![]() |
|
Log-Analyse und Auswertung: PUP.Optional.WebProtector im AdwCleanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() PUP.Optional.WebProtector im AdwCleaner Hallo liebes Trojaner-Board und insbesondere dessen Admins! Ich habe nun schon alles Mögliche versucht, aber bekomme im AdwCleaner immer und immer wieder ein Ergebnis "PUP.Optional.WebProtector" bzw. "Chrome-Erweiterung" mit der Bezeichnung "kfecnpmgnlnbmipaogfhoacoioifjgko". Code:
ATTFilter # ------------------------------- # Malwarebytes AdwCleaner 8.4.0.0 # ------------------------------- # Build: 08-30-2022 # Database: 2022-10-10.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 06-21-2023 # Duration: 00:00:04 # OS: Windows 10 (Build 19045.3086) # Scanned: 32036 # Detected: 1 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.WebProtector kfecnpmgnlnbmipaogfhoacoioifjgko ***** [ Chromium URLs ] ***** No malicious Chromium URLs found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. ***** [ Hosts File Entries ] ***** No malicious hosts file entries found. ***** [ Preinstalled Software ] ***** No Preinstalled Software found. AdwCleaner[C05].txt - [1532 octets] - [21/06/2023 13:36:41] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ########## Ich würde mich riesig freuen, wenn ihr mir dazu eine Einschätzung geben könntet oder sogar eine Lösung. Tausend Dank schonmal im Voraus und ein ganz dickes Lob für eure Arbeit! Hier die FRST Log-Dateien Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 20-06-2023 durchgeführt von Fabian (Administrator) auf I7-11700 (21-06-2023 13:41:13) Gestartet von C:\Users\Fabian\Desktop\FRST06\FRST64.exe Geladene Profile: Fabian Plattform: Microsoft Windows 10 Home Version 22H2 19045.3086 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: FF Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer64.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe (C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Scans\MsMpEngCP.exe (cmd.exe ->) () [Datei ist nicht signiert] C:\Users\Fabian\AppData\Local\KeeForm\keeform_host.exe <2> (DriverStore\FileRepository\cui_dch.inf_amd64_2e49f48165b8de10\igfxCUIServiceN.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_2e49f48165b8de10\igfxEMN.exe (explorer.exe ->) () [Datei ist nicht signiert] C:\Program Files (x86)\novideo-srgb\novideo_srgb.exe (explorer.exe ->) (6099D0EF-9374-47ED-BDFE-A82136831235 -> File-New-Project) C:\Program Files\WindowsApps\40459File-New-Project.EarTrumpet_2.2.2.0_x86__1sdd7yawvg6ne\EarTrumpet\EarTrumpet.exe (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <25> (explorer.exe ->) (Peter Eduard Verbeek -> ) C:\Program Files\EqualizerAPO\config\Peace.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12> (Rémi Mercier) [Datei ist nicht signiert] C:\Program Files (x86)\FanControl\FanControl.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_2ed8bbc35e514626\RstMwService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_670360bdb5a40a0d\WMIRegistrationService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_2e49f48165b8de10\igfxCUIServiceN.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_78ff17a5ea060c5f\OneApp.IGCC.WinService.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3ea756ac68d34d21\IntelCpHDCPSvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_01da06226db6f074\Display.NvContainer\NVDisplay.Container.exe <2> (svchost.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files\KeePass Password Safe 2\KeePass.exe [3274640 2023-06-03] (Open Source Developer, Dominik Reichl -> Dominik Reichl) HKLM\...\Policies\Explorer: [NoInstrumentation] 1 HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Beschränkung <==== ACHTUNG HKLM\Software\Policies\...\system: [EnableActivityFeed] 0 HKLM\Software\Policies\...\system: [UploadUserActivities] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Run: [novideo_srgb] => C:\Program Files (x86)\novideo-srgb\novideo_srgb.exe [176128 2022-08-17] () [Datei ist nicht signiert] HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\Explorer: [NoPreviewPane] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\Explorer: [NoWinkeys] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1156397584-2715397874-1246108200-1001\...\Policies\Explorer: [NoViewContextMenu] 0 HKLM\...\Windows x64\Print Processors\BJ Print Processor3: C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL [83968 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\BJ Language Monitor3_2: c:\windows\system32\CNBLM3_2.DLL [211456 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\PDF-XChange Lite Port Monitor: C:\WINDOWS\system32\pxcpmL.dll [953600 2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\114.0.5735.134\Installer\chrmstp.exe [2023-06-16] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{9459C573-B17A-45AE-9F64-1857B5D58CEE}] -> "C:\Program Files (x86)\Microsoft\Edge\Application\113.0.1774.35\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge --channel=stable Startup: C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notion.lnk [2021-05-19] ShortcutTarget: Notion.lnk -> C:\Users\Fabian\AppData\Local\Programs\Notion\Notion.exe (Notion Labs, Inc. -> Notion Labs, Inc) Startup: C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Peace.lnk [2022-04-29] ShortcutTarget: Peace.lnk -> C:\Program Files\EqualizerAPO\config\Peace.exe (Peter Eduard Verbeek -> ) GroupPolicy: Beschränkung ? <==== ACHTUNG Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG HKLM\SOFTWARE\Policies\Microsoft\Edge: Beschränkung <==== ACHTUNG ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {04D64DA5-A70E-4EE8-938D-DD256CAFEACA} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [804312 2023-04-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {169198C8-0091-41F1-AD4B-FC6173CE7330} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [5308576 2023-05-24] (Microsoft Windows -> Microsoft Corporation) Task: {24946AD6-1127-49DD-BB59-C192ABCEAF41} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (Keine Datei) Task: {4708D566-BBE5-47B7-8C40-3D3DC57248F9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {4E69CFE4-0AF1-4195-9DDE-DB7A9433951D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A5950D4A-5AC5-43B5-9398-DC290B82CE63} - System32\Tasks\RTSS => C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [436544 2023-03-30] (Alexey Nicolaychuk -> ) Task: {B41AE28F-BB7C-4C98-8A51-743BF058A260} - System32\Tasks\ViGEmBus_Updater => C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\ViGEmBus_Updater.exe [1117096 2022-09-27] (Nefarius Software Solutions e.U. -> Nefarius Software Solutions e.U.) Task: {B980123C-E901-4D47-B25A-4D47B26881F5} - System32\Tasks\GoogleUpdateTaskMachineUA{B988E800-5187-44F4-B9F3-D6EA382AA0CF} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2023-03-08] (Google LLC -> Google LLC) Task: {C3F67CD9-022B-4FAB-901C-45E96A2E41B8} - System32\Tasks\GoogleUpdateTaskMachineCore{266555DC-1875-4EC9-8D18-B2E2C9810694} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2023-03-08] (Google LLC -> Google LLC) Task: {CBA5098C-B5E9-4245-8042-E0E4B3C72293} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [732064 2023-06-20] (Mozilla Corporation -> Mozilla Foundation) <==== ACHTUNG Task: {D6072931-353C-455A-B510-0AA8AE9A03F1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {DCB56F94-87F8-45C4-B5AF-39700891EADC} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{FCC99019-2712-4615-A9D7-FF7235546EB3} => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler (Keine Datei) Task: {E04599DB-D87E-42CD-87AA-82A06245CE0C} - System32\Tasks\FanControl => c:\windows\system32\cmd.exe [289792 2021-10-06] (Microsoft Windows -> Microsoft Corporation) -> /C start /B FanControl.exe Task: {E7BFCAC2-188E-42A2-9560-927935DBF45C} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{07B0E02F-7275-4596-A823-B970E42FC36A} => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c (Keine Datei) Task: {E9553626-E455-4ED9-8D69-F840B1ECF362} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{4b0b5439-022e-45bf-88a0-38362586021a}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{9d784384-9f9e-41a1-85bf-0badb74702e2}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{9d784384-9f9e-41a1-85bf-0badb74702e2}: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{aa1defd5-5419-40dc-beae-552b76b2b0ee}: [DhcpNameServer] 192.168.8.1 DnsPolicyConfig: [{0A0FB82B-7316-4C84-B5B0-5607D59B2DEE}] => GenericDNSServers=8.8.8.8 DnsPolicyConfig: [{0A41985C-0245-4C18-84E0-705E8ED9F4D2}] => GenericDNSServers=8.8.8.8 DnsPolicyConfig: [{5BF51F1A-2EDD-4DF2-853B-E6CD29B4F541}] => GenericDNSServers=8.8.8.8 DnsPolicyConfig: [{98E4D2D5-2173-46DE-8926-A6474D30DEDE}] => GenericDNSServers=8.8.8.8 FireFox: ======== FF DefaultProfile: 6dx3uoje.default FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3uoje.default [2023-01-10] FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771 [2023-06-21] FF Homepage: Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771 -> visions.de FF Session Restore: Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771 -> ist aktiviert. FF Extension: (Facebook Container) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\@contain-facebook.xpi [2023-01-25] FF Extension: (CanvasBlocker) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\CanvasBlocker@kkapsner.de.xpi [2023-04-24] FF Extension: (I still don't care about cookies) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\idcac-pub@guus.ninja.xpi [2023-06-05] FF Extension: (Decentraleyes) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\jid1-BoFifL9Vbdl2zQ@jetpack.xpi [2023-01-25] FF Extension: (Privacy Badger) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2023-06-20] FF Extension: (AdBlocker for YouTube™) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\jid1-q4sG8pYhq8KGHs@jetpack.xpi [2023-01-25] FF Extension: (KeeForm) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\keeform@keeform.org.xpi [2023-04-05] FF Extension: (Grammatik- und Rechtschreibprüfung – LanguageTool) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\languagetool-webextension@languagetool.org.xpi [2023-03-25] FF Extension: (Startpage Privatsphäre-Schutz) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{5b1a796b-231a-4ad1-84ff-918db0818207}.xpi [2023-03-08] FF Extension: (NoScript) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2023-05-18] FF Extension: (DarkTheme) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{99c277af-d778-4a0b-9faa-b1d8165f0a55}.xpi [2023-01-25] FF Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-05-04] FF Extension: (Bypass Paywalls Clean) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{d133e097-46d9-4ecc-9903-fa6a722a6e0e}.xpi [2023-02-09] FF Extension: (colee) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\Extensions\{d1cc7cf8-8f1b-419a-9ac7-5f709d61ea45}.xpi [2023-01-25] FF Extension: (Add-ons Restricted Domains) - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\f6fkhara.default-release-1674606149771\features\{ee0ae0bc-fd24-4832-86c8-1a79cab6ea13}\addons-restricted-domains@mozilla.com.xpi [2023-06-13] FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [Datei ist nicht signiert] FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Keine Datei] FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1156397584-2715397874-1246108200-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1156397584-2715397874-1246108200-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1156397584-2715397874-1246108200-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2022-12-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> Tracker Software Products (Canada) Ltd.) Chrome: ======= CHR Profile: C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default [2023-06-21] CHR StartupUrls: Default -> "hxxp://visions.de/" CHR Extension: (KeeForm) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmhcphbkicakelgpchlhccaeljahoima [2023-04-05] CHR Extension: (Adblock Plus - kostenloser Adblocker) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-06-19] CHR Extension: (I still don't care about cookies) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\edibdbjcniadpccecjdfdjjppcpchdlm [2023-06-05] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-03-08] CHR Extension: (Grammatik- und Rechtschreibprüfung – LanguageTool) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2023-06-21] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 Backupper Service; C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.2.1\ABService.exe [1102328 2023-04-19] (AOMEI International Network Limited -> AOMEI International Network Limited) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9880840 2022-12-06] (BattlEye Innovations e.K. -> ) S3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [52590680 2023-04-13] (Electronic Arts, Inc. -> ) S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11498600 2023-06-21] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-11-03] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [943528 2023-05-17] (EasyAntiCheat Oy -> Epic Games, Inc.) S4 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-07-11] (Epic Games Inc. -> Epic Games, Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [347408 2023-04-28] (Underwriters Laboratories Inc. -> Futuremark) S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2117096 2023-02-11] (GOG Sp. z o.o. -> GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7166552 2022-09-20] (GOG Sp. z o.o. -> GOG.com) S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v3.0.5\ProtonVPNService.exe [472168 2023-04-19] (Proton Technologies AG -> ProtonVPN) S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v3.0.5\ProtonVPN.WireGuardService.exe [471656 2023-04-19] (Proton Technologies AG -> ProtonVPN) S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2703192 2023-01-10] (Rockstar Games, Inc. -> Rockstar Games) S3 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [17029944 2023-04-24] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe [5964328 2023-04-17] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe [3232576 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe [133592 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [12311392 2023-06-02] (KRAFTON, Inc. -> KRAFTON, Inc) S3 edgeupdate; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc [X] S3 edgeupdatem; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc [X] S3 MicrosoftEdgeElevationService; "C:\Program Files (x86)\Microsoft\Edge\Application\113.0.1774.35\elevation_service.exe" [X] R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_01da06226db6f074\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_01da06226db6f074\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem S4 RtkAudioUniversalService; "%SystemRoot%\System32\RtkAudUService64.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AcxHdAudio; C:\WINDOWS\System32\drivers\AcxHdAudio.sys [526848 2022-09-09] (Microsoft Windows -> Microsoft Corporation) R0 ambakdrv; C:\WINDOWS\System32\ambakdrv.sys [51120 2019-05-14] (CHENGDU AOMEI Tech Co., Ltd. -> ) R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [172928 2023-04-20] (AOMEI International Network Limited -> ) R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [32176 2023-04-20] (AOMEI International Network Limited -> ) S3 AndnetBus; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [30208 2016-08-31] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.) S3 AndNetDiag; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [30720 2016-08-24] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.) S3 ANDNetModem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [37376 2016-08-24] (Microsoft Windows Hardware Compatibility Publisher -> LG Electronics Inc.) S3 AsrDrv105; C:\WINDOWS\SysWOW64\Drivers\AsrDrv105.sys [40696 2022-04-13] (ASROCK INC. -> ASRock Incorporation) S3 AsrDrv106; C:\WINDOWS\SysWOW64\Drivers\AsrDrv106.sys [49984 2022-05-12] (ASROCK INC. -> ASRock Incorporation) S3 AxtuDrv; C:\WINDOWS\SysWOW64\Drivers\AxtuDrv.sys [21768 2020-04-01] (ASROCK Incorporation -> RW-Everything) R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [30728 2022-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.) R1 EneTechIo; C:\WINDOWS\system32\drivers\ene.sys [19968 2019-10-17] (Microsoft Windows Hardware Compatibility Publisher -> ) R1 GLCKIO2; C:\WINDOWS\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> ) S4 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [30720 2021-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd) R2 inpoutx64; C:\WINDOWS\System32\Drivers\inpoutx64.sys [15008 2022-05-23] (Red Fox UK Limited -> Highresolution Enterprises [www.highrez.co.uk]) S3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_04d4eecc5838a558\gna.sys [88776 2022-06-24] (Intel Corporation -> Intel Corporation) R3 MpKsl4b526d9f; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9032EEBA-29A5-4908-BE8B-1154DBD46D68}\MpKslDrv.sys [213288 2023-06-21] (Microsoft Windows -> Microsoft Corporation) R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v3.0.5\Resources\ProtonVPN.CalloutDriver.sys [34176 2023-04-17] (Microsoft Windows Hardware Compatibility Publisher -> Proton Technologies AG) R3 R0FanControl; C:\Program Files (x86)\FanControl\FanControl.sys [14544 2023-06-21] (Noriyuki MIYAZAKI -> OpenLibSys.org) S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12187328 2022-01-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation) S3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions) R2 SSGDIO; C:\WINDOWS\SysWOW64\DRIVERS\ssgdio64.sys [14608 2022-05-12] (ATI Technologies, Inc -> ATI Technologies Inc.) S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2022-04-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [249400 2022-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2023-06-13] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-06-13] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99568 2023-06-13] (Microsoft Windows -> Microsoft Corporation) R3 WiManH; C:\WINDOWS\System32\DriverStore\FileRepository\wiman.inf_amd64_367f6ef053419fd6\WiManH\WiManH.sys [180296 2022-09-20] (Intel Corporation -> Intel Corporation) S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2022-05-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 xhunter1; C:\WINDOWS\xhunter1.sys [1447240 2023-06-19] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 cpuz155; \??\C:\WINDOWS\temp\cpuz155\cpuz155_x64.sys [X] S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X] S3 semav6msr64; \??\C:\WINDOWS\system32\drivers\semav6msr64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-06-21 13:40 - 2023-06-21 13:41 - 000000000 ____D C:\Users\Fabian\Desktop\FRST06 2023-06-21 13:40 - 2023-06-21 13:41 - 000000000 ____D C:\FRST 2023-06-21 12:48 - 2023-06-21 12:48 - 000001574 _____ C:\Users\Fabian\AppData\Roaming\PureRef.ini 2023-06-21 12:34 - 2023-06-21 12:34 - 000003130 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner 2023-06-21 12:07 - 2023-06-21 13:16 - 000000000 ____D C:\Users\Fabian\AppData\LocalLow\IGDump 2023-06-20 19:38 - 2023-06-21 13:38 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-06-15 17:30 - 2023-06-15 17:31 - 002240336 _____ C:\Users\Fabian\Desktop\Bewerbung_Ausbildung_FabianMarcus.pdf 2023-06-15 16:17 - 2023-06-15 17:45 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\EasyAntiCheat 2023-06-15 16:14 - 2023-06-15 16:17 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat 2023-06-15 16:09 - 2023-06-15 16:09 - 000000000 ____D C:\Users\Fabian\AppData\Local\HellLetLoose 2023-06-14 20:48 - 2023-06-14 20:48 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\NVIDIA 2023-06-14 20:47 - 2023-06-14 20:49 - 000000000 ____D C:\Users\Fabian\AppData\Local\NVIDIA Corporation 2023-06-14 20:28 - 2023-06-20 12:01 - 000000000 ____D C:\Users\Fabian\AppData\Local\D3DSCache 2023-06-14 20:25 - 2023-06-21 13:37 - 000000000 ____D C:\ProgramData\NVIDIA 2023-06-14 20:25 - 2023-06-14 20:25 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation 2023-06-14 20:24 - 2023-06-14 20:24 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2023-06-14 20:24 - 2023-06-14 20:20 - 000121880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2023-06-14 20:23 - 2023-06-14 20:23 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2023-06-14 20:21 - 2023-06-14 20:20 - 014520328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 012066840 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 007858128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 006737000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 006190088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 005844448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 005550616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 003482632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 002167776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 001621472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 001537504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 001194976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000992224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000933896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000853488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000848976 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000848976 _____ C:\WINDOWS\system32\vulkaninfo.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000777200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000768520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000713808 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000713808 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000668640 _____ C:\WINDOWS\system32\nvofapi64.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000653352 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000653352 _____ C:\WINDOWS\system32\vulkan-1.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000636968 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000636968 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000504344 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2023-06-14 20:21 - 2023-06-14 20:20 - 000459800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2023-06-14 20:21 - 2023-06-14 20:20 - 000107938 _____ C:\WINDOWS\system32\nvinfo.pb 2023-06-14 19:35 - 2023-06-14 19:35 - 041892633 _____ C:\Users\Fabian\Desktop\xoio_3d_people_collection.zip 2023-06-14 19:18 - 2023-06-14 19:18 - 000000000 ____D C:\WINDOWS\system32\lxss 2023-06-14 19:18 - 2023-06-14 19:18 - 000000000 ____D C:\WINDOWS\LastGood.Tmp 2023-06-14 19:15 - 2023-06-14 19:13 - 001487896 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2023-06-14 19:15 - 2023-06-14 19:13 - 001227288 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2023-06-13 21:48 - 2023-06-13 21:48 - 000000000 ___HD C:\$WinREAgent 2023-06-13 14:26 - 2023-06-13 14:26 - 041906684 _____ C:\Users\Fabian\Desktop\Oekotest 5-23.pdf 2023-06-13 14:26 - 2023-06-13 14:26 - 026426336 _____ C:\Users\Fabian\Desktop\Oekotest 4-23.pdf 2023-06-13 11:36 - 2023-06-13 11:36 - 000031333 _____ C:\Users\Fabian\Desktop\OpenDocument Text (neu).odt 2023-06-09 17:33 - 2023-06-09 17:33 - 000000000 ____D C:\Users\Fabian\AppData\LocalLow\Intel 2023-06-09 16:38 - 2023-06-21 13:37 - 000000000 __SHD C:\Users\Fabian\IntelGraphicsProfiles 2023-06-09 16:37 - 2021-03-30 02:59 - 000309656 _____ (Intel Corporation) C:\WINDOWS\system32\libmfxhw64.dll 2023-06-09 16:37 - 2021-03-30 02:59 - 000257048 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\libmfxhw32.dll 2023-06-09 16:37 - 2021-03-30 02:59 - 000173080 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll 2023-06-09 16:37 - 2021-03-30 02:59 - 000148368 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll 2023-06-09 00:26 - 2023-06-12 15:21 - 000000000 ____D C:\Program Files (x86)\ROCCAT 2023-06-08 13:28 - 2023-06-08 13:28 - 000000000 ____D C:\Users\Fabian\AppData\Local\AWSToolkit 2023-06-07 10:59 - 2023-06-07 10:59 - 000000875 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon.lnk 2023-06-07 10:59 - 2023-06-07 10:59 - 000000000 ____D C:\Program Files\LatencyMon 2023-06-07 10:59 - 2021-03-09 15:07 - 000027744 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys 2023-06-06 16:11 - 2023-06-06 16:10 - 000033230 _____ C:\Users\Fabian\Desktop\Kaufmännische Berufe.odt 2023-06-06 15:09 - 2023-06-07 16:35 - 000018300 _____ C:\Users\Fabian\Desktop\Gehäusetests.odt 2023-06-05 18:22 - 2023-06-05 18:22 - 000003114 _____ C:\WINDOWS\system32\Tasks\RTSS 2023-06-03 20:21 - 2023-06-03 20:21 - 000000977 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk 2023-06-03 16:13 - 2023-06-03 16:13 - 000000000 ____D C:\Program Files (x86)\Futuremark 2023-06-02 19:40 - 2023-06-02 23:41 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\Microsoft\Teams 2023-06-02 19:40 - 2023-06-02 19:40 - 000002411 _____ C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk 2023-06-02 12:35 - 2023-06-02 12:35 - 000000000 ____D C:\Users\Fabian\AppData\Local\MidnightGhostHunt 2023-06-02 11:04 - 2023-06-02 11:04 - 000000000 ____D C:\WINDOWS\Panther 2023-05-31 09:18 - 2023-05-31 09:18 - 000095152 _____ C:\Users\Fabian\Desktop\Bewerbungsliste_FabianMarcus.pdf 2023-05-31 09:18 - 2023-05-31 09:18 - 000045712 _____ C:\Users\Fabian\Desktop\Ausbildungsoptionen_ProContra_FabianMarcus.pdf 2023-05-29 17:51 - 2023-05-29 17:50 - 000024230 _____ C:\Users\Fabian\Desktop\Ausbildungsoptionen_ProContra.odt 2023-05-26 13:49 - 2023-05-26 13:49 - 001058105 _____ C:\Users\Fabian\Desktop\Zeugnisse_FabianMarcus.pdf 2023-05-24 15:46 - 2023-05-29 17:50 - 000091855 _____ C:\Users\Fabian\Desktop\Anschreiben_Ausbildung_FabianMarcus.odt ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-06-21 13:39 - 2021-12-16 17:06 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-06-21 13:39 - 2021-04-17 14:04 - 000000000 ____D C:\Program Files (x86)\Google 2023-06-21 13:37 - 2022-05-12 12:16 - 000000000 ____D C:\Intel 2023-06-21 13:37 - 2022-05-03 14:49 - 000000000 ____D C:\Program Files (x86)\FanControl 2023-06-21 13:37 - 2021-11-15 17:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-06-21 13:37 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-06-21 13:37 - 2019-12-07 11:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2023-06-21 13:30 - 2021-11-15 17:11 - 001722856 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-06-21 13:30 - 2019-12-07 16:50 - 000743714 _____ C:\WINDOWS\system32\perfh007.dat 2023-06-21 13:30 - 2019-12-07 16:50 - 000150136 _____ C:\WINDOWS\system32\perfc007.dat 2023-06-21 13:30 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2023-06-21 13:23 - 2022-05-23 13:34 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK 2023-06-21 13:19 - 2019-09-15 01:23 - 000000000 ____D C:\Program Files (x86)\Steam 2023-06-21 13:16 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-06-21 12:32 - 2021-11-15 17:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-06-21 12:00 - 2021-09-13 11:52 - 000000000 ____D C:\Program Files\Mozilla Thunderbird 2023-06-21 12:00 - 2019-09-15 00:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-06-20 22:17 - 2022-10-11 17:42 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2023-06-20 20:02 - 2020-05-04 20:52 - 000000000 ____D C:\Users\Fabian\AppData\LocalLow\Mozilla 2023-06-20 14:19 - 2021-11-15 16:54 - 000000000 ____D C:\Users\Fabian 2023-06-20 12:26 - 2019-09-15 01:50 - 000007603 _____ C:\Users\Fabian\AppData\Local\Resmon.ResmonCfg 2023-06-20 10:00 - 2023-03-30 15:20 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\KeePass 2023-06-19 18:59 - 2022-12-13 00:02 - 000000000 ____D C:\Program Files\EA 2023-06-19 18:54 - 2023-03-15 22:29 - 000000000 ____D C:\ProgramData\EA Desktop 2023-06-19 18:47 - 2022-10-11 17:40 - 000000000 ____D C:\Users\Fabian\AppData\Local\NVIDIA 2023-06-19 18:47 - 2021-01-22 17:50 - 000000000 ____D C:\Users\Fabian\AppData\Local\CrashDumps 2023-06-19 18:34 - 2020-11-06 01:02 - 000000000 ____D C:\Program Files\Common Files\PUBG 2023-06-19 18:07 - 2021-06-29 14:27 - 001447240 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys 2023-06-19 18:02 - 2022-05-16 16:49 - 000000000 ____D C:\Users\Fabian\AppData\Local\Ubisoft Game Launcher 2023-06-19 17:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-06-19 16:29 - 2021-05-05 22:37 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\discord 2023-06-19 16:26 - 2023-01-21 00:57 - 000000000 ____D C:\Users\Fabian\AppData\Local\Discord 2023-06-19 16:08 - 2019-09-16 10:46 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\Telegram Desktop 2023-06-16 10:29 - 2023-03-08 20:12 - 000002241 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2023-06-16 02:57 - 2021-05-19 12:19 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\Notion 2023-06-15 17:23 - 2023-03-08 20:10 - 000004002 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA{B988E800-5187-44F4-B9F3-D6EA382AA0CF} 2023-06-15 17:23 - 2023-03-08 20:10 - 000003878 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore{266555DC-1875-4EC9-8D18-B2E2C9810694} 2023-06-14 20:48 - 2021-11-16 17:44 - 000000000 ____D C:\Users\Fabian\AppData\Local\UnrealEngine 2023-06-14 20:27 - 2019-03-19 14:07 - 000000000 ____D C:\Users\Fabian\AppData\Local\Packages 2023-06-14 20:26 - 2022-09-22 16:40 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2023-06-14 20:26 - 2022-06-21 16:18 - 001656868 _____ C:\WINDOWS\ntbtlog.txt 2023-06-14 20:25 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-06-14 19:38 - 2019-09-15 13:28 - 000000000 ____D C:\Users\Fabian\AppData\Local\Spotify 2023-06-14 19:36 - 2019-09-15 13:25 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\Spotify 2023-06-13 23:32 - 2023-03-08 20:01 - 000505656 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-06-13 23:32 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2023-06-13 23:32 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-06-13 21:54 - 2022-04-13 14:29 - 000000000 ____D C:\Program Files\dotnet 2023-06-13 21:54 - 2021-05-13 01:31 - 000000000 ____D C:\Users\Default\.dotnet 2023-06-13 21:54 - 2019-09-15 01:25 - 000000000 ____D C:\ProgramData\Package Cache 2023-06-13 21:50 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-06-13 21:49 - 2021-11-15 17:06 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-06-13 21:37 - 2019-09-14 23:32 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-06-13 21:35 - 2020-11-19 01:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-06-13 21:35 - 2019-09-14 23:32 - 170078616 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-06-12 15:21 - 2021-10-11 20:02 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2023-06-09 17:32 - 2022-05-17 20:41 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2023-06-09 16:31 - 2020-04-01 16:59 - 000000000 ____D C:\Program Files\Intel 2023-06-09 16:31 - 2019-09-15 23:10 - 000000000 ____D C:\ProgramData\Intel 2023-06-09 15:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2023-06-09 10:58 - 2022-02-23 13:54 - 000000000 ____D C:\WINDOWS\system32\SteelSeries 2023-06-06 20:07 - 2023-02-06 01:07 - 000000000 ____D C:\Users\Fabian\AppData\Roaming\vlc 2023-06-06 15:29 - 2021-10-19 01:28 - 000000000 ____D C:\Users\Fabian\AppData\Local\darktable 2023-06-06 15:28 - 2021-08-31 16:14 - 000000000 ____D C:\Users\Fabian\.dbus-keyrings 2023-06-06 15:28 - 2021-04-07 00:31 - 000000000 ____D C:\Users\Fabian\AppData\Local\babl-0.1 2023-06-06 14:56 - 2023-05-16 11:01 - 000034260 _____ C:\Users\Fabian\Desktop\Bewerbungsliste.odt 2023-06-03 20:21 - 2023-03-30 15:19 - 000000000 ____D C:\Program Files\KeePass Password Safe 2 2023-06-02 19:40 - 2023-01-21 00:57 - 000000000 ____D C:\Users\Fabian\AppData\Local\SquirrelTemp 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-05-24 15:59 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======== 2022-10-21 12:56 - 2022-08-31 19:20 - 000497096 ___SH (AOMEI International Network Limited) C:\Program Files (x86)\ABLaucher.exe 2022-04-28 22:52 - 2022-04-28 22:52 - 000000048 ____H () C:\Program Files (x86)\ufu8snbw0k.dat 2023-06-21 12:48 - 2023-06-21 12:48 - 000001574 _____ () C:\Users\Fabian\AppData\Roaming\PureRef.ini 2020-09-15 23:31 - 2021-02-01 20:29 - 000000081 _____ () C:\Users\Fabian\AppData\Local\.bidstack.fault 2022-04-09 00:04 - 2023-03-20 18:58 - 001065984 _____ () C:\Users\Fabian\AppData\Local\file__0.localstorage 2021-04-15 14:40 - 2021-06-08 14:27 - 000000505 _____ () C:\Users\Fabian\AppData\Local\karboncalligraphyrc 2021-04-15 14:31 - 2023-04-01 13:59 - 000007687 _____ () C:\Users\Fabian\AppData\Local\krita-sysinfo.log 2021-04-15 14:31 - 2023-04-01 13:59 - 000032349 _____ () C:\Users\Fabian\AppData\Local\krita.log 2023-04-01 13:59 - 2023-04-01 13:59 - 000000214 _____ () C:\Users\Fabian\AppData\Local\kritadisplayrc 2021-04-15 14:31 - 2023-04-01 13:59 - 000029190 _____ () C:\Users\Fabian\AppData\Local\kritarc 2020-03-22 21:16 - 2020-03-22 21:16 - 000000410 _____ () C:\Users\Fabian\AppData\Local\oobelibMkey.log 2023-05-07 15:27 - 2023-05-07 15:27 - 000003448 _____ () C:\Users\Fabian\AppData\Local\recently-used.xbel 2019-09-15 01:50 - 2023-06-20 12:26 - 000007603 _____ () C:\Users\Fabian\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== |
Themen zu PUP.Optional.WebProtector im AdwCleaner |
admins, arbeit, beitrag, code, detected, dickes, dll, ergebnis, files, firefox, folge, folgende, hosts, malwarebytes, mögliche, registry, riesig, schonmal, services, shortcuts, software, start, versucht, windows, wmi |