|
Antiviren-, Firewall- und andere Schutzprogramme: Windows Sicherheit / Defender zerschossenWindows 7 Sämtliche Fragen zur Bedienung von Firewalls, Anti-Viren Programmen, Anti Malware und Anti Trojaner Software sind hier richtig. Dies ist ein Diskussionsforum für Sicherheitslösungen für Windows Rechner. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen. |
28.08.2023, 19:35 | #1 |
| Windows Sicherheit / Defender zerschossen Ahoi, habe gestern wohl was falsches auf meine Win11 Pro Kiste installiert. Seitdem funktioniert mein Windows Virenprogramm nicht mehr. Virenschutz taugt überhaupt nicht mehr im Sicherheitscenter auf. Auch unter Einstellungen Antivirus steht kein Anbieter obwohl ich Kaspersky erstmal installiert habe. Wollte eigentlich gestern nur ein Template entpacken :-( Bisher habe ich folgendes gemacht: ADW Cleaner - Nichts gefunden Kaspersky hat nichts gefunden Malwarebytes hat auch nichts gefunden :-( Windows mittels einer Iso drüber gebügelt brachte ebenfalls keinen Erfolg. Daraufhin habe ich noch 2 Powershell eingaben versucht von einer anderen Hilfeseite, aber auch das brachte mein Virusprogramm nicht wieder zurück. Kernisolierung funktioniert auch nicht mehr aufgrund von alten Treibern. Hoffe Ihr könnt mir weiterhelfen. Ansonsten installiere ich die Kiste wohl neu Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2023 durchgeführt von Rose (Administrator) auf WORKSTATION (ASRock B760M Steel Legend WiFi) (28-08-2023 20:25:21) Gestartet von C:\Users\Rose\Downloads\FRST64.exe Geladene Profile: Rose Plattform: Microsoft Windows 11 Pro Version 22H2 22621.2134 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: FF Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe (C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe ->) (Logitech, Inc. -> ) C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.CpuIdRemote64.exe (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe (C:\Program Files\Logi\LogiBolt\LogiBolt.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logi\LogiBolt\logi_crashpad_handler.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe (C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe (C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <7> (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\Program Files\Classic Shell\ClassicStartMenu.exe (explorer.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logi\LogiBolt\LogiBolt.exe (explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe (explorer.exe ->) (Nenad Hrg SoftwareOK) [Datei ist nicht signiert] C:\Users\Rose\Downloads\DesktopOK401_x64\DesktopOK_x64.exe (explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe (explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.303\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.303\GoogleCrashHandler64.exe (hvsimgr.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsirdpclient.exe (hvsimgr.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsirpcd.exe (Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <23> (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (services.exe ->) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\BrYNSvc.exe (services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe (services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe (services.exe ->) (DEVGURU CO LTD -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) D:\Program Files (x86)\Origin\OriginWebHelperService.exe (services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe (services.exe ->) (eVenture Limited -> eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe (services.exe ->) (Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_21e0cf0737fd48af\WMIRegistrationService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Intel(R) Extreme Tuning Utility -> Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (services.exe ->) (Intel(R) INTELND1617S2 -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Panda Security S.L. -> Panda Security S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\pselamsvc.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_2d0366e4f3ea0eab\RtkAudUService64.exe <2> (services.exe ->) (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) D:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) D:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2333.8.0_x64__cv1g1gvanyjgm\WhatsApp.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SecHealthUI_1000.25873.9001.0_x64__8wekyb3d8bbwe\SecHealthUI.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBar.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe (svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsimgr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe (svchost.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\SecurityHealth\1.0.2306.10002-0\SecurityHealthHost.exe <2> (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (vmcompute.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\vmwp.exe konnte nicht auf den Prozess zugreifen -> vmmemCmZygote konnte nicht auf den Prozess zugreifen -> vmmemMDAG ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1687616 2022-02-21] (Logitech Inc -> Logitech, Inc.) HKLM\...\Run: [LogiBolt] => C:\Program Files\Logi\LogiBolt\LogiBolt.exe [22423104 2021-12-14] (Logitech Inc -> Logitech) HKLM\...\Run: [EPSON Stylus DX4200 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_FATIAEE.EXE [98304 2005-03-08] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9923856 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) HKLM\...\Run: [CORSAIR iCUE 4 Software] => C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe [185384 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_2d0366e4f3ea0eab\RtkAudUService64.exe [1629080 2022-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [11559648 2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3146752 2022-02-07] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [BrStsInd00] => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe [1885184 2012-12-18] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [186984 2022-11-02] (Panda Security S.L. -> Panda Security, S.L.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\Run: [DesktopOK] => C:\Users\Rose\Downloads\DesktopOK401_x64\DesktopOK_x64.exe [429568 2014-11-06] (Nenad Hrg SoftwareOK) [Datei ist nicht signiert] HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\Run: [LogiBolt] => C:\Program Files\Logi\LogiBolt\LogiBolt.exe [22423104 2021-12-14] (Logitech Inc -> Logitech) HKLM\...\Windows x64\Print Processors\HPZPP4wm: C:\Windows\System32\spool\prtprocs\x64\hpzpp4wm.DLL [231424 2007-02-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\...\Windows x64\Print Processors\us00aPC: C:\Windows\System32\spool\prtprocs\x64\us00apc.dll [43520 2015-08-20] (Windows (R) Codename Longhorn DDK provider) [Datei ist nicht signiert] HKLM\...\Print\Monitors\EPSON Stylus DX4200 Series 64MonitorBE: c:\windows\system32\E_ILMAEE.DLL [119808 2005-06-09] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\FRITZ!fax Color Port Monitor: c:\windows\system32\FritzColorPort64.dll [20480 2006-02-23] () [Datei ist nicht signiert] HKLM\...\Print\Monitors\us00a Langmon: c:\windows\system32\us00alm.dll [22528 2015-03-12] () [Datei ist nicht signiert] HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\116.0.5845.111\Installer\chrmstp.exe [2023-08-24] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2017-03-30] GroupPolicy: Beschränkung ? <==== ACHTUNG Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {019543EE-4D13-47D1-A0AE-774120648F52} - kein Dateipfad. <==== ACHTUNG Task: {079BF05B-A922-41CC-8513-A20AC421527C} - kein Dateipfad. <==== ACHTUNG Task: {0976C0B9-CC98-4BE1-8745-2716F212A9B3} - kein Dateipfad. <==== ACHTUNG Task: {0D7750E2-4B7C-400D-A0AD-71D122F98808} - kein Dateipfad. <==== ACHTUNG Task: {0DD4A495-11E8-4130-A524-4345DF5094CE} - kein Dateipfad. <==== ACHTUNG Task: {23B23D6A-BEBC-40BD-8422-F5C235961F96} - kein Dateipfad. <==== ACHTUNG Task: {2A378261-E64E-4B8F-80F6-0E8D07253E0C} - kein Dateipfad. <==== ACHTUNG Task: {30DD5265-0548-442F-A318-3B77A9F85B6D} - kein Dateipfad. <==== ACHTUNG Task: {45CC81A7-585B-493F-9D83-842B2EDCE6F8} - kein Dateipfad. <==== ACHTUNG Task: {47F15474-4AA4-4662-9AB5-7714590493F8} - kein Dateipfad. <==== ACHTUNG Task: {482F1863-5C9C-43DB-B601-C02069B2AAD2} - kein Dateipfad. <==== ACHTUNG Task: {4C9708CB-12E0-4627-9DB3-77711015D1A0} - kein Dateipfad. <==== ACHTUNG Task: {53436A7B-2D56-428D-9F5A-5D8DCE1B3262} - kein Dateipfad. <==== ACHTUNG Task: {5C4F63E8-A2A1-4411-80F9-C34BADC60D1D} - \RegistryUpdateTaskMachineQC -> Keine Datei <==== ACHTUNG Task: {66569078-72BD-41CB-99C6-D2C7E01B1D8D} - kein Dateipfad. <==== ACHTUNG Task: {6C6A7BDE-AE9F-483E-B068-B77A3073717A} - kein Dateipfad. <==== ACHTUNG Task: {6D2460A7-E9AD-4BC0-B792-338CB355F534} - kein Dateipfad. <==== ACHTUNG Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - kein Dateipfad. <==== ACHTUNG Task: {6FEFB20E-C881-4846-93A2-8219EE4B030A} - kein Dateipfad. <==== ACHTUNG Task: {7746E1E7-838C-4BF1-81C8-CF39DACB475D} - kein Dateipfad. <==== ACHTUNG Task: {86976673-D178-4FCB-AA2F-65B60CBFBE88} - kein Dateipfad. <==== ACHTUNG Task: {99DBFDE7-3F67-43E5-A624-A1B89879B406} - kein Dateipfad. <==== ACHTUNG Task: {9B196E71-4EDC-4D39-9C8A-4F7282EA54A5} - kein Dateipfad. <==== ACHTUNG Task: {A111E0AA-0D9F-4806-9F32-CB859C97D809} - kein Dateipfad. <==== ACHTUNG Task: {A2F854F6-B58F-440F-872A-4D4D14F2FE37} - kein Dateipfad. <==== ACHTUNG Task: {A39FED60-980C-494D-9856-E82F883B38AB} - kein Dateipfad. <==== ACHTUNG Task: {A3EFC5B4-B0A2-499D-AC5A-EE384B5F2D9D} - kein Dateipfad. <==== ACHTUNG Task: {AB3CBDE6-13CB-46A4-B8D6-F68531AE03A2} - kein Dateipfad. <==== ACHTUNG Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - kein Dateipfad. <==== ACHTUNG Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - kein Dateipfad. <==== ACHTUNG Task: {E261A39A-D677-4C52-AB94-4DAF87807935} - \Microsoft\Windows\Windows Media Sharing\UpdateLibrary -> Keine Datei <==== ACHTUNG Task: {E2BA1A3B-DD07-4BB8-B6A2-509CD4B02076} - kein Dateipfad. <==== ACHTUNG Task: {E58546D5-78FB-4E1E-8B88-DBB389CB90F2} - kein Dateipfad. <==== ACHTUNG Task: {F77C5FA7-BE5B-469F-86B8-1F45E4C3A18A} - kein Dateipfad. <==== ACHTUNG Task: {75D90835-F902-4AFD-8F19-A2DF70584784} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [5158128 2023-08-28] (Microsoft Windows -> Microsoft Corporation) Task: {44DCF4A0-FDC0-4EB6-9B4B-53CE075FCC88} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-30] (Google Inc -> Google Inc.) Task: {171A9E07-A4B1-4734-B0E6-7F283EA92EEE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-30] (Google Inc -> Google Inc.) Task: {DFA2BB8A-66DA-4D1B-9EB2-D1CE83596EB8} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {55690238-06EB-4FEF-86A9-E2C2D382531E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {13211ECA-9467-47CE-B947-F6E2B8CCB60A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {19335547-F2A5-4475-980E-0A6BF4AA7072} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {034E3EA1-268F-43F7-A9BF-663A09A936D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {848AB91F-1086-4BB3-BE97-B6FE1312AEA8} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {12F46FC7-E6BE-4480-A3B4-7ECE2E0F0E50} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-04-14] (Nvidia Corporation -> NVIDIA Corporation) Task: {0955ED6F-2DA0-4379-9C03-EFBD9D5FCD59} - System32\Tasks\SamsungMagician => d:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [121595968 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{34fbb743-8760-4fd5-a0ef-1e96048221fc}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{562f06cc-f48d-4fbe-bed3-376de26e94fd}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{81b80bfe-ff7c-4c3f-aba3-bae76196dd35}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{9d891342-3300-4267-8825-19017538f47d}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{fcee5666-980f-467d-8912-a6b1b325618e}: [DhcpNameServer] 192.168.178.1 Edge: ======= DownloadDir: C:\Users\Rose\Downloads Edge Notifications: HKU\S-1-5-21-653905286-3903209159-424152592-1001 -> hxxps://www.facebook.com; hxxps://www.mann.tv; hxxps://www.ruhr24.de Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden] Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden] Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden] Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden] Edge Profile: C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default [2023-08-28] Edge DownloadDir: Default -> C:\Users\Rose\Downloads Edge Notifications: Default -> hxxps://www.facebook.com; hxxps://www.mann.tv; hxxps://www.ruhr24.de Edge StartupUrls: Default -> "hxxps://de-de.facebook.com/" Edge Extension: (Google Webspam Report (by Google)) - C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\efinmbicabejjhjafeidhfbojhnfiepj [2020-12-19] Edge Extension: (Edge relevant text changes) - C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-08-09] FireFox: ======== FF DefaultProfile: pt4v4e5g.default-1490937754028 FF ProfilePath: C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 [2023-08-28] FF user.js: detected! => C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\user.js [2022-08-11] FF Homepage: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> www.google.de FF NetworkProxy: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> type", 0 FF Notifications: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> hxxps://www.facebook.com; hxxps://twitter.com; hxxps://www.online-slot.de FF Extension: (German dictionary (de_DE)) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\de_DE@dicts.j3e.de.xpi [2018-12-02] FF Extension: (uBlock Origin) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\uBlock0@raymondhill.net.xpi [2023-07-26] FF Extension: (TWP - Translate Web Pages) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2023-08-03] FF Extension: (SEOquake) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}.xpi [2023-01-17] FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF Extension: (Foxit PDF Creator) - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2018-01-29] [] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-08-19] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [Datei ist nicht signiert] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corporation -> Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems Incorporated -> Adobe Systems) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default [2023-08-28] CHR Extension: (SEO META in 1 CLICK) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjogjfinolnhfhkbipphpdlldadpnmhc [2021-07-05] CHR Extension: (uBlock Origin) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2023-07-24] CHR Extension: (Google Webspam Report (by Google)) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\efinmbicabejjhjafeidhfbojhnfiepj [2021-02-21] CHR Extension: (Word Counter Plus) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpjegfbcdijjfkceenlfoehpcakfgldj [2021-05-22] CHR Extension: (Google Docs Offline) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-23] CHR Extension: (Click&Clean) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2023-02-17] CHR Extension: (Google PageSpeed Insights API Extension) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfebkooaidmeboeblkkejdoepilnnjhn [2020-11-03] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30] CHR Extension: (Disavow File Generator Tool) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkppdgpkjmclhhlibhdphbllcgpllbch [2021-06-27] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-05-10] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2 [2023-08-03] CHR Extension: (Foxit PDF Creator) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2023-01-28] CHR Extension: (Google Docs Offline) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-03] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-01-28] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\System Profile [2023-08-19] CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2023-01-28] CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2023-01-28] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [103264 2023-03-01] (Apple Inc. -> Apple Inc.) S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-01-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-10-03] (BattlEye Innovations e.K. -> ) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2022-01-26] (Brother Industries, Ltd.) [Datei ist nicht signiert] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11878368 2023-08-04] (Microsoft Corporation -> Microsoft Corporation) R2 CMigrationService; d:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe [761408 2023-01-16] (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [614432 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R2 CorsairLLAService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe [238632 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) R2 CorsairService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe [84008 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) S2 CorsairUniwillService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueUniwillService.exe [108072 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) S3 CyberGhost8Service; C:\Program Files\CyberGhost 8\Dashboard.Service.exe [69840 2023-07-11] (CyberGhost S.R.L. -> CyberGhost S.R.L.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-11] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-11] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [46824 2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-10-03] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-05-01] (Epic Games Inc. -> Epic Games, Inc.) S3 FoxitPhantomService; D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitConnectedPDFService.exe [1658944 2018-04-17] (Foxit Software Incorporated -> Foxit Software Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [347408 2023-06-08] (Underwriters Laboratories Inc. -> Futuremark) R2 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [886528 2023-01-15] (Glarysoft LTD -> Glarysoft Ltd) S3 GUPMService; d:\Program Files (x86)\Glary Utilities 5\GUPMService.exe [76696 2023-08-07] (Glarysoft Ltd -> Glarysoft Ltd) R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [180496 2022-12-10] (eVenture Limited -> eVenture Limited) S3 iCUEDevicePluginHost; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe [462888 2023-01-20] (Corsair Memory, Inc. -> Corsair) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert] R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9286168 2023-08-28] (Malwarebytes Inc. -> Malwarebytes) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Datei ist nicht signiert] R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [118504 2022-10-31] (Panda Security S.L. -> Panda Security, S.L.) R2 OptionsPlusUpdaterService; C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe [17874688 2023-08-07] (Logitech Inc -> Logitech, Inc.) S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2572096 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; D:\Program Files (x86)\Origin\OriginWebHelperService.exe [3491144 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts) S3 Panda VPN Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\Hydra.Sdk.Windows.Service.exe [320848 2017-11-20] (AnchorFree Inc -> ) R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [84176 2019-02-19] (Panda Security S.L. -> Panda Security, S.L.) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2016-12-31] (Even Balance, Inc. -> ) R2 pselamsvc; C:\Program Files (x86)\Panda Security\Panda Security Protection\pselamsvc.exe [195736 2023-04-13] (Panda Security S.L. -> Panda Security S.L.) R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [78840 2022-11-02] (Panda Security S.L. -> Panda Security, S.L.) R2 SamsungMagicianSVC; d:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe [371776 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402200 2023-08-28] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU CO LTD -> DEVGURU Co., LTD.) R2 TeamViewer; d:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [15212856 2023-01-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) S4 TuneUp.Defrag; C:\WINDOWS\System32\TuneUpDefragService.exe [425216 2017-11-22] (TuneUp Software GmbH -> TuneUp Software GmbH) S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-12-14] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\NisSrv.exe [3104488 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe [133576 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) S4 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe [495720 2018-07-04] (Wondershare Technology Co.,Ltd -> Wondershare) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> ) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-04-15] (ASUSTeK Computer Inc. -> ) S3 AsrDrv101; C:\WINDOWS\SysWOW64\Drivers\AsrDrv101.sys [22280 2017-05-09] (ASROCK Incorporation -> ASRock Incorporation) S3 AsrDrv102; C:\WINDOWS\SysWOW64\Drivers\AsrDrv102.sys [22248 2018-01-17] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv103; C:\WINDOWS\SysWOW64\Drivers\AsrDrv103.sys [34568 2019-11-05] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv104; C:\WINDOWS\SysWOW64\Drivers\AsrDrv104.sys [34536 2022-01-16] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv106; C:\WINDOWS\SysWOW64\Drivers\AsrDrv106.sys [49984 2023-01-28] (ASROCK INC. -> ASRock Incorporation) R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [310984 2018-12-15] (Tages SA -> ) S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin2\brynhildr.sys [2188544 2022-12-15] (Activision Publishing Inc -> Activision Blizzard, Inc.) R3 avmaura; C:\WINDOWS\System32\drivers\avmaura.sys [116480 2016-07-27] (AVM Computersysteme Vertriebs GmbH -> AVM Berlin) S1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [144456 2016-01-22] (Rivet Networks LLC -> Rivet Networks, LLC.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [532480 2023-05-05] (Microsoft Corporation) [Datei ist nicht signiert] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [184320 2023-05-05] (Microsoft Corporation) [Datei ist nicht signiert] S3 CH341_A64; C:\WINDOWS\System32\Drivers\CH341W64.SYS [31232 2009-06-12] (Microsoft Windows Hardware Compatibility Publisher -> www.winchiphead.com) S3 CorsairGamingAudioService; C:\Windows\System32\drivers\CorsairGamingAudio64.sys [63008 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47032 2022-12-09] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [22968 2022-12-09] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) R3 cpuz154; C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys [40976 2023-08-28] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [32880 2023-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.) S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31376 2015-03-10] (PassMark Software Pty Ltd -> ) S3 dpK00701; C:\WINDOWS\System32\drivers\dpK00701.sys [64016 2010-02-24] (DigitalPersona, Inc. -> DigitalPersona, Inc.) R0 fse; C:\WINDOWS\System32\drivers\fse.sys [218464 2023-08-28] (Microsoft Windows -> Microsoft Corporation) S3 gdrv; C:\WINDOWS\gdrv.sys [26792 2018-01-25] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) S3 gdrv3; C:\WINDOWS\system32\drivers\gdrv3.sys [45248 2023-04-09] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2016-12-11] (Sony Mobile Communications AB -> Sony Mobile Communications) S1 GLCKIO2; C:\WINDOWS\system32\drivers\GLCKIO2.sys [19392 2018-04-23] (ASUSTeK Computer Inc. -> ) R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [23568 2023-07-19] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd) R1 hideFirewall; C:\WINDOWS\System32\drivers\hideFirewall.sys [100352 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Hewlett-Packard.) [Datei ist nicht signiert] S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Hewlett-Packard.) [Datei ist nicht signiert] S3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.) S3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-12-20] (Logitech Inc -> Logitech Inc.) R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [42696 2018-12-15] (Tages SA -> ) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-08-28] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-08-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 MHIKEY10; C:\WINDOWS\System32\Drivers\MHIKEY10x64.sys [59008 2007-07-04] (Microsoft Windows Hardware Compatibility Publisher -> ChunghwaTL) S3 MSIO; C:\Program Files (x86)\ASRock Utility\ASRRGBLED\Bin\msio64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-04-15] (Apple Inc.) [Datei ist nicht signiert] R1 NNSDNS; C:\WINDOWS\system32\DRIVERS\NNSDNS.sys [146184 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [215264 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [128744 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [146664 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [151152 2022-10-10] (Microsoft Windows Hardware Compatibility Publisher -> Panda Security, S.L.) R1 NNSNHWFP; C:\WINDOWS\system32\DRIVERS\NNSNHWFP.sys [211208 2022-12-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [164568 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [137960 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [407264 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [575720 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [125672 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [335064 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2023-04-14] (Nvidia Corporation -> NVIDIA Corporation) S3 PAC207; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [686592 2008-02-13] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Inc.) R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [198376 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) S0 psinelam; C:\WINDOWS\System32\DRIVERS\psinelam.sys [36552 2023-04-13] (Microsoft Windows Early Launch Anti-Malware Publisher -> Panda Security, S.L.) R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [176360 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [218856 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [150760 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [162536 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [130280 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72984 2019-02-20] (Panda Security S.L. -> Panda Security, S.L.) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) S3 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [132584 2017-10-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) S3 usbdpfp; C:\WINDOWS\System32\drivers\usbdpfp.sys [67088 2010-02-24] (DigitalPersona, Inc. -> DigitalPersona, Inc.) S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [94208 2023-08-28] (Microsoft Windows -> ) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55704 2023-08-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572656 2023-08-09] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [104688 2023-08-09] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\WINDOWS\system32\DRIVERS\wintun.sys [29680 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2019-12-14] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-08-28 20:25 - 2023-08-28 20:25 - 000050514 _____ C:\Users\Rose\Downloads\FRST.txt 2023-08-28 20:25 - 2023-08-28 20:25 - 000000000 ____D C:\FRST 2023-08-28 20:24 - 2023-08-28 20:24 - 002382336 _____ (Farbar) C:\Users\Rose\Downloads\FRST64.exe 2023-08-28 19:59 - 2023-08-28 19:59 - 000457374 _____ C:\Users\Rose\Downloads\condef.rar 2023-08-28 19:26 - 2023-08-28 19:26 - 000003832 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{7B919D33-27BD-435F-AB1E-5784AD3F09A6} 2023-08-28 19:26 - 2023-08-28 19:26 - 000003708 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{46F3BE1D-EC51-4C50-8452-7658FEEDA63F} 2023-08-28 19:26 - 2019-02-20 07:31 - 000072984 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSKMAD.sys 2023-08-28 19:25 - 2023-08-28 19:25 - 000003132 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner 2023-08-28 19:17 - 2023-08-28 19:17 - 000002320 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Dome.lnk 2023-08-28 19:16 - 2023-08-28 19:17 - 000002305 _____ C:\Users\Public\Desktop\Panda Dome.lnk 2023-08-28 19:16 - 2023-08-28 19:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Dome 2023-08-28 19:16 - 2022-12-06 12:53 - 000211208 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsnhwfp.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000575720 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsprv.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000407264 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsprot.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000335064 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsstrm.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000215264 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnshttp.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000164568 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnspicc.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000146664 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsids.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000146184 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsdns.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000137960 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnspop3.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000128744 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnshttps.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000125672 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnssmtp.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000218856 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINKNC.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000198376 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINAflt.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000176360 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINFile.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000162536 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProt.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000150760 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProc.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000130280 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINReg.sys 2023-08-28 19:12 - 2023-08-28 19:12 - 000000000 ____D C:\WINDOWS\Panther 2023-08-28 18:47 - 2023-08-28 18:48 - 000000000 ___HD C:\$WinREAgent 2023-08-28 18:04 - 2023-08-28 18:04 - 000000000 ____D C:\Users\Rose\Downloads\Autoruns 2023-08-28 17:43 - 2023-08-28 17:49 - 000012288 _____ C:\WINDOWS\SysWOW64\AppRulesStorage 2023-08-28 17:43 - 2023-08-28 17:43 - 000012288 _____ C:\WINDOWS\SysWOW64\DnsStorage 2023-08-28 17:42 - 2023-08-28 17:49 - 000000000 ____D C:\Program Files\Common Files\AV 2023-08-28 17:38 - 2023-08-28 18:41 - 000000000 ____D C:\Users\Rose\AppData\Local\ESET 2023-08-28 17:33 - 2023-08-28 17:35 - 000000000 ____D C:\ProgramData\HitmanPro 2023-08-28 14:30 - 2023-08-28 14:30 - 000000000 ___HD C:\$SysReset 2023-08-28 13:09 - 2023-08-28 18:54 - 000000000 ____D C:\Users\Rose\AppData\Local\Malwarebytes 2023-08-28 13:09 - 2023-08-28 13:09 - 000002041 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2023-08-28 13:09 - 2023-08-28 13:09 - 000002029 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2023-08-28 13:08 - 2023-08-28 13:08 - 000000000 ____D C:\Program Files\Malwarebytes 2023-08-28 11:18 - 2023-08-28 15:58 - 000000000 ____D C:\Users\Rose\Desktop\Neuer Ordner 2023-08-28 10:54 - 2023-08-28 19:16 - 000000000 ____D C:\ProgramData\Panda Security 2023-08-28 10:54 - 2023-08-28 19:16 - 000000000 ____D C:\Program Files (x86)\Panda Security 2023-08-28 10:54 - 2023-08-28 10:54 - 003142712 _____ (Panda Security, S.L.) C:\Users\Rose\Downloads\PANDAFREEAV.exe 2023-08-28 10:03 - 2023-08-28 10:20 - 000000000 ____D C:\KVRT2020_Data 2023-08-28 09:22 - 2023-08-28 19:26 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-08-28 09:22 - 2023-08-28 12:10 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2023-08-28 09:22 - 2023-08-28 09:22 - 000011433 _____ C:\WINDOWS\diagwrn.xml 2023-08-28 09:22 - 2023-08-28 09:22 - 000011433 _____ C:\WINDOWS\diagerr.xml 2023-08-28 09:22 - 2023-08-28 09:22 - 000003580 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2023-08-28 09:22 - 2023-08-28 09:22 - 000003356 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2023-08-28 09:22 - 2023-08-28 09:22 - 000003308 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{A386F23C-987F-4B30-B0AB-76CF6CFBB4BF} 2023-08-28 09:22 - 2023-08-28 09:22 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-08-28 09:22 - 2023-08-28 09:22 - 000002590 _____ C:\WINDOWS\system32\Tasks\SamsungMagician 2023-08-28 09:22 - 2023-08-28 09:22 - 000002586 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask 2023-08-28 09:22 - 2023-08-28 09:22 - 000000488 __RSH C:\ProgramData\ntuser.pol 2023-08-28 09:22 - 2023-08-28 09:22 - 000000020 ___SH C:\Users\Rose\ntuser.ini 2023-08-28 09:22 - 2023-08-28 09:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Elcomsoft 2023-08-28 09:21 - 2023-08-28 09:21 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network 2023-08-28 09:19 - 2023-08-28 19:25 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK 2023-08-28 09:19 - 2023-08-28 18:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-08-28 09:19 - 2023-08-28 10:47 - 005738896 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-08-28 09:17 - 2023-08-28 09:19 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Crypto 2023-08-28 09:17 - 2023-08-28 09:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\SystemCertificates 2023-08-28 09:17 - 2023-08-28 09:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Network 2023-08-28 09:15 - 2023-08-28 09:19 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate 2023-08-28 09:14 - 2023-08-28 17:57 - 000000000 ____D C:\Users\Rose 2023-08-28 09:14 - 2023-08-28 09:21 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows 2023-08-28 09:14 - 2023-08-28 09:19 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Spelling 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Vorlagen 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Startmenü 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Netzwerkumgebung 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Lokale Einstellungen 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Eigene Dateien 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Druckumgebung 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Videos 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Musik 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Bilder 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Local\Verlauf 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Local\Anwendungsdaten 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Anwendungsdaten 2023-08-28 09:13 - 2023-08-28 09:15 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2023-08-28 09:12 - 2023-08-28 09:12 - 000743150 _____ C:\WINDOWS\system32\perfh007.dat 2023-08-28 09:12 - 2023-08-28 09:12 - 000152540 _____ C:\WINDOWS\system32\perfc007.dat 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ___SD C:\WINDOWS\system32\containers 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\WINDOWS\system32\HvsiSettingsProviders 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files\Reference Assemblies 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files\MSBuild 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files (x86)\MSBuild 2023-08-28 09:09 - 2023-08-28 09:09 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2023-08-28 08:59 - 2023-08-28 09:00 - 000000000 ____D C:\AdwCleaner 2023-08-28 08:55 - 2023-08-28 08:55 - 002969821 _____ C:\Users\Rose\Downloads\Autoruns.zip 2023-08-28 08:55 - 2023-08-28 08:55 - 000000000 ____D C:\Users\Rose\Downloads\Win11_22H2_German_x64v2 2023-08-28 08:48 - 2023-08-28 08:48 - 000000000 ____D C:\Program Files (x86)\WindowsInstallationAssistant 2023-08-28 05:24 - 2023-08-28 05:24 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\IME 2023-08-27 21:07 - 2023-08-27 21:07 - 000000000 ____D C:\Program Files\Registry 2023-08-27 20:58 - 2016-06-08 23:27 - 007819493 _____ C:\Users\Rose\Desktop\KMSpico 10.2.0 Installer + Portable.mhktricks.net.zip 2023-08-27 18:18 - 2023-08-27 18:18 - 000000000 ____D C:\Users\Rose\AppData\Roaming\wiadss 2023-08-27 17:47 - 2023-08-27 18:32 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Xiaomi 2023-08-27 14:50 - 2023-08-27 17:32 - 000000000 ____D C:\Users\Rose\.android 2023-08-27 14:50 - 2023-08-27 14:50 - 000000000 ____D C:\Users\Public\Thunder Network 2023-08-27 14:50 - 2023-08-27 14:50 - 000000000 ____D C:\ProgramData\Thunder Network 2023-08-27 09:44 - 2023-08-27 09:44 - 000001747 _____ C:\Users\Rose\Desktop\Photoshop.exe - Verknüpfung.lnk 2023-08-27 09:41 - 2023-08-27 09:41 - 000001615 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk 2023-08-27 09:41 - 2023-08-27 09:41 - 000001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk 2023-08-27 09:38 - 2023-08-27 09:38 - 000000000 ____D C:\Users\Public\Documents\AdobeGCInfo 2023-08-25 21:14 - 2023-08-25 21:14 - 000150510 _____ C:\Users\Rose\Downloads\Verkaufsschild-SiemensKC3BChlschrank_-_7688040102433033862.pdf 2023-08-25 04:38 - 2023-08-28 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExplorerPatcher 2023-08-25 04:38 - 2023-08-25 04:38 - 000643584 _____ (VALINET Solutions SRL) C:\WINDOWS\dxgi.dll 2023-08-24 09:59 - 2023-08-24 09:59 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2023-08-24 06:15 - 2023-08-28 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2023-08-23 16:28 - 2023-08-23 16:28 - 000643072 _____ (VALINET Solutions SRL) C:\WINDOWS\dxgi.prev 2023-08-22 22:15 - 2023-08-15 06:23 - 000121880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2023-08-22 22:12 - 2023-08-16 12:15 - 000849088 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000849088 _____ C:\WINDOWS\system32\vulkaninfo.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000713912 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000713912 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000653504 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000653504 _____ C:\WINDOWS\system32\vulkan-1.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000637112 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000637112 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2023-08-22 22:12 - 2023-08-16 12:14 - 001487376 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2023-08-22 22:12 - 2023-08-16 12:14 - 001227296 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2023-08-22 22:12 - 2023-08-16 12:11 - 000669320 _____ C:\WINDOWS\system32\nvofapi64.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 001537544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 001195016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 000938608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 000504456 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 002168456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 001622152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 000992368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 000777760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2023-08-22 22:12 - 2023-08-16 12:09 - 000768648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 014520968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 012066320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 003483168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 000459912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2023-08-22 22:12 - 2023-08-16 12:07 - 006190088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 005845640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 005550728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 000853104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2023-08-22 22:12 - 2023-08-16 12:06 - 007858112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2023-08-22 22:12 - 2023-08-16 12:05 - 006737504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2023-08-22 22:12 - 2023-08-15 06:23 - 000108122 _____ C:\WINDOWS\system32\nvinfo.pb 2023-08-22 00:51 - 2023-08-22 00:51 - 000046824 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2023-08-21 21:33 - 2023-08-21 21:33 - 000066230 _____ C:\Users\Rose\Downloads\Klassentreffen-1.pdf 2023-08-21 11:38 - 2023-08-21 11:38 - 000000000 ____D C:\Users\Rose\Downloads\Red Dead Redemption - Game of the Year Edition (USA Europe) (EnFrDeEsIt) (Disc 2) (Undead Nightmare and Multiplayer) 2023-08-17 07:38 - 2023-08-17 07:38 - 000000000 ____D C:\Users\Rose\Downloads\Red Dead Redemption - Game of the Year Edition (USA Europe) (EnFrDeEsIt) (Disc 1) (Red Dead Redemption Single Player) 2023-08-16 14:35 - 2023-08-16 14:35 - 002299727 _____ C:\Users\Rose\Downloads\6 Deckblätter für Biologie zum Ausdrucken - Wunderbunt.de.pdf 2023-08-15 10:55 - 2023-08-28 19:26 - 000012288 ___SH C:\DumpStack.log.tmp 2023-08-13 12:39 - 2023-08-13 12:39 - 000000000 ____D C:\ProgramData\WinaeroTweaker 2023-08-13 07:49 - 2023-08-13 07:49 - 000000031 _____ C:\.txt 2023-08-13 06:53 - 2023-08-13 06:53 - 000000000 ___HD C:\$Windows.~WS 2023-08-12 11:04 - 2023-08-12 11:06 - 000000000 ____D C:\Users\Rose\Downloads\xenia_canary 2023-08-12 11:04 - 2023-08-12 11:04 - 003145058 _____ C:\Users\Rose\Downloads\xenia_canary.zip 2023-08-12 10:48 - 2023-08-12 10:50 - 000000000 ____D C:\Users\Rose\Documents\Xenia 2023-08-12 10:48 - 2023-08-12 10:48 - 000000000 ____D C:\Users\Rose\Downloads\xenia_master 2023-08-12 10:46 - 2023-08-12 10:46 - 017886779 _____ C:\Users\Rose\Downloads\xenia_master.zip 2023-08-10 09:21 - 2023-08-11 05:39 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Teams 2023-08-09 11:38 - 2023-08-09 11:38 - 000409871 _____ C:\Users\Rose\Downloads\Überweisungsbestätigung_1691573889447.pdf 2023-08-08 12:06 - 2023-08-08 12:06 - 006069127 _____ C:\Users\Rose\Downloads\Diagnostics_Logs-OLK-UTC.2023.8.8.10.6.55.810.zip 2023-08-08 06:38 - 2023-08-08 06:38 - 000022162 _____ C:\Users\Rose\Downloads\Guenstiger GA4 Report.xlsx 2023-08-07 17:32 - 2023-08-07 17:32 - 000000000 ____D C:\Program Files\LogiOptionsPlus 2023-08-03 09:27 - 2023-08-03 09:27 - 000001836 _____ C:\Users\Rose\Desktop\CrystalDiskInfo.lnk ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-08-28 20:22 - 2016-07-13 15:12 - 000000000 ____D C:\Users\Rose\Documents\Outlook-Dateien 2023-08-28 20:20 - 2022-12-06 19:42 - 000000000 ____D C:\Users\Rose\AppData\Local\LogiOptionsPlus 2023-08-28 20:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-08-28 20:05 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-08-28 19:37 - 2016-07-13 10:52 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Telegram Desktop 2023-08-28 19:32 - 2016-07-28 22:35 - 000000000 ____D C:\Program Files (x86)\Google 2023-08-28 19:31 - 2022-02-10 09:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-08-28 19:29 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-08-28 19:29 - 2017-10-13 07:52 - 000000000 ____D C:\Users\Rose\AppData\Local\Packages 2023-08-28 19:27 - 2016-07-13 09:39 - 000000000 ____D C:\Users\Rose\AppData\Local\ClassicShell 2023-08-28 19:26 - 2023-04-29 07:02 - 000000000 ____D C:\ProgramData\NVIDIA 2023-08-28 19:26 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps 2023-08-28 19:26 - 2021-09-07 15:10 - 000000000 ____D C:\Users\Rose\AppData\Local\LogiBolt 2023-08-28 19:26 - 2017-03-27 07:56 - 000000000 ____D C:\Users\Rose\AppData\Local\Dropbox 2023-08-28 19:26 - 2016-07-13 10:28 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Dropbox 2023-08-28 19:25 - 2022-05-07 07:17 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2023-08-28 19:19 - 2022-05-07 07:17 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2023-08-28 19:17 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF 2023-08-28 19:14 - 2023-04-29 07:00 - 000000000 ____D C:\Users\Rose\AppData\Local\D3DSCache 2023-08-28 19:13 - 2018-07-19 06:15 - 000000000 ____D C:\ProgramData\Packages 2023-08-28 19:03 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\PrintDialog 2023-08-28 19:03 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-08-28 18:58 - 2021-07-22 13:19 - 000000000 ____D C:\Users\Rose\AppData\LocalLow\IGDump 2023-08-28 18:56 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-08-28 18:53 - 2023-04-29 23:14 - 000000000 ____D C:\Users\Rose\AppData\Roaming\ExplorerPatcher 2023-08-28 18:51 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\setup 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-08-28 18:21 - 2023-04-09 15:54 - 000000000 ____D C:\Users\Rose\Downloads\Telegram Desktop 2023-08-28 17:49 - 2022-05-07 07:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-08-28 17:49 - 2017-08-09 20:21 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-08-28 17:43 - 2017-01-23 20:11 - 000000000 ____D C:\Users\TEMP 2023-08-28 17:43 - 2015-10-30 08:28 - 000000000 ____D C:\Users\Default.migrated 2023-08-28 17:10 - 2018-02-20 08:33 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2023-08-28 17:10 - 2018-02-20 08:33 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2023-08-28 15:42 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\appcompat 2023-08-28 13:08 - 2016-07-13 14:32 - 000000000 ____D C:\ProgramData\Malwarebytes 2023-08-28 12:09 - 2016-07-13 13:50 - 000000000 ____D C:\Users\Rose\AppData\Local\JDownloader v2.0 2023-08-28 11:05 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\USOPrivate 2023-08-28 10:54 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2023-08-28 10:52 - 2016-07-13 13:05 - 000000000 ____D C:\Users\Rose\AppData\Local\CrashDumps 2023-08-28 10:46 - 2023-04-29 22:06 - 000000000 ____D C:\WINDOWS\addins 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\WUModels 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemApps 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\vi-VN 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Sgrm 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\id-ID 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\gl-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\eu-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\et-EE 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\es-MX 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\DDFs 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\ca-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\appraiser 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellComponents 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\OCR 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Globalization 2023-08-28 10:46 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\servicing 2023-08-28 10:40 - 2016-07-13 22:20 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Registration 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Windows NT 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Windows Defender 2023-08-28 09:22 - 2016-07-13 09:36 - 000000000 __RHD C:\Users\Public\AccountPictures 2023-08-28 09:21 - 2023-01-28 20:34 - 000000000 ____D C:\Users\Rose\Downloads\Prime95-[Guru3D.com] 2023-08-28 09:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Media 2023-08-28 09:21 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2023-08-28 09:21 - 2017-04-05 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan 2023-08-28 09:20 - 2023-04-29 07:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation 2023-08-28 09:19 - 2023-06-15 21:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 8 2023-08-28 09:19 - 2023-05-16 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Torpedo Traffic Generator Ultimate 2023-08-28 09:19 - 2023-04-29 23:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winaero Tweaker 2023-08-28 09:19 - 2023-04-29 07:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2023-08-28 09:19 - 2023-04-09 05:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\AORUS 2023-08-28 09:19 - 2023-03-22 09:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair 2023-08-28 09:19 - 2023-02-01 22:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2023-08-28 09:19 - 2022-12-15 11:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother 2023-08-28 09:19 - 2022-06-09 05:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hide.me VPN 2023-08-28 09:19 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN 2023-08-28 09:19 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\WCN 2023-08-28 09:19 - 2022-05-07 07:24 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\spool 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\NDF 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2023-08-28 09:19 - 2021-09-12 21:30 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2023-08-28 09:19 - 2021-09-07 15:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2023-08-28 09:19 - 2021-03-21 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3uTools 2023-08-28 09:19 - 2020-07-01 10:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xat.com Image Optimizer 2023-08-28 09:19 - 2020-05-30 06:04 - 000000000 ____D C:\Program Files\UNP 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Macromed 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Catroot2.bak 2023-08-28 09:19 - 2019-12-04 12:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2023-08-28 09:19 - 2019-12-04 08:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2023-08-28 09:19 - 2019-11-05 14:26 - 000000000 ____D C:\WINDOWS\system32\AMD 2023-08-28 09:19 - 2019-10-06 10:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Combined Community Codec Pack 2023-08-28 09:19 - 2019-06-12 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell 2023-08-28 09:19 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2023-08-28 09:19 - 2018-07-12 21:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio 2023-08-28 09:19 - 2018-06-20 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebSite X5 - Professional 2023-08-28 09:19 - 2018-06-15 00:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photolemur 2023-08-28 09:19 - 2018-06-03 10:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace 2023-08-28 09:19 - 2018-06-02 13:09 - 000000000 ____D C:\WINDOWS\SysWOW64\xlive 2023-08-28 09:19 - 2018-05-28 07:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression 2023-08-28 09:19 - 2018-05-28 06:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2023-08-28 09:19 - 2018-05-25 22:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF 2023-08-28 09:19 - 2018-02-20 08:33 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server 2023-08-28 09:19 - 2018-02-20 08:33 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2023-08-28 09:19 - 2017-11-22 22:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2008 2023-08-28 09:19 - 2017-10-17 12:03 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2023-08-28 09:19 - 2017-08-12 23:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2023-08-28 09:19 - 2017-05-04 21:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5 2023-08-28 09:19 - 2017-04-23 20:25 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin 2023-08-28 09:19 - 2017-04-05 23:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2023-08-28 09:19 - 2017-04-05 23:05 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2023-08-28 09:19 - 2016-11-14 16:19 - 000000000 ____D C:\WINDOWS\de 2023-08-28 09:19 - 2016-11-08 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\LiveUpdate 2023-08-28 09:19 - 2016-08-27 14:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2023-08-28 09:19 - 2016-08-14 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn 2023-08-28 09:19 - 2016-08-14 09:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition 2023-08-28 09:19 - 2016-08-01 07:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2023-08-28 09:19 - 2016-07-25 12:25 - 000000000 ___HD C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup-Disabled 2023-08-28 09:19 - 2016-07-25 11:06 - 000000000 ____D C:\WINDOWS\system32\appmgmt 2023-08-28 09:19 - 2016-07-24 23:26 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2023-08-28 09:19 - 2016-07-13 23:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2023-08-28 09:19 - 2016-07-13 13:51 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2023-08-28 09:19 - 2016-07-13 13:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2023-08-28 09:19 - 2016-07-13 13:09 - 000000000 ____D C:\WINDOWS\system32\oodag 2023-08-28 09:19 - 2016-07-13 13:03 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2023-08-28 09:19 - 2016-07-13 11:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photomatix Pro 5.1 2023-08-28 09:19 - 2016-07-13 10:52 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop 2023-08-28 09:19 - 2016-07-13 10:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2023-08-28 09:19 - 2016-07-13 09:57 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-08-28 09:19 - 2016-07-13 09:42 - 000000000 ____D C:\Program Files\Intel 2023-08-28 09:19 - 2015-10-30 09:24 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2023-08-28 09:18 - 2022-05-07 07:28 - 000000000 ____D C:\WINDOWS\Setup 2023-08-28 09:17 - 2022-05-07 07:24 - 000000000 __RHD C:\Users\Public\Libraries 2023-08-28 09:15 - 2023-04-08 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2023-08-28 09:15 - 2023-03-21 20:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2023-08-28 09:15 - 2023-02-05 09:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D 2023-08-28 09:15 - 2023-01-30 16:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium 2023-08-28 09:15 - 2023-01-29 10:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS 2023-08-28 09:15 - 2022-10-26 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft 2023-08-28 09:15 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2023-08-28 09:15 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\winrm 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\slmgr 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\F12 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\dsc 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Resources 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Help 2023-08-28 09:15 - 2019-11-12 09:36 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2023-08-28 09:15 - 2019-10-30 08:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UL 2023-08-28 09:15 - 2019-05-01 10:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IVONA 2023-08-28 09:15 - 2018-10-23 10:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2023-08-28 09:15 - 2017-04-15 23:27 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WonderFox Soft 2023-08-28 09:14 - 2022-05-07 07:24 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows 2023-08-28 09:12 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2023-08-28 09:12 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\MUI 2023-08-28 09:00 - 2022-08-11 11:20 - 000000000 ____D C:\ProgramData\IObit 2023-08-28 09:00 - 2017-10-16 07:42 - 000000000 ____D C:\Users\Rose\AppData\Roaming\IObit 2023-08-28 09:00 - 2017-03-30 22:34 - 000000000 ____D C:\Users\Rose\AppData\LocalLow\IObit 2023-08-27 23:00 - 2016-07-13 21:27 - 000000000 ____D C:\Users\Rose\AppData\Local\ElevatedDiagnostics 2023-08-27 21:42 - 2017-11-20 13:31 - 000000000 ____D C:\Users\Rose\AppData\Local\PlaceholderTileLogoFolder 2023-08-27 21:21 - 2016-09-02 15:41 - 000000000 ____D C:\Users\Rose\AppData\Roaming\TeamViewer 2023-08-27 21:20 - 2018-05-28 06:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\FileZilla 2023-08-27 09:42 - 2016-07-13 10:43 - 000000000 ____D C:\ProgramData\Adobe 2023-08-27 09:41 - 2018-05-31 07:18 - 000000000 ____D C:\Program Files\Adobe 2023-08-27 09:41 - 2017-10-09 21:41 - 000000000 ____D C:\Users\Rose\Documents\Adobe 2023-08-27 09:41 - 2017-10-09 21:40 - 000000000 ____D C:\Program Files\Common Files\Adobe 2023-08-27 09:41 - 2016-07-13 09:42 - 000000000 ____D C:\ProgramData\Package Cache 2023-08-27 06:14 - 2020-05-31 10:39 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-08-25 12:51 - 2016-07-13 13:20 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Word 2023-08-25 04:40 - 2016-08-17 09:53 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Excel 2023-08-25 04:38 - 2023-04-29 23:14 - 000000000 ____D C:\Program Files\ExplorerPatcher 2023-08-24 21:33 - 2018-06-30 07:59 - 000002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2023-08-24 21:33 - 2018-06-30 07:59 - 000002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2023-08-24 06:15 - 2017-03-27 07:56 - 000000000 ____D C:\Program Files (x86)\Dropbox 2023-08-22 22:18 - 2021-05-19 12:22 - 000000000 ____D C:\Users\Rose\AppData\Local\NVIDIA 2023-08-22 18:21 - 2023-06-15 21:45 - 000000000 ____D C:\Users\Rose\AppData\Local\CyberGhost 2023-08-21 10:31 - 2018-05-28 07:17 - 000000128 _____ C:\Users\Rose\AppData\Local\PUTTY.RND 2023-08-20 08:53 - 2023-01-28 20:32 - 000000000 ____D C:\Users\Rose\Desktop\FUN 2023-08-19 21:42 - 2019-02-27 15:18 - 000008192 _____ C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2023-08-18 04:32 - 2017-04-27 22:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-08-17 21:03 - 2017-04-27 22:59 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-08-13 12:31 - 2023-04-29 23:00 - 000000000 ____D C:\Program Files\Winaero Tweaker 2023-08-13 08:57 - 2016-07-13 10:46 - 000000000 ____D C:\Users\Rose\AppData\Local\Steam 2023-08-13 07:37 - 2019-03-23 07:56 - 000000000 ____D C:\ESD 2023-08-10 09:59 - 2016-07-24 23:26 - 000000000 ____D C:\Users\Rose\AppData\Local\SquirrelTemp 2023-08-10 08:55 - 2023-05-22 16:01 - 000000000 ____D C:\Users\Rose\Desktop\peugeot 2023-08-10 08:52 - 2023-01-28 20:33 - 000000000 ____D C:\Users\Rose\Downloads\DesktopOK401_x64 2023-08-09 19:16 - 2017-05-04 21:54 - 000000824 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk 2023-08-09 19:16 - 2017-05-04 21:54 - 000000824 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk 2023-08-09 17:52 - 2018-03-01 15:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-08-09 05:13 - 2016-07-13 09:57 - 175983240 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-08-09 05:10 - 2023-04-16 10:07 - 000000000 ____D C:\Program Files\dotnet 2023-08-05 10:38 - 2018-07-12 21:54 - 000000000 ____D C:\Users\Rose\AppData\Roaming\obs-studio 2023-08-03 09:27 - 2019-12-04 12:52 - 000000000 ____D C:\Program Files\CrystalDiskInfo ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======== 2016-07-19 20:43 - 2016-08-25 10:52 - 000000624 _____ () C:\Users\Rose\AppData\Roaming\All CPU MeterV3_Settings.ini 2019-04-10 10:51 - 2019-04-10 10:51 - 000000078 _____ () C:\Users\Rose\AppData\Roaming\FC.dat 2022-01-20 17:57 - 2022-01-20 17:57 - 000000015 _____ () C:\Users\Rose\AppData\Roaming\obs-virtualcam.txt 2020-05-18 17:06 - 2023-06-25 11:40 - 000000128 _____ () C:\Users\Rose\AppData\Roaming\PUTTY.RND 2016-07-19 20:58 - 2016-07-19 20:58 - 000000119 _____ () C:\Users\Rose\AppData\Roaming\System Monitor II_UptimeRecord.ini 2016-08-03 09:44 - 2017-01-11 22:07 - 000000122 _____ () C:\Users\Rose\AppData\Roaming\wklnhst.dat 2019-02-27 15:18 - 2023-08-19 21:42 - 000008192 _____ () C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-07-13 09:46 - 2017-02-02 08:45 - 000000000 _____ () C:\Users\Rose\AppData\Local\Driver_LOM_8161Present.flag 2018-01-25 08:10 - 2018-01-25 08:10 - 000000291 _____ () C:\Users\Rose\AppData\Local\ledConfiguration.config 2016-12-26 09:19 - 2016-12-26 09:19 - 000000001 _____ () C:\Users\Rose\AppData\Local\llftool.4.40.agreement 2018-09-28 08:55 - 2023-08-27 09:38 - 000001025 _____ () C:\Users\Rose\AppData\Local\oobelibMkey.log 2018-05-28 07:17 - 2023-08-21 10:31 - 000000128 _____ () C:\Users\Rose\AppData\Local\PUTTY.RND 2020-07-13 13:21 - 2020-07-13 13:21 - 000002761 _____ () C:\Users\Rose\AppData\Local\recently-used.xbel 2016-12-27 11:04 - 2017-02-23 09:53 - 000007597 _____ () C:\Users\Rose\AppData\Local\resmon.resmoncfg 2023-04-27 22:28 - 2023-04-27 22:28 - 000000000 _____ () C:\Users\Rose\AppData\Local\{EBD3693D-572A-435F-A259-8E8C48611192} ==================== FLock ============================== 2017-11-09 13:42 C:\ProgramData\Application Data ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== |
28.08.2023, 19:36 | #2 |
| Windows Sicherheit / Defender zerschossenCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 28-08-2023 durchgeführt von Rose (28-08-2023 20:26:00) Gestartet von C:\Users\Rose\Downloads Microsoft Windows 11 Pro Version 22H2 22621.2134 (X64) (2023-08-28 07:22:36) Start-Modus: Normal ========================================================== ==================== Konten: ============================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) Administrator (S-1-5-21-653905286-3903209159-424152592-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-653905286-3903209159-424152592-503 - Limited - Disabled) Gast (S-1-5-21-653905286-3903209159-424152592-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-653905286-3903209159-424152592-1005 - Limited - Enabled) postgres (S-1-5-21-653905286-3903209159-424152592-1006 - Limited - Enabled) Rose (S-1-5-21-653905286-3903209159-424152592-1001 - Administrator - Enabled) => C:\Users\Rose WDAGUtilityAccount (S-1-5-21-653905286-3903209159-424152592-504 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Panda Dome (Enabled - Up to date) {8404BB29-B609-D604-AF5C-6806F0482FD3} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Kaspersky (Disabled - Up to date) {4F76F112-43EB-40E8-11D8-F7BD1853EA23} FW: Kaspersky (Disabled) {774D7037-0984-41B0-3A87-5E88E680AD58} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 3DMark (HKLM\...\{793A6554-A614-46E2-8381-EE34BC9F7F60}) (Version: 2.26.8125.0 - UL) Hidden 3DMark (HKLM-x32\...\{8ffabc1c-e7a8-4b49-b024-1eab1a3b562c}) (Version: 2.10.6799.0 - UL) 3uTools (HKLM-x32\...\3uTools) (Version: 2.56.012 - ShangHai ZhangZheng Network Technology Co., Ltd.) Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1031-1033-7760-BC15014EA700}) (Version: 23.003.20284 - Adobe) Adobe Fireworks CS6 (HKLM-x32\...\{CA7C485C-7A89-11E1-B2C8-CD54B377BC52}) (Version: 12.0.0 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden Anno 1800 (HKLM-x32\...\Uplay Install 4553) (Version: - Ubisoft) AORUS ENGINE (HKLM-x32\...\AORUS ENGINE_is1) (Version: 2.2.3.0 - GIGABYTE Technology Co.,Inc.) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{CA8EDE78-7A08-4F27-9B31-D6161C095986}) (Version: 16.5.0.12 - Apple Inc.) ASRRGBLED v2.0.136 (HKLM-x32\...\ASRock RGB LED_is1) (Version: 2.0.136 - ASRock Inc.) ASUS GLCKIO2 Driver (HKLM-x32\...\{548dd834-70c5-4426-8065-fbeabdd2bb5d}) (Version: 1.0.10 - ASUSTeK Computer Inc.) Hidden ASUS GLCKIO2 Driver (HKLM-x32\...\{5960FD0F-BB3B-49AF-B175-F77DC91E995A}) (Version: 1.0.10 - ASUSTeK Computer Inc.) Hidden Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team) Audacity 3.3.3 (64 Bit) (HKLM\...\Audacity_is1) (Version: 3.3.3 - Audacity Team) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Call of Duty Modern Warfare (HKLM-x32\...\Call of Duty Modern Warfare) (Version: - Blizzard Entertainment) CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft) Combined Community Codec Pack 2015-10-18 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2015.10.19.0 - CCCP Project) CORSAIR iCUE 4 Software (HKLM\...\{444A58EF-FD29-4558-BD8B-F4839576463C}) (Version: 4.33.138 - Corsair) CPUID CPU-Z 2.06 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.06 - CPUID, Inc.) CPUID HWMonitor 1.51 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.51 - CPUID, Inc.) CrystalDiskInfo 9.1.1 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.1.1 - Crystal Dew World) CyberGhost 8 (HKLM\...\CyberGhost 8) (Version: 8.3.11.10057 - CyberGhost S.R.L.) CyberGhost TUN (HKLM\...\{677232D6-72D6-4821-8CB5-47969B15D4DF}) (Version: 1.0 - CyberGhost S.R.L.) Hidden D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 181.4.5678 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.761.1 - Dropbox, Inc.) Hidden Dynamic Application Loader Host Interface Service (HKLM\...\{B8F67CAD-D16A-4AC8-B4F1-3AE8A9FF22F5}) (Version: 1.0.0.0 - Intel Corporation) Hidden ENE RGB HAL (HKLM\...\{2914DF72-932B-4DF2-9696-C2821EDA1CA9}) (Version: 1.00.09 - Ene Tech.) Hidden ENE RGB HAL (HKLM-x32\...\{546469ee-3f9d-4fe4-bf1c-893f79cf7327}) (Version: 1.00.09 - Ene Tech.) Hidden ENE_AIC_Marvell_HAL (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden ENE_DRAM_RGB_AIO (HKLM\...\{76D0C3A4-E975-4A56-BFB9-A8CCA61E07BC}) (Version: 1.0.6.2 - Ene Tech.) Hidden ENE_DRAM_RGB_AIO (HKLM-x32\...\{b3e8b10e-ec8c-410e-a0e6-05b04379cc43}) (Version: 1.0.6.2 - Ene Tech.) Hidden ENE_EHD_HAL (HKLM\...\{F56EC5A0-3A93-492E-882A-E036F5897CC7}) (Version: 1.00.04 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_HAL (HKLM-x32\...\{cc33eebd-777b-4177-8cd7-6ab9fd06ceed}) (Version: 1.00.04 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_M2_HAL (HKLM-x32\...\{6b617af3-c8f4-45a8-bf47-b32ffb4da1cc}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden ENE_External_Device_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.11.1 - ENE Tech) Hidden ENE_External_Device_HAL (HKLM-x32\...\{bb9d349f-b87b-4026-b336-1604708bd09c}) (Version: 1.0.11.1 - ENE Tech) Hidden ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden ENE_MousePad_HAL (HKLM-x32\...\{c2c794a4-7986-4c45-884d-d4ca43b88df9}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden ENE_X_AIC_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.4.0 - ENE TECHNOLOGY INC.) Hidden Epic Games Launcher (HKLM-x32\...\{422FC196-EA1D-448E-A505-BC7DFC21C880}) (Version: 1.1.236.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epic Online Services (HKLM-x32\...\{35905844-0610-427D-86A0-2103FABE3D4D}) (Version: 2.0.42.0 - Epic Games, Inc.) EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) ExplorerPatcher (HKLM\...\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher) (Version: 22621.1992.56.3 - VALINET Solutions SRL) FileZilla 3.64.0 (HKLM-x32\...\FileZilla Client) (Version: 3.64.0 - Tim Kosse) Fotogalerie (HKLM-x32\...\{41BF4A3B-D60A-4E92-883F-C88C8C157261}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Foxit PhantomPDF (HKLM-x32\...\{CB2155B6-4273-11E8-9ECE-000C296BF29B}) (Version: 9.1.0.5096 - Foxit Software Inc.) FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\195fa74437467f40) (Version: 2.3.4.0 - AVM Berlin) Futuremark SystemInfo (HKLM-x32\...\{93086761-C4E7-48FC-A090-E9AE1C73B254}) (Version: 5.64.1188.0 - Futuremark) Glary Utilities PRO 5.209 (HKLM-x32\...\Glary Utilities 5) (Version: 5.209.0.238 - Glarysoft Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 116.0.5845.111 - Google LLC) Grewe Scanner-Interface 7 (HKLM-x32\...\{B1C3F49A-DE7D-1AC1-0913-039C1A8B9B82}) (Version: 7 - Grewe Computertechnik GmbH) HD Video Converter Factory Pro 12.5 (HKLM-x32\...\HD Video Converter Factory Pro) (Version: 12.5 - WonderFox Soft, Inc.) hide.me VPN 3.14.1 (HKLM-x32\...\{0E00BDA5-7998-4889-BE4B-39A4BBD2EDFB}_is1) (Version: 3.14.1 - eVenture Limited) HL-1110 series (HKLM-x32\...\{4F2442B7-A89E-42A4-8F0E-6937499855CA}) (Version: 1.0.1.0 - Brother Industries, Ltd.) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Incomedia WebSite X5 - Pro (HKLM\...\{E8900B9A-2ED4-4032-8FBF-D714D134D01F}_is1) (Version: 2022.3.5.0 - Incomedia s.r.l.) Intel(R) Chipset Device Software (HKLM\...\{22987D97-5A46-4BD9-B1A5-2FFE44201081}) (Version: 10.1.19199.8340 - Intel Corporation) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{e6ecf35a-b1bb-4e59-9d90-4c98fde2ffa8}) (Version: 10.1.19199.8340 - Intel(R) Corporation) Intel(R) Management Engine Components (HKLM\...\{1B2B12B8-AE77-4104-97FE-904274D21B6C}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2230.3.19.0 - Intel Corporation) Intel(R) Management Engine Driver (HKLM\...\{5F953BF8-C54E-4335-B7C9-873508D2CE1A}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) ME WMI Provider (HKLM\...\{2D7D4B84-FDD2-42BC-9B5B-ADAB4E31AC5E}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) Network Connections 22.5.104.0 (HKLM\...\{B6C27920-8AD4-4D8B-BC97-2CC0043718E5}) (Version: 22.5.104.0 - Intel) Hidden Intel(R) Network Connections 22.5.104.0 (HKLM\...\PROSetDX) (Version: 22.5.104.0 - Intel) IVONA 2 (HKLM-x32\...\IVONA 2) (Version: 1.6.37 - IVONA Software Sp. z o.o.) IVONA ControlCenter (HKLM-x32\...\IVONA ControlCenter) (Version: 1.0.25 - IVONA Software Sp. z o.o.) Killer Bandwidth Control Filter Driver (HKLM\...\{5B7A2B7B-CEA9-4E50-B0E4-E82F204CBE78}) (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer E220x Drivers (HKLM\...\{77C95134-CA2D-4614-9C86-55B7A6A281AA}) (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Network Manager (HKLM\...\{51B5A084-A40D-4F4B-90AA-EF8354EA7D96}) (Version: 1.1.57.1125 - Rivet Networks) Hidden LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logi Bolt (HKLM\...\LogiBolt) (Version: 1.2.6024.0 - Logi) Logi Options+ (HKLM\...\{850cdc16-85df-4052-b06e-4e3e9e83c5c6}) (Version: 1.48.437015 - Logitech) Logitech Gaming Software (HKLM\...\{690285C2-2481-44FB-8402-162EA970A6DD}) (Version: 8.30.28 - Logitech Inc.) Hidden Logitech Options (HKLM\...\LogiOptions) (Version: 9.60.87 - Logitech) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) LWS Facebook (HKLM-x32\...\{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}) (Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (HKLM-x32\...\{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}) (Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (HKLM-x32\...\{1651216E-E7AD-4250-92A1-FB8ED61391C9}) (Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (HKLM-x32\...\{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}) (Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (HKLM-x32\...\{71E66D3F-A009-44AB-8784-75E2819BA4BA}) (Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (HKLM-x32\...\{08610298-29AE-445B-B37D-EFBE05802967}) (Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (HKLM-x32\...\{174A3B31-4C43-43DD-866F-73C9DB887B48}) (Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (HKLM-x32\...\{8937D274-C281-42E4-8CDB-A0B2DF979189}) (Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (HKLM-x32\...\{9DAEA76B-E50F-4272-A595-0124E826553D}) (Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (HKLM-x32\...\{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}) (Version: 13.31.1038.0 - Logitech) Hidden Macrium Reflect Free (HKLM\...\{0D4965D1-6B46-4F0A-B42D-B17056612AE0}) (Version: 8.0.7279 - Paramount Software (UK) Ltd.) Hidden Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7279 - Paramount Software (UK) Ltd.) MAGIX Video Pro X10 (HKLM\...\MAGIX Video Pro X10 16.0.1.236) (Version: 16.0.1.236 - MAGIX) Malwarebytes version 4.6.1.280 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.1.280 - Malwarebytes) Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host - 3.1.32 (x86) (HKLM-x32\...\{3C73457A-1A33-4DE0-B6C2-6FBA877E1FCF}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host FX Resolver - 3.1.32 (x86) (HKLM-x32\...\{CE1A992F-4571-423D-9CAE-1184E8F29471}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.32 (x86) (HKLM-x32\...\{841FE4B1-2C3F-4304-A686-6DF41B4CC1A1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Host - 5.0.6 (x64) (HKLM\...\{0541E599-10CB-44F4-A33A-32FE6DEA2F49}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Host - 6.0.21 (x64) (HKLM\...\{26FF35F7-ADBB-4C9F-97DA-79120DB80EC6}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 5.0.6 (x64) (HKLM\...\{54F41FBB-AB2F-46B5-AA28-3C9492066E9C}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 6.0.21 (x64) (HKLM\...\{D937EF87-F11D-4778-973C-B71E178F95D0}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 5.0.6 (x64) (HKLM\...\{DDBF9749-FF6E-419C-BAAD-9F4948B75DDE}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 6.0.21 (x64) (HKLM\...\{8D2EC92E-5903-4B25-9406-182B8EFA834F}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 116.0.1938.62 - Microsoft Corporation) Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 116.0.1938.62 - Microsoft Corporation) Microsoft Expression Web 4 (HKLM-x32\...\{5F8D931D-B230-47F3-A9C0-0C8CA459A332}) (Version: 4.0.1460.0 - Microsoft Corporation) Hidden Microsoft Expression Web 4 (HKLM-x32\...\Web_4.0.1460.0) (Version: 4.0.1460.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Professional Plus 2016 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 16.0.16626.20170 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{43D501A5-E5E3-46EC-8F33-9E15D2A2CBD5}) (Version: 5.70.0.0 - Microsoft Corporation) Microsoft Visual Basic/C++ Runtime (x86) (HKLM-x32\...\{C5E3A69D-D391-45A6-A8FB-00B01E2B010D}) (Version: 1.1.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.30919 (HKLM\...\{D55C642A-D7A4-4581-90A2-D74864791E92}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.30919 (HKLM\...\{E749F10C-EFEA-43D3-8404-B477DD92AF03}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Additional Runtime - 14.31.30919 (HKLM-x32\...\{8681860E-E7D2-421A-A09E-7A6890CE62E5}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.31.30919 (HKLM-x32\...\{4CA1C5EC-16E5-4438-9704-A4F6D84068C4}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM\...\{5BEE5F3E-4D78-4DE8-A8F3-36D3E9D8868C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM-x32\...\{0eddeab6-01c1-4cf7-83ba-164ea8974c90}) (Version: 3.1.32.31915 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{25D5B94A-E3CD-44E8-9C3A-FE320B7B38FC}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{4f894285-fd43-43ac-8669-33e8b7c0a97d}) (Version: 3.1.32.31915 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 5.0.6 (x64) (HKLM\...\{0F871294-4452-40AB-BAAD-A1D624E7E405}) (Version: 40.24.30021 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 5.0.6 (x64) (HKLM-x32\...\{744f4ca7-5613-4d87-8332-b816ecf7dabd}) (Version: 5.0.6.30021 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM\...\{AF6BF7DD-2B12-40C5-919C-2EC99054BBE1}) (Version: 48.87.64723 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM-x32\...\{0f39db03-9030-48f3-82ef-5384bed81d85}) (Version: 6.0.21.32717 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{70C91B91-61E8-4D06-86D6-A9DCC291983A}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox 116.0.3 (x64 de)) (Version: 116.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0 - Mozilla) MSI Afterburner 4.6.4 (HKLM-x32\...\Afterburner) (Version: 4.6.4 - MSI Co., LTD) MSI Kombustor 4.1.19.0 (64-bit) (HKLM\...\{F3D3CC6B-9AD7-4F43-8C69-40D5902FDC5C}}_is1) (Version: - MSI / Geeks3D) MSVCRT (HKLM-x32\...\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}) (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (HKLM\...\{0C025A40-A716-11E8-953B-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT Redists (HKLM\...\{0EC4A100-12A2-11E9-9504-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT Redists (HKLM\...\{75AFFE51-DA39-11E9-842E-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT110 (HKLM-x32\...\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}) (Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (HKLM\...\{E9FA781F-3E80-4399-825A-AD3E11C28C77}) (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) Nero 7 Ultra Edition (HKLM-x32\...\{2D7D9D86-923A-41A8-919F-437332AB1031}) (Version: 7.02.2760 - Nero AG) NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation) NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation) NVIDIA Grafiktreiber 537.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 537.13 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 21.1.2 - OBS Project) OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20118 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0407-0000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.5.122.52971 - Electronic Arts, Inc.) Panda Devices Agent (HKLM-x32\...\{DB0164A2-ADE9-4FEE-B080-D506BDD6427F}) (Version: 1.08.09 - Panda Security) Hidden Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.09 - Panda Security) Hidden Panda Dome (HKLM\...\{AC555D5A-A9A3-4897-B9E0-97D594F1E10D}) (Version: 12.12.10 - Panda Security) Hidden Panda Dome (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 22.01.01.0000 - Panda Security) Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.1 - Patriot Memory) Hidden Photo Common (HKLM-x32\...\{87DABDEA-47A4-4182-AA7C-2C90DAAE3117}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photo Gallery (HKLM-x32\...\{07AAB66E-4718-422D-9218-4AFB3C922A71}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photolemur (HKLM\...\{7711E044-95EE-4B74-B02E-054F3190A0A9}) (Version: 2.3.0.1796 - Photolemur) Hidden Photolemur (HKLM-x32\...\{e31d858c-09d7-4d60-83f8-600db941fa67}) (Version: 2.3.0.1796 - Photolemur) Photomatix Pro Version 5.1.2 (HKLM\...\PhotomatixPro5x64_is1) (Version: 5.1.2 - HDRsoft Ltd) proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.115.3 - proDAD GmbH) Hidden proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.127 - proDAD GmbH) Hidden proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.257.1 - proDAD GmbH) Hidden proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.257.1 - proDAD GmbH) Hidden proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.244 - proDAD GmbH) Hidden Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9448.1 - Realtek Semiconductor Corp.) RGB Fusion (HKLM-x32\...\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.22.1130.1 - Gigabyte) RivaTuner Statistics Server 7.3.4 (HKLM-x32\...\RTSS) (Version: 7.3.4 - Unwinder) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 7.2.1.980 - Samsung Electronics) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.) Silent Hunter Wolves of the Pacific (HKLM-x32\...\{0D005F09-A5F4-473B-A901-5735C6AF5628}) (Version: 1.00.0000 - Ubisoft) Sp5 (HKLM-x32\...\{560F47F7-EB23-44B1-AAFC-667F1CD8FE5C}) (Version: 5.1.4324.0 - Microsoft) Hidden Sp5Intl (HKLM-x32\...\{FD4B33E1-24AE-4535-AA7B-162B30FB57CD}) (Version: 5.1.4324.0 - Microsoft) Hidden Sp5TTInt (HKLM-x32\...\{E415C943-37E5-473F-8BAE-043C56734124}) (Version: 5.1.4324.0 - Microsoft) Hidden SpCommon (HKLM-x32\...\{6C3959C6-943E-44B3-BAAD-570B04B134E5}) (Version: 5.1.4324.0 - Microsoft) Hidden SpPhones (HKLM-x32\...\{4DFF1415-4C29-44A8-BFD4-2BCE249C4991}) (Version: 6.0.3122.0 - Microsoft) Hidden StatusMonitor (HKLM-x32\...\{D9584EB4-1D28-4BD1-8F81-6E097C0827EE}) (Version: 1.33.1.0 - Brother Industries, Ltd.) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.38.3 - TeamViewer) Telegram Desktop (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.9.2 - Telegram FZ-LLC) Text Speaker 3 (HKLM-x32\...\Text Speaker_is1) (Version: - Deskshare Inc.) Torpedo Traffic Generator Ultimate V8.5 (HKLM\...\{B77E0741-7726-472B-A94A-B19B0EBD3D67}_is1) (Version: - Gem's Softwares) TuneUp Utilities 2008 (HKLM-x32\...\{5888428E-699C-4E71-BF71-94EE06B497DA}) (Version: 7.0.7986 - TuneUp Software) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 98.0 - Ubisoft) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) VEGAS Pro 16.0 (HKLM\...\{0AAC190F-A716-11E8-AD83-00155D6302F2}) (Version: 16.0.261 - VEGAS) Visual C++ 10.0 CRT (x64) (HKLM\...\{BFF61907-AA2D-3A26-8666-98D956A62ABC}) (Version: 10.0 - Microsoft Corporation) Hidden WD P40 Game Drive (HKLM\...\{EE55DBAE-ECDD-4ADD-AAB5-23DE848B0996}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden WhatsApp (Outdated) (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\WhatsApp) (Version: 2.2326.10 - WhatsApp) Winaero Tweaker (HKLM\...\Winaero Tweaker_is1) (Version: 1.55.0.0 - Winaero) Windows Live Communications Platform (HKLM-x32\...\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\{66233218-CA57-4AB2-BA43-A97AA4635960}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Installer (HKLM-x32\...\{659CB81C-B54E-4DF1-B618-F35777393A54}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Photo Common (HKLM-x32\...\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live PIMT Platform (HKLM-x32\...\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE (HKLM-x32\...\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (HKLM-x32\...\{D1893000-EA77-493C-8DDD-E262436E959B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform (HKLM-x32\...\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (HKLM-x32\...\{FC071B45-4A5F-408F-92F8-4D9D693E866F}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows*11-Installationsassistent (HKLM-x32\...\{115DF11E-4B4C-4EA9-9A79-00DB0C7EF02D}) (Version: 1.4.19041.2063 - Microsoft Corporation) Windows-PC-Integritätsprüfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation) Windows-Treiberpaket - Corsair Components, Inc. (SIUSBXP) USB (07/14/2017 3.3) (HKLM\...\A2206C09905C467F30CB24DCBB49F056D7F0A290) (Version: 07/14/2017 3.3 - Corsair Components, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) xat.com Image Optimizer (HKLM-x32\...\xat.com Image Optimizer) (Version: - ) Packages: ========= Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2590.1.0_x64__kgqvnymyfvs32 [2023-08-28] (king.com) Coollage -> C:\Program Files\WindowsApps\63969AppsandFun.Coollage_2.6.0.0_neutral__ffwx7pcdtznr8 [2023-08-28] (Apps and Fun) Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Dropbox -> C:\Program Files (x86)\Dropbox\Client\PackageAssets [2023-08-28] (Dropbox Inc.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] Microsoft.MPEG2VideoExtension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.61931.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Microsoft.WindowsAppRuntime.CBS -> C:\WINDOWS\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Microsoft.XboxCompanion -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] MicrosoftWindows.Client.FileExp -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2023-08-28] (Microsoft Corporation) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-08-28] (NVIDIA Corp.) Pic Collage -> C:\Program Files\WindowsApps\CARDINALBLUE.PICCOLLAGE_2.0.30.0_x64__nyvb5jmhdxy8g [2023-08-28] (Cardinal Blue Software) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.40.287.0_x64__dt26b99r8h8gj [2023-08-28] (Realtek Semiconductor Corp) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2023-08-28] (Twitter Inc.) WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2333.8.0_x64__cv1g1gvanyjgm [2023-08-28] (WhatsApp Inc.) [Startup Task] Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter.gadget\CoreTempReader.dll (AddGadgets IT -> ) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) [Datei ist nicht signiert] CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) [Datei ist nicht signiert] CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 -> => Keine Datei CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{d93ed569-3b3e-4bff-8355-3c44f6a52bb5}\InprocServer32 -> => Keine Datei CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => E:\Dropbox [2023-04-21 14:23] ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Keine Datei ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Keine Datei ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Keine Datei ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Keine Datei ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-08-28] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [TuneUp Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => D:\Program Files (x86)\TuneUp Utilities 2008\SDShelEx-x64.dll [2007-09-04] (TuneUp Software GmbH -> TuneUp Software GmbH) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\nvshext.dll [2023-08-16] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers6: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-08-28] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Drivers32: [VIDC.FPS1] => c:\windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [Datei ist nicht signiert] HKLM\...\Drivers32: [VIDC.RTV1] => c:\windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [Datei ist nicht signiert] HKLM\...\Drivers32: [vidc.pDAD] => c:\windows\system32\prodad-codec.dll [607256 2018-08-30] (proDAD GmbH -> proDAD GmbH) HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [Datei ist nicht signiert] HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [Datei ist nicht signiert] ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\Rose\Desktop\Frederik - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default" ShortcutWithArgument: C:\Users\Rose\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=ghgabhipcejejjmhhchfonmamedcbeod ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============= 2022-12-15 11:32 - 2009-02-27 17:38 - 000139264 ____R () [Datei ist nicht signiert] C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 000542720 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\BrMonitor.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 000208896 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrFirmUpdateCheck.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 001859584 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000232960 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000057344 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000668672 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000074240 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000371712 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000058368 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000074240 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000368640 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll 2017-10-29 00:00 - 2006-02-23 11:35 - 000020480 ____R () [Datei ist nicht signiert] C:\WINDOWS\System32\FritzColorPort64.dll 2017-02-14 16:20 - 2015-03-12 04:43 - 000022528 ____R () [Datei ist nicht signiert] C:\WINDOWS\System32\us00alm.dll 2022-12-15 11:32 - 2008-08-18 19:27 - 000122880 ____N (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\brlmw03a.dll 2017-06-20 11:34 - 2017-06-20 11:34 - 000349696 ____R (Intel(R) Corporation) [Datei ist nicht signiert] C:\WINDOWS\system32\NCS2Setp.dll 2018-07-15 13:15 - 2018-07-15 13:15 - 003664696 _____ (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll 2003-04-02 17:22 - 2003-04-02 17:22 - 000024576 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\1031\mdmui.dll 2023-04-29 22:13 - 2023-04-29 22:13 - 001654784 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\WINDOWS\WinSxS\Fusion\amd64_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_none_758c8a477f89a995\8.0\8.0.50727.6195\MFC80U.DLL 2023-04-29 22:13 - 2023-04-29 22:13 - 000054272 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\WINDOWS\WinSxS\Fusion\amd64_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_none_eeb8165fbcb9c171\8.0\8.0.50727.6195\MFC80DEU.DLL 2023-01-17 14:13 - 2023-01-17 14:13 - 000090112 _____ (Silicon Laboratories, Inc.) [Datei ist nicht signiert] C:\Program Files\Corsair\CORSAIR iCUE 4 Software\SiUSBXp.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\LIBEAY32.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\ssleay32.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001611264 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\platforms\qwindows.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005487104 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Core.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005841920 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Gui.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001179136 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Network.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000146432 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5WebSockets.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005089792 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Widgets.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000184832 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Xml.dll 2017-10-29 00:00 - 2006-02-23 12:16 - 000047616 ____R (TODO: <Company name>) [Datei ist nicht signiert] C:\WINDOWS\System32\AvmColorFax.dll 2023-08-25 04:38 - 2023-08-25 04:38 - 000643584 _____ (VALINET Solutions SRL) [Datei ist nicht signiert] C:\WINDOWS\dxgi.dll 2017-02-14 16:20 - 2015-08-20 03:14 - 000043520 ____R (Windows (R) Codename Longhorn DDK provider) [Datei ist nicht signiert] C:\WINDOWS\system32\spool\PRTPROCS\x64\us00apc.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\usosvc.dll:com.dropbox.attrs [52] AlternateDataStreams: C:\WINDOWS\SysWOW64\CH341DLL.DLL:com.dropbox.attributes [168] AlternateDataStreams: C:\WINDOWS\SysWOW64\CH341DLL.DLL:com.dropbox.attrs [54] AlternateDataStreams: C:\WINDOWS\SysWOW64\USBIOX.DLL:com.dropbox.attributes [168] AlternateDataStreams: C:\WINDOWS\SysWOW64\USBIOX.DLL:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Rose\Desktop\Top 500 Referer Links.txt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Rose\Downloads\www-rzmenden-de_20210628T051507Z_DisavowLinks.txt:com.dropbox.attrs [52] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ================= ==================== Internet Explorer (Nicht auf der Ausnahmeliste) ========== HKU\S-1-5-21-653905286-3903209159-424152592-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO-x32: Foxit PhantomPDF Create PDF ToolBar Helper -> {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-04-16] (Foxit Software Incorporated -> ) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-04-16] (Foxit Software Incorporated -> ) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1473946269758 Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts Inhalt: ========================= (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2015-10-30 09:24 - 2018-10-23 10:09 - 000001736 ____R C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 cap.cyberlink.com 127.0.0.1 activation.cyberlink.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 tools.avanquest.com 127.0.0.1 api.avanquest.com 127.0.0.1 aims.avanquest.com 127.0.0.1 widgetcast.reallusion.com 127.0.0.1 da.reallusion.com 127.0.0.1 ctifiles2.reallusion.com ==================== Andere Bereiche =========================== (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> c:\programdata\oracle\java\javapath;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0;c:\program files (x86)\windows live\shared;c:\program files (x86)\skype\phone;c:\windows\system32\openssh;c:\program files\nvidia corporation\nvidia nvdlisr;c:\windows\system32\windowspowershell\v1.0\;c:\windows\system32\openssh\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NGX;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Common Files\Ulead Systems\Mpeg;C:\Program Files\dotnet\ HKU\S-1-5-21-653905286-3903209159-424152592-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rose\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\wallpaper672898.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1) HKU\S-1-5-21-653905286-3903209159-424152592-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1) ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) MSCONFIG\Services: WsAppService => 3 HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "Reflect UI" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\StartupFolder: => "Logitech . Produktregistrierung.lnk" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "iFunBox" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "Adobe Reader Synchronizer" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{B0A9A42B-A8C1-478A-A44E-871CC9572330}C:\program files\logioptionsplus\logioptionsplus_agent.exe] => (Allow) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{6E4EAA32-A326-4A41-8353-58047494A768}C:\program files\logioptionsplus\logioptionsplus_agent.exe] => (Allow) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{B458A398-D033-469D-8C1D-8FA996CE7DFA}] => (Block) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{FE563E98-0315-48D3-8BC1-9CE950B855D8}] => (Block) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{F67264B9-4271-4BB3-AE2A-4F0044F9BF67}C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe] => (Allow) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{A857FE7E-6FFD-4DD5-B85B-D4EE1FFD106B}C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe] => (Allow) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{4C9D908D-2400-4B13-95B7-71B80215BE23}] => (Block) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{7930E66B-D922-4728-A2CB-9E4EB4072804}] => (Block) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{AAB9C3B9-D4C2-4907-B6D6-541476651529}C:\program files (x86)\dropbox\client\dropbox.exe] => (Allow) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [UDP Query User{0AA3A383-0D16-406D-B955-87061C7435FF}C:\program files (x86)\dropbox\client\dropbox.exe] => (Allow) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{364E4381-3CC8-447F-9DF6-B884EA7E0D9F}] => (Block) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{0110C8BD-70BB-4818-BC97-D87E71479B98}] => (Block) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{CAE99229-255E-4FB5-9FEE-7E2D6E1D800B}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23216.905.2334.6698_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{3E396E06-26F9-4D6B-95BE-7F611DCFC439}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23216.905.2334.6698_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= 28-08-2023 09:31:14 Windows Modules Installer ==================== Fehlerhafte Geräte im Gerätemanager ============ Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ======================== Applikationsfehler: ================== Error: (08/28/2023 07:28:27 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode: hr=0xC004F074 Befehlszeilenargumente: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (08/28/2023 07:28:05 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode: hr=0xC004F074 Befehlszeilenargumente: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (08/28/2023 07:26:53 PM) (Source: Application Error) (EventID: 1000) (User: NT-AUTORITÄT) Description: Name der fehlerhaften Anwendung: SecurityHealthService.exe, Version: 10.0.22621.1635, Zeitstempel: 0xc9cb2878 Name des fehlerhaften Moduls: ucrtbase.dll, Version: 10.0.22621.608, Zeitstempel: 0xf5fc15a3 Ausnahmecode: 0xc0000409 Fehleroffset: 0x000000000007f61e ID des fehlerhaften Prozesses: 0x0x4860 Startzeit der fehlerhaften Anwendung: 0x0x1d9d9d4c3e89b5a Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\SecurityHealthService.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\SYSTEM32\ucrtbase.dll Berichtskennung: e521a5bb-032c-48c6-9901-03d600f83b38 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (08/28/2023 07:26:43 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/28/2023 07:26:43 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/28/2023 07:26:43 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/28/2023 07:26:43 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/28/2023 07:26:40 PM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Systemfehler: ============= Error: (08/28/2023 07:26:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows-Sicherheitsdienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/28/2023 07:26:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst asComSvc erreicht. Error: (08/28/2023 07:26:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "UxTuneUp" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (08/28/2023 07:26:05 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst UxTuneUp erreicht. Error: (08/28/2023 07:26:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "WSearch" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/28/2023 07:26:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "WSearch" wurde mit folgendem Fehler beendet: Der RPC-Server ist nicht verfügbar. Error: (08/28/2023 07:12:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst asComSvc erreicht. Error: (08/28/2023 07:12:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "UxTuneUp" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. CodeIntegrity: =============== Date: 2023-08-28 19:28:52 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Panda Security\Panda Security Protection\PSNWSC.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2023-08-28 19:26:54 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system. Date: 2023-08-28 19:25:57 Description: Code Integrity determined that a process (System) attempted to load \Device\HarddiskVolume4\Windows\SysWOW64\drivers\AsIO.sys that did not meet the Authenticode signing level requirements or violated code integrity policy (Policy ID:{d2bda982-ccf6-4344-ac5b-0b44427b6816}). Date: 2023-08-28 19:25:57 Description: The driver \Device\HarddiskVolume4\Windows\SysWOW64\drivers\AsIO.sys is blocked from loading as the driver has been revoked by Microsoft. Date: 2023-08-28 19:25:57 Description: Code Integrity determined that a process (System) attempted to load \Device\HarddiskVolume4\Windows\System32\drivers\GLCKIO2.sys that did not meet the Authenticode signing level requirements or violated code integrity policy (Policy ID:{d2bda982-ccf6-4344-ac5b-0b44427b6816}). Date: 2023-08-28 19:25:57 Description: The driver \Device\HarddiskVolume4\Windows\System32\drivers\GLCKIO2.sys is blocked from loading as the driver has been revoked by Microsoft. Date: 2023-08-28 19:22:12 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== BIOS: American Megatrends International, LLC. 5.04 06/15/2023 Hauptplatine: ASRock B760M Steel Legend WiFi Prozessor: 13th Gen Intel(R) Core(TM) i5-13600 Prozentuale Nutzung des RAM: 27% Installierter physikalischer RAM: 32522.63 MB Verfügbarer physikalischer RAM: 23709.2 MB Summe virtueller Speicher: 34570.63 MB Verfügbarer virtueller Speicher: 20186.56 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:463.52 GB) (Free:334.73 GB) (Model: Samsung SSD 980 PRO 500GB) NTFS Drive d: () (Fixed) (Total:465.75 GB) (Free:310.96 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS Drive e: () (Fixed) (Total:465.75 GB) (Free:304.09 GB) (Model: CT500P3SSD8) NTFS \\?\Volume{cc76ba45-879a-436a-b7c9-8e215cafa51a}\ (Wiederherstellung) (Fixed) (Total:0.58 GB) (Free:0.09 GB) NTFS \\?\Volume{92376e1a-4fb5-499f-a317-a248ef0dde91}\ () (Fixed) (Total:0.73 GB) (Free:0.08 GB) NTFS \\?\Volume{668c8dc3-fb7d-4d2c-a445-06f4db319cea}\ () (Fixed) (Total:0.59 GB) (Free:0.08 GB) NTFS \\?\Volume{04e2fe14-5f6b-44d9-855f-eca23a75003f}\ () (Fixed) (Total:0.32 GB) (Free:0.29 GB) FAT32 ==================== MBR & Partitionstabelle ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 2 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ======================= |
29.08.2023, 06:59 | #3 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Sicherheit / Defender zerschossenZitat:
Code:
ATTFilter 127.0.0.1 cap.cyberlink.com 127.0.0.1 activation.cyberlink.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 tools.avanquest.com 127.0.0.1 api.avanquest.com 127.0.0.1 aims.avanquest.com 127.0.0.1 widgetcast.reallusion.com 127.0.0.1 da.reallusion.com 127.0.0.1 ctifiles2.reallusion.com Cracks, Keygens und andere illegale Software Bitte lesen => Cracks, Keygens und andere illegale Software Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ |
29.08.2023, 07:24 | #4 |
| Windows Sicherheit / Defender zerschossen Besten Dank für den Hinweis. Diese Programme sind meine ich gar nicht installiert. Hatte die Kiste 2017 von meinem Bruder übernommen und immer nur die Hardware erneuert. Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2023 durchgeführt von Rose (Administrator) auf WORKSTATION (ASRock B760M Steel Legend WiFi) (29-08-2023 08:17:15) Gestartet von C:\Users\Rose\Downloads\FRST64.exe Geladene Profile: Rose Plattform: Microsoft Windows 11 Pro Version 22H2 22621.2134 (X64) Sprache: Deutsch (Deutschland) Standard-Browser: FF Start-Modus: Normal ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe (C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe ->) (Logitech, Inc. -> ) C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.CpuIdRemote64.exe (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe (C:\Program Files\Logi\LogiBolt\LogiBolt.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logi\LogiBolt\logi_crashpad_handler.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe (C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe (C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <8> (explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\Program Files\Classic Shell\ClassicStartMenu.exe (explorer.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logi\LogiBolt\LogiBolt.exe (explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <9> (explorer.exe ->) (Nenad Hrg SoftwareOK) [Datei ist nicht signiert] C:\Users\Rose\Downloads\DesktopOK401_x64\DesktopOK_x64.exe (explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe (explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.303\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.303\GoogleCrashHandler64.exe (hvsimgr.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsirdpclient.exe (hvsimgr.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsirpcd.exe (Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe (services.exe ->) (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\BrYNSvc.exe (services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe (services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe (services.exe ->) (DEVGURU CO LTD -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) D:\Program Files (x86)\Origin\OriginWebHelperService.exe (services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe (services.exe ->) (eVenture Limited -> eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe (services.exe ->) (Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_21e0cf0737fd48af\WMIRegistrationService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Intel(R) INTELND1617S2 -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Panda Security S.L. -> Panda Security S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\pselamsvc.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (services.exe ->) (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_2d0366e4f3ea0eab\RtkAudUService64.exe <2> (services.exe ->) (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) D:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) D:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\hvsimgr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.22621.2061_none_e9764a2042bb8e95\TiWorker.exe (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (vmcompute.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\vmwp.exe konnte nicht auf den Prozess zugreifen -> vmmemCmZygote konnte nicht auf den Prozess zugreifen -> vmmemMDAG ==================== Registry (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1687616 2022-02-21] (Logitech Inc -> Logitech, Inc.) HKLM\...\Run: [LogiBolt] => C:\Program Files\Logi\LogiBolt\LogiBolt.exe [22423104 2021-12-14] (Logitech Inc -> Logitech) HKLM\...\Run: [EPSON Stylus DX4200 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_FATIAEE.EXE [98304 2005-03-08] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9923856 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) HKLM\...\Run: [CORSAIR iCUE 4 Software] => C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe [185384 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_2d0366e4f3ea0eab\RtkAudUService64.exe [1629080 2022-12-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [11559648 2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3146752 2022-02-07] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [BrStsInd00] => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe [1885184 2012-12-18] (Brother Industries, Ltd.) [Datei ist nicht signiert] HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [186984 2022-11-02] (Panda Security S.L. -> Panda Security, S.L.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Beschränkung <==== ACHTUNG HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\Run: [DesktopOK] => C:\Users\Rose\Downloads\DesktopOK401_x64\DesktopOK_x64.exe [429568 2014-11-06] (Nenad Hrg SoftwareOK) [Datei ist nicht signiert] HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\Run: [LogiBolt] => C:\Program Files\Logi\LogiBolt\LogiBolt.exe [22423104 2021-12-14] (Logitech Inc -> Logitech) HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\Run: [MicrosoftEdgeAutoLaunch_9953146D049CCFE434D0A8BCA98616C7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4107728 2023-08-25] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Windows x64\Print Processors\HPZPP4wm: C:\Windows\System32\spool\prtprocs\x64\hpzpp4wm.DLL [231424 2007-02-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\...\Windows x64\Print Processors\us00aPC: C:\Windows\System32\spool\prtprocs\x64\us00apc.dll [43520 2015-08-20] (Windows (R) Codename Longhorn DDK provider) [Datei ist nicht signiert] HKLM\...\Print\Monitors\EPSON Stylus DX4200 Series 64MonitorBE: c:\windows\system32\E_ILMAEE.DLL [119808 2005-06-09] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\FRITZ!fax Color Port Monitor: c:\windows\system32\FritzColorPort64.dll [20480 2006-02-23] () [Datei ist nicht signiert] HKLM\...\Print\Monitors\us00a Langmon: c:\windows\system32\us00alm.dll [22528 2015-03-12] () [Datei ist nicht signiert] HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\116.0.5845.111\Installer\chrmstp.exe [2023-08-24] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2017-03-30] BootExecute: autocheck autochk * GroupPolicy: Beschränkung ? <==== ACHTUNG Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {019543EE-4D13-47D1-A0AE-774120648F52} - kein Dateipfad. <==== ACHTUNG Task: {079BF05B-A922-41CC-8513-A20AC421527C} - kein Dateipfad. <==== ACHTUNG Task: {0976C0B9-CC98-4BE1-8745-2716F212A9B3} - kein Dateipfad. <==== ACHTUNG Task: {0D7750E2-4B7C-400D-A0AD-71D122F98808} - kein Dateipfad. <==== ACHTUNG Task: {0DD4A495-11E8-4130-A524-4345DF5094CE} - kein Dateipfad. <==== ACHTUNG Task: {23B23D6A-BEBC-40BD-8422-F5C235961F96} - kein Dateipfad. <==== ACHTUNG Task: {2A378261-E64E-4B8F-80F6-0E8D07253E0C} - kein Dateipfad. <==== ACHTUNG Task: {30DD5265-0548-442F-A318-3B77A9F85B6D} - kein Dateipfad. <==== ACHTUNG Task: {45CC81A7-585B-493F-9D83-842B2EDCE6F8} - kein Dateipfad. <==== ACHTUNG Task: {47F15474-4AA4-4662-9AB5-7714590493F8} - kein Dateipfad. <==== ACHTUNG Task: {482F1863-5C9C-43DB-B601-C02069B2AAD2} - kein Dateipfad. <==== ACHTUNG Task: {4C9708CB-12E0-4627-9DB3-77711015D1A0} - kein Dateipfad. <==== ACHTUNG Task: {53436A7B-2D56-428D-9F5A-5D8DCE1B3262} - kein Dateipfad. <==== ACHTUNG Task: {5C4F63E8-A2A1-4411-80F9-C34BADC60D1D} - \RegistryUpdateTaskMachineQC -> Keine Datei <==== ACHTUNG Task: {66569078-72BD-41CB-99C6-D2C7E01B1D8D} - kein Dateipfad. <==== ACHTUNG Task: {6C6A7BDE-AE9F-483E-B068-B77A3073717A} - kein Dateipfad. <==== ACHTUNG Task: {6D2460A7-E9AD-4BC0-B792-338CB355F534} - kein Dateipfad. <==== ACHTUNG Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - kein Dateipfad. <==== ACHTUNG Task: {6FEFB20E-C881-4846-93A2-8219EE4B030A} - kein Dateipfad. <==== ACHTUNG Task: {7746E1E7-838C-4BF1-81C8-CF39DACB475D} - kein Dateipfad. <==== ACHTUNG Task: {86976673-D178-4FCB-AA2F-65B60CBFBE88} - kein Dateipfad. <==== ACHTUNG Task: {99DBFDE7-3F67-43E5-A624-A1B89879B406} - kein Dateipfad. <==== ACHTUNG Task: {9B196E71-4EDC-4D39-9C8A-4F7282EA54A5} - kein Dateipfad. <==== ACHTUNG Task: {A111E0AA-0D9F-4806-9F32-CB859C97D809} - kein Dateipfad. <==== ACHTUNG Task: {A2F854F6-B58F-440F-872A-4D4D14F2FE37} - kein Dateipfad. <==== ACHTUNG Task: {A39FED60-980C-494D-9856-E82F883B38AB} - kein Dateipfad. <==== ACHTUNG Task: {A3EFC5B4-B0A2-499D-AC5A-EE384B5F2D9D} - kein Dateipfad. <==== ACHTUNG Task: {AB3CBDE6-13CB-46A4-B8D6-F68531AE03A2} - kein Dateipfad. <==== ACHTUNG Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - kein Dateipfad. <==== ACHTUNG Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - kein Dateipfad. <==== ACHTUNG Task: {E261A39A-D677-4C52-AB94-4DAF87807935} - \Microsoft\Windows\Windows Media Sharing\UpdateLibrary -> Keine Datei <==== ACHTUNG Task: {E2BA1A3B-DD07-4BB8-B6A2-509CD4B02076} - kein Dateipfad. <==== ACHTUNG Task: {E58546D5-78FB-4E1E-8B88-DBB389CB90F2} - kein Dateipfad. <==== ACHTUNG Task: {F77C5FA7-BE5B-469F-86B8-1F45E4C3A18A} - kein Dateipfad. <==== ACHTUNG Task: {75D90835-F902-4AFD-8F19-A2DF70584784} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [5158128 2023-08-28] (Microsoft Windows -> Microsoft Corporation) Task: {44DCF4A0-FDC0-4EB6-9B4B-53CE075FCC88} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-30] (Google Inc -> Google Inc.) Task: {171A9E07-A4B1-4734-B0E6-7F283EA92EEE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-30] (Google Inc -> Google Inc.) Task: {DFA2BB8A-66DA-4D1B-9EB2-D1CE83596EB8} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {55690238-06EB-4FEF-86A9-E2C2D382531E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {13211ECA-9467-47CE-B947-F6E2B8CCB60A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {19335547-F2A5-4475-980E-0A6BF4AA7072} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {034E3EA1-268F-43F7-A9BF-663A09A936D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A25C12E0-7DB4-403C-BE95-A9F17413BC94} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [804408 2021-12-03] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {12F46FC7-E6BE-4480-A3B4-7ECE2E0F0E50} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-04-14] (Nvidia Corporation -> NVIDIA Corporation) Task: {0955ED6F-2DA0-4379-9C03-EFBD9D5FCD59} - System32\Tasks\SamsungMagician => d:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [121595968 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{34fbb743-8760-4fd5-a0ef-1e96048221fc}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{562f06cc-f48d-4fbe-bed3-376de26e94fd}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{81b80bfe-ff7c-4c3f-aba3-bae76196dd35}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{9d891342-3300-4267-8825-19017538f47d}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{fcee5666-980f-467d-8912-a6b1b325618e}: [DhcpNameServer] 192.168.178.1 Edge: ======= DownloadDir: C:\Users\Rose\Downloads Edge Notifications: HKU\S-1-5-21-653905286-3903209159-424152592-1001 -> hxxps://www.facebook.com; hxxps://www.mann.tv; hxxps://www.ruhr24.de Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden] Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden] Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden] Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden] Edge Profile: C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default [2023-08-29] Edge DownloadDir: Default -> C:\Users\Rose\Downloads Edge Notifications: Default -> hxxps://www.facebook.com; hxxps://www.mann.tv; hxxps://www.ruhr24.de Edge StartupUrls: Default -> "hxxps://de-de.facebook.com/" Edge Extension: (Google Webspam Report (by Google)) - C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\efinmbicabejjhjafeidhfbojhnfiepj [2020-12-19] Edge Extension: (Google Docs Offline) - C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-29] Edge Extension: (Edge relevant text changes) - C:\Users\Rose\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-08-09] FireFox: ======== FF DefaultProfile: pt4v4e5g.default-1490937754028 FF ProfilePath: C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 [2023-08-29] FF user.js: detected! => C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\user.js [2022-08-11] FF Homepage: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> www.google.de FF NetworkProxy: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> type", 0 FF Notifications: Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028 -> hxxps://www.facebook.com; hxxps://twitter.com; hxxps://www.online-slot.de FF Extension: (German dictionary (de_DE)) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\de_DE@dicts.j3e.de.xpi [2018-12-02] FF Extension: (uBlock Origin) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\uBlock0@raymondhill.net.xpi [2023-07-26] FF Extension: (TWP - Translate Web Pages) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2023-08-03] FF Extension: (SEOquake) - C:\Users\Rose\AppData\Roaming\Mozilla\Firefox\Profiles\pt4v4e5g.default-1490937754028\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}.xpi [2023-01-17] FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF Extension: (Foxit PDF Creator) - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2018-01-29] [] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-08-19] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [Datei ist nicht signiert] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-04-08] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corporation -> Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems Incorporated -> Adobe Systems) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default [2023-08-29] CHR Extension: (SEO META in 1 CLICK) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjogjfinolnhfhkbipphpdlldadpnmhc [2021-07-05] CHR Extension: (uBlock Origin) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2023-07-24] CHR Extension: (Google Webspam Report (by Google)) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\efinmbicabejjhjafeidhfbojhnfiepj [2021-02-21] CHR Extension: (Word Counter Plus) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpjegfbcdijjfkceenlfoehpcakfgldj [2021-05-22] CHR Extension: (Google Docs Offline) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-23] CHR Extension: (Click&Clean) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2023-02-17] CHR Extension: (Google PageSpeed Insights API Extension) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfebkooaidmeboeblkkejdoepilnnjhn [2020-11-03] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30] CHR Extension: (Disavow File Generator Tool) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkppdgpkjmclhhlibhdphbllcgpllbch [2021-06-27] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-05-10] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2 [2023-08-03] CHR Extension: (Foxit PDF Creator) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2023-01-28] CHR Extension: (Google Docs Offline) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-03] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Rose\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-01-28] CHR Profile: C:\Users\Rose\AppData\Local\Google\Chrome\User Data\System Profile [2023-08-19] CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2023-01-28] CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2023-01-28] ==================== Dienste (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [103264 2023-03-01] (Apple Inc. -> Apple Inc.) S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-01-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-10-03] (BattlEye Innovations e.K. -> ) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2022-01-26] (Brother Industries, Ltd.) [Datei ist nicht signiert] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11878368 2023-08-04] (Microsoft Corporation -> Microsoft Corporation) R2 CMigrationService; d:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe [761408 2023-01-16] (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [614432 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R2 CorsairLLAService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe [238632 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) R2 CorsairService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe [84008 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) S2 CorsairUniwillService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueUniwillService.exe [108072 2023-01-20] (Corsair Memory, Inc. -> Corsair Memory, Inc.) S3 CyberGhost8Service; C:\Program Files\CyberGhost 8\Dashboard.Service.exe [69840 2023-07-11] (CyberGhost S.R.L. -> CyberGhost S.R.L.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-11] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-11] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [46824 2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-10-03] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-05-01] (Epic Games Inc. -> Epic Games, Inc.) S3 FoxitPhantomService; D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitConnectedPDFService.exe [1658944 2018-04-17] (Foxit Software Incorporated -> Foxit Software Inc.) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [347408 2023-06-08] (Underwriters Laboratories Inc. -> Futuremark) R2 GUBootService; C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe [886528 2023-01-15] (Glarysoft LTD -> Glarysoft Ltd) S3 GUPMService; d:\Program Files (x86)\Glary Utilities 5\GUPMService.exe [76696 2023-08-26] (Glarysoft Ltd -> Glarysoft Ltd) R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [180496 2022-12-10] (eVenture Limited -> eVenture Limited) S3 iCUEDevicePluginHost; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUEDevicePluginHost.exe [462888 2023-01-20] (Corsair Memory, Inc. -> Corsair) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert] R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9286168 2023-08-28] (Malwarebytes Inc. -> Malwarebytes) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Datei ist nicht signiert] R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [118504 2022-10-31] (Panda Security S.L. -> Panda Security, S.L.) R2 OptionsPlusUpdaterService; C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe [17874688 2023-08-07] (Logitech Inc -> Logitech, Inc.) S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2572096 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; D:\Program Files (x86)\Origin\OriginWebHelperService.exe [3491144 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts) S3 Panda VPN Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\Hydra.Sdk.Windows.Service.exe [320848 2017-11-20] (AnchorFree Inc -> ) R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [84176 2019-02-19] (Panda Security S.L. -> Panda Security, S.L.) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2016-12-31] (Even Balance, Inc. -> ) R2 pselamsvc; C:\Program Files (x86)\Panda Security\Panda Security Protection\pselamsvc.exe [195736 2023-04-13] (Panda Security S.L. -> Panda Security S.L.) R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [78840 2022-11-02] (Panda Security S.L. -> Panda Security, S.L.) R2 SamsungMagicianSVC; d:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe [371776 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402200 2023-08-28] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU CO LTD -> DEVGURU Co., LTD.) R2 TeamViewer; d:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [15212856 2023-01-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) S4 TuneUp.Defrag; C:\WINDOWS\System32\TuneUpDefragService.exe [425216 2017-11-22] (TuneUp Software GmbH -> TuneUp Software GmbH) S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-12-14] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\NisSrv.exe [3104488 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe [133576 2023-08-09] (Microsoft Windows Publisher -> Microsoft Corporation) S4 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe [495720 2018-07-04] (Wondershare Technology Co.,Ltd -> Wondershare) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Treiber (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> ) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-04-15] (ASUSTeK Computer Inc. -> ) S3 AsrDrv101; C:\WINDOWS\SysWOW64\Drivers\AsrDrv101.sys [22280 2017-05-09] (ASROCK Incorporation -> ASRock Incorporation) S3 AsrDrv102; C:\WINDOWS\SysWOW64\Drivers\AsrDrv102.sys [22248 2018-01-17] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv103; C:\WINDOWS\SysWOW64\Drivers\AsrDrv103.sys [34568 2019-11-05] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv104; C:\WINDOWS\SysWOW64\Drivers\AsrDrv104.sys [34536 2022-01-16] (ASROCK Incorporation -> ASRock Incorporation) [Datei ist nicht signiert] S3 AsrDrv106; C:\WINDOWS\SysWOW64\Drivers\AsrDrv106.sys [49984 2023-01-28] (ASROCK INC. -> ASRock Incorporation) R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [310984 2018-12-15] (Tages SA -> ) S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin2\brynhildr.sys [2188544 2022-12-15] (Activision Publishing Inc -> Activision Blizzard, Inc.) S3 avmaura; C:\WINDOWS\System32\drivers\avmaura.sys [116480 2016-07-27] (AVM Berlin) [Datei ist nicht signiert] S1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [144456 2016-01-22] (Rivet Networks LLC -> Rivet Networks, LLC.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [532480 2023-05-05] (Microsoft Corporation) [Datei ist nicht signiert] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [184320 2023-05-05] (Microsoft Corporation) [Datei ist nicht signiert] S3 CH341_A64; C:\WINDOWS\System32\Drivers\CH341W64.SYS [31232 2009-06-12] (Microsoft Windows Hardware Compatibility Publisher -> www.winchiphead.com) S3 CorsairGamingAudioService; C:\Windows\System32\drivers\CorsairGamingAudio64.sys [63008 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2023-01-20] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47032 2022-12-09] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [22968 2022-12-09] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) R3 cpuz154; C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys [40976 2023-08-29] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [32880 2023-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.) S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31376 2015-03-10] (PassMark Software Pty Ltd -> ) S3 dpK00701; C:\WINDOWS\System32\drivers\dpK00701.sys [64016 2010-02-24] (DigitalPersona, Inc. -> DigitalPersona, Inc.) R0 fse; C:\WINDOWS\System32\drivers\fse.sys [218464 2023-08-28] (Microsoft Windows -> Microsoft Corporation) S3 gdrv; C:\WINDOWS\gdrv.sys [26792 2018-01-25] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) S3 gdrv3; C:\WINDOWS\system32\drivers\gdrv3.sys [45248 2023-04-09] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2016-12-11] (Sony Mobile Communications AB -> Sony Mobile Communications) S1 GLCKIO2; C:\WINDOWS\system32\drivers\GLCKIO2.sys [19392 2018-04-23] (ASUSTeK Computer Inc. -> ) R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [23568 2023-07-19] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd) R1 hideFirewall; C:\WINDOWS\System32\drivers\hideFirewall.sys [100352 2021-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Hewlett-Packard.) [Datei ist nicht signiert] S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Hewlett-Packard.) [Datei ist nicht signiert] S3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.) S3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-12-20] (Logitech Inc -> Logitech Inc.) R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [42696 2018-12-15] (Tages SA -> ) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-08-28] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-08-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 MHIKEY10; C:\WINDOWS\System32\Drivers\MHIKEY10x64.sys [59008 2007-07-04] (Microsoft Windows Hardware Compatibility Publisher -> ChunghwaTL) S3 MSIO; C:\Program Files (x86)\ASRock Utility\ASRRGBLED\Bin\msio64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-04-15] (Apple Inc.) [Datei ist nicht signiert] R1 NNSDNS; C:\WINDOWS\system32\DRIVERS\NNSDNS.sys [146184 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [215264 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [128744 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [146664 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [151152 2022-10-10] (Microsoft Windows Hardware Compatibility Publisher -> Panda Security, S.L.) R1 NNSNHWFP; C:\WINDOWS\system32\DRIVERS\NNSNHWFP.sys [211208 2022-12-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [164568 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [137960 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [407264 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [575720 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [125672 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [335064 2022-11-06] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2023-04-14] (Nvidia Corporation -> NVIDIA Corporation) S3 PAC207; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [686592 2008-02-13] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Inc.) R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [198376 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) S0 psinelam; C:\WINDOWS\System32\DRIVERS\psinelam.sys [36552 2023-04-13] (Microsoft Windows Early Launch Anti-Malware Publisher -> Panda Security, S.L.) R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [176360 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [218856 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [150760 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [162536 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [130280 2022-11-03] (WatchGuard Technologies, Inc. -> Panda Security, S.L.) U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72984 2019-02-20] (Panda Security S.L. -> Panda Security, S.L.) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) S3 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [132584 2017-10-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) S3 usbdpfp; C:\WINDOWS\System32\drivers\usbdpfp.sys [67088 2010-02-24] (DigitalPersona, Inc. -> DigitalPersona, Inc.) S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [94208 2023-08-28] (Microsoft Windows -> ) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55704 2023-08-09] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572656 2023-08-09] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [104688 2023-08-09] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\WINDOWS\system32\DRIVERS\wintun.sys [29680 2023-06-15] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2019-12-14] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat (erstellte) (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-08-29 08:16 - 2019-02-20 07:31 - 000072984 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSKMAD.sys 2023-08-29 08:15 - 2023-08-29 08:15 - 000003132 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner 2023-08-28 20:26 - 2023-08-28 20:26 - 000074542 _____ C:\Users\Rose\Downloads\Addition.txt 2023-08-28 20:25 - 2023-08-29 08:17 - 000050409 _____ C:\Users\Rose\Downloads\FRST.txt 2023-08-28 20:25 - 2023-08-29 08:17 - 000000000 ____D C:\FRST 2023-08-28 20:24 - 2023-08-28 20:24 - 002382336 _____ (Farbar) C:\Users\Rose\Downloads\FRST64.exe 2023-08-28 19:26 - 2023-08-28 19:26 - 000003832 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{7B919D33-27BD-435F-AB1E-5784AD3F09A6} 2023-08-28 19:26 - 2023-08-28 19:26 - 000003708 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{46F3BE1D-EC51-4C50-8452-7658FEEDA63F} 2023-08-28 19:17 - 2023-08-28 19:17 - 000002320 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Dome.lnk 2023-08-28 19:16 - 2023-08-28 19:17 - 000002305 _____ C:\Users\Public\Desktop\Panda Dome.lnk 2023-08-28 19:16 - 2023-08-28 19:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Dome 2023-08-28 19:16 - 2022-12-06 12:53 - 000211208 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsnhwfp.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000575720 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsprv.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000407264 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsprot.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000335064 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsstrm.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000215264 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnshttp.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000164568 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnspicc.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000146664 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsids.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000146184 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnsdns.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000137960 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnspop3.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000128744 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnshttps.sys 2023-08-28 19:16 - 2022-11-06 12:24 - 000125672 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\nnssmtp.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000218856 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINKNC.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000198376 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINAflt.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000176360 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINFile.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000162536 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProt.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000150760 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProc.sys 2023-08-28 19:16 - 2022-11-03 01:33 - 000130280 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINReg.sys 2023-08-28 19:12 - 2023-08-28 19:12 - 000000000 ____D C:\WINDOWS\Panther 2023-08-28 18:47 - 2023-08-28 18:48 - 000000000 ___HD C:\$WinREAgent 2023-08-28 18:04 - 2023-08-28 18:04 - 000000000 ____D C:\Users\Rose\Downloads\Autoruns 2023-08-28 17:43 - 2023-08-28 17:49 - 000012288 _____ C:\WINDOWS\SysWOW64\AppRulesStorage 2023-08-28 17:43 - 2023-08-28 17:43 - 000012288 _____ C:\WINDOWS\SysWOW64\DnsStorage 2023-08-28 17:42 - 2023-08-28 17:49 - 000000000 ____D C:\Program Files\Common Files\AV 2023-08-28 17:38 - 2023-08-28 18:41 - 000000000 ____D C:\Users\Rose\AppData\Local\ESET 2023-08-28 17:33 - 2023-08-28 17:35 - 000000000 ____D C:\ProgramData\HitmanPro 2023-08-28 14:30 - 2023-08-28 14:30 - 000000000 ___HD C:\$SysReset 2023-08-28 13:09 - 2023-08-28 18:54 - 000000000 ____D C:\Users\Rose\AppData\Local\Malwarebytes 2023-08-28 13:09 - 2023-08-28 13:09 - 000002041 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2023-08-28 13:09 - 2023-08-28 13:09 - 000002029 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2023-08-28 13:08 - 2023-08-28 13:08 - 000000000 ____D C:\Program Files\Malwarebytes 2023-08-28 11:18 - 2023-08-28 20:56 - 000000000 ____D C:\Users\Rose\Desktop\Neuer Ordner 2023-08-28 10:54 - 2023-08-28 19:16 - 000000000 ____D C:\ProgramData\Panda Security 2023-08-28 10:54 - 2023-08-28 19:16 - 000000000 ____D C:\Program Files (x86)\Panda Security 2023-08-28 10:54 - 2023-08-28 10:54 - 003142712 _____ (Panda Security, S.L.) C:\Users\Rose\Downloads\PANDAFREEAV.exe 2023-08-28 10:03 - 2023-08-28 20:47 - 000000000 ____D C:\KVRT2020_Data 2023-08-28 09:22 - 2023-08-29 08:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-08-28 09:22 - 2023-08-28 12:10 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2023-08-28 09:22 - 2023-08-28 09:22 - 000011433 _____ C:\WINDOWS\diagwrn.xml 2023-08-28 09:22 - 2023-08-28 09:22 - 000011433 _____ C:\WINDOWS\diagerr.xml 2023-08-28 09:22 - 2023-08-28 09:22 - 000003580 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2023-08-28 09:22 - 2023-08-28 09:22 - 000003356 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2023-08-28 09:22 - 2023-08-28 09:22 - 000003308 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{A386F23C-987F-4B30-B0AB-76CF6CFBB4BF} 2023-08-28 09:22 - 2023-08-28 09:22 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-08-28 09:22 - 2023-08-28 09:22 - 000002590 _____ C:\WINDOWS\system32\Tasks\SamsungMagician 2023-08-28 09:22 - 2023-08-28 09:22 - 000002586 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask 2023-08-28 09:22 - 2023-08-28 09:22 - 000000488 __RSH C:\ProgramData\ntuser.pol 2023-08-28 09:22 - 2023-08-28 09:22 - 000000020 ___SH C:\Users\Rose\ntuser.ini 2023-08-28 09:22 - 2023-08-28 09:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\Elcomsoft 2023-08-28 09:21 - 2023-08-28 09:21 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network 2023-08-28 09:19 - 2023-08-29 04:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-08-28 09:19 - 2023-08-28 19:25 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK 2023-08-28 09:19 - 2023-08-28 10:47 - 005738896 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-08-28 09:17 - 2023-08-28 09:19 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Crypto 2023-08-28 09:17 - 2023-08-28 09:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\SystemCertificates 2023-08-28 09:17 - 2023-08-28 09:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Network 2023-08-28 09:15 - 2023-08-28 09:19 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate 2023-08-28 09:14 - 2023-08-28 17:57 - 000000000 ____D C:\Users\Rose 2023-08-28 09:14 - 2023-08-28 09:21 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows 2023-08-28 09:14 - 2023-08-28 09:19 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Spelling 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Vorlagen 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Startmenü 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Netzwerkumgebung 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Lokale Einstellungen 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Eigene Dateien 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Druckumgebung 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Videos 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Musik 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Documents\Eigene Bilder 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Local\Verlauf 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\AppData\Local\Anwendungsdaten 2023-08-28 09:14 - 2023-08-28 09:14 - 000000000 _SHDL C:\Users\Rose\Anwendungsdaten 2023-08-28 09:13 - 2023-08-28 09:15 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2023-08-28 09:12 - 2023-08-28 09:12 - 000743150 _____ C:\WINDOWS\system32\perfh007.dat 2023-08-28 09:12 - 2023-08-28 09:12 - 000152540 _____ C:\WINDOWS\system32\perfc007.dat 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ___SD C:\WINDOWS\system32\containers 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\WINDOWS\system32\HvsiSettingsProviders 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files\Reference Assemblies 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files\MSBuild 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2023-08-28 09:12 - 2023-08-28 09:12 - 000000000 ____D C:\Program Files (x86)\MSBuild 2023-08-28 09:09 - 2023-08-28 09:09 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2023-08-28 08:59 - 2023-08-28 09:00 - 000000000 ____D C:\AdwCleaner 2023-08-28 08:55 - 2023-08-28 08:55 - 002969821 _____ C:\Users\Rose\Downloads\Autoruns.zip 2023-08-28 08:55 - 2023-08-28 08:55 - 000000000 ____D C:\Users\Rose\Downloads\Win11_22H2_German_x64v2 2023-08-28 08:48 - 2023-08-28 08:48 - 000000000 ____D C:\Program Files (x86)\WindowsInstallationAssistant 2023-08-28 05:24 - 2023-08-28 05:24 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\IME 2023-08-27 21:07 - 2023-08-27 21:07 - 000000000 ____D C:\Program Files\Registry 2023-08-27 20:58 - 2016-06-08 23:27 - 007819493 _____ C:\Users\Rose\Desktop\KMSpico 10.2.0 Installer + Portable.mhktricks.net.zip 2023-08-27 18:18 - 2023-08-27 18:18 - 000000000 ____D C:\Users\Rose\AppData\Roaming\wiadss 2023-08-27 17:47 - 2023-08-27 18:32 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Xiaomi 2023-08-27 14:50 - 2023-08-27 17:32 - 000000000 ____D C:\Users\Rose\.android 2023-08-27 14:50 - 2023-08-27 14:50 - 000000000 ____D C:\Users\Public\Thunder Network 2023-08-27 14:50 - 2023-08-27 14:50 - 000000000 ____D C:\ProgramData\Thunder Network 2023-08-27 09:44 - 2023-08-27 09:44 - 000001747 _____ C:\Users\Rose\Desktop\Photoshop.exe - Verknüpfung.lnk 2023-08-27 09:41 - 2023-08-27 09:41 - 000001615 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk 2023-08-27 09:41 - 2023-08-27 09:41 - 000001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk 2023-08-27 09:38 - 2023-08-27 09:38 - 000000000 ____D C:\Users\Public\Documents\AdobeGCInfo 2023-08-25 21:14 - 2023-08-25 21:14 - 000150510 _____ C:\Users\Rose\Downloads\Verkaufsschild-SiemensKC3BChlschrank_-_7688040102433033862.pdf 2023-08-25 04:38 - 2023-08-28 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExplorerPatcher 2023-08-25 04:38 - 2023-08-25 04:38 - 000643584 _____ (VALINET Solutions SRL) C:\WINDOWS\dxgi.dll 2023-08-24 09:59 - 2023-08-24 09:59 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2023-08-24 06:15 - 2023-08-28 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2023-08-23 16:28 - 2023-08-23 16:28 - 000643072 _____ (VALINET Solutions SRL) C:\WINDOWS\dxgi.prev 2023-08-22 22:15 - 2023-08-15 06:23 - 000121880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2023-08-22 22:12 - 2023-08-16 12:15 - 000849088 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000849088 _____ C:\WINDOWS\system32\vulkaninfo.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000713912 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000713912 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2023-08-22 22:12 - 2023-08-16 12:15 - 000653504 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000653504 _____ C:\WINDOWS\system32\vulkan-1.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000637112 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2023-08-22 22:12 - 2023-08-16 12:15 - 000637112 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2023-08-22 22:12 - 2023-08-16 12:14 - 001487376 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2023-08-22 22:12 - 2023-08-16 12:14 - 001227296 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2023-08-22 22:12 - 2023-08-16 12:11 - 000669320 _____ C:\WINDOWS\system32\nvofapi64.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 001537544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 001195016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 000938608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2023-08-22 22:12 - 2023-08-16 12:10 - 000504456 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 002168456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 001622152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 000992368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2023-08-22 22:12 - 2023-08-16 12:09 - 000777760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2023-08-22 22:12 - 2023-08-16 12:09 - 000768648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 014520968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 012066320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 003483168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2023-08-22 22:12 - 2023-08-16 12:08 - 000459912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2023-08-22 22:12 - 2023-08-16 12:07 - 006190088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 005845640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 005550728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll 2023-08-22 22:12 - 2023-08-16 12:07 - 000853104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2023-08-22 22:12 - 2023-08-16 12:06 - 007858112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2023-08-22 22:12 - 2023-08-16 12:05 - 006737504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2023-08-22 22:12 - 2023-08-15 06:23 - 000108122 _____ C:\WINDOWS\system32\nvinfo.pb 2023-08-22 00:51 - 2023-08-22 00:51 - 000046824 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2023-08-21 21:33 - 2023-08-21 21:33 - 000066230 _____ C:\Users\Rose\Downloads\Klassentreffen-1.pdf 2023-08-21 11:38 - 2023-08-21 11:38 - 000000000 ____D C:\Users\Rose\Downloads\Red Dead Redemption - Game of the Year Edition (USA Europe) (EnFrDeEsIt) (Disc 2) (Undead Nightmare and Multiplayer) 2023-08-17 07:38 - 2023-08-17 07:38 - 000000000 ____D C:\Users\Rose\Downloads\Red Dead Redemption - Game of the Year Edition (USA Europe) (EnFrDeEsIt) (Disc 1) (Red Dead Redemption Single Player) 2023-08-16 14:35 - 2023-08-16 14:35 - 002299727 _____ C:\Users\Rose\Downloads\6 Deckblätter für Biologie zum Ausdrucken - Wunderbunt.de.pdf 2023-08-15 10:55 - 2023-08-29 08:16 - 000012288 ___SH C:\DumpStack.log.tmp 2023-08-13 12:39 - 2023-08-13 12:39 - 000000000 ____D C:\ProgramData\WinaeroTweaker 2023-08-13 07:49 - 2023-08-13 07:49 - 000000031 _____ C:\.txt 2023-08-13 06:53 - 2023-08-13 06:53 - 000000000 ___HD C:\$Windows.~WS 2023-08-12 11:04 - 2023-08-12 11:06 - 000000000 ____D C:\Users\Rose\Downloads\xenia_canary 2023-08-12 11:04 - 2023-08-12 11:04 - 003145058 _____ C:\Users\Rose\Downloads\xenia_canary.zip 2023-08-12 10:48 - 2023-08-12 10:50 - 000000000 ____D C:\Users\Rose\Documents\Xenia 2023-08-12 10:48 - 2023-08-12 10:48 - 000000000 ____D C:\Users\Rose\Downloads\xenia_master 2023-08-12 10:46 - 2023-08-12 10:46 - 017886779 _____ C:\Users\Rose\Downloads\xenia_master.zip 2023-08-10 09:21 - 2023-08-11 05:39 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Teams 2023-08-09 11:38 - 2023-08-09 11:38 - 000409871 _____ C:\Users\Rose\Downloads\Überweisungsbestätigung_1691573889447.pdf 2023-08-08 12:06 - 2023-08-08 12:06 - 006069127 _____ C:\Users\Rose\Downloads\Diagnostics_Logs-OLK-UTC.2023.8.8.10.6.55.810.zip 2023-08-08 06:38 - 2023-08-08 06:38 - 000022162 _____ C:\Users\Rose\Downloads\Guenstiger GA4 Report.xlsx 2023-08-07 17:32 - 2023-08-07 17:32 - 000000000 ____D C:\Program Files\LogiOptionsPlus 2023-08-03 09:27 - 2023-08-03 09:27 - 000001836 _____ C:\Users\Rose\Desktop\CrystalDiskInfo.lnk ==================== Ein Monat (geänderte) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2023-08-29 08:17 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-08-29 08:17 - 2017-03-27 07:56 - 000000000 ____D C:\Users\Rose\AppData\Local\Dropbox 2023-08-29 08:17 - 2016-07-13 10:28 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Dropbox 2023-08-29 08:16 - 2023-04-29 07:02 - 000000000 ____D C:\ProgramData\NVIDIA 2023-08-29 08:16 - 2022-12-06 19:42 - 000000000 ____D C:\Users\Rose\AppData\Local\LogiOptionsPlus 2023-08-29 08:16 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-08-29 08:16 - 2022-05-07 07:17 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2023-08-29 08:16 - 2021-09-07 15:10 - 000000000 ____D C:\Users\Rose\AppData\Local\LogiBolt 2023-08-29 08:16 - 2016-07-28 22:35 - 000000000 ____D C:\Program Files (x86)\Google 2023-08-29 08:15 - 2022-02-10 09:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-08-29 08:15 - 2016-07-13 15:12 - 000000000 ____D C:\Users\Rose\Documents\Outlook-Dateien 2023-08-29 08:15 - 2016-07-13 09:39 - 000000000 ____D C:\Users\Rose\AppData\Local\ClassicShell 2023-08-29 08:03 - 2023-04-29 07:00 - 000000000 ____D C:\Users\Rose\AppData\Local\D3DSCache 2023-08-29 05:01 - 2016-07-13 13:51 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader 2023-08-29 05:00 - 2017-05-04 21:54 - 000000824 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk 2023-08-29 05:00 - 2017-05-04 21:54 - 000000824 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk 2023-08-29 04:49 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF 2023-08-29 04:42 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps 2023-08-29 04:42 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-08-29 04:32 - 2018-02-20 08:33 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2023-08-29 04:32 - 2018-02-20 08:33 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2023-08-28 21:12 - 2016-07-13 10:52 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Telegram Desktop 2023-08-28 20:56 - 2022-05-07 07:17 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2023-08-28 19:29 - 2017-10-13 07:52 - 000000000 ____D C:\Users\Rose\AppData\Local\Packages 2023-08-28 19:13 - 2018-07-19 06:15 - 000000000 ____D C:\ProgramData\Packages 2023-08-28 19:03 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\PrintDialog 2023-08-28 19:03 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-08-28 18:58 - 2021-07-22 13:19 - 000000000 ____D C:\Users\Rose\AppData\LocalLow\IGDump 2023-08-28 18:56 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-08-28 18:53 - 2023-04-29 23:14 - 000000000 ____D C:\Users\Rose\AppData\Roaming\ExplorerPatcher 2023-08-28 18:51 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\setup 2023-08-28 18:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-08-28 18:21 - 2023-04-09 15:54 - 000000000 ____D C:\Users\Rose\Downloads\Telegram Desktop 2023-08-28 17:49 - 2022-05-07 07:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-08-28 17:49 - 2017-08-09 20:21 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-08-28 17:43 - 2017-01-23 20:11 - 000000000 ____D C:\Users\TEMP 2023-08-28 17:43 - 2015-10-30 08:28 - 000000000 ____D C:\Users\Default.migrated 2023-08-28 15:42 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\appcompat 2023-08-28 13:08 - 2016-07-13 14:32 - 000000000 ____D C:\ProgramData\Malwarebytes 2023-08-28 12:09 - 2016-07-13 13:50 - 000000000 ____D C:\Users\Rose\AppData\Local\JDownloader v2.0 2023-08-28 11:05 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\USOPrivate 2023-08-28 10:54 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2023-08-28 10:52 - 2016-07-13 13:05 - 000000000 ____D C:\Users\Rose\AppData\Local\CrashDumps 2023-08-28 10:46 - 2023-04-29 22:06 - 000000000 ____D C:\WINDOWS\addins 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\WUModels 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemApps 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\vi-VN 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Sgrm 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\id-ID 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\gl-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\eu-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\et-EE 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\es-MX 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\DDFs 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\ca-ES 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\appraiser 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellComponents 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\OCR 2023-08-28 10:46 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Globalization 2023-08-28 10:46 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\servicing 2023-08-28 10:40 - 2016-07-13 22:20 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Registration 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Windows NT 2023-08-28 09:22 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Windows Defender 2023-08-28 09:22 - 2016-07-13 09:36 - 000000000 __RHD C:\Users\Public\AccountPictures 2023-08-28 09:21 - 2023-01-28 20:34 - 000000000 ____D C:\Users\Rose\Downloads\Prime95-[Guru3D.com] 2023-08-28 09:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Media 2023-08-28 09:21 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2023-08-28 09:21 - 2017-04-05 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan 2023-08-28 09:20 - 2023-04-29 07:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation 2023-08-28 09:19 - 2023-06-15 21:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 8 2023-08-28 09:19 - 2023-05-16 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Torpedo Traffic Generator Ultimate 2023-08-28 09:19 - 2023-04-29 23:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winaero Tweaker 2023-08-28 09:19 - 2023-04-29 07:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2023-08-28 09:19 - 2023-04-09 05:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\AORUS 2023-08-28 09:19 - 2023-03-22 09:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair 2023-08-28 09:19 - 2023-02-01 22:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2023-08-28 09:19 - 2022-12-15 11:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother 2023-08-28 09:19 - 2022-06-09 05:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hide.me VPN 2023-08-28 09:19 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN 2023-08-28 09:19 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\WCN 2023-08-28 09:19 - 2022-05-07 07:24 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\spool 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\NDF 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState 2023-08-28 09:19 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2023-08-28 09:19 - 2021-09-12 21:30 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2023-08-28 09:19 - 2021-09-07 15:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2023-08-28 09:19 - 2021-03-21 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3uTools 2023-08-28 09:19 - 2020-07-01 10:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xat.com Image Optimizer 2023-08-28 09:19 - 2020-05-30 06:04 - 000000000 ____D C:\Program Files\UNP 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Macromed 2023-08-28 09:19 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Catroot2.bak 2023-08-28 09:19 - 2019-12-04 12:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2023-08-28 09:19 - 2019-12-04 08:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2023-08-28 09:19 - 2019-11-05 14:26 - 000000000 ____D C:\WINDOWS\system32\AMD 2023-08-28 09:19 - 2019-10-06 10:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Combined Community Codec Pack 2023-08-28 09:19 - 2019-06-12 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell 2023-08-28 09:19 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2023-08-28 09:19 - 2018-07-12 21:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio 2023-08-28 09:19 - 2018-06-20 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebSite X5 - Professional 2023-08-28 09:19 - 2018-06-15 00:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photolemur 2023-08-28 09:19 - 2018-06-03 10:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace 2023-08-28 09:19 - 2018-06-02 13:09 - 000000000 ____D C:\WINDOWS\SysWOW64\xlive 2023-08-28 09:19 - 2018-05-28 07:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression 2023-08-28 09:19 - 2018-05-28 06:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2023-08-28 09:19 - 2018-05-25 22:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF 2023-08-28 09:19 - 2018-02-20 08:33 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server 2023-08-28 09:19 - 2018-02-20 08:33 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2023-08-28 09:19 - 2017-11-22 22:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2008 2023-08-28 09:19 - 2017-10-17 12:03 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box 2023-08-28 09:19 - 2017-08-12 23:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2023-08-28 09:19 - 2017-05-04 21:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5 2023-08-28 09:19 - 2017-04-23 20:25 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin 2023-08-28 09:19 - 2017-04-05 23:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2023-08-28 09:19 - 2017-04-05 23:05 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2023-08-28 09:19 - 2016-11-14 16:19 - 000000000 ____D C:\WINDOWS\de 2023-08-28 09:19 - 2016-11-08 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\LiveUpdate 2023-08-28 09:19 - 2016-08-27 14:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2023-08-28 09:19 - 2016-08-14 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn 2023-08-28 09:19 - 2016-08-14 09:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition 2023-08-28 09:19 - 2016-08-01 07:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2023-08-28 09:19 - 2016-07-25 12:25 - 000000000 ___HD C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup-Disabled 2023-08-28 09:19 - 2016-07-25 11:06 - 000000000 ____D C:\WINDOWS\system32\appmgmt 2023-08-28 09:19 - 2016-07-24 23:26 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2023-08-28 09:19 - 2016-07-13 23:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2023-08-28 09:19 - 2016-07-13 13:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2023-08-28 09:19 - 2016-07-13 13:09 - 000000000 ____D C:\WINDOWS\system32\oodag 2023-08-28 09:19 - 2016-07-13 13:03 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2023-08-28 09:19 - 2016-07-13 11:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photomatix Pro 5.1 2023-08-28 09:19 - 2016-07-13 10:52 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop 2023-08-28 09:19 - 2016-07-13 10:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2023-08-28 09:19 - 2016-07-13 09:57 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-08-28 09:19 - 2016-07-13 09:42 - 000000000 ____D C:\Program Files\Intel 2023-08-28 09:19 - 2015-10-30 09:24 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2023-08-28 09:18 - 2022-05-07 07:28 - 000000000 ____D C:\WINDOWS\Setup 2023-08-28 09:17 - 2022-05-07 07:24 - 000000000 __RHD C:\Users\Public\Libraries 2023-08-28 09:15 - 2023-04-08 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE 2023-08-28 09:15 - 2023-03-21 20:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility 2023-08-28 09:15 - 2023-02-05 09:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D 2023-08-28 09:15 - 2023-01-30 16:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium 2023-08-28 09:15 - 2023-01-29 10:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS 2023-08-28 09:15 - 2022-10-26 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft 2023-08-28 09:15 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2023-08-28 09:15 - 2022-05-07 12:39 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\winrm 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\slmgr 2023-08-28 09:15 - 2022-05-07 12:29 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\F12 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\dsc 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Resources 2023-08-28 09:15 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Help 2023-08-28 09:15 - 2019-11-12 09:36 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2023-08-28 09:15 - 2019-10-30 08:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UL 2023-08-28 09:15 - 2019-05-01 10:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IVONA 2023-08-28 09:15 - 2018-10-23 10:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2023-08-28 09:15 - 2017-04-15 23:27 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WonderFox Soft 2023-08-28 09:14 - 2022-05-07 07:24 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows 2023-08-28 09:12 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2023-08-28 09:12 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\MUI 2023-08-28 09:00 - 2022-08-11 11:20 - 000000000 ____D C:\ProgramData\IObit 2023-08-28 09:00 - 2017-10-16 07:42 - 000000000 ____D C:\Users\Rose\AppData\Roaming\IObit 2023-08-28 09:00 - 2017-03-30 22:34 - 000000000 ____D C:\Users\Rose\AppData\LocalLow\IObit 2023-08-27 23:00 - 2016-07-13 21:27 - 000000000 ____D C:\Users\Rose\AppData\Local\ElevatedDiagnostics 2023-08-27 21:42 - 2017-11-20 13:31 - 000000000 ____D C:\Users\Rose\AppData\Local\PlaceholderTileLogoFolder 2023-08-27 21:21 - 2016-09-02 15:41 - 000000000 ____D C:\Users\Rose\AppData\Roaming\TeamViewer 2023-08-27 21:20 - 2018-05-28 06:17 - 000000000 ____D C:\Users\Rose\AppData\Roaming\FileZilla 2023-08-27 09:42 - 2016-07-13 10:43 - 000000000 ____D C:\ProgramData\Adobe 2023-08-27 09:41 - 2018-05-31 07:18 - 000000000 ____D C:\Program Files\Adobe 2023-08-27 09:41 - 2017-10-09 21:41 - 000000000 ____D C:\Users\Rose\Documents\Adobe 2023-08-27 09:41 - 2017-10-09 21:40 - 000000000 ____D C:\Program Files\Common Files\Adobe 2023-08-27 09:41 - 2016-07-13 09:42 - 000000000 ____D C:\ProgramData\Package Cache 2023-08-27 06:14 - 2020-05-31 10:39 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-08-25 12:51 - 2016-07-13 13:20 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Word 2023-08-25 04:40 - 2016-08-17 09:53 - 000000000 ____D C:\Users\Rose\AppData\Roaming\Microsoft\Excel 2023-08-25 04:38 - 2023-04-29 23:14 - 000000000 ____D C:\Program Files\ExplorerPatcher 2023-08-24 21:33 - 2018-06-30 07:59 - 000002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2023-08-24 21:33 - 2018-06-30 07:59 - 000002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2023-08-24 06:15 - 2017-03-27 07:56 - 000000000 ____D C:\Program Files (x86)\Dropbox 2023-08-22 22:18 - 2021-05-19 12:22 - 000000000 ____D C:\Users\Rose\AppData\Local\NVIDIA 2023-08-22 18:21 - 2023-06-15 21:45 - 000000000 ____D C:\Users\Rose\AppData\Local\CyberGhost 2023-08-21 10:31 - 2018-05-28 07:17 - 000000128 _____ C:\Users\Rose\AppData\Local\PUTTY.RND 2023-08-20 08:53 - 2023-01-28 20:32 - 000000000 ____D C:\Users\Rose\Desktop\FUN 2023-08-19 21:42 - 2019-02-27 15:18 - 000008192 _____ C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2023-08-18 04:32 - 2017-04-27 22:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-08-17 21:03 - 2017-04-27 22:59 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-08-13 12:31 - 2023-04-29 23:00 - 000000000 ____D C:\Program Files\Winaero Tweaker 2023-08-13 08:57 - 2016-07-13 10:46 - 000000000 ____D C:\Users\Rose\AppData\Local\Steam 2023-08-13 07:37 - 2019-03-23 07:56 - 000000000 ____D C:\ESD 2023-08-10 09:59 - 2016-07-24 23:26 - 000000000 ____D C:\Users\Rose\AppData\Local\SquirrelTemp 2023-08-10 08:55 - 2023-05-22 16:01 - 000000000 ____D C:\Users\Rose\Desktop\peugeot 2023-08-10 08:52 - 2023-01-28 20:33 - 000000000 ____D C:\Users\Rose\Downloads\DesktopOK401_x64 2023-08-09 17:52 - 2018-03-01 15:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-08-09 05:13 - 2016-07-13 09:57 - 175983240 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-08-09 05:10 - 2023-04-16 10:07 - 000000000 ____D C:\Program Files\dotnet 2023-08-05 10:38 - 2018-07-12 21:54 - 000000000 ____D C:\Users\Rose\AppData\Roaming\obs-studio 2023-08-03 09:27 - 2019-12-04 12:52 - 000000000 ____D C:\Program Files\CrystalDiskInfo ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======== 2016-07-19 20:43 - 2016-08-25 10:52 - 000000624 _____ () C:\Users\Rose\AppData\Roaming\All CPU MeterV3_Settings.ini 2019-04-10 10:51 - 2019-04-10 10:51 - 000000078 _____ () C:\Users\Rose\AppData\Roaming\FC.dat 2022-01-20 17:57 - 2022-01-20 17:57 - 000000015 _____ () C:\Users\Rose\AppData\Roaming\obs-virtualcam.txt 2020-05-18 17:06 - 2023-06-25 11:40 - 000000128 _____ () C:\Users\Rose\AppData\Roaming\PUTTY.RND 2016-07-19 20:58 - 2016-07-19 20:58 - 000000119 _____ () C:\Users\Rose\AppData\Roaming\System Monitor II_UptimeRecord.ini 2016-08-03 09:44 - 2017-01-11 22:07 - 000000122 _____ () C:\Users\Rose\AppData\Roaming\wklnhst.dat 2019-02-27 15:18 - 2023-08-19 21:42 - 000008192 _____ () C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-07-13 09:46 - 2017-02-02 08:45 - 000000000 _____ () C:\Users\Rose\AppData\Local\Driver_LOM_8161Present.flag 2018-01-25 08:10 - 2018-01-25 08:10 - 000000291 _____ () C:\Users\Rose\AppData\Local\ledConfiguration.config 2016-12-26 09:19 - 2016-12-26 09:19 - 000000001 _____ () C:\Users\Rose\AppData\Local\llftool.4.40.agreement 2018-09-28 08:55 - 2023-08-27 09:38 - 000001025 _____ () C:\Users\Rose\AppData\Local\oobelibMkey.log 2018-05-28 07:17 - 2023-08-21 10:31 - 000000128 _____ () C:\Users\Rose\AppData\Local\PUTTY.RND 2020-07-13 13:21 - 2020-07-13 13:21 - 000002761 _____ () C:\Users\Rose\AppData\Local\recently-used.xbel 2016-12-27 11:04 - 2017-02-23 09:53 - 000007597 _____ () C:\Users\Rose\AppData\Local\resmon.resmoncfg 2023-04-27 22:28 - 2023-04-27 22:28 - 000000000 _____ () C:\Users\Rose\AppData\Local\{EBD3693D-572A-435F-A259-8E8C48611192} ==================== FLock ============================== 2017-11-09 13:42 C:\ProgramData\Application Data ==================== SigCheck ============================ (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) ==================== Ende von FRST.txt ======================== |
29.08.2023, 07:25 | #5 |
| Windows Sicherheit / Defender zerschossenCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 28-08-2023 durchgeführt von Rose (29-08-2023 08:17:53) Gestartet von C:\Users\Rose\Downloads Microsoft Windows 11 Pro Version 22H2 22621.2134 (X64) (2023-08-28 07:22:36) Start-Modus: Normal ========================================================== ==================== Konten: ============================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) Administrator (S-1-5-21-653905286-3903209159-424152592-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-653905286-3903209159-424152592-503 - Limited - Disabled) Gast (S-1-5-21-653905286-3903209159-424152592-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-653905286-3903209159-424152592-1005 - Limited - Enabled) postgres (S-1-5-21-653905286-3903209159-424152592-1006 - Limited - Enabled) Rose (S-1-5-21-653905286-3903209159-424152592-1001 - Administrator - Enabled) => C:\Users\Rose WDAGUtilityAccount (S-1-5-21-653905286-3903209159-424152592-504 - Limited - Disabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Panda Dome (Enabled - Up to date) {8404BB29-B609-D604-AF5C-6806F0482FD3} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Kaspersky (Disabled - Up to date) {4F76F112-43EB-40E8-11D8-F7BD1853EA23} FW: Kaspersky (Disabled) {774D7037-0984-41B0-3A87-5E88E680AD58} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 3DMark (HKLM\...\{793A6554-A614-46E2-8381-EE34BC9F7F60}) (Version: 2.26.8125.0 - UL) Hidden 3DMark (HKLM-x32\...\{8ffabc1c-e7a8-4b49-b024-1eab1a3b562c}) (Version: 2.10.6799.0 - UL) 3uTools (HKLM-x32\...\3uTools) (Version: 2.56.012 - ShangHai ZhangZheng Network Technology Co., Ltd.) Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1031-1033-7760-BC15014EA700}) (Version: 23.003.20284 - Adobe) Adobe Fireworks CS6 (HKLM-x32\...\{CA7C485C-7A89-11E1-B2C8-CD54B377BC52}) (Version: 12.0.0 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden Anno 1800 (HKLM-x32\...\Uplay Install 4553) (Version: - Ubisoft) AORUS ENGINE (HKLM-x32\...\AORUS ENGINE_is1) (Version: 2.2.3.0 - GIGABYTE Technology Co.,Inc.) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{CA8EDE78-7A08-4F27-9B31-D6161C095986}) (Version: 16.5.0.12 - Apple Inc.) ASRRGBLED v2.0.136 (HKLM-x32\...\ASRock RGB LED_is1) (Version: 2.0.136 - ASRock Inc.) ASUS GLCKIO2 Driver (HKLM-x32\...\{548dd834-70c5-4426-8065-fbeabdd2bb5d}) (Version: 1.0.10 - ASUSTeK Computer Inc.) Hidden ASUS GLCKIO2 Driver (HKLM-x32\...\{5960FD0F-BB3B-49AF-B175-F77DC91E995A}) (Version: 1.0.10 - ASUSTeK Computer Inc.) Hidden Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team) Audacity 3.3.3 (64 Bit) (HKLM\...\Audacity_is1) (Version: 3.3.3 - Audacity Team) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Call of Duty Modern Warfare (HKLM-x32\...\Call of Duty Modern Warfare) (Version: - Blizzard Entertainment) CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft) Combined Community Codec Pack 2015-10-18 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2015.10.19.0 - CCCP Project) CORSAIR iCUE 4 Software (HKLM\...\{444A58EF-FD29-4558-BD8B-F4839576463C}) (Version: 4.33.138 - Corsair) CPUID CPU-Z 2.06 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.06 - CPUID, Inc.) CPUID HWMonitor 1.51 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.51 - CPUID, Inc.) CrystalDiskInfo 9.1.1 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.1.1 - Crystal Dew World) CyberGhost 8 (HKLM\...\CyberGhost 8) (Version: 8.3.11.10057 - CyberGhost S.R.L.) CyberGhost TUN (HKLM\...\{677232D6-72D6-4821-8CB5-47969B15D4DF}) (Version: 1.0 - CyberGhost S.R.L.) Hidden D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 181.4.5678 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.761.1 - Dropbox, Inc.) Hidden Dynamic Application Loader Host Interface Service (HKLM\...\{B8F67CAD-D16A-4AC8-B4F1-3AE8A9FF22F5}) (Version: 1.0.0.0 - Intel Corporation) Hidden ENE RGB HAL (HKLM\...\{2914DF72-932B-4DF2-9696-C2821EDA1CA9}) (Version: 1.00.09 - Ene Tech.) Hidden ENE RGB HAL (HKLM-x32\...\{546469ee-3f9d-4fe4-bf1c-893f79cf7327}) (Version: 1.00.09 - Ene Tech.) Hidden ENE_AIC_Marvell_HAL (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.7.0 - ENE TECHNOLOGY INC.) Hidden ENE_DRAM_RGB_AIO (HKLM\...\{76D0C3A4-E975-4A56-BFB9-A8CCA61E07BC}) (Version: 1.0.6.2 - Ene Tech.) Hidden ENE_DRAM_RGB_AIO (HKLM-x32\...\{b3e8b10e-ec8c-410e-a0e6-05b04379cc43}) (Version: 1.0.6.2 - Ene Tech.) Hidden ENE_EHD_HAL (HKLM\...\{F56EC5A0-3A93-492E-882A-E036F5897CC7}) (Version: 1.00.04 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_HAL (HKLM-x32\...\{cc33eebd-777b-4177-8cd7-6ab9fd06ceed}) (Version: 1.00.04 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden ENE_EHD_M2_HAL (HKLM-x32\...\{6b617af3-c8f4-45a8-bf47-b32ffb4da1cc}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden ENE_External_Device_HAL (HKLM\...\{2B8E611F-0B51-4FAC-87BB-AF50D82E7DDA}) (Version: 1.0.11.1 - ENE Tech) Hidden ENE_External_Device_HAL (HKLM-x32\...\{bb9d349f-b87b-4026-b336-1604708bd09c}) (Version: 1.0.11.1 - ENE Tech) Hidden ENE_MousePad_HAL (HKLM\...\{9E97178A-ADB8-4778-BE60-7E28E2A72721}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden ENE_MousePad_HAL (HKLM-x32\...\{c2c794a4-7986-4c45-884d-d4ca43b88df9}) (Version: 1.0.2.0 - ENE TECHNOLOGY INC.) Hidden ENE_X_AIC_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.4.0 - ENE TECHNOLOGY INC.) Hidden Epic Games Launcher (HKLM-x32\...\{422FC196-EA1D-448E-A505-BC7DFC21C880}) (Version: 1.1.236.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epic Online Services (HKLM-x32\...\{35905844-0610-427D-86A0-2103FABE3D4D}) (Version: 2.0.42.0 - Epic Games, Inc.) EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) ExplorerPatcher (HKLM\...\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher) (Version: 22621.1992.56.3 - VALINET Solutions SRL) FileZilla 3.64.0 (HKLM-x32\...\FileZilla Client) (Version: 3.64.0 - Tim Kosse) Fotogalerie (HKLM-x32\...\{41BF4A3B-D60A-4E92-883F-C88C8C157261}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Foxit PhantomPDF (HKLM-x32\...\{CB2155B6-4273-11E8-9ECE-000C296BF29B}) (Version: 9.1.0.5096 - Foxit Software Inc.) FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\195fa74437467f40) (Version: 2.3.4.0 - AVM Berlin) Futuremark SystemInfo (HKLM-x32\...\{93086761-C4E7-48FC-A090-E9AE1C73B254}) (Version: 5.64.1188.0 - Futuremark) Glary Utilities PRO 5.210 (HKLM-x32\...\Glary Utilities 5) (Version: 5.210.0.239 - Glarysoft Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 116.0.5845.111 - Google LLC) Grewe Scanner-Interface 7 (HKLM-x32\...\{B1C3F49A-DE7D-1AC1-0913-039C1A8B9B82}) (Version: 7 - Grewe Computertechnik GmbH) HD Video Converter Factory Pro 12.5 (HKLM-x32\...\HD Video Converter Factory Pro) (Version: 12.5 - WonderFox Soft, Inc.) hide.me VPN 3.14.1 (HKLM-x32\...\{0E00BDA5-7998-4889-BE4B-39A4BBD2EDFB}_is1) (Version: 3.14.1 - eVenture Limited) HL-1110 series (HKLM-x32\...\{4F2442B7-A89E-42A4-8F0E-6937499855CA}) (Version: 1.0.1.0 - Brother Industries, Ltd.) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Incomedia WebSite X5 - Pro (HKLM\...\{E8900B9A-2ED4-4032-8FBF-D714D134D01F}_is1) (Version: 2022.3.5.0 - Incomedia s.r.l.) Intel(R) Chipset Device Software (HKLM\...\{22987D97-5A46-4BD9-B1A5-2FFE44201081}) (Version: 10.1.19199.8340 - Intel Corporation) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{e6ecf35a-b1bb-4e59-9d90-4c98fde2ffa8}) (Version: 10.1.19199.8340 - Intel(R) Corporation) Intel(R) Management Engine Components (HKLM\...\{1B2B12B8-AE77-4104-97FE-904274D21B6C}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2230.3.19.0 - Intel Corporation) Intel(R) Management Engine Driver (HKLM\...\{5F953BF8-C54E-4335-B7C9-873508D2CE1A}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) ME WMI Provider (HKLM\...\{2D7D4B84-FDD2-42BC-9B5B-ADAB4E31AC5E}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) Network Connections 22.5.104.0 (HKLM\...\{B6C27920-8AD4-4D8B-BC97-2CC0043718E5}) (Version: 22.5.104.0 - Intel) Hidden Intel(R) Network Connections 22.5.104.0 (HKLM\...\PROSetDX) (Version: 22.5.104.0 - Intel) IVONA 2 (HKLM-x32\...\IVONA 2) (Version: 1.6.37 - IVONA Software Sp. z o.o.) IVONA ControlCenter (HKLM-x32\...\IVONA ControlCenter) (Version: 1.0.25 - IVONA Software Sp. z o.o.) Killer Bandwidth Control Filter Driver (HKLM\...\{5B7A2B7B-CEA9-4E50-B0E4-E82F204CBE78}) (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer E220x Drivers (HKLM\...\{77C95134-CA2D-4614-9C86-55B7A6A281AA}) (Version: 1.1.57.1125 - Rivet Networks) Hidden Killer Network Manager (HKLM\...\{51B5A084-A40D-4F4B-90AA-EF8354EA7D96}) (Version: 1.1.57.1125 - Rivet Networks) Hidden LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logi Bolt (HKLM\...\LogiBolt) (Version: 1.2.6024.0 - Logi) Logi Options+ (HKLM\...\{850cdc16-85df-4052-b06e-4e3e9e83c5c6}) (Version: 1.48.437015 - Logitech) Logitech Gaming Software (HKLM\...\{690285C2-2481-44FB-8402-162EA970A6DD}) (Version: 8.30.28 - Logitech Inc.) Hidden Logitech Options (HKLM\...\LogiOptions) (Version: 9.60.87 - Logitech) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) LWS Facebook (HKLM-x32\...\{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}) (Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (HKLM-x32\...\{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}) (Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (HKLM-x32\...\{1651216E-E7AD-4250-92A1-FB8ED61391C9}) (Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (HKLM-x32\...\{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}) (Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (HKLM-x32\...\{71E66D3F-A009-44AB-8784-75E2819BA4BA}) (Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (HKLM-x32\...\{08610298-29AE-445B-B37D-EFBE05802967}) (Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (HKLM-x32\...\{174A3B31-4C43-43DD-866F-73C9DB887B48}) (Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (HKLM-x32\...\{8937D274-C281-42E4-8CDB-A0B2DF979189}) (Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (HKLM-x32\...\{9DAEA76B-E50F-4272-A595-0124E826553D}) (Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (HKLM-x32\...\{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}) (Version: 13.31.1038.0 - Logitech) Hidden Macrium Reflect Free (HKLM\...\{0D4965D1-6B46-4F0A-B42D-B17056612AE0}) (Version: 8.0.7279 - Paramount Software (UK) Ltd.) Hidden Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7279 - Paramount Software (UK) Ltd.) MAGIX Video Pro X10 (HKLM\...\MAGIX Video Pro X10 16.0.1.236) (Version: 16.0.1.236 - MAGIX) Malwarebytes version 4.6.1.280 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.1.280 - Malwarebytes) Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host - 3.1.32 (x86) (HKLM-x32\...\{3C73457A-1A33-4DE0-B6C2-6FBA877E1FCF}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Host FX Resolver - 3.1.32 (x86) (HKLM-x32\...\{CE1A992F-4571-423D-9CAE-1184E8F29471}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.32 (x86) (HKLM-x32\...\{841FE4B1-2C3F-4304-A686-6DF41B4CC1A1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft .NET Host - 5.0.6 (x64) (HKLM\...\{0541E599-10CB-44F4-A33A-32FE6DEA2F49}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Host - 6.0.21 (x64) (HKLM\...\{26FF35F7-ADBB-4C9F-97DA-79120DB80EC6}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 5.0.6 (x64) (HKLM\...\{54F41FBB-AB2F-46B5-AA28-3C9492066E9C}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 6.0.21 (x64) (HKLM\...\{D937EF87-F11D-4778-973C-B71E178F95D0}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 5.0.6 (x64) (HKLM\...\{DDBF9749-FF6E-419C-BAAD-9F4948B75DDE}) (Version: 40.24.30020 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 6.0.21 (x64) (HKLM\...\{8D2EC92E-5903-4B25-9406-182B8EFA834F}) (Version: 48.87.64667 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 116.0.1938.62 - Microsoft Corporation) Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 116.0.1938.62 - Microsoft Corporation) Microsoft Expression Web 4 (HKLM-x32\...\{5F8D931D-B230-47F3-A9C0-0C8CA459A332}) (Version: 4.0.1460.0 - Microsoft Corporation) Hidden Microsoft Expression Web 4 (HKLM-x32\...\Web_4.0.1460.0) (Version: 4.0.1460.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Professional Plus 2016 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 16.0.16626.20170 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{43D501A5-E5E3-46EC-8F33-9E15D2A2CBD5}) (Version: 5.70.0.0 - Microsoft Corporation) Microsoft Visual Basic/C++ Runtime (x86) (HKLM-x32\...\{C5E3A69D-D391-45A6-A8FB-00B01E2B010D}) (Version: 1.1.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.30919 (HKLM\...\{D55C642A-D7A4-4581-90A2-D74864791E92}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.30919 (HKLM\...\{E749F10C-EFEA-43D3-8404-B477DD92AF03}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Additional Runtime - 14.31.30919 (HKLM-x32\...\{8681860E-E7D2-421A-A09E-7A6890CE62E5}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.31.30919 (HKLM-x32\...\{4CA1C5EC-16E5-4438-9704-A4F6D84068C4}) (Version: 14.31.30919 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM\...\{5BEE5F3E-4D78-4DE8-A8F3-36D3E9D8868C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM-x32\...\{0eddeab6-01c1-4cf7-83ba-164ea8974c90}) (Version: 3.1.32.31915 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{25D5B94A-E3CD-44E8-9C3A-FE320B7B38FC}) (Version: 24.192.31915 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 3.1.32 (x86) (HKLM-x32\...\{4f894285-fd43-43ac-8669-33e8b7c0a97d}) (Version: 3.1.32.31915 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 5.0.6 (x64) (HKLM\...\{0F871294-4452-40AB-BAAD-A1D624E7E405}) (Version: 40.24.30021 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 5.0.6 (x64) (HKLM-x32\...\{744f4ca7-5613-4d87-8332-b816ecf7dabd}) (Version: 5.0.6.30021 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM\...\{AF6BF7DD-2B12-40C5-919C-2EC99054BBE1}) (Version: 48.87.64723 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM-x32\...\{0f39db03-9030-48f3-82ef-5384bed81d85}) (Version: 6.0.21.32717 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{70C91B91-61E8-4D06-86D6-A9DCC291983A}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox (x64 de) (HKLM\...\Mozilla Firefox 116.0.3 (x64 de)) (Version: 116.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0 - Mozilla) MSI Afterburner 4.6.4 (HKLM-x32\...\Afterburner) (Version: 4.6.4 - MSI Co., LTD) MSI Kombustor 4.1.19.0 (64-bit) (HKLM\...\{F3D3CC6B-9AD7-4F43-8C69-40D5902FDC5C}}_is1) (Version: - MSI / Geeks3D) MSVCRT (HKLM-x32\...\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}) (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (HKLM\...\{0C025A40-A716-11E8-953B-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT Redists (HKLM\...\{0EC4A100-12A2-11E9-9504-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT Redists (HKLM\...\{75AFFE51-DA39-11E9-842E-00155D6302F2}) (Version: 1.0 - MAGIX Computer Products Intl. Co.) Hidden MSVCRT110 (HKLM-x32\...\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}) (Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (HKLM\...\{E9FA781F-3E80-4399-825A-AD3E11C28C77}) (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) Nero 7 Ultra Edition (HKLM-x32\...\{2D7D9D86-923A-41A8-919F-437332AB1031}) (Version: 7.02.2760 - Nero AG) NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation) NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation) NVIDIA Grafiktreiber 537.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 537.13 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 21.1.2 - OBS Project) OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20118 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0407-0000-0000000FF1CE}) (Version: 16.0.16626.20170 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.5.122.52971 - Electronic Arts, Inc.) Panda Devices Agent (HKLM-x32\...\{DB0164A2-ADE9-4FEE-B080-D506BDD6427F}) (Version: 1.08.09 - Panda Security) Hidden Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.09 - Panda Security) Hidden Panda Dome (HKLM\...\{AC555D5A-A9A3-4897-B9E0-97D594F1E10D}) (Version: 12.12.10 - Panda Security) Hidden Panda Dome (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 22.01.01.0000 - Panda Security) Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.1 - Patriot Memory) Hidden Photo Common (HKLM-x32\...\{87DABDEA-47A4-4182-AA7C-2C90DAAE3117}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photo Gallery (HKLM-x32\...\{07AAB66E-4718-422D-9218-4AFB3C922A71}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photolemur (HKLM\...\{7711E044-95EE-4B74-B02E-054F3190A0A9}) (Version: 2.3.0.1796 - Photolemur) Hidden Photolemur (HKLM-x32\...\{e31d858c-09d7-4d60-83f8-600db941fa67}) (Version: 2.3.0.1796 - Photolemur) Photomatix Pro Version 5.1.2 (HKLM\...\PhotomatixPro5x64_is1) (Version: 5.1.2 - HDRsoft Ltd) proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.115.3 - proDAD GmbH) Hidden proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.127 - proDAD GmbH) Hidden proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.257.1 - proDAD GmbH) Hidden proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.257.1 - proDAD GmbH) Hidden proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.244 - proDAD GmbH) Hidden Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9448.1 - Realtek Semiconductor Corp.) RGB Fusion (HKLM-x32\...\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.22.1130.1 - Gigabyte) RivaTuner Statistics Server 7.3.4 (HKLM-x32\...\RTSS) (Version: 7.3.4 - Unwinder) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 7.2.1.980 - Samsung Electronics) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.) Silent Hunter Wolves of the Pacific (HKLM-x32\...\{0D005F09-A5F4-473B-A901-5735C6AF5628}) (Version: 1.00.0000 - Ubisoft) Sp5 (HKLM-x32\...\{560F47F7-EB23-44B1-AAFC-667F1CD8FE5C}) (Version: 5.1.4324.0 - Microsoft) Hidden Sp5Intl (HKLM-x32\...\{FD4B33E1-24AE-4535-AA7B-162B30FB57CD}) (Version: 5.1.4324.0 - Microsoft) Hidden Sp5TTInt (HKLM-x32\...\{E415C943-37E5-473F-8BAE-043C56734124}) (Version: 5.1.4324.0 - Microsoft) Hidden SpCommon (HKLM-x32\...\{6C3959C6-943E-44B3-BAAD-570B04B134E5}) (Version: 5.1.4324.0 - Microsoft) Hidden SpPhones (HKLM-x32\...\{4DFF1415-4C29-44A8-BFD4-2BCE249C4991}) (Version: 6.0.3122.0 - Microsoft) Hidden StatusMonitor (HKLM-x32\...\{D9584EB4-1D28-4BD1-8F81-6E097C0827EE}) (Version: 1.33.1.0 - Brother Industries, Ltd.) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.38.3 - TeamViewer) Telegram Desktop (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.9.2 - Telegram FZ-LLC) Text Speaker 3 (HKLM-x32\...\Text Speaker_is1) (Version: - Deskshare Inc.) Torpedo Traffic Generator Ultimate V8.5 (HKLM\...\{B77E0741-7726-472B-A94A-B19B0EBD3D67}_is1) (Version: - Gem's Softwares) TuneUp Utilities 2008 (HKLM-x32\...\{5888428E-699C-4E71-BF71-94EE06B497DA}) (Version: 7.0.7986 - TuneUp Software) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 98.0 - Ubisoft) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) VEGAS Pro 16.0 (HKLM\...\{0AAC190F-A716-11E8-AD83-00155D6302F2}) (Version: 16.0.261 - VEGAS) Visual C++ 10.0 CRT (x64) (HKLM\...\{BFF61907-AA2D-3A26-8666-98D956A62ABC}) (Version: 10.0 - Microsoft Corporation) Hidden WD P40 Game Drive (HKLM\...\{EE55DBAE-ECDD-4ADD-AAB5-23DE848B0996}) (Version: 1.0.2.18 - Western Digital Corporation) Hidden WhatsApp (Outdated) (HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\WhatsApp) (Version: 2.2326.10 - WhatsApp) Winaero Tweaker (HKLM\...\Winaero Tweaker_is1) (Version: 1.55.0.0 - Winaero) Windows Live Communications Platform (HKLM-x32\...\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\{66233218-CA57-4AB2-BA43-A97AA4635960}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Installer (HKLM-x32\...\{659CB81C-B54E-4DF1-B618-F35777393A54}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Photo Common (HKLM-x32\...\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live PIMT Platform (HKLM-x32\...\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE (HKLM-x32\...\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (HKLM-x32\...\{D1893000-EA77-493C-8DDD-E262436E959B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform (HKLM-x32\...\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (HKLM-x32\...\{FC071B45-4A5F-408F-92F8-4D9D693E866F}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows*11-Installationsassistent (HKLM-x32\...\{115DF11E-4B4C-4EA9-9A79-00DB0C7EF02D}) (Version: 1.4.19041.2063 - Microsoft Corporation) Windows-PC-Integritätsprüfung (HKLM\...\{B3956CF3-F6C5-4567-AC38-1FD4432B319C}) (Version: 3.6.2204.08001 - Microsoft Corporation) Windows-Treiberpaket - Corsair Components, Inc. (SIUSBXP) USB (07/14/2017 3.3) (HKLM\...\A2206C09905C467F30CB24DCBB49F056D7F0A290) (Version: 07/14/2017 3.3 - Corsair Components, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) xat.com Image Optimizer (HKLM-x32\...\xat.com Image Optimizer) (Version: - ) Packages: ========= Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2590.1.0_x64__kgqvnymyfvs32 [2023-08-28] (king.com) Coollage -> C:\Program Files\WindowsApps\63969AppsandFun.Coollage_2.6.0.0_neutral__ffwx7pcdtznr8 [2023-08-28] (Apps and Fun) Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Dropbox -> C:\Program Files (x86)\Dropbox\Client\PackageAssets [2023-08-28] (Dropbox Inc.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] Microsoft.MPEG2VideoExtension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.61931.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Microsoft.WindowsAppRuntime.CBS -> C:\WINDOWS\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) Microsoft.XboxCompanion -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) [MS Ad] MicrosoftWindows.Client.FileExp -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2023-08-28] (Microsoft Corporation) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-08-28] (NVIDIA Corp.) Pic Collage -> C:\Program Files\WindowsApps\CARDINALBLUE.PICCOLLAGE_2.0.30.0_x64__nyvb5jmhdxy8g [2023-08-28] (Cardinal Blue Software) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.40.287.0_x64__dt26b99r8h8gj [2023-08-28] (Realtek Semiconductor Corp) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2023-08-28] (Twitter Inc.) WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2333.8.0_x64__cv1g1gvanyjgm [2023-08-28] (WhatsApp Inc.) [Startup Task] Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2023-08-28] (Microsoft Corporation) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter.gadget\CoreTempReader.dll (AddGadgets IT -> ) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) [Datei ist nicht signiert] CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Rose\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) [Datei ist nicht signiert] CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 -> => Keine Datei CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpcdmc64.dll (Microsoft Windows Hardware Compatibility Publisher -> HP) CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{d93ed569-3b3e-4bff-8355-3c44f6a52bb5}\InprocServer32 -> => Keine Datei CustomCLSID: HKU\S-1-5-21-653905286-3903209159-424152592-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => E:\Dropbox [2023-04-21 14:23] ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Keine Datei ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Keine Datei ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Keine Datei ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Keine Datei ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Keine Datei ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-08-28] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [TuneUp Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => D:\Program Files (x86)\TuneUp Utilities 2008\SDShelEx-x64.dll [2007-09-04] (TuneUp Software GmbH -> TuneUp Software GmbH) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.64.0.dll [2023-08-22] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\nvshext.dll [2023-08-16] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers6: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-04-16] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => d:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2023-03-03] (Glarysoft Ltd -> Glarysoft Ltd) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-08-28] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2023-01-02] (Panda Security S.L. -> Panda Security, S.L.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Drivers32: [VIDC.FPS1] => c:\windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [Datei ist nicht signiert] HKLM\...\Drivers32: [VIDC.RTV1] => c:\windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [Datei ist nicht signiert] HKLM\...\Drivers32: [vidc.pDAD] => c:\windows\system32\prodad-codec.dll [607256 2018-08-30] (proDAD GmbH -> proDAD GmbH) HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [Datei ist nicht signiert] HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [Datei ist nicht signiert] ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\Rose\Desktop\Frederik - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default" ShortcutWithArgument: C:\Users\Rose\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=ghgabhipcejejjmhhchfonmamedcbeod ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============= 2022-12-15 11:32 - 2009-02-27 17:38 - 000139264 ____R () [Datei ist nicht signiert] C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 000542720 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\BrMonitor.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 000208896 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrFirmUpdateCheck.dll 2022-01-26 20:00 - 2022-01-26 20:00 - 001859584 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000232960 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000057344 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000668672 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000074240 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000371712 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000058368 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000074240 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll 2023-03-14 17:57 - 2023-03-14 17:57 - 000368640 _____ () [Datei ist nicht signiert] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll 2017-10-29 00:00 - 2006-02-23 11:35 - 000020480 ____R () [Datei ist nicht signiert] C:\WINDOWS\System32\FritzColorPort64.dll 2017-02-14 16:20 - 2015-03-12 04:43 - 000022528 ____R () [Datei ist nicht signiert] C:\WINDOWS\System32\us00alm.dll 2022-12-15 11:32 - 2008-08-18 19:27 - 000122880 ____N (Brother Industries, Ltd.) [Datei ist nicht signiert] C:\Program Files (x86)\Browny02\brlmw03a.dll 2017-06-20 11:34 - 2017-06-20 11:34 - 000349696 ____R (Intel(R) Corporation) [Datei ist nicht signiert] C:\WINDOWS\system32\NCS2Setp.dll 2018-07-15 13:15 - 2018-07-15 13:15 - 000885560 _____ (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\Program Files\Classic Shell\ClassicExplorer64.dll 2018-07-15 13:15 - 2018-07-15 13:15 - 003664696 _____ (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll 2018-07-15 13:15 - 2018-07-15 13:15 - 000291128 ____R (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] C:\WINDOWS\System32\StartMenuHelper64.dll 2003-04-02 17:22 - 2003-04-02 17:22 - 000024576 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\1031\mdmui.dll 2023-04-29 22:13 - 2023-04-29 22:13 - 001654784 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\WINDOWS\WinSxS\Fusion\amd64_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_none_758c8a477f89a995\8.0\8.0.50727.6195\MFC80U.DLL 2023-04-29 22:13 - 2023-04-29 22:13 - 000054272 _____ (Microsoft Corporation) [Datei ist nicht signiert] C:\WINDOWS\WinSxS\Fusion\amd64_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_none_eeb8165fbcb9c171\8.0\8.0.50727.6195\MFC80DEU.DLL 2023-01-17 14:13 - 2023-01-17 14:13 - 000090112 _____ (Silicon Laboratories, Inc.) [Datei ist nicht signiert] C:\Program Files\Corsair\CORSAIR iCUE 4 Software\SiUSBXp.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\LIBEAY32.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\ssleay32.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001611264 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\platforms\qwindows.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005487104 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Core.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005841920 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Gui.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 001179136 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Network.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000146432 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5WebSockets.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 005089792 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Widgets.dll 2023-03-14 22:05 - 2022-01-19 20:03 - 000184832 _____ (The Qt Company Ltd) [Datei ist nicht signiert] D:\Program Files (x86)\Origin\Qt5Xml.dll 2017-10-29 00:00 - 2006-02-23 12:16 - 000047616 ____R (TODO: <Company name>) [Datei ist nicht signiert] C:\WINDOWS\System32\AvmColorFax.dll 2023-08-25 04:38 - 2023-08-25 04:38 - 000643584 _____ (VALINET Solutions SRL) [Datei ist nicht signiert] C:\WINDOWS\dxgi.dll 2017-02-14 16:20 - 2015-08-20 03:14 - 000043520 ____R (Windows (R) Codename Longhorn DDK provider) [Datei ist nicht signiert] C:\WINDOWS\system32\spool\PRTPROCS\x64\us00apc.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\usosvc.dll:com.dropbox.attrs [52] AlternateDataStreams: C:\WINDOWS\SysWOW64\CH341DLL.DLL:com.dropbox.attributes [168] AlternateDataStreams: C:\WINDOWS\SysWOW64\CH341DLL.DLL:com.dropbox.attrs [54] AlternateDataStreams: C:\WINDOWS\SysWOW64\USBIOX.DLL:com.dropbox.attributes [168] AlternateDataStreams: C:\WINDOWS\SysWOW64\USBIOX.DLL:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Rose\Desktop\Top 500 Referer Links.txt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Rose\Downloads\www-rzmenden-de_20210628T051507Z_DisavowLinks.txt:com.dropbox.attrs [52] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ================= ==================== Internet Explorer (Nicht auf der Ausnahmeliste) ========== HKU\S-1-5-21-653905286-3903209159-424152592-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] BHO-x32: Foxit PhantomPDF Create PDF ToolBar Helper -> {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-04-16] (Foxit Software Incorporated -> ) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-04-16] (Foxit Software Incorporated -> ) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [Datei ist nicht signiert] DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1473946269758 Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-28] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts Inhalt: ========================= (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2023-08-29 08:14 - 2023-08-29 08:14 - 000000741 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Andere Bereiche =========================== (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> c:\programdata\oracle\java\javapath;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0;c:\program files (x86)\windows live\shared;c:\program files (x86)\skype\phone;c:\windows\system32\openssh;c:\program files\nvidia corporation\nvidia nvdlisr;c:\windows\system32\windowspowershell\v1.0\;c:\windows\system32\openssh\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NGX;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Common Files\Ulead Systems\Mpeg;C:\Program Files\dotnet\ HKU\S-1-5-21-653905286-3903209159-424152592-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rose\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\wallpaper672898.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1) HKU\S-1-5-21-653905286-3903209159-424152592-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1) ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) MSCONFIG\Services: WsAppService => 3 HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "Reflect UI" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\StartupFolder: => "Logitech . Produktregistrierung.lnk" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "iFunBox" HKU\S-1-5-21-653905286-3903209159-424152592-1001\...\StartupApproved\Run: => "Adobe Reader Synchronizer" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================ (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{B0A9A42B-A8C1-478A-A44E-871CC9572330}C:\program files\logioptionsplus\logioptionsplus_agent.exe] => (Allow) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{6E4EAA32-A326-4A41-8353-58047494A768}C:\program files\logioptionsplus\logioptionsplus_agent.exe] => (Allow) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{B458A398-D033-469D-8C1D-8FA996CE7DFA}] => (Block) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{FE563E98-0315-48D3-8BC1-9CE950B855D8}] => (Block) C:\program files\logioptionsplus\logioptionsplus_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{F67264B9-4271-4BB3-AE2A-4F0044F9BF67}C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe] => (Allow) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{A857FE7E-6FFD-4DD5-B85B-D4EE1FFD106B}C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe] => (Allow) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{4C9D908D-2400-4B13-95B7-71B80215BE23}] => (Block) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{7930E66B-D922-4728-A2CB-9E4EB4072804}] => (Block) C:\programdata\logishrd\logioptions\software\current\logioptionsmgr.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{AAB9C3B9-D4C2-4907-B6D6-541476651529}C:\program files (x86)\dropbox\client\dropbox.exe] => (Allow) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [UDP Query User{0AA3A383-0D16-406D-B955-87061C7435FF}C:\program files (x86)\dropbox\client\dropbox.exe] => (Allow) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{364E4381-3CC8-447F-9DF6-B884EA7E0D9F}] => (Block) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{0110C8BD-70BB-4818-BC97-D87E71479B98}] => (Block) C:\program files (x86)\dropbox\client\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{CAE99229-255E-4FB5-9FEE-7E2D6E1D800B}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23216.905.2334.6698_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{3E396E06-26F9-4D6B-95BE-7F611DCFC439}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23216.905.2334.6698_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{FC5215C9-6C87-469D-A21B-6904D814E1D5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{5FCC1D10-CA4A-4061-A496-BE164AB93CFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{9682808F-D359-4F8D-B628-7DCDFE4AD5DC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{3D0B8046-5E61-4332-A7C6-B775D129EF4A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) ==================== Wiederherstellungspunkte ========================= 28-08-2023 09:31:14 Windows Modules Installer ==================== Fehlerhafte Geräte im Gerätemanager ============ Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Fehlereinträge in der Ereignisanzeige: ======================== Applikationsfehler: ================== Error: (08/29/2023 08:18:00 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode: hr=0xC004F074 Befehlszeilenargumente: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (08/29/2023 08:17:07 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/29/2023 08:17:07 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/29/2023 08:17:07 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/29/2023 08:17:07 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/29/2023 08:17:05 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Das Objekt oder die Eigenschaft wurde nicht gefunden. Error: (08/29/2023 08:05:04 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode: hr=0xC004F074 Befehlszeilenargumente: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (08/29/2023 08:04:25 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode: hr=0xC004F074 Befehlszeilenargumente: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Systemfehler: ============= Error: (08/29/2023 08:17:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst asComSvc erreicht. Error: (08/29/2023 08:16:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "UxTuneUp" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (08/29/2023 08:16:38 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst UxTuneUp erreicht. Error: (08/29/2023 08:12:50 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (08/29/2023 08:03:03 AM) (Source: DCOM) (EventID: 10010) (User: WORKSTATION) Description: Der Server "{8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (08/29/2023 08:01:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst asComSvc erreicht. Error: (08/29/2023 08:01:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "UxTuneUp" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (08/29/2023 08:01:11 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (45000 ms) wurde beim Verbindungsversuch mit dem Dienst UxTuneUp erreicht. CodeIntegrity: =============== Date: 2023-08-29 08:16:32 Description: Code Integrity determined that a process (System) attempted to load \Device\HarddiskVolume4\Windows\SysWOW64\drivers\AsIO.sys that did not meet the Authenticode signing level requirements or violated code integrity policy (Policy ID:{d2bda982-ccf6-4344-ac5b-0b44427b6816}). Date: 2023-08-29 08:16:32 Description: The driver \Device\HarddiskVolume4\Windows\SysWOW64\drivers\AsIO.sys is blocked from loading as the driver has been revoked by Microsoft. Date: 2023-08-29 08:16:32 Description: Code Integrity determined that a process (System) attempted to load \Device\HarddiskVolume4\Windows\System32\drivers\GLCKIO2.sys that did not meet the Authenticode signing level requirements or violated code integrity policy (Policy ID:{d2bda982-ccf6-4344-ac5b-0b44427b6816}). Date: 2023-08-29 08:16:32 Description: The driver \Device\HarddiskVolume4\Windows\System32\drivers\GLCKIO2.sys is blocked from loading as the driver has been revoked by Microsoft. Date: 2023-08-29 05:02:53 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== BIOS: American Megatrends International, LLC. 5.04 06/15/2023 Hauptplatine: ASRock B760M Steel Legend WiFi Prozessor: 13th Gen Intel(R) Core(TM) i5-13600 Prozentuale Nutzung des RAM: 23% Installierter physikalischer RAM: 32522.63 MB Verfügbarer physikalischer RAM: 24877.12 MB Summe virtueller Speicher: 34570.63 MB Verfügbarer virtueller Speicher: 22613.26 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:463.52 GB) (Free:333.1 GB) (Model: Samsung SSD 980 PRO 500GB) NTFS Drive d: () (Fixed) (Total:465.75 GB) (Free:310.96 GB) (Model: Samsung SSD 970 EVO 500GB) NTFS Drive e: () (Fixed) (Total:465.75 GB) (Free:304.09 GB) (Model: CT500P3SSD8) NTFS \\?\Volume{cc76ba45-879a-436a-b7c9-8e215cafa51a}\ (Wiederherstellung) (Fixed) (Total:0.58 GB) (Free:0.09 GB) NTFS \\?\Volume{92376e1a-4fb5-499f-a317-a248ef0dde91}\ () (Fixed) (Total:0.73 GB) (Free:0.08 GB) NTFS \\?\Volume{668c8dc3-fb7d-4d2c-a445-06f4db319cea}\ () (Fixed) (Total:0.59 GB) (Free:0.08 GB) NTFS \\?\Volume{04e2fe14-5f6b-44d9-855f-eca23a75003f}\ () (Fixed) (Total:0.32 GB) (Free:0.29 GB) FAT32 ==================== MBR & Partitionstabelle ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 2 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ======================= |
29.08.2023, 08:24 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Sicherheit / Defender zerschossen Ich gebe dir schon extra den Hinweis auf gecrackte Adobe-Software und du hälst es dann nichtmal für nötig, selbst mal kurz nachzuschauen sondern einfach aus dem Bauch heraus zu raten um dann zu behaupten, die Programme seien nicht installiert? Was ist denn das: Zitat:
__________________ --> Windows Sicherheit / Defender zerschossen |
29.08.2023, 08:31 | #7 | |
| Windows Sicherheit / Defender zerschossenZitat:
Also kann man das nicht mehr retten? |
29.08.2023, 09:03 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Sicherheit / Defender zerschossen Natürlich muss da da stehen. FRST listet das doch auch auf.
__________________ Logfiles bitte immer in CODE-Tags posten |
06.09.2023, 15:45 | #9 |
/// TB-Ausbilder | Windows Sicherheit / Defender zerschossen Ich sehe in den Logdateien Reste einer Malware, die bekannt dafür ist, Windows-Dienste zu "zerstören". Eine saubere Neuinstallation ist hier angebracht. |
14.09.2023, 07:09 | #10 |
| Windows Sicherheit / Defender zerschossen Naja hatte mich dazu entschlossen die Kiste neu zu installieren. Was danach passierte gleicht einem Alptraum. Da muss irgendwas installiert gewesen sein. Alle Passwörter von Facebook, Email Anbieten etc. alles wurde gehackt. Eine von meinem Emailadressen (Yahoo) wurde in unzähligen Portalen verwendet und bei Newslettern angemeldet. Bei Yahoo habe ich bereits 1000 Emailadressen gesperrt und es kommen weiterhin noch täglich ca. 20-40 Emails. Es wird langsam weniger. Natürlich habe ich überall 2 Faktor Schutz aktiviert und trotzdem schafft es der Häcker bei der Yahoo Adresse diesen jedes mal auszuhebeln und dann mein Passwort zu ändern. Kann der Virus auch in der Hardware sein? |
14.09.2023, 08:06 | #11 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Sicherheit / Defender zerschossen Hoffentlich dieses Mal ohne Cracks. Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
14.09.2023, 08:32 | #12 |
| Windows Sicherheit / Defender zerschossen Nein, weil der es schafft trotz 2 Faktor Sicherheit in meine Emails kommt und das Passwort ändert. Allerdings nur bei Yahoo |
14.09.2023, 08:59 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Sicherheit / Defender zerschossen Du hast da mit ziemlicher Sicherheit irgendeinen gedanklichen Fehler. Ein zweiter Faktor zieht nach sich, dass es eben NICHT reicht, nur den Login und das Passwort zu kennen. Du behauptest hier aber, dass der Angreifer nicht nur ständig das kennt, sondern auch noch deinen 2. Faktor abgreift. Behauptung losgelassen und wir im Forum sollen dir jetzt diese Behauptung als Wahrheit bestätigen oder was soll das werden was du dir vorstellst?!
__________________ Logfiles bitte immer in CODE-Tags posten Geändert von cosinus (14.09.2023 um 13:16 Uhr) |
14.09.2023, 13:09 | #14 |
/// TB-Ausbilder | Windows Sicherheit / Defender zerschossen Der Erhalt von Spam-Mails ist kein Beleg dafür, dass die Zugangsdaten des E-Mail-Kontos selbst abgegriffen wurden. |
Themen zu Windows Sicherheit / Defender zerschossen |
anbieter, anderen, antivirus, cleaner, defender, ebenfalls, einstellungen, folge, folgendes, funktioniert, gen, kaspersky, kis, neu, nichts, programm, schutz, sicherheit, sicherheitscenter, taugt, treiber, virenschutz, win, windows, überhaupt |