|
Alles rund um Windows: Windows 10: Bluescreen in unregelmäßigen abständenWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
14.05.2021, 18:38 | #1 |
| Problem: Windows 10: Bluescreen in unregelmäßigen abständen Hallo zusammen, ich habe nun schon längere Zeit das Problem das ich nach ungewisser Zeit einen Bluescreen bekomme und mein PC wieder neu startet. Ich habe meinen PC über CCleaner die Registries nachschauen lassen und mir fällt auf, das ich folgenden Verweis nicht entfernen kann. localserver32\c:\windows\syswow64\speech_onecore\common\speechruntime.exe -toastnotifier hkcr\clsid\{265b1075-d22b-41eb-bc97-87568f3e6dab} Dieses Problem habe ich schon versucht über eine Neuinstallation von Windows zu beheben, leider ohne Erfolg. Einen Virenscan habe ich noch nicht erstellt. Habe mit dem FRST einen Scan erstellt. FRST-Log: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2021 durchgeführt von belar (Administrator) auf DESKTOP-E8L34PA (HP HP Pavilion Gaming Desktop TG01-1xxx) (14-05-2021 19:12:37) Gestartet von C:\Users\belar\Downloads Geladene Profile: belar Platform: Windows 10 Home Version 20H2 19042.985 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: Opera Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Discord Inc. -> Discord Inc.) C:\Users\belar\AppData\Local\Discord\app-1.0.9001\Discord.exe <6> (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <4> (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\123.3.4805\QtWebEngineProcess.exe <2> (Electronic Arts, Inc. -> ) D:\Origin\QtWebEngineProcess.exe (Electronic Arts, Inc. -> Electronic Arts) D:\Origin\Origin.exe (Electronic Arts, Inc. -> Electronic Arts) D:\Origin\OriginWebHelperService.exe (Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe (Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP Support Framework\Resources\HPUpdate\HPUpdate.exe (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_eb7ea98d07646ece\x64\TouchpointAnalyticsClientService.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_eb7ea98d07646ece\x64\TouchpointGpuInfo.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\AppHelperCap.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\BridgeCommunication.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\DiagsCap.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\NetworkCap.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\SysInfoCap.exe (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_c0309a48bef2b923\x64\OmenCap.exe (HP Inc.) C:\Program Files\WindowsApps\ad2f1837.hpjumpstarts_1.9.1548.0_x64__v10z8vjag6ke6\HP.JumpStarts.exe (HP Inc.) C:\Program Files\WindowsApps\ad2f1837.hpsupportassistant_9.7.290.0_x64__v10z8vjag6ke6\www\HPSFCopy\Resources\HPSAAppLauncher.exe (HP Inc.) C:\Program Files\WindowsApps\ad2f1837.hpsystemeventutility_1.1.21.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe (HP Inc.) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_2ca0a47853f51398\esif_uf.exe (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a031792b512c1a2a\RstMwService.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowsstore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\NisSrv.exe (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a494df49ba2f9f36\Display.NvContainer\NVDisplay.Container.exe <2> (Opera Software AS -> Opera Software) C:\Users\belar\AppData\Local\Programs\Opera\76.0.4017.107\opera.exe <39> (Opera Software AS -> Opera Software) C:\Users\belar\AppData\Local\Programs\Opera\76.0.4017.107\opera_crashreporter.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe <2> (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtAudioServ.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2> (ROCCAT GmbH) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.exe (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (Swift Media Entertainment, Inc. -> Blitz, Inc.) C:\Users\belar\AppData\Local\Programs\Blitz\Blitz.exe <6> (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe (Voicemod Sociedad Limitada -> Voicemod) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_dev_service.exe (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe (WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [471432 2019-12-11] (Express Vpn LLC -> ExpressVPN) HKLM-x32\...\Run: [RoccatIsku] => C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.EXE [536576 2013-10-30] (ROCCAT GmbH) [Datei ist nicht signiert] HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [8172776 2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe [528392 2020-09-04] (HP Inc. -> HP Inc.) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [Opera Browser Assistant] => C:\Users\belar\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4042904 2021-05-06] (Opera Software AS -> Opera Software) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33698888 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [EADM] => D:\Origin\Origin.exe [3144760 2021-05-11] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [com.blitz.app] => C:\Users\belar\AppData\Local\Programs\Blitz\Blitz.exe [109893896 2021-05-12] (Swift Media Entertainment, Inc. -> Blitz, Inc.) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4087528 2021-04-12] (Valve -> Valve Corporation) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [Discord] => C:\Users\belar\AppData\Local\Discord\Update.exe [1512040 2021-03-18] (Discord Inc. -> GitHub) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Run: [Voicemod] => C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe [5790352 2021-04-22] (Voicemod Sociedad Limitada -> Voicemod) HKLM\...\Print\Monitors\PDF-XChange Lite Port Monitor: C:\Windows\system32\pxcpmL.dll [2044248 2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ROCCAT Swarm Monitor.lnk [2021-05-11] ShortcutTarget: ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe (Voyetra Turtle Beach, Inc. -> ROCCAT) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {06AFE5D3-AB50-49D7-AFA3-646077A41017} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {105D676A-D551-4274-81E7-97AC52E4FD87} - \Microsoft\Windows\Speech\HeadsetButtonPress -> Keine Datei <==== ACHTUNG Task: {1949073A-8FDA-4EA4-8E59-407CDB02440F} - \Microsoft\Windows\WindowsUpdate\sihpostreboot -> Keine Datei <==== ACHTUNG Task: {252DEDEF-309E-4C23-8EB6-782284A5FB98} - \Microsoft\Office\OfficeBackgroundTaskHandlerRegistration -> Keine Datei <==== ACHTUNG Task: {25966F87-300B-45CA-97C7-95F862E966A7} - \NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {2670AB17-D9C2-4892-9411-31E195B6D4BD} - System32\Tasks\RtkAudUService64_BG => C:\Windows\System32\RtkAudUService64.exe [1084720 2020-05-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {2764F8D1-C1F5-4C35-AE7E-7DAD04ACC26B} - System32\Tasks\ROCCAT DEVICE SERVICE => C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_dev_service.exe [442888 2021-04-19] (Voyetra Turtle Beach, Inc. -> ROCCAT) Task: {2EA4C67A-62E8-468E-8CCC-766F7FD9A338} - \HPAudioSwitch -> Keine Datei <==== ACHTUNG Task: {2F13B1C1-3D3B-41CF-BBB6-96D46F11E92F} - \Microsoft\Office\Office Feature Updates Logon -> Keine Datei <==== ACHTUNG Task: {375CAE3C-ACF2-4C21-A037-4B52BBAC1BFD} - \Microsoft\Office\Office Automatic Updates 2.0 -> Keine Datei <==== ACHTUNG Task: {40630994-A001-4701-B341-45F9BF46C718} - \Microsoft\Office\OfficeBackgroundTaskHandlerLogon -> Keine Datei <==== ACHTUNG Task: {41AFBE96-AA2C-42D3-8D4B-0B2CEBE9581F} - System32\Tasks\HP\Consent Manager Launcher => sc start hptouchpointanalyticsservice Task: {4F7878E4-EF61-4BED-95E6-1FEE43C9CB55} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-04-22] (Piriform Software Ltd -> Piriform) Task: {50FC7FB8-989A-4104-B8DE-04BC98C1CE47} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {5100A477-348F-48CA-A0F9-BA0C7018AC24} - \OneDrive Standalone Update Task-S-1-5-21-4259826236-3749853712-4035207543-500 -> Keine Datei <==== ACHTUNG Task: {52A4B5A8-F729-4D75-AD99-80BC4A879193} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1139032 2021-03-04] (HP Inc. -> HP Inc.) Task: {54B795D2-F3EA-4260-A914-463E18F49EB6} - \HyperXRamApp -> Keine Datei <==== ACHTUNG Task: {5B4B10C7-9E22-4346-AEFD-FA45657A3AF9} - \NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {6D343E6E-A3D6-4682-B587-67D3194F359A} - \NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {6DB64DF9-179D-4DD0-BB1B-671ACE26F71E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6EE0A99B-D5EE-4F43-AE45-787AA40E243A} - \NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {755BD16F-B7B9-4A33-85C2-6830087EAAD5} - \NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {7579CBE7-E9F9-44A1-9FDC-1B158E34C497} - \Microsoft\Office\Office ClickToRun Service Monitor -> Keine Datei <==== ACHTUNG Task: {7EC2114A-C04B-490C-9434-7F9AC98FA3AE} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2021-05-13] (Dropbox, Inc -> Dropbox, Inc.) Task: {827AACDD-6BC5-44CC-87A8-2C415F1F3436} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28082760 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd) Task: {94C2B8CF-A06E-426D-9FE9-E5C2555E6651} - \NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {A1A9EC49-3668-4F31-BC54-D03FD4D7082A} - System32\Tasks\Opera scheduled Autoupdate 1620756554 => C:\Users\belar\AppData\Local\Programs\Opera\launcher.exe [2199704 2021-05-06] (Opera Software AS -> Opera Software) Task: {A233FC21-13EE-4174-B7EE-5E5B6644B7AB} - \NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {A62D212A-CA0D-4C79-99D9-E005A41BC273} - \NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {AC38800C-44FF-4A44-A463-61ECF79532D2} - \NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {BB72F61E-8145-496D-89E0-FA0557530894} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [555640 2021-04-24] (HP Inc. -> HP Inc.) Task: {C2F14FCA-544B-4D40-BA43-F49F3D428C22} - \Microsoft\Office\Office Feature Updates -> Keine Datei <==== ACHTUNG Task: {C7AE827C-17EB-4B19-9B3C-A1E98DD4D125} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {CBFB6BE6-9828-4121-A91C-8ADE8B6B1C36} - \Microsoft\Windows\Management\Provisioning\PostResetBoot -> Keine Datei <==== ACHTUNG Task: {DA24F8EC-BAFE-4195-97DD-6DE71896021A} - \NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> Keine Datei <==== ACHTUNG Task: {DB2E42F9-D7FF-4768-A676-46DA758F1FD2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [135000 2020-10-02] (HP Inc. -> HP Inc.) Task: {E6D09E2D-E60F-48F3-8055-3E033E239DC9} - System32\Tasks\Opera scheduled assistant Autoupdate 1620756557 => C:\Users\belar\AppData\Local\Programs\Opera\launcher.exe [2199704 2021-05-06] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\belar\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {F066D7D4-C80F-48CC-82A9-71A7AA1E1B71} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2021-05-13] (Dropbox, Inc -> Dropbox, Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{bc4c2879-76ba-4091-9c48-fe677cee6ad0}: [DhcpNameServer] 192.168.0.1 Edge: ======= Edge Profile: C:\Users\belar\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-14] FireFox: ======== FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-429667387-3557466396-1298814767-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-429667387-3557466396-1298814767-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-429667387-3557466396-1298814767-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) Opera: ======= OPR Profile: C:\Users\belar\AppData\Roaming\Opera Software\Opera Stable [2021-05-14] OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} OPR Extension: (Rich Hints Agent) - C:\Users\belar\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-05-11] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11595120 2019-10-08] (Microsoft Corporation -> Microsoft Corporation) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2021-05-13] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2021-05-13] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [44272 2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [438664 2019-12-11] (Express Vpn LLC -> ExpressVPN) R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [891256 2020-07-30] (HP Inc. -> HP Inc.) R2 HPAppHelperCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\AppHelperCap.exe [731152 2021-03-24] (HP Inc. -> HP Inc.) R2 HPDiagsCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\DiagsCap.exe [728608 2021-03-24] (HP Inc. -> HP Inc.) R2 HPNetworkCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\NetworkCap.exe [728608 2021-03-24] (HP Inc. -> HP Inc.) R2 HPOmenCap; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_c0309a48bef2b923\x64\OmenCap.exe [688888 2020-12-23] (HP Inc. -> HP Inc.) R2 HPSysInfoCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\SysInfoCap.exe [729608 2021-03-24] (HP Inc. -> HP Inc.) R2 HpTouchpointAnalyticsService; C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_eb7ea98d07646ece\x64\TouchpointAnalyticsClientService.exe [480280 2021-03-17] (HP Inc. -> HP Inc.) S3 Origin Client Service; D:\Origin\OriginClientService.exe [2546776 2021-05-11] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3486808 2021-05-11] (Electronic Arts, Inc. -> Electronic Arts) R2 RtkBtAudioServ; C:\Windows\RtkBtAudioServ.exe [234064 2020-12-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13103632 2020-09-17] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\NisSrv.exe [2599328 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1642744 2021-03-15] (WildTangent Inc -> ) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MsMpEng.exe [128376 2021-05-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a494df49ba2f9f36\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a494df49ba2f9f36\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [28440 2019-12-11] (ExprsVPN LLC -> ExpressVPN) R3 HPCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1f5602eb8a12ac4c\x64\hpcustomcapdriver.sys [25024 2019-04-17] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.) R3 HPOmenCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_326f2e1d16385daf\x64\hpomencustomcapdriver.sys [23888 2019-05-02] (HP Inc. -> HP Inc.) R3 MpKslb30a4957; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D516103C-720F-43BC-95A4-A6856A6AFBF2}\MpKslDrv.sys [107744 2021-05-14] (Microsoft Windows -> Microsoft Corporation) S3 PHYMEM; c:\ProgramData\HyperXLighting\otipcibus64.sys [17488 2018-08-28] (Ours Technology Inc. -> OTi) R1 rtf64; C:\Windows\system32\DRIVERS\rtf64x64.sys [70560 2018-09-04] (Realtek Semiconductor Corp. -> Realtek) S3 RtkAvrcp; C:\Windows\System32\drivers\RtkAvrcp.sys [96984 2019-05-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation) R3 tapexpressvpn; C:\Windows\System32\drivers\tapexpressvpn.sys [44304 2019-12-11] (ExprsVPN LLC -> The OpenVPN Project) R3 ViGEmBus; C:\Windows\System32\DriverStore\FileRepository\vigembus.inf_amd64_8a927fc43d8a7838\x64\ViGEmBus.sys [82840 2019-04-24] (HP Inc. -> Benjamin Hoeglinger-Stelzer) R3 VOICEMOD_Driver; C:\Windows\system32\drivers\vmdrv.sys [48136 2021-03-03] (Voicemod Sociedad Limitada -> Windows (R) Win 7 DDK provider) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49560 2021-05-14] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [421112 2021-05-14] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-14] (Microsoft Windows -> Microsoft Corporation) U3 aspnet_state; kein ImagePath S3 MpKsl3051b483; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5937076-6019-43C7-B00F-B2A4D2406CA5}\MpKslDrv.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2021-05-14 19:12 - 2021-05-14 19:13 - 000027487 _____ C:\Users\belar\Downloads\FRST.txt 2021-05-14 19:12 - 2021-05-14 19:12 - 000000000 ____D C:\FRST 2021-05-14 19:11 - 2021-05-14 19:11 - 002299392 _____ (Farbar) C:\Users\belar\Downloads\FRST64.exe 2021-05-14 19:01 - 2021-05-14 19:01 - 000000000 ____D C:\Windows\LastGood 2021-05-14 19:00 - 2021-05-14 19:00 - 002965896 _____ (Intel Corporation) C:\Windows\system32\iaStorAfsService.exe 2021-05-14 19:00 - 2021-05-14 19:00 - 001489272 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorAC.sys 2021-05-14 19:00 - 2021-05-14 19:00 - 000219528 _____ (Intel Corporation) C:\Windows\system32\iaStorAfsNative.exe 2021-05-14 19:00 - 2021-05-14 19:00 - 000119688 _____ (Intel Corporation) C:\Windows\system32\Optane.dll 2021-05-14 19:00 - 2021-05-14 19:00 - 000073080 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorAfs.sys 2021-05-14 19:00 - 2021-05-14 19:00 - 000027528 _____ (Intel Corporation) C:\Windows\system32\RstMwEventLogMsg.dll 2021-05-14 19:00 - 2021-05-14 19:00 - 000023432 _____ (Intel Corporation) C:\Windows\system32\OptaneEventLogMsg.dll 2021-05-14 18:58 - 2021-05-14 19:01 - 000000000 ____D C:\hpswsetup 2021-05-14 18:58 - 2021-05-14 18:58 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard 2021-05-14 16:53 - 2021-05-14 16:53 - 000000000 ____D C:\Windows\system32\lxss 2021-05-14 16:53 - 2021-05-14 16:53 - 000000000 ____D C:\Windows\LastGood.Tmp 2021-05-14 16:52 - 2021-04-24 03:08 - 000038640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 001855192 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe 2021-05-14 16:51 - 2021-04-27 23:16 - 001855192 _____ C:\Windows\system32\vulkaninfo.exe 2021-05-14 16:51 - 2021-04-27 23:16 - 001453344 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2021-05-14 16:51 - 2021-04-27 23:16 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2021-05-14 16:51 - 2021-04-27 23:16 - 001192736 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 001094880 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 001094880 _____ C:\Windows\system32\vulkan-1.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll 2021-05-14 16:51 - 2021-04-27 23:16 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1.dll 2021-05-14 16:51 - 2021-04-27 23:13 - 000715544 _____ C:\Windows\system32\nvofapi64.dll 2021-05-14 16:51 - 2021-04-27 23:13 - 000626976 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll 2021-05-14 16:51 - 2021-04-27 23:13 - 000575760 _____ C:\Windows\SysWOW64\nvofapi.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 002106144 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 001590560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 001514784 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 001166112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 000811808 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 000689952 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe 2021-05-14 16:51 - 2021-04-27 23:12 - 000675104 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2021-05-14 16:51 - 2021-04-27 23:12 - 000564000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2021-05-14 16:51 - 2021-04-27 23:11 - 008317232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2021-05-14 16:51 - 2021-04-27 23:11 - 007434032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2021-05-14 16:51 - 2021-04-27 23:11 - 004795152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2021-05-14 16:51 - 2021-04-27 23:11 - 002823472 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2021-05-14 16:51 - 2021-04-27 23:11 - 000445744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe 2021-05-14 16:51 - 2021-04-27 23:10 - 000848664 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe 2021-05-14 16:51 - 2021-04-27 23:09 - 006159176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2021-05-14 16:51 - 2021-04-24 03:08 - 000087164 _____ C:\Windows\system32\nvinfo.pb 2021-05-14 16:49 - 2021-05-14 16:49 - 000000000 ____D C:\Users\belar\AppData\Local\NVIDIA 2021-05-14 16:49 - 2021-05-14 16:49 - 000000000 ____D C:\Users\belar\ansel 2021-05-13 23:03 - 2021-05-13 23:03 - 002755584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2021-05-13 23:03 - 2021-05-13 23:03 - 001687040 _____ C:\Windows\system32\libcrypto.dll 2021-05-13 23:03 - 2021-05-13 23:03 - 000700928 _____ C:\Windows\system32\FsNVSDeviceSource.dll 2021-05-13 23:02 - 2021-05-13 23:02 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2021-05-13 23:02 - 2021-05-13 23:02 - 001823816 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2021-05-13 23:02 - 2021-05-13 23:02 - 001393504 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2021-05-13 23:02 - 2021-05-13 23:02 - 001314120 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi 2021-05-13 23:02 - 2021-05-13 23:02 - 001163776 _____ C:\Windows\system32\MBR2GPT.EXE 2021-05-13 23:02 - 2021-05-13 23:02 - 000165888 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe 2021-05-13 23:02 - 2021-05-13 23:02 - 000060928 _____ C:\Windows\system32\runexehelper.exe 2021-05-13 23:02 - 2021-05-13 23:02 - 000013312 _____ C:\Windows\system32\agentactivationruntimestarter.exe 2021-05-13 23:02 - 2021-05-13 23:02 - 000011351 _____ C:\Windows\system32\DrtmAuthTxt.wim 2021-05-13 22:57 - 2021-05-13 22:57 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-05-13 22:56 - 2021-05-13 22:57 - 000000000 ____D C:\Windows\system32\MRT 2021-05-13 18:26 - 2021-05-14 18:54 - 000000000 ____D C:\ProgramData\Voicemod 2021-05-13 18:26 - 2021-05-14 16:44 - 000000000 ____D C:\Users\belar\AppData\Local\Voicemod 2021-05-13 18:26 - 2021-05-13 18:26 - 068445120 _____ (Voicemod S.L. ) C:\Users\belar\Downloads\VoicemodSetup_2.11.0.2.exe 2021-05-13 18:26 - 2021-05-13 18:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voicemod 2021-05-13 18:26 - 2021-05-13 18:26 - 000000000 ____D C:\Program Files\Voicemod Desktop 2021-05-13 18:26 - 2021-03-03 11:04 - 000048136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\vmdrv.sys 2021-05-13 18:22 - 2021-05-13 18:22 - 000000000 ____D C:\Users\belar\AppData\LocalLow\Adobe 2021-05-13 18:21 - 2021-05-13 18:24 - 000000000 ____D C:\Program Files (x86)\Adobe 2021-05-13 18:21 - 2021-05-13 18:22 - 000000000 ____D C:\ProgramData\Adobe 2021-05-13 18:20 - 2021-05-13 18:22 - 000000000 ____D C:\Users\belar\AppData\Local\Adobe 2021-05-13 17:51 - 2021-05-13 17:51 - 001246416 _____ (Adobe Inc) C:\Users\belar\Downloads\readerdc_de_ha_crd_install.exe 2021-05-13 15:02 - 2021-05-13 15:02 - 000000000 ____D C:\Users\belar\AppData\Local\ElevatedDiagnostics 2021-05-13 14:36 - 2021-05-13 14:36 - 000000000 ____D C:\Users\belar\AppData\Local\HP_Inc 2021-05-13 14:15 - 2021-05-13 15:11 - 000000000 ___RD C:\Users\belar\Dropbox 2021-05-13 14:15 - 2021-05-13 14:15 - 000001306 _____ C:\Users\belar\Desktop\Dropbox.lnk 2021-05-13 14:13 - 2021-05-13 14:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2021-05-13 14:12 - 2021-05-13 14:12 - 000673488 _____ (Dropbox, Inc.) C:\Users\belar\Downloads\DropboxInstaller (1).exe 2021-05-13 14:11 - 2021-05-13 14:11 - 000000000 ____D C:\Users\belar\AppData\Local\cache 2021-05-13 14:10 - 2021-05-14 16:42 - 000001244 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2021-05-13 14:10 - 2021-05-14 16:42 - 000001240 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2021-05-13 14:10 - 2021-05-13 14:16 - 000004304 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineUA 2021-05-13 14:10 - 2021-05-13 14:16 - 000004072 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineCore 2021-05-13 14:10 - 2021-05-13 14:15 - 000000000 ____D C:\Users\belar\AppData\Local\Dropbox 2021-05-13 14:10 - 2021-05-13 14:13 - 000000000 ____D C:\Program Files (x86)\Dropbox 2021-05-13 14:10 - 2021-05-13 14:10 - 000673488 _____ (Dropbox, Inc.) C:\Users\belar\Downloads\DropboxInstaller.exe 2021-05-13 14:10 - 2021-05-13 14:10 - 000000000 ____D C:\Users\belar\AppData\Roaming\Dropbox 2021-05-13 14:10 - 2021-05-13 14:10 - 000000000 ____D C:\ProgramData\Dropbox 2021-05-11 22:09 - 2021-05-11 22:09 - 000000000 ___HD C:\$WinREAgent 2021-05-11 21:02 - 2021-05-11 21:02 - 000000000 ____D C:\Users\belar\Documents\League of Legends 2021-05-11 21:01 - 2021-05-11 21:01 - 000000000 ____D C:\ProgramData\ROCCAT 2021-05-11 20:37 - 2021-05-11 19:42 - 000000000 ___HD C:\system.sav 2021-05-11 20:37 - 2021-05-11 19:42 - 000000000 ____D C:\Program Files\HP 2021-05-11 20:36 - 2021-05-11 20:36 - 000000000 ____D C:\Users\belar\Downloads\isku_54-1.22-1.25-1248-v1 2021-05-11 20:36 - 2021-05-11 19:47 - 000000000 ____D C:\Windows\Panther 2021-05-11 20:35 - 2021-05-11 20:35 - 000003694 _____ C:\Windows\system32\Tasks\ROCCAT DEVICE SERVICE 2021-05-11 20:35 - 2021-05-11 20:35 - 000000000 ____D C:\Users\belar\AppData\Roaming\ROCCAT 2021-05-11 20:34 - 2021-05-11 20:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT 2021-05-11 20:34 - 2021-05-11 20:34 - 000000000 ____D C:\Windows\Firmware 2021-05-11 20:32 - 2021-05-14 19:01 - 000744982 _____ C:\Windows\system32\perfh007.dat 2021-05-11 20:32 - 2021-05-14 19:01 - 000150388 _____ C:\Windows\system32\perfc007.dat 2021-05-11 20:32 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\OpenSSH 2021-05-11 20:32 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\HoloShell 2021-05-11 20:32 - 2021-05-11 20:32 - 000306166 _____ C:\Windows\system32\perfi007.dat 2021-05-11 20:32 - 2021-05-11 20:32 - 000040520 _____ C:\Windows\system32\perfd007.dat 2021-05-11 20:32 - 2021-05-11 20:32 - 000008192 _____ C:\Windows\system32\config\userdiff 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\TextInput 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\sysprep 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\MailContactsCalendarSync 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\FxsTmp 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\de 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\0409 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\MailContactsCalendarSync 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\de 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\0409 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\Setup 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\DigitalLocker 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\addins 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\ProgramData\ssh 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files\Reference Assemblies 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files\MSBuild 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2021-05-11 20:32 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files (x86)\MSBuild 2021-05-11 20:32 - 2021-05-11 19:48 - 000000000 ____D C:\Windows\system32\FxsTmp 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\SysWOW64\winrm 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\SysWOW64\WCN 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\SysWOW64\slmgr 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\winrm 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\WCN 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\slmgr 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2021-05-11 20:32 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\OCR 2021-05-11 20:31 - 2021-05-14 16:51 - 000000000 ____D C:\Users\belar\AppData\Local\NVIDIA Corporation 2021-05-11 20:30 - 2021-05-14 18:58 - 000000000 ___RD C:\Program Files (x86) 2021-05-11 20:30 - 2021-05-14 18:54 - 000000000 ____D C:\Windows\ServiceState 2021-05-11 20:30 - 2021-05-14 18:54 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-05-11 20:30 - 2021-05-14 16:53 - 000000000 ____D C:\Windows\AppReadiness 2021-05-11 20:30 - 2021-05-14 16:53 - 000000000 ____D C:\Program Files\Windows Defender 2021-05-11 20:30 - 2021-05-14 16:46 - 000000000 ___HD C:\Program Files\WindowsApps 2021-05-11 20:30 - 2021-05-14 16:43 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ___RD C:\Windows\PrintDialog 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\SysWOW64\setup 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\SysWOW64\oobe 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\SysWOW64\Dism 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\SystemResources 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\WinMetadata 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\SystemResetPlatform 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\setup 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\oobe 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\system32\Dism 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\Provisioning 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\PolicyDefinitions 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\DiagTrack 2021-05-11 20:30 - 2021-05-13 23:05 - 000000000 ____D C:\Windows\bcastdvr 2021-05-11 20:30 - 2021-05-13 14:14 - 000000000 ____D C:\Windows\appcompat 2021-05-11 20:30 - 2021-05-11 20:37 - 000028672 _____ C:\Windows\system32\config\BCD-Template 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\MUI 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SysWOW64\Com 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\SystemApps 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\Sysprep 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\MUI 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\migwiz 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\system32\Com 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Windows\Help 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files (x86)\Windows NT 2021-05-11 20:30 - 2021-05-11 20:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2021-05-11 20:30 - 2021-05-11 20:30 - 015664374 _____ C:\Users\belar\Downloads\isku_54-1.22-1.25-1248-v1.zip 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 __SHD C:\Program Files\Windows Sidebar 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 __RSD C:\Windows\Media 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 __RHD C:\Users\Public\Libraries 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\SysWOW64\Nui 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\SysWOW64\Configuration 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\system32\UNP 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\system32\Nui 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\system32\Configuration 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___SD C:\Windows\Downloaded Program Files 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___RD C:\Windows\Offline Web Pages 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___HD C:\Windows\LanguageOverlayCache 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ___HD C:\Windows\ELAMBKUP 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Web 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\WaaS 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Vss 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\tracing 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\TAPI 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\SMI 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\ras 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\NDF 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\Msdtc 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\migwiz 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\Keywords 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\Ipmi 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\InputMethod 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\inetsrv 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\IME 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\icsxml 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicyUsers 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\downlevel 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\Bthprops 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\AppLocker 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\winevt 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ti-et 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ta-lk 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ta-in 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\si-lk 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ShellExperiences 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\Sgrm 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\SecureBootUpdates 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ras 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ProximityToast 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\PointOfService 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\osa-Osge-001 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\NDF 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\my-mm 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\Keywords 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\Ipmi 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\InputMethod 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\inetsrv 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\IME 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\icsxml 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ias 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\Hydrogen 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ff-Adlm-SN 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\DriverState 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\downlevel 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\DDFs 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\ContainerSettingsProviders 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\config\TxR 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\config\systemprofile 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\config\RegBack 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\config\Journal 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\Bthprops 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\appraiser 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\AppLocker 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\am-et 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\AdvancedInstallers 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\System 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SKB 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\ShellExperiences 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\ShellComponents 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\security 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\schemas 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\SchCache 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Resources 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\rescache 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Registration 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\PLA 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Performance 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\ModemLogs 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\L2Schemas 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\InputMethod 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\IdentityCRL 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Globalization 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\GameBarPresenceWriter 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Cursors 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Containers 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\Branding 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\ProgramData\USOShared 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files\Windows Security 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files\Windows Portable Devices 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files\Windows Multimedia Platform 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files\ModifiableWindowsApps 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files\Common Files\Services 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices 2021-05-11 20:30 - 2021-05-11 20:30 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2021-05-11 20:30 - 2021-05-11 20:29 - 000215943 _____ C:\Windows\SysWOW64\dssec.dat 2021-05-11 20:30 - 2021-05-11 20:29 - 000215943 _____ C:\Windows\system32\dssec.dat 2021-05-11 20:30 - 2021-05-11 20:29 - 000020908 _____ C:\Windows\system32\OEMDefaultAssociations.xml 2021-05-11 20:30 - 2021-05-11 20:29 - 000003683 _____ C:\Windows\system32\Drivers\etc\lmhosts.sam 2021-05-11 20:30 - 2021-05-11 20:29 - 000003103 _____ C:\Windows\SysWOW64\mmc.exe.config 2021-05-11 20:30 - 2021-05-11 20:29 - 000003103 _____ C:\Windows\system32\mmc.exe.config 2021-05-11 20:30 - 2021-05-11 20:29 - 000000858 _____ C:\Windows\system32\DefaultQuestions.json 2021-05-11 20:30 - 2021-05-11 20:29 - 000000741 _____ C:\Windows\SysWOW64\NOISE.DAT 2021-05-11 20:30 - 2021-05-11 20:29 - 000000741 _____ C:\Windows\system32\NOISE.DAT 2021-05-11 20:30 - 2021-05-11 20:13 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2021-05-11 20:30 - 2021-05-11 19:48 - 000000000 ____D C:\Windows\system32\WinBioDatabase 2021-05-11 20:30 - 2021-05-11 19:48 - 000000000 ____D C:\Windows\system32\spool 2021-05-11 20:30 - 2021-05-11 19:47 - 000000000 ____D C:\ProgramData\USOPrivate 2021-05-11 20:30 - 2021-05-11 19:46 - 000000000 ____D C:\Program Files\Windows NT 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ___SD C:\Windows\SysWOW64\F12 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ___SD C:\Windows\system32\F12 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ___SD C:\Windows\system32\dsc 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ___SD C:\Windows\system32\DiagSvcs 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\WinBioPlugIns 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\system32\PerceptionSimulation 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\LiveKernelReports 2021-05-11 20:30 - 2021-05-11 19:44 - 000000000 ____D C:\Windows\IME 2021-05-11 20:30 - 2021-05-11 19:42 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2021-05-11 20:30 - 2021-05-11 19:42 - 000000000 ____D C:\Program Files\Common Files\System 2021-05-11 20:30 - 2021-05-11 19:42 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2021-05-11 20:30 - 2021-05-11 19:39 - 000000000 ____D C:\Windows\system32\Drivers\DriverData 2021-05-11 20:29 - 2021-05-14 19:01 - 000000000 ____D C:\Windows\INF 2021-05-11 20:27 - 2021-05-13 23:05 - 094109696 _____ C:\Windows\system32\config\SOFTWARE 2021-05-11 20:27 - 2021-05-13 23:05 - 018087936 _____ C:\Windows\system32\config\SYSTEM 2021-05-11 20:27 - 2021-05-13 23:05 - 000786432 _____ C:\Windows\system32\config\DEFAULT 2021-05-11 20:27 - 2021-05-13 23:05 - 000524288 _____ C:\Windows\system32\config\BBI 2021-05-11 20:27 - 2021-05-13 23:05 - 000131072 _____ C:\Windows\system32\config\SAM 2021-05-11 20:27 - 2021-05-13 23:05 - 000032768 _____ C:\Windows\system32\config\SECURITY 2021-05-11 20:27 - 2021-05-13 23:04 - 000000000 ____D C:\Windows\servicing 2021-05-11 20:27 - 2021-05-13 23:04 - 000000000 ____D C:\Windows\CbsTemp 2021-05-11 20:27 - 2021-05-11 20:34 - 000032768 _____ C:\Windows\system32\config\ELAM 2021-05-11 20:27 - 2021-05-11 20:30 - 000000000 ____D C:\Windows\system32\SMI 2021-05-11 20:26 - 2021-05-11 20:39 - 000000000 ___HD C:\$SysReset 2021-05-11 20:24 - 2021-05-14 18:55 - 000000000 ____D C:\Users\belar\AppData\Roaming\discord 2021-05-11 20:24 - 2021-05-14 18:54 - 000000000 ____D C:\Users\belar\AppData\Local\Discord 2021-05-11 20:24 - 2021-05-13 23:04 - 000000000 ____D C:\Users\belar\AppData\Roaming\Factorio 2021-05-11 20:24 - 2021-05-11 20:24 - 000002236 _____ C:\Users\belar\Desktop\Discord.lnk 2021-05-11 20:24 - 2021-05-11 20:24 - 000000000 ____D C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2021-05-11 20:24 - 2021-05-11 20:24 - 000000000 ____D C:\Users\belar\AppData\Local\SquirrelTemp 2021-05-11 20:23 - 2021-05-11 20:23 - 070939752 _____ (Discord Inc.) C:\Users\belar\Downloads\DiscordSetup.exe 2021-05-11 20:21 - 2021-05-14 18:54 - 000000000 ____D C:\Program Files (x86)\Steam 2021-05-11 20:21 - 2021-05-11 20:21 - 000001039 _____ C:\Users\Public\Desktop\Steam.lnk 2021-05-11 20:21 - 2021-05-11 20:21 - 000001039 _____ C:\ProgramData\Desktop\Steam.lnk 2021-05-11 20:21 - 2021-05-11 20:21 - 000000000 ____D C:\Users\belar\AppData\Local\Steam 2021-05-11 20:21 - 2021-05-11 20:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2021-05-11 20:20 - 2021-05-14 18:54 - 000000000 ____D C:\ProgramData\Riot Games 2021-05-11 20:20 - 2021-05-11 21:02 - 000000000 ____D C:\Users\belar\AppData\Local\Riot Games 2021-05-11 20:20 - 2021-05-11 20:21 - 000001681 _____ C:\Users\Public\Desktop\League of Legends.lnk 2021-05-11 20:20 - 2021-05-11 20:21 - 000001681 _____ C:\ProgramData\Desktop\League of Legends.lnk 2021-05-11 20:20 - 2021-05-11 20:20 - 000000000 ____D C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games 2021-05-11 20:20 - 2021-05-11 20:20 - 000000000 ____D C:\Users\belar\AppData\Local\CEF 2021-05-11 20:20 - 2021-05-11 20:20 - 000000000 ____D C:\Riot Games 2021-05-11 20:20 - 2021-05-11 20:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games 2021-05-11 20:19 - 2021-05-11 20:19 - 069746200 _____ (Riot Games, Inc.) C:\Users\belar\Downloads\Install League of Legends euw.exe 2021-05-11 20:19 - 2021-05-11 20:19 - 001770744 _____ C:\Users\belar\Downloads\SteamSetup.exe 2021-05-11 20:18 - 2021-05-13 14:50 - 000000000 ____D C:\Users\belar\AppData\Local\HP 2021-05-11 20:18 - 2021-05-11 20:18 - 000000000 ____D C:\Windows\system32\Tasks\Hewlett-Packard 2021-05-11 20:18 - 2021-05-11 20:18 - 000000000 ____D C:\Users\belar\AppData\Roaming\Hewlett-Packard 2021-05-11 20:18 - 2021-05-11 20:18 - 000000000 ____D C:\Users\belar\AppData\Local\Comms 2021-05-11 20:16 - 2021-05-14 18:55 - 000000000 ____D C:\Users\belar\AppData\Roaming\Blitz 2021-05-11 20:16 - 2021-05-11 20:16 - 000002252 _____ C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blitz.lnk 2021-05-11 20:16 - 2021-05-11 20:16 - 000002244 _____ C:\Users\belar\Desktop\Blitz.lnk 2021-05-11 20:16 - 2021-05-11 20:16 - 000000000 ____D C:\Users\belar\AppData\Local\blitz-updater 2021-05-11 20:15 - 2021-05-11 20:15 - 000000579 _____ C:\Users\Public\Desktop\Origin.lnk 2021-05-11 20:15 - 2021-05-11 20:15 - 000000579 _____ C:\ProgramData\Desktop\Origin.lnk 2021-05-11 20:15 - 2021-05-11 20:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2021-05-11 20:15 - 2021-05-11 20:15 - 000000000 ____D C:\ProgramData\Electronic Arts 2021-05-11 20:14 - 2021-05-14 18:54 - 000000000 ____D C:\Users\belar\AppData\Local\Origin 2021-05-11 20:14 - 2021-05-14 18:54 - 000000000 ____D C:\ProgramData\Origin 2021-05-11 20:14 - 2021-05-11 20:15 - 000000000 ____D C:\Users\belar\AppData\Roaming\Origin 2021-05-11 20:14 - 2021-05-11 20:14 - 000000000 ____D C:\Users\belar\.QtWebEngineProcess 2021-05-11 20:14 - 2021-05-11 20:14 - 000000000 ____D C:\Users\belar\.Origin 2021-05-11 20:12 - 2021-05-11 20:36 - 000000000 ____D C:\Program Files (x86)\ROCCAT 2021-05-11 20:12 - 2021-05-11 20:12 - 000000000 ____D C:\Users\belar\AppData\Roaming\WinRAR 2021-05-11 20:10 - 2021-05-14 18:58 - 000000000 ____D C:\Program Files\CCleaner 2021-05-11 20:10 - 2021-05-11 20:10 - 031412280 _____ (Piriform Software Ltd) C:\Users\belar\Downloads\ccsetup579.exe 2021-05-11 20:10 - 2021-05-11 20:10 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update 2021-05-11 20:10 - 2021-05-11 20:10 - 000002888 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC 2021-05-11 20:10 - 2021-05-11 20:10 - 000000870 _____ C:\Users\Public\Desktop\CCleaner.lnk 2021-05-11 20:10 - 2021-05-11 20:10 - 000000870 _____ C:\ProgramData\Desktop\CCleaner.lnk 2021-05-11 20:10 - 2021-05-11 20:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2021-05-11 20:09 - 2021-05-11 20:09 - 000004460 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1620756557 2021-05-11 20:09 - 2021-05-11 20:09 - 000004228 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1620756554 2021-05-11 20:09 - 2021-05-11 20:09 - 000001416 _____ C:\Users\belar\Desktop\Opera-Browser.lnk 2021-05-11 20:09 - 2021-05-11 20:09 - 000001406 _____ C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk 2021-05-11 20:09 - 2021-05-11 20:09 - 000000000 ____D C:\Users\belar\AppData\Roaming\Opera Software 2021-05-11 20:09 - 2021-05-11 20:09 - 000000000 ____D C:\Users\belar\AppData\Local\Opera Software 2021-05-11 20:08 - 2021-05-11 20:08 - 000001122 _____ C:\Users\Public\Desktop\PDF-XChange Editor.lnk 2021-05-11 20:08 - 2021-05-11 20:08 - 000001122 _____ C:\ProgramData\Desktop\PDF-XChange Editor.lnk 2021-05-11 20:08 - 2021-05-11 20:08 - 000000000 ____D C:\Users\belar\AppData\Roaming\Tracker Software 2021-05-11 20:08 - 2021-05-11 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software 2021-05-11 20:08 - 2021-05-11 20:08 - 000000000 ____D C:\ProgramData\FileOpen 2021-05-11 20:08 - 2021-05-11 20:08 - 000000000 ____D C:\Program Files\Tracker Software 2021-05-11 20:08 - 2021-05-11 20:08 - 000000000 ____D C:\Program Files\Common Files\Tracker Software 2021-05-11 20:08 - 2021-01-14 11:51 - 002044248 _____ (Tracker Software Products (Canada) Ltd.) C:\Windows\system32\pxcpmL.dll 2021-05-11 20:06 - 2021-05-14 18:54 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2021-05-11 20:06 - 2021-05-11 20:06 - 000001119 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk 2021-05-11 20:06 - 2021-05-11 20:06 - 000001107 _____ C:\Users\Public\Desktop\TeamViewer.lnk 2021-05-11 20:06 - 2021-05-11 20:06 - 000001107 _____ C:\ProgramData\Desktop\TeamViewer.lnk 2021-05-11 20:06 - 2021-05-11 20:06 - 000000000 ____D C:\Users\belar\AppData\Roaming\TeamViewer 2021-05-11 20:06 - 2021-05-11 20:06 - 000000000 ____D C:\Users\belar\AppData\Local\TeamViewer 2021-05-11 20:05 - 2021-05-11 20:05 - 000000000 ____D C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2021-05-11 20:05 - 2021-05-11 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2021-05-11 20:05 - 2021-05-11 20:05 - 000000000 ____D C:\Program Files\WinRAR 2021-05-11 20:03 - 2021-05-11 20:31 - 000000000 ___RD C:\Users\belar\OneDrive 2021-05-11 20:03 - 2021-05-11 20:31 - 000000000 ____D C:\Users\belar\AppData\Roaming\HP 2021-05-11 20:03 - 2021-05-11 20:19 - 000000000 ____D C:\Users\belar\AppData\Local\PlaceholderTileLogoFolder 2021-05-11 20:03 - 2021-05-11 20:03 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-429667387-3557466396-1298814767-1001 2021-05-11 20:03 - 2021-05-11 20:03 - 000000000 ___HD C:\OneDriveTemp 2021-05-11 20:03 - 2021-05-11 20:03 - 000000000 ____D C:\Users\belar\AppData\Local\ExpressVPN 2021-05-11 20:03 - 2021-05-11 20:03 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2021-05-11 20:02 - 2021-05-11 20:18 - 000000000 ____D C:\Users\belar\AppData\Local\Publishers 2021-05-11 20:01 - 2021-05-14 18:58 - 000000000 ____D C:\Windows\system32\Tasks\HP 2021-05-11 20:01 - 2021-05-14 16:51 - 000000000 ____D C:\Users\belar\AppData\Local\D3DSCache 2021-05-11 20:01 - 2021-05-13 18:22 - 000000000 ____D C:\Users\belar\AppData\Roaming\Adobe 2021-05-11 20:01 - 2021-05-11 21:01 - 000000000 ____D C:\Users\belar\AppData\Local\VirtualStore 2021-05-11 20:01 - 2021-05-11 20:30 - 000000000 ____D C:\Users\belar\AppData\Local\ConnectedDevicesPlatform 2021-05-11 20:01 - 2021-05-11 20:01 - 000000000 ___RD C:\Users\belar\3D Objects 2021-05-11 20:01 - 2021-05-11 20:01 - 000000000 ____D C:\Users\belar\AppData\Local\SoundResearch 2021-05-11 19:59 - 2021-05-14 18:54 - 000000000 ____D C:\Users\belar 2021-05-11 19:59 - 2021-05-13 18:22 - 000000000 ____D C:\Users\belar\AppData\Local\Packages 2021-05-11 19:59 - 2021-05-11 20:03 - 000002386 _____ C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-05-11 19:59 - 2021-05-11 19:59 - 000000020 ___SH C:\Users\belar\ntuser.ini 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Vorlagen 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Startmenü 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Netzwerkumgebung 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Lokale Einstellungen 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Eigene Dateien 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Druckumgebung 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Documents\Eigene Videos 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Documents\Eigene Musik 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Documents\Eigene Bilder 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\AppData\Local\Verlauf 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\AppData\Local\Anwendungsdaten 2021-05-11 19:59 - 2021-05-11 19:59 - 000000000 _SHDL C:\Users\belar\Anwendungsdaten 2021-05-11 19:59 - 2021-05-11 19:41 - 000000000 ____D C:\Users\belar\AppData\Roaming\WildTangent 2021-05-11 19:50 - 2021-05-14 19:01 - 001722992 _____ C:\Windows\system32\PerfStringBackup.INI 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Vorlagen 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Startmenü 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Netzwerkumgebung 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Lokale Einstellungen 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Eigene Dateien 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Druckumgebung 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default\Anwendungsdaten 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\Default User 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Users\All Users 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Programme 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\ProgramData\Vorlagen 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\ProgramData\Startmenü 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\ProgramData\Dokumente 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien 2021-05-11 19:46 - 2021-05-11 19:46 - 000000000 _SHDL C:\Dokumente und Einstellungen 2021-05-11 19:39 - 2021-05-14 18:54 - 000008192 ___SH C:\DumpStack.log.tmp 2021-05-11 19:39 - 2021-05-14 18:54 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2021-05-11 19:39 - 2021-05-14 18:54 - 000000000 ____D C:\Windows\system32\SleepStudy 2021-05-11 19:39 - 2021-05-14 16:53 - 000000000 ____D C:\Windows\system32\Drivers\wd 2021-05-11 19:39 - 2021-05-14 16:53 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation 2021-05-11 19:39 - 2021-05-14 16:51 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2021-05-11 19:39 - 2021-05-14 16:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-05-11 19:39 - 2021-05-14 16:46 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-05-11 19:39 - 2021-05-14 16:46 - 000002281 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk 2021-05-11 19:39 - 2021-05-14 16:42 - 000541856 _____ C:\Windows\system32\FNTCACHE.DAT 2021-05-11 19:39 - 2021-05-11 19:45 - 000000000 ____D C:\ProgramData\Realtek 2021-05-11 19:39 - 2021-05-11 19:42 - 000000000 ____D C:\ProgramData\HP 2021-05-11 19:39 - 2021-05-11 19:42 - 000000000 ____D C:\Intel 2021-05-11 19:39 - 2021-05-11 19:40 - 000003700 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-05-11 19:39 - 2021-05-11 19:40 - 000003576 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-05-11 19:39 - 2021-05-11 19:39 - 000003228 _____ C:\Windows\system32\Tasks\RtkAudUService64_BG 2021-05-11 19:39 - 2021-05-11 19:39 - 000000000 ____D C:\Windows\system32\Tasks\Intel 2021-05-11 19:39 - 2021-05-11 19:39 - 000000000 ____D C:\Windows\ServiceProfiles 2021-05-11 18:58 - 2021-04-27 23:12 - 000656160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2021-05-11 18:58 - 2021-04-27 23:09 - 007212232 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2021-05-11 18:58 - 2020-10-07 13:34 - 000816368 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll 2021-05-11 18:58 - 2020-10-07 13:32 - 005519600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2021-05-08 20:48 - 2021-05-08 20:48 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2021-05-08 20:48 - 2021-05-08 20:48 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2021-05-08 20:48 - 2021-05-08 20:48 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2021-05-08 20:48 - 2021-05-08 20:48 - 000044272 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2021-05-06 07:39 - 2021-04-24 03:08 - 000135408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2021-04-22 20:51 - 2021-04-22 20:50 - 000067456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys 2021-04-14 22:17 - 2021-04-14 22:17 - 000231248 _____ C:\Windows\system32\containerdevicemanagement.dll 2021-04-14 22:10 - 2018-10-16 22:57 - 000131744 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaLPSS2_GPIO2.sys 2021-04-14 22:05 - 2021-03-15 12:28 - 000044984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvswcfilter.sys ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2021-05-14 19:01 - 2020-12-07 00:37 - 011766248 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlane.sys 2021-05-14 18:59 - 2020-06-16 07:50 - 000000000 ____D C:\Program Files (x86)\REALTEK 2021-05-14 18:59 - 2020-06-16 07:19 - 000000000 ____D C:\Program Files\HPCommRecovery 2021-05-14 18:58 - 2020-06-16 07:57 - 000000000 ____D C:\Windows\HP 2021-05-14 18:56 - 2020-06-16 07:50 - 000000000 ____D C:\ProgramData\NVIDIA 2021-05-11 20:36 - 2020-06-16 07:19 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2021-05-11 20:19 - 2020-06-16 07:49 - 000000000 ____D C:\ProgramData\Packages 2021-05-11 20:18 - 2020-06-16 07:47 - 000000000 ____D C:\ProgramData\Hewlett-Packard 2021-05-11 20:14 - 2020-06-16 07:48 - 000000000 ____D C:\ProgramData\Package Cache 2021-05-11 20:03 - 2019-04-15 17:39 - 000000000 __RHD C:\Users\Public\AccountPictures 2021-05-11 19:47 - 2020-06-16 07:56 - 000000000 ____D C:\ProgramData\WildTangent 2021-05-11 19:46 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\Tasks_Migrated 2021-05-11 19:44 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2021-05-11 19:44 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\Macromed 2021-05-11 19:42 - 2020-06-16 08:01 - 000000000 ____D C:\ProgramData\McInstTemp0157371592287275 2021-05-11 19:42 - 2020-06-16 07:58 - 000000000 ____D C:\ProgramData\HyperXLighting 2021-05-11 19:42 - 2020-06-16 07:58 - 000000000 ____D C:\Program Files (x86)\Intel 2021-05-11 19:42 - 2020-06-16 07:57 - 000000000 ____D C:\ProgramData\ExpressVPN 2021-05-11 19:42 - 2020-06-16 07:57 - 000000000 ____D C:\Program Files (x86)\WildGames 2021-05-11 19:42 - 2020-06-16 07:57 - 000000000 ____D C:\Program Files (x86)\ExpressVPN 2021-05-11 19:42 - 2020-06-16 07:56 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games 2021-05-11 19:42 - 2020-06-16 07:56 - 000000000 ____D C:\Program Files (x86)\WildTangent Games 2021-05-11 19:42 - 2020-06-16 07:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2021-05-11 19:42 - 2020-06-16 07:49 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2021-05-11 19:42 - 2020-06-16 07:49 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2021-05-11 19:42 - 2020-06-16 07:48 - 000000000 ____D C:\Program Files\Intel 2021-05-11 19:42 - 2020-06-16 07:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2021-05-11 19:42 - 2020-06-16 07:21 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2021-05-11 19:42 - 2020-06-16 07:20 - 000000000 ____D C:\Program Files\Microsoft Office 15 2021-05-11 19:42 - 2020-06-16 07:20 - 000000000 ____D C:\Program Files\Microsoft Office 2021-05-11 19:42 - 2020-06-16 07:19 - 000000000 ___RD C:\Program Files\Online Services 2021-05-11 19:42 - 2020-06-16 07:19 - 000000000 ___RD C:\Program Files (x86)\Online Services 2021-05-11 19:42 - 2020-06-16 07:18 - 000000000 ____D C:\Program Files (x86)\HP 2021-05-11 19:42 - 2019-12-17 21:06 - 000000000 ___HD C:\hp 2021-05-11 19:42 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\MsDtc 2021-05-11 19:41 - 2020-06-16 07:56 - 000000000 ____D C:\Users\Default\AppData\Roaming\WildTangent 2021-05-11 19:41 - 2020-06-16 07:56 - 000000000 ____D C:\Users\Default\AppData\Local\Packages ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== |
14.05.2021, 18:39 | #2 |
| Windows 10: Bluescreen in unregelmäßigen abständen Anleitung / Hilfe Hier noch die beiden anderen Logs da sie im ersten Beitrag leider keinen Platz gefunden haben.
__________________Addition-Log: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 14-05-2021 durchgeführt von belar (14-05-2021 19:14:24) Gestartet von C:\Users\belar\Downloads Windows 10 Home Version 20H2 19042.985 (X64) (2021-05-11 17:47:12) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-429667387-3557466396-1298814767-500 - Administrator - Disabled) belar (S-1-5-21-429667387-3557466396-1298814767-1001 - Administrator - Enabled) => C:\Users\belar DefaultAccount (S-1-5-21-429667387-3557466396-1298814767-503 - Limited - Disabled) Gast (S-1-5-21-429667387-3557466396-1298814767-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-429667387-3557466396-1298814767-504 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Blitz 1.14.13 (HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\153f8ce0-b97a-575b-ba12-4ff8b1481894) (Version: 1.14.13 - Blitz, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.79 - Piriform) Discord (HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Discord) (Version: 1.0.9001 - Discord Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 123.3.4805 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.463.1 - Dropbox, Inc.) Hidden ExpressVPN (HKLM-x32\...\{6fecf3aa-1a9a-4e75-aa73-9ffc33b1f046}) (Version: 7.7.12.4 - ExpressVPN) ExpressVPN (HKLM-x32\...\{E5B9C3E5-889C-4F22-A959-F4B8463D3835}) (Version: 7.7.12.4 - ExpressVPN) Hidden HP Audio Switch (HKLM-x32\...\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.) HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.19.0 - HP) HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.) Intel XTU SDK (HKLM-x32\...\{43A58350-CB99-4F4E-9BB6-F058D7B27985}) (Version: 1.0.15 - HP Inc.) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{b666e502-9089-483b-9816-0774ccc9cb61}) (Version: 10.1.18295.8201 - Intel(R) Corporation) Intel(R) Dynamic Tuning (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.7.10200.12510 - Intel Corporation) League of Legends (HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 90.0.818.62 - Microsoft Corporation) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.11929.20394 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.11929.20394 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\OneDriveSetup.exe) (Version: 21.073.0411.0002 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{A0E1B43D-5F4A-46AF-9925-ABA3423325DC}) (Version: 2.77.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.28.29325 (HKLM-x32\...\{33628a12-6787-4b9f-95a1-92449f69fae0}) (Version: 14.28.29325.2 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29325 (HKLM-x32\...\{d7a6435f-ac9a-4af6-8fdc-ca130d13fac9}) (Version: 14.28.29325.2 - Microsoft Corporation) NVIDIA GeForce Experience 3.20.0.118 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.0.118 - NVIDIA Corporation) NVIDIA Grafiktreiber 466.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 466.27 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.38.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.40 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) NVIDIA USBC Driver 1.46.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.46.831.832 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20394 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20394 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0407-1000-0000000FF1CE}) (Version: 16.0.11929.20394 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.11929.20394 - Microsoft Corporation) Hidden Opera Stable 76.0.4017.107 (HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\Opera 76.0.4017.107) (Version: 76.0.4017.107 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.5.98.47688 - Electronic Arts, Inc.) PDF-XChange Editor (HKLM\...\{0CB9427E-F0C4-4A7F-A43C-A09A46027A54}) (Version: 9.0.350.0 - Tracker Software Products (Canada) Ltd.) REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1.0.0.106 - REALTEK Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.36.701.2019 - Realtek) ROCCAT Isku Keyboard Driver (HKLM-x32\...\{4ABAF918-A6BD-43D8-AE0B-5292034B14CB}) (Version: - Roccat GmbH) ROCCAT Swarm (HKLM-x32\...\{9D12397F-45AF-4517-B492-1D1E2FA475EE}) (Version: 1.93.890 - ROCCAT GmbH) Hidden ROCCAT Swarm (HKLM-x32\...\InstallShield_{9D12397F-45AF-4517-B492-1D1E2FA475EE}) (Version: 1.93.890 - ROCCAT GmbH) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.10.5 - TeamViewer) Voicemod (HKLM\...\{8435A407-F778-4647-9CDB-46E5EC50BAD0}_is1) (Version: 2.11.0.2 - Voicemod S.L.) WildTangent Helper (HKLM-x32\...\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}) (Version: 1.0.0.437 - WildTangent) Hidden WildTangent ShortcutProvider (HKLM-x32\...\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}) (Version: 7.0.0.402 - WildTangent) Hidden WildTangent-Spiele (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.1.1.47 - WildTangent) WinRAR 6.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH) Packages: ========= Amazon -> C:\Program Files\WindowsApps\Amazon.com.Amazon_2018.519.2815.0_x64__343d40qqvtj1t [2021-05-11] (Amazon.com) Booking.com EMEA: Big savings on hotels in 96,000 destinations worldwide -> C:\Program Files\WindowsApps\PricelinePartnerNetwork.Booking.comEMEABigsavingso_2.0.5.0_x64__mgae2k3ys4ra0 [2021-05-11] (Priceline Partner Network) Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_1.2.0.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP Audio Center -> C:\Program Files\WindowsApps\AD2F1837.HPAudioCenter_1.11.218.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.9.1548.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\ad2f1837.hppchardwarediagnosticswindows_1.6.8.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.0.42.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_127.1.115.0_x64__v10z8vjag6ke6 [2021-05-13] (HP Inc.) HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.7.290.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) HP System Event Utility -> C:\Program Files\WindowsApps\ad2f1837.hpsystemeventutility_1.1.21.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1015.0_x64__8j3eq9eme6ctt [2021-05-11] (INTEL CORP) McAfee® Personal Security -> C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.60.0_x64__wafk5atnkzcwy [2021-05-11] (McAfee LLC.) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.5060.0_x64__8wekyb3d8bbwe [2021-05-13] (Microsoft Studios) [MS Ad] Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2021-05-11] (Netflix, Inc.) NVIDIA Control Panel -> C:\Program Files\WindowsApps\nvidiacorp.nvidiacontrolpanel_8.1.960.0_x64__56jybvy8sckqj [2021-05-14] (NVIDIA Corp.) OMEN Gaming Hub -> C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6 [2021-05-11] (HP Inc.) [Startup Task] Solitär -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_7.2.5.0_x64__kx24dqmazqk8j [2021-05-11] (Random Salad Games LLC) Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0 [2021-05-11] (Spotify AB) [Startup Task] WildTangent Games -> C:\Program Files\WindowsApps\WildTangentGames.63435CFB65F55_2.0.84.0_x64__qt5r5pa5dyg8m [2021-05-11] (WildTangent Games) XING -> C:\Program Files\WindowsApps\XINGAG.XING_4.0.8.0_x86__xpfg3f7e9an52 [2021-05-11] (New Work SE) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-429667387-3557466396-1298814767-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\belar\Dropbox [2021-05-13 14:15] ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Windows\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_21802104c9b3e45d\OptaneShellExt.dll [2021-05-14] (Intel(R) Rapid Storage Technology -> ) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [PDFXChange Editor Context menu] -> {2ACD35AB-F74A-4C20-AA9B-2DE80081626D} => C:\Program Files\Tracker Software\Shell Extensions\XCShellMenu.x64.dll [2021-01-14] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Windows\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_21802104c9b3e45d\OptaneShellExt.dll [2021-05-14] (Intel(R) Rapid Storage Technology -> ) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-08] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a494df49ba2f9f36\nvshext.dll [2021-04-27] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Nicht auf der Ausnahmeliste) ==================== ==================== Verknüpfungen & WMI ======================== ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============= 2021-05-13 18:26 - 2019-05-03 11:41 - 001750016 _____ () [Datei ist nicht signiert] [Datei wird verwendet] C:\Program Files\Voicemod Desktop\CefSharp.Core.dll 2021-05-11 20:16 - 2021-05-12 14:23 - 000415232 _____ () [Datei ist nicht signiert] \\?\C:\Users\belar\AppData\Local\Programs\Blitz\resources\app.asar.unpacked\node_modules\leveldown\prebuilds\win32-ia32\node.napi.node 2021-05-11 20:36 - 2010-11-04 11:48 - 000061440 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\Isku Keyboard\hiddriver.dll 2020-12-11 18:03 - 2021-04-09 06:06 - 000643584 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\aimo.dll 2015-12-29 06:25 - 2015-12-29 00:25 - 000120334 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\libgcc_s_dw2-1.dll 2015-12-29 06:25 - 2015-12-29 00:25 - 001540622 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\libstdc++-6.dll 2020-11-30 13:59 - 2020-11-30 07:59 - 007523840 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\resource.dll 2021-05-13 18:26 - 2019-04-25 10:23 - 109914112 _____ () [Datei ist nicht signiert] C:\Program Files\Voicemod Desktop\libcef.dll 2021-05-11 20:16 - 2021-05-12 14:23 - 002662912 _____ () [Datei ist nicht signiert] C:\Users\belar\AppData\Local\Programs\Blitz\ffmpeg.dll 2021-05-11 20:16 - 2021-05-12 14:23 - 000367104 _____ () [Datei ist nicht signiert] C:\Users\belar\AppData\Local\Programs\Blitz\libegl.dll 2021-05-11 20:16 - 2021-05-12 14:23 - 006631936 _____ () [Datei ist nicht signiert] C:\Users\belar\AppData\Local\Programs\Blitz\libglesv2.dll 2021-05-13 14:59 - 2021-05-13 14:59 - 000138240 _____ () [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\ecef5c0b3dc7256c00a55105e31c2f9d\Interop.IWshRuntimeLibrary.ni.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000015360 _____ () [Datei ist nicht signiert] D:\Origin\libEGL.DLL 2021-05-11 20:15 - 2021-05-11 20:15 - 003090944 _____ () [Datei ist nicht signiert] D:\Origin\libGLESv2.dll 2021-05-13 14:58 - 2021-05-13 14:58 - 000134656 _____ (hardcodet.net) [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\4fcac439055613daff799732addf1556\Hardcodet.Wpf.TaskbarNotification.ni.dll 2020-08-23 00:33 - 2020-08-30 23:56 - 000014336 _____ (HP Inc.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ad2f1837.hpsystemeventutility_1.1.21.0_x64__v10z8vjag6ke6\SystemEventUtility\NativeRpcClient.DLL 2021-04-18 20:16 - 2021-04-18 20:17 - 006968832 _____ (HP Inc.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\OmenCommandCenterApp_UWP.dll 2020-09-27 11:17 - 2020-09-27 11:17 - 000014848 _____ (HP Inc.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\NativeRpcClient.DLL 2021-05-13 14:59 - 2021-05-13 14:59 - 001701888 _____ (Mark Heath & Contributors) [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_32\NAudio\78d1e372b19da81dc04e35855b17fc28\NAudio.ni.dll 2015-12-29 06:25 - 2015-12-29 00:25 - 000079360 _____ (MingW-W64 Project. All rights reserved.) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\libwinpthread-1.dll 2021-05-13 14:59 - 2021-05-13 14:59 - 003060736 _____ (Newtonsoft) [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\e5e20eaa3bfed45a3478e203cc62209b\Newtonsoft.Json.ni.dll 2021-05-13 18:26 - 2019-06-08 16:53 - 001625088 _____ (Robert Simpson, et al.) [Datei ist nicht signiert] C:\Program Files\Voicemod Desktop\SQLite.Interop.dll 2020-08-23 00:33 - 2020-08-30 23:57 - 001662976 _____ (Robert Simpson, et al.) [Datei ist nicht signiert] C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\SQLite.Interop.dll 2021-05-13 14:59 - 2021-05-13 14:59 - 000793088 _____ (The Apache Software Foundation) [Datei ist nicht signiert] C:\Windows\assembly\NativeImages_v4.0.30319_32\log4net\99ce6136aae3bc57a1c49add2632a650\log4net.ni.dll 2021-05-13 18:26 - 2019-04-25 10:22 - 000799744 _____ (The Chromium Authors) [Datei ist nicht signiert] C:\Program Files\Voicemod Desktop\chrome_elf.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000002560 _____ (The ICU Project) [Datei ist nicht signiert] D:\Origin\icudt58.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 001252864 _____ (The ICU Project) [Datei ist nicht signiert] D:\Origin\icuuc58.dll 2015-12-29 06:52 - 2015-12-29 00:52 - 002177536 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\LIBEAY32.dll 2015-12-29 06:52 - 2015-12-29 00:52 - 000462336 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ssleay32.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Origin\LIBEAY32.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Origin\ssleay32.dll 2016-06-11 02:15 - 2016-06-10 20:15 - 000058880 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qdds.dll 2016-06-10 15:32 - 2016-06-10 09:32 - 000033792 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qgif.dll 2016-06-11 02:15 - 2016-06-10 20:15 - 000046592 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qicns.dll 2016-06-10 15:33 - 2016-06-10 09:33 - 000036352 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qico.dll 2016-06-10 15:32 - 2016-06-10 09:32 - 000258560 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qjpeg.dll 2016-06-11 01:51 - 2016-06-10 19:51 - 000028672 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qsvg.dll 2016-06-11 02:15 - 2016-06-10 20:15 - 000028672 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qtga.dll 2016-06-11 02:15 - 2016-06-10 20:15 - 000495616 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qtiff.dll 2016-06-11 02:15 - 2016-06-10 20:15 - 000027648 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qwbmp.dll 2016-06-11 02:16 - 2016-06-10 20:16 - 000416768 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\imageformats\qwebp.dll 2016-06-13 03:38 - 2016-06-12 21:38 - 000317440 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\mediaservice\dsengine.dll 2016-06-10 15:34 - 2016-06-10 09:34 - 001489920 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\platforms\qwindows.dll 2020-01-13 09:29 - 2020-01-13 03:29 - 005384704 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Core.dll 2016-06-10 15:23 - 2016-06-10 09:23 - 005283840 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Gui.dll 2016-06-13 03:29 - 2016-06-12 21:29 - 000853504 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Multimedia.dll 2016-06-10 15:17 - 2016-06-10 09:17 - 001610240 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Network.dll 2016-06-11 01:51 - 2016-06-10 19:51 - 000348160 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Svg.dll 2016-06-10 15:29 - 2016-06-10 09:29 - 006358528 _____ (The Qt Company Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\Qt5Widgets.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000030208 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qgif.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000032768 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qico.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000256512 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qjpeg.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000026112 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qtga.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000305152 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qtiff.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000025600 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\imageformats\qwbmp.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 001611264 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\platforms\qwindows.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 005487104 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Core.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 005841920 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Gui.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000709120 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Multimedia.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 001179136 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Network.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000207360 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Positioning.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000310272 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5PrintSupport.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 003513344 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Qml.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 003390976 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Quick.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000068096 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5QuickWidgets.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000045568 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5TextToSpeech.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000116224 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5WebChannel.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 054071296 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5WebEngineCore.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000211456 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5WebEngineWidgets.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000146432 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5WebSockets.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 005089792 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Widgets.dll 2021-05-11 20:15 - 2021-05-11 20:15 - 000184832 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Origin\Qt5Xml.dll 2020-10-26 18:13 - 2020-10-26 12:13 - 000110207 _____ (Un4seen Developments) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\BASS.dll 2020-10-26 18:13 - 2020-10-26 12:13 - 000012166 _____ (Un4seen Developments) [Datei ist nicht signiert] C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\BASSWASAPI.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ======== ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ================= ==================== Internet Explorer (Nicht auf der Ausnahmeliste) ========== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=HCTE HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?pc=HCTE HKU\S-1-5-21-429667387-3557466396-1298814767-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?pc=HCTE HKU\S-1-5-21-429667387-3557466396-1298814767-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=HCTE SearchScopes: HKLM -> {916E80B6-517D-47B6-A24B-E7D5EB4C9F19} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {916E80B6-517D-47B6-A24B-E7D5EB4C9F19} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-429667387-3557466396-1298814767-1001 -> {916E80B6-517D-47B6-A24B-E7D5EB4C9F19} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2020-08-23] (HP Inc. -> HP Inc.) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2020-08-23] (HP Inc. -> HP Inc.) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-06-16] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts Inhalt: ========================= (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Andere Bereiche =========================== (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-429667387-3557466396-1298814767-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\HP Backgrounds\backgroundDefault.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) ist aktiviert. Network Binding: ============= Ethernet: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled) Ethernet 2: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled) WLAN: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled) ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) HKLM\...\StartupApproved\Run32: => "ExpressVPNNotificationService" HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-429667387-3557466396-1298814767-1001\...\StartupApproved\Run: => "Voicemod" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{3289854E-1731-471E-8F36-5756A248C87B}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\StreamerV2\Omen.exe (HP Inc. -> HP Inc) FirewallRules: [{2A7845B9-6437-455E-AAF6-4CDCC593D1A5}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\StreamerV2\Omen.exe (HP Inc. -> HP Inc) FirewallRules: [{702E6A9F-51AF-4516-B463-3D37F8D19C4E}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\StreamerV2\Omen.exe (HP Inc. -> HP Inc) FirewallRules: [{27F10401-552A-4F90-90E0-EA019F9871B4}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\StreamerV2\Omen.exe (HP Inc. -> HP Inc) FirewallRules: [{B1B33257-4379-4114-A121-09BD9D82E74B}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{91FDA5E8-8B89-4F1E-81EC-3CFD6C4794DA}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{FBD08CB9-6A57-435D-AB6F-9D06E66110C6}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{3B6C7545-C19F-4476-89E5-039A61A19EF4}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{0F041973-1520-4684-8379-8EDB93E0DBA4}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{BF4E4D29-9F9D-4CD6-B9E6-E16C628353E1}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{8CEF68C5-54C4-42A1-9C48-497B0425DFE4}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{6AB5CA0C-B682-450C-9D4A-D0B8F5AC3D63}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{73D27741-F446-4EC5-B64F-6E82856E785B}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{C338B4A5-0AB3-421C-8E54-978652A0E035}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{3DB1F604-F35B-42FB-AA3F-38BF597D47D4}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{C2DC6241-7CB9-411F-BFDA-1CAFCC075750}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{7C5588A3-D303-4C11-8C50-AB829F7E74D9}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{514F322F-3D48-4BE1-8D5C-90C53E9C8D29}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.) FirewallRules: [{CAECEBCE-9CD5-42CF-84ED-DEF9B1F538D2}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.) FirewallRules: [{414041D8-3752-44AB-BFCD-305511A2FF0A}] => (Allow) C:\Program Files\WindowsApps\ad2f1837.omencommandcenter_11.4.2.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.) FirewallRules: [{6FC86168-AE2B-40A5-B2AB-3BF9C1BCBF9D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{48B6EFB8-CB48-4120-86AF-A51159ACC349}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{5144A49B-2FAA-4541-B91E-A4CC0981B7DE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{DFC39A3C-DBD3-4ABC-A052-DD2BBB2BB179}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{07A61ECA-61B5-492E-AAD3-60DFDA8F7C48}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{A180D3FC-46F1-4C09-94D6-31A44461674E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{99AB0D8C-EC19-4C67-81D0-6CD6183A30E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{FCA82011-3581-42C7-B79B-EB924F7EF59D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{0390BDA0-30F7-4D37-9A30-0F51B5BB0BF8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{D84CFE73-B09F-4654-AAC1-4B7E8AC1E594}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{C2C36F8C-8049-4DD8-ACC0-CB035D465CCF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{1A012EB4-A762-4CF0-8466-AE1E8F1AF5EE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{F6C84179-C08B-4932-9488-B1682104548D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{437E854E-ACFE-4160-BCBB-0E15812B4F46}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{3833F45B-AD24-441A-AE66-F35CE264BB10}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [TCP Query User{7F9957C4-1BFE-4C0E-99D8-0F07E5EBCA5C}C:\users\belar\appdata\local\programs\opera\76.0.4017.107\opera.exe] => (Allow) C:\users\belar\appdata\local\programs\opera\76.0.4017.107\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [UDP Query User{3D91A1F2-B07B-4808-A879-F91CFFEE6900}C:\users\belar\appdata\local\programs\opera\76.0.4017.107\opera.exe] => (Allow) C:\users\belar\appdata\local\programs\opera\76.0.4017.107\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{882F0172-E075-4282-AE6E-A0D8866CEA15}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B34211BE-62F4-4A5E-A077-ADEC8F48823E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{F09076FA-7449-411E-9EAF-D6A8DF1CF333}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{09B05CD3-4D4D-4A42-8348-0C3270403DBC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{48D34563-1FDD-4712-B577-2977B9A09BF3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{73A6A492-AC09-4957-B5AA-1C8A90E37705}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{587D43E0-C779-4C31-BBCC-83E62CD5D39C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{6B0BC0F7-14CC-4B4D-809C-FCE745EF6BEB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.158.820.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{5860F0D3-8C1A-4ECC-948D-B221A5C78188}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{8A36DDE7-6EB5-4034-9029-CE5CA50509A1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{D2A397A7-F004-4EDC-A086-44AC94ADB932}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{C4DA778A-F57C-48E8-BCCE-BD40E6F9F59E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{07437AAD-2668-46D5-9DBB-9CEA9B3EBCE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Factorio\bin\x64\factorio.exe (Wube Software) [Datei ist nicht signiert] FirewallRules: [{644B3367-BCE9-490B-AF5D-1E4C583A4F24}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Factorio\bin\x64\factorio.exe (Wube Software) [Datei ist nicht signiert] FirewallRules: [{61481179-63AF-4B2F-A934-04734CB0ED28}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [TCP Query User{25F6BEAD-06C6-4735-8319-4BD848198E75}C:\users\belar\appdata\local\programs\blitz\blitz.exe] => (Allow) C:\users\belar\appdata\local\programs\blitz\blitz.exe (Swift Media Entertainment, Inc. -> Blitz, Inc.) FirewallRules: [UDP Query User{6EBA0128-4644-44FF-975B-69F18D5C28E8}C:\users\belar\appdata\local\programs\blitz\blitz.exe] => (Allow) C:\users\belar\appdata\local\programs\blitz\blitz.exe (Swift Media Entertainment, Inc. -> Blitz, Inc.) ==================== Wiederherstellungspunkte ========================= 13-05-2021 22:57:53 Windows Modules Installer ==================== Fehlerhafte Geräte im Gerätemanager ============ ==================== Fehlereinträge in der Ereignisanzeige: ======================== Applikationsfehler: ================== Error: (05/13/2021 02:13:32 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (05/13/2021 02:13:32 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (05/13/2021 02:10:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MsMpEng.exe, Version: 4.18.1909.6, Zeitstempel: 0x2b5ae0b5 Name des fehlerhaften Moduls: mprtp.dll, Version: 4.18.1909.6, Zeitstempel: 0x64f86809 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000007c16d ID des fehlerhaften Prozesses: 0x4724 Startzeit der fehlerhaften Anwendung: 0x01d747f0d37c5c2c Pfad der fehlerhaften Anwendung: C:\Program Files\Windows Defender\MsMpEng.exe Pfad des fehlerhaften Moduls: C:\Program Files\Windows Defender\mprtp.dll Berichtskennung: f6497116-bae7-49a1-a87a-151d68f81044 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (05/13/2021 02:08:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MsMpEng.exe, Version: 4.18.1909.6, Zeitstempel: 0x2b5ae0b5 Name des fehlerhaften Moduls: mprtp.dll, Version: 4.18.1909.6, Zeitstempel: 0x64f86809 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000007c16d ID des fehlerhaften Prozesses: 0x1294 Startzeit der fehlerhaften Anwendung: 0x01d747f09f15fd1b Pfad der fehlerhaften Anwendung: C:\Program Files\Windows Defender\MsMpEng.exe Pfad des fehlerhaften Moduls: C:\Program Files\Windows Defender\mprtp.dll Berichtskennung: ddc5cb30-1cfb-44d6-93cc-bde9277d1c42 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (05/13/2021 02:07:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MsMpEng.exe, Version: 4.18.1909.6, Zeitstempel: 0x2b5ae0b5 Name des fehlerhaften Moduls: mprtp.dll, Version: 4.18.1909.6, Zeitstempel: 0x64f86809 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000007c16d ID des fehlerhaften Prozesses: 0x1574 Startzeit der fehlerhaften Anwendung: 0x01d747f05f78bf2c Pfad der fehlerhaften Anwendung: C:\Program Files\Windows Defender\MsMpEng.exe Pfad des fehlerhaften Moduls: C:\Program Files\Windows Defender\mprtp.dll Berichtskennung: df8792b6-6c64-426e-bcea-dec112e02632 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (05/11/2021 08:30:28 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007045b, Der Computer wird heruntergefahren. . Error: (05/11/2021 08:30:28 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x8007045b, Der Computer wird heruntergefahren. ] Error: (05/11/2021 08:30:28 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x8007045b, Der Computer wird heruntergefahren. . Systemfehler: ============= Error: (05/14/2021 06:54:11 PM) (Source: volmgr) (EventID: 161) (User: ) Description: Erstellung einer Abbilddatei aufgrund eines Fehlers beim Erstellen der Abbildkopie fehlgeschlagen. Error: (05/14/2021 06:54:19 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 14.05.2021 um 18:42:50 unerwartet heruntergefahren. Error: (05/14/2021 04:53:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "NVIDIA LocalSystem Container" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 6000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/14/2021 04:53:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "NVIDIA LocalSystem Container" wurde mit folgendem Fehler beendet: Für einen allgemeinen Befehl wurde ein Ergebnis zurückgegeben, das auf einen Fehler hinweist. Error: (05/13/2021 11:04:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-E8L34PA) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (05/13/2021 11:04:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-E8L34PA) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (05/13/2021 11:04:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-E8L34PA) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (05/13/2021 11:04:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-E8L34PA) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. CodeIntegrity: =============== Date: 2021-05-13 14:10:19 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system. Date: 2021-05-11 20:33:02 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Windows signing level requirements. Date: 2021-05-11 20:07:30 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Microsoft signing level requirements. ==================== Speicherinformationen =========================== BIOS: AMI F.30 01/25/2021 Hauptplatine: HP 8767 Prozessor: Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz Prozentuale Nutzung des RAM: 44% Installierter physikalischer RAM: 16249.75 MB Verfügbarer physikalischer RAM: 9040.99 MB Summe virtueller Speicher: 19193.75 MB Verfügbarer virtueller Speicher: 8249.68 MB ==================== Laufwerke ================================ Drive c: (Windows) (Fixed) (Total:953.08 GB) (Free:871.11 GB) NTFS Drive d: (DATA) (Fixed) (Total:931.51 GB) (Free:931.04 GB) NTFS Drive e: () (Removable) (Total:7.49 GB) (Free:5.49 GB) FAT32 Drive f: (LEXAR) (Removable) (Total:29.81 GB) (Free:9.03 GB) NTFS \\?\Volume{648c8087-c488-4eb1-aca0-08e85fd1cdd6}\ (Windows RE tools) (Fixed) (Total:0.52 GB) (Free:0.06 GB) NTFS \\?\Volume{2fe36d90-5d55-4645-a95f-76987bbf14c8}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.17 GB) FAT32 ==================== MBR & Partitionstabelle ==================== ========================================================== Disk: 0 (Size: 953.9 GB) (Disk ID: E7877EE9) Partition: GPT. ========================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 542D53E6) Partition: GPT. ========================================================== Disk: 2 (MBR Code: Windows XP) (Size: 29.8 GB) (Disk ID: C3072E18) Partition 1: (Not Active) - (Size=29.8 GB) - (Type=07 NTFS) ========================================================== Disk: 3 (Size: 7.5 GB) (Disk ID: 02073108) Partition 1: (Active) - (Size=7.5 GB) - (Type=0B) ==================== Ende von Addition.txt ======================= Shortcut-Log: Code:
ATTFilter Untersuchungsergebnis der Verknüpfungen des Benutzers (x64) Version: 14-05-2021 durchgeführt von belar (14-05-2021 19:15:24) Gestartet von C:\Users\belar\Downloads Start-Modus: Normal ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExpressVPN.lnk -> C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe (ExpressVPN) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Audio Switch.lnk -> C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe (HP Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk -> C:\Program Files\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Was ist neu in dieser Version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Free Games by wild.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\free-to-play\free-to-play.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Hidden Object Games.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\hidden-object\hidden-object.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Mahjong Games.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\mahjong-games\mahjong-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\New Games .lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\new-games\new-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\RPG.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\role-playing-games\role-playing-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Solitaire, Poker & More.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\cards-games\cards-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Strategy Games.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\strategy-games\strategy-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Time Management Games.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\time-management-games\time-management-games.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voicemod\Voicemod.lnk -> C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Editor (Compatibility mode).lnk -> C:\Program Files\Tracker Software\PDF Editor\PDFXEdit_low.exe (Tracker Software Products (Canada) Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Editor.lnk -> C:\Program Files\Tracker Software\PDF Editor\PDFXEdit.exe (Tracker Software Products (Canada) Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\Tracker Updater.lnk -> C:\Program Files\Tracker Software\Update\TrackerUpdate.exe (Tracker Software Products (Canada) Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Lite\PDF-XChange Lite License Agreement.lnk -> C:\Program Files\Tracker Software\PDF-XChange Lite\Help\PDFXLicense.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Lite\PDF-XChange Lite User Manual.lnk -> C:\Program Files\Tracker Software\PDF-XChange Lite\Help\PDFX8ManLiteSm.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Editor\PDF-XChange Editor Help.lnk -> C:\Program Files\Tracker Software\PDF Editor\Help\PDFXVE8Sm.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Editor\PDF-XChange Editor License Agreement.lnk -> C:\Program Files\Tracker Software\PDF Editor\PDF_VE.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT\ROCCAT SWARM\ROCCAT Swarm.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm.exe (ROCCAT) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin deinstallieren.lnk -> D:\Origin\OriginUninstall.exe (Electronic Arts) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin Fehlermeldungs-Hilfe.lnk -> D:\Origin\OriginER.exe (Electronic Arts) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin.lnk -> D:\Origin\Origin.exe (Electronic Arts) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk -> C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk -> C:\Windows\regedit.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\Windows\System32\quickassist.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\Users\belar\Links\Desktop.lnk -> C:\Users\belar\Desktop () Shortcut: C:\Users\belar\Links\Downloads.lnk -> C:\Users\belar\Downloads () Shortcut: C:\Users\belar\Desktop\Blitz.lnk -> C:\Users\belar\AppData\Local\Programs\Blitz\Blitz.exe (Blitz, Inc.) Shortcut: C:\Users\belar\Desktop\Opera-Browser.lnk -> C:\Users\belar\AppData\Local\Programs\Opera\launcher.exe (Opera Software) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blitz.lnk -> C:\Users\belar\AppData\Local\Programs\Blitz\Blitz.exe (Blitz, Inc.) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\belar\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk -> C:\Users\belar\AppData\Local\Programs\Opera\launcher.exe (Opera Software) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Was ist neu in dieser Version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth-Dateiübertragung.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Voicemod.lnk -> C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera-Browser.lnk -> C:\Users\belar\AppData\Local\Programs\Opera\launcher.exe (Opera Software) Shortcut: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Steam.lnk -> C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\belar\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd) Shortcut: C:\Users\Public\Desktop\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Origin.lnk -> D:\Origin\Origin.exe (Electronic Arts) Shortcut: C:\Users\Public\Desktop\PDF-XChange Editor.lnk -> C:\Program Files\Tracker Software\PDF Editor\PDFXEdit.exe (Tracker Software Products (Canada) Ltd.) Shortcut: C:\Users\Public\Desktop\Steam.lnk -> C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) Shortcut: C:\Users\Public\Desktop\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Documentation.lnk -> C:\Program Files\HP\Documentation\platform_guides\languages\index.html () -> /Arguments:Shortcut ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Hearts.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\heartshtml5\heartshtml5.ico () -> /src=gamesmenu /id=heartshtml5 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Mahjong Classic.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\mahjongclassichtml5\mahjongclassichtml5.ico () -> /src=gamesmenu /id=mahjongclassichtml5 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games\Solitaire with Themes.lnk -> C:\ProgramData\WildTangent\WildTangent Games\ShortcutProvider\solitairehtml5\solitairehtml5.ico () -> /src=gamesmenu /id=solitairehtml5 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tracker Software\PDF-XChange Lite\PDF-XChange Lite pdfSaver.lnk -> C:\Program Files\Tracker Software\PDF-XChange Lite\pdfSaverL.exe (Tracker Software Products (Canada) Ltd.) -> /Show ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe (ROCCAT) -> 0 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT\Isku Keyboard\Isku Driver.lnk -> C:\Program Files (x86)\ROCCAT\Isku Keyboard\IskuMonitor.exe (ROCCAT GmbH) -> 1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT\Isku Keyboard\Uninstall Driver.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{4ABAF918-A6BD-43D8-AE0B-5292034B14CB}\Setup.exe" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games\League of Legends.lnk -> C:\Riot Games\Riot Client\RiotClientServices.exe (Riot Games, Inc.) -> --launch-product=league_of_legends --launch-patchline=live ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Upload Center.lnk -> C:\Program Files\Microsoft Office\root\Client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files\Microsoft Office\Root\Office16\MSOUC.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk -> C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) -> /home ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\belar\Desktop\Discord.lnk -> C:\Users\belar\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\belar\Desktop\Dropbox.lnk -> C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) -> /home ShortcutWithArgument: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools ShortcutWithArgument: C:\Users\belar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc\Discord.lnk -> C:\Users\belar\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\belar\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\belar\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) -> --sendto ShortcutWithArgument: C:\Users\belar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\League of Legends.lnk -> C:\Riot Games\Riot Client\RiotClientServices.exe (Riot Games, Inc.) -> --launch-product=league_of_legends --launch-patchline=live ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\belar\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.AdministrativeTools ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) -> --sendto ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Public\Desktop\League of Legends.lnk -> C:\Riot Games\Riot Client\RiotClientServices.exe (Riot Games, Inc.) -> --launch-product=league_of_legends --launch-patchline=live InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url -> URL: hxxp://support.steampowered.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox Website.URL -> InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.ccleaner.com/ccleaner InternetURL: C:\Users\belar\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\belar\Favorites\Links\Amazon.de – online einkaufen.url -> URL: hxxp://www.amazon.de/gp/bit/amazonbookmark.html?tag=hp2-brobookmark-de-21&partner=HP InternetURL: C:\Users\belar\Favorites\Links\Booking.com.url -> URL: hxxp://secure.rezserver.com/sdk/v1/LinkFwd?refid=7684&destination=booking&refclickid=webslice1819 InternetURL: C:\Users\belar\Favorites\HP\Amazon.de – online einkaufen.url -> URL: hxxp://www.amazon.de/gp/bit/amazonbookmark.html?tag=hp2-brobookmark-de-21&partner=HP InternetURL: C:\Users\belar\Favorites\HP\Booking.com.url -> URL: hxxp://secure.rezserver.com/sdk/v1/LinkFwd?refid=7684&destination=booking&refclickid=iefav1819 InternetURL: C:\Users\belar\Favorites\HP\HP Store.url -> URL: hxxp://js.redirect.hp.com/jumpstation?bd=*&c=*&locale=de_de&pf=*&s=Hpstore&tp=*&TYPE=3 InternetURL: C:\Users\belar\Dropbox\audi a4.url -> URL: hxxps://suchen.mobile.de/fahrzeuge/details.html?id=317162180&damageUnrepaired=NO_DAMAGE_UNREPAIRED&fuels=PETROL&grossPrice=true&isSearchRequest=true&makeModelVariant1.makeId=1900&maxPowerAsArray=109&maxPowerAsArray=KW&maxPrice=4000&minCubicCapacity=1600&minPowerAsArray=74&minPowerAsArray=KW&pageNumber=1&scopeId=C&sfmr=false&transmissions=MANUAL_GEAR&searchId=b9a00e56-d2e4-8132-42cc-13b360671f4c InternetURL: C:\Users\belar\Dropbox\audi münchen.url -> URL: hxxps://www.autoscout24.de/angebote/audi-a3-1-4-tfsi-attraction-benzin-grau-dc5aad04-e68e-4fca-9145-d1b8889f26de?utm_source=web-native-share&utm_campaign=share InternetURL: C:\Users\belar\Dropbox\audi nersingen.url -> URL: hxxps://www.autoscout24.de/angebote/audi-a3-1-6-attraction-8p1-benzin-grau-4247062e-4832-4f21-b484-23358e10c842?utm_source=web-native-share&utm_campaign=share InternetURL: C:\Users\Default\Favorites\Links\Amazon.de – online einkaufen.url -> URL: hxxp://www.amazon.de/gp/bit/amazonbookmark.html?tag=hp2-brobookmark-de-21&partner=HP InternetURL: C:\Users\Default\Favorites\Links\Booking.com.url -> URL: hxxp://secure.rezserver.com/sdk/v1/LinkFwd?refid=7684&destination=booking&refclickid=webslice1819 InternetURL: C:\Users\Default\Favorites\HP\Amazon.de – online einkaufen.url -> URL: hxxp://www.amazon.de/gp/bit/amazonbookmark.html?tag=hp2-brobookmark-de-21&partner=HP InternetURL: C:\Users\Default\Favorites\HP\Booking.com.url -> URL: hxxp://secure.rezserver.com/sdk/v1/LinkFwd?refid=7684&destination=booking&refclickid=iefav1819 InternetURL: C:\Users\Default\Favorites\HP\HP Store.url -> URL: hxxp://js.redirect.hp.com/jumpstation?bd=*&c=*&locale=de_de&pf=*&s=Hpstore&tp=*&TYPE=3 ==================== Ende vom Shortcut.txt ============================= |
15.05.2021, 15:52 | #3 |
/// Helfer-Team | Windows 10: Bluescreen in unregelmäßigen abständen Details Wenn ich das so durchlese, hast Du ja schon einiges angestellt. Von CCleaner bis McAffe.
__________________Hast Du ein Update des BIOS durchgeführt? Ansonsten müsste der Rechner ja neu sein. Wie wäre es mit Gewährleistung? BIOS: AMI F.30 01/25/2021
__________________ |
15.05.2021, 18:03 | #4 |
| Lösung: Windows 10: Bluescreen in unregelmäßigen abständen Hi, danke für die schnelle Antwort. Mcaffee ist bei der system wieder Herstellung Standard mäßig leider drauf, ich wollte es nicht haben -.- Ja der CCleaner habe ich drauf gemacht, weil ich früher nie Probleme hatte. Die bluescreen haben auch lange lange vorher angefangen bevor ich den installiert hatte. BIOS habe ich schon über den hersteller upgedatet. Hatte heute eine spiele Session von ca. 8 Stunden. Diesmal keinen bluescreen. |
15.05.2021, 18:44 | #5 | |
| Wie Windows 10: Bluescreen in unregelmäßigen abständenZitat:
1.) Datenträger testen. 2.) Richtige Neuinstallation durchführen, ohne die ganze Vorinstallations-Software. 3.) Prüfen auf aktuelles UEFI und aktuelle Treiber. Du brauchst eine verlässliche Grundlage, um dann ggf. weitere Tests zur Ursache durchführen zu können. |
15.05.2021, 19:03 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Wo Windows 10: Bluescreen in unregelmäßigen abständen Lösung! Und man sollte sich auch mal die Frage stellen, ob man sich mit aller Gewalt wirklich Windows antun muss oder nicht eine Linux-Distro installiert, mit der man was Wartung/Updates anbelangt erheblich weniger Aufwand zu leisten hat.
__________________ --> Windows 10: Bluescreen in unregelmäßigen abständen |
15.05.2021, 19:34 | #7 | |
| Windows 10: Bluescreen in unregelmäßigen abständenZitat:
__________________ Windows 10 64 Pro 22H2 |
15.05.2021, 19:56 | #8 |
/// Helfer-Team | Windows 10: Bluescreen in unregelmäßigen abständen Soweit alles richtig. Es steht immer noch die Frage nach dem Kaufdatum. Wenn noch Gewährleistung besteht, ist der Händler in der Pflicht.
__________________ LG Der Felix Keine Hilfe per PN und E-Mail |
15.05.2021, 21:33 | #9 |
| Windows 10: Bluescreen in unregelmäßigen abständen Vielen Dank für die Tipps, ich werde mal alles nach schauen. Werde mal das Diagnose Tool CrystalDiskInfo benutzen und mich mit den Logs wieder melden Die Neuinstallation kann ich nur über das System machen, da bei meinem PC kein Optisches Laufwerk mehr vorhanden ist und beim Kauf kein USB-Datenträger gab, mit einer Windows Version. Die Aktuellen UEFI habe ich über die Hersteller Oberfläche getätigt. Da ist alles aktuell. Ebenfalls sind die Grafiktreiber aktuell. Ich werde noch einmal den CristalDiskInfo durchlaufen lassen und schauen was der mir sagt. Vielen Dank für eure unterstützung So das sind die Daten, welche mir CrystalDeskInfo angibt. Hoffe das Ihr mir hierzu ein paar Hilfestellungen und Erläuterungen geben könnt, solltet Ihr einen Fehler finden der Auf die Festplatten schließt. Code:
ATTFilter ---------------------------------------------------------------------------- CrystalDiskInfo 8.1.0 (C) 2008-2019 hiyohiyo Crystal Dew World : https://crystalmark.info/ ---------------------------------------------------------------------------- OS : Windows 10 [10.0 Build 19042] (x64) Date : 2021/05/15 22:32:20 -- Controller Map ---------------------------------------------------------- + Intel(R) NVMe Controller [SCSI] - INTEL SSDPEKNW010T8H - Microsoft-Controller für Speicherplätze [SCSI] + Intel(R) Chipset SATA/PCIe RST Premium Controller [SCSI] - ST1000DM003-1SB102 - Intel(R) Optane(TM) Pinning Shell Extensions -- Disk List --------------------------------------------------------------- (1) INTEL SSDPEKNW010T8H : 1024,2 GB [0/0/0, nt] - nv (2) ST1000DM003-1SB102 : 1000,2 GB [1/1/2, pd1] - st ---------------------------------------------------------------------------- (1) INTEL SSDPEKNW010T8H ---------------------------------------------------------------------------- Model : INTEL SSDPEKNW010T8H Firmware : HPS0 Serial Number : BTNH01610GM51P0B Disk Size : 1024,2 GB Buffer Size : Unbekannt # of Sectors : Rotation Rate : ---- (SSD) Interface : NVM Express Major Version : NVM Express 1.3 Minor Version : Transfer Mode : PCIe 3.0 x4 | PCIe 3.0 x4 Power On Hours : 858 Std. Power On Count : 322 mal Host Reads : 6346 GB Host Writes : 5704 GB Temperature : 25 C (77 F) Health Status : Gut (100 %) Features : S.M.A.R.T. APM Level : ---- AAM Level : ---- Drive Letter : C: -- S.M.A.R.T. -------------------------------------------------------------- ID RawValues(6) Attribute Name 01 000000000000 Critical Warning 02 00000000012A Composite Temperature 03 000000000064 Available Spare 04 00000000000A Available Spare Threshold 05 000000000000 Percentage Used 06 000000C6551C Data Units Read 07 000000B2412E Data Units Written 08 000008532586 Host Read Commands 09 000008045C7C Host Write Commands 0A 000000000DC6 Controller Busy Time 0B 000000000142 Power Cycles 0C 00000000035A Power On Hours 0D 0000000000F8 Unsafe Shutdowns 0E 000000000000 Media and Data Integrity Errors 0F 000000000000 Number of Error Information Log Entries -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 8086 8086 5442 484E 3130 3136 4730 354D 5031 4230 010: 2020 2020 4E49 4554 204C 5353 5044 4B45 574E 3130 020: 5430 4838 2020 2020 2020 2020 2020 2020 2020 2020 030: 2020 2020 5048 3053 2020 2020 E406 5CD2 0500 0001 040: 0300 0001 A120 0007 8480 001E 0200 0000 0002 0000 050: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 060: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 070: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 080: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 090: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 100: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 120: 0000 0000 0000 0000 0000 0000 0000 0000 0017 0703 130: 0F14 04FF 0100 015E 0161 0032 0000 0000 0000 0000 140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 150: 0000 0000 0000 0000 0000 0000 0000 0000 0005 0001 160: 0000 0001 012F 015C 0003 0000 0000 0000 0000 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 0000 -- SMART_NVME -------------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 00 2A 01 64 0A 00 00 00 00 00 00 00 00 00 00 00 010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 020: 1C 55 C6 00 00 00 00 00 00 00 00 00 00 00 00 00 030: 2E 41 B2 00 00 00 00 00 00 00 00 00 00 00 00 00 040: 86 25 53 08 00 00 00 00 00 00 00 00 00 00 00 00 050: 7C 5C 04 08 00 00 00 00 00 00 00 00 00 00 00 00 060: C6 0D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 42 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 5A 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: F8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ---------------------------------------------------------------------------- (2) ST1000DM003-1SB102 ---------------------------------------------------------------------------- Model : ST1000DM003-1SB102 Firmware : HPH5 Serial Number : ZN1GAD50 Disk Size : 1000,2 GB (8,4/137,4/1000,2/----) Buffer Size : Unbekannt Queue Depth : 32 # of Sectors : 1953525168 Rotation Rate : 7200 RPM Interface : Serial ATA Major Version : ACS-3 Minor Version : ACS-3 Revision 3b Transfer Mode : SATA/600 | SATA/600 Power On Hours : 856 Std. Power On Count : 319 mal Temperature : 28 C (82 F) Health Status : Gut Features : S.M.A.R.T., APM, 48bit LBA, NCQ APM Level : 8080h [ON] AAM Level : ---- Drive Letter : D: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 01 _75 _63 __6 0000027B9228 Lesefehlerrate 03 _97 _97 __0 000000000000 Mittlere Anlaufzeit 04 100 100 __0 000000000345 Start/Stopp-Zyklen der Spindel 05 100 100 _10 000000000000 Wiederzugewiesene Sektoren 07 _64 _60 _30 0000002E0848 Suchfehler 09 100 100 __0 000000000358 Betriebsstunden 0A 100 100 _97 000000000000 Misslungene Spindelanläufe 0C 100 100 __0 00000000013F Geräte-Einschaltvorgänge B4 100 100 __0 00007756DE19 Herstellerspezifisch B7 100 100 __0 000000000000 Herstellerspezifisch B8 100 100 _97 000000000000 Ende-zu-Ende-Fehler BB 100 100 __0 000000000000 Gemeldete unkorrigierbare Fehler BC 100 100 __0 000000000000 Befehlszeitüberschreitung BD 100 100 __0 000000000000 Übergeordnete Schreibvorgänge BE _72 _59 _40 00001C13001C Luftstromtemperatur C1 100 100 __0 000000000346 Laden/Entladen-Zyklen C2 _28 _15 __0 000F0000001C Temperatur C3 _21 __5 __0 0000027B9228 Hardware-ECC wiederhergestellt C4 100 100 __0 000000000000 Wiederzuweisungsereignisse C5 100 100 __0 000000000000 Aktuell ausstehende Sektoren C6 100 100 __0 000000000000 Nicht korrigierbare Sektoren C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 5A4E 3147 4144 3530 2020 2020 2020 2020 2020 2020 020: 0000 0000 0000 4850 4835 2020 2020 5354 3130 3030 030: 444D 3030 332D 3153 4231 3032 2020 2020 2020 2020 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4001 0200 0200 0007 3FFF 0010 003F FC10 00FB 0010 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0100 070: 0000 0000 0000 0000 0000 001F 850E 0006 00CC 004C 080: 07F0 001F 706B 7469 4123 7069 B449 4123 203F 0034 090: 0034 8080 FFFE 0000 D0D0 0000 0000 0000 0000 0000 100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5000 C500 110: C5E7 CC8B 0000 0000 0000 0000 0000 0000 0000 405C 120: 401C 0000 0000 0000 0000 0000 0000 0000 0021 6DB0 130: 7470 6DB0 7470 2020 0002 0140 0100 5000 3C06 3C0A 140: 0000 0078 0000 0008 0000 0000 FDFF 0280 0000 0000 150: 0008 0000 0000 0000 0000 8000 0000 0184 9400 8000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0002 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 10BD 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000 220: 0000 0000 107F 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 85A5 -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 20 00 01 2F 00 4B 3F 28 92 7B 02 00 00 00 03 23 010: 00 61 61 00 00 00 00 00 00 00 04 32 00 64 64 45 020: 03 00 00 00 00 00 05 33 00 64 64 00 00 00 00 00 030: 00 00 07 2F 00 40 3C 48 08 2E 00 00 00 00 09 32 040: 00 64 64 58 03 00 00 00 00 00 0A 33 00 64 64 00 050: 00 00 00 00 00 00 0C 32 00 64 64 3F 01 00 00 00 060: 00 00 B4 2A 00 64 64 19 DE 56 77 00 00 00 B7 32 070: 00 64 64 00 00 00 00 00 00 00 B8 33 00 64 64 00 080: 00 00 00 00 00 00 BB 32 00 64 64 00 00 00 00 00 090: 00 00 BC 32 00 64 64 00 00 00 00 00 00 00 BD 3A 0A0: 00 64 64 00 00 00 00 00 00 00 BE 22 00 48 3B 1C 0B0: 00 13 1C 00 00 00 C1 32 00 64 64 46 03 00 00 00 0C0: 00 00 C2 22 00 1C 0F 1C 00 00 00 0F 00 00 C3 3A 0D0: 00 15 05 28 92 7B 02 00 00 00 C4 32 00 64 64 00 0E0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00 0F0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 32 100: 00 C8 C8 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 37 02 00 53 170: 03 00 01 00 02 67 00 00 00 00 00 00 00 00 00 00 180: 00 00 02 00 31 0B 00 00 06 03 03 03 03 03 03 03 190: 03 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 93 F9 63 B4 CD 02 00 00 1B0: 00 00 00 00 01 00 CE 04 D7 77 BD BD 00 00 00 00 1C0: B6 63 57 49 00 00 00 00 00 00 00 00 17 49 04 00 1D0: 01 00 00 00 00 00 00 00 CE 00 00 00 06 00 00 00 1E0: 00 00 00 00 19 00 00 00 00 00 00 00 00 00 00 06 1F0: 00 00 00 00 00 00 00 00 00 00 14 16 00 00 00 54 -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 20 00 01 06 00 00 00 00 00 00 00 00 00 00 03 00 010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 020: 00 00 00 00 00 00 05 0A 00 00 00 00 00 00 00 00 030: 00 00 07 1E 00 00 00 00 00 00 00 00 00 00 09 00 040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00 050: 00 00 00 00 00 00 0C 00 00 00 00 00 00 00 00 00 060: 00 00 B4 00 00 00 00 00 00 00 00 00 00 00 B7 00 070: 00 00 00 00 00 00 00 00 00 00 B8 61 00 00 00 00 080: 00 00 00 00 00 00 BB 00 00 00 00 00 00 00 00 00 090: 00 00 BC 00 00 00 00 00 00 00 00 00 00 00 BD 00 0A0: 00 00 00 00 00 00 00 00 00 00 BE 28 00 00 00 00 0B0: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00 0C0: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C3 00 0D0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00 0E0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00 0F0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 Code:
ATTFilter ---------------------------------------------------------------------------- CrystalDiskInfo 8.1.0 (C) 2008-2019 hiyohiyo Crystal Dew World : https://crystalmark.info/ ---------------------------------------------------------------------------- OS : Windows 10 [10.0 Build 19042] (x64) Date : 2021/05/15 22:32:48 -- Controller Map ---------------------------------------------------------- + Intel(R) NVMe Controller [SCSI] - INTEL SSDPEKNW010T8H - Microsoft-Controller für Speicherplätze [SCSI] + Intel(R) Chipset SATA/PCIe RST Premium Controller [SCSI] - ST1000DM003-1SB102 - Intel(R) Optane(TM) Pinning Shell Extensions -- Disk List --------------------------------------------------------------- (1) INTEL SSDPEKNW010T8H : 1024,2 GB [0/0/0, nt] - nv (2) ST1000DM003-1SB102 : 1000,2 GB [1/1/2, pd1] - st ---------------------------------------------------------------------------- (1) INTEL SSDPEKNW010T8H ---------------------------------------------------------------------------- Model : INTEL SSDPEKNW010T8H Firmware : HPS0 Serial Number : BTNH01610GM51P0B Disk Size : 1024,2 GB Buffer Size : Unbekannt # of Sectors : Rotation Rate : ---- (SSD) Interface : NVM Express Major Version : NVM Express 1.3 Minor Version : Transfer Mode : PCIe 3.0 x4 | PCIe 3.0 x4 Power On Hours : 858 Std. Power On Count : 322 mal Host Reads : 6346 GB Host Writes : 5704 GB Temperature : 25 C (77 F) Health Status : Gut (100 %) Features : S.M.A.R.T. APM Level : ---- AAM Level : ---- Drive Letter : C: -- S.M.A.R.T. -------------------------------------------------------------- ID RawValues(6) Attribute Name 01 000000000000 Critical Warning 02 00000000012A Composite Temperature 03 000000000064 Available Spare 04 00000000000A Available Spare Threshold 05 000000000000 Percentage Used 06 000000C6551C Data Units Read 07 000000B2412E Data Units Written 08 000008532586 Host Read Commands 09 000008045C7C Host Write Commands 0A 000000000DC6 Controller Busy Time 0B 000000000142 Power Cycles 0C 00000000035A Power On Hours 0D 0000000000F8 Unsafe Shutdowns 0E 000000000000 Media and Data Integrity Errors 0F 000000000000 Number of Error Information Log Entries -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 8086 8086 5442 484E 3130 3136 4730 354D 5031 4230 010: 2020 2020 4E49 4554 204C 5353 5044 4B45 574E 3130 020: 5430 4838 2020 2020 2020 2020 2020 2020 2020 2020 030: 2020 2020 5048 3053 2020 2020 E406 5CD2 0500 0001 040: 0300 0001 A120 0007 8480 001E 0200 0000 0002 0000 050: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 060: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 070: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 080: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 090: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 100: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 120: 0000 0000 0000 0000 0000 0000 0000 0000 0017 0703 130: 0F14 04FF 0100 015E 0161 0032 0000 0000 0000 0000 140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 150: 0000 0000 0000 0000 0000 0000 0000 0000 0005 0001 160: 0000 0001 012F 015C 0003 0000 0000 0000 0000 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 0000 -- SMART_NVME -------------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 00 2A 01 64 0A 00 00 00 00 00 00 00 00 00 00 00 010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 020: 1C 55 C6 00 00 00 00 00 00 00 00 00 00 00 00 00 030: 2E 41 B2 00 00 00 00 00 00 00 00 00 00 00 00 00 040: 86 25 53 08 00 00 00 00 00 00 00 00 00 00 00 00 050: 7C 5C 04 08 00 00 00 00 00 00 00 00 00 00 00 00 060: C6 0D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 070: 42 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 080: 5A 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 090: F8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ---------------------------------------------------------------------------- (2) ST1000DM003-1SB102 ---------------------------------------------------------------------------- Model : ST1000DM003-1SB102 Firmware : HPH5 Serial Number : ZN1GAD50 Disk Size : 1000,2 GB (8,4/137,4/1000,2/----) Buffer Size : Unbekannt Queue Depth : 32 # of Sectors : 1953525168 Rotation Rate : 7200 RPM Interface : Serial ATA Major Version : ACS-3 Minor Version : ACS-3 Revision 3b Transfer Mode : SATA/600 | SATA/600 Power On Hours : 856 Std. Power On Count : 319 mal Temperature : 28 C (82 F) Health Status : Gut Features : S.M.A.R.T., APM, 48bit LBA, NCQ APM Level : 8080h [ON] AAM Level : ---- Drive Letter : D: -- S.M.A.R.T. -------------------------------------------------------------- ID Cur Wor Thr RawValues(6) Attribute Name 01 _75 _63 __6 0000027B9228 Lesefehlerrate 03 _97 _97 __0 000000000000 Mittlere Anlaufzeit 04 100 100 __0 000000000345 Start/Stopp-Zyklen der Spindel 05 100 100 _10 000000000000 Wiederzugewiesene Sektoren 07 _64 _60 _30 0000002E0848 Suchfehler 09 100 100 __0 000000000358 Betriebsstunden 0A 100 100 _97 000000000000 Misslungene Spindelanläufe 0C 100 100 __0 00000000013F Geräte-Einschaltvorgänge B4 100 100 __0 00007756DE19 Herstellerspezifisch B7 100 100 __0 000000000000 Herstellerspezifisch B8 100 100 _97 000000000000 Ende-zu-Ende-Fehler BB 100 100 __0 000000000000 Gemeldete unkorrigierbare Fehler BC 100 100 __0 000000000000 Befehlszeitüberschreitung BD 100 100 __0 000000000000 Übergeordnete Schreibvorgänge BE _72 _59 _40 00001C13001C Luftstromtemperatur C1 100 100 __0 000000000346 Laden/Entladen-Zyklen C2 _28 _15 __0 000F0000001C Temperatur C3 _21 __5 __0 0000027B9228 Hardware-ECC wiederhergestellt C4 100 100 __0 000000000000 Wiederzuweisungsereignisse C5 100 100 __0 000000000000 Aktuell ausstehende Sektoren C6 100 100 __0 000000000000 Nicht korrigierbare Sektoren C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler -- IDENTIFY_DEVICE --------------------------------------------------------- 0 1 2 3 4 5 6 7 8 9 000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000 010: 5A4E 3147 4144 3530 2020 2020 2020 2020 2020 2020 020: 0000 0000 0000 4850 4835 2020 2020 5354 3130 3030 030: 444D 3030 332D 3153 4231 3032 2020 2020 2020 2020 040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00 050: 4001 0200 0200 0007 3FFF 0010 003F FC10 00FB 0010 060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0100 070: 0000 0000 0000 0000 0000 001F 850E 0006 00CC 004C 080: 07F0 001F 706B 7469 4123 7069 B449 4123 203F 0034 090: 0034 8080 FFFE 0000 D0D0 0000 0000 0000 0000 0000 100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5000 C500 110: C5E7 CC8B 0000 0000 0000 0000 0000 0000 0000 405C 120: 401C 0000 0000 0000 0000 0000 0000 0000 0021 6DB0 130: 7470 6DB0 7470 2020 0002 0140 0100 5000 3C06 3C0A 140: 0000 0078 0000 0008 0000 0000 FDFF 0280 0000 0000 150: 0008 0000 0000 0000 0000 8000 0000 0184 9400 8000 160: 0000 0000 0000 0000 0000 0000 0000 0000 0002 0000 170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 200: 0000 0000 0000 0000 0000 0000 10BD 0000 0000 4000 210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000 220: 0000 0000 107F 0000 0000 0000 0000 0000 0000 0000 230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000 240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 250: 0000 0000 0000 0000 0000 85A5 -- SMART_READ_DATA --------------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 20 00 01 2F 00 4B 3F 28 92 7B 02 00 00 00 03 23 010: 00 61 61 00 00 00 00 00 00 00 04 32 00 64 64 45 020: 03 00 00 00 00 00 05 33 00 64 64 00 00 00 00 00 030: 00 00 07 2F 00 40 3C 48 08 2E 00 00 00 00 09 32 040: 00 64 64 58 03 00 00 00 00 00 0A 33 00 64 64 00 050: 00 00 00 00 00 00 0C 32 00 64 64 3F 01 00 00 00 060: 00 00 B4 2A 00 64 64 19 DE 56 77 00 00 00 B7 32 070: 00 64 64 00 00 00 00 00 00 00 B8 33 00 64 64 00 080: 00 00 00 00 00 00 BB 32 00 64 64 00 00 00 00 00 090: 00 00 BC 32 00 64 64 00 00 00 00 00 00 00 BD 3A 0A0: 00 64 64 00 00 00 00 00 00 00 BE 22 00 48 3B 1C 0B0: 00 13 1C 00 00 00 C1 32 00 64 64 46 03 00 00 00 0C0: 00 00 C2 22 00 1C 0F 1C 00 00 00 0F 00 00 C3 3A 0D0: 00 15 05 28 92 7B 02 00 00 00 C4 32 00 64 64 00 0E0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00 0F0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 32 100: 00 C8 C8 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 37 02 00 53 170: 03 00 01 00 02 67 00 00 00 00 00 00 00 00 00 00 180: 00 00 02 00 31 0B 00 00 06 03 03 03 03 03 03 03 190: 03 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 D8 0F EE C0 CD 02 00 00 1B0: 00 00 00 00 01 00 CE 04 D7 77 BD BD 00 00 00 00 1C0: B6 63 57 49 00 00 00 00 00 00 00 00 17 49 04 00 1D0: 01 00 00 00 00 00 00 00 D1 00 00 00 06 00 00 00 1E0: 00 00 00 00 19 00 00 00 00 00 00 00 00 00 00 06 1F0: 00 00 00 00 00 00 00 00 00 00 14 16 00 00 00 5F -- SMART_READ_THRESHOLD ---------------------------------------------------- +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F 000: 20 00 01 06 00 00 00 00 00 00 00 00 00 00 03 00 010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 020: 00 00 00 00 00 00 05 0A 00 00 00 00 00 00 00 00 030: 00 00 07 1E 00 00 00 00 00 00 00 00 00 00 09 00 040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00 050: 00 00 00 00 00 00 0C 00 00 00 00 00 00 00 00 00 060: 00 00 B4 00 00 00 00 00 00 00 00 00 00 00 B7 00 070: 00 00 00 00 00 00 00 00 00 00 B8 61 00 00 00 00 080: 00 00 00 00 00 00 BB 00 00 00 00 00 00 00 00 00 090: 00 00 BC 00 00 00 00 00 00 00 00 00 00 00 BD 00 0A0: 00 00 00 00 00 00 00 00 00 00 BE 28 00 00 00 00 0B0: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00 0C0: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C3 00 0D0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00 0E0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00 0F0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00 100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 |
15.05.2021, 22:46 | #10 | |
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst] Und wie sieht es mit dem erfragten Kaufdatum aus? Zitat:
https://www.microsoft.com/de-de/soft...d/windows10ISO Steht aber auch alles so in der verlinkten Anleitung zur Neuinstallation beschrieben. Geändert von mmk (15.05.2021 um 22:52 Uhr) |
15.05.2021, 22:57 | #11 |
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst] Hier:https://www.microsoft.com/de-de/software-download/windows10 kriegst du ganz offiziell die neueste Version von Windows 10 als iso Datei die du dann nur mit dem Creation Tool oder mit Rufus bootfähig auf einen USB Stick machen/brennen musst der grösser als 4 GB ist und damit kannst du dann Windows 10 nach der Anleitung des TB neu installieren.
__________________ Windows 10 64 Pro 22H2 |
16.05.2021, 08:49 | #12 |
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst] Die Frage nach der Garantie ist immer noch nicht beantwortet. Das Gerät hat einen i5 der 10. Generation, muss also ziemlich neu sein. Und?
__________________ +++ +++ Reh-Animation: Mann mit Herzstillstand wird durch tanzende Waldtiere ins Leben zurückgerufen +++ +++ https://www.der-postillon.com/search/label/Newsticker |
16.05.2021, 09:08 | #13 | |
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst]Zitat:
|
16.05.2021, 09:29 | #14 | ||
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst]Zitat:
seit weit über 10 Jahren wird davon abgeraten PS: frisch gewienert Zitat:
__________________ Glaub ja nicht, was du denkst, wer ich bin |
16.05.2021, 10:27 | #15 |
| Windows 10: Bluescreen in unregelmäßigen abständen [gelöst] Solche "Wundertools" wie CCleaner gehören eindeutig in die Kategorie "Software, die die Welt nicht braucht" Um so erstaunlicher, dass dieser Ramsch in Foren immer noch von Usern (meist selbst ernannte Experten) empfohlen wird. Solche Stümper gehören zensiert.
__________________ Zorin OS 17.2 Core Geändert von PC_User (16.05.2021 um 10:52 Uhr) |
Themen zu Windows 10: Bluescreen in unregelmäßigen abständen |
administrator, bluescreen, defender, entfernen, geforce, home, internet, microsoft, neu, nvcontainer, nvcontainer.exe, nvidia, ordner, problem, prozesse, realtek, registry, rundll, scan, software, sound, system, system32, treiber, update, updates, windows |