|
Plagegeister aller Art und deren Bekämpfung: Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.04.2021, 07:59 | #1 |
| Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. Hallo, ich wende mich heute an euch mit der Hoffnung auf Untersützung / Klärung. Seit einigen Wochen taucht immer mal wieder exsalut.com mit verschiedenen Einträgen in meiner Firefox-Chronik auf. Ich nutze das Laptop als Einzelunternehmer ohne eigene IT-Support .und freue mich wenn ihr helft. Bisher gibt es keinerlei mir bekannten Systemeinschränkungen, ausser das diese Einträge immer wieder auftauchen und ich gerne wüsste, was es damit auf sich hat. Vielen Dank und Gruß gerard |
21.04.2021, 09:28 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. Hinweise für Hilfesuchende gelesen?
__________________
__________________ |
21.04.2021, 12:40 | #3 |
| Danke für den Hinweis, jetzt habe ich die Anweisungen vollständig gelesen. Shortcut
__________________Code:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 17-04-2021 durchgeführt von gerar (21-04-2021 13:20:53) Gestartet von C:\Users\gerar\Downloads Start-Modus: Normal ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\gerar\Favorites\Downloadseite von NCH Software.lnk -> [LFjhSBi+00Tahttps://www.nch.com.au/de/index.htmlWavePad Audio-Editor starten] Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk -> C:\Program Files (x86)\Audacity\audacity.exe (Audacity Team) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MixPad Musikstudio-Software.lnk -> C:\Program Files (x86)\NCH Software\MixPad\mixpad.exe (NCH Software) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streamlabs OBS.lnk -> C:\Program Files\Streamlabs OBS\Streamlabs OBS.exe (General Workings, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audio-Editor.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Create USB Recovery.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio\OBS Studio (64bit).lnk -> C:\Program Files\obs-studio\bin\64bit\obs64.exe (OBS) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio\Uninstall.lnk -> C:\Program Files\obs-studio\uninstall.exe (obsproject.com) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol Z2\Traktor Kontrol Z2 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol Z2 Driver\nikz2cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol Z1\Traktor Kontrol Z1 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol Z1 Driver\nikz1cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol S8\Traktor Kontrol S8 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol S8 Driver\niks8cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol S5\Traktor Kontrol S5 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol S5 Driver\nikst4cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol S4 MK2\Traktor Kontrol S4 MK2 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol S4 MK2 Driver\niks4m2cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Kontrol S2 MK2\Traktor Kontrol S2 MK2 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Kontrol S2 MK2 Driver\niks2m2cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Audio 6\Traktor Audio 6 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Audio 6 Driver\nita6cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Audio 2 MK2\Traktor Audio 2 MK2 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Audio 2 MK2 Driver\nita2m2cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor Audio 10\Traktor Audio 10 Control Panel.lnk -> C:\Program Files\Native Instruments\Traktor Audio 10 Driver\nita10cpl.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Traktor 2\Traktor 2.lnk -> C:\Program Files\Native Instruments\Traktor 2\Traktor.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Service Center.lnk -> C:\Program Files\Native Instruments\Service Center\ServiceCenter.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Controller Editor\Controller Editor.lnk -> C:\Program Files\Native Instruments\Controller Editor\Controller Editor.exe (Native Instruments GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup\MozBackup.lnk -> C:\Program Files (x86)\MozBackup\MozBackup.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup\Uninstall.lnk -> C:\Program Files (x86)\MozBackup\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk -> C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\Music Maker (64-Bit)\Music Maker (64-Bit).lnk -> C:\Program Files\MAGIX\Music Maker\29\MusicMaker.exe (MAGIX Software GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Loopcloud\Loopcloud.lnk -> C:\Program Files\Loopcloud\Loopcloud.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Kameraeinstellungen\Logitech Kameraeinstellungen.lnk -> C:\Program Files (x86)\Common Files\logishrd\LogiUCDpp\LogitechCamera.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer\Uninstall Win32DiskImager.lnk -> C:\Program Files (x86)\ImageWriter\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer\Win32DiskImager.lnk -> C:\Program Files (x86)\ImageWriter\Win32DiskImager.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64\HWiNFO64.lnk -> C:\Program Files\HWiNFO64\HWiNFO64.EXE (REALiX) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Peripheral Manager.lnk -> C:\Program Files\Dell\Dell Peripheral Manager\DPM.exe (Dell Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Dell Feature Enhancement Pack User's Guide.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\help\de\index.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Smart Settings\Smart Settings User’s Guide .lnk -> C:\Program Files\Dell\Feature Enhancement Pack\help\de\Dell_SmartSettings.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Power and Battery\Dell Battery Information .lnk -> C:\Program Files\Dell\Feature Enhancement Pack\BatteryInformation.exe (Dell Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Power and Battery\Power and Battery user’s guide .lnk -> C:\Program Files\Dell\Feature Enhancement Pack\help\de\Dell_Power&Battery.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Platform Enablement\Platform Enablement Pack User’s Guide .lnk -> C:\Program Files\Dell\Feature Enhancement Pack\help\de\Dell_PlatformEnablement.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Keyboard and Devices\Keyboard and Devices User’s Guide .lnk -> C:\Program Files\Dell\Feature Enhancement Pack\help\de\Dell_Keyboard&Devices.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Web Service Registration Tool\EOS Web Service Registration Tool.lnk -> C:\Program Files (x86)\Canon\EOS Web Service Registration Tool\EOS Web Service Registration Tool.exe (CANON INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Utility\EOS Utility 2 - INFO.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EU2\readme.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Utility\EOS Utility 2.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EU2\EOS Utility 2.exe (CANON INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Utility\EOS Utility 3 - INFO.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EU3\readme.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Utility\EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Network Setting Tool\EOS Network Setting Tool.lnk -> C:\Program Files (x86)\Canon\EOS Network Setting Tool\EOS Network Setting Tool.exe (Canon INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\EOS Lens Registration Tool\EOS Lens Registration Tool.lnk -> C:\Program Files (x86)\Canon\EOS Lens Registration Tool\EOS Lens Registration Tool.exe (CANON INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities\Digital Photo Professional 4\Digital Photo Professional 4.lnk -> C:\Program Files\Canon\Digital Photo Professional 4\Dpp4.exe (CANON INC.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Backup and Sync from Google.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (32 bits)\Avidemux 2.7 - 32 bits (32-bit).lnk -> C:\Program Files (x86)\Avidemux 2.7 - 32 bits\avidemux.exe (Free Software Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (32 bits)\Avidemux job control (32 Bits).lnk -> C:\Program Files (x86)\Avidemux 2.7 - 32 bits\avidemux_jobs.exe (Free Software Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (32 bits)\Change Log 2.7.lnk -> C:\Program Files (x86)\Avidemux 2.7 - 32 bits\ChangeLog.html () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk -> C:\Windows\regedit.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\Windows\System32\quickassist.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\gerar\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\Music\Meditative Chillout WAV - Verknüpfung.lnk -> C:\Users\gerar\Music\SL_Meditative_Chillout_WAV\Meditative Chillout WAV () Shortcut: C:\Users\gerar\Links\Desktop.lnk -> C:\Users\gerar\Desktop () Shortcut: C:\Users\gerar\Links\Downloads.lnk -> C:\Users\gerar\Downloads () Shortcut: C:\Users\gerar\Links\Google Drive.lnk -> C:\Users\gerar\Google Drive () Shortcut: C:\Users\gerar\Documents\Downloads - Verknüpfung.lnk -> C:\Users\gerar\Downloads () Shortcut: C:\Users\gerar\Documents\MAGIX\Music Maker\_Demos.LNK -> C:\ProgramData\MAGIX\Music Maker\29\_Demos () Shortcut: C:\Users\gerar\Desktop\Movavi Video Editor 15.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Editor 15\VideoEditor.exe (Movavi) Shortcut: C:\Users\gerar\Desktop\Movavi Video Suite 2020.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 2020\Suite.exe (Movavi) Shortcut: C:\Users\gerar\Desktop\Movavi Video Suite 21.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\Suite.exe (Movavi) Shortcut: C:\Users\gerar\Creative Cloud Files\_Cloud-Dokumente.lnk -> C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe (Keine Datei) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk -> C:\Users\gerar\AppData\Local\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\gerar\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch Studio.lnk -> C:\Users\gerar\AppData\Roaming\Twitch Studio\Bin\TwitchStudio.exe (Twitch Interactive, Inc.) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom\Zoom.lnk -> C:\Users\gerar\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc.) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp\WhatsApp.lnk -> C:\Users\gerar\AppData\Local\WhatsApp\WhatsApp.exe (WhatsApp) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QScan System-Check.lnk -> C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan.exe (System-Check) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 21\Movavi Video Suite 21 deinstallieren.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\uninst.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 21\Movavi Video Suite 21.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\Suite.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 21\Website Movavi Video Suite 21.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\Movavi Video Suite 21.url () Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 2020\Movavi Video Suite 2020 deinstallieren.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 2020\uninst.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 2020\Movavi Video Suite 2020.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 2020\Suite.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 2020\Website Movavi Video Suite 2020.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 2020\Movavi Video Suite 2020.url () Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 15\Movavi Video Editor 15 deinstallieren.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Editor 15\uninst.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 15\Movavi Video Editor 15.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Editor 15\VideoEditor.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 15\Website Movavi Video Editor 15.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Editor 15\Movavi Video Editor 15.url () Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Acrobat Reader DC.lnk -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Movavi Video Suite 21.lnk -> C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\Suite.exe (Movavi) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk -> C:\Users\gerar\AppData\Local\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) Shortcut: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\WhatsApp.lnk -> C:\Users\gerar\AppData\Local\WhatsApp\WhatsApp.exe (WhatsApp) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Audacity.lnk -> C:\Program Files (x86)\Audacity\audacity.exe (Audacity Team) Shortcut: C:\Users\Public\Desktop\Controller Editor.lnk -> C:\Program Files\Native Instruments\Controller Editor\Controller Editor.exe (Native Instruments GmbH) Shortcut: C:\Users\Public\Desktop\Digital Photo Professional 4.lnk -> C:\Program Files\Canon\Digital Photo Professional 4\Dpp4.exe (CANON INC.) Shortcut: C:\Users\Public\Desktop\EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\Users\Public\Desktop\Logitech Kameraeinstellungen.lnk -> C:\Program Files (x86)\Common Files\logishrd\LogiUCDpp\LogitechCamera.exe () Shortcut: C:\Users\Public\Desktop\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\MixPad Musikstudio-Software.lnk -> C:\Program Files (x86)\NCH Software\MixPad\mixpad.exe (NCH Software) Shortcut: C:\Users\Public\Desktop\Music Maker (64-Bit).lnk -> C:\Program Files\MAGIX\Music Maker\29\MusicMaker.exe (MAGIX Software GmbH) Shortcut: C:\Users\Public\Desktop\OBS Studio.lnk -> C:\Program Files\obs-studio\bin\64bit\obs64.exe (OBS) Shortcut: C:\Users\Public\Desktop\Service Center.lnk -> C:\Program Files\Native Instruments\Service Center\ServiceCenter.exe (Native Instruments GmbH) Shortcut: C:\Users\Public\Desktop\Traktor 2.lnk -> C:\Program Files\Native Instruments\Traktor 2\Traktor.exe (Native Instruments GmbH) Shortcut: C:\Users\Public\Desktop\WavePad Audio-Editor.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Produktpalette.lnk -> C:\Program Files (x86)\NCH Software\MixPad\mixpad.exe (NCH Software) -> -extsuite ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZOOM\H and F Series Multi Track Driver\Uninstall H and F Series Multi Track Driver.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /x {0751E62E-5898-4791-B97A-F91C3EF3366C} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\Update Notifier\Update Notifier.lnk -> C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe (MAGIX) -> -show ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Feature Enhancement Pack\Smart Settings\Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) -> -expanded ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Docs.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_document ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Sheets.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_spreadsheet ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Slides.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_presentation ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Anrufrecorder.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind VRS ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Audio-Converter.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Switch ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Bestandssoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Inventoria ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Bildkonverter.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Pixillion ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Brennprogramm.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ExpressBurn ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Buchhaltungssoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ExpressAccounts ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\CD-Ripper.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Rip ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Classic FTP Software.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ClassicFTP ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Diashow-Programm.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind PhotoStage ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Diktiersoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Express ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Disc-Beschriftungssoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Disketch ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Doxillion Dokumentkonverter.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Doxillion ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Flussdiagramm-Software.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ClickCharts ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Foto-Editor.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind PhotoPad ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Hausplaner.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind DreamPlan ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Musikstudio-Software.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind MixPad ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Point-of-Sale-Software.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Copper ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Private Finanzsoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind MoneyLine ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Rechnungsprogramm.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ExpressInvoice ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Streaming-Audio-Recorder.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind SoundTap ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Textbaustein-Programm.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind FastFox ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Tipptrainer.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind KeyBlaze ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Transkriptionssoftware.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Scribe ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\VHS-Konverter.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind GoldenVideos ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Video-Converter.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Prism ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Video-Editor.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind VideoPad ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\Videoaufnahme-Software.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind Debut ShortcutWithArgument: C:\Users\gerar\NCH Software Produktpalette\ZIP-Programm.lnk -> C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe (NCH Software) -> -extfind ExpressZip ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MaxxAudio Pro von Waves - Lautsprecher und Mikrofon Audio Control und Nx 3D Sound.lnk -> C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_bb48ea8c326b06ff\WavesSvc64.exe (Waves Audio Ltd.) -> /toast ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom\Uninstall Zoom.lnk -> C:\Users\gerar\AppData\Roaming\Zoom\uninstall\Installer.exe (Zoom Video Communications, Inc.) -> /uninstall ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check\System Check.lnk -> C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan.exe (System-Check) -> start ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) -> /AutoStartUp ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\SendTo\Faxempfänger.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\gerar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\gerar\AppData\Local\Microsoft\Edge\User Data\Default\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup\Homepage.url -> URL: hxxp://mozbackup.jasnapaka.com InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup\Support.url -> URL: hxxp://mozbackup.jasnapaka.com/support.php InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer\Win32DiskImager on the Web.url -> URL: hxxp://win32diskimager.sourceforge.net InternetURL: C:\Users\gerar\Music\Fort Romeau - Untitled III - YouTube.URL -> URL: hxxps://www.youtube.com/watch?v=oDeQC5MQwo4 InternetURL: C:\Users\gerar\Music\XX von Acid Pauli.URL -> URL: hxxps://soundcloud.com/acidpauli InternetURL: C:\Users\gerar\Music\SL_Meditative_Chillout_WAV\__MACOSX\Meditative Chillout WAV\._01_Soundtrack Loops Website.url -> InternetURL: C:\Users\gerar\Music\SL_Meditative_Chillout_WAV\__MACOSX\Meditative Chillout WAV\03 Promotional\._Get More Samples.url -> InternetURL: C:\Users\gerar\Music\SL_Meditative_Chillout_WAV\Meditative Chillout WAV\01_Soundtrack Loops Website.url -> BASEURL: hxxp://www.peaceloveproductions.com/ URL: hxxp://www.soundtrackloops.com/ InternetURL: C:\Users\gerar\Music\SL_Meditative_Chillout_WAV\Meditative Chillout WAV\03 Promotional\Get More Samples.url -> BASEURL: hxxp://www.peaceloveproductions.com/ URL: hxxp://www.soundtrackloops.com/ InternetURL: C:\Users\gerar\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\gerar\Favorites\Dell\Dell Auction.url -> URL: hxxp://www.dellauction.com/ InternetURL: C:\Users\gerar\Favorites\Dell\Dell.url -> URL: hxxp://www.dell.com/ InternetURL: C:\Users\gerar\Favorites\Dell\Support.Dell.Com.url -> URL: hxxp://www.dell.com/support/home InternetURL: C:\Users\gerar\Documents\hazrat inayat khan.URL -> URL: hxxps://wahiduddin.net/mv2/index.htm InternetURL: C:\Users\gerar\Documents\Vintage Lava Lamp, 1970s for sale at Pamono.URL -> URL: hxxps://www.pamono.eu/vintage-lava-lamp-1970s InternetURL: C:\Users\gerar\Desktop\(1) gongnamo - Twitch.URL -> URL: hxxps://www.twitch.tv/gongnamo InternetURL: C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\Movavi Video Suite 21.url -> URL: hxxps://links.movavi.com/?asrc=start&app=suite&module=installer&version=21-0-1&lang=de_de&isTrial=0&partner=&huid=73d78551f93a37e3f857150126a941bad016a458&utm_nooverride=1 InternetURL: C:\Users\gerar\AppData\Roaming\Movavi Video Suite 2020\Movavi Video Suite 2020.url -> URL: hxxps://links.movavi.com/?asrc=start&app=suite&module=installer&version=20-4-1&lang=de_de&isTrial=0&partner=&huid=73d78551f93a37e3f857150126a941bad016a458&utm_nooverride=1 InternetURL: C:\Users\gerar\AppData\Roaming\Movavi Video Editor 15\Movavi Video Editor 15.url -> URL: hxxps://links.movavi.com/?asrc=start&app=videoeditor&module=installer&version=15-4-1&lang=de_de&isTrial=1&partner=&huid=73d78551f93a37e3f857150126a941bad016a458&utm_nooverride=1 ==================== Ende vom Shortcut.txt ============================= |
21.04.2021, 12:41 | #4 |
| Teil 2 der Logfiles FRST FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2021 durchgeführt von gerar (Administrator) auf DESKTOP-VUAFHKR (Dell Inc. Vostro 5391) (21-04-2021 13:17:21) Gestartet von C:\Users\gerar\Downloads Geladene Profile: gerar Platform: Windows 10 Pro Version 20H2 19042.928 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: FF Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Canon Inc. -> Canon INC.) C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (Dell Inc -> ) C:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.WinSvc.exe (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe (Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <2> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.72\GoogleCrashHandler64.exe (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (IndiLogic LLC -> Dell Inc.) C:\Program Files\Dell\Dell Peripheral Manager\DPM.exe (IndiLogic LLC -> Dell Inc.) C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe (Ingenium AI Solutions LTD -> System-Check) C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan Worker.exe (Ingenium AI Solutions LTD -> System-Check) C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_1da48d5885266bb7\dptf_helper.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_1da48d5885266bb7\esif_uf.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_8a00302ff60aed46\LMS.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_bbd2c587f8c21bc5\IntelCpHDCPSvc.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_bbd2c587f8c21bc5\IntelCpHeciSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_42f9d9bfb72d84cf\RstMwService.exe (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe (MAGIX Software GmbH -> MAGIX) C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20122.11121.0_x64__8wekyb3d8bbwe\Music.UI.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\System32\drivers\SessionService.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\NisSrv.exe (Movavi Software Limited -> Movavi) C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\AgentInformer.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12> (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdmi.inf_amd64_af978b59a0727cf8\Display.NvContainer\NVDisplay.Container.exe <2> (PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <3> (Rivet Networks LLC -> Rivet Networks LLC) C:\Program Files\Rivet Networks\SmartByte\RAPS.exe (Rivet Networks LLC -> Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteAnalyticsService.exe (Rivet Networks LLC -> Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe (Rivet Networks LLC -> Rivet Networks, LLC.) C:\Program Files\Rivet Networks\SmartByte\RAPSService.exe (Screenovate Technologies) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (Screenovate Technologies) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\DellMobileConnectUniversalClient.exe (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\IAS\IntelAudioService.exe (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_bb48ea8c326b06ff\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_bb48ea8c326b06ff\WavesSysSvc64.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) C:\Program Files (x86)\Common Files\Zoom\Support\CptService.exe ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1110824 2020-07-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [WavesSvc] => C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_bb48ea8c326b06ff\WavesSvc64.exe [1767512 2020-07-09] (Waves Inc -> Waves Audio Ltd.) HKLM\...\Run: [DellMobileConnectWelcome] => C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWelcome.exe [345848 2019-06-21] (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [DFEPApplication] => C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077880 2013-01-22] (Dell Inc. -> Dell Inc.) HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50041472 2021-03-12] (Google LLC -> ) HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Run: [movavi_suite_agent] => C:\Users\gerar\AppData\Roaming\Movavi Video Suite 21\AgentInformer.exe [905080 2020-11-28] (Movavi Software Limited -> Movavi) HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Run: [QScan System-Check] => C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan.exe [10566624 2020-10-22] (Ingenium AI Solutions LTD -> System-Check) <==== ACHTUNG HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe [858360 2019-08-13] (MAGIX Software GmbH -> MAGIX) HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Run: [Zoom] => C:\Users\gerar\AppData\Roaming\Zoom\bin\Zoom.exe [264024 2020-11-16] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\Windows\system32\hpinkstsE311LM.dll [392200 2019-03-15] (HP Inc -> HP Inc.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.128\Installer\chrmstp.exe [2021-04-14] (Google LLC -> Google LLC) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2021-03-30] ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.) Startup: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2020-05-03] ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> Canon INC.) Startup: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QScan System-Check.lnk [2020-10-22] <==== ACHTUNG ShortcutTarget: QScan System-Check.lnk -> C:\Users\gerar\AppData\Roaming\QScan System-Check\QScan.exe (Ingenium AI Solutions LTD -> System-Check) <==== ACHTUNG Startup: C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2021-03-30] ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc. -> Dell Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {02E5B25B-B16F-43BE-8C02-8965EBEC35DB} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141160 2021-04-17] (Microsoft Corporation -> Microsoft Corporation) Task: {08AFF392-4E9A-44DC-B3BF-E67AF1C3EF4A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MpCmdRun.exe [591144 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {2907FF55-98DC-4016-9F2E-2800B6C527F3} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-19] (Mozilla Corporation -> Mozilla Foundation) Task: {2C006DEA-780A-4CD5-B0CF-07AD710847E0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {3C4BBE4E-B6AE-4078-B280-E235AB76CA75} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-22] (Google LLC -> Google LLC) Task: {492003D4-4632-4CC1-8A96-D10BA3B7406E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) Task: {5C8ED413-BCA0-45F9-A245-1DCBCAEAB1A6} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248792 2021-04-07] (Microsoft Corporation -> Microsoft Corporation) Task: {6D9FC1B4-FBF1-46F1-8FBA-2F68247B2414} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-22] (Google LLC -> Google LLC) Task: {81E8FA13-BEF7-4232-ADA0-2577F529FD2F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MpCmdRun.exe [591144 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {C7043AC9-CBB7-4F42-B1D4-5C718B437D07} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23248792 2021-04-07] (Microsoft Corporation -> Microsoft Corporation) Task: {CA685515-DE88-445A-A58E-B94B87F042C1} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1059336 2021-01-09] (Dell Inc -> Dell Inc.) Task: {E41EF3A2-C394-4C4A-8C03-F7580964E63A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MpCmdRun.exe [591144 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {EBE64F84-9718-40E1-B953-AABDF89917DE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MpCmdRun.exe [591144 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FA56DE7D-2FFC-4585-A54C-84AC3F12FB0F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141160 2021-04-17] (Microsoft Corporation -> Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{01916a45-6db0-4708-9393-7b86cfa3c06e}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{0b0e7603-314e-4b1b-891b-acaeed41d023}: [DhcpNameServer] 172.21.1.174 Tcpip\..\Interfaces\{101e173b-a3e3-4873-95b8-3a81734dc67a}: [DhcpNameServer] 192.168.0.1 Edge: ======= Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden] Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden] Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden] Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden] Edge DefaultProfile: Default Edge Profile: C:\Users\gerar\AppData\Local\Microsoft\Edge\User Data\Default [2021-04-21] Edge Notifications: Default -> hxxps://www.pc-magazin.de FireFox: ======== FF DefaultProfile: f3nn80p1.default FF ProfilePath: C:\Users\gerar\AppData\Roaming\Mozilla\Firefox\Profiles\f3nn80p1.default [2020-01-14] FF ProfilePath: C:\Users\gerar\AppData\Roaming\Mozilla\Firefox\Profiles\thgthxd9.default-release [2021-04-21] FF Session Restore: Mozilla\Firefox\Profiles\thgthxd9.default-release -> ist aktiviert. FF Extension: (audio-prime) - C:\Users\gerar\AppData\Roaming\Mozilla\Firefox\Profiles\thgthxd9.default-release\Extensions\jid1-l5dUGwHjz2WXo2@jetpack.xpi [2020-12-08] FF Extension: (Timer) - C:\Users\gerar\AppData\Roaming\Mozilla\Firefox\Profiles\thgthxd9.default-release\Extensions\{457040a2-afa9-457c-8a13-609c2327023a}.xpi [2020-01-18] FF Extension: (Web Developer) - C:\Users\gerar\AppData\Roaming\Mozilla\Firefox\Profiles\thgthxd9.default-release\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2020-01-18] FF Extension: (Picture-In-Picture) - C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi [2021-04-19] [ist nicht signiert] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-14] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default [2021-04-19] CHR Extension: (Präsentationen) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-08-22] CHR Extension: (Docs) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-08-22] CHR Extension: (Google Drive) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-12-08] CHR Extension: (YouTube) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-08-22] CHR Extension: (Tabellen) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-08-22] CHR Extension: (Google Docs Offline) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-25] CHR Extension: (Anwendungs-Launcher für Drive (von Google)) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-03-14] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-14] CHR Extension: (Google Mail) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-12-08] CHR Extension: (Chrome Media Router) - C:\Users\gerar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-14] CHR HKU\S-1-5-21-2752837909-2800631316-633405880-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3780296 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3548360 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8788392 2021-04-07] (Microsoft Corporation -> Microsoft Corporation) S3 dcpm-notify; C:\Program Files\Dell\CommandPowerManager\NotifyService.exe [315008 2020-08-18] (Dell Inc -> Dell Inc.) R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [287776 2020-10-26] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3750944 2020-10-26] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [507936 2020-10-26] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 Dell Digital Delivery Services; C:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.WinSvc.exe [48832 2020-11-19] (Dell Inc -> ) R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7240.285\DSAPI.exe [985584 2021-01-22] (PC-Doctor, Inc. -> PC-Doctor, Inc.) R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [308424 2019-09-26] (Dell Inc -> Dell Inc.) S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{1D4D591D-1651-4FC3-873F-B63D362482B1} [21312 2021-04-07] (Microsoft Windows -> Microsoft Corporation) S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{1D4D591D-1651-4FC3-873F-B63D362482B1} [21312 2021-04-07] (Microsoft Windows -> Microsoft Corporation) R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38592 2021-01-19] (Dell Inc -> ) R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280952 2013-01-22] (Dell Inc. -> Dell Inc.) R2 DPMService; C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe [1585760 2020-11-25] (IndiLogic LLC -> Dell Inc.) S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [287720 2020-11-07] (NVIDIA Corporation -> NVIDIA) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [288392 2021-04-13] (HP Inc. -> HP Inc.) R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech) R2 RAPSService; C:\Program Files\Rivet Networks\SmartByte\RAPSService.exe [64848 2020-08-14] (Rivet Networks LLC -> Rivet Networks, LLC.) S3 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64856 2020-08-14] (Rivet Networks LLC -> Rivet Networks, LLC.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5361256 2021-04-16] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SessionSvc; C:\WINDOWS\System32\drivers\SessionService.exe [28592 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> ) R2 SmartByte Analytics Service; C:\Program Files\Rivet Networks\SmartByte\SmartByteAnalyticsService.exe [1630576 2020-08-14] (Rivet Networks LLC -> Rivet Networks) R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2385256 2020-08-14] (Rivet Networks LLC -> Rivet Networks) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39432 2021-01-09] (Dell Inc -> Dell Inc.) S3 TwitchService; C:\Program Files\Common Files\Twitch\TwitchService.exe [331648 2021-02-14] (Twitch Interactive, Inc. -> ) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\NisSrv.exe [2599296 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.5-0\MsMpEng.exe [128360 2021-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_af978b59a0727cf8\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_af978b59a0727cf8\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem R2 ZoomCptService; "C:\Program Files (x86)\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\gerar\AppData\Roaming\Zoom" ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [42376 2020-10-26] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.) R3 DPMDriver; C:\WINDOWS\System32\drivers\DPMDriver.sys [133864 2020-10-01] (IndiLogic LLC -> Dell Inc.) R3 MpKsl24712ce6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9B43B5C2-9E0A-40CD-B758-01E3E7421553}\MpKslDrv.sys [97528 2021-04-21] (Microsoft Windows -> Microsoft Corporation) S3 niks4m2audio; C:\WINDOWS\System32\Drivers\niks4m2audio.sys [382920 2015-09-04] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH) S3 niks4m2usb; C:\WINDOWS\system32\DRIVERS\niks4m2usb.sys [104304 2015-09-04] (NATIVE INSTRUMENTS GmbH -> Native Instruments GmbH) R3 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [164424 2020-08-14] (Rivet Networks LLC -> Rivet Networks, LLC.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49544 2021-04-17] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-04-17] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73952 2021-04-17] (Microsoft Windows -> Microsoft Corporation) S3 ZMHFMAudioSrv; C:\WINDOWS\system32\drivers\zmhfmau.sys [152704 2017-01-10] (Microsoft Windows Hardware Compatibility Publisher -> ZOOM) S4 DBUtilDrv2; \SystemRoot\System32\drivers\DBUtilDrv2.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2021-04-21 13:17 - 2021-04-21 13:17 - 000027209 _____ C:\Users\gerar\Downloads\FRST.txt 2021-04-21 13:16 - 2021-04-21 13:17 - 000000000 ____D C:\FRST 2021-04-21 13:16 - 2021-04-21 13:16 - 002298368 _____ (Farbar) C:\Users\gerar\Downloads\FRST64.exe 2021-04-21 09:17 - 2021-04-21 09:17 - 000000220 _____ C:\Users\gerar\Desktop\(1) gongnamo - Twitch.URL 2021-04-21 08:28 - 2021-04-21 08:28 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-04-19 16:04 - 2021-04-21 08:28 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-04-16 20:39 - 2021-04-16 20:39 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2021-04-16 20:39 - 2021-04-16 20:39 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll 2021-04-16 20:39 - 2021-04-16 20:39 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-04-15 14:34 - 2021-04-15 14:35 - 050075428 _____ C:\Users\gerar\Desktop\gong auswahl clip.mp4 2021-04-15 13:11 - 2021-04-15 13:11 - 000064713 _____ C:\Users\gerar\Downloads\GONGSTER SHOW(1).zip 2021-04-15 11:44 - 2021-04-15 11:44 - 042393752 _____ C:\Users\gerar\Desktop\aum sita ram_denoised.wav 2021-04-15 11:11 - 2021-04-15 11:11 - 042393752 _____ C:\Users\gerar\Desktop\aum sita ram.wav 2021-04-15 09:42 - 2021-04-15 09:42 - 025717912 _____ C:\Users\gerar\Desktop\gerar voice + tanpura droid.wav 2021-04-14 11:31 - 2021-04-14 11:31 - 000000000 ____D C:\Program Files\HPPrintScanDoctor 2021-04-13 18:33 - 2021-04-13 21:12 - 000000000 ____D C:\Users\gerar\AppData\Local\Mozilla Thunderbird 2021-04-11 10:36 - 2021-04-11 10:36 - 045115787 _____ C:\Users\gerar\Downloads\test zoom line out.mp4 2021-04-09 16:48 - 2021-04-09 16:49 - 000000000 ___RD C:\Users\gerar\Downloads\WavesAudio.MaxxAudioProforDell2019_fh4rh281wavaa!App 2021-04-07 22:46 - 2021-04-07 22:48 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate 2021-04-07 22:44 - 2021-04-07 22:46 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2021-04-07 22:44 - 2021-04-07 22:44 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2021-04-07 22:43 - 2021-04-07 22:43 - 000000000 ____D C:\ProgramData\ssh 2021-04-07 22:40 - 2021-04-07 22:40 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2021-04-07 22:40 - 2021-04-07 22:40 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2021-04-07 22:40 - 2021-04-07 22:40 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll 2021-04-07 22:40 - 2021-04-07 22:40 - 000157184 _____ C:\WINDOWS\system32\uwfcsp.dll 2021-04-07 22:40 - 2021-04-07 22:40 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll 2021-04-07 22:40 - 2021-04-07 22:40 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll 2021-04-07 22:40 - 2021-04-07 22:40 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll 2021-04-07 22:39 - 2021-04-07 22:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2021-04-07 22:39 - 2021-04-07 22:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2021-04-07 22:39 - 2021-04-07 22:39 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx 2021-04-07 22:39 - 2021-04-07 22:39 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2021-04-07 22:39 - 2021-04-07 22:39 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\VBICodec.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VBICodec.ax 2021-04-07 22:39 - 2021-04-07 22:39 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2021-04-07 22:39 - 2021-04-07 22:39 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2021-04-07 22:39 - 2021-04-07 22:39 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2021-04-07 22:39 - 2021-04-07 22:39 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2021-04-07 22:39 - 2021-04-07 22:39 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll 2021-04-07 22:39 - 2021-04-07 22:39 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2021-04-07 22:38 - 2021-04-07 22:38 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2021-04-07 22:38 - 2021-04-07 22:38 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx 2021-04-07 22:38 - 2021-04-07 22:38 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000455680 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000446976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2021-04-07 22:38 - 2021-04-07 22:38 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\activeds.tlb 2021-04-07 22:38 - 2021-04-07 22:38 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl 2021-04-07 22:38 - 2021-04-07 22:38 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2021-04-07 22:38 - 2021-04-07 22:38 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msacm32.drv 2021-04-07 22:38 - 2021-04-07 22:38 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter.exe 2021-04-07 22:37 - 2021-04-07 22:37 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin 2021-04-07 22:37 - 2021-04-07 22:37 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 001394024 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2021-04-07 22:37 - 2021-04-07 22:37 - 000707016 _____ C:\WINDOWS\system32\TextShaping.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000643072 _____ C:\WINDOWS\system32\WindowManagementAPI.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2021-04-07 22:37 - 2021-04-07 22:37 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl 2021-04-07 22:37 - 2021-04-07 22:37 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl 2021-04-07 22:37 - 2021-04-07 22:37 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl 2021-04-07 22:37 - 2021-04-07 22:37 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2021-04-07 22:37 - 2021-04-07 22:37 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe 2021-04-07 22:37 - 2021-04-07 22:37 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\activeds.tlb 2021-04-07 22:37 - 2021-04-07 22:37 - 000091136 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2021-04-07 22:37 - 2021-04-07 22:37 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.proxystub.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2021-04-07 22:37 - 2021-04-07 22:37 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msacm32.drv 2021-04-07 22:37 - 2021-04-07 22:37 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll 2021-04-07 22:37 - 2021-04-07 22:37 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe 2021-04-07 22:37 - 2021-04-07 22:37 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt 2021-04-07 22:30 - 2021-04-07 22:46 - 000000000 ____D C:\WINDOWS\system32\Intel 2021-04-07 22:30 - 2021-04-07 22:46 - 000000000 ____D C:\WINDOWS\system32\cAVS 2021-04-07 22:00 - 2021-04-07 22:00 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2021-04-07 21:59 - 2021-04-19 14:58 - 001632020 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-04-07 21:57 - 2021-04-17 03:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-04-07 21:57 - 2021-04-14 11:31 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP 2021-04-07 21:57 - 2021-04-12 18:05 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2752837909-2800631316-633405880-1001 2021-04-07 21:57 - 2021-04-07 21:57 - 000003628 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-04-07 21:57 - 2021-04-07 21:57 - 000003558 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-04-07 21:57 - 2021-04-07 21:57 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2021-04-07 21:57 - 2021-04-07 21:57 - 000003404 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-04-07 21:57 - 2021-04-07 21:57 - 000003334 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-04-07 21:57 - 2021-04-07 21:57 - 000003274 _____ C:\WINDOWS\system32\Tasks\Dell SupportAssistAgent AutoUpdate 2021-04-07 21:57 - 2021-04-07 21:57 - 000002612 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0 2021-04-07 21:57 - 2021-04-07 21:57 - 000000020 ___SH C:\Users\gerar\ntuser.ini 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Vorlagen 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Startmenü 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Netzwerkumgebung 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Lokale Einstellungen 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Eigene Dateien 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Druckumgebung 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Users\Default\Anwendungsdaten 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Programme 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\ProgramData\Vorlagen 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\ProgramData\Startmenü 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\ProgramData\Dokumente 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 _SHDL C:\Dokumente und Einstellungen 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\S-1-5-21-2752837909-2800631316-633405880-1001 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software 2021-04-07 21:57 - 2021-04-07 21:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel 2021-04-07 21:56 - 2021-04-07 21:57 - 000007623 _____ C:\WINDOWS\diagwrn.xml 2021-04-07 21:56 - 2021-04-07 21:57 - 000007623 _____ C:\WINDOWS\diagerr.xml 2021-04-07 21:53 - 2021-04-07 21:53 - 000027108 _____ C:\WINDOWS\system32\emptyregdb.dat 2021-04-07 21:50 - 2021-04-16 23:22 - 000000000 ____D C:\Users\gerar 2021-04-07 21:50 - 2021-04-12 18:05 - 000002381 _____ C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Vorlagen 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Startmenü 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Netzwerkumgebung 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Lokale Einstellungen 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Eigene Dateien 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Druckumgebung 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Documents\Eigene Videos 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Documents\Eigene Musik 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Documents\Eigene Bilder 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\AppData\Local\Verlauf 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\AppData\Local\Anwendungsdaten 2021-04-07 21:50 - 2021-04-07 21:50 - 000000000 _SHDL C:\Users\gerar\Anwendungsdaten 2021-04-07 21:48 - 2021-04-21 13:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-04-07 21:48 - 2021-04-17 03:45 - 000008192 ___SH C:\DumpStack.log.tmp 2021-04-07 21:48 - 2021-04-16 23:23 - 000671992 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-04-06 20:14 - 2021-04-07 13:55 - 000000229 _____ C:\Users\gerar\Desktop\sammlung für lektion 12.txt 2021-04-06 11:49 - 2021-04-06 11:55 - 940829368 _____ C:\Users\gerar\Desktop\Lektion 2 GT II - 30 Min WS Gong + 5 Fragen_Aufgaben.mp4 2021-04-04 07:41 - 2021-04-04 07:41 - 000000000 ____D C:\Users\gerar\Downloads\fontwerk-download-000001945 2021-04-04 07:40 - 2021-04-04 07:40 - 004072781 _____ C:\Users\gerar\Downloads\fontwerk-download-000001945.zip 2021-04-04 07:23 - 2021-04-20 09:46 - 000000000 ___DC C:\WINDOWS\Panther 2021-04-04 07:23 - 2021-04-04 07:23 - 000000008 _____ C:\Users\gerar\Desktop\Turbine Font CI.txt 2021-04-04 07:22 - 2021-04-04 07:22 - 000000000 ____D C:\Users\gerar\Downloads\fontwerk-download-000001944 2021-04-04 07:20 - 2021-04-04 07:20 - 003350475 _____ C:\Users\gerar\Downloads\fontwerk-download-000001944.zip 2021-04-04 07:17 - 2021-04-04 07:17 - 000000000 ___HD C:\$WinREAgent 2021-04-01 21:02 - 2021-04-09 20:58 - 000000170 _____ C:\Users\gerar\Desktop\spende an c.a..txt 2021-03-31 12:42 - 2021-03-31 12:55 - 142290228 _____ C:\Users\gerar\Desktop\lektion 11.mp4 2021-03-31 12:32 - 2021-03-31 12:32 - 043750874 _____ C:\Users\gerar\Desktop\VID_20210331_115237992.mp4 2021-03-31 12:23 - 2021-03-31 12:24 - 1461022168 _____ C:\Users\gerar\Desktop\VID_20210331_115946482.mp4 2021-03-31 11:23 - 2021-03-31 11:23 - 126720676 _____ C:\Users\gerar\Desktop\Gérard 11 Minuten.wav 2021-03-31 11:16 - 2021-03-31 11:16 - 238647420 _____ C:\Users\gerar\Desktop\Gérard 22 Minuten mit White Sound.wav 2021-03-31 11:07 - 2021-03-31 11:07 - 238647466 _____ C:\Users\gerar\Downloads\gerar Gong Meditation Leiser Take 1_MASTER_16-44-22min32.wav 2021-03-31 11:07 - 2021-03-31 11:07 - 126720722 _____ C:\Users\gerar\Downloads\gerar Gong Meditation Leiser Take 2_MASTER_16-44-11min58.wav 2021-03-31 10:46 - 2021-03-31 10:46 - 328877978 _____ C:\Users\gerar\Desktop\gerar Gong Meditation Lauter Take_MASTER_16-44-31min04.wav 2021-03-31 09:25 - 2021-03-31 09:25 - 000000000 ____D C:\Users\gerar\Downloads\Movavi Sync 2021-03-30 18:55 - 2021-03-30 18:55 - 480820052 _____ C:\Users\gerar\Downloads\GMT20210309-175902_Zoom-Live-_gvo_1280x720.mp4 2021-03-30 18:55 - 2021-03-30 18:55 - 248633424 _____ C:\Users\gerar\Downloads\GMT20210309-175902_Zoom-Live-_avo_640x360.mp4 2021-03-30 18:55 - 2021-03-30 18:55 - 064863409 _____ C:\Users\gerar\Downloads\GMT20210309-175902_Zoom-Live-.mp4 2021-03-30 01:56 - 2021-03-30 01:56 - 000046629 _____ C:\Users\gerar\Downloads\In welchen Aspekten hege ich Groll gegen Go.pdf 2021-03-30 01:33 - 2021-03-30 01:33 - 000000000 ____D C:\WINDOWS\{74ECC31F-16C6-44ED-8F57-530C3F79C3A8} 2021-03-30 01:32 - 2021-03-30 01:32 - 025389384 _____ (Dell Inc.) C:\Users\gerar\Downloads\System-Utilities_Application_MHVWP_WN_2.2.1_A00.EXE 2021-03-27 21:41 - 2021-04-07 22:48 - 000000000 ____D C:\WINDOWS\system32\appmgmt 2021-03-27 02:20 - 2021-04-13 21:09 - 000000000 ____D C:\Users\gerar\AppData\Roaming\WhatsApp 2021-03-27 02:20 - 2021-04-13 20:56 - 000000000 ____D C:\Users\gerar\AppData\Local\WhatsApp 2021-03-27 02:20 - 2021-04-07 21:51 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2021-03-27 02:20 - 2021-03-27 02:20 - 000000000 ____D C:\Users\gerar\AppData\Local\SquirrelTemp 2021-03-27 02:20 - 2021-03-27 02:20 - 000000000 ____D C:\ProgramData\gerar ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2021-04-21 13:16 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2021-04-21 13:14 - 2020-01-14 22:39 - 000000000 ____D C:\Users\gerar\AppData\LocalLow\Mozilla 2021-04-21 13:06 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-04-21 11:20 - 2020-11-28 10:55 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2021-04-21 10:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-04-21 08:29 - 2020-01-22 21:44 - 000000000 ___RD C:\Users\gerar\Google Drive 2021-04-21 08:29 - 2020-01-14 22:39 - 000000000 ____D C:\ProgramData\Mozilla 2021-04-21 08:28 - 2020-01-14 22:39 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-04-21 08:28 - 2020-01-14 22:39 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-04-21 08:26 - 2020-10-22 09:00 - 000000000 ____D C:\Users\gerar\AppData\Roaming\QScan System-Check 2021-04-21 08:26 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2021-04-21 08:25 - 2020-01-14 17:04 - 000000000 __SHD C:\Users\gerar\IntelGraphicsProfiles 2021-04-21 08:25 - 2020-01-02 22:30 - 000000000 ____D C:\ProgramData\Goodix 2021-04-20 15:25 - 2020-01-02 22:32 - 000000000 ____D C:\ProgramData\NVIDIA 2021-04-20 14:43 - 2020-01-02 22:32 - 000000000 ____D C:\Program Files (x86)\Dell Digital Delivery Services 2021-04-20 10:02 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-04-20 08:38 - 2021-02-17 17:59 - 000000000 ____D C:\Users\gerar\AppData\Roaming\audacity 2021-04-19 14:58 - 2019-12-07 16:51 - 000708572 _____ C:\WINDOWS\system32\perfh007.dat 2021-04-19 14:58 - 2019-12-07 16:51 - 000142814 _____ C:\WINDOWS\system32\perfc007.dat 2021-04-19 14:57 - 2020-11-07 09:47 - 000000000 ____D C:\Program Files\Common Files\logishrd 2021-04-17 21:50 - 2019-12-17 10:04 - 000000000 ____D C:\Program Files\Microsoft Office 2021-04-17 03:52 - 2019-12-17 09:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-04-17 03:45 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2021-04-16 23:23 - 2019-12-07 11:03 - 002621440 _____ C:\WINDOWS\system32\config\BBI 2021-04-16 23:22 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-04-16 23:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-04-16 20:59 - 2020-06-21 17:57 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-04-16 20:59 - 2020-06-21 17:57 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-04-16 20:59 - 2020-06-21 17:57 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk 2021-04-16 20:41 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing 2021-04-16 20:41 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-04-16 20:33 - 2020-01-18 17:59 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-04-16 20:32 - 2020-01-22 22:05 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-04-16 20:30 - 2020-01-18 17:59 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-04-14 11:32 - 2020-08-22 03:50 - 000002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-04-14 11:32 - 2020-08-22 03:50 - 000002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2021-04-14 11:32 - 2020-08-22 03:50 - 000002254 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2021-04-13 21:12 - 2020-01-21 13:08 - 000001325 _____ C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2021-04-13 18:59 - 2020-03-18 08:38 - 000000000 ___RD C:\Users\gerar\Documents\Zoom 2021-04-12 18:05 - 2020-01-14 17:07 - 000000000 ___RD C:\Users\gerar\OneDrive 2021-04-09 22:33 - 2020-08-22 14:54 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-04-09 10:26 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\appcompat 2021-04-07 22:48 - 2021-02-09 22:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Kameraeinstellungen 2021-04-07 22:48 - 2020-10-23 21:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64 2021-04-07 22:48 - 2020-09-09 20:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer 2021-04-07 22:48 - 2020-05-30 11:39 - 000000000 ____D C:\Program Files\UNP 2021-04-07 22:48 - 2020-05-04 09:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio 2021-04-07 22:48 - 2020-03-25 18:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (32 bits) 2021-04-07 22:48 - 2020-01-30 06:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Loopcloud 2021-04-07 22:48 - 2020-01-22 21:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google 2021-04-07 22:48 - 2020-01-21 14:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup 2021-04-07 22:48 - 2020-01-17 19:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2021-04-07 22:48 - 2020-01-02 22:29 - 000000000 ____D C:\Program Files\Intel 2021-04-07 22:48 - 2019-12-17 10:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2021-04-07 22:48 - 2019-12-07 11:18 - 000000000 ____D C:\WINDOWS\Setup 2021-04-07 22:48 - 2019-12-07 11:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\spool 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Macromed 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData 2021-04-07 22:48 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2021-04-07 22:48 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2021-04-07 22:48 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2021-04-07 22:46 - 2021-03-09 22:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2021-04-07 22:46 - 2020-10-07 20:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZOOM 2021-04-07 22:46 - 2020-05-03 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2021-04-07 22:46 - 2020-01-18 18:18 - 000000000 ____D C:\WINDOWS\Firmware 2021-04-07 22:46 - 2020-01-18 17:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments 2021-04-07 22:43 - 2019-12-07 16:54 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2021-04-07 22:43 - 2019-12-07 16:54 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2021-04-07 22:43 - 2019-12-07 16:54 - 000000000 ___SD C:\WINDOWS\system32\AppV 2021-04-07 22:43 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2021-04-07 22:43 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Keywords 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Com 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellComponents 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\IME 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System 2021-04-07 22:43 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\winrm 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\WCN 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\slmgr 2021-04-07 22:32 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2021-04-07 22:32 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\dsc 2021-04-07 22:15 - 2020-01-14 17:04 - 000000000 ____D C:\Users\gerar\AppData\Local\Packages 2021-04-07 22:15 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2021-04-07 22:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Registration 2021-04-07 21:58 - 2020-01-14 17:04 - 000000000 ___RD C:\Users\gerar\3D Objects 2021-04-07 21:58 - 2020-01-02 22:43 - 000000000 ____D C:\ProgramData\Packages 2021-04-07 21:58 - 2019-12-17 10:24 - 000000000 __RHD C:\Users\Public\AccountPictures 2021-04-07 21:58 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\USOPrivate 2021-04-07 21:57 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows NT 2021-04-07 21:57 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows Defender 2021-04-07 21:57 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2021-04-07 21:53 - 2019-12-07 11:14 - 000000000 __RHD C:\Users\Public\Libraries 2021-04-07 21:51 - 2020-11-28 10:08 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 21 2021-04-07 21:51 - 2020-11-16 21:16 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom 2021-04-07 21:51 - 2020-10-22 09:00 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check 2021-04-07 21:51 - 2020-08-20 20:29 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 2020 2021-04-07 21:51 - 2020-05-12 16:28 - 000000000 ____D C:\Users\gerar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 15 2021-04-07 21:49 - 2020-01-02 22:32 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation 2021-04-07 21:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2021-03-30 01:33 - 2020-01-02 22:33 - 000000000 ____D C:\ProgramData\Dell 2021-03-30 01:33 - 2020-01-02 22:28 - 000000000 ____D C:\Program Files\Dell 2021-03-27 20:21 - 2021-03-16 11:39 - 000000000 ____D C:\Users\gerar\Documents\Soundaufnahmen 2021-03-27 16:36 - 2020-03-05 06:26 - 000000000 ____D C:\Users\gerar\AppData\Local\ElevatedDiagnostics ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======== 2020-10-09 17:18 - 2020-10-09 17:18 - 000000015 _____ () C:\Users\gerar\AppData\Roaming\obs-virtualcam.txt 2020-11-28 11:28 - 2020-11-28 11:28 - 000000000 _____ () C:\Users\gerar\AppData\Local\oobelibMkey.log 2020-05-03 17:33 - 2020-05-03 17:33 - 000000017 _____ () C:\Users\gerar\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== Addition Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 17-04-2021 durchgeführt von gerar (21-04-2021 13:19:35) Gestartet von C:\Users\gerar\Downloads Windows 10 Pro Version 20H2 19042.928 (X64) (2021-04-07 19:57:19) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2752837909-2800631316-633405880-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2752837909-2800631316-633405880-503 - Limited - Disabled) Gast (S-1-5-21-2752837909-2800631316-633405880-501 - Limited - Disabled) gerar (S-1-5-21-2752837909-2800631316-633405880-1001 - Administrator - Enabled) => C:\Users\gerar WDAGUtilityAccount (S-1-5-21-2752837909-2800631316-633405880-504 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 21.001.20149 - Adobe Systems Incorporated) Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: - Adobe) Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team) Avidemux 2.7 - 32 bits (32-bit) (HKLM-x32\...\Avidemux 2.7 - 32 bits) (Version: 2.7.4.190815 - ) Backup and Sync from Google (HKLM\...\{3CBE1074-3A4F-4BA6-95E3-7A660B54FE33}) (Version: 3.55.3625.9414 - Google, Inc.) Canon Utilities Digital Photo Professional 4 (HKLM-x32\...\Digital Photo Professional 4 (x64)) (Version: 4.12.20.3 - Canon Inc.) Canon Utilities EOS Lens Registration Tool (HKLM-x32\...\EOS Lens Registration Tool) (Version: 1.12.30.6 - Canon Inc.) Canon Utilities EOS Network Setting Tool (HKLM-x32\...\EOS Network Setting Tool) (Version: 1.1.0.9 - Canon Inc.) Canon Utilities EOS Utility 2 (HKLM-x32\...\EOS Utility 2) (Version: 2.14.20.0 - Canon Inc.) Canon Utilities EOS Utility 3 (HKLM-x32\...\EOS Utility 3) (Version: 3.12.30.9 - Canon Inc.) Canon Utilities EOS Web Service Registration Tool (HKLM-x32\...\EOS Web Service Registration Tool) (Version: 1.9.10.5 - Canon Inc.) Dell Digital Delivery Services (HKLM-x32\...\{81C48559-E2EB-4F18-9854-51331B9DB552}) (Version: 4.0.70.0 - Dell Inc.) Dell Feature Enhancement Pack (HKLM\...\{992D1CE7-A20F-4AB0-9D9D-AFC3418844DA}) (Version: 2.2.1 - Dell) Dell Mobile Connect Drivers (HKLM\...\{4674F112-9AB7-4701-AEC0-C1FD1FE7CD4E}) (Version: 2.0.8401 - Screenovate Technologies Ltd.) Dell Peripheral Manager (HKLM\...\Dell Peripheral Manager) (Version: 1.3.0 - Dell Inc.) Dell Power Manager Service (HKLM\...\{18469ED8-8C36-4CF7-BD43-0FC9B1931AF8}) (Version: 3.7.0 - Dell Inc.) Dell SupportAssist (HKLM\...\{C5A70974-2F89-4BE0-90F7-749E62468C4D}) (Version: 3.8.1.23 - Dell Inc.) Dell SupportAssist Remediation (HKLM\...\{1906C253-4035-4CA5-A501-075E691CCEC9}) (Version: 5.0.0.10859 - Dell Inc.) Hidden Dell SupportAssist Remediation (HKLM-x32\...\{96846915-505c-49a2-8aa0-63f90927de87}) (Version: 5.0.0.10859 - Dell Inc.) Dell Update - SupportAssist Update Plugin (HKLM\...\{C559D0AB-2D9E-4B59-B2B8-0C2061B3F9BC}) (Version: 5.0.0.10859 - Dell Inc.) Hidden Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{3a267e2b-0948-4f12-a103-e2ac0461179d}) (Version: 5.0.0.10859 - Dell Inc.) Dell Update for Windows 10 (HKLM\...\{41D2D254-D869-4CD8-B440-5DF49083C4BA}) (Version: 4.1.0 - Dell Inc.) Dynamic Application Loader Host Interface Service (HKLM\...\{B2B50A9C-3A65-4BDC-AA76-5D7537D8A7D1}) (Version: 1.0.0.0 - Intel Corporation) Hidden EOS Webcam Utility (HKLM\...\{09435D17-130D-4D05-93C3-D90556E48972}) (Version: 1.0.12 - Canon U.S.A., Inc.) EOS Webcam Utility Beta (HKLM\...\{6A2053A2-6427-44AA-8FFA-46A184C47663}) (Version: 0.9.0 - Canon U.S.A., Inc.) Goodix Fingerprint Driver (HKLM\...\{60FAB781-18F2-4D2B-A8E7-B3AADD327955}_is1) (Version: 3.0.35.450 - Goodix, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 89.0.4389.128 - Google LLC) H_and_F-Series_Multi_Track_ASIO64 (HKLM\...\{0751E62E-5898-4791-B97A-F91C3EF3366C}) (Version: 2.1.0.19 - ZOOM) HWiNFO64 Version 6.32 (HKLM\...\HWiNFO64_is1) (Version: 6.32 - Martin Malik - REALiX) Intel(R) Dynamic Tuning (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.6.10401.9906 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1937.14.0.1350 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.6911 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.5.3.1026 - Intel Corporation) Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.2020.7 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000080-0210-1031-84C8-B8D95FA3C8C3}) (Version: 21.80.0.3 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (HKLM-x32\...\{37942a92-9e3f-4d70-9b5c-5955cbc54505}) (Version: 10.1.18121.8164 - Intel(R) Corporation) Intel® Integrated Sensor Solution (HKLM-x32\...\{8567e89c-3664-472e-b7fa-f9580c29214f}) (Version: 3.10.100.4109 - Intel Corporation) Intel® Optane™ Pinning Explorer Extensions (HKLM\...\{5EEB8181-5D0C-4913-A61F-00DCB6CBAF63}) (Version: 17.5.3.1026 - Intel Corporation) Intel® Software Installer (HKLM-x32\...\{4a50fa17-2911-43ed-a2a1-d3a34411e2bb}) (Version: 21.110.2.1 - Intel Corporation) Hidden ISS_Drivers_x64 (HKLM\...\{8E4F419B-AB8D-4D06-8D1E-1144646F5CAF}) (Version: 3.10.100.4109 - Intel Corporation) Hidden Logitech Kameraeinstellungen (HKLM-x32\...\LogiUCDPP) (Version: 2.12.8.0 - Logitech Europe S.A.) Loopcloud version 5.0.32 (HKLM\...\Loopcloud_is1) (Version: 5.0.32 - ) LUFS Meter 2 version 2.1.2 (HKLM\...\LUFS Meter 2_is1) (Version: 2.1.2 - klangfreund.com) MAGIX Content und Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Soundpool Music Maker - Feel good (HKLM\...\{677F8E85-8686-476B-829A-D5ED9ECA16E6}) (Version: 1.0.1.0 - MAGIX Software GmbH) Hidden Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13901.20400 - Microsoft Corporation) Microsoft 365 - fr-fr (HKLM\...\O365HomePremRetail - fr-fr) (Version: 16.0.13901.20400 - Microsoft Corporation) Microsoft 365 - it-it (HKLM\...\O365HomePremRetail - it-it) (Version: 16.0.13901.20400 - Microsoft Corporation) Microsoft 365 - nl-nl (HKLM\...\O365HomePremRetail - nl-nl) (Version: 16.0.13901.20400 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 89.0.774.77 - Microsoft Corporation) Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 90.0.818.42 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\OneDriveSetup.exe) (Version: 21.052.0314.0001 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{99FAF70F-9B61-4AB0-9EC0-B31F98FFDC4A}) (Version: 2.75.0.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation) MixPad Musikstudio-Software (HKLM-x32\...\MixPad) (Version: 7.07 - NCH Software) Movavi Video Editor 15 (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Movavi Video Editor 15) (Version: 15.4.1 - Movavi) Movavi Video Suite 2020 (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Movavi Video Suite 2020) (Version: 20.4.1 - Movavi) Movavi Video Suite 21 (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Movavi Video Suite 21) (Version: 21.0.1 - Movavi) MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 88.0 (x64 de) (HKLM\...\Mozilla Firefox 88.0 (x64 de)) (Version: 88.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 72.0.1 - Mozilla) Mozilla Thunderbird 78.9.1 (x86 de) (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\Mozilla Thunderbird 78.9.1 (x86 de)) (Version: 78.9.1 - Mozilla) Music Maker (64-Bit) (HKLM\...\{500A036B-F08F-4E9E-ADC0-4EF3BA4D6C0D}) (Version: 29.0.4.25 - MAGIX Software GmbH) Hidden Music Maker (64-Bit) (HKLM\...\MX.{500A036B-F08F-4E9E-ADC0-4EF3BA4D6C0D}) (Version: 29.0.4.25 - MAGIX Software GmbH) Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 2.1.0.183 - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: 2.6.0.137 - Native Instruments) Native Instruments Traktor 2 (HKLM-x32\...\Native Instruments Traktor 2) (Version: 2.11.1.31 - Native Instruments) Native Instruments Traktor Audio 10 Driver (HKLM-x32\...\Native Instruments Traktor Audio 10 Driver) (Version: - Native Instruments) Native Instruments Traktor Audio 2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Audio 2 MK2 Driver) (Version: - Native Instruments) Native Instruments Traktor Audio 6 Driver (HKLM-x32\...\Native Instruments Traktor Audio 6 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol D2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol D2 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol F1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol F1 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol S2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S2 MK2 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol S4 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S4 MK2 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol S5 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S5 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol S8 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S8 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol X1 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol X1 MK2 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol Z1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z1 Driver) (Version: - Native Instruments) Native Instruments Traktor Kontrol Z2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z2 Driver) (Version: - Native Instruments) NVIDIA FrameView SDK 1.1.4923.29214634 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29214634 - NVIDIA Corporation) NVIDIA Grafiktreiber 457.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 457.30 - NVIDIA Corporation) NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 25.0.8 - OBS Project) obs-virtualcam (HKLM-x32\...\obs-virtualcam) (Version: - ) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13901.20400 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13901.20400 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13901.20336 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-040C-1000-0000000FF1CE}) (Version: 16.0.13901.20336 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0410-1000-0000000FF1CE}) (Version: 16.0.13901.20336 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0413-1000-0000000FF1CE}) (Version: 16.0.13901.20336 - Microsoft Corporation) Hidden QScan System-Check (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\QScan System-Check) (Version: 1.0.0 - QScan System-Check Services) <==== ACHTUNG Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8984.1 - Realtek Semiconductor Corp.) SmartByte Drivers and Services (HKLM\...\{9668B1BB-D0FE-4C0C-800C-B1555E069A62}) (Version: 3.1.940 - Rivet Networks) Streamlabs OBS 0.24.1 (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 0.24.1 - General Workings, Inc.) Twitch Studio (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF372B0}) (Version: 8.0.0 - Twitch Interactive, Inc.) Update Notifier (HKLM\...\{9387807D-92D3-4DF3-B500-C7C81A353809}) (Version: 3.0.0.50 - MAGIX Software GmbH) Hidden Update Notifier (HKLM\...\MX.{9387807D-92D3-4DF3-B500-C7C81A353809}) (Version: 3.0.0.50 - MAGIX Software GmbH) VdhCoApp 1.5.0 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper) Vita Concert Grand LE (HKLM\...\{2C61CE04-1EEF-4582-ABBA-B9CCFC3743EB}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden WavePad Audio-Editor (HKLM-x32\...\WavePad) (Version: 12.22 - NCH Software) WhatsApp (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\WhatsApp) (Version: 2.2112.10 - WhatsApp) Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers) Windows-Treiberpaket - Canon U.S.A., Inc. (WUDFRd) Camera (08/11/2020 16.16.0.56) (HKLM\...\787F19D70938C6A2C7457C5F8EB87C3164D8434A) (Version: 08/11/2020 16.16.0.56 - Canon U.S.A., Inc.) Zoom (HKU\S-1-5-21-2752837909-2800631316-633405880-1001\...\ZoomUMX) (Version: 5.4.3 (58891.1115) - Zoom Video Communications, Inc.) Packages: ========= Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.56.3.0_x86__kgqvnymyfvs32 [2021-04-13] (king.com) Dell Customer Connect -> C:\Program Files\WindowsApps\DellInc.DellCustomerConnect_5.2.52.0_x64__htrsf667h5kn2 [2021-04-12] (Dell Inc) Dell Digital Delivery -> C:\Program Files\WindowsApps\DellInc.DellDigitalDelivery_4.0.70.0_x64__htrsf667h5kn2 [2021-04-07] (Dell Inc) Dell Mobile Connect -> C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0 [2021-01-24] (Screenovate Technologies) [Startup Task] Dell Power Manager -> C:\Program Files\WindowsApps\DellInc.DellPowerManager_3.7.10.0_x64__htrsf667h5kn2 [2021-04-07] (Dell Inc) Dell SupportAssist for Home PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.8.10.0_x64__htrsf667h5kn2 [2021-01-22] (Dell Inc) Dell Update -> C:\Program Files\WindowsApps\DellInc.DellUpdate_4.1.15.0_x86__htrsf667h5kn2 [2021-02-14] (Dell Inc) Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.56.4.0_x86__kgqvnymyfvs32 [2021-04-01] (king.com) Fotos-Add-On -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-13] (Microsoft Corporation) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_126.2.222.0_x64__v10z8vjag6ke6 [2021-04-13] (HP Inc.) Intel® Grafik-Kontrollraum -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3282.0_x64__8j3eq9eme6ctt [2021-04-07] (INTEL CORP) [Startup Task] Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2020-03-01] (INTEL CORP) Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1015.0_x64__8j3eq9eme6ctt [2021-03-13] (INTEL CORP) Media Engine-Add-On für Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Corporation) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-04-07] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-04-07] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.1252.0_x64__8wekyb3d8bbwe [2021-04-07] (Microsoft Studios) [MS Ad] Microsoft-Remotedesktop -> C:\Program Files\WindowsApps\Microsoft.RemoteDesktop_10.2.1810.0_x64__8wekyb3d8bbwe [2021-03-07] (Microsoft Corporation) MPEG-2-Videoerweiterung -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2020-01-19] (Microsoft Corporation) My Dell -> C:\Program Files\WindowsApps\DellInc.MyDell_1.7.33.0_x64__htrsf667h5kn2 [2021-03-26] (Dell Inc) Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-15] (Netflix, Inc.) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.960.0_x64__56jybvy8sckqj [2021-04-07] (NVIDIA Corp.) SmartByte -> C:\Program Files\WindowsApps\RivetNetworks.SmartByte_3.1.958.0_x64__rh07ty8m5nkag [2021-01-14] (Rivet Networks LLC) Waves MaxxAudio Pro for Dell 2019 -> C:\Program Files\WindowsApps\WavesAudio.MaxxAudioProforDell2019_2.0.54.0_x64__fh4rh281wavaa [2020-01-02] (Waves Audio) XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.8.0_x86__xpfg3f7e9an52 [2021-04-07] (New Work SE) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2752837909-2800631316-633405880-1001_Classes\CLSID\{ca31933b-b116-4444-9c6d-e5103390fb76}\localserver32 -> "C:\Program Files\TechSmith\Camtasia 2020\CamtasiaStudio.exe" -ToastActivated => Keine Datei ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2021-03-12] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2021-03-12] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2021-03-12] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2019-07-23] (Intel(R) Rapid Storage Technology -> ) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2021-03-12] (Google LLC -> Google) ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2019-07-23] (Intel(R) Rapid Storage Technology -> ) ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2021-03-12] (Google LLC -> Google) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_af978b59a0727cf8\nvshext.dll [2020-11-07] (NVIDIA Corporation -> NVIDIA Corporation) ==================== Codecs (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Drivers32: [vidc.i420] => C:\Windows\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.) HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.) ==================== Verknüpfungen & WMI ======================== ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============= 2020-11-19 14:12 - 2020-11-19 14:12 - 000019456 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.HSA.Server.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000011776 _____ () [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\libEGL.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 002013696 _____ () [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\libGLESv2.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000739840 _____ () [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\QtQuick\Controls\qtquickcontrolsplugin.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000114176 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_ctypes.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000172544 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_elementtree.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 002255872 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_hashlib.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000032256 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_multiprocessing.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000046080 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_psutil_windows.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000047616 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_socket.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 002824704 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_ssl.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000026112 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\_yappi.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000080896 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\bz2.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000015872 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\common.time34.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000007680 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\hashobjs_ext.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000301568 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\PIL._imaging.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000168448 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\pyexpat.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 001084416 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\pysqlite2._sqlite.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000548864 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\pythoncom27.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000137728 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\pywintypes27.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000010752 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\select.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000020992 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\thumbnails_ext.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000689664 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\unicodedata.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000119808 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\usb_ext.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000128512 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32api.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000438784 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32com.shell.shell.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000011776 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32crypt.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000023040 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32event.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000149504 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32file.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000223232 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32gui.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000048128 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32inet.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000029696 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32pdh.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000027648 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32pipe.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000044032 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32process.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000020480 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32profile.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000136192 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32security.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000026624 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\win32ts.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000034304 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\windows.conditional.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000037888 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\windows.connectivity.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000071680 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\windows.device_monitor.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000103936 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\windows.volumes.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000019968 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\windows.winwrap.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 001325056 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._controls_.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 001489408 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._core_.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 001007104 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._gdi_.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000103424 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._html2.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 000916992 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._misc_.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 001039872 _____ () [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wx._windows_.pyd 2021-04-21 08:26 - 2021-04-21 08:26 - 003043328 _____ (Python Software Foundation) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\python27.dll 2020-12-01 01:14 - 2020-12-01 01:14 - 001638912 _____ (Robert Simpson, et al.) [Datei ist nicht signiert] C:\Program Files\Dell\SupportAssistAgent\bin\x64\SQLite.Interop.dll 2021-01-24 20:12 - 2021-01-24 20:12 - 008830976 _____ (Screenovate Technologies Ltd.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\core.uwp.dll 2021-01-24 20:12 - 2021-01-24 20:12 - 045847040 _____ (Screenovate Technologies Ltd.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\DellMobileConnectUniversalClient.dll 2019-01-22 16:02 - 2019-01-22 16:02 - 000213504 _____ (simplitec GmbH) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\MrStyler_x64.dll 2018-12-20 09:03 - 2018-12-20 09:03 - 000290304 _____ (simplitec GmbH) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\MrTracker.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000045568 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\bearer\qgenericbearer.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000047616 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\bearer\qnativewifibearer.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000049664 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qdds.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000029696 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qgif.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000037376 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qicns.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000030208 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qico.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000459776 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qjp2.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000236544 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qjpeg.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000275456 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qmng.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000023552 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qsvg.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000022528 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qtga.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000351744 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qtiff.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000021504 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qwbmp.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000374784 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\imageformats\qwebp.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 001212928 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\platforms\qwindows.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 005500416 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Core.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 005804544 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Gui.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 001064448 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Network.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 003189248 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Qml.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 002928128 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Quick.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000310784 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Svg.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 005446144 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\Qt5Widgets.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000015360 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\QtQuick.2\qtquick2plugin.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000072192 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\QtQuick\Layouts\qquicklayoutsplugin.dll 2018-06-14 13:18 - 2018-06-14 13:18 - 000015360 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files\Common Files\MAGIX Services\Update Notifier\QtQuick\Window.2\windowplugin.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000202240 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxbase30u_net_vc90_x64.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 002831872 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxbase30u_vc90_x64.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 001654784 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxmsw30u_adv_vc90_x64.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 006542336 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxmsw30u_core_vc90_x64.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000773632 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxmsw30u_html_vc90_x64.dll 2021-04-21 08:26 - 2021-04-21 08:26 - 000137216 _____ (wxWidgets development team) [Datei ist nicht signiert] C:\Users\gerar\AppData\Local\Temp\_MEI99282\wxmsw30u_webview_vc90_x64.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ======== ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ================== ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ================= ==================== Internet Explorer (Nicht auf der Ausnahmeliste) ========== HKU\S-1-5-21-2752837909-2800631316-633405880-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=DCTE HKU\S-1-5-21-2752837909-2800631316-633405880-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?pc=DCTE BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-03-05] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-04-09] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts Inhalt: ========================= (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts 2020-02-13 05:34 - 2020-11-05 17:58 - 000000446 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics ==================== Andere Bereiche =========================== (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2752837909-2800631316-633405880-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\gerar\Desktop\sun shepardess.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{CD1913FF-E579-4DCA-84BF-EED48B7D114C}] => (Allow) C:\Program Files\MAGIX\Music Maker\29\MusicMaker.exe (MAGIX Software GmbH -> MAGIX Software GmbH) FirewallRules: [{FDE4877F-ADBC-41B5-AA8C-2F06D5CBCCA5}] => (Allow) C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe (MAGIX Software GmbH -> MAGIX) FirewallRules: [UDP Query User{E69E649A-B5C3-4162-ABC2-4ED83DEAA66E}C:\program files (x86)\nch software\mixpad\mixpad.exe] => (Allow) C:\program files (x86)\nch software\mixpad\mixpad.exe (NCH Software, Inc. -> NCH Software) FirewallRules: [TCP Query User{069F31E4-343E-45E4-A5B5-C9C2BA05A53A}C:\program files (x86)\nch software\mixpad\mixpad.exe] => (Allow) C:\program files (x86)\nch software\mixpad\mixpad.exe (NCH Software, Inc. -> NCH Software) FirewallRules: [UDP Query User{9ABFF91D-7104-48E5-A0E7-CCBC6DE1F2EB}C:\users\gerar\appdata\roaming\twitch studio\bin\twitchstudioagent.exe] => (Allow) C:\users\gerar\appdata\roaming\twitch studio\bin\twitchstudioagent.exe (Twitch Interactive, Inc. -> ) FirewallRules: [TCP Query User{F31D27FA-C7B9-4E2A-991C-C90F71FE16FF}C:\users\gerar\appdata\roaming\twitch studio\bin\twitchstudioagent.exe] => (Allow) C:\users\gerar\appdata\roaming\twitch studio\bin\twitchstudioagent.exe (Twitch Interactive, Inc. -> ) FirewallRules: [{3CAABE6A-6DD3-49B7-BA9F-559F91BD8F64}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{8722D9CD-6C65-4A80-9111-3A0E6BCA5ABE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{61564D98-EFFA-4A41-BA10-BB096F295D1A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{38700E81-8D45-4692-A07B-8FDD573CBF89}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{F390655A-0F5E-4BF6-9363-C05E0E7185F0}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.) FirewallRules: [{9B1AC12C-94CF-4902-B491-409E08D33078}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9771.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.) FirewallRules: [{E23C4C13-031A-49DF-A640-A20D3EF954B5}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{25FE221F-A0FC-4FE9-A5F8-25B48688604A}C:\program files\adobe\adobe premiere pro 2020\dvaaudiofilterscan.exe] => (Allow) C:\program files\adobe\adobe premiere pro 2020\dvaaudiofilterscan.exe => Keine Datei FirewallRules: [TCP Query User{A75E352F-393D-4749-8F73-58365890F90C}C:\program files\adobe\adobe premiere pro 2020\dvaaudiofilterscan.exe] => (Allow) C:\program files\adobe\adobe premiere pro 2020\dvaaudiofilterscan.exe => Keine Datei FirewallRules: [{B184A877-4FF6-44B8-91FC-994ED147F479}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe => Keine Datei FirewallRules: [{6524EC99-B952-4495-94EB-DCDB2AD5CD36}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe => Keine Datei FirewallRules: [UDP Query User{9B8BA24B-FB6B-4391-BE9F-22C72FBF70FB}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{DAE74AA5-B90A-4DE2-AF83-DD02C0E7C3F0}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{1AE260C6-6A6A-43CB-B72E-5E2FE519B667}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe => Keine Datei FirewallRules: [{950D36CC-D221-4F3B-BA72-CE9766E4D956}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe => Keine Datei FirewallRules: [{7EBB4318-309A-4E51-ACB2-D92E2ABD2749}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (Canon Inc. -> CANON INC.) FirewallRules: [{E4B1E3C4-4050-4AB8-AD53-B07CF396A0E5}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (Canon Inc. -> CANON INC.) FirewallRules: [{2648E147-2E40-41C6-975E-1DA9AD592A2F}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (Canon Inc. -> CANON INC.) FirewallRules: [{B5CAB5F6-EE74-4A0E-8942-FBC23C9A608B}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (Canon Inc. -> CANON INC.) FirewallRules: [{68C8A36C-AB52-415D-B694-94F399E14938}] => (Allow) C:\Users\gerar\AppData\Roaming\Zoom\bin\airhost.exe => Keine Datei FirewallRules: [{F2ABEB62-5000-484F-9EE9-3D8C44D78976}] => (Allow) C:\Users\gerar\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [UDP Query User{20C9E236-D893-49C0-8DCC-7E95BB06B2BB}C:\program files\loopcloud\loopcloud.exe] => (Allow) C:\program files\loopcloud\loopcloud.exe () [Datei ist nicht signiert] FirewallRules: [TCP Query User{5166E42B-EF60-48AC-8CC6-E618ACB327B7}C:\program files\loopcloud\loopcloud.exe] => (Allow) C:\program files\loopcloud\loopcloud.exe () [Datei ist nicht signiert] FirewallRules: [{3C9E898A-263D-4D3C-A60F-8C21AE2F1D4E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{9A03B728-2694-4A12-9264-77CCC2E45A68}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{AB7C3447-9518-4848-BCBE-CF35CF4BE0A3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{A3986A36-3C6D-4BF5-995D-56B90307734B}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\90.0.818.42\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:221.44 GB) (Free:33.01 GB) (15%) ==================== Fehlerhafte Geräte im Gerätemanager ============ ==================== Fehlereinträge in der Ereignisanzeige: ======================== Applikationsfehler: ================== Error: (04/21/2021 08:28:40 AM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: ) Description: Event-ID 12007 Error: (04/21/2021 08:28:40 AM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: ) Description: Event-ID 0 Error: (04/20/2021 08:28:27 AM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: ) Description: Event-ID 12007 Error: (04/20/2021 08:28:27 AM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: ) Description: Event-ID 0 Error: (04/15/2021 10:39:48 PM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: ) Description: Event-ID 12007 Error: (04/15/2021 10:39:48 PM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: ) Description: Event-ID 0 Error: (04/15/2021 04:14:50 AM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: ) Description: Event-ID 12007 Error: (04/15/2021 04:14:50 AM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: ) Description: Event-ID 0 Systemfehler: ============= Error: (04/21/2021 09:19:42 AM) (Source: EOSWebcam) (EventID: 0) (User: ) Description: OpenSession Err: 128 Error: (04/21/2021 08:40:42 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (04/21/2021 08:29:22 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (04/21/2021 08:25:40 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: ) Description: Für den Miniport "Microsoft Wi-Fi Direct Virtual Adapter #4, {9154da53-86c8-4a75-87a7-fd408db35f5f}" ist das Ereignis "74" aufgetreten. Error: (04/20/2021 03:24:56 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (04/20/2021 03:24:56 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (04/20/2021 03:24:56 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "Microsoft.WebMediaExtensions_1.0.40831.0_x64__8wekyb3d8bbwe!App.AppX5mvjzgfkp7zwcj41y2acxgs5c976dxda.mca" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (04/20/2021 03:24:56 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VUAFHKR) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Windows Defender: ================ Date: 2021-04-21 10:46:33 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {24F04E53-FFC4-451F-9F29-58D6B47727B6} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2021-04-20 09:45:35 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {CA1FC968-AA60-4BA6-A60F-02B0FAFAF17B} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2021-04-17 04:09:48 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {F591800F-29B0-4D45-98A4-ACCE2E645AFF} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2021-04-16 21:37:50 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {AF3C0B28-280D-43DB-B886-B148D0EE27D1} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM Date: 2021-04-15 12:14:22 Description: Die Microsoft Defender Antivirus-Überprüfung wurde vor ihrem Abschluss beendet. Überprüfungs-ID: {8E62D2FB-091B-4D9C-A871-85C16B90AF09} Überprüfungstyp: Antimalware Überprüfungsparameter: Schnellüberprüfung Benutzer: NT-AUTORITÄT\SYSTEM CodeIntegrity: =============== Date: 2021-04-16 22:15:05 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\WindowManagementAPI.dll because the set of per-page image hashes could not be found on the system. Date: 2021-04-16 22:14:46 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdmi.inf_amd64_af978b59a0727cf8\nvdlistx.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== BIOS: Dell Inc. 1.10.0 09/02/2020 Hauptplatine: Dell Inc. 0WFF79 Prozessor: Intel(R) Core(TM) i5-10210U CPU @ 1.60GHz Prozentuale Nutzung des RAM: 95% Installierter physikalischer RAM: 7976.24 MB Verfügbarer physikalischer RAM: 361.65 MB Summe virtueller Speicher: 13352.24 MB Verfügbarer virtueller Speicher: 2086.27 MB ==================== Laufwerke ================================ Drive c: (OS) (Fixed) (Total:221.44 GB) (Free:33.01 GB) (Protected) NTFS \\?\Volume{56ca636c-c840-49c4-95df-a7b2d0e4aa4e}\ (WINRETOOLS) (Fixed) (Total:0.97 GB) (Free:0.26 GB) NTFS \\?\Volume{a76febe3-352d-4a8a-9e52-f117f9211f96}\ (Image) (Fixed) (Total:13.96 GB) (Free:0.15 GB) NTFS \\?\Volume{95369428-26f5-4c69-83ae-0a6963a6be11}\ (DELLSUPPORT) (Fixed) (Total:1.32 GB) (Free:0.48 GB) NTFS \\?\Volume{200ad4ec-6922-4a8d-acd8-6ccf1d29c9cd}\ (ESP) (Fixed) (Total:0.63 GB) (Free:0.56 GB) FAT32 ==================== MBR & Partitionstabelle ==================== ========================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: D348EE5C) Partition: GPT. ==================== Ende von Addition.txt ======================= |
21.04.2021, 12:48 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. Störende, veraltete oder unnötige Programme deinstallieren Bitte über Programme und Features (appwiz.cpl) deinstallieren: Adobe Acrobat Reader DC Google Chrome QScan System-Check
__________________ Logfiles bitte immer in CODE-Tags posten |
21.04.2021, 13:00 | #6 |
| Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. okay Danke, QScan System Check konnte ist deinstallieren, taucht aber weiterhin in der Programmübersicht auf. Beim erneutten Klick auf "deinstallieren" taucht die Meldung auf das die QScan Uninstall.exe nicht mehr gefunden werden kann. Chrome und Acrobat Reader benutze ich gelegentlich. |
21.04.2021, 14:18 | #7 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf.Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.04.2021, 15:23 | #8 |
| Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. nun gut, die beiden sind runter. ich verstehe nur nicht, wie Verlaufseinträge im Firefox mit Chrome oder Reader zusammenhängen können. |
21.04.2021, 20:54 | #9 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf.Zitat:
Das ist aber kein Grund, besch.... Programme wenn man die sieht einfach drauf zu lassen. Übrigens die Überschrift zur Instruktion war nicht aus Spaß so geschrieben: Zitat:
Weiter gehts mit: adwCleaner Führe AdwCleaner gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei in CODE-Tags. adwcleaner zwecks Kontrolle bitte wiederholen, falls es Funde gab.
__________________ Logfiles bitte immer in CODE-Tags posten |
22.04.2021, 15:27 | #10 |
| Adw Cleaner LogdateiCode:
ATTFilter # ------------------------------- # Malwarebytes AdwCleaner 8.2.0.0 # ------------------------------- # Build: 03-22-2021 # Database: 2021-04-20.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 04-22-2021 # Duration: 00:00:02 # OS: Windows 10 Pro # Cleaned: 20 # Awaiting reboot:4 # Failed: 0 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** No malicious folders cleaned. ***** [ Files ] ***** No malicious files cleaned. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\QScan System-Check Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474} ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ***** [ Hosts File Entries ] ***** No malicious hosts file entries cleaned. ***** [ Preinstalled Software ] ***** Deleted Preinstalled.DellCommand|PowerManager Folder C:\Program Files\DELL\COMMANDPOWERMANAGER Deleted Preinstalled.DellCommand|PowerManager Folder C:\ProgramData\DELL\COMMANDPOWERMANAGER Deleted Preinstalled.DellCommand|PowerManager Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{18469ED8-8C36-4CF7-BD43-0FC9B1931AF8} Deleted Preinstalled.DellSupportAssistAgent Folder C:\Program Files\DELL\SAREMEDIATION\AGENT Deleted Preinstalled.DellSupportAssistAgent Folder C:\Program Files\DELL\SAREMEDIATION\AUDIT Deleted Preinstalled.DellSupportAssistAgent Folder C:\ProgramData\DELL\SAREMEDIATION\AGENT Deleted Preinstalled.DellSupportAssistAgent Folder C:\ProgramData\DELL\SAREMEDIATION\PLUGIN Deleted Preinstalled.DellSupportAssistAgent Folder C:\ProgramData\SUPPORTASSIST\CLIENT\TECHNICIANTOOLKIT Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA685515-DE88-445A-A58E-B94B87F042C1} Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA685515-DE88-445A-A58E-B94B87F042C1} Deleted Preinstalled.DellSupportAssistAgent Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dell SupportAssistAgent AutoUpdate Deleted Preinstalled.DellSupportAssistAgent Task C:\Windows\System32\Tasks\DELL SUPPORTASSISTAGENT AUTOUPDATE Deleted Preinstalled.DellUpdateforWindows10 Folder C:\Program Files\DELL\UPDATE Deleted Preinstalled.SmartByte Folder C:\Program Files\RIVET NETWORKS Needs Reboot Preinstalled.DellSupportAssistAgent Folder C:\Program Files\DELL\SAREMEDIATION\PLUGIN Needs Reboot Preinstalled.DellSupportAssistAgent Folder C:\Program Files\DELL\SUPPORTASSISTAGENT Needs Reboot Preinstalled.DellUpdateforWindows10 Folder C:\Program Files (x86)\DELL\UPDATESERVICE Needs Reboot Preinstalled.DellUpdateforWindows10 Folder C:\ProgramData\DELL\UPDATESERVICE ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* ***** Reboot Required to Complete ***** ***** [ Folders ] ***** Cleaning failed C:\Program Files (x86)\DELL\UPDATESERVICE Cleaning failed C:\Program Files\DELL\SAREMEDIATION\PLUGIN Cleaning failed C:\Program Files\DELL\SUPPORTASSISTAGENT Cleaning failed C:\ProgramData\DELL\UPDATESERVICE ************************* AdwCleaner[S00].txt - [3456 octets] - [22/04/2021 16:17:22] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## |
23.04.2021, 19:29 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. Posting richtig gelesen? Was sollst du tun wenn es Funde gab beim adwCleaner?
__________________ Logfiles bitte immer in CODE-Tags posten |
27.04.2021, 08:05 | #12 |
/// TB-Ausbilder | Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. Fehlende Rückmeldung Dieses Thema wurde aus unseren Abos gelöscht. Somit bekommen wir keine Benachrichtigung über neue Antworten. Solltest Du das Thema erneut brauchen, schicke uns bitte eine Erinnerung inklusive Link zum Thema. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und ein eigenes Thema erstellen! |
Themen zu Exsalut.com taucht in meiner Firefox-Chronik seit einiger Zeit regelmäßig auf. |
.com, ausser, bekannte, einiger, einträge, einträgen, freue, heute, hoffnung, immer wieder, keinerlei, laptop, nutze, regelmäßig, taucht, träge, verschiedene, verschiedenen, woche, wochen, wüsste |