![]() |
|
Log-Analyse und Auswertung: HTML Datei mit Wacatac.B! ausgeführt, noch keine Symptome, was kann ich ausser MSWD noch tun?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() HTML Datei mit Wacatac.B! ausgeführt, noch keine Symptome, was kann ich ausser MSWD noch tun? Hallihallo, habe soeben meine Rechnungen durchgearbeitet und praktischerweise war die vermeintliche Mail von Ionos eine mit Rechnung, die ich im Mordsstress - was ich NIE tue - prompt geöffnet habe... War eine HTML Datei mit dem Script/Wacatac.B! Trojaner drin. Habe den Windows Defender ausgeführt, er hat ihn auch sogleich erkannt und entfernt. Jetzt habe ich allerdings seitdem noch nichts gemacht, auch nicht neugestartet - ich habe ein bisschen Angst, dass ich mir da jetzt einen fetten Keylogger, Kryptoware oder sonstwas geladen habe und das im System sitzt. Was könnte ich jetzt sinnvolles tun, um eine Infektion oder Verbreitung zu verhindern? Vielen Dank schonmal für jegliche Hilfe! Hier sind schonmal meine Logs aus dem FRST als Anhang weil zu groß. Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11-05-2022 durchgeführt von hoodvisions (Administrator) auf HOODVISIONS-PC (Micro-Star International Co., Ltd. MS-7C91) (16-05-2022 10:08:41) Gestartet von E:\downloads Geladene Profile: hoodvisions Plattform: Microsoft Windows 10 Pro Version 20H2 19042.746 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: Chrome Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe (C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe ->) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe ->) (Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe <2> (C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe (C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe ->) (Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe (C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe ->) (Tobii AB -> Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Interaction.exe (C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe ->) (Tobii AB -> Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Tray.exe (C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe ->) (Tobii AB -> Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX\Tobii.EyeX.Engine.exe (C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe ->) (Electronic Arts, Inc. -> The Qt Company Ltd.) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\QtWebEngineProcess.exe <2> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe (C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe (C:\Program Files\WindowsApps\Microsoft.GamingApp_2204.1001.3.0_x64__8wekyb3d8bbwe\XboxAppServices.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCopyAccelerator.exe (Creative Technology Ltd -> Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\Creative Audio Task\CTAudTsk.exe (Creative Technology Ltd -> Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\Creative HID Task\CTHIDTsk.exe (Creative Technology Ltd) [Datei ist nicht signiert] C:\Program Files (x86)\Creative\BlasterX Acoustic Engine Pro\BlasterX Acoustic Engine Pro\BlasterX.exe (Discord Inc. -> Discord Inc.) C:\Users\hoodvisions\AppData\Local\Discord\app-1.0.9004\Discord.exe <7> (E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe ->) (Adobe Systems Incorporated -> ) E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Required\Plug-ins\Spaces\Adobe Spaces Helper.exe <3> (E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe <6> (E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe ->) (Node.js Foundation -> Node.js) E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\node.exe (E:\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) E:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (explorer.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) [Datei ist nicht signiert] E:\Photoshop_CC_hmm\installiert\Adobe Photoshop CC 2019\Photoshop.exe (explorer.exe ->) (Atheros Communications Inc. -> Atheros Commnucations) [Datei ist nicht signiert] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <36> (explorer.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2204.1001.3.0_x64__8wekyb3d8bbwe\XboxAppServices.exe (explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe <3> (explorer.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe (explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe (explorer.exe ->) (SatoshiLabs, s.r.o. -> ) C:\Program Files (x86)\TREZOR Bridge\trezord.exe (explorer.exe ->) (Signal Messenger, LLC -> Signal Messenger, LLC) C:\Users\hoodvisions\AppData\Local\Programs\signal-desktop\Signal.exe <5> (explorer.exe ->) (Signify Netherlands B.V. -> Signify Netherlands B.V.) C:\Program Files\Hue Sync\HueSync.exe (explorer.exe ->) (Spotify AB -> Spotify Ltd) C:\Users\hoodvisions\AppData\Roaming\Spotify\Spotify.exe <6> (explorer.exe ->) (Valve Corp. -> Valve Corporation) E:\Steam\steam.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe (Intel Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (services.exe ->) () [Datei ist nicht signiert] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe (services.exe ->) (Acronis International GmbH -> Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (services.exe ->) (Acronis International GmbH -> Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (services.exe ->) (Acronis International GmbH -> Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (services.exe ->) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\BrYNSvc.exe (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) E:\Program Files (x86)\Origin\OriginWebHelperService.exe (services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe (services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\101.0.4951.13\remoting_host.exe <2> (services.exe ->) (Hi-Rez Studios) [Datei ist nicht signiert] E:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (services.exe ->) (Intel(R) Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2> (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.65.8001.0_x64__8wekyb3d8bbwe\gamingservices.exe (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_3.65.8001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®) C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSIRegister\MSIRegisterService.exe (services.exe ->) (Nefarius Software Solutions) [Datei ist nicht signiert] E:\BetterJoyForCemu\Drivers\HidCerberus.Srv\HidCerberus.Srv.exe (services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe (services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4> (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe (services.exe ->) (Parsec Cloud, Inc. -> Parsec) C:\Program Files\Parsec\pservice.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe (services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe (services.exe ->) (Synology Inc. -> ) C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (services.exe ->) (Tobii AB -> Tobii AB) C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe (services.exe ->) (Tobii AB -> Tobii AB) C:\Windows\System32\DriverStore\FileRepository\tobii_generic.inf_amd64_c21b62cacea99033\TobiiVirtualDevice.exe (services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (svchost.exe ->) (Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\hoodvisions\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2204.1001.3.0_x64__8wekyb3d8bbwe\XboxPcApp.exe (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [Datei ist nicht signiert] HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [571192 2014-08-14] (Acronis International GmbH -> Acronis) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-05-11] (Apple Inc. -> Apple Inc.) HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3183328 2022-03-12] (Riot Games, Inc. -> Riot Games, Inc.) HKLM\...\Run: [] => [X] HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Datei ist nicht signiert] HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5380368 2015-07-20] (Acronis International GmbH -> Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [693336 2015-07-20] (Acronis International GmbH -> Acronis International GmbH) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation) [Datei ist nicht signiert] HKLM-x32\...\Run: [FLxHCIm64] => C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [56952 2015-09-11] (Fresco Logic Inc -> Windows (R) Win 7 DDK provider) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2016-02-03] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [Creative Audio Task] => C:\Program Files (x86)\Creative\Shared Files\Creative Audio Task\CTAudTsk.exe [123848 2016-03-03] (Creative Technology Ltd -> Creative Technology Ltd) HKLM-x32\...\Run: [Creative HID Task] => C:\Program Files (x86)\Creative\Shared Files\Creative HID Task\CTHIDTsk.exe [104392 2016-02-10] (Creative Technology Ltd -> Creative Technology Ltd) HKLM-x32\...\Run: [BlasterX Acoustic Engine Pro] => C:\Program Files (x86)\Creative\BlasterX Acoustic Engine Pro\BlasterX Acoustic Engine Pro\BlasterX.exe [1138176 2017-07-11] (Creative Technology Ltd) [Datei ist nicht signiert] HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [26327864 2021-04-08] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) HKLM-x32\...\Run: [MSIRegister] => C:\Program Files (x86)\MSI\MSIRegister\MSIRegister.exe [1266864 2019-08-28] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) HKU\S-1-5-21-3227405742-4072025680-4140124765-1000\...\Run: [Google Update] => C:\Users\hoodvisions\AppData\Local\Google\Update\1.3.36.132\GoogleUpdateCore.exe [227512 2022-04-21] (Google LLC -> Google LLC) HKU\S-1-5-21-3227405742-4072025680-4140124765-1000\...\Run: [HueSync] => C:\Program Files\Hue Sync\HueSync.exe [20274256 2022-03-10] (Signify Netherlands B.V. -> Signify Netherlands B.V.) HKU\S-1-5-21-3227405742-4072025680-4140124765-1000\...\Run: [] => [X] HKU\S-1-5-21-3227405742-4072025680-4140124765-1000\...\Run: [Spotify] => C:\Users\hoodvisions\AppData\Roaming\Spotify\Spotify.exe [19687400 2022-05-13] (Spotify AB -> Spotify Ltd) HKU\S-1-5-21-3227405742-4072025680-4140124765-1000\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3532928 2022-05-07] (Razer USA Ltd. -> Razer Inc.) HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3532928 2022-05-07] (Razer USA Ltd. -> Razer Inc.) HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [55872 2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc) HKLM\...\Print\Monitors\EPSON XP-312 313 315 Series 64MonitorBE: C:\Windows\system32\E_ILMBLFE.DLL [179712 2013-10-22] (SEIKO EPSON CORPORATION) [Datei ist nicht signiert] HKLM\Software\Microsoft\Active Setup\Installed Components: [{401C381F-E0DE-4B85-8BD8-4F3F14FBDA57}] -> C:\Program Files (x86)\Microsoft\Edge Dev\Application\103.0.1253.0\Installer\setup.exe [2022-05-12] (Microsoft Corporation -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\101.0.4951.54\Installer\chrmstp.exe [2022-05-06] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TREZOR Bridge.lnk [2020-01-28] ShortcutTarget: TREZOR Bridge.lnk -> C:\Program Files (x86)\TREZOR Bridge\trezord.exe (SatoshiLabs, s.r.o. -> ) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {018FF5C6-1C94-4909-9C2C-7444E21E1065} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {07828500-7394-4BAA-96A3-8D5E6EFF9100} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22894544 2022-05-14] (Microsoft Corporation -> Microsoft Corporation) Task: {089ED678-A30B-4E56-8FF6-CE01415510F2} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -SqlLiteRecoveryTask (Keine Datei) Task: {0B1D9F45-2936-47CD-858F-E021B3A0EBD5} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (Keine Datei) Task: {0C586C21-72D8-4871-ADAF-6F54ADC00F65} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (Keine Datei) Task: {0E8F979B-AC70-48E4-A55F-96BD0D9461C5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {0FDFCF75-1E25-477D-8372-9A8064E176AF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {12EB0865-7EF7-4F35-9593-040908AC90D6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.) Task: {18BDD9C6-B6FF-4D47-9FDF-8304789DEE0E} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {1938539B-F5B7-4804-BD11-C7B2ED873F53} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1980B0A8-428D-4428-9546-507B63BAC4FA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {19963ED3-1A0B-4C02-9765-4E713A2060BC} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-info@hoodvisions.de => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {1DF61475-7462-49BA-B7E4-541EFFDB591C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2118352 2014-03-19] (Microsoft Corporation -> Microsoft Corporation) Task: {2CCE3FD6-7358-4B4D-A43D-FDFEEC3A0FB9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe -crl -hms -pscn 15 (Keine Datei) Task: {2ED7E7F3-2905-411C-9072-327B091481A2} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {3212BCD8-0428-4010-A860-081528B12E30} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Keine Datei <==== ACHTUNG Task: {370A6A65-9FC5-4E35-BCB2-632CD285E351} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1487568 2014-03-19] (Microsoft Corporation -> Microsoft Corporation) Task: {3C1DCFD9-0DED-4B14-9518-6ABB9FC68B3C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {4045F198-34A7-4B87-B7BC-DE707A8A7764} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1487568 2014-03-19] (Microsoft Corporation -> Microsoft Corporation) Task: {4334FCAF-8295-414E-9427-762A385545C2} - \Microsoft\Windows\UNP\RunCampaignManager -> Keine Datei <==== ACHTUNG Task: {4832BD64-E084-495F-900C-69763EC0D18F} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [677624 2019-11-21] (Advanced Micro Devices INC. -> ) Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB} Task: {48D16D17-5F91-413C-8448-CD402E542EC3} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {4E295815-E35F-4700-B3BE-563092D6B7B7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22894544 2022-05-14] (Microsoft Corporation -> Microsoft Corporation) Task: {53C2C50E-5BE8-465F-9AD4-49586794F689} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {55AD7D83-B4D9-4583-A8D5-7A648951F2C2} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe /RestartRecording (Keine Datei) Task: {56F21F33-EC61-4B27-8C89-BD4F16AA536A} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1173504 2015-04-15] () [Datei ist nicht signiert] Task: {57E87A57-551E-4F22-AE33-434785DC7791} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (Keine Datei) Task: {5B16C670-2638-4034-A2DA-013E3D619FB7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (Keine Datei) Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A} Task: {5D8A51A8-6EEF-49A1-9BAF-608F2D98BB3F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {5E00B6CF-0C24-4A51-BBBB-AAADE3E56D00} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {615242B6-5908-43EC-81DE-7543F9B85B8B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {62D401AA-9576-4FF8-B62D-9AF283F4C040} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe -PvrSchedule (Keine Datei) Task: {64D447EF-2C18-4B3B-BBBA-2F03450BA489} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000Core => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe [154440 2016-02-18] (Google Inc -> Google Inc.) Task: {65A3E34E-966F-4618-9211-83B79C66BB35} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {693B44C5-5666-492F-ABC9-0254097124CF} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {6BB3BCBA-D8AE-4DAF-8D11-97240476DC00} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe /DoReindexSearchRoot (Keine Datei) Task: {6E267334-5ED4-4161-9C61-765BBE08375C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-05-14] (Google Inc -> Google Inc.) Task: {7569560E-E2B2-4A61-9D93-7F3A05FB258A} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {75AFEE1F-7790-4A0B-94D9-F85A99E61BFC} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {9A15892B-1C44-4A03-B7D6-D9C58AE31F85} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE /EXE:"{9A15892B-1C44-4A03-B7D6-D9C58AE31F85}" /F:"Invitation" (Keine Datei) Task: {76E8CA63-6E5C-46C6-8D44-F8D9E2B707D3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {770261D4-DA50-4D75-B656-FC2E85465F42} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1551520 2015-05-14] (ASUSTeK Computer Inc. -> ) [Datei ist nicht signiert] Task: {78DF2635-98B7-4BE8-B6CA-969D5E1B35F7} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {7B216B86-6784-471E-9DE4-2C1DEDEE1141} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {7C9B02D7-69A5-4B91-8B87-C08638FA7C4E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1} Task: {80DDBBE3-D14B-4AF5-ACE6-4312C47BE42F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" Task: {80F9DCE8-71E7-4095-B885-7642E6B5CC5D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000UA => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe [154440 2016-02-18] (Google Inc -> Google Inc.) Task: {8261DE13-098D-4BE1-8CF5-72EA8B526489} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -ObjectStoreRecoveryTask (Keine Datei) Task: {827A3EA7-FC0A-4472-809D-12B18C04F57A} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [65448 2020-05-21] (Microsoft Corporation -> Microsoft) Task: {8EA966C7-4A72-4BE4-9786-30064D92D935} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoActivateWindowsSearch (Keine Datei) Task: {8F0474A9-A33A-4E85-8A38-332D39070812} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144816 2022-05-14] (Microsoft Corporation -> Microsoft Corporation) Task: {907B742B-939C-49A0-9DCF-64C12B31ECA6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969} Task: {90BCF7A6-EDE8-446F-AD94-06B39486AF71} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /PBDADiscovery (Keine Datei) Task: {92237578-0C44-4F4E-814F-0FC0ACFBB192} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316} Task: {9282F755-20A8-42DD-A347-10ABDD9133C0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe /DRMInit (Keine Datei) Task: {966B8F97-F37F-42AA-9C7F-653F704BA867} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {981E2700-C7EB-474F-BDF4-2F5C526A7E30} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {9841FA84-BF29-47EA-AE86-28C3E58AC2F8} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (Keine Datei) Task: {9F5A4BCF-949B-4E05-89AB-229E8666265D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000UA1d257dbf3eadeec => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe [154440 2016-02-18] (Google Inc -> Google Inc.) Task: {9F8B6ABF-BD9A-4CAF-B77E-90BE20C40BEE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (Keine Datei) Task: {A2C2AC95-6AAE-4008-852D-91D755A4E641} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32} Task: {A870D518-6D3F-43F5-8FBA-646BEEC88E80} - System32\Tasks\MSI_Toast_Server => C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe [31904 2019-03-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) Task: {AD6514E0-B836-40C6-A42A-1044B60F6DA4} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E} Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {B2878BFC-6D76-44EF-8B9A-EA9A41DB5D09} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61} Task: {B2CDCBA0-53F0-48F8-8F96-D8CE330770C1} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (Keine Datei) Task: {B39BD544-A3AE-4682-9C5E-3970C929DA52} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG Task: {B764F8F7-E1F9-47B8-A5C8-B030D861AC45} - System32\Tasks\EPSON XP-312 313 315 Series Update {FF92B4F2-C43D-4590-AF40-4573C31E5186} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE /EXE:"{FF92B4F2-C43D-4590-AF40-4573C31E5186}" /F:"Update" (Keine Datei) Task: {BC42543D-ED15-4EE2-A82F-D8DF67A544A7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144816 2022-05-14] (Microsoft Corporation -> Microsoft Corporation) Task: {C2E071C4-558E-4161-B828-4A9556A81AD0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {C58ADA2D-EDD3-4443-AE0E-282A47C5E4F7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000Core1d257dbf3e7a868 => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe [154440 2016-02-18] (Google Inc -> Google Inc.) Task: {C613293F-D2E9-4446-A241-F7E9B5A9EA30} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-05-14] (Google Inc -> Google Inc.) Task: {CC287F7F-D0BD-4DDF-A169-F287A2FE3833} - System32\Tasks\EPSON XP-312 313 315 Series Update {9A15892B-1C44-4A03-B7D6-D9C58AE31F85} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE /EXE:"{9A15892B-1C44-4A03-B7D6-D9C58AE31F85}" /F:"Update" (Keine Datei) Task: {D4157551-D494-42A7-8064-27A6A0DE1E1A} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {D7087DEB-FCBC-41EC-879D-BC4C9448DC42} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -PvrRecoveryTask (Keine Datei) Task: {D7638C2C-DDF7-4FC4-BB73-3F3FEC23D583} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe /OCURActivate (Keine Datei) Task: {D92E8445-FF42-4450-A73C-5F9C761ED9AF} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2118352 2014-03-19] (Microsoft Corporation -> Microsoft Corporation) Task: {DC29320C-1194-4768-A1F0-354C93B06236} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -MediaCenterRecoveryTask (Keine Datei) Task: {E5D16544-21D3-4C41-B3EE-CD8C7C046B5A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe $(Arg0) (Keine Datei) Task: {E7F5E9A5-D005-49D8-B45E-4F876211D765} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {FF92B4F2-C43D-4590-AF40-4573C31E5186} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE /EXE:"{FF92B4F2-C43D-4590-AF40-4573C31E5186}" /F:"Invitation" (Keine Datei) Task: {E94D6678-2547-4D44-8871-DCE694D55EE8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (Keine Datei) Task: {EB4EDA16-1CD0-4B87-9949-1D68C696822D} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2211024 2014-03-19] (Microsoft Corporation -> Microsoft) Task: {F3F2F804-AAD4-408D-BF00-5CA71816DB24} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {F8400061-E64E-448C-8675-C533C4608FD0} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {FA34EF32-636A-4DEC-A129-890DEBF6C968} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe -pscn 0 (Keine Datei) Task: {FA5D0E61-B13F-4364-A66B-89EC3F1AE13D} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [61336 2022-04-29] (Microsoft Corporation -> Microsoft Corporation) Task: {FAF142E0-C2D0-4643-894B-4600D6CCE847} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\EPSON XP-312 313 315 Series Invitation {9A15892B-1C44-4A03-B7D6-D9C58AE31F85}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE Task: C:\WINDOWS\Tasks\EPSON XP-312 313 315 Series Invitation {FF92B4F2-C43D-4590-AF40-4573C31E5186}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE Task: C:\WINDOWS\Tasks\EPSON XP-312 313 315 Series Update {9A15892B-1C44-4A03-B7D6-D9C58AE31F85}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE:/EXE:{9A15892B-1C44-4A03-B7D6-D9C58AE31F85} /F:UpdateARBEITSGRUPPE\HOODVISIONS-PC$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON XP-312 313 315 Series Update {FF92B4F2-C43D-4590-AF40-4573C31E5186}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE:/EXE:{FF92B4F2-C43D-4590-AF40-4573C31E5186} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000Core.job => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000UA.job => C:\Users\hoodvisions\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ACHTUNG (Beschränkung - Zones) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.206 192.168.2.1 Tcpip\..\Interfaces\{2484227b-7903-471c-a3db-67e991b32794}: [DhcpNameServer] 192.168.2.206 192.168.2.1 Tcpip\..\Interfaces\{a306c492-1c35-458a-aa61-dc3f4347ef4a}: [DhcpNameServer] 192.168.2.206 192.168.2.1 Tcpip\..\Interfaces\{acd3bbc8-26ce-4460-80a9-7e2f99334ce9}: [DhcpNameServer] 192.168.2.206 192.168.2.1 Edge: ======= Edge Profile: C:\Users\hoodvisions\AppData\Local\Microsoft\Edge\User Data\Default [2022-05-06] StartMenuInternet: Microsoft Edge Dev - C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe FireFox: ======== FF DefaultProfile: cz4kyyrb.default-1510951611533 FF ProfilePath: C:\Users\hoodvisions\AppData\Roaming\Mozilla\Firefox\Profiles\cz4kyyrb.default-1510951611533 [2022-05-13] FF Homepage: Mozilla\Firefox\Profiles\cz4kyyrb.default-1510951611533 -> hxxps://www.google.de/?gws_rd=ssl FF Session Restore: Mozilla\Firefox\Profiles\cz4kyyrb.default-1510951611533 -> ist aktiviert. FF Extension: (uBlock Origin) - C:\Users\hoodvisions\AppData\Roaming\Mozilla\Firefox\Profiles\cz4kyyrb.default-1510951611533\Extensions\uBlock0@raymondhill.net.xpi [2021-11-19] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2016-04-13] [] [ist nicht signiert] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (Electronic Arts -> EA Digital Illusions CE AB) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-04-06] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] (Apple Inc. -> ) FF Plugin-x32: @D-Link.com/camclictrl -> C:\Program Files (x86)\D-Link\Plugin\npCamCliCtrl.dll [2013-10-11] (D-LINK CORPORATION -> D-Link Corp.) [Datei ist nicht signiert] FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (Electronic Arts -> EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-06] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> e:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> e:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> e:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.7 -> e:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> e:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3227405742-4072025680-4140124765-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\hoodvisions\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-18] (Unity Technologies ApS -> Unity Technologies ApS) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default [2022-05-16] CHR DownloadDir: E:\downloads CHR Notifications: Default -> hxxps://ibb.queue-it.net CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn","hxxp://www.google.com" CHR Session Restore: Default -> ist aktiviert. CHR Extension: (Ledger Manager) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\beimhnaefocolcplfimocfiaiefpkgbf [2020-07-27] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-05-20] CHR Extension: (DuckDuckGo) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2022-04-27] CHR Extension: (uBlock Origin) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-04-08] CHR Extension: (Tampermonkey) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2022-05-13] CHR Extension: (Google Kalender) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-06] CHR Extension: (minerBlock) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\emikbbbebcdfohonlaifafnoanocnebl [2021-02-02] CHR Extension: (Google Play Musik) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2020-11-20] CHR Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2021-07-16] CHR Extension: (Window Resizer) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgcikanifihhgnacepigehgmplgkkgcl [2020-04-23] CHR Extension: (Tracking Time | Button) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\fglmkdhomaklnckgbjfnfmbfmlkjippg [2022-05-10] CHR Extension: (Stylish- Benutzerdef. Motive f. jede Webseite) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2022-04-28] CHR Extension: (Authy) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb [2020-03-30] CHR Extension: (Chrome Remote Desktop) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-19] CHR Extension: (LastPass: Free Password Manager) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2022-04-28] CHR Extension: (Ledger Wallet Ethereum) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmlhkialjkaldndjnlcdfdphcgeadkkm [2019-03-20] CHR Extension: (Cookie Editor) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\iphcomljdfghbkdcfndaijbokpgddeno [2020-09-08] CHR Extension: (WhatFont) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-05-09] CHR Extension: (TREZOR Chrome Extension) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcjjhjgimijdkoamemaghajlhegmoclj [2017-12-13] CHR Extension: (Tag Assistant Legacy (by Google)) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2021-09-24] CHR Extension: (Ledger Wallet Bitcoin) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdpmhnladdopljabkgpacgpliggeeaf [2020-07-27] CHR Extension: (Locale Switcher) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\kngfjpghaokedippaapkfihdlmmlafcc [2022-03-21] CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2022-04-06] CHR Extension: (Moqups · Mockups, Wireframes & Prototypenentwicklung) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlfbhphohgafllkjnakmdppmmkjfbnke [2017-10-18] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Ubersuggest - SEO und Keywordrecherche) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpgaoofmjlimabncmnmnopjabbflegf [2022-05-04] CHR Extension: (ColorPick Eyedropper) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohcpnigalekghcmgcdcenkpelffpdolg [2022-01-14] CHR Extension: (Material Simple Dark Grey) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Default\Extensions\ookepigabmicjpgfnmncjiplegcacdbm [2018-12-12] CHR Profile: C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-09-11] CHR Notifications: Profile 1 -> hxxps://mail.google.com CHR DefaultSearchURL: Profile 1 -> hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Profile 1 -> Yahoo CHR DefaultSuggestURL: Profile 1 -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Session Restore: Profile 1 -> ist aktiviert. CHR Extension: (Präsentationen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-09] CHR Extension: (Docs) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-09] CHR Extension: (Google Drive) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-07-09] CHR Extension: (YouTube) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-09] CHR Extension: (uBlock Origin) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-07-26] CHR Extension: (Full Page Screen Capture) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdpohaocaechififmbbbbbknoalclacl [2019-08-02] CHR Extension: (Tabellen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-09] CHR Extension: (Chrome Remote Desktop) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-22] CHR Extension: (Google Docs Offline) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-07-10] CHR Extension: (Find & Replace for Text Editing) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jajhdmnpiocpbpnlpejbgmpijgmoknnl [2019-07-09] CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2019-07-09] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-07-09] CHR Extension: (Google Mail) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-09] CHR Extension: (Chrome Media Router) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-09] CHR Profile: C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2 [2021-01-12] CHR Extension: (Präsentationen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-01-12] CHR Extension: (Docs) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2021-01-12] CHR Extension: (Google Drive) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-01-12] CHR Extension: (YouTube) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-01-12] CHR Extension: (Tabellen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-01-12] CHR Extension: (Google Docs Offline) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-01-12] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-12] CHR Extension: (Google Mail) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-01-12] CHR Extension: (Chrome Media Router) - C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-01-12] CHR Profile: C:\Users\hoodvisions\AppData\Local\Google\Chrome\User Data\System Profile [2021-01-12] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM-x32\...\Chrome\Extension: [ibbfklbaljofpaanmpaeadejijfdddco] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1264472 2014-08-14] (Acronis International GmbH -> Acronis) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.) R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [4029432 2015-07-22] (Acronis International GmbH -> Acronis) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3849472 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3617024 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc. -> Apple Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8894752 2021-01-27] (BattlEye Innovations e.K. -> ) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [289792 2014-10-23] (Brother Industries, Ltd.) [Datei ist nicht signiert] R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\101.0.4951.13\remoting_host.exe [72024 2022-03-27] (Google LLC -> Google LLC) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11759056 2022-05-14] (Microsoft Corporation -> Microsoft Corporation) R2 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10725584 2022-05-13] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-02-22] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-03-28] (EasyAntiCheat Oy -> Epic Games, Inc.) S3 ElfoService; C:\Program Files (x86)\ElsterFormular Update Service\bin\elfoService.exe [1115560 2021-04-10] (Bayerisches Landesamt fuer Steuern -> ) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2022-03-03] (Epic Games Inc. -> Epic Games, Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342240 2015-11-05] (FUTUREMARK INC -> Futuremark) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1955680 2021-08-18] (GOG Sp. z o.o. -> GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2021-08-18] (GOG Sp. z o.o. -> GOG.com) R2 HidCerberus.Srv; E:\BetterJoyForCemu\Drivers\HidCerberus.Srv\HidCerberus.Srv.exe [600064 2017-06-28] (Nefarius Software Solutions) [Datei ist nicht signiert] U2 HiPatchService; E:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-09-23] (Hi-Rez Studios) [Datei ist nicht signiert] S2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [Datei ist nicht signiert] S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Datei ist nicht signiert] R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Datei ist nicht signiert] S3 MicrosoftEdgeDevElevationService; C:\Program Files (x86)\Microsoft\Edge Dev\Application\103.0.1253.0\elevation_service.exe [1714592 2022-05-10] (Microsoft Corporation -> Microsoft Corporation) R2 MSIREGISTER_MR; C:\Program Files (x86)\MSI\MSIRegister\MSIRegisterService.exe [2019504 2019-08-28] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2210104 2021-04-08] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2021-06-07] (nordvpn s.a. -> TEFINCOM S.A.) R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [281464 2021-06-09] (nordvpn s.a. -> TEFINCOM S.A.) S3 Origin Client Service; E:\Program Files (x86)\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; E:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts) S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [146608 2022-04-19] (Oculus VR, LLC -> Facebook Technologies, LLC) R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [513200 2022-04-19] (Oculus VR, LLC -> Facebook Technologies, LLC) R2 Parsec; C:\Program Files\Parsec\pservice.exe [394256 2021-04-21] (Parsec Cloud, Inc. -> Parsec) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2015-07-23] (Even Balance, Inc. -> ) R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [2029544 2022-03-31] (Razer USA Ltd. -> Razer Inc.) R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [464928 2022-03-31] (Razer USA Ltd. -> Razer Inc.) R2 Razer Chroma Stream Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe [1349688 2022-02-03] (Razer USA Ltd. -> Razer Inc.) R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [254224 2021-11-16] (Razer USA Ltd. -> Razer Inc) R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [299136 2022-05-06] (Razer USA Ltd. -> Razer Inc.) S3 Rockstar Service; E:\RockstarGames\RockstarService.exe [1631360 2020-12-09] (Rockstar Games, Inc. -> Rockstar Games) R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [533824 2022-02-18] (Razer USA Ltd. -> Razer Inc.) R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [291320 2021-11-25] (Razer USA Ltd. -> Razer Inc.) S3 SandraAgentSrv; E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\RpcAgentSrv.exe [73200 2015-02-15] (SiSoftware SPC -> SiSoftware) [Datei ist nicht signiert] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Datei ist nicht signiert] R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [6857752 2014-09-13] (Acronis International GmbH -> Acronis) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 tmHInstall; C:\Program Files\Thrustmaster\TM Flight Series\drivers\amd64\tmHInstall.exe [110608 2020-07-31] (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®) R2 Tobii Service; C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe [202088 2019-08-29] (Tobii AB -> Tobii AB) R2 TobiiGeneric; C:\WINDOWS\System32\DriverStore\FileRepository\tobii_generic.inf_amd64_c21b62cacea99033\TobiiVirtualDevice.exe [320736 2020-11-17] (Tobii AB -> Tobii AB) S3 TwitchService; C:\Program Files\Common Files\Twitch\TwitchService.exe [331648 2021-05-29] (Twitch Interactive, Inc. -> ) S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Uncheater\ucldr_battlegrounds_gl.exe [6969856 2021-01-27] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [253912 2019-10-30] (Synology Inc. -> ) S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [692992 2019-05-13] (Oracle Corporation -> Oracle Corporation) S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [10401912 2022-03-12] (Riot Games, Inc. -> Riot Games, Inc.) S3 wampapache64; e:\wamp64\bin\apache\apache2.4.41\bin\httpd.exe [29696 2019-08-09] (Apache Software Foundation) [Datei ist nicht signiert] S3 wampmariadb64; e:\wamp64\bin\mariadb\mariadb10.4.10\bin\mysqld.exe [15837608 2019-11-07] (MariaDB Corporation Ab -> ) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [7023744 2021-01-27] (PUBG CORPORATION -> PUBG Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] (ASUSTeK Computer Inc. -> ) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2014-02-25] (ASUSTeK Computer Inc. -> ) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Datei ist nicht signiert] S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [75560 2017-05-25] (Broadcom Corporation -> Broadcom Corporation.) R3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider) S3 chdrvr01; C:\WINDOWS\System32\drivers\chdrvr01.sys [248496 2012-08-25] (Joystick Technologies LLC -> CH Products) S3 chdrvr02; C:\WINDOWS\System32\drivers\chdrvr02.sys [11440 2012-08-25] (Joystick Technologies LLC -> CH Products) S3 chdrvr03; C:\WINDOWS\System32\drivers\chdrvr03.sys [24240 2012-08-25] (Joystick Technologies LLC -> CH Products) R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [296736 2015-05-20] (Acronis International GmbH -> Acronis International GmbH) R0 fltsrv; C:\WINDOWS\System32\DRIVERS\fltsrv.sys [134432 2015-05-20] (Acronis International GmbH -> Acronis International GmbH) R3 HidEmulator; C:\WINDOWS\System32\drivers\HidEmulator.sys [14200 2014-10-02] (Leap Motion Inc -> Leap Motion, Inc.) R3 HidEmulatorKmdf; C:\WINDOWS\System32\drivers\HidEmulatorKmdf.sys [28152 2014-10-02] (Leap Motion Inc -> ) S3 HidGuardian; C:\WINDOWS\System32\drivers\HidGuardian.sys [37280 2017-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer) R3 KsUSBa64; C:\WINDOWS\system32\drivers\ksUSBa64.sys [1671656 2017-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) S3 MpKsl26a0cab2; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{36F39C35-8058-468A-B1D9-394E3DE300AE}\MpKslDrv.sys [137464 2022-05-16] (Microsoft Windows -> Microsoft Corporation) S3 MpKsl4232ca6e; C:\WINDOWS\system32\MpEngineStore\MpKslDrv.sys [137464 2022-05-11] (Microsoft Windows -> Microsoft Corporation) R3 mt7612US; C:\WINDOWS\System32\drivers\mt7612US.sys [377864 2015-12-09] (Windows Central Build Account - X -> MediaTek Inc.) R2 NDivert; C:\Program Files\NordVPN\6.45.8.0\Drivers\NDivert.sys [130424 2022-03-16] (nordvpn s.a. -> Nordvpn S.A.) S3 nlwt; C:\WINDOWS\System32\drivers\nlwt.sys [39360 2021-01-11] (TEFINCOM S.A. -> WireGuard LLC) R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [38608 2020-07-10] (TEFINCOM S.A. -> TEFINCOM S.A.) S3 npusbio; C:\WINDOWS\System32\Drivers\npusbio_x64.sys [38400 2015-12-14] (NaturalPoint, Inc -> ) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation) R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [72208 2020-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2020-06-23] (Oculus VR, LLC -> Facebook Inc.) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [54632 2021-03-30] (Razer USA Ltd. -> Razer Inc) R3 RzDev_0084; C:\WINDOWS\System32\drivers\RzDev_0084.sys [54152 2020-08-24] (Razer USA Ltd. -> Razer Inc) S3 SANDRA; E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\WNt600x64\Sandra.sys [23112 2009-08-07] (SiSoftware Ltd -> SiSoftware) R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software) S3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [48848 2020-09-25] (SteelSeries ApS -> SteelSeries ApS) R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-28] (Valve Corp. -> ) R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] (Valve Corp. -> ) R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project) R2 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1058632 2015-07-22] (Acronis International GmbH -> Acronis International GmbH) R2 tib_mounter; C:\WINDOWS\System32\DRIVERS\tib_mounter.sys [248648 2015-07-22] (Acronis International GmbH -> Acronis International GmbH) S3 uvhid; C:\WINDOWS\System32\drivers\uvhid.sys [27064 2016-03-22] (Unified Intents AB -> Windows (R) Win 7 DDK provider) S3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [236352 2019-05-13] (Oracle Corporation -> Oracle Corporation) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [247736 2019-05-13] (Oracle Corporation -> Oracle Corporation) R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [8508504 2022-03-11] (Riot Games, Inc. -> Riot Games, Inc.) R3 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [69168 2020-01-10] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer) S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [52592 2015-09-23] (Cisco Systems, Inc. -> Cisco Systems, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-04-08] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [443664 2022-04-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-08] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\WINDOWS\system32\DRIVERS\wintun.sys [29592 2022-03-12] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 xhunter1; C:\WINDOWS\xhunter1.sys [2742720 2021-01-27] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 cmudaxp; \SystemRoot\system32\drivers\cmudaxp.sys [X] U3 idsvc; kein ImagePath S3 VBAudioVACMME; \SystemRoot\System32\drivers\vbaudio_cable64_win7.sys [X] S3 wacomrouterfilter; \SystemRoot\System32\drivers\wacomrouterfilter.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2022-05-16 10:08 - 2022-05-16 10:09 - 000000000 ____D C:\FRST 2022-05-16 09:58 - 2022-05-16 09:58 - 000000000 ___HD C:\$WinREAgent 2022-05-16 09:57 - 2022-05-16 09:57 - 001003137 ____N C:\WINDOWS\Minidump\051622-32109-01.dmp 2022-05-13 13:15 - 2022-05-05 03:00 - 000047792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll 2022-05-13 12:20 - 2022-05-13 12:20 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Necesse 2022-05-13 10:00 - 2022-05-06 00:39 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2022-05-13 10:00 - 2022-05-06 00:39 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo.exe 2022-05-13 10:00 - 2022-05-06 00:39 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2022-05-13 10:00 - 2022-05-06 00:39 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2022-05-13 10:00 - 2022-05-06 00:38 - 001467992 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2022-05-13 10:00 - 2022-05-06 00:38 - 001432328 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2022-05-13 10:00 - 2022-05-06 00:38 - 001432328 _____ C:\WINDOWS\system32\vulkan-1.dll 2022-05-13 10:00 - 2022-05-06 00:38 - 001209400 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2022-05-13 10:00 - 2022-05-06 00:38 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2022-05-13 10:00 - 2022-05-06 00:38 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2022-05-13 10:00 - 2022-05-06 00:35 - 000724688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2022-05-13 10:00 - 2022-05-06 00:35 - 000586432 _____ C:\WINDOWS\system32\nvofapi64.dll 2022-05-13 10:00 - 2022-05-06 00:35 - 000461384 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 002120928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 001602248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 001529552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 001178184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 000731224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2022-05-13 10:00 - 2022-05-06 00:34 - 000713304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2022-05-13 10:00 - 2022-05-06 00:34 - 000581856 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 006963928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 006226648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 005729880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 005100768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 002932960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2022-05-13 10:00 - 2022-05-06 00:33 - 000458808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2022-05-13 10:00 - 2022-05-06 00:32 - 000851144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2022-05-13 10:00 - 2022-05-05 03:00 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb 2022-05-13 09:19 - 2022-05-13 09:19 - 000923097 ____N C:\WINDOWS\Minidump\051322-34250-01.dmp 2022-05-12 10:00 - 2022-05-12 10:00 - 000000028 ____H C:\.GamingRoot 2022-05-12 10:00 - 2022-05-12 10:00 - 000000000 ____D C:\XboxGames 2022-05-11 22:15 - 2022-05-11 22:15 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\JDGame 2022-05-11 19:34 - 2022-05-11 19:34 - 000879099 ____N C:\WINDOWS\Minidump\051122-30953-01.dmp 2022-05-11 10:13 - 2022-05-11 10:13 - 000000000 ____D C:\Users\hoodvisions\AppData\LocalLow\OddGiant 2022-05-11 09:56 - 2022-05-11 09:56 - 000000000 ____D C:\WINDOWS\system32\MpEngineStore 2022-05-10 16:12 - 2022-05-10 16:12 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\EOSInstallHelper 2022-05-10 09:59 - 2022-05-10 10:09 - 001265664 _____ C:\Users\hoodvisions\Documents\ok.de - Zeichnungsschein ok.de Corp. DE 6 Monate Haltefrist_hh_100522.indd 2022-05-10 09:59 - 2022-05-10 09:59 - 000892928 _____ C:\Users\hoodvisions\Documents\ok.de - Zeichnungsschein ok.de Corp. DE 6 Monate Haltefrist_100522.indd 2022-05-10 09:54 - 2022-05-10 09:56 - 001359872 _____ C:\Users\hoodvisions\Documents\ok.de - Zeichnungsschein ok.de Corp. DE 6 Monate Haltefrist_hh_030522.indd 2022-05-09 08:28 - 2022-05-09 08:28 - 000770977 ____N C:\WINDOWS\Minidump\050922-27031-01.dmp 2022-05-06 22:19 - 2022-05-06 22:19 - 000894353 ____N C:\WINDOWS\Minidump\050622-27828-01.dmp 2022-05-06 09:51 - 2022-05-06 09:51 - 001835427 ____N C:\WINDOWS\Minidump\050622-30765-01.dmp 2022-05-05 15:04 - 2022-05-15 01:32 - 000003152 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner 2022-05-05 14:07 - 2022-05-13 15:34 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2022-05-05 14:07 - 2022-05-05 14:07 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2022-05-05 12:35 - 2022-05-05 12:35 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\BMIBenchMark 2022-05-05 12:29 - 2022-05-05 12:29 - 000001048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z.lnk 2022-05-05 12:29 - 2022-05-05 12:29 - 000001036 _____ C:\Users\Public\Desktop\TechPowerUp GPU-Z.lnk 2022-05-05 12:29 - 2022-05-05 12:29 - 000000000 ____D C:\Program Files (x86)\GPU-Z 2022-05-05 09:44 - 2022-05-06 09:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2022-05-04 14:27 - 2022-05-06 09:50 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-05-04 13:05 - 2022-05-04 13:05 - 000092447 _____ C:\Users\hoodvisions\Documents\rg_musikant_tf_mai_2022.pdf 2022-05-04 13:04 - 2022-05-04 13:04 - 001382381 _____ C:\Users\hoodvisions\Documents\rechng_transparentfinanz_mai_2022.ai 2022-05-04 12:23 - 2022-05-04 12:23 - 000091480 _____ C:\Users\hoodvisions\Documents\rg_jmusikant_mai_2022.pdf 2022-05-04 12:11 - 2022-05-04 12:11 - 001379493 _____ C:\Users\hoodvisions\Documents\rechng_gaiapisauro_mai_2022.ai 2022-05-03 12:40 - 2022-05-03 12:45 - 007442432 _____ C:\Users\hoodvisions\Documents\digisell-Zeichnungsschein-DE-6-Monate-Haltefrist030522.indd 2022-05-03 12:00 - 2022-05-10 09:55 - 001368064 _____ C:\Users\hoodvisions\Documents\ok.de - Zeichnungsschein ok.de Corp. DE 6 Monate Haltefrist_030522.indd 2022-05-02 17:08 - 2022-05-02 17:08 - 000909947 ____N C:\WINDOWS\Minidump\050222-28703-01.dmp 2022-05-02 16:59 - 2022-05-02 17:02 - 001232896 _____ C:\Users\hoodvisions\Documents\ok.de - Zeichnungsschein ok.de Corp. DE 6 Monate Haltefrist_020522.indd 2022-05-02 08:36 - 2022-05-02 08:36 - 000021157 _____ C:\Users\hoodvisions\Documents\Bescheiddaten_Einkommensteuer_2021_1120045064608.pdf 2022-05-02 08:36 - 2022-05-02 08:36 - 000006350 _____ C:\Users\hoodvisions\Documents\Vergleich_Bescheiddaten_Einkommensteuer_2021_1120045064608.pdf 2022-05-02 08:20 - 2022-05-02 08:20 - 000878025 ____N C:\WINDOWS\Minidump\050222-27375-01.dmp 2022-04-29 21:51 - 2022-04-29 21:51 - 000000000 ____D C:\Users\hoodvisions\AppData\LocalLow\One Hamsa 2022-04-28 10:58 - 2022-04-28 10:58 - 000000000 _____ C:\WINDOWS\wiso.ini 2022-04-26 09:55 - 2022-04-26 09:55 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk 2022-04-26 09:55 - 2022-04-26 09:55 - 000000000 ____D C:\Program Files\PCHealthCheck 2022-04-23 23:02 - 2022-04-23 23:02 - 000000000 ____D C:\Users\hoodvisions\AppData\LocalLow\Cortopia Studios 2022-04-23 00:13 - 2022-04-23 00:13 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Home2 2022-04-21 10:12 - 2022-04-27 21:24 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Daedalic Entertainment GmbH 2022-04-21 10:12 - 2022-04-21 10:12 - 000000000 ____D C:\Users\hoodvisions\AppData\LocalLow\Daedalic Entertainment GmbH 2022-04-20 15:36 - 2022-04-20 15:58 - 028459008 _____ C:\Users\hoodvisions\Documents\ffpc_investorenbrief_de.indd 2022-04-20 15:14 - 2022-04-20 15:36 - 018427904 _____ C:\Users\hoodvisions\Documents\ffpc_invbestorenbrief.indd 2022-04-20 10:33 - 2022-04-20 10:33 - 001375918 _____ C:\Users\hoodvisions\Documents\rechng_ff24rent_apr_2022.ai 2022-04-20 10:33 - 2022-04-20 10:33 - 000091283 _____ C:\Users\hoodvisions\Documents\rg_musikant_ff24rent_apr_2022.pdf 2022-04-20 10:32 - 2022-04-20 10:32 - 001379102 _____ C:\Users\hoodvisions\Documents\rechng_dyh_apr_2022.ai 2022-04-20 10:32 - 2022-04-20 10:32 - 000092656 _____ C:\Users\hoodvisions\Documents\rg_musikant_dyh_apr_2022.pdf 2022-04-20 10:29 - 2022-04-20 10:30 - 000092144 _____ C:\Users\hoodvisions\Documents\rg_musikant_okde_apr_2022.pdf 2022-04-20 10:29 - 2022-04-20 10:29 - 001378462 _____ C:\Users\hoodvisions\Documents\rechng_okde_apr_2022.ai 2022-04-20 10:26 - 2022-04-20 10:27 - 000093854 _____ C:\Users\hoodvisions\Documents\rg_musikant_ff24_apr_2022.pdf 2022-04-20 10:26 - 2022-04-20 10:26 - 001382116 _____ C:\Users\hoodvisions\Documents\rechng_ff24_apr_2022.ai ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2022-05-16 10:05 - 2017-07-14 22:04 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\discord 2022-05-16 10:04 - 2020-07-27 09:35 - 001926382 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-05-16 10:04 - 2019-12-07 16:51 - 000824302 _____ C:\WINDOWS\system32\perfh007.dat 2022-05-16 10:04 - 2019-12-07 16:51 - 000178278 _____ C:\WINDOWS\system32\perfc007.dat 2022-05-16 10:04 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2022-05-16 10:03 - 2019-01-15 09:57 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Signal 2022-05-16 10:03 - 2015-05-15 08:19 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Adobe 2022-05-16 10:03 - 2015-05-14 17:21 - 000000000 ____D C:\Program Files (x86)\Google 2022-05-16 10:02 - 2017-11-17 22:46 - 000000000 ____D C:\Users\hoodvisions\AppData\LocalLow\Mozilla 2022-05-16 10:02 - 2017-05-16 20:20 - 000000000 ____D C:\ProgramData\NVIDIA 2022-05-16 10:00 - 2020-06-02 20:02 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat 2022-05-16 09:59 - 2015-07-27 19:15 - 000000000 ____D C:\ProgramData\Mozilla 2022-05-16 09:59 - 2015-05-15 14:22 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Spotify 2022-05-16 09:58 - 2021-01-13 22:08 - 000000000 ____D C:\WINDOWS\Minidump 2022-05-16 09:58 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2022-05-16 09:58 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-05-16 09:58 - 2017-07-14 22:04 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Discord 2022-05-16 09:58 - 2016-03-15 15:47 - 000000000 ____D C:\steamgames 2022-05-16 09:58 - 2015-05-15 14:22 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Spotify 2022-05-16 09:58 - 2015-05-14 20:50 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Oculus 2022-05-16 09:57 - 2020-07-27 09:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-05-16 09:57 - 2020-07-27 09:29 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-05-16 09:57 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-05-16 09:57 - 2016-06-29 20:00 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2022-05-15 01:06 - 2015-05-16 00:53 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\CrashDumps 2022-05-14 22:31 - 2020-05-19 08:37 - 000000000 ____D C:\Program Files\Microsoft Office 2022-05-14 22:25 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-05-14 22:22 - 2020-11-07 22:41 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-05-14 22:22 - 2020-11-07 22:41 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2022-05-14 22:22 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-05-13 22:26 - 2020-04-06 08:23 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Authy Desktop 2022-05-13 15:33 - 2019-12-07 11:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2022-05-13 15:30 - 2015-05-14 17:19 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\NVIDIA 2022-05-13 10:02 - 2015-05-15 09:25 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2022-05-13 09:58 - 2020-07-27 09:39 - 000004308 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003976 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003940 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003894 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2020-07-27 09:39 - 000003654 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2022-05-13 09:58 - 2017-05-16 20:20 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2022-05-13 09:58 - 2017-05-16 20:20 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2022-05-13 09:58 - 2017-05-16 20:20 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2022-05-13 09:58 - 2016-11-03 21:51 - 000001447 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2022-05-13 09:39 - 2019-10-04 21:40 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2022-05-13 09:19 - 2020-06-23 14:17 - 000000000 ____D C:\ProgramData\Oculus 2022-05-12 13:12 - 2017-10-20 19:04 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Packages 2022-05-12 13:12 - 2015-09-25 23:04 - 000000128 _____ C:\Users\hoodvisions\AppData\Roaming\winscp.rnd 2022-05-12 10:04 - 2015-05-14 17:53 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-05-12 10:00 - 2021-11-19 09:57 - 000132560 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll 2022-05-12 10:00 - 2020-05-04 18:00 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll 2022-05-12 10:00 - 2019-12-15 01:17 - 000394704 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll 2022-05-12 10:00 - 2019-11-13 20:50 - 002274768 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll 2022-05-12 10:00 - 2019-11-13 20:50 - 000222672 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll 2022-05-12 10:00 - 2019-11-13 20:50 - 000198096 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll 2022-05-12 10:00 - 2019-11-13 20:50 - 000062952 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe 2022-05-12 10:00 - 2015-05-14 17:53 - 145501456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-05-12 09:57 - 2019-08-30 11:22 - 000002342 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge Dev.lnk 2022-05-11 23:36 - 2020-07-27 09:29 - 000000000 ____D C:\Users\hoodvisions 2022-05-11 23:02 - 2019-02-20 23:40 - 000013241 _____ C:\Users\hoodvisions\AppData\Roaming\SpeedRunnersLog.txt 2022-05-11 13:27 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2022-05-11 09:55 - 2018-06-01 23:48 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\D3DSCache 2022-05-11 08:22 - 2018-08-24 19:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2022-05-10 16:22 - 2022-01-22 23:27 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Vampire_Survivors 2022-05-10 16:17 - 2021-01-18 11:12 - 000000000 ____D C:\Program Files (x86)\Epic Games 2022-05-10 16:17 - 2019-04-08 13:56 - 000001272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk 2022-05-10 16:17 - 2019-04-08 13:56 - 000001260 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk 2022-05-10 15:55 - 2020-04-09 12:03 - 000000000 ____D C:\ProgramData\TetServer 2022-05-10 12:30 - 2015-05-15 09:11 - 000001456 _____ C:\Users\hoodvisions\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2022-05-10 09:01 - 2020-07-27 09:39 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2022-05-10 09:01 - 2020-07-27 09:39 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2022-05-09 09:11 - 2015-05-15 12:10 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\vlc 2022-05-06 09:54 - 2015-05-14 17:31 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-05-06 09:50 - 2015-07-27 19:15 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2022-05-06 00:30 - 2022-03-02 12:32 - 006465216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2022-05-06 00:30 - 2020-07-10 14:50 - 007618608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2022-05-05 16:00 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing 2022-05-05 11:46 - 2021-12-13 11:06 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3227405742-4072025680-4140124765-1000 2022-05-05 11:46 - 2020-07-27 09:39 - 000003390 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3227405742-4072025680-4140124765-1000 2022-05-05 11:46 - 2020-07-27 09:29 - 000002461 _____ C:\Users\hoodvisions\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-05-05 03:00 - 2020-07-10 14:50 - 000134832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2022-05-04 21:27 - 2021-10-15 13:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2022-05-04 21:27 - 2015-09-10 19:54 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2022-04-30 22:21 - 2021-11-26 12:36 - 000000000 ____D C:\Program Files (x86)\Razer Chroma SDK 2022-04-28 11:07 - 2016-10-21 20:22 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller 2022-04-28 11:06 - 2020-08-30 01:50 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Deployment 2022-04-28 11:06 - 2017-12-21 20:59 - 000000000 ____D C:\Program Files (x86)\AceBIT 2022-04-28 11:06 - 2015-05-14 19:04 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AceBIT 2022-04-28 11:05 - 2016-04-08 16:19 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\Ubisoft Game Launcher 2022-04-28 11:04 - 2020-11-05 14:55 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tracking Time LLC 2022-04-28 11:04 - 2020-11-05 14:55 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\trackingtime 2022-04-28 11:03 - 2020-11-05 14:55 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\TrackingTime 2022-04-28 11:03 - 2016-02-17 19:41 - 000000000 ____D C:\Program Files (x86)\Leap Motion 2022-04-28 10:58 - 2020-05-25 17:32 - 000000000 ____D C:\Program Files (x86)\WISO 2022-04-28 10:56 - 2015-05-14 16:10 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2022-04-27 21:25 - 2018-02-24 01:53 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\GameAnalytics 2022-04-26 11:20 - 2019-06-07 20:53 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\NordVPN 2022-04-23 22:12 - 2016-11-06 01:08 - 000000000 ____D C:\Users\hoodvisions\AppData\Local\ElevatedDiagnostics 2022-04-23 00:44 - 2016-04-20 13:56 - 000000000 ____D C:\Users\hoodvisions\AppData\Roaming\OculusClient 2022-04-23 00:15 - 2016-04-20 13:54 - 000000000 ____D C:\Program Files\Oculus 2022-04-23 00:13 - 2020-07-27 09:29 - 000000000 ____D C:\Users\OVRLibraryService 2022-04-21 16:28 - 2021-09-10 11:42 - 015355904 _____ C:\Users\hoodvisions\Documents\digisell-Zeichnungsschein-DE-6-Monate-Haltefrist.indd 2022-04-21 10:36 - 2020-07-27 09:39 - 000003938 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000UA1d257dbf3eadeec 2022-04-21 10:36 - 2020-07-27 09:39 - 000003670 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-3227405742-4072025680-4140124765-1000Core1d257dbf3e7a868 2022-04-20 20:52 - 2021-12-22 21:34 - 000000000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Oculus.lnk 2022-04-20 20:52 - 2021-06-24 19:24 - 000003582 _____ C:\ProgramData\cfSB1710.ini 2022-04-20 20:52 - 2021-06-24 19:24 - 000003582 _____ C:\ProgramData\cfMF8245.ini 2022-04-20 20:52 - 2021-06-24 19:24 - 000003439 _____ C:\ProgramData\cfLH0330.ini 2022-04-20 20:52 - 2021-06-24 19:24 - 000002595 _____ C:\ProgramData\cfSB1610.ini 2022-04-20 20:52 - 2021-06-24 19:24 - 000002244 _____ C:\ProgramData\cfSB1700.ini 2022-04-20 20:52 - 2021-06-24 19:24 - 000002244 _____ C:\ProgramData\cfSB1590.ini 2022-04-20 20:52 - 2020-06-02 10:38 - 000000000 ____D C:\ProgramData\Riot Games 2022-04-20 20:52 - 2019-05-28 17:14 - 000000978 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2019.lnk 2022-04-20 20:52 - 2016-04-12 12:20 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk 2022-04-20 20:52 - 2016-04-12 12:19 - 000001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk 2022-04-20 20:52 - 2009-07-14 06:45 - 000014960 _____ C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2022-04-20 20:52 - 2009-07-14 06:45 - 000014960 _____ C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2022-04-20 20:06 - 2020-07-27 09:39 - 000003632 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2022-04-20 20:06 - 2020-07-27 09:39 - 000003508 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2022-04-20 10:54 - 2021-10-29 12:14 - 001273856 _____ C:\Users\hoodvisions\Documents\lebenslauf2021.indd 2022-04-19 10:29 - 2022-03-09 11:13 - 000000000 ____D C:\Program Files\NordUpdater 2022-04-19 10:29 - 2020-09-27 19:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordSec 2022-04-19 10:29 - 2020-07-15 12:49 - 000000000 ____D C:\Program Files\NordVPN ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======== 2016-02-09 13:05 - 2016-02-09 13:32 - 000000132 _____ () C:\Users\hoodvisions\AppData\Roaming\Adobe CS6-BMP-Format - Voreinstellungen 2022-03-28 11:47 - 2022-04-09 22:48 - 000000076 _____ () C:\Users\hoodvisions\AppData\Roaming\BattleBitConfig.ini 2020-05-04 17:18 - 2020-05-04 17:20 - 000028333 _____ () C:\Users\hoodvisions\AppData\Roaming\Durch Trennzeichen getrennte Werte.ADR 2020-05-04 17:17 - 2020-08-18 11:58 - 000012459 _____ () C:\Users\hoodvisions\AppData\Roaming\Durch Trennzeichen getrennte Werte.EML 2021-06-07 14:50 - 2021-06-09 19:50 - 000000016 _____ () C:\Users\hoodvisions\AppData\Roaming\obs-virtualcam.txt 2016-04-05 10:39 - 2016-04-05 12:11 - 000009787 _____ () C:\Users\hoodvisions\AppData\Roaming\PS13_panel.log 2015-05-14 20:26 - 2020-01-18 18:50 - 014848000 _____ () C:\Users\hoodvisions\AppData\Roaming\Sandra.mdb 2019-02-20 23:40 - 2022-05-11 23:02 - 000013241 _____ () C:\Users\hoodvisions\AppData\Roaming\SpeedRunnersLog.txt 2015-09-25 23:04 - 2022-05-12 13:12 - 000000128 _____ () C:\Users\hoodvisions\AppData\Roaming\winscp.rnd 2022-03-10 15:01 - 2022-03-10 15:01 - 000006246 _____ () C:\Users\hoodvisions\AppData\Local\2240114613 2015-05-15 09:11 - 2022-05-10 12:30 - 000001456 _____ () C:\Users\hoodvisions\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2016-04-12 14:18 - 2019-10-23 10:37 - 000001456 _____ () C:\Users\hoodvisions\AppData\Local\Adobe Save for Web 13.0 Prefs 2018-09-29 21:26 - 2018-09-29 21:26 - 000000000 _____ () C:\Users\hoodvisions\AppData\Local\oobelibMkey.log 2016-03-15 15:40 - 2021-07-28 12:21 - 000000600 _____ () C:\Users\hoodvisions\AppData\Local\PUTTY.RND 2015-05-14 20:19 - 2015-05-14 20:19 - 000000017 _____ () C:\Users\hoodvisions\AppData\Local\resmon.resmoncfg 2015-08-22 12:12 - 2015-08-22 12:12 - 000353118 _____ () C:\Users\hoodvisions\AppData\Local\SquareClock.Production_HBMV1Icon.ico ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== Geändert von hoodie (16.05.2022 um 09:43 Uhr) |
Themen zu HTML Datei mit Wacatac.B! ausgeführt, noch keine Symptome, was kann ich ausser MSWD noch tun? |
angst, anhang, ausgeführt, ausser, datei, defender, entfern, erkannt, fette, geladen, gen, html, infektion, jegliche, keylogger, mail, nichts, nvcontainer, nvcontainer.exe, schonmal, seitdem, system, troja, trojaner, verbreitung, verhindern, virtualbox, windows |