Code:
Alles auswählen Aufklappen ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2023 02
durchgeführt von Whitewolf (Administrator) auf WHITESLATITUDE (Dell Inc. Latitude E6400) (03-12-2023 12:09:48)
Gestartet von C:\Users\Whitewolf\AppData\Local\Temp\scoped_dir10152_1796965055\FRST64.exe
Geladene Profile: Whitewolf & Gast
Plattform: Microsoft Windows 10 Pro Version 22H2 19045.3570 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Opera
Start-Modus: Normal
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(C:\Program Files\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Program Files\Opera\105.0.4970.21\opera_crashreporter.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (VideoLAN -> VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(nvvsvc.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Opera Norway AS -> Opera Software) C:\Program Files\Opera\opera.exe <24>
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\NisSrv.exe
(services.exe ->) (NoVirusThanks Company Srl -> NoVirusThanks Company Srl) C:\Program Files\NoVirusThanks\Win Update Stop\WinUpdStopSvc.exe
(services.exe ->) (NVIDIA Corporation -> ) C:\Windows\System32\nvwmi64.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [atchk] => C:\Program Files (x86)\Intel\AMT\atchk.exe [401408 2009-12-01] (Intel Corporation) [Datei ist nicht signiert]
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM-x32\...\Run: [Opera Browser Assistant] => C:\Program Files\Opera\assistant\browser_assistant.exe [4152776 2022-10-19] (Opera Norway AS -> Opera Software)
HKLM-x32\...\Run: [o2 my Service Suite] => C:\Program Files (x86)\o2 Service Suite\o2_ServiceSuite_launcher.exe [14466968 2021-03-17] (mquadr.at software engineering und consulting GmbH -> o2 Telefonica Germany)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Beschränkung <==== ACHTUNG
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\Run: [WirelessManager] => C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe [182824 2010-01-29] (Ericsson AB -> Ericsson AB)
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\Run: [TheAeroClock] => C:\Program Files\TheAeroClock\TheAeroClock.exe [2041024 2018-05-10] (Nenad Hrg -> Nenad Hrg (SoftwareOK.com))
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\Run: [OpenOffice Updater] => C:\Users\Whitewolf\AppData\Roaming\OpenOffice Updater\Updater.exe [388112 2019-01-12] (Arne Koenig -> ) <==== ACHTUNG
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44529568 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\Run: [MicrosoftEdgeAutoLaunch_BBBA0249A8DD57594F74F1A3A10FB79D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3896784 2023-11-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1190701440-3224281968-238608962-1000\...\MountPoints2: {e94c7bba-8808-11ee-bcab-0013ef4f131f} - "E:\WifiAutoInstallSetup.exe"
HKLM\...\Print\Monitors\Canon SELPHY Language Monitor 3: C:\WINDOWS\SYSTEM32\CNYLCP03.DLL [62976 2013-09-13] (Microsoft Windows Hardware Compatibility Publisher -> Canon INC.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [>{F0DC35EF-6A04-4B5A-AC80-7653D02E21E9}] -> RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwCP.dll [2016-02-17] (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2018-06-05]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Keine Datei)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Opera-Browser.lnk [2017-10-24]
ShortcutTarget: Opera-Browser.lnk -> C:\Program Files\Opera\launcher.exe (Opera Norway AS -> Opera Software)
GroupPolicy: Beschränkung ? <==== ACHTUNG
Policies: C:\ProgramData\NTUSER.pol: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Beschränkung <==== ACHTUNG
HKLM\SOFTWARE\Policies\Google: Beschränkung <==== ACHTUNG
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {33B0D2F5-81B1-4285-966E-59BF97FF0A63} - \Opera scheduled assistant Autoupdate 1581111148 -> Keine Datei <==== ACHTUNG
Task: {DDE4AF8B-E95C-4F2D-BF36-C9A006A59894} - \RealDownloader Update Check -> Keine Datei <==== ACHTUNG
Task: {2D36D13E-D6A2-42FC-8212-F71D61FC034A} - System32\Tasks\{30D4DDF9-7FE9-4C29-891A-87FC33A85A11} => C:\Windows\system32\pcalua.exe [53760 2023-11-08] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Whitewolf\Downloads\CV_Setup_46KM0_A28_ZPE.exe -d C:\Users\Whitewolf\Downloads
Task: {0CD83075-C942-4302-B524-79378CBA54E3} - System32\Tasks\{7DCDA9E1-84AD-4E11-89C7-3407001FB84D} => C:\Windows\system32\pcalua.exe [53760 2023-11-08] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\Whitewolf\Downloads\MEI_ALLOS_6.1.0.1042_PV.exe -d C:\Users\Whitewolf\Downloads
Task: {BBA02D7A-368A-44F7-BD5C-823D4400D663} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_270_pepper.exe -check pepperplugin (Keine Datei)
Task: {EBB4F0B0-697C-4F34-89C9-F56E468A8E89} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {800DA439-D208-4D23-B43B-BE3943213162} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "6ed12878-4769-4267-a934-d7f471a836d5" --version "6.18.10838" --silent
Task: {9B8CFB34-0493-4B3C-A21F-7EB282E93EEF} - System32\Tasks\CCleanerSkipUAC - Whitewolf => C:\Program Files\CCleaner\CCleaner.exe [37546912 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {B01224F5-8268-4C47-8ACA-F2AE6675026A} - System32\Tasks\Core Temp Autostart Whitewolf => C:\Program Files\Core Temp\Core Temp.exe [1040648 2022-12-04] (ALCPU -> ALCPU)
Task: {027974C9-4069-4C20-8150-A58B1F91C8B3} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe --autorun (Keine Datei)
Task: {75D80DD6-3429-488A-A85C-2CCB959D7698} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (Keine Datei)
Task: {7A40487D-A3CB-49D9-9854-4D3FB132F50A} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (Keine Datei)
Task: {1DD06EEC-859C-4AD9-8CFB-1DB834F2D1C7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (Keine Datei)
Task: {6DA067B2-B147-439A-9F97-2C2A0DE4261A} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (Keine Datei)
Task: {73C2DA9B-7294-4FCE-BD48-39837507B543} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (Keine Datei)
Task: {BCD401C3-AA64-4FE4-9DE8-2154015A9F14} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (Keine Datei)
Task: {26D1CA61-2C52-44C7-8754-D4C4E811F2D2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (Keine Datei)
Task: {52198EFE-042D-42F0-AA06-33CCD7440518} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (Keine Datei)
Task: {2721C26A-B9D0-4056-950B-4A63D944961C} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (Keine Datei)
Task: {D2284DE1-BFFC-4321-9AC1-BF09DBEC11D7} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (Keine Datei)
Task: {DDB869E0-C2AD-4135-B3DC-11E23318DA7F} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (Keine Datei)
Task: {3FA95669-C82B-41DA-8488-C089B5141090} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (Keine Datei)
Task: {0137139D-8E35-4988-8B58-298D43E906A7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (Keine Datei)
Task: {1A4759B6-EA91-4FAA-B235-E5CE872C1417} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (Keine Datei)
Task: {3D330532-B571-4824-9724-73C3D01E7D2C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (Keine Datei)
Task: {215C797C-69F8-4D1B-B781-DAFED78E8062} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (Keine Datei)
Task: {DAE7A976-A296-47E2-8880-C9A92D34E98D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (Keine Datei)
Task: {F4C8AEF3-28F5-43FC-AECA-E491E4F56088} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (Keine Datei)
Task: {690BDE30-1E67-4BFB-9246-155902FA15BB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (Keine Datei)
Task: {CBA76997-FA8A-498F-954B-00AA41965116} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (Keine Datei)
Task: {14A5B42C-52AA-4155-BC85-F72851A9CC8F} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (Keine Datei)
Task: {451F79CB-7FE9-4461-8B16-F007CFB66241} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec /StartRecording (Keine Datei)
Task: {9042BF28-9D0D-4CDC-9DD9-CD0BEAC84E0D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (Keine Datei)
Task: {C663B3BB-2EE4-40E0-AE43-9F792C3481A7} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {D847EB09-5E16-4D5C-A841-592A1ED46104} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {950327B8-478C-435C-9D0B-5C9F69FDB68F} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {CE8E011F-EED0-47DC-ADC1-E3795212A490} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {5655D3BA-9ACD-4D5E-94EB-8DC388CFCCF7} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {D9E21195-A057-41F0-AE32-0BD60104761A} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistant => %windir%\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV24:{} (Keine Datei)
Task: {96411CF4-7D00-49BB-8BAD-A959345F7D1A} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantAllUsersRun => %windir%\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV24:{} /AllUsersRun (Keine Datei)
Task: {74EF0246-96B4-4FF8-89F8-3C6E5F7EEFFC} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantCalendarRun => %windir%\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV24:{} /CalendarRun (Keine Datei)
Task: {B6868BC2-D95E-48B7-BF24-396489BBA680} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantWakeupRun => %windir%\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV24:{} /WakeupRun (Keine Datei)
Task: {3F32AD4E-207A-4A7F-94F7-26DAE2FD85F4} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {062269A5-9646-4849-84E1-C5D43E42DD76} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MpCmdRun.exe [1604680 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {64E90702-46B7-47D2-9B52-12FF22F20A5F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MpCmdRun.exe [1604680 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E26A1BBE-6C20-4FB6-A8A0-F58F28B9D015} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MpCmdRun.exe [1604680 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8D350CA9-85E8-4F05-8C13-747BAB88E9D5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MpCmdRun.exe [1604680 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A5C5069C-9C65-4190-8062-8532D96CA71A} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675232 2023-09-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {EFDBC712-985F-461F-B947-9DC031795729} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [722336 2023-09-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {3427710B-EDBF-4188-9542-0874E3FB8329} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1190701440-3224281968-238608962-1000 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (Keine Datei)
Task: {40FD1117-915C-434F-91CC-49C725D31287} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1190701440-3224281968-238608962-1000 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Keine Datei)
Task: {32FB7656-BF38-4A68-8B9E-D726C1DE04DA} - System32\Tasks\Opera scheduled Autoupdate 1508824110 => C:\Program Files\Opera\launcher.exe [2353056 2023-11-22] (Opera Norway AS -> Opera Software)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ACHTUNG (Beschränkung - Zones)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{29a21912-9991-4c1c-aab7-83307f0a22ef}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2a0473b5-9759-4365-8291-095e06a30eda}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3d18a970-a2f9-49a0-aa07-43409bbb0347}: [DhcpNameServer] 192.168.42.129
Edge:
=======
DownloadDir: C:\Users\Whitewolf\Downloads
Edge Session Restore: HKU\S-1-5-21-1190701440-3224281968-238608962-1000 -> ist aktiviert.
Edge Notifications: HKU\S-1-5-21-1190701440-3224281968-238608962-1000 -> hxxps://www.facebook.com; hxxps://www.mp3-download.yt
Edge Extension: (Kein Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nicht gefunden]
Edge Extension: (Kein Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nicht gefunden]
Edge Extension: (Kein Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nicht gefunden]
Edge Extension: (Kein Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nicht gefunden]
Edge Profile: C:\Users\Whitewolf\AppData\Local\Microsoft\Edge\User Data\Default [2023-12-03]
Edge Session Restore: Default -> ist aktiviert.
Edge Extension: (Google Docs Offline) - C:\Users\Whitewolf\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-16]
Edge Extension: (Edge relevant text changes) - C:\Users\Whitewolf\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-15]
FireFox:
========
FF DefaultProfile: itppo5we.default-1489414921434
FF ProfilePath: C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\tlk1e179.default-release [2023-12-03]
FF ProfilePath: C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434 [2023-12-03]
FF Homepage: Mozilla\Firefox\Profiles\itppo5we.default-1489414921434 -> about :home
FF Session Restore: Mozilla\Firefox\Profiles\itppo5we.default-1489414921434 -> ist aktiviert.
FF Notifications: Mozilla\Firefox\Profiles\itppo5we.default-1489414921434 -> hxxp://www.andre-citroen-club.de; hxxp://www.mapup.de
FF Extension: (Avast SafePrice) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\sp@avast.com.xpi [2017-10-14] [UpdateUrl:hxxps://firefoxextension.avast.com/sp/update.json]
FF Extension: (Avast Online Security) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\wrc@avast.com.xpi [2017-10-19] [UpdateUrl:hxxps://firefoxextension.avast.com/aos/update.json]
FF Extension: (BlackFox V2-Blue) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\zigboom.designs@gmail.com [2017-09-30] []
FF Extension: (BlackFox V2) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\zigboom@hotmail.com [2017-09-30] []
FF Extension: (Bloody Red) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\{2458abc0-f443-11dd-87af-0800200c9a66} [2017-03-13] [] [ist nicht signiert]
FF Extension: (IE Tab) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2017-03-13] []
FF Extension: (Red Google Theme) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\itppo5we.default-1489414921434\Extensions\{f9f573f6-3ab6-4ef6-934e-33b4be3d7bfc}.xpi [2017-03-13] []
FF ProfilePath: C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\vqh5c8ne.default-1478799288136 [2023-12-03]
FF Homepage: Mozilla\Firefox\Profiles\vqh5c8ne.default-1478799288136 -> www1.online/?w=RD6763
FF Extension: (Avast SafePrice) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\vqh5c8ne.default-1478799288136\Extensions\sp@avast.com.xpi [2017-05-12] [UpdateUrl:hxxps://firefoxextension.avast.com/sp/update.json]
FF Extension: (Avast Online Security) - C:\Users\Whitewolf\AppData\Roaming\Mozilla\Firefox\Profiles\vqh5c8ne.default-1478799288136\Extensions\wrc@avast.com.xpi [2017-10-19] [UpdateUrl:hxxps://firefoxextension.avast.com/aos/update.json]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_170.dll [2017-10-16] (Adobe Systems Incorporated -> )
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_170.dll [Keine Datei]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-23] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-23] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-23] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-23] (Foxit Software Incorporated -> Foxit Corporation)
Chrome:
=======
CHR HKU\S-1-5-21-1190701440-3224281968-238608962-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mhmphnocemakkjdampibehejoaleebpo]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
Opera:
=======
OPR DefaultProfile: Default
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2010-08-16] (Microsoft Windows Hardware Compatibility Publisher -> Andrea Electronics Corporation)
S4 atchksrv; C:\Program Files (x86)\Intel\AMT\atchksrv.exe [176128 2009-12-01] (Intel Corporation) [Datei ist nicht signiert]
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1083808 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S4 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2016-12-29] (Foxit Software Incorporated -> Foxit Software Inc.)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [86920 2021-05-27] (Mixbyte Inc -> Freemake)
S4 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [102400 2009-12-01] (Intel) [Datei ist nicht signiert]
R2 NVWMI; C:\WINDOWS\system32\nvwmi64.exe [2701696 2016-10-18] (NVIDIA Corporation -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-11-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [263168 2010-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [18033464 2023-10-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S4 UNS; C:\Program Files (x86)\Intel\AMT\UNS.exe [2519040 2009-12-01] (Intel) [Datei ist nicht signiert]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\NisSrv.exe [3121120 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 WifiAutoInstallSrv; C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe [124864 2017-07-31] (Realtek Semiconductor Corp. -> Realtek)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe [133704 2023-11-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinUpdStopSvc; C:\Program Files\NoVirusThanks\Win Update Stop\WinUpdStopSvc.exe [2178280 2018-08-24] (NoVirusThanks Company Srl -> NoVirusThanks Company Srl)
S4 WMCoreService; C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe [430080 2009-09-24] () [Datei ist nicht signiert]
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 CtClsFlt; C:\WINDOWS\System32\DRIVERS\CtClsFlt.sys [172704 2009-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
R3 d554gps; C:\WINDOWS\system32\DRIVERS\d554gps64.sys [96296 2009-07-10] (Ericsson AB -> Ericsson AB)
R3 d557bus; C:\WINDOWS\System32\drivers\d557bus.sys [328704 2009-06-29] (MCCI Corporation -> MCCI Corporation)
R3 d557mdfl; C:\WINDOWS\system32\DRIVERS\d557mdfl.sys [19456 2009-06-29] (MCCI Corporation -> MCCI Corporation)
R3 d557mdm; C:\WINDOWS\system32\DRIVERS\d557mdm.sys [432128 2009-06-29] (MCCI Corporation -> MCCI Corporation)
R3 d557mgmt; C:\WINDOWS\system32\DRIVERS\d557mgmt.sys [376320 2009-06-29] (MCCI Corporation -> MCCI Corporation)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Techporch Incorporated -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation)
R3 KMWDFILTER; C:\WINDOWS\System32\drivers\KMWDFILTER.sys [30208 2009-04-29] (MLK Technologies Limited -> Windows (R) Codename Longhorn DDK provider)
R3 OA001Ufd; C:\WINDOWS\system32\DRIVERS\OA001Ufd.sys [159840 2009-03-06] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
R3 OA001Vid; C:\WINDOWS\system32\DRIVERS\OA001Vid.sys [319840 2009-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
R2 rimmptsk; C:\WINDOWS\System32\drivers\rimmpx64.sys [67072 2009-09-03] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12183512 2022-02-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
R3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [515584 2010-08-16] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55744 2023-11-07] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [578856 2023-11-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105768 2023-11-07] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Drei Monate (erstellte) (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2023-12-03 12:08 - 2023-12-03 12:08 - 002384384 _____ (Farbar) C:\Users\Whitewolf\Downloads\FRST64.exe
2023-12-03 10:41 - 2023-12-03 12:23 - 188252160 _____ C:\Users\Whitewolf\Downloads\64KlbmnJij.part3.rar.opdownload
2023-12-03 06:23 - 2023-12-03 08:17 - 209715200 _____ C:\Users\Whitewolf\Downloads\64KlbmnJij.part2.rar
2023-12-03 04:12 - 2023-12-03 04:12 - 000000000 ____D C:\Users\Whitewolf\Downloads\NoWaOu78662054
2023-12-03 03:24 - 2023-12-03 05:18 - 209715200 _____ C:\Users\Whitewolf\Downloads\64KlbmnJij.part1.rar
2023-12-02 22:47 - 2023-12-02 22:50 - 915915713 _____ C:\Users\Whitewolf\Downloads\Hercules_23.11.25_20-15_vox_130_TVOON_DE.mpg.HQ.cut.mp4
2023-12-02 18:02 - 2023-12-02 18:02 - 000000000 ____D C:\Users\Whitewolf\Downloads\Theres.Something.wrong.with.the.Barn.AC3.WEBRip
2023-12-02 05:48 - 2023-12-02 05:48 - 000047877 _____ C:\Users\Whitewolf\Desktop\Addition scan 2.12.23.txt
2023-12-02 05:08 - 2023-12-03 12:12 - 000000000 ____D C:\FRST
2023-12-02 04:56 - 2023-12-02 04:56 - 000000000 ____D C:\Users\Whitewolf\Downloads\FRST11 (2)
2023-12-02 04:55 - 2023-12-02 04:55 - 000000000 ____D C:\Users\Whitewolf\Downloads\FRST11
2023-12-01 11:51 - 2023-12-01 11:51 - 000000000 ____D C:\Users\Whitewolf\Downloads\Big.George.Foreman.AC3.Web
2023-11-30 12:12 - 2023-11-30 12:14 - 000000000 ____D C:\Users\Whitewolf\Downloads\Die_andere_Front
2023-11-29 06:01 - 2023-11-29 06:01 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\TacticsTechnology
2023-11-28 20:49 - 2023-11-28 20:49 - 000000000 ____D C:\Program Files\Realtek
2023-11-28 13:58 - 2023-11-28 13:58 - 000001155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera-Browser.lnk
2023-11-26 06:14 - 2023-11-27 19:50 - 000023935 _____ C:\Users\Whitewolf\Documents\tod einer mutter.odt
2023-11-25 20:17 - 2023-11-25 20:17 - 000015985 _____ C:\Users\Whitewolf\Documents\pitstop.odt
2023-11-24 04:06 - 2023-11-24 04:29 - 000000708 _____ C:\Users\Whitewolf\Desktop\Schriftart.reg
2023-11-22 00:09 - 2023-11-22 00:09 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\BrightData
2023-11-22 00:09 - 2023-11-22 00:09 - 000000000 ____D C:\ProgramData\BrightData
2023-11-21 03:06 - 2023-11-21 03:07 - 000000000 ____D C:\Program Files (x86)\Cisco
2023-11-21 03:06 - 2017-05-31 07:15 - 001139416 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\system32\Rtlihvs.dll
2023-11-21 03:02 - 2023-11-21 03:03 - 000000000 ____D C:\Users\Whitewolf\Downloads\Neuer Ordner
2023-11-21 02:56 - 2023-11-21 02:56 - 000000000 ____D C:\Users\Whitewolf\Downloads\realtek 8812bu treiber
2023-11-14 06:23 - 2023-11-14 06:26 - 1089565527 _____ C:\Users\Whitewolf\Downloads\Super_8_23.11.11_20-15_zdfneo_100_TVOON_DE.mpg.HQ.cut.mp4
2023-11-12 21:59 - 2023-11-12 22:04 - 000000000 ____D C:\Users\Whitewolf\Downloads\Fleisch.Und.Blut.REMASTERED.GERMAN.1985.DL.BDRiP.x264-GOREHOUNDS
2023-11-12 04:22 - 2023-11-12 04:23 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\TeamViewer
2023-11-12 04:21 - 2023-11-12 04:21 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer Host.lnk
2023-11-10 15:20 - 2023-11-10 15:20 - 001603554 _____ C:\Users\Whitewolf\Downloads\Einladung_PrinterONE_DIN lang_Digital.pdf
2023-11-10 04:02 - 2023-11-10 04:02 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\Backup
2023-11-08 09:45 - 2023-11-08 09:45 - 000016059 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2023-11-08 08:38 - 2023-11-08 08:38 - 000000000 ___HD C:\$WinREAgent
2023-10-29 04:02 - 2023-10-29 04:02 - 000000000 ____D C:\Users\Whitewolf\Downloads\What.the.Waters.Left.Behind.Scars.AC3.BDRiP
2023-10-29 04:02 - 2014-05-30 21:28 - 000000000 ____D C:\Users\Whitewolf\Downloads\CoolWorld
2023-10-27 22:38 - 2023-10-27 22:38 - 000007055 _____ C:\Users\Whitewolf\AppData\Local\recently-used.xbel
2023-10-25 11:47 - 2023-10-25 11:47 - 001605461 _____ C:\Users\Whitewolf\Downloads\Aktionen zur Black Week 2023.pdf
2023-10-25 11:43 - 2023-10-25 11:43 - 000243279 _____ C:\Users\Whitewolf\Downloads\Infosheet_Wartung_Ceramill Units_2023.pdf
2023-10-22 18:01 - 2023-10-22 18:01 - 000000020 ___SH C:\Users\Whitewolf\ntuser.ini
2023-10-22 17:47 - 2023-10-22 17:47 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1190701440-3224281968-238608962-1000
2023-10-22 17:47 - 2023-10-22 17:47 - 000003384 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1190701440-3224281968-238608962-1000
2023-10-22 17:43 - 2023-10-22 17:43 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2023-10-22 17:38 - 2023-10-22 17:38 - 000000392 __RSH C:\ProgramData\ntuser.pol
2023-10-22 17:32 - 2023-10-22 17:33 - 000000000 ____D C:\Users\TEMP
2023-10-22 17:32 - 2023-10-22 14:58 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Microsoft\Network
2023-10-22 17:32 - 2023-10-22 14:45 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
2023-10-22 17:32 - 2011-04-12 08:54 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Media Center Programs
2023-10-22 15:26 - 2023-10-22 15:33 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2023-10-22 15:20 - 2023-10-22 15:25 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2023-10-22 15:19 - 2023-10-22 15:19 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2023-10-22 15:08 - 2023-12-03 03:16 - 000003326 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1508824110
2023-10-22 15:08 - 2023-12-02 22:37 - 000004176 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{5FED5BF6-B0B1-46A9-8CDB-B5B75D3CC382}
2023-10-22 15:08 - 2023-11-30 01:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-10-22 15:08 - 2023-11-24 10:52 - 000003380 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2023-10-22 15:08 - 2023-11-24 10:51 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2023-10-22 15:08 - 2023-10-27 23:01 - 000003754 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-10-22 15:08 - 2023-10-27 23:01 - 000003630 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-10-22 15:08 - 2023-10-22 15:09 - 000003816 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2023-10-22 15:08 - 2023-10-22 15:09 - 000002260 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Whitewolf
2023-10-22 15:08 - 2023-10-22 15:08 - 000002466 _____ C:\WINDOWS\system32\Tasks\DriverToolkit Autorun
2023-10-22 15:08 - 2023-10-22 15:08 - 000002318 _____ C:\WINDOWS\system32\Tasks\{7DCDA9E1-84AD-4E11-89C7-3407001FB84D}
2023-10-22 15:08 - 2023-10-22 15:08 - 000002316 _____ C:\WINDOWS\system32\Tasks\{30D4DDF9-7FE9-4C29-891A-87FC33A85A11}
2023-10-22 15:08 - 2023-10-22 15:08 - 000002280 _____ C:\WINDOWS\system32\Tasks\Core Temp Autostart Whitewolf
2023-10-22 15:08 - 2023-10-22 15:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2023-10-22 15:08 - 2023-10-22 15:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software
2023-10-22 15:08 - 2023-10-22 15:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2023-10-22 15:08 - 2023-10-22 15:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avira
2023-10-22 15:07 - 2023-10-22 15:08 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2023-10-22 15:07 - 2023-10-22 15:08 - 000011433 _____ C:\WINDOWS\diagerr.xml
2023-10-22 15:07 - 2023-10-22 15:07 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2023-10-22 14:58 - 2023-10-22 14:58 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2023-10-22 14:56 - 2023-11-21 03:23 - 001835912 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-10-22 14:54 - 2023-10-22 14:54 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\Microsoft\SystemCertificates
2023-10-22 14:54 - 2023-10-22 14:54 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\Microsoft\Network
2023-10-22 14:54 - 2023-10-22 14:54 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\Microsoft\Crypto
2023-10-22 14:53 - 2023-10-22 14:53 - 000000000 ____D C:\Users\Gast\AppData\Roaming\Microsoft\SystemCertificates
2023-10-22 14:53 - 2023-10-22 14:53 - 000000000 ____D C:\Users\Gast\AppData\Roaming\Microsoft\Network
2023-10-22 14:44 - 2023-10-22 14:44 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\Microsoft\CLR Security Config
2023-10-22 14:43 - 2023-12-03 00:01 - 000000000 ____D C:\Users\Whitewolf
2023-10-22 14:43 - 2023-11-09 07:59 - 000000000 ____D C:\Users\Gast
2023-10-22 14:43 - 2023-10-22 14:58 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\Microsoft\Windows
2023-10-22 14:43 - 2023-10-22 14:53 - 000000000 ____D C:\Users\Gast\AppData\Roaming\Microsoft\Windows
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Vorlagen
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Startmenü
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Netzwerkumgebung
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Lokale Einstellungen
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Eigene Dateien
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Druckumgebung
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Documents\Eigene Videos
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Documents\Eigene Musik
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Documents\Eigene Bilder
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\AppData\Local\Verlauf
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\AppData\Local\Anwendungsdaten
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Whitewolf\Anwendungsdaten
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Vorlagen
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Startmenü
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Netzwerkumgebung
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Lokale Einstellungen
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Eigene Dateien
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Druckumgebung
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Documents\Eigene Videos
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Documents\Eigene Musik
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Documents\Eigene Bilder
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\AppData\Local\Verlauf
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\AppData\Local\Anwendungsdaten
2023-10-22 14:43 - 2023-10-22 14:43 - 000000000 _SHDL C:\Users\Gast\Anwendungsdaten
2023-10-22 14:35 - 2023-12-03 11:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-10-22 14:35 - 2023-11-24 04:37 - 000324496 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-10-22 14:19 - 2023-10-22 14:19 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2023-10-22 14:19 - 2023-10-22 14:19 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2023-10-22 14:19 - 2023-10-22 14:19 - 000000000 ____D C:\WINDOWS\system32\msmq
2023-10-22 14:19 - 2023-10-22 14:19 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2023-10-22 14:18 - 2023-10-22 14:18 - 000000000 ____D C:\Program Files\Reference Assemblies
2023-10-22 14:18 - 2023-10-22 14:18 - 000000000 ____D C:\Program Files\MSBuild
2023-10-22 14:18 - 2023-10-22 14:18 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2023-10-22 14:18 - 2023-10-22 14:18 - 000000000 ____D C:\Program Files (x86)\MSBuild
2023-10-22 14:18 - 2023-10-22 14:18 - 000000000 ____D C:\inetpub
2023-10-21 09:52 - 2023-11-02 16:52 - 000000000 ___DC C:\WINDOWS\Panther
2023-10-05 03:17 - 2023-10-05 03:20 - 773769621 _____ C:\Users\Whitewolf\Downloads\Colombiana_23.09.28_22-25_vox_130_TVOON_DE.mpg.HQ.cut.mp4
2023-10-04 20:43 - 2023-10-04 20:43 - 000000000 ____D C:\Users\Whitewolf\Downloads\Im.Todeskreis.1997.GERMAN.TVRip.Xvid
2023-09-26 15:36 - 2016-08-26 22:23 - 000000000 ____D C:\Users\Whitewolf\Downloads\Laurel.&.Hardy.-.Im.Regenbogenclub.German.1930.DVDRip.XVID
2023-09-24 05:46 - 2023-09-24 05:46 - 000002076 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Privater Modus.lnk
2023-09-24 05:46 - 2023-09-24 05:46 - 000001047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-09-24 05:46 - 2023-09-24 05:46 - 000001035 _____ C:\Users\Public\Desktop\Firefox.lnk
2023-09-24 05:46 - 2023-09-24 05:46 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-09-19 01:43 - 2023-09-19 01:45 - 575053094 _____ C:\Users\Whitewolf\Downloads\Alien_vs__Predator_23.09.12_20-15_4plus_130_TVOON_DE.mpg.HQ.cut.mp4
2023-09-14 09:33 - 2016-01-19 14:18 - 000004216 _____ C:\WINDOWS\PidVid_List.txt
2023-09-14 09:17 - 2023-11-21 03:06 - 000000000 ____D C:\Program Files (x86)\REALTEK
2023-09-13 05:18 - 2023-09-13 05:21 - 981832034 _____ C:\Users\Whitewolf\Downloads\47_Meters_Down_23.09.09_22-35_4plus_120_TVOON_DE.mpg.HQ.avi
==================== Drei Monate (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2023-12-03 05:33 - 2020-06-10 10:04 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\vlc
2023-12-03 04:18 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-12-03 03:07 - 2022-11-07 15:36 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-12-03 03:05 - 2016-02-26 17:05 - 000000000 ____D C:\Program Files\CCleaner
2023-12-02 08:00 - 2018-06-04 17:50 - 000000000 ____D C:\Program Files\Core Temp
2023-12-02 03:15 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-11-30 01:29 - 2023-01-16 22:37 - 000002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-11-30 01:29 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-11-30 01:05 - 2022-11-09 20:21 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2023-11-30 01:05 - 2020-10-18 00:36 - 000008192 ___SH C:\DumpStack.log.tmp
2023-11-30 01:05 - 2017-10-24 06:45 - 000000000 ____D C:\Program Files\Opera
2023-11-28 20:49 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2023-11-25 22:55 - 2018-06-04 07:36 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-11-24 04:35 - 2019-12-07 10:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2023-11-24 02:53 - 2023-04-04 19:46 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2023-11-24 02:53 - 2020-02-11 18:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-11-22 05:39 - 2022-11-07 15:30 - 000001097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2023-11-22 00:12 - 2018-06-05 16:36 - 000000000 ____D C:\ProgramData\Realtek
2023-11-21 12:14 - 2016-11-16 04:23 - 000000000 ____D C:\Users\Whitewolf\AppData\LocalLow\Mozilla
2023-11-21 03:23 - 2019-12-07 15:51 - 000787000 _____ C:\WINDOWS\system32\perfh007.dat
2023-11-21 03:23 - 2019-12-07 15:51 - 000168078 _____ C:\WINDOWS\system32\perfc007.dat
2023-11-21 03:06 - 2016-02-22 15:11 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2023-11-21 02:28 - 2016-02-27 11:50 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\ElevatedDiagnostics
2023-11-21 02:25 - 2018-06-04 08:22 - 000000000 ____D C:\Users\Whitewolf\AppData\Local\PlaceholderTileLogoFolder
2023-11-17 03:19 - 2016-11-05 18:53 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2023-11-12 04:20 - 2020-06-10 10:04 - 000000958 _____ C:\Users\Public\Desktop\VLC media player.lnk
2023-11-12 04:08 - 2018-10-01 10:56 - 000000000 ____D C:\Users\Whitewolf\AppData\Roaming\OpenOffice Updater
2023-11-09 08:11 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-11-09 07:53 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\SysWOW64\de
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2023-11-09 07:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2023-11-09 07:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2023-11-09 07:50 - 2019-12-07 15:54 - 000000000 ___SD C:\WINDOWS\system32\AppV
2023-11-09 07:50 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\system32\de
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-11-09 07:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2023-11-09 07:48 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-11-09 07:47 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-11-09 07:47 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-11-09 07:47 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2023-11-09 07:47 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-11-09 07:47 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2023-11-09 07:46 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2023-11-08 10:48 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-11-08 10:41 - 2019-12-07 15:54 - 000023552 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2023-11-08 10:41 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2023-11-08 10:39 - 2019-12-07 15:54 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2023-11-08 10:38 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2023-11-08 04:43 - 2022-11-08 00:06 - 000015625 _____ C:\Users\Whitewolf\Documents\kündi22222.odt
2023-11-07 17:34 - 2018-07-28 17:25 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2019-10-29 19:58 - 2020-01-07 18:16 - 000001269 _____ () C:\Users\Whitewolf\AppData\Roaming\downloads.json
2016-06-25 06:46 - 2016-08-10 19:01 - 000000158 _____ () C:\Users\Whitewolf\AppData\Roaming\WB.CFG
2020-01-04 12:34 - 2020-01-04 12:37 - 000005120 _____ () C:\Users\Whitewolf\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2023-10-27 22:38 - 2023-10-27 22:38 - 000007055 _____ () C:\Users\Whitewolf\AppData\Local\recently-used.xbel
2017-10-19 09:29 - 2023-09-10 10:51 - 000007600 _____ () C:\Users\Whitewolf\AppData\Local\Resmon.ResmonCfg
==================== SigCheckExt =========================
2006-12-08 15:42 - 2008-12-09 18:46 - 000155136 _____ C:\WINDOWS\system32\bioapi100.dll
2006-12-08 15:41 - 2008-12-09 18:46 - 000239104 _____ C:\WINDOWS\system32\bioapi_mds300.dll
2011-04-12 08:54 - 2010-11-21 04:23 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvscres.dll
2017-02-19 17:14 - 2017-02-19 17:14 - 000425744 _____ (Lavasoft Limited) C:\WINDOWS\system32\LavasoftTcpService64.dll
2018-06-04 08:16 - 2016-11-14 12:15 - 000067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2010-03-09 14:56 - 2010-03-09 14:56 - 000209920 _____ (IDT, Inc.) C:\WINDOWS\system32\st646274.dll
2008-01-17 18:25 - 2008-01-17 18:25 - 002520064 _____ (UPEK, Inc.) C:\WINDOWS\system32\tfmessbsp.dll
2016-02-27 18:39 - 2012-12-03 14:58 - 000279040 _____ (Nicomsoft Ltd.) C:\WINDOWS\system32\WiFiMan.dll
2019-05-26 18:40 - 2006-08-25 20:17 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl70.dll
2016-03-02 12:16 - 2011-01-12 19:53 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl71.dll
2016-02-22 15:08 - 2009-09-02 06:13 - 000131072 _____ (Dell, Inc.) C:\WINDOWS\SysWOW64\DellSPMsg.dll
2016-10-16 05:14 - 2003-05-22 10:26 - 000638976 _____ (DivXNetworks, Inc.) C:\WINDOWS\SysWOW64\divx.dll
2016-10-16 05:14 - 2011-12-07 17:32 - 000216064 _____ ( ) C:\WINDOWS\SysWOW64\Lagarith.dll
2017-02-19 17:14 - 2017-02-19 17:14 - 000345360 _____ (Lavasoft Limited) C:\WINDOWS\SysWOW64\LavasoftTcpService.dll
2016-10-16 05:14 - 2003-05-21 21:50 - 000261632 _____ (MainConcept) C:\WINDOWS\SysWOW64\mcdvd_32.dll
1999-01-26 15:26 - 1999-01-26 15:26 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC42DEU.DLL
2019-05-26 18:40 - 2006-08-25 21:07 - 001024000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70chs.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70cht.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70deu.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70enu.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70esp.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70fra.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70ita.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70jpn.dll
2019-05-26 18:40 - 2006-08-25 21:15 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70kor.dll
2019-05-26 18:40 - 2006-08-25 21:28 - 001017344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc70u.dll
2016-03-02 12:16 - 2011-01-12 20:19 - 001060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71.dll
2019-05-26 18:40 - 2011-01-12 20:25 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71CHS.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71CHT.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71DEU.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ENU.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ESP.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71FRA.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71ITA.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71JPN.DLL
2019-05-26 18:40 - 2011-01-12 20:25 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71KOR.DLL
2016-03-02 12:16 - 2011-01-12 20:36 - 001054208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFC71u.dll
2016-10-16 05:14 - 2002-08-19 22:41 - 000413760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg4c32.dll
2006-11-15 00:42 - 2006-11-15 00:42 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscmcde.dll
1998-08-18 01:01 - 1998-08-18 01:01 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPRPDE.DLL
2000-05-11 12:06 - 2000-05-11 12:06 - 000397312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSRDO20.DLL
2019-05-26 18:40 - 2008-04-15 13:00 - 001355776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvbvm50.dll
2019-05-26 18:40 - 2005-01-20 16:25 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvci70.dll
2019-05-26 18:40 - 2002-01-05 02:40 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVCP70.DLL
2019-05-26 18:40 - 2007-01-30 17:04 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr70.dll
2019-05-26 18:40 - 1994-11-17 22:00 - 000210944 _____ C:\WINDOWS\SysWOW64\msvcrt10.dll
2016-10-16 05:14 - 2003-05-21 21:50 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3a.dll
2016-12-27 19:26 - 2007-05-13 12:24 - 000086683 _____ (Open Source Software community project) C:\WINDOWS\SysWOW64\pthreadGC2.dll
2000-04-03 16:52 - 2000-04-03 16:52 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RDOCURS.DLL
2017-09-10 07:53 - 2013-10-03 16:02 - 000040960 _____ (vbAccelerator) C:\WINDOWS\SysWOW64\ssubtmr6.dll
2019-05-26 18:40 - 1996-01-12 01:00 - 000722192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Vb40032.dll
2006-11-15 00:41 - 2006-11-15 00:41 - 000125712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vb6de.dll
2016-10-16 05:14 - 2004-12-10 08:03 - 000438272 _____ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2016-02-27 18:39 - 2012-12-03 14:57 - 000238592 _____ (Nicomsoft Ltd.) C:\WINDOWS\SysWOW64\WiFiMan.dll
2016-10-16 05:14 - 2004-07-03 18:59 - 000524288 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2016-10-16 05:14 - 2004-07-03 19:08 - 000139264 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2010-04-09 21:08 - 2010-04-09 21:08 - 000094208 _____ C:\WINDOWS\SysWOW64\zmbv.dll
2023-12-03 12:08 - 2023-12-03 12:08 - 002384384 _____ (Farbar) C:\Users\Whitewolf\Downloads\FRST64.exe
2018-06-05 19:27 - 2018-06-05 19:27 - 001540104 _____ (CHIP Digital GmbH) C:\Users\Whitewolf\Documents\ClocX - CHIP-Installer.exe
2018-11-07 21:45 - 2018-11-07 21:45 - 001542152 _____ (CHIP Digital GmbH) C:\Users\Whitewolf\Documents\D Fend Reloaded - CHIP-Installer.exe
2018-08-18 18:56 - 2018-08-18 18:59 - 037953312 _____ (EaseUS ) C:\Users\Whitewolf\Documents\epm.exe
2020-01-04 20:22 - 2020-01-04 20:23 - 005023797 _____ (ffdshow ) C:\Users\Whitewolf\Documents\ffdshow_rev4531_20140628_x64.exe
2018-12-22 12:14 - 2018-12-22 12:31 - 024686205 _____ C:\Users\Whitewolf\Documents\RetroShare-0.6.4-20180312-91634ba6-Qt-4.8.7-setup.exe
2018-06-05 19:41 - 2018-06-05 19:41 - 001540104 _____ (CHIP Digital GmbH) C:\Users\Whitewolf\Documents\The Aero Clock - CHIP-Installer.exe
2019-05-16 19:46 - 2019-05-16 19:46 - 001336336 _____ (CHIP Digital GmbH) C:\Users\Whitewolf\Documents\Windows Update Blocker - CHIP-Installer.exe
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== BCD ================================
Windows-Start-Manager
---------------------
Bezeichner {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale de-DE
inherit {globalsettings}
default {current}
resumeobject {ff12922a-70e7-11ee-927b-aceb846d0a59}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Windows-Startladeprogramm
-------------------------
Bezeichner {419231c7-70e0-11ee-bca5-b016f99ae24d}
device ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{419231c8-70e0-11ee-bca5-b016f99ae24d}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale de-DE
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{419231c8-70e0-11ee-bca5-b016f99ae24d}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows-Startladeprogramm
-------------------------
Bezeichner {815d685c-d8bc-11e5-a2be-ddcfe1d725b8}
device ramdisk=[C:]\Recovery\815d685c-d8bc-11e5-a2be-ddcfe1d725b8\Winre.wim,{815d685d-d8bc-11e5-a2be-ddcfe1d725b8}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[C:]\Recovery\815d685c-d8bc-11e5-a2be-ddcfe1d725b8\Winre.wim,{815d685d-d8bc-11e5-a2be-ddcfe1d725b8}
systemroot \windows
nx OptIn
winpe Yes
Windows-Startladeprogramm
-------------------------
Bezeichner {cb30a939-10d1-11eb-bc35-80bd5b68b537}
device ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{cb30a93a-10d1-11eb-bc35-80bd5b68b537}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale de-DE
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{cb30a93a-10d1-11eb-bc35-80bd5b68b537}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows-Startladeprogramm
-------------------------
Bezeichner {current}
device partition=C:
path \WINDOWS\system32\winload.exe
description Windows 10
locale de-DE
inherit {bootloadersettings}
recoverysequence {419231c7-70e0-11ee-bca5-b016f99ae24d}
displaymessageoverride Recovery
recoveryenabled Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {ff12922a-70e7-11ee-927b-aceb846d0a59}
nx OptIn
bootmenupolicy Standard
Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner {ff12922a-70e7-11ee-927b-aceb846d0a59}
device partition=C:
path \WINDOWS\system32\winresume.exe
description Windows Resume Application
locale de-DE
inherit {resumeloadersettings}
recoverysequence {419231c7-70e0-11ee-bca5-b016f99ae24d}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows-Speichertestprogramm
----------------------------
Bezeichner {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Windows-Speicherdiagnose
locale de-DE
inherit {globalsettings}
badmemoryaccess Yes
EMS-Einstellungen
-----------------
Bezeichner {emssettings}
bootems No
Debuggereinstellungen
---------------------
Bezeichner {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM-Defekte
-----------
Bezeichner {badmemory}
Globale Einstellungen
---------------------
Bezeichner {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Startladeprogramm-Einstellungen
-------------------------------
Bezeichner {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisoreinstellungen
-----------------------
Bezeichner {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner {resumeloadersettings}
inherit {globalsettings}
Geräteoptionen
--------------
Bezeichner {419231c8-70e0-11ee-bca5-b016f99ae24d}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume3
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Geräteoptionen
--------------
Bezeichner {815d685d-d8bc-11e5-a2be-ddcfe1d725b8}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\815d685c-d8bc-11e5-a2be-ddcfe1d725b8\boot.sdi
==================== Ende von FRST.txt ========================