x86__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\ApplicationFrameHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12009.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20082.10421.0_x64__8wekyb3d8bbwe\Video.UI.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.20090.1002.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.46.22742.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe () C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe (Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe (Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\SystemSettingsBroker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Windows\system32\SecurityHealthSystray.exe [86016 2019-12-07] (Microsoft Corporation) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2012-12-19] (Pixart Imaging Inc) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] () HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [638352 2018-05-17] (Citrix Systems, Inc.) HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [407440 2018-05-17] (Citrix Systems, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710264 2020-06-18] (Oracle Corporation) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [30870320 2019-12-07] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [30870320 2019-12-07] (Microsoft Corporation) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [OneDrive] => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\OneDrive.exe [1915752 2020-09-11] (Microsoft Corporation) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [Steam] => C:\Steam\steam.exe [3416352 2020-10-07] (Valve Corporation) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [HP Officejet 4630 series (NET)] => C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [Discord] => C:\Users\Azad\AppData\Local\Discord\app-0.0.307\Discord.exe [91023672 2020-08-04] (Discord Inc.) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [Spotify] => C:\Users\Azad\AppData\Roaming\Spotify\Spotify.exe [22824680 2020-05-22] (Spotify Ltd) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [com.blitz.app] => C:\Users\Azad\AppData\Local\Blitz\Update.exe --processStart "Blitz.exe" --process-start-args "--hidden" HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [AnyTransToolHelper] => C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe [572928 2020-08-31] (iMobie Inc.) HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\amd64\FileSyncShell64.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Users\Azad\AppData\Local\Microsoft\OneDrive\20.143.0716.0003\FileSyncShell.dll [2020-09-11] (Microsoft Corporation) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-21-4008508967-1143171168-3858184327-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COS2&ptag=D090920-A74DCDF78DC&form=CONMHP&conlogo=CT3335043 SearchScopes: HKU\S-1-5-21-4008508967-1143171168-3858184327-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COS2&ptag=D090920-N0700A74DCDF78DC&form=CONBDF&conlogo=CT3335043&q={searchTerms} BHO: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho_64.dll [2020-10-08] (Microsoft Corporation) BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_261\bin\ssv.dll [2020-07-23] (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-07-23] (Oracle Corporation) BHO-x32: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho.dll [2020-10-08] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2019-06-12] (Microsoft Corporation) Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2019-12-07] (Microsoft Corporation) Handler-x32: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2019-12-07] (Microsoft Corporation) Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-05-17] (Citrix Systems, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{d7c8a815-ac65-4c33-bc3f-70bb13fdd9e7}: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Azad\AppData\Roaming\Mozilla\Firefox\Profiles\6uu47y6w.default FF NewTab: https://defaultsearch.co/homepage?hp=1&pId=CH180901FF&iDate=2020-09-09 04:09:01&bName=&bitmask=0600 FF DefaultSearchEngine: Bing Default Search FF SelectedSearchEngine: Bing Default Search FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_433.dll [2020-09-08] () FF Plugin: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-23] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-23] (Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_433.dll [2020-09-08] () FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2018-05-17] (Citrix Systems, Inc.) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-06-25] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-09-11] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2019-06-25] (Microsoft Corporation) FF Extension: Kein Name - C:\Users\Azad\AppData\Roaming\Mozilla\Firefox\Profiles\6uu47y6w.default\Extensions\jid1-OY8Xu5BsKZQa6A@jetpack.xpi [2018-11-06] FF Extension: Kein Name - C:\Users\Azad\AppData\Roaming\Mozilla\Firefox\Profiles\6uu47y6w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-08-29] StartMenuInternet: Firefox-308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Slides) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-10-22] CHR Extension: (Docs) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-10-22] CHR Extension: (Google Drive) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-10-22] CHR Extension: (YouTube) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-10-22] CHR Extension: (Sheets) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-10-22] CHR Extension: (Google Docs Offline) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-10-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-22] CHR Extension: (Gmail) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-10-22] CHR Extension: (Chrome Media Router) - C:\Users\Azad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-22] ==================== Services (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-08] (Adobe) S3 AJRouter; C:\Windows\System32\AJRouter.dll [26112 2019-12-07] (Microsoft Corporation) S4 AppVClient; C:\Windows\system32\AppVClient.exe [756552 2020-08-11] (Microsoft Corporation) S3 AssignedAccessManagerSvc; C:\Windows\System32\assignedaccessmanagersvc.dll [859136 2020-09-11] (Microsoft Corporation) S3 autotimesvc; C:\Windows\System32\autotimesvc.dll [114176 2019-12-07] (Microsoft Corporation) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7356680 2018-10-06] () R2 BrokerInfrastructure; C:\Windows\System32\psmsrv.dll [247296 2020-08-11] (Microsoft Corporation) S3 BTAGService; C:\Windows\System32\BTAGService.dll [1021952 2020-09-11] (Microsoft Corporation) S3 BTAGService; C:\Windows\SysWOW64\BTAGService.dll [733184 2020-09-11] (Microsoft Corporation) R3 BthAvctpSvc; C:\Windows\System32\BthAvctpSvc.dll [392192 2020-08-11] (Microsoft Corporation) R3 camsvc; C:\Windows\system32\CapabilityAccessManager.dll [389632 2020-08-11] (Microsoft Corporation) R2 CDPSvc; C:\Windows\System32\CDPSvc.dll [609792 2020-09-11] (Microsoft Corporation) R2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2018-10-25] (Chip Digital GmbH) [Datei ist nicht signiert] S3 ClipSVC; C:\Windows\System32\ClipSVC.dll [1092392 2020-09-11] (Microsoft Corporation) R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [986976 2020-08-14] (Microsoft Corporation) R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [630088 2020-08-14] (Microsoft Corporation) S3 DevQueryBroker; C:\Windows\system32\DevQueryBroker.dll [65024 2019-12-07] (Microsoft Corporation) S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [94208 2020-09-11] (Microsoft Corporation) S3 diagsvc; C:\Windows\system32\DiagSvc.dll [203264 2020-08-11] (Microsoft Corporation) R2 DispBrokerDesktopSvc; C:\Windows\System32\DispBroker.Desktop.dll [378368 2020-08-11] (Microsoft Corporation) R3 DisplayEnhancementService; C:\Windows\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll [1188352 2020-08-11] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [1008640 2020-09-11] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [707584 2020-09-11] (Microsoft Corporation) S3 dmwappushservice; C:\Windows\system32\dmwappushsvc.dll [58880 2019-12-07] (Microsoft Corporation) S2 DoSvc; C:\Windows\System32\svchost.exe [57368 2019-12-07] (Microsoft Corporation) S2 DoSvc; C:\Windows\SysWOW64\svchost.exe [47232 2019-12-07] (Microsoft Corporation) R3 DsSvc; C:\Windows\System32\DsSvc.dll [162816 2020-08-11] (Microsoft Corporation) R2 DusmSvc; C:\Windows\System32\dusmsvc.dll [341504 2019-12-07] (Microsoft Corporation) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2020-02-28] (EasyAntiCheat Ltd) S2 edgeupdate; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [224160 2020-08-09] (Microsoft Corporation) S3 edgeupdatem; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [224160 2020-08-09] (Microsoft Corporation) S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [160256 2019-12-07] (Microsoft Corporation) S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [592384 2020-08-11] (Microsoft Corporation) S3 FrameServer; C:\Windows\system32\FrameServer.dll [986624 2020-08-14] (Microsoft Corporation) S3 GoogleChromeElevationService; C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.75\elevation_service.exe [1406448 2020-10-05] (Google LLC) S3 GraphicsPerfSvc; C:\Windows\System32\GraphicsPerfSvc.dll [106496 2019-12-07] (Microsoft Corporation) S3 HvHost; C:\Windows\System32\hvhostsvc.dll [66360 2019-12-07] (Microsoft Corporation) S3 icssvc; C:\Windows\System32\tetheringservice.dll [237568 2020-09-11] (Microsoft Corporation) R3 InstallService; C:\Windows\system32\InstallService.dll [2422784 2020-09-11] (Microsoft Corporation) R3 InstallService; C:\Windows\SysWOW64\InstallService.dll [1834496 2020-09-11] (Microsoft Corporation) S3 IpxlatCfgSvc; C:\Windows\System32\IpxlatCfg.dll [66048 2019-12-07] (Microsoft Corporation) R3 lfsvc; C:\Windows\System32\lfsvc.dll [48640 2019-12-07] (Microsoft Corporation) R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [51200 2019-12-07] (Microsoft Corporation) S3 LxpSvc; C:\Windows\System32\LanguageOverlayServer.dll [302592 2019-12-07] (Microsoft Corporation) S2 MapsBroker; C:\Windows\System32\moshost.dll [94720 2019-12-07] (Microsoft Corporation) S3 MicrosoftEdgeElevationService; C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\elevation_service.exe [1535376 2020-10-08] (Microsoft Corporation) S3 MixedRealityOpenXRSvc; C:\Windows\System32\MixedRealityRuntime.dll [134248 2019-12-07] (Microsoft Corporation) S3 MixedRealityOpenXRSvc; C:\Windows\SysWOW64\MixedRealityRuntime.dll [104808 2019-12-07] (Microsoft Corporation) S3 NaturalAuthentication; C:\Windows\System32\NaturalAuth.dll [454144 2020-08-11] (Microsoft Corporation) S3 NetSetupSvc; C:\Windows\System32\NetSetupSvc.dll [309248 2019-12-07] (Microsoft Corporation) R3 NgcCtnrSvc; C:\Windows\System32\NgcCtnrSvc.dll [768512 2020-08-14] (Microsoft Corporation) R3 NgcSvc; C:\Windows\system32\ngcsvc.dll [922112 2020-08-14] (Microsoft Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [884024 2020-09-24] (NVIDIA Corporation) S3 Origin Client Service; D:\Origin\OriginClientService.exe [2519864 2020-09-09] (Electronic Arts) R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3473216 2020-09-09] (Electronic Arts) S3 perceptionsimulation; C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe [105984 2020-08-11] (Microsoft Corporation) S3 PhoneSvc; C:\Windows\System32\PhoneService.dll [954880 2020-08-11] (Microsoft Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2020-07-10] () S3 PushToInstall; C:\Windows\system32\PushToInstall.dll [263168 2020-08-11] (Microsoft Corporation) S2 RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe [170352 2020-04-10] (TMRG, Inc.) <==== ATTENTION S3 RetailDemo; C:\Windows\system32\RDXService.dll [738304 2019-12-07] (Microsoft Corporation) R3 RmSvc; C:\Windows\System32\RMapi.dll [152576 2020-08-14] (Microsoft Corporation) R2 RtkAudioUniversalService; C:\Windows\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor) R3 SecurityHealthService; C:\Windows\system32\SecurityHealthService.exe [976680 2020-09-11] (Microsoft Corporation) S3 SEMgrSvc; C:\Windows\system32\SEMgrSvc.dll [1222656 2020-08-11] (Microsoft Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097896 2020-09-11] (Microsoft Corporation) S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1263104 2019-12-07] (Microsoft Corporation) S3 SensorService; C:\Windows\system32\SensorService.dll [466432 2020-08-11] (Microsoft Corporation) R2 SgrmBroker; C:\Windows\system32\SgrmBroker.exe [329496 2020-08-11] (Microsoft Corporation) S3 SharedRealitySvc; C:\Windows\System32\SharedRealitySvc.dll [306688 2019-12-07] (Microsoft Corporation) S4 shpamsvc; C:\Windows\system32\Windows.SharedPC.AccountManager.dll [224768 2020-08-11] (Microsoft Corporation) S3 SmsRouter; C:\Windows\system32\SmsRouterSvc.dll [625664 2019-12-07] (Microsoft Corporation) S3 spectrum; C:\Windows\system32\spectrum.exe [874496 2020-08-11] (Microsoft Corporation) S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [384512 2019-10-15] () R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [5870496 2020-09-11] (Microsoft Corporation) R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [5430480 2020-09-11] (Microsoft Corporation) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109264 2020-06-22] (TeamViewer Germany GmbH) S3 TieringEngineService; C:\Windows\system32\TieringEngineService.exe [325632 2019-12-07] (Microsoft Corporation) R3 TimeBrokerSvc; C:\Windows\System32\TimeBrokerServer.dll [179200 2019-12-07] (Microsoft Corporation) R3 TokenBroker; C:\Windows\System32\TokenBroker.dll [1530880 2020-09-11] (Microsoft Corporation) R3 TokenBroker; C:\Windows\SysWOW64\TokenBroker.dll [1239552 2020-08-11] (Microsoft Corporation) S3 TroubleshootingSvc; C:\Windows\system32\MitigationClient.dll [417792 2020-08-11] (Microsoft Corporation) S4 tzautoupdate; C:\Windows\system32\tzautoupdate.dll [97792 2019-12-07] (Microsoft Corporation) S4 tzautoupdate; C:\Windows\SysWOW64\tzautoupdate.dll [73216 2019-12-07] (Microsoft Corporation) S4 UevAgentService; C:\Windows\system32\AgentService.exe [1201152 2020-09-11] (Microsoft Corporation) R2 UserManager; C:\Windows\System32\usermgr.dll [1488384 2020-09-11] (Microsoft Corporation) R2 UsoSvc; C:\Windows\system32\usosvc.dll [566272 2020-09-11] (Microsoft Corporation) S3 VacSvc; C:\Windows\System32\vac.dll [383224 2020-08-11] (Microsoft Corporation) S3 VBoxSDS; D:\Virtual Box\VBoxSDS.exe [744968 2020-06-04] (Oracle Corporation) S3 vmicrdv; C:\Windows\System32\icsvcext.dll [304640 2020-08-11] (Microsoft Corporation) S3 vmicvmsession; C:\Windows\System32\icsvc.dll [292152 2019-12-07] (Microsoft Corporation) S3 vmicvss; C:\Windows\System32\icsvcext.dll [304640 2020-08-11] (Microsoft Corporation) R3 WaaSMedicSvc; C:\Windows\System32\WaaSMedicSvc.dll [362496 2020-08-14] (Microsoft Corporation) S3 WalletService; C:\Windows\system32\WalletService.dll [441856 2020-08-14] (Microsoft Corporation) S3 WarpJITSvc; C:\Windows\System32\Windows.WARP.JITService.dll [65536 2019-12-07] (Microsoft Corporation) S3 WFDSConMgrSvc; C:\Windows\System32\wfdsconmgrsvc.dll [675840 2019-12-07] (Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-07] (Microsoft Corporation) S3 wisvc; C:\Windows\system32\flightsettings.dll [939448 2020-09-11] (Microsoft Corporation) S3 wisvc; C:\Windows\SysWOW64\flightsettings.dll [750976 2020-09-11] (Microsoft Corporation) S3 wlpasvc; C:\Windows\System32\lpasvc.dll [1253376 2020-08-14] (Microsoft Corporation) S3 WManSvc; C:\Windows\system32\Windows.Management.Service.dll [934912 2020-09-11] (Microsoft Corporation) S3 WpcMonSvc; C:\Windows\System32\WpcDesktopMonSvc.dll [1905664 2020-09-11] (Microsoft Corporation) R2 WpnService; C:\Windows\system32\WpnService.dll [244736 2019-12-07] (Microsoft Corporation) R3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [1046528 2020-08-14] (Microsoft Corporation) S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1267712 2020-08-11] (Microsoft Corporation) S3 XboxGipSvc; C:\Windows\System32\XboxGipSvc.dll [72704 2019-12-07] (Microsoft Corporation) S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1293824 2020-09-11] (Microsoft Corporation) R3 WdNisSvc; "%ProgramData%\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe" [X] S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Wondershare UniConverter (Desktop Deutsch)\Transfer\DriverInstall.exe" [X] ==================== Drivers (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AarSvc; No ImagePath R3 AarSvc_95637d8b; No ImagePath S3 AcpiDev; C:\Windows\System32\drivers\AcpiDev.sys [23040 2019-12-07] (Microsoft Corporation) S3 Acx01000; C:\Windows\System32\drivers\Acx01000.sys [415232 2019-12-07] (Microsoft Corporation) R1 afunix; C:\Windows\system32\drivers\afunix.sys [41984 2020-09-11] (Microsoft Corporation) S3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [18432 2019-12-07] (Advanced Micro Devices, Inc) S3 amdi2c; C:\Windows\System32\drivers\amdi2c.sys [45568 2019-12-07] (Advanced Micro Devices, Inc) S3 AppleKmdfFilter; C:\Windows\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (Apple Inc.) S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (Apple Inc.) S3 applockerfltr; C:\Windows\System32\drivers\applockerfltr.sys [18432 2020-09-11] (Microsoft Corporation) S3 AppvStrm; C:\Windows\system32\drivers\AppvStrm.sys [138272 2019-12-07] (Microsoft Corporation) S3 AppvVemgr; C:\Windows\system32\drivers\AppvVemgr.sys [174608 2019-12-07] (Microsoft Corporation) S3 AppvVfs; C:\Windows\system32\drivers\AppvVfs.sys [154936 2019-12-07] (Microsoft Corporation) S0 b06bdrv; C:\Windows\System32\drivers\bxvbda.sys [533816 2019-12-07] (QLogic Corporation) R1 bam; C:\Windows\System32\drivers\bam.sys [78136 2019-12-07] (Microsoft Corporation) R1 BasicDisplay; C:\Windows\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_62ba5773ba05edee\BasicDisplay.sys [68608 2019-12-07] (Microsoft Corporation) R1 BasicRender; C:\Windows\System32\DriverStore\FileRepository\basicrender.inf_amd64_49a8589f00d970d9\BasicRender.sys [38912 2020-08-11] (Microsoft Corporation) S3 BcastDVRUserService; No ImagePath S3 BcastDVRUserService_95637d8b; No ImagePath R2 bindflt; C:\Windows\system32\drivers\bindflt.sys [143160 2020-08-11] (Microsoft Corporation) R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-07-26] (Bluestack System Inc. ) S3 BluetoothUserService; No ImagePath S3 BluetoothUserService_95637d8b; No ImagePath S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) S3 BthLEEnum; C:\Windows\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [106496 2020-09-11] (Microsoft Corporation) S3 BthMini; C:\Windows\System32\drivers\BTHMINI.sys [45568 2020-09-11] (Microsoft Corporation) S0 bttflt; C:\Windows\System32\drivers\bttflt.sys [43832 2019-12-07] (Microsoft Corporation) S3 buttonconverter; C:\Windows\System32\drivers\buttonconverter.sys [44032 2019-12-07] (Microsoft Corporation) S3 CAD; C:\Windows\System32\drivers\CAD.sys [66576 2019-12-07] (Microsoft Corporation) S3 CaptureService; No ImagePath S3 CaptureService_95637d8b; No ImagePath S3 cbdhsvc; No ImagePath R3 cbdhsvc_95637d8b; No ImagePath S2 CDPUserSvc; No ImagePath R2 CDPUserSvc_95637d8b; No ImagePath S0 cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [319800 2019-12-07] (Chelsio Communications) S3 cht4vbd; C:\Windows\System32\drivers\cht4vx64.sys [1853752 2019-12-07] (Chelsio Communications) R1 CimFS; C:\Windows\System32\Drivers\CimFS.sys [91136 2019-12-07] () R2 CldFlt; C:\Windows\System32\drivers\cldflt.sys [491520 2020-09-11] (Microsoft Corporation) S4 cnghwassist; C:\Windows\System32\DRIVERS\cnghwassist.sys [40968 2019-12-07] (Microsoft Corporation) R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys [41984 2019-12-07] (Microsoft Corporation) S3 ConsentUxUserSvc; No ImagePath S3 ConsentUxUserSvc_95637d8b; No ImagePath S3 CredentialEnrollmentManagerUserSvc; No ImagePath S3 CredentialEnrollmentManagerUserSvc_95637d8b; No ImagePath S3 DeviceAssociationBrokerSvc; No ImagePath S3 DeviceAssociationBrokerSvc_95637d8b; No ImagePath S3 DevicePickerUserSvc; No ImagePath S3 DevicePickerUserSvc_95637d8b; No ImagePath S3 DevicesFlowUserSvc; No ImagePath S3 DevicesFlowUserSvc_95637d8b; No ImagePath R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [254528 2018-11-26] (DT Soft Ltd) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3418936 2019-12-07] (QLogic Corporation) R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [59392 2019-12-07] (Microsoft Corporation) S3 genericusbfn; C:\Windows\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys [23040 2019-12-07] (Microsoft Corporation) R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8704 2019-12-07] (Microsoft Corporation) S3 hidinterrupt; C:\Windows\System32\drivers\hidinterrupt.sys [55824 2019-12-07] (Microsoft Corporation) S3 hidspi; C:\Windows\System32\drivers\hidspi.sys [66560 2019-12-07] (Microsoft Corporation) S4 hvcrash; C:\Windows\System32\drivers\hvcrash.sys [35128 2019-12-07] (Microsoft Corporation) S3 hvservice; C:\Windows\System32\drivers\hvservice.sys [95032 2020-09-11] (Microsoft Corporation) S3 HwNClx0101; C:\Windows\System32\Drivers\mshwnclx.sys [30208 2019-12-07] (Microsoft Corporation) S3 iagpio; C:\Windows\System32\drivers\iagpio.sys [36352 2019-12-07] (Intel(R) Corporation) S3 iai2c; C:\Windows\System32\drivers\iai2c.sys [91136 2019-12-07] (Intel(R) Corporation) S3 iaLPSS2i_GPIO2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [79360 2019-12-07] (Intel Corporation) S3 iaLPSS2i_GPIO2_BXT_P; C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [93184 2019-12-07] (Intel Corporation) S3 iaLPSS2i_GPIO2_CNL; C:\Windows\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [112128 2019-12-07] (Intel Corporation) S3 iaLPSS2i_GPIO2_GLK; C:\Windows\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [96256 2019-12-07] (Intel Corporation) S3 iaLPSS2i_I2C; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [171520 2019-12-07] (Intel Corporation) S3 iaLPSS2i_I2C_BXT_P; C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [175104 2019-12-07] (Intel Corporation) S3 iaLPSS2i_I2C_CNL; C:\Windows\System32\drivers\iaLPSS2i_I2C_CNL.sys [177152 2019-12-07] (Intel Corporation) S3 iaLPSS2i_I2C_GLK; C:\Windows\System32\drivers\iaLPSS2i_I2C_GLK.sys [177664 2019-12-07] (Intel Corporation) S0 iaStorAVC; C:\Windows\System32\drivers\iaStorAVC.sys [884752 2019-12-07] (Intel Corporation) S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [558904 2019-12-07] (Mellanox) S1 iecwkmqd; C:\WINDOWS\system32\drivers\iecwkmqd.sys [72816 2020-10-13] (Microsoft Corporation) S3 IndirectKmd; C:\Windows\System32\drivers\IndirectKmd.sys [47104 2019-12-07] (Microsoft Corporation) S3 intelpmax; C:\Windows\System32\drivers\intelpmax.sys [30720 2019-12-07] (Microsoft Corporation) R0 iorate; C:\Windows\System32\drivers\iorate.sys [57360 2019-12-07] (Microsoft Corporation) S3 IPT; C:\Windows\System32\drivers\ipt.sys [59704 2019-12-07] (Microsoft Corporation) S1 irwuvrud; C:\WINDOWS\system32\drivers\irwuvrud.sys [72816 2020-10-13] (Microsoft Corporation) S0 ItSas35i; C:\Windows\System32\drivers\ItSas35i.sys [172344 2019-12-07] (Avago Technologies) S1 kvkgwdaj; C:\WINDOWS\system32\drivers\kvkgwdaj.sys [72816 2020-10-13] (Microsoft Corporation) S0 LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [124216 2019-12-07] (LSI Corporation) S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [135992 2019-12-07] (Avago Technologies) S3 mausbhost; C:\Windows\System32\drivers\mausbhost.sys [537608 2019-12-07] (Microsoft Corporation) S3 mausbip; C:\Windows\System32\drivers\mausbip.sys [64016 2019-12-07] (Microsoft Corporation) S3 MbbCx; C:\Windows\System32\drivers\MbbCx.sys [386048 2020-08-14] (Microsoft Corporation) S0 megasas; C:\Windows\System32\drivers\megasas.sys [59704 2019-12-07] (Avago Technologies) S0 megasas2i; C:\Windows\System32\drivers\MegaSas2i.sys [81720 2019-12-07] (Avago Technologies) S0 megasas35i; C:\Windows\System32\drivers\megasas35i.sys [105480 2019-12-07] (Avago Technologies) R3 MEIx64; C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys [266128 2019-04-17] (Intel Corporation) S3 MessagingService; No ImagePath S3 MessagingService_95637d8b; No ImagePath S3 Microsoft_Bluetooth_AvrcpTransport; C:\Windows\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [65024 2019-12-07] (Microsoft Corporation) S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [1131320 2019-12-07] (Mellanox) R2 MMCSS; C:\Windows\system32\drivers\mmcss.sys [53248 2019-12-07] (Microsoft Corporation) R1 MpKslDrv; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B61A155A-0FC1-4511-ACFD-2F59EF093A8E}\MpKslDrv.sys [47328 2020-10-13] (Microsoft Corporation) R3 MsQuic; C:\Windows\System32\drivers\msquic.sys [322376 2020-09-11] (Microsoft Corporation) R0 MsSecFlt; C:\Windows\System32\drivers\mssecflt.sys [293176 2020-08-14] (Microsoft Corporation) S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [146232 2019-12-07] (Mellanox) S3 NDKPing; C:\Windows\System32\drivers\NDKPing.sys [72720 2019-12-07] (Microsoft Corporation) S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [206336 2019-12-07] (Microsoft Corporation) S3 netvsc; C:\Windows\System32\drivers\netvsc.sys [249144 2019-12-07] (Microsoft Corporation) S0 nvdimm; C:\Windows\System32\drivers\nvdimm.sys [168464 2019-12-07] (Microsoft Corporation) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_7c6629f3404619ed\nvlddmkm.sys [32460528 2020-09-26] (NVIDIA Corporation) R3 NvModuleTracker; C:\Windows\System32\drivers\NvModuleTracker.sys [50592 2020-03-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [69840 2019-04-17] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [67456 2020-03-11] (NVIDIA Corporation) S2 OneSyncSvc; No ImagePath R2 OneSyncSvc_95637d8b; No ImagePath S0 percsas2i; C:\Windows\System32\drivers\percsas2i.sys [58680 2019-12-07] (Avago Technologies) S0 percsas3i; C:\Windows\System32\drivers\percsas3i.sys [68408 2019-12-07] (Avago Technologies) S3 PimIndexMaintenanceSvc; No ImagePath R3 PimIndexMaintenanceSvc_95637d8b; No ImagePath S3 PktMon; C:\Windows\System32\drivers\PktMon.sys [104456 2019-12-07] (Microsoft Corporation) S0 pmem; C:\Windows\System32\drivers\pmem.sys [138040 2019-12-07] (Microsoft Corporation) S3 portcfg; C:\Windows\System32\drivers\portcfg.sys [27136 2019-12-07] (Microsoft Corporation) S3 PrintWorkflowUserSvc; No ImagePath R3 PrintWorkflowUserSvc_95637d8b; No ImagePath S0 Ramdisk; C:\Windows\System32\DRIVERS\ramdisk.sys [42296 2019-12-07] (Microsoft Corporation) S3 ReFSv1; C:\Windows\System32\Drivers\ReFSv1.sys [990008 2019-12-07] (Microsoft Corporation) S3 rhproxy; C:\Windows\System32\drivers\rhproxy.sys [115712 2019-12-07] (Microsoft Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1167768 2019-11-20] (Realtek ) S1 rvtdidqw; C:\WINDOWS\system32\drivers\rvtdidqw.sys [72816 2020-10-13] (Microsoft Corporation) S0 scmbus; C:\Windows\System32\drivers\scmbus.sys [158736 2019-12-07] (Microsoft Corporation) S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [35128 2019-12-07] (Microsoft Corporation) R0 SgrmAgent; C:\Windows\System32\drivers\SgrmAgent.sys [88080 2019-12-07] (Microsoft Corporation) S0 SmartSAMD; C:\Windows\System32\drivers\SmartSAMD.sys [209720 2019-12-07] (Microsemi Corportation) S3 smbdirect; C:\Windows\System32\DRIVERS\smbdirect.sys [172544 2019-12-07] (Microsoft Corporation) S3 spaceparser; C:\Windows\System32\drivers\spaceparser.sys [26624 2019-12-07] (Microsoft Corporation) S3 SpatialGraphFilter; C:\Windows\System32\drivers\SpatialGraphFilter.sys [90936 2019-12-07] (Microsoft Corporation) R3 SteamStreamingMicrophone; C:\Windows\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-28] () R3 SteamStreamingSpeakers; C:\Windows\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] () R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [92984 2019-12-07] (Microsoft Corporation) S0 storufs; C:\Windows\System32\drivers\storufs.sys [60744 2020-09-11] (Microsoft Corporation) R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys [18952 2019-12-07] (Microsoft Corporation) R0 Telemetry; C:\Windows\System32\drivers\IntelTA.sys [26600 2020-08-14] (Microsoft Corporation) S1 tzaasctk; C:\WINDOWS\system32\drivers\tzaasctk.sys [72816 2020-10-13] (Microsoft Corporation) S3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2012-12-19] () S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [160256 2019-12-07] (Microsoft Corporation) S3 UcmTcpciCx0101; C:\Windows\System32\Drivers\UcmTcpciCx.sys [188416 2019-12-07] (Microsoft Corporation) S3 UcmUcsiAcpiClient; C:\Windows\System32\drivers\UcmUcsiAcpiClient.sys [36864 2019-12-07] (Microsoft Corporation) S3 UcmUcsiCx0101; C:\Windows\System32\Drivers\UcmUcsiCx.sys [113152 2020-09-11] (Microsoft Corporation) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [52736 2019-12-07] (Microsoft Corporation) S3 UdkUserSvc; No ImagePath R3 UdkUserSvc_95637d8b; No ImagePath R3 UEFI; C:\Windows\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys [34104 2019-12-07] (Microsoft Corporation) S4 UevAgentDriver; C:\Windows\system32\drivers\UevAgentDriver.sys [41488 2019-12-07] (Microsoft Corporation) S3 Ufx01000; C:\Windows\System32\drivers\ufx01000.sys [321040 2019-12-07] (Microsoft Corporation) S3 UfxChipidea; C:\Windows\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys [110608 2019-12-07] (Microsoft Corporation) S3 ufxsynopsys; C:\Windows\System32\drivers\ufxsynopsys.sys [168248 2019-12-07] (Microsoft Corporation) R3 umbus; C:\Windows\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys [58368 2019-12-07] (Microsoft Corporation) S3 UnistoreSvc; No ImagePath R3 UnistoreSvc_95637d8b; No ImagePath S3 UrsChipidea; C:\Windows\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys [32056 2019-12-07] (Microsoft Corporation) S3 UrsCx01000; C:\Windows\System32\drivers\urscx01000.sys [76304 2019-12-07] (Microsoft Corporation) S3 UrsSynopsys; C:\Windows\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys [29496 2019-12-07] (Microsoft Corporation) S3 usbaudio2; C:\Windows\System32\drivers\usbaudio2.sys [260608 2019-12-07] (Microsoft Corporation) S3 UserDataSvc; No ImagePath R3 UserDataSvc_95637d8b; No ImagePath S3 VBoxNetAdp; C:\Windows\System32\drivers\VBoxNetAdp6.sys [237832 2020-06-04] (Oracle Corporation) R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [247232 2020-06-04] (Oracle Corporation) S3 vhf; C:\Windows\System32\drivers\vhf.sys [47616 2019-12-07] (Microsoft Corporation) S3 VirtualRender; C:\Windows\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys [11264 2019-12-07] (Microsoft Corporation) S3 vmgid; C:\Windows\System32\drivers\vmgid.sys [19768 2019-12-07] (Microsoft Corporation) R0 volume; C:\Windows\System32\drivers\volume.sys [16696 2019-12-07] (Microsoft Corporation) R2 wcifs; C:\Windows\system32\drivers\wcifs.sys [202552 2019-12-07] (Microsoft Corporation) S3 wcnfs; C:\Windows\system32\drivers\wcnfs.sys [93184 2019-12-07] (Microsoft Corporation) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-10-07] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [428264 2020-10-07] (Microsoft Corporation) S3 wdiwifi; C:\Windows\System32\DRIVERS\wdiwifi.sys [951808 2020-09-11] (Microsoft Corporation) S3 WdmCompanionFilter; C:\Windows\System32\drivers\WdmCompanionFilter.sys [23560 2019-12-07] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-07] (Microsoft Corporation) R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [76984 2019-12-07] (Microsoft Corporation) R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [18920 2019-12-07] (Microsoft Corporation) S3 WinMad; C:\Windows\System32\drivers\winmad.sys [36152 2019-12-07] (Mellanox) S3 WinNat; C:\Windows\System32\drivers\winnat.sys [259584 2020-09-11] (Microsoft Corporation) S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [73016 2019-12-07] (Mellanox) S2 WpnUserService; No ImagePath R2 WpnUserService_95637d8b; No ImagePath S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [324608 2019-12-07] (Microsoft Corporation) S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [48640 2019-12-07] (Microsoft Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) NETSVC: InstallService -> C:\Windows\system32\InstallService.dll (Microsoft Corporation) NETSVC: PushToInstall -> C:\Windows\system32\PushToInstall.dll (Microsoft Corporation) NETSVC: TroubleshootingSvc -> C:\Windows\system32\MitigationClient.dll (Microsoft Corporation) NETSVC: LxpSvc -> C:\Windows\System32\LanguageOverlayServer.dll (Microsoft Corporation) NETSVC: shpamsvc -> C:\Windows\system32\Windows.SharedPC.AccountManager.dll (Microsoft Corporation) NETSVC: XblGameSave -> C:\Windows\System32\XblGameSave.dll (Microsoft Corporation) NETSVC: DmEnrollmentSvc -> C:\Windows\system32\Windows.Internal.Management.dll (Microsoft Corporation) NETSVC: WManSvc -> C:\Windows\system32\Windows.Management.Service.dll (Microsoft Corporation) NETSVC: UserManager -> C:\Windows\System32\usermgr.dll (Microsoft Corporation) NETSVC: NetSetupSvc -> C:\Windows\System32\NetSetupSvc.dll (Microsoft Corporation) NETSVC: TokenBroker -> C:\Windows\System32\TokenBroker.dll (Microsoft Corporation) NETSVC: NaturalAuthentication -> C:\Windows\System32\NaturalAuth.dll (Microsoft Corporation) NETSVC: dmwappushservice -> C:\Windows\system32\dmwappushsvc.dll (Microsoft Corporation) NETSVC: wisvc -> C:\Windows\system32\flightsettings.dll (Microsoft Corporation) NETSVC: WpnService -> C:\Windows\system32\WpnService.dll (Microsoft Corporation) NETSVC: XboxNetApiSvc -> C:\Windows\system32\XboxNetApiSvc.dll (Microsoft Corporation) NETSVC: UsoSvc -> C:\Windows\system32\usosvc.dll (Microsoft Corporation) NETSVC: XboxGipSvc -> C:\Windows\System32\XboxGipSvc.dll (Microsoft Corporation) NETSVC: XblAuthManager -> C:\Windows\System32\XblAuthManager.dll (Microsoft Corporation) NETSVCx32: TokenBroker -> C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation) NETSVCx32: UserManager -> C:\Windows\SysWOW64\usermgr.dll ==> Keine Datei ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2020-10-13 18:02 - 2020-10-13 18:03 - 00110757 _____ C:\Users\Azad\Downloads\Addition.txt 2020-10-13 18:01 - 2020-10-13 18:04 - 00053533 _____ C:\Users\Azad\Downloads\FRST.txt 2020-10-13 18:01 - 2020-10-13 18:04 - 00000000 ____D C:\FRST 2020-10-13 18:00 - 2020-10-13 18:00 - 02169856 _____ (Farbar) C:\Users\Azad\Downloads\FRST64.exe 2020-10-13 17:52 - 2020-10-13 17:52 - 00072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\irwuvrud.sys 2020-10-13 17:51 - 2020-10-13 17:51 - 00072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kvkgwdaj.sys 2020-10-13 16:17 - 2020-10-13 16:17 - 00072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iecwkmqd.sys 2020-10-13 16:16 - 2020-10-13 16:16 - 00072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rvtdidqw.sys 2020-10-13 13:30 - 2020-10-13 13:30 - 00072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tzaasctk.sys 2020-10-09 19:25 - 2020-10-09 19:25 - 00000000 ____D C:\Users\Azad\AppData\Local\AVGame 2020-10-05 16:10 - 2020-10-05 16:10 - 00000000 ____D C:\WINDOWS\System32\Tasks\Agent Activation Runtime 2020-10-04 15:57 - 2020-10-04 15:57 - 00000000 ____D C:\WINDOWS\System32\Tasks\Mozilla 2020-10-04 12:59 - 2020-10-04 16:55 - 00000000 ____D C:\Program Files\Mozilla Firefox 2020-09-30 17:43 - 2020-09-30 17:43 - 00000000 ____D C:\Users\Azad\Documents\AnyTrans-Exportieren-20200930 2020-09-28 20:55 - 2020-09-28 20:55 - 00000000 ____D C:\WINDOWS\LastGood 2020-09-28 20:53 - 2020-10-13 17:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge 2020-09-28 20:52 - 2020-09-26 01:41 - 01769688 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2020-09-28 20:52 - 2020-09-26 01:41 - 01769688 _____ C:\WINDOWS\system32\vulkaninfo.exe 2020-09-28 20:52 - 2020-09-26 01:41 - 01370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2020-09-28 20:52 - 2020-09-26 01:41 - 01370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2020-09-28 20:52 - 2020-09-26 01:41 - 01054944 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2020-09-28 20:52 - 2020-09-26 01:41 - 01054944 _____ C:\WINDOWS\system32\vulkan-1.dll 2020-09-28 20:52 - 2020-09-26 01:41 - 00917728 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2020-09-28 20:52 - 2020-09-26 01:41 - 00917728 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2020-09-28 20:52 - 2020-09-26 01:41 - 00455408 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2020-09-28 20:52 - 2020-09-26 01:41 - 00349936 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 02097560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 01585048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 01506200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 01160600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00815856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00811248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00674200 _____ C:\WINDOWS\system32\nvofapi64.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00670104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00656792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00555928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2020-09-28 20:52 - 2020-09-26 01:40 - 00540912 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 07705320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 06859152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 04174736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 02509200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 01733008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6445655.dll 2020-09-28 20:52 - 2020-09-26 01:39 - 01482984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6445655.dll 2020-09-28 20:52 - 2020-09-26 01:35 - 05964496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2020-09-28 18:00 - 2020-09-28 18:12 - 00000000 ____D C:\Users\Azad\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien 2020-09-28 17:49 - 2020-09-28 17:49 - 00000768 _____ C:\Users\Public\Desktop\Die Schlacht um Mittelerde™ II.lnk 2020-09-28 17:49 - 2020-09-28 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts 2020-09-28 17:44 - 2020-09-28 17:45 - 00000000 ____D C:\Users\Azad\AppData\Roaming\DAEMON Tools Lite 2020-09-28 17:44 - 2020-09-28 17:45 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2020-09-28 17:44 - 2020-09-28 17:44 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images 2020-09-28 16:37 - 2020-10-13 17:51 - 00000000 ____D C:\Program Files (x86)\RelevantKnowledge 2020-09-28 16:37 - 2020-04-10 01:02 - 01111408 ____N (TMRG, Inc.) C:\WINDOWS\system32\rlls64.dll 2020-09-28 16:37 - 2020-04-10 01:02 - 00754032 ____N (TMRG, Inc.) C:\WINDOWS\SysWOW64\rlls.dll 2020-09-25 11:17 - 2020-10-08 16:31 - 00000000 ____D C:\Users\Azad\Desktop\Logos 2020-09-23 14:09 - 2020-09-23 14:09 - 00000000 ____D C:\Users\Azad\AppData\Local\Epic Games 2020-09-17 18:23 - 2020-09-17 18:24 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2020-09-17 18:20 - 2020-09-15 00:13 - 00038816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2020-09-16 17:28 - 2020-09-16 17:28 - 00000000 ____D C:\ProgramData\Mount and Blade II Bannerlord 2020-09-16 17:27 - 2020-10-09 15:31 - 00000000 ____D C:\Users\Azad\Documents\Mount and Blade II Bannerlord ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2020-10-13 17:28 - 2020-08-11 21:53 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2020-10-13 17:19 - 2019-12-07 11:14 - 00000000 ____D C:\WINDOWS\system32\sru 2020-10-13 17:17 - 2019-10-22 17:54 - 00002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-10-13 17:17 - 2019-10-22 17:54 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-10-13 12:25 - 2018-08-27 18:00 - 00000000 ____D C:\ProgramData\NVIDIA 2020-10-13 12:24 - 2018-08-28 20:11 - 00000000 ____D C:\Users\Azad\AppData\Local\D3DSCache 2020-10-13 12:23 - 2019-12-07 11:14 - 00000000 ____D C:\WINDOWS\AppReadiness 2020-10-13 12:13 - 2020-09-04 11:26 - 00000000 ___RD C:\Users\Azad\iCloudDrive 2020-10-13 12:13 - 2020-08-11 21:58 - 00003700 _____ C:\WINDOWS\System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2020-10-13 12:13 - 2020-08-11 21:58 - 00003576 _____ C:\WINDOWS\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2020-10-12 23:26 - 2019-11-07 19:41 - 00000000 ____D C:\Users\Azad\AppData\Local\Battle.net 2020-10-12 23:26 - 2018-08-28 20:01 - 00000000 ____D C:\Steam 2020-10-12 22:59 - 2020-09-04 13:14 - 00000000 ____D C:\Users\Azad\AppData\Roaming\vlc 2020-10-10 20:28 - 2019-11-10 18:08 - 00000000 ____D C:\Users\Azad\AppData\Roaming\Discord 2020-10-10 19:49 - 2019-08-27 17:25 - 00000000 ____D C:\Users\Azad\AppData\Roaming\TS3Client 2020-10-10 17:27 - 2019-11-10 18:08 - 00002232 _____ C:\Users\Azad\Desktop\Discord.lnk 2020-10-10 17:27 - 2019-11-10 18:08 - 00000000 ____D C:\Users\Azad\AppData\Local\Discord 2020-10-10 16:26 - 2020-03-17 17:47 - 00000000 ____D C:\Program Files (x86)\Battle.net 2020-10-10 12:31 - 2019-11-07 19:50 - 00000569 _____ C:\Users\Public\Desktop\Hearthstone.lnk 2020-10-10 10:17 - 2020-08-09 10:21 - 00002419 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2020-10-10 10:17 - 2020-08-09 10:21 - 00002257 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2020-10-09 19:25 - 2018-08-28 21:21 - 00000000 ____D C:\Users\Azad\AppData\Local\UnrealEngine 2020-10-09 12:19 - 2020-08-14 13:58 - 00003944 _____ C:\WINDOWS\System32\Tasks\BlueStacksHelper 2020-10-07 11:09 - 2018-08-24 18:26 - 00000000 ____D C:\WINDOWS\system32\Drivers\wd 2020-10-06 15:55 - 2020-08-27 15:44 - 00000000 ____D C:\Users\Azad\Documents\Soundaufnahmen 2020-10-04 18:57 - 2020-08-11 21:57 - 01722788 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-10-04 18:57 - 2019-12-07 16:51 - 00743686 _____ C:\WINDOWS\system32\perfh007.dat 2020-10-04 18:57 - 2019-12-07 16:51 - 00150108 _____ C:\WINDOWS\system32\perfc007.dat 2020-10-04 18:51 - 2018-08-24 18:29 - 00000276 _____ C:\WINDOWS\WindowsUpdate.log 2020-10-04 16:55 - 2020-08-11 21:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-10-04 16:55 - 2020-08-11 21:53 - 00008192 ___SH C:\DumpStack.log.tmp 2020-10-04 16:55 - 2020-07-07 23:38 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2020-10-04 16:55 - 2019-12-07 11:14 - 00000000 ____D C:\WINDOWS\ServiceState 2020-10-04 16:55 - 2018-08-29 14:00 - 00093632 _____ C:\WINDOWS\PFRO.log 2020-10-04 16:55 - 2018-08-27 14:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-10-04 16:54 - 2019-12-07 11:03 - 00524288 _____ C:\WINDOWS\system32\config\BBI 2020-10-04 15:57 - 2018-08-27 14:08 - 00001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-09-30 17:44 - 2020-09-04 19:11 - 00000000 ____D C:\Users\Azad\Documents\Temp 2020-09-29 22:02 - 2020-03-20 18:18 - 00000000 ____D C:\Users\Azad\AppData\Roaming\Origin 2020-09-29 22:02 - 2020-03-20 18:18 - 00000000 ____D C:\ProgramData\Origin 2020-09-29 19:34 - 2020-03-20 18:18 - 00000000 ____D C:\Users\Azad\AppData\Local\Origin 2020-09-28 20:56 - 2020-08-11 21:53 - 00041839 _____ C:\WINDOWS\setupact.log 2020-09-28 17:49 - 2018-08-28 21:25 - 00225033 _____ C:\WINDOWS\DirectX.log 2020-09-27 19:48 - 2018-08-27 17:50 - 00000000 ____D C:\WINDOWS\system32\MRT 2020-09-27 19:46 - 2018-08-27 17:49 - 129170736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2020-09-26 01:35 - 2020-07-10 08:54 - 06992184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2020-09-25 10:09 - 2019-02-04 22:21 - 00000000 ____D C:\ProgramData\Mozilla 2020-09-25 00:55 - 2020-07-10 08:54 - 00058630 _____ C:\WINDOWS\system32\nvinfo.pb 2020-09-24 22:26 - 2018-08-27 18:00 - 05510456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 02635752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 01759032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 00990520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 00195560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 00122344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2020-09-24 22:26 - 2018-08-27 18:00 - 00083256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2020-09-24 14:33 - 2020-08-11 21:58 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2020-09-24 14:32 - 2019-01-29 14:20 - 00002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2020-09-23 16:41 - 2020-06-05 21:02 - 00000081 _____ C:\Users\Azad\AppData\Local\.bidstack.fault 2020-09-22 16:09 - 2019-12-28 21:05 - 00000000 ____D C:\Users\Azad\Desktop\Uni neu 2020-09-18 22:23 - 2018-08-27 13:28 - 00000000 ____D C:\Users\Azad\AppData\Local\PlaceholderTileLogoFolder 2020-09-18 12:22 - 2018-08-24 18:32 - 00000000 ____D C:\Users\Azad\AppData\Local\Packages 2020-09-17 18:24 - 2018-08-27 17:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2020-09-17 18:23 - 2018-08-27 18:01 - 00000000 ____D C:\Users\Azad\AppData\Local\NVIDIA 2020-09-17 18:23 - 2018-08-27 17:58 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2020-09-17 08:28 - 2019-12-07 11:14 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2020-09-16 08:44 - 2018-08-27 18:00 - 09302127 _____ C:\WINDOWS\system32\nvcoproc.bin 2020-09-15 00:13 - 2020-07-10 08:54 - 01682368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2020-09-15 00:13 - 2020-07-10 08:54 - 00222112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2020-09-14 17:22 - 2018-12-07 12:43 - 00000000 ____D C:\Users\Azad\Documents\Paradox Interactive 2020-09-14 17:21 - 2019-12-18 15:08 - 00000000 ____D C:\Users\Azad\AppData\Local\Paradox Interactive ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2020-06-05 21:02 - 2020-09-23 16:41 - 0000081 _____ () C:\Users\Azad\AppData\Local\.bidstack.fault 2018-09-24 22:53 - 2018-09-24 22:53 - 0000003 _____ () C:\Users\Azad\AppData\Local\updater.log 2018-09-24 22:53 - 2018-09-24 22:53 - 0000425 _____ () C:\Users\Azad\AppData\Local\UserProducts.xml 2019-01-26 14:17 - 2019-01-26 14:17 - 0000057 _____ () C:\ProgramData\Ament.ini 2018-08-27 18:04 - 2018-08-27 18:04 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2020-09-04 12:00 - 2020-09-04 12:00 - 0004892 _____ () C:\ProgramData\lzmiudcz.flf 2020-09-04 12:00 - 2020-09-04 12:00 - 0000016 _____ () C:\ProgramData\mntemp ==================== Bamital & volsnap Check ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\System32\winlogon.exe => Datei ist digital signiert C:\Windows\System32\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\System32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\System32\services.exe => Datei ist digital signiert C:\Windows\System32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\System32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\System32\rpcss.dll => Datei ist digital signiert C:\Windows\System32\Drivers\volsnap.sys => Datei ist digital signiert C:\Windows\system32\codeintegrity\Bootcat.cache FEHLT <==== ATTENTION!. ==================== Ende von log ============================ |
Themen zu Misleading:Win32/Lodi Virus? |
.dll, administrator, dateien, defender, explorer, firefox, geforce, google, microsoft, mozilla, nvidia, ordner, prozesse, realtek, router, scan, software, svchost.exe, system, viren, virus, virus?, windows, winlogon.exe, wma |